How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Palo Alto Networks Policies API

The Policies API from Palo Alto Networks — 82 operation(s) for policies.

Palo Alto Networks Policies API is one of 741 APIs that Palo Alto Networks publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Policies. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 139 operations across 82 paths, and defines 250 schemas. It is described by OpenAPI 3.2.0, at version 1.0.

Requests are made against 2 base URLs: https://api.prismacloud.io, PATH_TO_CONSOLE.

139 operations 82 paths 250 schemas 5 DELETE71 GET18 POST45 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0
Base URL
https://{firewall}/api/
Authentication
API Key
Resource Areas
1

Authentication & Security 1

Palo Alto Networks Policies API declares 1 security scheme for authenticating requests. An API key is passed in the header as authorization (CustomAuthorizer).

Paths & Operations 139

Across 82 paths, the API surfaces 139 operations — 5 DELETE, 71 GET, 18 POST, 45 PUT. Each is listed below with its method, path, parameters, and response codes.

Policies 139
POST
/code/api/v1/policies/definition/{queryId}
Validate Policies - Code-based
validateCustomPolicy 1 param body → 200400403422
POST
/code/api/v1/policiesdeprecated
Save New Policy
savePolicy body → 200202400403422500
GET
/code/api/v1/policies/table/datadeprecated
Get Custom Policies Table Data
getCustomPoliciesTable → 200500
PUT
/code/api/v1/policies/{policyId}deprecated
Update Policy
updatePolicy 1 param body → 200202400422500
DELETE
/code/api/v1/policies/{policyId}deprecated
Delete Policy
removePolicy 1 param → 200201404422500
POST
/code/api/v1/policies/preview
Policy Preview
policyPreview body → 200403404422500
POST
/code/api/v1/policies/clone/{policyId}deprecated
Policy Clone
clonePolicy 1 param body → 200400422500
GET
/api/v34.03/policies/compliance/ci/images
Get Continuous Integration (CI) Image Compliance Policy
get-policies-compliance-ci-images → 200default
PUT
/api/v34.03/policies/compliance/ci/images
Update Continuous Integration (CI) Image Compliance Policy
put-policies-compliance-ci-images body → 200default
GET
/api/v34.03/policies/compliance/ci/serverless
Get Continuous Integration (CI) Serverless Compliance Policy
get-policies-compliance-ci-serverless → 200default
PUT
/api/v34.03/policies/compliance/ci/serverless
Update Continuous Integration (CI) Serverless Compliance Policy
put-policies-compliance-ci-serverless body → 200default
GET
/api/v34.03/policies/compliance/container
Get Container Compliance Policy
get-policies-compliance-container → 200default
PUT
/api/v34.03/policies/compliance/container
Update Container Compliance Policy
put-policies-compliance-container body → 200default
GET
/api/v34.03/policies/compliance/container/impacted
Get Impacted Container Compliance Policy
get-policies-compliance-container-impacted 5 params → 200default
GET
/api/v34.03/policies/compliance/host
Get Host Compliance Policy
get-policies-compliance-host → 200default
PUT
/api/v34.03/policies/compliance/host
Update Host Compliance Policy
put-policies-compliance-host body → 200default
GET
/api/v34.03/policies/compliance/serverless
Get Serverless Compliance Policy
get-policies-compliance-serverless → 200default
PUT
/api/v34.03/policies/compliance/serverless
Update Serverless Compliance Policy
put-policies-compliance-serverless body → 200default
GET
/api/v34.03/policies/compliance/vms/impacted
Get Impacted VMs Compliance Policy
get-policies-compliance-vms-impacted 5 params → 200default
GET
/api/v34.03/policies/firewall/app/agentless
Get Agentless App Firewall Policy
get-policies-firewall-app-agentless → 200default
PUT
/api/v34.03/policies/firewall/app/agentless
Set Agentless App Firewall Policy
put-policies-firewall-app-agentless body → 200default
GET
/api/v34.03/policies/firewall/app/agentless/impacted
Get Agentless App Firewall Policy Impacted
get-policies-firewall-app-agentless-impacted 5 params → 200default
GET
/api/v34.03/policies/firewall/app/agentless/resources
Get Agentless App Firewall Policy Resources
get-policies-firewall-app-agentless-resources 5 params → 200default
GET
/api/v34.03/policies/firewall/app/agentless/state
Get Agentless App Firewall Policy State
get-policies-firewall-app-agentless-state → 200default
POST
/api/v34.03/policies/firewall/app/apispec
Generate a WAAS API Specification Object
post-policies-firewall-app-apispec → 200default
GET
/api/v34.03/policies/firewall/app/app-embedded
Get WAAS App-embedded Policy
get-policies-firewall-app-app-embedded → 200default
PUT
/api/v34.03/policies/firewall/app/app-embedded
Update WAAS App-embedded Policy
put-policies-firewall-app-app-embedded body → 200default
GET
/api/v34.03/policies/firewall/app/container
Get WAAS Container Policy
get-policies-firewall-app-container → 200default
PUT
/api/v34.03/policies/firewall/app/container
Update WAAS Container Policy
put-policies-firewall-app-container body → 200default
GET
/api/v34.03/policies/firewall/app/container/impacted
Container App Firewall Policy Impacted
get-policies-firewall-app-container-impacted 5 params → 200default
GET
/api/v34.03/policies/firewall/app/host
Get WAAS Host Policy
get-policies-firewall-app-host → 200default
PUT
/api/v34.03/policies/firewall/app/host
Update WAAS Host Policy
put-policies-firewall-app-host body → 200default
GET
/api/v34.03/policies/firewall/app/host/impacted
Host App Firewall Policy Impacted
get-policies-firewall-app-host-impacted 5 params → 200default
GET
/api/v34.03/policies/firewall/app/network-list
Get WAAS Network List
get-policies-firewall-app-network-list → 200default
POST
/api/v34.03/policies/firewall/app/network-list
Add WAAS Network List
post-policies-firewall-app-network-list body → 200default
PUT
/api/v34.03/policies/firewall/app/network-list
Update WAAS Network List
put-policies-firewall-app-network-list body → 200default
DELETE
/api/v34.03/policies/firewall/app/network-list/{id}
Delete WAAS Network List
delete-policies-firewall-app-network-list-id 1 param → 200default
GET
/api/v34.03/policies/firewall/app/out-of-band
Get Out-of-Band WAAS Policy
get-policies-firewall-app-out-of-band → 200default
PUT
/api/v34.03/policies/firewall/app/out-of-band
Update Out-of-Band WAAS Policy
put-policies-firewall-app-out-of-band body → 200default
GET
/api/v34.03/policies/firewall/app/out-of-band/impacted
Get Impacted Resources for Out-of-Band WAAS Policy
get-policies-firewall-app-out-of-band-impacted 5 params → 200default
GET
/api/v34.03/policies/firewall/app/serverless
Get WAAS Serverless Policy
get-policies-firewall-app-serverless → 200default
PUT
/api/v34.03/policies/firewall/app/serverless
Update WAAS Serverless Policy
put-policies-firewall-app-serverless body → 200default
GET
/api/v34.03/policies/firewall/network
Get CNNS Container and Host Policy
get-policies-firewall-network → 200default
PUT
/api/v34.03/policies/firewall/network
Update CNNS Container and Host Policy
put-policies-firewall-network body → 200default
GET
/api/v34.03/policies/runtime/app-embedded
Get Runtime App-embedded Policy
get-policies-runtime-app-embedded → 200default
POST
/api/v34.03/policies/runtime/app-embedded
Add Runtime App-embedded Policy
post-policies-runtime-app-embedded body → 200default
PUT
/api/v34.03/policies/runtime/app-embedded
Update Runtime App-embedded Policy
put-policies-runtime-app-embedded body → 200default
GET
/api/v34.03/policies/runtime/container
Get Runtime Container Policy
get-policies-runtime-container → 200default
POST
/api/v34.03/policies/runtime/container
Update Runtime Container Policy
post-policies-runtime-container body → 200default
PUT
/api/v34.03/policies/runtime/container
Set Container Runtime Policy
put-policies-runtime-container body → 200default
GET
/api/v34.03/policies/runtime/container/impacted
Update Runtime Impacted Container Policy
get-policies-runtime-container-impacted 5 params → 200default
GET
/api/v34.03/policies/runtime/host
Get Runtime Host Policy
get-policies-runtime-host → 200default
POST
/api/v34.03/policies/runtime/host
Update Runtime Host Policy
post-policies-runtime-host body → 200default
PUT
/api/v34.03/policies/runtime/host
Set Host Runtime Policy
put-policies-runtime-host body → 200default
GET
/api/v34.03/policies/runtime/serverless
Get Runtime Serverless Policy
get-policies-runtime-serverless → 200default
POST
/api/v34.03/policies/runtime/serverless
Update Runtime Serverless Policy
post-policies-runtime-serverless body → 200default
PUT
/api/v34.03/policies/runtime/serverless
Set Serverless Runtime Policy
put-policies-runtime-serverless body → 200default
GET
/api/v34.03/policies/vulnerability/base-images
Get Base Images Rules
get-policies-vulnerability-base-images → 200default
POST
/api/v34.03/policies/vulnerability/base-images
Add Base Images Rule
post-policies-vulnerability-base-images body → 200default
GET
/api/v34.03/policies/vulnerability/base-images/download
Download Base Images Rules
get-policies-vulnerability-base-images-download → 200default
DELETE
/api/v34.03/policies/vulnerability/base-images/{id}
Delete Base Images Rule
delete-policies-vulnerability-base-images-id 1 param → 200default
GET
/api/v34.03/policies/vulnerability/ci/images
Get CI Image Vulnerability Policy
get-policies-vulnerability-ci-images → 200default
PUT
/api/v34.03/policies/vulnerability/ci/images
Update CI Image Vulnerability Policy
put-policies-vulnerability-ci-images body → 200default
GET
/api/v34.03/policies/vulnerability/ci/serverless
Get CI Serverless Vulnerability Policy
get-policies-vulnerability-ci-serverless → 200default
PUT
/api/v34.03/policies/vulnerability/ci/serverless
Update CI Serverless Vulnerability Policy
put-policies-vulnerability-ci-serverless body → 200default
GET
/api/v34.03/policies/vulnerability/host
Get Host Vulnerability Policy
get-policies-vulnerability-host → 200default
PUT
/api/v34.03/policies/vulnerability/host
Update Host Vulnerability Policy
put-policies-vulnerability-host body → 200default
GET
/api/v34.03/policies/vulnerability/host/impacted
Get Impacted Host Vulnerability Policy
get-policies-vulnerability-host-impacted 5 params → 200default
GET
/api/v34.03/policies/vulnerability/images
Get Image Vulnerability Policy
get-policies-vulnerability-images → 200default
PUT
/api/v34.03/policies/vulnerability/images
Update Image Vulnerability Policy
put-policies-vulnerability-images body → 200default
GET
/api/v34.03/policies/vulnerability/images/impacted
Get Impacted Image Vulnerability Policy
get-policies-vulnerability-images-impacted 5 params → 200default
GET
/api/v34.03/policies/vulnerability/serverless
Get Serverless Vulnerability Policy
get-policies-vulnerability-serverless → 200default
PUT
/api/v34.03/policies/vulnerability/serverless
Update Serverless Vulnerability Policy
put-policies-vulnerability-serverless body → 200default
GET
/api/v34.04/policies/compliance/ci/images
Get Continuous Integration (CI) Image Compliance Policy
get-policies-compliance-ci-images → 200default
PUT
/api/v34.04/policies/compliance/ci/images
Update Continuous Integration (CI) Image Compliance Policy
put-policies-compliance-ci-images body → 200default
GET
/api/v34.04/policies/compliance/ci/serverless
Get Continuous Integration (CI) Serverless Compliance Policy
get-policies-compliance-ci-serverless → 200default
PUT
/api/v34.04/policies/compliance/ci/serverless
Update Continuous Integration (CI) Serverless Compliance Policy
put-policies-compliance-ci-serverless body → 200default
GET
/api/v34.04/policies/compliance/container
Get Container Compliance Policy
get-policies-compliance-container → 200default
PUT
/api/v34.04/policies/compliance/container
Update Container Compliance Policy
put-policies-compliance-container body → 200default
GET
/api/v34.04/policies/compliance/container/impacted
Get Impacted Container Compliance Policy
get-policies-compliance-container-impacted 5 params → 200default
GET
/api/v34.04/policies/compliance/host
Get Host Compliance Policy
get-policies-compliance-host → 200default
PUT
/api/v34.04/policies/compliance/host
Update Host Compliance Policy
put-policies-compliance-host body → 200default
GET
/api/v34.04/policies/compliance/serverless
Get Serverless Compliance Policy
get-policies-compliance-serverless → 200default
PUT
/api/v34.04/policies/compliance/serverless
Update Serverless Compliance Policy
put-policies-compliance-serverless body → 200default
GET
/api/v34.04/policies/compliance/vms/impacted
Get Impacted VMs Compliance Policy
get-policies-compliance-vms-impacted 5 params → 200default
GET
/api/v34.04/policies/firewall/app/agentless
Get Agentless App Firewall Policy
get-policies-firewall-app-agentless → 200default
PUT
/api/v34.04/policies/firewall/app/agentless
Set Agentless App Firewall Policy
put-policies-firewall-app-agentless body → 200default
GET
/api/v34.04/policies/firewall/app/agentless/impacted
Get Agentless App Firewall Policy Impacted
get-policies-firewall-app-agentless-impacted 5 params → 200default
GET
/api/v34.04/policies/firewall/app/agentless/resources
Get Agentless App Firewall Policy Resources
get-policies-firewall-app-agentless-resources 5 params → 200default
GET
/api/v34.04/policies/firewall/app/agentless/state
Get Agentless App Firewall Policy State
get-policies-firewall-app-agentless-state → 200default
POST
/api/v34.04/policies/firewall/app/apispec
Generate a WAAS API Specification Object
post-policies-firewall-app-apispec → 200default
GET
/api/v34.04/policies/firewall/app/app-embedded
Get WAAS App-embedded Policy
get-policies-firewall-app-app-embedded → 200default
PUT
/api/v34.04/policies/firewall/app/app-embedded
Update WAAS App-embedded Policy
put-policies-firewall-app-app-embedded body → 200default
GET
/api/v34.04/policies/firewall/app/container
Get WAAS Container Policy
get-policies-firewall-app-container → 200default
PUT
/api/v34.04/policies/firewall/app/container
Update WAAS Container Policy
put-policies-firewall-app-container body → 200default
GET
/api/v34.04/policies/firewall/app/container/impacted
Container App Firewall Policy Impacted
get-policies-firewall-app-container-impacted 5 params → 200default
GET
/api/v34.04/policies/firewall/app/host
Get WAAS Host Policy
get-policies-firewall-app-host → 200default
PUT
/api/v34.04/policies/firewall/app/host
Update WAAS Host Policy
put-policies-firewall-app-host body → 200default
GET
/api/v34.04/policies/firewall/app/host/impacted
Host App Firewall Policy Impacted
get-policies-firewall-app-host-impacted 5 params → 200default
GET
/api/v34.04/policies/firewall/app/network-list
Get WAAS Network List
get-policies-firewall-app-network-list → 200default
POST
/api/v34.04/policies/firewall/app/network-list
Add WAAS Network List
post-policies-firewall-app-network-list body → 200default
PUT
/api/v34.04/policies/firewall/app/network-list
Update WAAS Network List
put-policies-firewall-app-network-list body → 200default
DELETE
/api/v34.04/policies/firewall/app/network-list/{id}
Delete WAAS Network List
delete-policies-firewall-app-network-list-id 1 param → 200default
GET
/api/v34.04/policies/firewall/app/out-of-band
Get Out-of-Band WAAS Policy
get-policies-firewall-app-out-of-band → 200default
PUT
/api/v34.04/policies/firewall/app/out-of-band
Update Out-of-Band WAAS Policy
put-policies-firewall-app-out-of-band body → 200default
GET
/api/v34.04/policies/firewall/app/out-of-band/impacted
Get Impacted Resources for Out-of-Band WAAS Policy
get-policies-firewall-app-out-of-band-impacted 5 params → 200default
GET
/api/v34.04/policies/firewall/app/serverless
Get WAAS Serverless Policy
get-policies-firewall-app-serverless → 200default
PUT
/api/v34.04/policies/firewall/app/serverless
Update WAAS Serverless Policy
put-policies-firewall-app-serverless body → 200default
GET
/api/v34.04/policies/firewall/network
Get CNNS Container and Host Policy
get-policies-firewall-network → 200default
PUT
/api/v34.04/policies/firewall/network
Update CNNS Container and Host Policy
put-policies-firewall-network body → 200default
GET
/api/v34.04/policies/runtime/app-embedded
Get Runtime App-embedded Policy
get-policies-runtime-app-embedded → 200default
POST
/api/v34.04/policies/runtime/app-embedded
Add Runtime App-embedded Policy
post-policies-runtime-app-embedded body → 200default
PUT
/api/v34.04/policies/runtime/app-embedded
Update Runtime App-embedded Policy
put-policies-runtime-app-embedded body → 200default
GET
/api/v34.04/policies/runtime/container
Get Runtime Container Policy
get-policies-runtime-container → 200default
POST
/api/v34.04/policies/runtime/container
Update Runtime Container Policy
post-policies-runtime-container body → 200default
PUT
/api/v34.04/policies/runtime/container
Set Container Runtime Policy
put-policies-runtime-container body → 200default
GET
/api/v34.04/policies/runtime/container/impacted
Update Runtime Impacted Container Policy
get-policies-runtime-container-impacted 5 params → 200default
GET
/api/v34.04/policies/runtime/host
Get Runtime Host Policy
get-policies-runtime-host → 200default
POST
/api/v34.04/policies/runtime/host
Update Runtime Host Policy
post-policies-runtime-host body → 200default
PUT
/api/v34.04/policies/runtime/host
Set Host Runtime Policy
put-policies-runtime-host body → 200default
GET
/api/v34.04/policies/runtime/serverless
Get Runtime Serverless Policy
get-policies-runtime-serverless → 200default
POST
/api/v34.04/policies/runtime/serverless
Update Runtime Serverless Policy
post-policies-runtime-serverless body → 200default
PUT
/api/v34.04/policies/runtime/serverless
Set Serverless Runtime Policy
put-policies-runtime-serverless body → 200default
GET
/api/v34.04/policies/vulnerability/base-images
Get Base Images Rules
get-policies-vulnerability-base-images → 200default
POST
/api/v34.04/policies/vulnerability/base-images
Add Base Images Rule
post-policies-vulnerability-base-images body → 200default
GET
/api/v34.04/policies/vulnerability/base-images/download
Download Base Images Rules
get-policies-vulnerability-base-images-download → 200default
DELETE
/api/v34.04/policies/vulnerability/base-images/{id}
Delete Base Images Rule
delete-policies-vulnerability-base-images-id 1 param → 200default
GET
/api/v34.04/policies/vulnerability/ci/images
Get CI Image Vulnerability Policy
get-policies-vulnerability-ci-images → 200default
PUT
/api/v34.04/policies/vulnerability/ci/images
Update CI Image Vulnerability Policy
put-policies-vulnerability-ci-images body → 200default
GET
/api/v34.04/policies/vulnerability/ci/serverless
Get CI Serverless Vulnerability Policy
get-policies-vulnerability-ci-serverless → 200default
PUT
/api/v34.04/policies/vulnerability/ci/serverless
Update CI Serverless Vulnerability Policy
put-policies-vulnerability-ci-serverless body → 200default
GET
/api/v34.04/policies/vulnerability/host
Get Host Vulnerability Policy
get-policies-vulnerability-host → 200default
PUT
/api/v34.04/policies/vulnerability/host
Update Host Vulnerability Policy
put-policies-vulnerability-host body → 200default
GET
/api/v34.04/policies/vulnerability/host/impacted
Get Impacted Host Vulnerability Policy
get-policies-vulnerability-host-impacted 5 params → 200default
GET
/api/v34.04/policies/vulnerability/images
Get Image Vulnerability Policy
get-policies-vulnerability-images → 200default
PUT
/api/v34.04/policies/vulnerability/images
Update Image Vulnerability Policy
put-policies-vulnerability-images body → 200default
GET
/api/v34.04/policies/vulnerability/images/impacted
Get Impacted Image Vulnerability Policy
get-policies-vulnerability-images-impacted 5 params → 200default
GET
/api/v34.04/policies/vulnerability/serverless
Get Serverless Vulnerability Policy
get-policies-vulnerability-serverless → 200default
PUT
/api/v34.04/policies/vulnerability/serverless
Update Serverless Vulnerability Policy
put-policies-vulnerability-serverless body → 200default

Schemas 250

The contract defines 250 schemas that model the data the API accepts and returns. The most detailed are shared.ImageScanResult_2 (89 properties), shared.ImageScanResult_3 (89 properties), shared.ImageScanResult (87 properties), vuln.Vulnerability (37 properties). Each schema is shown below with its type and property counts.

AlibabaCloudResourceTypes
string
MetadataPolicy
object
4 properties 4 required
ProviderBigType
string
Definition
KubernetesResourceTypes
string
CategoryTypeBig
string
PolicyValidation
ConnectionQuery
object
4 properties 4 required
AndQuery
object
1 property
AccountData
object
2 properties 2 required
PolicyCode
object
1 property 1 required
BenchmarksIds
object
PolicyPreviewBody
object
5 properties
PoliciesTableData
object
7 properties 7 required
AwsResourceTypes
string
SeverityTypeBig
string
PolicyDefinition
object
3 properties 2 required
CloudFormationResourceTypes
string
PreviewDataResults
object
10 properties 10 required
OrQuery
object
1 property 1 required
ErrorsReturn
object
1 property 1 required
ProviderType
string
ResourceType
object
2 properties 2 required
SeverityType
string
FrameworkTypes
string
QueryPreview
object
3 properties 1 required
PoliciesTable
object
2 properties 2 required
PolicyRes
object
1 property 1 required
AttributeOperator
AccountsData
object
ComplexQuery
object
3 properties
filters
object
7 properties 7 required
CategoryType
string
SecretsQuery
object
2 properties 1 required
ClonePolicy
object
11 properties
ScopePolicy
object
1 property 1 required
FilterQuery
object
4 properties 4 required
Amount
object
6 properties 6 required
ErrorMessage
object
1 property 1 required
AzureResourceTypes
string
policyPreviewResult
object
2 properties 1 required
BaseAttributeOperator
string
ErrorResponse
object
2 properties
GcpResourceTypes
string
ResourceTypes
object
PolicyPreviewDetails
object
1 property 1 required
AttributeQuery
object
5 properties 4 required
waas.ParamStyle
string
ParamStyle is a param format style, defined by OpenAPI specification It describes how the parameter value will be serialized depending on the type of the param…
waas.KnownBotProtectionsSpec
object
KnownBotProtectionsSpec is the known bot protections spec
9 properties
vulnerability.ExploitType
string
ExploitType represents the source of an exploit
shared.ImageTag
object
ImageTag represents an image repository and its associated tag or registry digest
5 properties
common.NetworkDeviceIP
object
NetworkDeviceIP represents a network device name and address pair
2 properties
common.HostForensicSettings
object
HostForensicSettings indicates how to perform host forensic
6 properties
waas.ParamType
string
ParamType is the type of a parameter, defined by OpenAPI specification Ref: https://github.com/OAI/OpenAPI-Specification/blob/master/versions/2.0.mddata-types
common.ACIMetadata
object
1 property
shared.Port
object
Port is a container port
3 properties
shared.FileDetails
object
FileDetails contains file details as the file path, hash checksum
5 properties
vuln.SecretType
string
SecretType represents a secret type
vulnerability.RiskFactors
object
RiskFactors maps the existence of vulnerability risk factors
runtime.ContainerNetworkRule
object
ContainerNetworkRule represents the restrictions/suppression for networking
10 properties
shared.ImageInstance
object
ImageInstance represents an image on a single host
6 properties
shared.PkgsTimes
object
PkgsTimes are the compressed layer times for pkgs of the specific type
2 properties
trust.Status
string
Status is the trust status for an image
shared.Conditions
object
Conditions contains rule conditions. Conditions apply only for their respective policy type
3 properties
waas.VPCConfigStatus
string
VPCConfigStatus is the status of a VPC configuration deployment
waas.DoSRates
object
DoSRates specifies dos requests rates (thresholds)
2 properties
waas.RequestAnomalyThreshold
integer
RequestAnomalyThreshold is the score threshold for which request anomaly violation is triggered
agentless.ImageScanResultErrCode
integer
ImageScanResultErrCode represents the asset status error
customrules.Action
string
Action is the action to perform if the custom rule applies
runtime.HostPolicy
object
HostPolicy represents a host runtime policy enforced for a given running resource
3 properties
runtime.ContainerPolicy
object
ContainerPolicy represents a runtime policy enforced for a given running resource
3 properties
waas.UnknownBotProtectionSpec
object
UnknownBotProtectionSpec is the unknown bot protection spec
8 properties
customrules.Ref
object
Ref represents a custom rule that is referenced by a policy rule
3 properties
shared.BlockThreshold
object
BlockThreshold is the vulnerability policy block threshold Threshold values typically vary between 0 and 10 (noninclusive)
2 properties
waas.MaliciousUploadConfig
object
MaliciousUploadConfig is the configuration for file upload protection
3 properties
common.PortRange
object
PortRange represents a port range
3 properties
runtime.PortListRule
object
PortListRule represents a rule containing ports to allowed/denied and the required effect
3 properties
shared.ImageHosts
object
ImageHosts is a fast index for image scan results metadata per host
runtime.AntiMalwareRule
object
AntiMalwareRule represents restrictions/suppression for suspected anti-malware
16 properties
runtime.ContainerDNSRule
object
ContainerDNSRule is the DNS runtime rule for container
3 properties
runtime.DenyListRule
object
DenyListRule represents a rule containing paths of files and processes to alert/prevent and the required effect
2 properties
vulnerability.RiskFactor
string
RiskFactor represents a vulnerability risk factor, used in determining a vulnerability risk score
common.ClusterType
string
ClusterType is the cluster type
shared.LicenseConfig
object
LicenseConfig is the compliance policy license configuration
6 properties
waas.FeatureExceptions
object
FeatureExceptions represents subnets that should bypass WAAS features
1 property
shared.CompressedLayerTimes
object
CompressedLayerTimes represent the compressed layer times of the image apps and pkgs
2 properties
shared.ImageHistory
object
ImageHistory represent a layer in the image's history
8 properties
types.ImpactedOutOfBandEntity
object
ImpactedOutOfBandEntity holds the info of an impacted out of band entity
3 properties
waas.OutOfBandMode
string
OutOfBandMode holds the app firewall out-of-band mode
runtime.FileIntegrityRule
object
FileIntegrityRule represents a single file integrity monitoring rule
8 properties
shared.ContainerPort
object
ContainerPort represents the state of a port in a given container
5 properties
waas.CustomBlockResponseConfig
object
CustomBlockResponseConfig is a custom block message config for a policy
3 properties
int
integer
shared.InstalledProducts
object
InstalledProducts contains data regarding products running in environment TODO 34713: Swarm support was deprecated in Joule, remove swarm node/manager boolean…
24 properties
int64
integer
runtime.ServerlessPolicy
object
ServerlessPolicy represents a serverless runtime policy enforced for a given running resource
3 properties
runtime.HostDNSRule
object
HostDNSRule represents a host DNS runtime rule
4 properties
common.AzureMetadata
object
2 properties
waas.DoSConfig
object
DoSConfig is a dos policy specification
6 properties
cnnf.RuleID
integer
RuleID represents the ID of each container network firewall policy rule
runtime.ContainerFilesystemRule
object
ContainerFilesystemRule represents restrictions/suppression for filesystem changes
8 properties
vulnerability.ExploitKind
string
ExploitKind represents the kind of the exploit
types.BaseImage
object
BaseImage represents an image which is defined as a base image
3 properties
waas.Param
object
Param contains a parameter information
10 properties
shared.ScanResultType
string
ScanResultType represents a cloud scan result type
-_waas.VPCConfigMirroredResource
array
runtime.ContainerPolicyRule
object
ContainerPolicyRule represents a single rule in the runtime policy
17 properties
collection.Collection
object
Collection is a collection of resources
16 properties
waas.VPCConfigMirroredResource
object
VPCConfigMirroredResource is a resource(vm or LB) mirrored by a VPC configuration deployment
2 properties
common.CloudProvider
string
CloudProvider specifies the cloud provider name
vuln.AllCompliance
object
AllCompliance contains data regarding passed compliance checks
2 properties
cnnf.RuleEntityType
string
RuleEntityType is the network firewall rule entity type
vuln.Secret
object
Secret represents a secret found on the scanned workload
12 properties
vuln.WildFireMalware
object
WildFireMalware holds the data for WildFire malicious MD5
3 properties
waas.OutOfBandRuleScope
string
OutOfBandRuleScope represents the Out-of-Band Rule Scope
vuln.Vulnerability
object
Vulnerability is a general schema for vulnerabilities (e.g., for compliance or packages)
37 properties
waas.UserDefinedBot
object
UserDefinedBot indicates a user-defined bot and its effect
5 properties
vuln.Distribution
object
Distribution counts the number of vulnerabilities per type
5 properties
waas.IntelGatheringConfig
object
IntelGatheringConfig is the configuration for intelligence gathering protections
2 properties
shared.ContainerScanResult
object
ContainerScanResult contains the result of a scanning a container
11 properties
common.ExternalLabelSourceType
string
ExternalLabelSourceType indicates the source of the labels
shared.Binary
object
Binary represents a detected binary file (ELF)
12 properties
runtime.NetworkRule
object
NetworkRule represents the restrictions/suppression for networking
7 properties
waas.Endpoint
object
Endpoint is an application endpoint
7 properties
waas.FileType
string
FileType is the type of an uploaded file
waas.CertificateMeta
object
CertificateMeta is the certificate metadata
3 properties
waas.AutoApplyPatchesSpec
object
AutoApplyPatchesSpec is the configuration for automation apply patches protection
1 property
runtime.HostPolicyRule
object
HostPolicyRule represents a single rule in the runtime policy
14 properties
shared.RiskFactorEffect
object
RiskFactorEffect represents the effect which is applied by a risk factor
2 properties
waas.VPCConfigState
object
VPCConfigState is the state of a VPC configuration This includes only the state needed by the frontend bson bindings do not omit empty as the structure is upda…
4 properties
trust.ImageResult
object
ImageResult represents an aggregated image trust result
2 properties
vuln.Condition
object
Condition are extended options for vulnerability assessment in authorization flows
2 properties
cnnf.Policy
object
Policy holds the data for firewall policies (host and container)
8 properties
shared.ImageHost
object
ImageHost holds information about image scan result per host
9 properties
shared.ContainerProcess
object
ContainerProcess represents a process inside a container
1 property
waas.ParamLocation
string
ParamLocation is the location of a parameter
vuln.ExpirationDate
object
ExpirationDate is the vulnerability expiration date
2 properties
vuln.Application
object
Application represents a detected application
10 properties
runtime.LogInspectionRule
object
LogInspectionRule represents a single log inspection rule
2 properties
waas.NetworkControls
object
NetworkControls contains the network controls config (e.g., access controls for IPs and countries)
5 properties
-_types.BaseImagesRule
array
-_types.ImpactedOutOfBandEntity
array
waas.StatusCodeRange
object
StatusCodeRange represents a status code range
2 properties
waas.RemoteHostForwardingConfig
object
RemoteHostForwardingConfig defines a remote host to forward requests to
2 properties
waas.Rule
object
Rule details for an application firewall
15 properties
runtime.ContainerProcessesRule
object
ContainerProcessesRule represents restrictions/suppression for running processes
10 properties
waas.SameSite
string
SameSite allows a server to define a cookie attribute making it impossible for the browser to send this cookie along with cross-site requests. The main goal is…
shared.LicenseThreshold
object
LicenseThreshold is the license severity threshold to indicate whether to perform an action (alert/block) Threshold values typically vary between 0 and 10 (non…
2 properties
secrets.SecretScanMetrics
object
SecretScanMetrics represents metrics collected during secret scan
10 properties
common.CloudRunMetadata
object
2 properties
vuln.ComplianceTemplate
string
ComplianceTemplate represents the compliance template
waas.AgentlessPolicyState
object
AgentlessPolicyState is the state of the agentless policy
2 properties
vulnerability.Type
string
Type represents the vulnerability type
common.ExternalLabel
object
ExternalLabel holds an external label with a source and timestamp
5 properties
vulnerability.ExploitData
object
ExploitData holds information about an exploit
3 properties
string
string
cnnf.Rule
object
Rule contains the properties common to both host and container network firewall
11 properties
common.Secret
object
Secret Stores the plain and encrypted version of a value. The plain version is not stored in a database
2 properties
shared.CVERule
object
CVERule is a vuln rule for specific vulnerability
4 properties
shared.GraceDaysPolicy
object
GraceDaysPolicy indicates the grace days policy by severity
5 properties
waas.Policy
object
Policy representation details
4 properties
waas.ExceptionField
object
ExceptionField is used to perform the protection exception fields
5 properties
common.Effect
string
Effect is the effect that is used in the CNNF rule
common.PolicyEffect
string
PolicyEffect state the effect of evaluating the given policy
shared.Policy
object
Policy represents a policy that should be enforced by the Auditor
3 properties
waas.ProtectionConfig
object
ProtectionConfig represents a WAAS protection config
2 properties
shared.ScanType
string
ScanType displays the components for an ongoing scan
cnnf.Subnet
object
Subnet is a network firewall subnet
2 properties
waas.ProtectionStatus
object
ProtectionStatus describes the status of the WAAS protection
6 properties
shared.TagRule
object
TagRule is a tag rule for specific vulnerabilities
4 properties
cnnf.NetworkEntities
array
NetworkEntities represents a list of network firewall entities
waas.AccessControls
object
AccessControls contains the access controls config (e.g., denied/allowed sources)
6 properties
waas.TLSConfig
object
TLSConfig holds the user TLS configuration and the certificate data
3 properties
trust.Group
object
Group represents a group of images
9 properties
packages.Type
string
Type describes the package type
shared.PkgTypeThreshold
object
PkgTypeThreshold represents specific vulnerability alert and block thresholds for a package type
3 properties
waas.BotProtectionSpec
object
BotProtectionSpec is the bot protections spec
7 properties
waas.CustomReCAPTCHAPageSpec
object
CustomReCAPTCHAPageSpec is the custom reCAPTCHA page spec
2 properties
runtime.RuleEffect
string
RuleEffect is the effect that will be used in the runtime rule
runtime.HostNetworkRule
object
HostNetworkRule represents the restrictions/suppression for host networking
7 properties
waas.ReCAPTCHASpec
object
ReCAPTCHASpec is the reCAPTCHA spec
7 properties
vuln.TagInfo
object
TagInfo is the tag info in a specific vulnerability context
3 properties
waas.ReCAPTCHAType
string
ReCAPTCHAType is the reCAPTCHA configured type
runtime.AppEmbeddedPolicyRule
object
AppEmbeddedPolicyRule represents a single rule in the app embedded runtime policy
14 properties
shared.ContainerInfo
object
ContainerInfo contains all information gathered on a specific container
25 properties
shared.DockerNetworkInfo
object
DockerNetworkInfo contains network-related information about a container
4 properties
common.PolicyType
string
PolicyType represents the type of the policy
vulnerability.Exploits
array
Exploits represents the exploits data found for a CVE
waas.JSInjectionSpec
object
JSInjectionSpec is the js injection protection spec
2 properties
runtime.ServerlessPolicyRule
object
ServerlessPolicyRule represents a single rule in the serverless runtime policy
17 properties
wildfire.Usage
object
Usage holds wildfire usage stats, period for the usage varies with context
3 properties
runtime.FilesystemRule
object
FilesystemRule represents restrictions/suppression for filesystem changes
7 properties
common.CloudMetadata
object
CloudMetadata is the metadata for a cloud provider managed asset (e.g., as part of AWS/GCP/Azure/OCI)
15 properties
waas.VPCConfigResource
object
VPCConfigResource is a resource created by a VPC configuration deployment
3 properties
shared.PolicyRule
object
PolicyRule is a single rule in the policy
28 properties
waas.UnprotectedProcess
object
UnprotectedProcess holds unprotected processes alongside the port
3 properties
-_waas.VPCConfigResource
array
common.Color
string
Color is a hexadecimal representation of color code value
customrules.Effect
string
Effect is the effect that will be used for custom rule
runtime.DNSRule
object
DNSRule is the DNS runtime rule
3 properties
shared.Packages
object
Packages is a collection of packages
2 properties
types.BaseImagesRule
object
BaseImagesRule holds the base images defined by a single scope
3 properties
common.GCPCloudMetadata
object
1 property
waas.ApplicationSpec
object
ApplicationSpec is an application of a firewall instance
32 properties
cnnf.AllowAllConnections
object
AllowAllConnections indicates if connections are allowed to/from any entity of the specified types e.g. if inbound contains the type subnet, the entity is allo…
2 properties
waas.BodyConfig
object
BodyConfig represents app configuration related to HTTP Body
3 properties
shared.NetworkInfo
object
NetworkInfo contains data about a container regarding a specific network
3 properties
common.PolicyBlockMsg
string
PolicyBlockMsg represent the block message in a Policy
waas.NetworkList
object
NetworkList represent network list of IP/CIDR in waas
9 properties
runtime.DNSListRule
object
DNSListRule represents an explicitly allowed/denied domains list rule
3 properties
waas.Effect
string
Effect is the effect that will be used in the rule
trust.HostStatus
object
HostStatus represents an image trust status on a host
2 properties
shared.ImageScanResult
object
ImageScanResult holds the result of an image scan
87 properties
waas.MinTLSVersion
string
MinTLSVersion is the list of acceptable TLS versions
waas.ExceptionLocation
string
ExceptionLocation indicates exception http field location
waas.APISpec
object
APISpec is an API specification
6 properties
waas.RequestAnomalies
object
RequestAnomalies is the request anomalies spec
2 properties
shared.ContainerNetwork
object
ContainerNetwork contains details about the container network (ports, IPs, type etc...)
1 property
waas.Path
object
Path is an API path information
2 properties
waas.HSTSConfig
object
HSTSConfig is the HTTP Strict Transport Security configuration in order to enforce HSTS header see: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/S…
4 properties
shared.AlertThreshold
object
AlertThreshold is the vulnerability policy alert threshold Threshold values typically vary between 0 and 10 (noninclusive)
2 properties
waas.DoSMatchCondition
object
DoSMatchCondition is used for matching a request for tracking
3 properties
vuln.Effect
string
Effect specifies relevant action for a vulnerability
waas.TrafficMirroringConfig
object
TrafficMirroringConfig specifies the traffic mirroring configuration is fine in that case
3 properties
shared.Image
object
Image represents a container image
13 properties
int16
integer
-_shared.ContainerScanResult
array
-_waas.NetworkList
array
waas.VPCConfig
object
VPCConfig is the VPC configuration (there is a 1-to-1 relation with the rule, only one configuration per rule)
15 properties
waas.HeaderSpec
object
HeaderSpec is specification for a single header and its allowed or blocked values
5 properties
waas.Method
object
Method is a method information
2 properties
shared.Package
object
Package stores relevant package information
22 properties
runtime.ProcessesRule
object
ProcessesRule represents restrictions/suppression for running processes
8 properties
runtime.AppEmbeddedPolicy
object
AppEmbeddedPolicy represents a runtime policy enforced for a given running resource
2 properties
waas.ResponseHeaderSpec
object
ResponseHeaderSpec is specification for a single response header to modify
3 properties
cnnf.EntityID
integer
EntityID represents the ID of each network firewall entity. 20 bits are used. Max legal value: 2^20-1
-_shared.ImageScanResult
array
cnnf.NetworkEntity
object
NetworkEntity represents a network firewall entity
7 properties
shared.InstalledProducts_2
object
InstalledProducts contains data regarding products running in environment TODO 34713: Swarm support was deprecated in Joule, remove swarm node/manager boolean…
25 properties
vuln.Vulnerability_2
object
Vulnerability is a general schema for vulnerabilities (e.g., for compliance or packages)
37 properties
vulnerability.VulnerabilityDataSource
object
VulnerabilityDataSource identifies the source of a specific vulnerability attribute. Example: CVSS from NVD, Severity from RedHat.
2 properties
vulnerability.VulnerabilitySource
integer
VulnerabilitySource represents the authority that provided vulnerability-related data (severity, CVSS, links).
vulnerability.VulnerabilityAttribute
integer
VulnerabilityAttribute represents a specific vulnerability property whose value may come from different sources
shared.ImageScanResult_2
object
ImageScanResult holds the result of an image scan
89 properties
vulnerability.VulnerabilityDataSources
array
VulnerabilityDataSources is a slice of VulnerabilityDataSource that implements the sql.Scanner and driver.Valuer interfaces
shared.Package_2
object
Package stores relevant package information
21 properties
shared.InstalledProducts_3
object
InstalledProducts contains data regarding products running in environment TODO 34713: Swarm support was deprecated in Joule, remove swarm node/manager boolean…
25 properties
vuln.Vulnerability_3
object
Vulnerability is a general schema for vulnerabilities (e.g., for compliance or packages)
37 properties
shared.ImageScanResult_3
object
ImageScanResult holds the result of an image scan
89 properties
shared.Package_3
object
Package stores relevant package information
21 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

palo-alto-networks-policies-api-openapi.yml Raw ↑

Other APIs Palo Alto Networks publishes across the network.

PAN-OS XML API
PAN-OS OpenConfig API
Panorama API
AutoFocus API (Deprecated)
Prisma SASE Service Status API
Cross-Platform Service Status API
SASE Authentication Service API
Expedition API (Deprecated)
VM-Series Licensing API
Palo Alto Networks 5G Deregistered Trend API
Palo Alto Networks 5G Network Interconnects and Bandwidth API
Palo Alto Networks 5G Registered Trend API
Where this information came from

This is an independent, third-party profile of Palo Alto Networks Policies API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.