How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Palo Alto Networks Scans API

The Scans API from Palo Alto Networks — 14 operation(s) for scans.

Palo Alto Networks Scans API is one of 741 APIs that Palo Alto Networks publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Scans. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 11 operations across 9 paths, and defines 102 schemas. It is described by OpenAPI 3.2.0, at version 1.0.

Requests are made against 6 base URLs: https://api.prismacloud.io, PATH_TO_CONSOLE, https://service.api.aisecurity.paloaltonetworks.com, https://service-de.api.aisecurity.paloaltonetworks.com, https://service-in.api.aisecurity.paloaltonetworks.com, https://service-sg.api.aisecurity.paloaltonetworks.com.

11 operations 9 paths 102 schemas 6 GET5 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0
Base URL
https://{firewall}/api/
Authentication
API Key, API Key
Resource Areas
1

Authentication & Security 2

Palo Alto Networks Scans API declares 2 security schemes for authenticating requests. An API key is passed in the header as authorization (CustomAuthorizer). An API key is passed in the header as x-pan-token (x-pan-token).

  • x-pan-token — API key token generated during [onboarding Prisma AIRS AI Runtime API intercept](https://docs.paloaltonetworks.com/ai-runtime-security/activation-and-onboardin…

Paths & Operations 11

Across 9 paths, the API surfaces 11 operations — 6 GET, 5 POST. Each is listed below with its method, path, parameters, and response codes.

Scans 11
POST
/code/api/v1/scans/integrations
Trigger a Scan
scanIntegrations → 201
GET
/api/v34.03/scans
Get All CI Image Scan Results
get-scans 17 params → 200default
POST
/api/v34.03/scans
Add CLI Scan Result
post-scans body → 200default
GET
/api/v34.03/scans/download
Download CI Image Scan Results
get-scans-download 17 params → 200default
GET
/api/v34.03/scans/{id}
Get CI Image Scan Results
get-scans-id 1 param → 200default
GET
/api/v34.04/scans
Get All CI Image Scan Results
get-scans 17 params → 200default
POST
/api/v34.04/scans
Add CLI Scan Result
post-scans body → 200default
GET
/api/v34.04/scans/download
Download CI Image Scan Results
get-scans-download 17 params → 200default
GET
/api/v34.04/scans/{id}
Get CI Image Scan Results
get-scans-id 1 param → 200default
POST
/v1/scan/sync/request
Send a Synchronous Scan Request
ScanSyncRequest body → 200400401403404405413415
POST
/v1/scan/async/request
Send an Asynchronous Scan Request
ScanAsyncRequest body → 200400401403404405413415

Schemas 102

The contract defines 102 schemas that model the data the API accepts and returns. The most detailed are shared.ImageScanResult_2 (89 properties), shared.ImageScanResult_3 (89 properties), shared.ImageScanResult (87 properties), vuln.Vulnerability (37 properties). Each schema is shown below with its type and property counts.

vuln.Application
object
Application represents a detected application
10 properties
vulnerability.ExploitType
string
ExploitType represents the source of an exploit
wildfire.Usage
object
Usage holds wildfire usage stats, period for the usage varies with context
3 properties
shared.ImageTag
object
ImageTag represents an image repository and its associated tag or registry digest
5 properties
common.NetworkDeviceIP
object
NetworkDeviceIP represents a network device name and address pair
2 properties
common.CloudMetadata
object
CloudMetadata is the metadata for a cloud provider managed asset (e.g., as part of AWS/GCP/Azure/OCI)
15 properties
waas.UnprotectedProcess
object
UnprotectedProcess holds unprotected processes alongside the port
3 properties
shared.ScanResultType
string
ScanResultType represents a cloud scan result type
common.Color
string
Color is a hexadecimal representation of color code value
common.ACIMetadata
object
1 property
secrets.SecretScanMetrics
object
SecretScanMetrics represents metrics collected during secret scan
10 properties
shared.Packages
object
Packages is a collection of packages
2 properties
vuln.ComplianceTemplate
string
ComplianceTemplate represents the compliance template
shared.FileDetails
object
FileDetails contains file details as the file path, hash checksum
5 properties
vuln.SecretType
string
SecretType represents a secret type
common.CloudRunMetadata
object
2 properties
vulnerability.RiskFactors
object
RiskFactors maps the existence of vulnerability risk factors
vulnerability.Type
string
Type represents the vulnerability type
common.CloudProvider
string
CloudProvider specifies the cloud provider name
shared.ImageInstance
object
ImageInstance represents an image on a single host
6 properties
-_shared.CLIScanResult
array
common.ExternalLabel
object
ExternalLabel holds an external label with a source and timestamp
5 properties
trust.Status
string
Status is the trust status for an image
vulnerability.ExploitData
object
ExploitData holds information about an exploit
3 properties
string
string
vuln.AllCompliance
object
AllCompliance contains data regarding passed compliance checks
2 properties
shared.PkgsTimes
object
PkgsTimes are the compressed layer times for pkgs of the specific type
2 properties
vuln.Secret
object
Secret represents a secret found on the scanned workload
12 properties
agentless.ImageScanResultErrCode
integer
ImageScanResultErrCode represents the asset status error
vuln.WildFireMalware
object
WildFireMalware holds the data for WildFire malicious MD5
3 properties
vuln.Vulnerability
object
Vulnerability is a general schema for vulnerabilities (e.g., for compliance or packages)
37 properties
vuln.Distribution
object
Distribution counts the number of vulnerabilities per type
5 properties
shared.CLIScanResult
object
CLIScanResult describes a CLI scan result
9 properties
shared.ScanType
string
ScanType displays the components for an ongoing scan
shared.ImageHosts
object
ImageHosts is a fast index for image scan results metadata per host
trust.HostStatus
object
HostStatus represents an image trust status on a host
2 properties
shared.ImageScanResult
object
ImageScanResult holds the result of an image scan
87 properties
common.ExternalLabelSourceType
string
ExternalLabelSourceType indicates the source of the labels
shared.Binary
object
Binary represents a detected binary file (ELF)
12 properties
waas.ProtectionStatus
object
ProtectionStatus describes the status of the WAAS protection
6 properties
common.GCPCloudMetadata
object
1 property
common.ClusterType
string
ClusterType is the cluster type
shared.CompressedLayerTimes
object
CompressedLayerTimes represent the compressed layer times of the image apps and pkgs
2 properties
shared.ImageHistory
object
ImageHistory represent a layer in the image's history
8 properties
trust.Group
object
Group represents a group of images
9 properties
packages.Type
string
Type describes the package type
waas.OutOfBandMode
string
OutOfBandMode holds the app firewall out-of-band mode
vuln.TagInfo
object
TagInfo is the tag info in a specific vulnerability context
3 properties
int
integer
shared.Image
object
Image represents a container image
13 properties
int16
integer
shared.InstalledProducts
object
InstalledProducts contains data regarding products running in environment TODO 34713: Swarm support was deprecated in Joule, remove swarm node/manager boolean…
24 properties
int64
integer
shared.Package
object
Package stores relevant package information
22 properties
trust.ImageResult
object
ImageResult represents an aggregated image trust result
2 properties
common.AzureMetadata
object
2 properties
shared.ImageHost
object
ImageHost holds information about image scan result per host
9 properties
vulnerability.ExploitKind
string
ExploitKind represents the kind of the exploit
vulnerability.Exploits
array
Exploits represents the exploits data found for a CVE
vulnerability.VulnerabilityAttribute
integer
VulnerabilityAttribute represents a specific vulnerability property whose value may come from different sources
vuln.Vulnerability_2
object
Vulnerability is a general schema for vulnerabilities (e.g., for compliance or packages)
37 properties
shared.ImageScanResult_2
object
ImageScanResult holds the result of an image scan
89 properties
vulnerability.VulnerabilityDataSource
object
VulnerabilityDataSource identifies the source of a specific vulnerability attribute. Example: CVSS from NVD, Severity from RedHat.
2 properties
vulnerability.VulnerabilityDataSources
array
VulnerabilityDataSources is a slice of VulnerabilityDataSource that implements the sql.Scanner and driver.Valuer interfaces
vulnerability.VulnerabilitySource
integer
VulnerabilitySource represents the authority that provided vulnerability-related data (severity, CVSS, links).
shared.InstalledProducts_2
object
InstalledProducts contains data regarding products running in environment TODO 34713: Swarm support was deprecated in Joule, remove swarm node/manager boolean…
25 properties
shared.Package_2
object
Package stores relevant package information
21 properties
vuln.Vulnerability_3
object
Vulnerability is a general schema for vulnerabilities (e.g., for compliance or packages)
37 properties
shared.ImageScanResult_3
object
ImageScanResult holds the result of an image scan
89 properties
shared.InstalledProducts_3
object
InstalledProducts contains data regarding products running in environment TODO 34713: Swarm support was deprecated in Joule, remove swarm node/manager boolean…
25 properties
shared.Package_3
object
Package stores relevant package information
21 properties
ToxicContentDetails
object
1 property
AgentMeta
object
3 properties
ErrorStatus
string
Status indicating error or timeout
ToolEvent
object
3 properties
ToolDetectionDetails
object
1 property
ScanContent
object
6 properties
IODetected
object
1 property
PromptDetected
object
7 properties
TopicGuardRails
object
2 properties
AsyncScanObject
object
2 properties 2 required
AsyncScanRequest
array
ToolDetectionEntry
object
5 properties
ScanRequest
object
5 properties 2 required
PromptDetectionDetails
object
2 properties
ContentErrors
object
Errors information for prompt and response detection services
3 properties
OffsetObject
array
Array of start, end offsets
AsyncScanResponse
object
4 properties 2 required
ScanResponse
object
21 properties 7 required
MaskedData
object
2 properties
AiProfile
object
2 properties
Error
object
2 properties 2 required
ResponseDetectionDetails
object
2 properties
PatternDetections
object
2 properties
ScanSummary
object
2 properties 2 required
ResponseDetected
object
8 properties
DetectionServiceName
string
Name of detection service
ToolDetected
object
5 properties
Metadata
object
5 properties
ToolDetectionFlags
object
8 properties
ContentErrorType
string
Type of content that encountered an error
ToolEventMetadata
object
4 properties 3 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

palo-alto-networks-scans-api-openapi.yml Raw ↑

Other APIs Palo Alto Networks publishes across the network.

PAN-OS XML API
PAN-OS OpenConfig API
Panorama API
AutoFocus API (Deprecated)
Prisma SASE Service Status API
Cross-Platform Service Status API
SASE Authentication Service API
Expedition API (Deprecated)
VM-Series Licensing API
Palo Alto Networks 5G Deregistered Trend API
Palo Alto Networks 5G Network Interconnects and Bandwidth API
Palo Alto Networks 5G Registered Trend API
Where this information came from

This is an independent, third-party profile of Palo Alto Networks Scans API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.