Palo Alto Networks Agentless Users API API

Endpoint to retrieve the count of active users without requiring an agent.

Operations 6

POST /insights/v3.0/resource/query/agentless/risky_user_count Risky User Data #
POST /insights/v3.0/resource/query/users/agentless/active_user_count Agentless Active User Data #
POST /insights/v3.0/resource/query/users/agentless/active_user_list Agentless Internal User List #
POST /insights/v3.0/resource/query/users/agentless/session_list Agentless Internal User Session List #
POST /insights/v3.0/resource/query/users/agentless/user_count_histogram Agentless Internal User Histogram #
POST /insights/v3.0/resource/query/users/agentless/users Get agentless users data #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/palo-alto-networks-agentless-users-api-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

palo-alto-networks-agentless-users-api-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  contact:
    email: support@paloaltonetworks.com
  description: 'The Open API specification file represents the APIs available for Prisma Access Insights 3.0.

    The Prisma Access Insights 3.0 APIs allow you to query your Prisma Access tenant for the health of

    your Prisma Access network deployment. The 3.0 APIs are intended for cloud-managed Prisma Access

    customers, where the tenants have been onboarded by Palo Alto Networks using a Tenant Service Group

    (TSG) identifier.


    These APIs use the common SASE authentication mechanism and base URL. See the

    [Prisma SASE API Get Started](https://pan.dev/sase/docs/getstarted) guide for more information.


    This Open API spec file was created on May 30, 2025. To check for a more recent version of this file, see

    [Prisma Insights APIs on pan.dev](https://pan.dev//access/api/insights/).


    © 2025 Palo Alto Networks, Inc. Palo Alto Networks is a registered trademark of Palo

    Alto Networks. A list of our trademarks can be found at


    [https://www.paloaltonetworks.com/company/trademarks.html](https://www.paloaltonetworks.com/company/trademarks.html)


    All other marks mentioned herein may be trademarks of their respective companies.

    '
  license:
    name: MIT
    url: https://opensource.org/license/mit
  termsOfService: https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/legal/palo-alto-networks-end-user-license-agreement-eula.pdf
  title: Palo Alto Networks 3.0 Agentless Users API
  version: '3.0'
servers:
- url: https://api.sase.paloaltonetworks.com
tags:
- description: 'Endpoint to retrieve the count of active users without requiring an agent.

    '
  name: Agentless Users API
paths:
  /insights/v3.0/resource/query/agentless/risky_user_count:
    post:
      description: 'Retrieve the number of risky users based on specified filters.

        '
      operationId: post-insights-v3.0-resource-query-agentless-risky_user_count
      parameters:
      - description: 'Map the region for the tenant.

          '
        in: header
        name: X-PANW-Region
        required: true
        schema:
          example: americas
          type: string
      - description: 'Use a unique Prisma-Tenant identifier for precise tenant management and resource allocation within single or multi-tenant architectures.

          '
        in: header
        name: Prisma-Tenant
        required: false
        schema:
          example: 12345678:12345679
          type: string
      requestBody:
        content:
          application/json:
            examples:
              With mandatory filters:
                value:
                  filter:
                    rules:
                    - operator: last_n_hours
                      property: event_time
                      values:
                      - 5
              With possible filters:
                value:
                  filter:
                    rules:
                    - operator: last_n_hours
                      property: event_time
                      values:
                      - 5
                    - operator: in
                      property: platform_type
                      values:
                      - prisma_access
                      - ngfw
                    - operator: in
                      property: username
                      values:
                      - john.doe
                    - operator: in
                      property: edge_location_display_name
                      values:
                      - US West
                    - operator: in
                      property: source_city
                      values:
                      - San Jose
                    - operator: in
                      property: geoip_from_country_name
                      values:
                      - US
            schema:
              properties:
                filter:
                  properties:
                    rules:
                      items:
                        properties:
                          edge_location_display_name:
                            description: Prisma Access Location.
                            example: US West
                            type: string
                          event_time:
                            description: Time of the event.
                            example: 5
                            type: number
                          platform_type:
                            description: Type of platform.
                            example: prisma_access
                            type: string
                          source_city:
                            description: City from GeoIP.
                            example: San Jose
                            type: string
                          source_country:
                            description: Country from GeoIP.
                            example: US
                            type: string
                          username:
                            description: Source User.
                            example: john.doe
                            type: string
                        type: object
                      required:
                      - event_time
                      type: array
                  type: object
              type: object
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                properties:
                  user_count:
                    description: Count of risky users.
                    example: 10
                    type: integer
                type: object
          description: OK
        '400':
          description: Resource property is not valid
        '403':
          description: Permission Denied
        '404':
          description: Resource not found
        '500':
          description: Failed to process request
      security:
      - Bearer: []
      summary: Risky User Data
      tags:
      - Agentless Users API
  /insights/v3.0/resource/query/users/agentless/active_user_count:
    post:
      description: 'Retrieve the number of active users without requiring an agent.

        '
      operationId: post-insights-v3.0-resource-query-users-agentless-active_user_count
      parameters:
      - description: 'Map the region for the tenant.

          '
        in: header
        name: X-PANW-Region
        required: true
        schema:
          example: americas
          type: string
      - description: 'Use a unique Prisma-Tenant identifier for precise tenant management and resource allocation within single or multi-tenant architectures.

          '
        in: header
        name: Prisma-Tenant
        required: false
        schema:
          example: 12345678:12345679
          type: string
      requestBody:
        content:
          application/json:
            examples:
              With mandatory filters:
                value:
                  filter:
                    rules:
                    - operator: last_n_hours
                      property: event_time
                      values:
                      - 5
                    - operator: in
                      property: node_type
                      values:
                      - 153
              With possible filters:
                value:
                  filter:
                    rules:
                    - operator: last_n_hours
                      property: event_time
                      values:
                      - 5
                    - operator: in
                      property: source_user
                      values:
                      - john.doe
                    - operator: in
                      property: edge_location_display_name
                      values:
                      - US West
                    - operator: in
                      property: source_city
                      values:
                      - San Jose
                    - operator: in
                      property: source_country
                      values:
                      - US
                    - operator: in
                      property: node_type
                      values:
                      - 153
                    - operator: in
                      property: platform_type
                      values:
                      - prisma_access
                      - ngfw
            schema:
              properties:
                filter:
                  properties:
                    rules:
                      items:
                        properties:
                          edge_location_display_name:
                            description: Prisma Access Location.
                            example: US West
                            type: string
                          event_time:
                            description: Time of the event.
                            example: 5
                            type: number
                          node_type:
                            description: Type of node.
                            example: 153
                            type: number
                          platform_type:
                            description: Platform type.
                            example: prisma_access
                            type: string
                          source_city:
                            description: City from GeoIP.
                            example: San Jose
                            type: string
                          source_country:
                            description: Country from GeoIP.
                            example: US
                            type: string
                          source_user:
                            description: Username.
                            example: john.doe
                            type: string
                        type: object
                      required:
                      - event_time
                      - node_type
                      type: array
                  type: object
              type: object
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                properties:
                  user_count:
                    description: Count of active users.
                    example: 10
                    type: integer
                type: object
          description: OK
        '400':
          description: Resource property is not valid
        '403':
          description: Permission Denied
        '404':
          description: Resource not found
        '500':
          description: Failed to process request
      security:
      - Bearer: []
      summary: Agentless Active User Data
      tags:
      - Agentless Users API
  /insights/v3.0/resource/query/users/agentless/active_user_list:
    post:
      description: 'Retrieve a list of internal users without requiring an agent.

        '
      operationId: post-insights-v3.0-resource-query-users-agentless-active_user_list
      parameters:
      - description: 'Map the region for the tenant.

          '
        in: header
        name: X-PANW-Region
        required: true
        schema:
          example: americas
          type: string
      - description: 'Use a unique Prisma-Tenant identifier for precise tenant management and resource allocation within single or multi-tenant architectures.

          '
        in: header
        name: Prisma-Tenant
        required: false
        schema:
          example: 12345678:12345679
          type: string
      requestBody:
        content:
          application/json:
            examples:
              With mandatory filters:
                value:
                  filter:
                    rules:
                    - operator: last_n_hours
                      property: event_time
                      values:
                      - 5
                    - operator: in
                      property: node_type
                      values:
                      - 153
              With possible filters:
                value:
                  filter:
                    rules:
                    - operator: last_n_hours
                      property: event_time
                      values:
                      - 5
                    - operator: in
                      property: username
                      values:
                      - achalla1kerbuser@dss-qa.com
                    - operator: in
                      property: edge_location_display_name
                      values:
                      - US West
                    - operator: in
                      property: source_city
                      values:
                      - San Jose
                    - operator: in
                      property: source_country
                      values:
                      - US
                    - operator: in
                      property: node_type
                      values:
                      - 153
                    - operator: in
                      property: platform_type
                      values:
                      - prisma_access
                      - ngfw
            schema:
              properties:
                filter:
                  properties:
                    rules:
                      items:
                        properties:
                          edge_location_display_name:
                            description: Prisma Access Location.
                            example: US West
                            type: string
                          event_time:
                            description: Time of the event.
                            example: 5
                            type: number
                          node_type:
                            description: Type of node.
                            example: 153
                            type: number
                          platform_type:
                            description: Platform type.
                            example: prisma_access
                            type: string
                          source_city:
                            description: City from GeoIP.
                            example: San Jose
                            type: string
                          source_country:
                            description: Country from GeoIP.
                            example: US
                            type: string
                          username:
                            description: Username.
                            example: achalla1kerbuser@dss-qa.com
                            type: string
                        type: object
                      required:
                      - event_time
                      - node_type
                      type: array
                  type: object
              type: object
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                properties:
                  browser_name:
                    description: Browser name.
                    example: Chrome
                    type: string
                  last_activity_epoc_time_millis:
                    description: Last activity epoch time in milliseconds.
                    example: 1678886400000
                    type: integer
                  last_activity_time:
                    description: Last activity time.
                    example: '2023-03-15T00:00:00Z'
                    type: string
                  os_family:
                    description: OS family.
                    example: Windows
                    type: string
                  pa_fw_location:
                    description: PA Firewall location.
                    example: US West
                    type: string
                  source_city:
                    description: Source city.
                    example: San Francisco
                    type: string
                  source_country:
                    description: Source country.
                    example: USA
                    type: string
                  user_source_ip:
                    description: User source IP address.
                    example: 192.168.1.1
                    type: string
                  username:
                    description: Username.
                    example: john.doe
                    type: string
                type: object
          description: OK
        '400':
          description: Resource property is not valid
        '403':
          description: Permission Denied
        '404':
          description: Resource not found
        '500':
          description: Failed to process request
      security:
      - Bearer: []
      summary: Agentless Internal User List
      tags:
      - Agentless Users API
  /insights/v3.0/resource/query/users/agentless/session_list:
    post:
      description: 'Retrieve a list of internal user sessions without requiring an agent.

        '
      operationId: post-insights-v3.0-resource-query-users-agentless-session_list
      parameters:
      - description: 'Map the region for the tenant.

          '
        in: header
        name: X-PANW-Region
        required: true
        schema:
          example: americas
          type: string
      - description: 'Use a unique Prisma-Tenant identifier for precise tenant management and resource allocation within single or multi-tenant architectures.

          '
        in: header
        name: Prisma-Tenant
        required: false
        schema:
          example: 12345678:12345679
          type: string
      requestBody:
        content:
          application/json:
            examples:
              With mandatory filters:
                value:
                  filter:
                    rules:
                    - operator: last_n_hours
                      property: event_time
                      values:
                      - 5
              With possible filters:
                value:
                  filter:
                    rules:
                    - operator: last_n_hours
                      property: event_time
                      values:
                      - 5
                    - operator: in
                      property: username
                      values:
                      - john.doe
                    - operator: in
                      property: edge_location_display_name
                      values:
                      - US West
                    - operator: in
                      property: source_city
                      values:
                      - San Jose
                    - operator: in
                      property: source_country
                      values:
                      - US
                    - operator: in
                      property: platform_type
                      values:
                      - prisma_access
                      - ngfw
            schema:
              properties:
                filter:
                  properties:
                    rules:
                      items:
                        properties:
                          edge_location_display_name:
                            description: Prisma Access Location.
                            example: US West
                            type: string
                          event_time:
                            description: Time of the event.
                            example: 5
                            type: number
                          platform_type:
                            description: Platform type.
                            example: prisma_access
                            type: string
                          source_city:
                            description: City from GeoIP.
                            example: San Jose
                            type: string
                          source_country:
                            description: Country from GeoIP.
                            example: US
                            type: string
                          username:
                            description: Username.
                            example: john.doe
                            type: string
                        type: object
                      required:
                      - event_time
                      type: array
                  type: object
              type: object
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                properties:
                  bytes_received:
                    description: Bytes received.
                    example: 2048.0
                    format: float
                    type: number
                  bytes_sent:
                    description: Bytes sent.
                    example: 1024.0
                    format: float
                    type: number
                  login_time:
                    description: Login time.
                    example: '2023-03-15T00:00:00Z'
                    type: string
                  pa_fw_location:
                    description: PA Firewall location.
                    example: US West
                    type: string
                  source_city:
                    description: Source city.
                    example: San Francisco
                    type: string
                  source_country:
                    description: Source country.
                    example: USA
                    type: string
                  user_source_ip:
                    description: User source IP address.
                    example: 192.168.1.1
                    type: string
                type: object
          description: OK
        '400':
          description: Resource property is not valid
        '403':
          description: Permission Denied
        '404':
          description: Resource not found
        '500':
          description: Failed to process request
      security:
      - Bearer: []
      summary: Agentless Internal User Session List
      tags:
      - Agentless Users API
  /insights/v3.0/resource/query/users/agentless/user_count_histogram:
    post:
      description: 'Retrieve a histogram of internal users without requiring an agent.

        '
      operationId: post-insights-v3.0-resource-query-users-agentless-user_count_histogram
      parameters:
      - description: 'Map the region for the tenant.

          '
        in: header
        name: X-PANW-Region
        required: true
        schema:
          example: americas
          type: string
      - description: 'Use a unique Prisma-Tenant identifier for precise tenant management and resource allocation within single or multi-tenant architectures.

          '
        in: header
        name: Prisma-Tenant
        required: false
        schema:
          example: 12345678:12345679
          type: string
      requestBody:
        content:
          application/json:
            examples:
              With mandatory filters:
                value:
                  filter:
                    rules:
                    - operator: last_n_hours
                      property: event_time
                      values:
                      - 5
                  histogram:
                    enableEmptyInterval: true
                    property: event_time
                    range: minute
                    value: 30
              With possible filters:
                value:
                  filter:
                    rules:
                    - operator: last_n_hours
                      property: event_time
                      values:
                      - 5
                    - operator: in
                      property: platform_type
                      values:
                      - prisma_access
                      - ngfw
                    - operator: in
                      property: source_user
                      values:
                      - test@example.com
                    - operator: in
                      property: edge_location_display_name
                      values:
                      - US West
                    - operator: in
                      property: source_city
                      values:
                      - San Jose
                    - operator: in
                      property: source_country
                      values:
                      - US
                  histogram:
                    enableEmptyInterval: true
                    property: event_time
                    range: minute
                    value: 30
            schema:
              properties:
                filter:
                  properties:
                    rules:
                      items:
                        properties:
                          edge_location_display_name:
                            description: Prisma Access Location.
                            example: US West
                            type: string
                          event_time:
                            description: Time of the event.
                            example: 5
                            type: number
                          platform_type:
                            description: Type of platform.
                            example: prisma_access
                            type: string
                          source_city:
                            description: City from GeoIP.
                            example: San Jose
                            type: string
                          source_country:
                            description: Country from GeoIP.
                            example: US
                            type: string
                          source_user:
                            description: Source User.
                            example: test@example.com
                            type: string
                        type: object
                      required:
                      - event_time
                      type: array
                  type: object
              type: object
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                properties:
                  event_time:
                    description: Event time.
                    example: 1678886400000
                    type: number
                  user_count:
                    description: Count of users.
                    example: 1034
                    type: integer
                type: object
          description: OK
        '400':
          description: Resource property is not valid
        '403':
          description: Permission Denied
        '404':
          description: Resource not found
        '500':
          description: Failed to process request
      security:
      - Bearer: []
      summary: Agentless Internal User Histogram
      tags:
      - Agentless Users API
  /insights/v3.0/resource/query/users/agentless/users:
    post:
      description: Retrieves agentless user data.
      operationId: post-insights-v3.0-resource-query-users-agentless-users
      parameters:
      - description: Region mapping for the tenant.
        in: header
        name: X-PANW-Region
        required: true
        schema:
          example: americas
          type: string
      - description: A Prisma-Tenant is a unique identifier for a tenant or a subtenant within a single or multi-tenant architecture, providing precise tenant management and resource allocation.
        in: header
        name: Prisma-Tenant
        required: false
        schema:
          example: 12345678:12345679
          type: string
      requestBody:
        content:
          application/json:
            examples:
              With mandatory filters:
                value:
                  filter:
                    rules:
                    - operator: last_n_hours
                      property: event_time
                      values:
                      - 5
              With possible filters:
                value:
                  filter:
                    rules:
                    - operator: last_n_hours
                      property: event_time
                      values:
                      - 5
                    - operator: in
                      property: edge_location_display_name
                      values:
                      - US West
                    - operator: in
                      property: source_city
                      values:
                      - San Jose
                    - operator: in
                      property: source_country
                      values:
                      - US
                    - operator: in
                      property: platform_type
                      values:
                      - prisma_access
                      - ngfw
            schema:
              properties:
                filter:
                  properties:
                    rules:
                      items:
                        properties:
                          edge_location_display_name:
                            description: Prisma Access Location.
                            example: US West
                            type: string
                          event_time:
                            description: Time of the event.
                            example: 5
                            type: number
                          platform_type:
                            description: Platform type.
                            example: prisma_access
                            type: string
                          source_city:
                            description: City from GeoIP.
                            example: San Jose
                            type: string
                          source_country:
                            description: Country from GeoIP.
                            example: US
                            type: string
                        type: object
                      required:
                      - event_time
                      type: array
                  type: object
              type: object
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                properties:
                  username:
                    description: Username.
                    example: john.doe
                    type: string
                type: object
          description: OK
        '400':
          description: Resource property is not valid
        '403':
          description: Permission Denied
        '404':
          description: Resource not found
        '500':
          description: Failed to process request
      security:
      - Bearer: []
      summary: Get agentless users data
      tags:
      - Agentless Users API
components:
  securitySchemes:
    Bearer:
      scheme: bearer
      type: http