How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Palo Alto Networks Scan API

Operations for creating and managing scan jobs.

Palo Alto Networks Scan API is one of 741 APIs that Palo Alto Networks publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Scans. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 4 operations across 3 paths, and defines 37 schemas. It is described by OpenAPI 3.2.0, at version 0.7.75.

Requests are made against a single base URL, https://api.sase.paloaltonetworks.com/ai-red-teaming/data-plane.

4 operations 3 paths 37 schemas 2 GET2 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
0.7.75
Base URL
https://{firewall}/api/
Authentication
HTTP Bearer
License
Terms of Service
Resource Areas
1

Authentication & Security 1

Palo Alto Networks Scan API declares 1 security scheme for authenticating requests. It accepts HTTP bearer tokens (JWT) (bearerAuth). By default, every request must be authenticated.

Paths & Operations 4

Across 3 paths, the API surfaces 4 operations — 2 GET, 2 POST. Each is listed below with its method, path, parameters, and response codes.

Scan 4

Operations for creating and managing scan jobs.

POST
/v1/scan
Create scan
create_job_v1_scan_post body → 200422
GET
/v1/scan
List scans
list_jobs_v1_scan_get 6 params → 200422
GET
/v1/scan/{job_id}
Get scan details
get_job_v1_scan__job_id__get 1 param → 200422
POST
/v1/scan/{job_id}/abort
Abort scan
abort_job_v1_scan__job_id__abort_post 1 param → 200422

Schemas 37

The contract defines 37 schemas that model the data the API accepts and returns. The most detailed are TargetReferenceSchema (28 properties), JobResponseSchema (23 properties), DynamicJobMetadata (19 properties), TargetMetadata (15 properties). Each schema is shown below with its type and property counts.

StaticJobMetadata
object
Enhanced metadata for static attack jobs with validation.
12 properties 1 required
AuthType
string
Authentication method for target API access.
PaginationSchema
object
1 property
Category
string
ResponseMode
string
Response mode for target interactions.
GoalCategory
string
ClaraJobMetadata
object
Metadata for CLARA scan jobs. Intentionally minimal — no ratelimit/contentfilter since CLARA doesn't execute attacks.
3 properties 1 required
DynamicJobMetadata
object
Enhanced metadata for dynamic attack jobs with proper constraints.
19 properties
CountedQuotaEnum
string
Enum for counting Quota.
TargetBackground
object
Target background - used in create/update API requests and stored in DB/GCS. Required fields for activation: - industry (string, required) - usecase (string, r…
4 properties
TargetAdditionalContext
object
Additional context - used in create/update API requests and stored in DB/GCS. Single value fields are strings. List fields are lists of strings.
6 properties
CustomJobMetadata
object
Enhanced metadata for custom attack jobs.
11 properties 1 required
TargetMetadata
object
Metadata stored in the database for targets (user-provided + computed fields). Inherits the multimodal-capability fields from MultiModalResult and the multi-tu…
15 properties
StaticJobReportStats
object
Report statistics for static jobs stored in job.reportstats JSONB field. Tracks output completion and partial report unlock status.
4 properties 1 required
JobType
string
Type of job execution.
JobAbortResponseSchema
object
Response schema for job abort operation.
2 properties 2 required
JobCreateRequestSchema
object
Request schema for creating jobs.
6 properties 4 required
TargetReferenceSchema
object
28 properties 8 required
ComplianceSubCategory
string
DynamicJobReportStats
object
5 properties
SafetySubCategory
string
JobStatus
string
Complete job status enum including internal INIT status.
JobStatusFilter
string
Job status enum for API filtering - excludes INIT from public API.
JobListResponseSchema
object
Response schema for listing jobs following common pagination pattern.
2 properties 2 required
LanguageOptionSchema
object
Language representation with code and display name.
2 properties 2 required
TargetJobRequest
object
Enhanced request schema for targeting specific targets.
2 properties 1 required
TargetConnectionType
string
Connection type/provider for the target.
BrandSubCategory
string
ValidationError
object
3 properties 3 required
SecuritySubCategory
string
TargetStatus
string
Status enumeration for scan targets.
HTTPValidationError
object
1 property
ProfilingStatus
string
Status of target profiling workflow.
TargetType
string
Target Types Available
JobResponseSchema
object
Job response schema. ONLY to be used in API response.
23 properties 8 required
ApiEndpointType
string
API endpoint accessibility type.
JobTimeRecord
object
Enhanced time tracking with validation.
4 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

palo-alto-networks-scan-api-openapi.yml Raw ↑

Other APIs Palo Alto Networks publishes across the network.

PAN-OS XML API
PAN-OS OpenConfig API
Panorama API
AutoFocus API (Deprecated)
Prisma SASE Service Status API
Cross-Platform Service Status API
SASE Authentication Service API
Expedition API (Deprecated)
VM-Series Licensing API
Palo Alto Networks 5G Deregistered Trend API
Palo Alto Networks 5G Network Interconnects and Bandwidth API
Palo Alto Networks 5G Registered Trend API
Where this information came from

This is an independent, third-party profile of Palo Alto Networks Scan API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.