Palo Alto Networks Access Policies API
Access policy management for role-based access control.
Access policy management for role-based access control.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/palo-alto-networks-access-policies-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: Palo Alto Networks SASE IAM Service Access Policies API
description: SASE Identity and Access Management (IAM) Service API. Provides programmatic management of service accounts, API key credentials, and access policies for the Palo Alto Networks SASE platform. Service accounts are machine identities used for API automation. Access policies bind roles to service accounts or users, controlling what operations they can perform within a Tenant Service Group scope.
version: '1.0'
contact:
name: Palo Alto Networks Developer Support
url: https://pan.dev/
license:
name: Proprietary
url: https://www.paloaltonetworks.com/legal
servers:
- url: https://api.sase.paloaltonetworks.com/iam/v1
description: SASE IAM Service API production server.
security:
- oauth2Bearer: []
tags:
- name: Access Policies
description: Access policy management for role-based access control.
paths:
/access-policies:
get:
operationId: listAccessPolicies
summary: Palo Alto Networks List Access Policies
description: Returns the access policies defined for the tenant. Access policies bind a principal (service account or user) to a role within a specific TSG scope, controlling what API operations the principal can perform.
tags:
- Access Policies
parameters:
- name: principal_id
in: query
description: Filter policies by principal ID (service account or user).
schema:
type: string
example: '179028'
- name: tsg_id
in: query
description: Filter policies by TSG scope.
schema:
type: string
example: '561662'
- name: offset
in: query
description: Number of results to skip for pagination.
schema:
type: integer
default: 0
example: 0
- name: limit
in: query
description: Maximum number of policies to return.
schema:
type: integer
default: 50
maximum: 200
example: 50
responses:
'200':
description: Access policies returned.
content:
application/json:
schema:
type: object
properties:
total:
type: integer
offset:
type: integer
limit:
type: integer
items:
type: array
items:
$ref: '#/components/schemas/AccessPolicy'
examples:
ListAccessPolicies200Example:
summary: Default listAccessPolicies 200 response
x-microcks-default: true
value:
total: 216
offset: 770
limit: 432
items:
- id: example-id
principal_id: '228082'
principal_type: service_account
role_id: '930355'
role_name: Primary Policy 48
tsg_id: '568011'
created_at: '2025-08-17T04:28:20Z'
'401':
description: Invalid or missing Bearer token.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
ListAccessPolicies401Example:
summary: Default listAccessPolicies 401 response
x-microcks-default: true
value:
error: example-error
message: Malware endpoint traffic incident on on traffic rule endpoint traffic.
request_id: 1e1e39dd-16dd-4699-a272-365b75e92268
'403':
description: Insufficient permissions.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
ListAccessPolicies403Example:
summary: Default listAccessPolicies 403 response
x-microcks-default: true
value:
error: example-error
message: Malware endpoint traffic incident on on traffic rule endpoint traffic.
request_id: 1e1e39dd-16dd-4699-a272-365b75e92268
'500':
description: Internal server error.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
ListAccessPolicies500Example:
summary: Default listAccessPolicies 500 response
x-microcks-default: true
value:
error: example-error
message: Malware endpoint traffic incident on on traffic rule endpoint traffic.
request_id: 1e1e39dd-16dd-4699-a272-365b75e92268
x-microcks-operation:
delay: 0
dispatcher: FALLBACK
post:
operationId: createAccessPolicy
summary: Palo Alto Networks Create Access Policy
description: Creates a new access policy binding a principal to a role within a TSG scope. The role determines which API operations the principal can perform on resources within the specified TSG.
tags:
- Access Policies
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/AccessPolicyRequest'
examples:
CreateAccessPolicyRequestExample:
summary: Default createAccessPolicy request
x-microcks-default: true
value:
principal_id: '988877'
principal_type: user
role_id: '955130'
tsg_id: '732912'
responses:
'201':
description: Access policy created successfully.
content:
application/json:
schema:
$ref: '#/components/schemas/AccessPolicy'
examples:
CreateAccessPolicy201Example:
summary: Default createAccessPolicy 201 response
x-microcks-default: true
value:
id: example-id
principal_id: '228082'
principal_type: service_account
role_id: '930355'
role_name: Primary Policy 48
tsg_id: '568011'
created_at: '2025-08-17T04:28:20Z'
'400':
description: Invalid request body.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
CreateAccessPolicy400Example:
summary: Default createAccessPolicy 400 response
x-microcks-default: true
value:
error: example-error
message: Malware endpoint traffic incident on on traffic rule endpoint traffic.
request_id: 1e1e39dd-16dd-4699-a272-365b75e92268
'401':
description: Invalid or missing Bearer token.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
CreateAccessPolicy401Example:
summary: Default createAccessPolicy 401 response
x-microcks-default: true
value:
error: example-error
message: Malware endpoint traffic incident on on traffic rule endpoint traffic.
request_id: 1e1e39dd-16dd-4699-a272-365b75e92268
'403':
description: Insufficient permissions.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
CreateAccessPolicy403Example:
summary: Default createAccessPolicy 403 response
x-microcks-default: true
value:
error: example-error
message: Malware endpoint traffic incident on on traffic rule endpoint traffic.
request_id: 1e1e39dd-16dd-4699-a272-365b75e92268
'500':
description: Internal server error.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
CreateAccessPolicy500Example:
summary: Default createAccessPolicy 500 response
x-microcks-default: true
value:
error: example-error
message: Malware endpoint traffic incident on on traffic rule endpoint traffic.
request_id: 1e1e39dd-16dd-4699-a272-365b75e92268
x-microcks-operation:
delay: 0
dispatcher: FALLBACK
/access-policies/{id}:
get:
operationId: getAccessPolicy
summary: Palo Alto Networks Get Access Policy
description: Returns full details for a specific access policy.
tags:
- Access Policies
parameters:
- name: id
in: path
required: true
description: Unique identifier of the access policy.
schema:
type: string
example: example-id
responses:
'200':
description: Access policy details returned.
content:
application/json:
schema:
$ref: '#/components/schemas/AccessPolicy'
examples:
GetAccessPolicy200Example:
summary: Default getAccessPolicy 200 response
x-microcks-default: true
value:
id: example-id
principal_id: '228082'
principal_type: service_account
role_id: '930355'
role_name: Primary Policy 48
tsg_id: '568011'
created_at: '2025-08-17T04:28:20Z'
'401':
description: Invalid or missing Bearer token.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
GetAccessPolicy401Example:
summary: Default getAccessPolicy 401 response
x-microcks-default: true
value:
error: example-error
message: Malware endpoint traffic incident on on traffic rule endpoint traffic.
request_id: 1e1e39dd-16dd-4699-a272-365b75e92268
'403':
description: Insufficient permissions.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
GetAccessPolicy403Example:
summary: Default getAccessPolicy 403 response
x-microcks-default: true
value:
error: example-error
message: Malware endpoint traffic incident on on traffic rule endpoint traffic.
request_id: 1e1e39dd-16dd-4699-a272-365b75e92268
'404':
description: Access policy not found.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
GetAccessPolicy404Example:
summary: Default getAccessPolicy 404 response
x-microcks-default: true
value:
error: example-error
message: Malware endpoint traffic incident on on traffic rule endpoint traffic.
request_id: 1e1e39dd-16dd-4699-a272-365b75e92268
'500':
description: Internal server error.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
GetAccessPolicy500Example:
summary: Default getAccessPolicy 500 response
x-microcks-default: true
value:
error: example-error
message: Malware endpoint traffic incident on on traffic rule endpoint traffic.
request_id: 1e1e39dd-16dd-4699-a272-365b75e92268
x-microcks-operation:
delay: 0
dispatcher: FALLBACK
put:
operationId: updateAccessPolicy
summary: Palo Alto Networks Update Access Policy
description: Updates the role assignment for an existing access policy.
tags:
- Access Policies
parameters:
- name: id
in: path
required: true
description: Unique identifier of the access policy to update.
schema:
type: string
example: example-id
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/AccessPolicyRequest'
examples:
UpdateAccessPolicyRequestExample:
summary: Default updateAccessPolicy request
x-microcks-default: true
value:
principal_id: '988877'
principal_type: user
role_id: '955130'
tsg_id: '732912'
responses:
'200':
description: Access policy updated successfully.
content:
application/json:
schema:
$ref: '#/components/schemas/AccessPolicy'
examples:
UpdateAccessPolicy200Example:
summary: Default updateAccessPolicy 200 response
x-microcks-default: true
value:
id: example-id
principal_id: '228082'
principal_type: service_account
role_id: '930355'
role_name: Primary Policy 48
tsg_id: '568011'
created_at: '2025-08-17T04:28:20Z'
'400':
description: Invalid request body.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
UpdateAccessPolicy400Example:
summary: Default updateAccessPolicy 400 response
x-microcks-default: true
value:
error: example-error
message: Malware endpoint traffic incident on on traffic rule endpoint traffic.
request_id: 1e1e39dd-16dd-4699-a272-365b75e92268
'401':
description: Invalid or missing Bearer token.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
UpdateAccessPolicy401Example:
summary: Default updateAccessPolicy 401 response
x-microcks-default: true
value:
error: example-error
message: Malware endpoint traffic incident on on traffic rule endpoint traffic.
request_id: 1e1e39dd-16dd-4699-a272-365b75e92268
'403':
description: Insufficient permissions.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
UpdateAccessPolicy403Example:
summary: Default updateAccessPolicy 403 response
x-microcks-default: true
value:
error: example-error
message: Malware endpoint traffic incident on on traffic rule endpoint traffic.
request_id: 1e1e39dd-16dd-4699-a272-365b75e92268
'404':
description: Access policy not found.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
UpdateAccessPolicy404Example:
summary: Default updateAccessPolicy 404 response
x-microcks-default: true
value:
error: example-error
message: Malware endpoint traffic incident on on traffic rule endpoint traffic.
request_id: 1e1e39dd-16dd-4699-a272-365b75e92268
'500':
description: Internal server error.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
UpdateAccessPolicy500Example:
summary: Default updateAccessPolicy 500 response
x-microcks-default: true
value:
error: example-error
message: Malware endpoint traffic incident on on traffic rule endpoint traffic.
request_id: 1e1e39dd-16dd-4699-a272-365b75e92268
x-microcks-operation:
delay: 0
dispatcher: FALLBACK
delete:
operationId: deleteAccessPolicy
summary: Palo Alto Networks Delete Access Policy
description: Deletes an access policy, revoking the role binding from the principal.
tags:
- Access Policies
parameters:
- name: id
in: path
required: true
description: Unique identifier of the access policy to delete.
schema:
type: string
example: example-id
responses:
'204':
description: Access policy deleted successfully.
'401':
description: Invalid or missing Bearer token.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
DeleteAccessPolicy401Example:
summary: Default deleteAccessPolicy 401 response
x-microcks-default: true
value:
error: example-error
message: Malware endpoint traffic incident on on traffic rule endpoint traffic.
request_id: 1e1e39dd-16dd-4699-a272-365b75e92268
'403':
description: Insufficient permissions.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
DeleteAccessPolicy403Example:
summary: Default deleteAccessPolicy 403 response
x-microcks-default: true
value:
error: example-error
message: Malware endpoint traffic incident on on traffic rule endpoint traffic.
request_id: 1e1e39dd-16dd-4699-a272-365b75e92268
'404':
description: Access policy not found.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
DeleteAccessPolicy404Example:
summary: Default deleteAccessPolicy 404 response
x-microcks-default: true
value:
error: example-error
message: Malware endpoint traffic incident on on traffic rule endpoint traffic.
request_id: 1e1e39dd-16dd-4699-a272-365b75e92268
'500':
description: Internal server error.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
DeleteAccessPolicy500Example:
summary: Default deleteAccessPolicy 500 response
x-microcks-default: true
value:
error: example-error
message: Malware endpoint traffic incident on on traffic rule endpoint traffic.
request_id: 1e1e39dd-16dd-4699-a272-365b75e92268
x-microcks-operation:
delay: 0
dispatcher: FALLBACK
/iam/v1/access_policies:
get:
description: 'List all access policies. If `role` or `principal` is specified,
this returns all access policies using the specified role or
or that is assigned to the identified principal.'
operationId: get-iam-v1-access_policies
parameters:
- description: 'The [role](/sase/docs/all-roles) that you want to use for this list operation.
'
in: query
name: role
schema:
type: string
- description: 'The email address of the principal that you want to use for this list operation.
'
in: query
name: principal
schema:
type: string
responses:
'200':
$ref: '#/components/responses/access_policy_list'
security:
- Bearer: []
summary: List all access policies
tags:
- Access Policies
post:
description: 'Assign an access policy to a user or a service account. If the
email address supplied to the `principal` request body field is not
known to the IAM service, a new user account is created to track that
email address within the IAM service. However, a corresponding
SSO user account is not created at that time. Use the
create SSO user
call to create a corresponding SSO user account.
If the `principal` email address corresponds to a service account,
then the specified role is applied
to that service account. Service account email addresses conform
to the following format:
`.iam.panServiceAccounts.com`'
operationId: post-iam-v1-access_policies
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/access_policy_create_required'
description: 'Specifies the role to be assigned to the principal for the specified
resource.
'
required: true
responses:
'201':
content:
application/json:
schema:
$ref: '#/components/schemas/access_policy_create'
description: Successful response.
security:
- Bearer: []
summary: Assign an access policy
tags:
- Access Policies
/iam/v1/access_policies/{id}:
delete:
description: Delete an access policy.
operationId: delete-iam-v1-access_policies-id
parameters:
- description: 'Access policy''s unique identifier.
'
in: path
name: id
required: true
schema:
type: string
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/access_policy'
description: Successful Response
security:
- Bearer: []
summary: Delete an access policy
tags:
- Access Policies
get:
description: Get an access policy by ID.
operationId: get-iam-v1-access_policies-id
parameters:
- description: 'Access policy''s unique identifier.
'
in: path
name: id
required: true
schema:
type: string
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/access_policy'
description: Successful response - returns a single `access_policy`.
security:
- Bearer: []
summary: Get an access policy
tags:
- Access Policies
components:
schemas:
ErrorResponse:
type: object
properties:
error:
type: string
description: Error code identifying the error type.
example: example-error
message:
type: string
description: Human-readable description of the error.
example: Malware endpoint traffic incident on on traffic rule endpoint traffic.
request_id:
type: string
description: Request identifier for support correlation.
example: 1e1e39dd-16dd-4699-a272-365b75e92268
AccessPolicyRequest:
type: object
required:
- principal_id
- principal_type
- role_id
- tsg_id
properties:
principal_id:
type: string
description: ID of the service account or user to grant access to.
example: '988877'
principal_type:
type: string
enum:
- service_account
- user
description: Type of principal.
example: user
role_id:
type: string
description: ID of the role to assign.
example: '955130'
tsg_id:
type: string
description: TSG scope for this policy.
example: '732912'
AccessPolicy:
type: object
properties:
id:
type: string
description: Unique identifier of the access policy.
example: example-id
principal_id:
type: string
description: ID of the service account or user this policy applies to.
example: '228082'
principal_type:
type: string
enum:
- service_account
- user
description: Type of principal.
example: service_account
role_id:
type: string
description: ID of the role assigned by this policy.
example: '930355'
role_name:
type: string
description: Name of the role assigned.
example: Primary Policy 48
tsg_id:
type: string
description: TSG scope this policy applies to.
example: '568011'
created_at:
type: string
format: date-time
example: '2025-08-17T04:28:20Z'
access_policy_create:
properties:
id:
description: 'Access policy''s unique identifier.
'
example: 9d5104a0-1b0e-4f1d-be40-87f7810327e9
type: string
principal:
description: "Email address of the user or service account which is receiving this role. \n"
example: user@paloaltonetworks.com
type: string
resource:
description: "Resource to which the principal is gaining access. This is a string in the format:\n\n `prn:<TSG_ID>::::`\n"
example: 'prn:123::::'
type: string
role:
description: '[Role](/sase/docs/all-roles) to assign to the principal.
'
example: superuser
type: string
title: Root Type for access_policy
type: object
_pagination:
properties:
count:
default: 1
description: Total count of the items
type: integer
required:
- count
- items
type: object
access_policy:
properties:
principal:
description: 'The email address of the user or service account that is granted this
access policy.
'
example: username@paloaltonetworks.com
type: string
principal_display_name:
description: '_firstname lastname_ OR _firstname_ OR _username_.
'
example: username
type: string
principal_type:
description: 'Whether the principal is a user or a service account.
'
example: user
type: string
resource:
description: "The resource to which this access policy is assigned. It is in the format:\n\n `prn:<TSG_ID>::::`\n"
example: 'prn:123::::'
type: string
role:
description: 'The [role](/sase/docs/all-roles) used for this access policy.
'
example: superuser
type: string
title: Root Type for access_policy
type: object
access_policy_create_required:
properties:
principal:
description: "The email address for the user or \n[service account](/sase/docs/service-accounts) to which you are assigning\nthis access policy. \n"
example: user@paloaltonetworks.com
type: string
resource:
description: "The PAN Resource Name that identifies the TSG for which you are assigning\nthis access policy. It follows this format:\n\n `prn:<TSG_ID>::::`\n"
example: 'prn:123::::'
type: string
role:
description: 'The [role](/sase/docs/all-roles) that you are using for this access policy. If you are assigning a custom role, then this must be the custom role''s ID.
'
example: superuser
type: string
required:
- role
- principal
- resource
title: Root Type for access_policy
type: object
access_policy_list:
properties:
id:
description: 'Access policy unique identifier.
'
example: 9d5104a0-1b0e-4f1d-be40-87f7810327e9
type: string
inherited_from:
description: 'The lowest level TSG to which the access policy belongs.
'
example: '1234567890'
type: string
principal:
description: 'The email address of the user or service account that is granted this
access policy.
'
example: user@paloaltonetworks.com
type: string
principal_display_name:
description: '_firstname lastname_ OR _firstname_ OR _username_.
'
example: firstname lastname
type: string
principal_type:
description: 'Whether the principal is a user or a service account.
'
example: user
type: string
resource:
description: "The resource to which this access policy is assigned. It is in the format:\n\n `prn:<TSG_ID>::::`\n"
example: 'prn:123::::'
type: string
role:
description: 'The [role](/sase/docs/all-roles) used for this access policy.
'
example: superuser
type: string
title: List Type for access_policy
type: object
securitySchemes:
oauth2Bearer:
type: http
scheme: bearer
bearerFormat: JWT
description: OAuth 2.0 Bearer token for SASE platform authentication. Obtain using the client_credentials grant with your SASE service account client ID and client secret.
Bearer:
scheme: bearer
type: http
responses:
access_policy_list:
content:
application/json:
schema:
allOf:
- $ref: '#/components/schemas/_pagination'
- example:
count: 1
items:
- id: 9d5104a0-1b0e-4f1d-be40-87f7810327e9
inherited_from: '1234567890'
principal: user@paloaltonetworks.com
principal_display_name: firstname lastname
principal_type: user
resource: 'prn:123::::'
role: superuser
- properties:
items:
items:
allOf:
- $ref: '#/components/schemas/access_policy_list'
type: array
type: object
description: Successful response.