How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Palo Alto Networks Sandbox API

{'$ref': 'desc/sandbox/sandbox.md'}

Palo Alto Networks Sandbox API is one of 741 APIs that Palo Alto Networks publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Sandbox. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 2 operations across 2 paths, and defines 68 schemas. It is described by OpenAPI 3.2.0, at version 1.0.

Requests are made against a single base URL, PATH_TO_CONSOLE.

2 operations 2 paths 68 schemas 2 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0
Base URL
https://{firewall}/api/
Resource Areas
1

Paths & Operations 2

Across 2 paths, the API surfaces 2 operations — 2 POST. Each is listed below with its method, path, parameters, and response codes.

Sandbox 2

Sandbox. 1 operation in this definition.

POST
/api/v34.03/sandbox
AddSandboxScanResult
post-sandbox body → 200default
POST
/api/v34.04/sandbox
AddSandboxScanResult
post-sandbox body → 200default

Schemas 68

The contract defines 68 schemas that model the data the API accepts and returns. The most detailed are shared.ImageInfo_3 (61 properties), shared.ImageInfo_2 (61 properties), shared.ImageInfo (60 properties), vuln.Vulnerability_3 (37 properties). Each schema is shown below with its type and property counts.

vuln.Application
object
Application represents a detected application
10 properties
sandbox.SuspiciousFile
object
SuspiciousFile represents a suspicious file
4 properties
vulnerability.ExploitType
string
ExploitType represents the source of an exploit
shared.ImageTag
object
ImageTag represents an image repository and its associated tag or registry digest
5 properties
common.CloudMetadata
object
CloudMetadata is the metadata for a cloud provider managed asset (e.g., as part of AWS/GCP/Azure/OCI)
15 properties
common.NetworkDeviceIP
object
NetworkDeviceIP represents a network device name and address pair
2 properties
common.Color
string
Color is a hexadecimal representation of color code value
sandbox.Event
object
Event is a single event in a chain that lead to finding detection
2 properties
common.ACIMetadata
object
1 property
secrets.SecretScanMetrics
object
SecretScanMetrics represents metrics collected during secret scan
10 properties
shared.Packages
object
Packages is a collection of packages
2 properties
vuln.ComplianceTemplate
string
ComplianceTemplate represents the compliance template
shared.FileDetails
object
FileDetails contains file details as the file path, hash checksum
5 properties
vuln.SecretType
string
SecretType represents a secret type
common.CloudRunMetadata
object
2 properties
sandbox.FindingType
string
FindingType represents a unique sandbox-detected finding type
vulnerability.RiskFactors
object
RiskFactors maps the existence of vulnerability risk factors
vulnerability.Type
string
Type represents the vulnerability type
common.CloudProvider
string
CloudProvider specifies the cloud provider name
vuln.AllCompliance
object
AllCompliance contains data regarding passed compliance checks
2 properties
sandbox.ScanResult
object
ScanResult represents sandbox scan results
16 properties
shared.PkgsTimes
object
PkgsTimes are the compressed layer times for pkgs of the specific type
2 properties
vulnerability.ExploitData
object
ExploitData holds information about an exploit
3 properties
common.ExternalLabel
object
ExternalLabel holds an external label with a source and timestamp
5 properties
string
string
common.GCPCloudMetadata
object
1 property
sandbox.FindingSeverity
string
FindingSeverity represents a finding severity level
sandbox.ConnectionEvent
object
ConnectionEvent represents a network connection event
6 properties
vuln.WildFireMalware
object
WildFireMalware holds the data for WildFire malicious MD5
3 properties
vuln.Secret
object
Secret represents a secret found on the scanned workload
12 properties
sandbox.ListeningEvent
object
ListeningEvent represents a network listening event
3 properties
vuln.Vulnerability
object
Vulnerability is a general schema for vulnerabilities (e.g., for compliance or packages)
37 properties
vuln.Distribution
object
Distribution counts the number of vulnerabilities per type
5 properties
sandbox.FilesystemAccessType
string
FilesystemAccessType represents a type of accessing a file
common.ExternalLabelSourceType
string
ExternalLabelSourceType indicates the source of the labels
sandbox.FilesystemEvent
object
FilesystemEvent represents a filesystem event during sandbox scan
4 properties
shared.Binary
object
Binary represents a detected binary file (ELF)
12 properties
sandbox.Finding
object
Finding represents a finding detected during sandbox scan
5 properties
common.ClusterType
string
ClusterType is the cluster type
sandbox.ProcessEvent
object
ProcessEvent represents a process event during sandbox scan
6 properties
sandbox.DNSQueryEvent
object
DNSQueryEvent represents a DNS query event with it's connection details
6 properties
shared.ImageHistory
object
ImageHistory represent a layer in the image's history
8 properties
packages.Type
string
Type describes the package type
shared.CompressedLayerTimes
object
CompressedLayerTimes represent the compressed layer times of the image apps and pkgs
2 properties
vuln.TagInfo
object
TagInfo is the tag info in a specific vulnerability context
3 properties
sandbox.ProcessInfo
object
ProcessInfo holds process information
5 properties
shared.Image
object
Image represents a container image
13 properties
int16
integer
int
integer
shared.InstalledProducts
object
InstalledProducts contains data regarding products running in environment TODO 34713: Swarm support was deprecated in Joule, remove swarm node/manager boolean…
24 properties
int64
integer
shared.Package
object
Package stores relevant package information
22 properties
common.AzureMetadata
object
2 properties
shared.ImageInfo
object
ImageInfo contains image information collected during image scan
60 properties
vulnerability.ExploitKind
string
ExploitKind represents the kind of the exploit
vulnerability.Exploits
array
Exploits represents the exploits data found for a CVE
vulnerability.VulnerabilityAttribute
integer
VulnerabilityAttribute represents a specific vulnerability property whose value may come from different sources
vuln.Vulnerability_2
object
Vulnerability is a general schema for vulnerabilities (e.g., for compliance or packages)
37 properties
vulnerability.VulnerabilityDataSource
object
VulnerabilityDataSource identifies the source of a specific vulnerability attribute. Example: CVSS from NVD, Severity from RedHat.
2 properties
vulnerability.VulnerabilityDataSources
array
VulnerabilityDataSources is a slice of VulnerabilityDataSource that implements the sql.Scanner and driver.Valuer interfaces
vulnerability.VulnerabilitySource
integer
VulnerabilitySource represents the authority that provided vulnerability-related data (severity, CVSS, links).
shared.InstalledProducts_2
object
InstalledProducts contains data regarding products running in environment TODO 34713: Swarm support was deprecated in Joule, remove swarm node/manager boolean…
25 properties
shared.Package_2
object
Package stores relevant package information
21 properties
shared.ImageInfo_2
object
ImageInfo contains image information collected during image scan
61 properties
vuln.Vulnerability_3
object
Vulnerability is a general schema for vulnerabilities (e.g., for compliance or packages)
37 properties
shared.InstalledProducts_3
object
InstalledProducts contains data regarding products running in environment TODO 34713: Swarm support was deprecated in Joule, remove swarm node/manager boolean…
25 properties
shared.Package_3
object
Package stores relevant package information
21 properties
shared.ImageInfo_3
object
ImageInfo contains image information collected during image scan
61 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

palo-alto-networks-sandbox-api-openapi.yml Raw ↑

Other APIs Palo Alto Networks publishes across the network.

PAN-OS XML API
PAN-OS OpenConfig API
Panorama API
AutoFocus API (Deprecated)
Prisma SASE Service Status API
Cross-Platform Service Status API
SASE Authentication Service API
Expedition API (Deprecated)
VM-Series Licensing API
Palo Alto Networks 5G Deregistered Trend API
Palo Alto Networks 5G Network Interconnects and Bandwidth API
Palo Alto Networks 5G Registered Trend API
Where this information came from

This is an independent, third-party profile of Palo Alto Networks Sandbox API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.