Palo Alto Networks Connector Group API
The Connector-Group API from Palo Alto Networks — 9 operation(s) for connector-group.
The Connector-Group API from Palo Alto Networks — 9 operation(s) for connector-group.
openapi: 3.2.0
info:
title: ZTNA Connector Restful Connector Group API
version: v2
license:
name: Palo Alto Networks EULA
url: https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/legal/palo-alto-networks-end-user-license-agreement-eula.pdf
description: ZTNA Connector Restful API Specification This Open API spec file was created on March 25, 2026. © 2026 Palo Alto Networks, Inc. Palo Alto Networks is a registered trademark of Palo Alto Networks. A list of our trademarks can be found at [https://www.paloaltonetworks.com/company/trademarks.html](https://www.paloaltonetworks.com/company/trademarks.html). All other marks mentioned herein may be trademarks of their respective companies.
servers:
- url: https://api.sase.paloaltonetworks.com
security:
- bearerAuth: []
tags:
- name: Connector-Group
paths:
/sse/connector/v2.0/api/connector-groups:
get:
summary: List Connector Groups
description: Retrieve the connector groups details through this Application Programming Interface endpoint.
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/connector_group.list'
'400':
$ref: '#/components/responses/error-400'
'401':
$ref: '#/components/responses/error-401'
parameters:
- $ref: '#/components/parameters/x-panw-region'
- $ref: '#/components/parameters/pagination.offset'
- $ref: '#/components/parameters/pagination.limit'
- $ref: '#/components/parameters/query.sort'
- $ref: '#/components/parameters/query.search'
- $ref: '#/components/parameters/query.filters'
tags:
- Connector-Group
operationId: list.connector_groups.v2
post:
summary: Create Connector Group
description: Create the connector groups details through this Application Programming Interface endpoint.
responses:
'201':
$ref: '#/components/responses/http.201_created'
'400':
$ref: '#/components/responses/error-400'
'401':
$ref: '#/components/responses/error-401'
'403':
$ref: '#/components/responses/error-403'
'409':
$ref: '#/components/responses/error-409'
parameters:
- $ref: '#/components/parameters/x-panw-region'
tags:
- Connector-Group
operationId: create.connector_group.v2
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/connector_group-new'
/sse/connector/v2.0/api/connector-groups/{oid}:
get:
summary: Get Connector Group
description: Retrieve the {oid} details through this Application Programming Interface endpoint.
responses:
'200':
description: OK
content:
application/json:
schema:
allOf:
- $ref: '#/components/schemas/connector_group-existing'
- $ref: '#/components/schemas/entity_meta'
'400':
$ref: '#/components/responses/error-400'
'401':
$ref: '#/components/responses/error-401'
'404':
$ref: '#/components/responses/error-404'
parameters:
- $ref: '#/components/parameters/x-panw-region'
- $ref: '#/components/parameters/path.oid'
tags:
- Connector-Group
operationId: get.connector_group.v2
put:
summary: Update Connector Group
description: Update the {oid} details through this Application Programming Interface endpoint.
responses:
'200':
$ref: '#/components/responses/http.200_ok'
'400':
$ref: '#/components/responses/error-400'
'401':
$ref: '#/components/responses/error-401'
'403':
$ref: '#/components/responses/error-403'
'404':
$ref: '#/components/responses/error-404'
'409':
$ref: '#/components/responses/error-409'
parameters:
- $ref: '#/components/parameters/x-panw-region'
- $ref: '#/components/parameters/path.oid'
tags:
- Connector-Group
operationId: update.connector_group.v2
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/connector_group-existing'
delete:
summary: Delete Connector Group
description: Delete the {oid} details through this Application Programming Interface endpoint.
responses:
'202':
$ref: '#/components/responses/http.202_accepted'
'400':
$ref: '#/components/responses/error-400'
'401':
$ref: '#/components/responses/error-401'
'403':
$ref: '#/components/responses/error-403'
'404':
$ref: '#/components/responses/error-404'
'409':
$ref: '#/components/responses/error-409'
parameters:
- $ref: '#/components/parameters/x-panw-region'
- $ref: '#/components/parameters/path.oid'
tags:
- Connector-Group
operationId: delete.connector-group.v2
/sse/connector/v2.0/api/connector-groups/filters:
get:
summary: List Connector Group Filters
description: Get filter values for connector group fields.
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/filters'
examples:
empty:
$ref: '#/components/examples/filter-empty'
common:
$ref: '#/components/examples/filter'
'400':
$ref: '#/components/responses/error-400'
'401':
$ref: '#/components/responses/error-401'
parameters:
- $ref: '#/components/parameters/x-panw-region'
- $ref: '#/components/parameters/query.field'
- $ref: '#/components/parameters/query.search'
tags:
- Connector-Group
operationId: list.connector_group.filters.v2
/sse/connector/v2.0/api/connector-groups/{oid}/connectors:
get:
summary: List Connectors per Connector Group
description: Retrieve the connectors details through this Application Programming Interface endpoint.
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/connector_group.connectors'
'400':
$ref: '#/components/responses/error-400'
'401':
$ref: '#/components/responses/error-401'
'404':
$ref: '#/components/responses/error-404'
parameters:
- $ref: '#/components/parameters/x-panw-region'
- $ref: '#/components/parameters/path.oid'
- $ref: '#/components/parameters/query.sort'
- $ref: '#/components/parameters/query.search'
- $ref: '#/components/parameters/query.filters'
tags:
- Connector-Group
operationId: list.connector_group.connectors.v2
/sse/connector/v2.0/api/connector-groups/{oid}/applications:
get:
summary: List FQDNs per Connector Group
description: Retrieve the applications details through this Application Programming Interface endpoint.
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/connector_group.fqdn_rules'
'400':
$ref: '#/components/responses/error-400'
'401':
$ref: '#/components/responses/error-401'
'404':
$ref: '#/components/responses/error-404'
parameters:
- $ref: '#/components/parameters/x-panw-region'
- $ref: '#/components/parameters/path.oid'
- $ref: '#/components/parameters/query.sort'
- $ref: '#/components/parameters/query.search'
- $ref: '#/components/parameters/query.filters'
tags:
- Connector-Group
operationId: list.connector_group.fqdn_rules.v2
/sse/connector/v2.0/api/connector-groups/{oid}/subnets:
get:
summary: List Subnets per Connector Group
description: Retrieve the subnets details through this Application Programming Interface endpoint.
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/connector_group.subnet_rules'
'400':
$ref: '#/components/responses/error-400'
'401':
$ref: '#/components/responses/error-401'
'404':
$ref: '#/components/responses/error-404'
parameters:
- $ref: '#/components/parameters/x-panw-region'
- $ref: '#/components/parameters/path.oid'
- $ref: '#/components/parameters/query.sort'
- $ref: '#/components/parameters/query.search'
- $ref: '#/components/parameters/query.filters'
tags:
- Connector-Group
operationId: list.connector_group.subnet_rules.v2
/sse/connector/v2.0/api/connector-groups/{oid}/wildcards:
get:
summary: List Wildcards per Connector Group
description: Retrieve the wildcards details through this Application Programming Interface endpoint.
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/connector_group.wildcards'
'400':
$ref: '#/components/responses/error-400'
'401':
$ref: '#/components/responses/error-401'
'404':
$ref: '#/components/responses/error-404'
parameters:
- $ref: '#/components/parameters/x-panw-region'
- $ref: '#/components/parameters/path.oid'
- $ref: '#/components/parameters/query.sort'
- $ref: '#/components/parameters/query.search'
- $ref: '#/components/parameters/query.filters'
tags:
- Connector-Group
operationId: list.connector_group.wildcards.v2
/sse/connector/v2.0/api/connector-groups/{oid}/scheduled-upgrade:
post:
summary: Create Connector Group Scheduled Upgrade
description: Create the scheduled upgrade details through this Application Programming Interface endpoint.
responses:
'201':
$ref: '#/components/responses/http.201_created'
'400':
$ref: '#/components/responses/error-400'
'404':
$ref: '#/components/responses/error-404'
parameters:
- $ref: '#/components/parameters/path.oid'
tags:
- Connector-Group
operationId: create.connector_group.scheduled_upgrade.v2
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/connector_group.scheduled_upgrade'
get:
summary: Get Connector Group Scheduled Upgrade
description: Retrieve the scheduled upgrade details through this Application Programming Interface endpoint.
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/connector_group.scheduled_upgrade'
'400':
$ref: '#/components/responses/error-400'
'401':
$ref: '#/components/responses/error-401'
'404':
$ref: '#/components/responses/error-404'
parameters:
- $ref: '#/components/parameters/path.oid'
tags:
- Connector-Group
operationId: get.connector_group.scheduled_upgrade.v2
put:
summary: Update Connector Group Scheduled Upgrade
description: Update the scheduled upgrade details through this Application Programming Interface endpoint.
responses:
'200':
$ref: '#/components/responses/http.200_ok'
'400':
$ref: '#/components/responses/error-400'
'404':
$ref: '#/components/responses/error-404'
parameters:
- $ref: '#/components/parameters/path.oid'
tags:
- Connector-Group
operationId: update.connector_group.scheduled_upgrade.v2
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/connector_group.scheduled_upgrade'
delete:
summary: Delete Connector Group Scheduled Upgrade
description: Delete the scheduled upgrade details through this Application Programming Interface endpoint.
responses:
'202':
$ref: '#/components/responses/http.202_accepted'
'400':
$ref: '#/components/responses/error-400'
'401':
$ref: '#/components/responses/error-401'
'403':
$ref: '#/components/responses/error-403'
'404':
$ref: '#/components/responses/error-404'
parameters:
- $ref: '#/components/parameters/path.oid'
tags:
- Connector-Group
operationId: delete.connector_group.scheduled_upgrade.v2
/sse/connector/v2.0/api/connector-groups/{oid}/scheduled-upgrade-status:
get:
summary: Get Connector Group Scheduled Upgrade Status
description: Retrieves the scheduled upgrade status for a connector group, including the upgrade status of all connectors in the group.
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/connector_group.upgrade_status'
'400':
$ref: '#/components/responses/error-400'
'401':
$ref: '#/components/responses/error-401'
'404':
$ref: '#/components/responses/error-404'
parameters:
- $ref: '#/components/parameters/x-panw-region'
- $ref: '#/components/parameters/path.oid'
tags:
- Connector-Group
operationId: get.connector_group.scheduled_upgrade_status.v2
components:
examples:
filter-empty:
summary: when no filter value is available
value: []
filter:
summary: common scenario
value:
- value 1
- value 2
schemas:
pagination.total:
type: integer
title: The total number of objects
wildcard.list:
type: object
properties:
data:
type: array
items:
allOf:
- $ref: '#/components/schemas/wildcard-existing'
- $ref: '#/components/schemas/entity_meta'
total:
$ref: '#/components/schemas/pagination.total'
limit:
$ref: '#/components/schemas/pagination.limit'
offset:
$ref: '#/components/schemas/pagination.offset'
required:
- data
- total
- offset
- limit
pagination.limit:
type: integer
title: The manimum number of objects to return
connector_group.status:
type: object
properties:
token_active:
type: string
token_secret:
type: string
counts:
type: object
properties:
applications:
type: integer
connectors:
type: integer
wildcards:
type: integer
ipsubnets:
type: integer
pa_region:
type: string
anycast_ip:
type: string
sw_version:
type: string
user_id_ip:
type: string
user_id_port:
type: string
connector_group-new:
type: object
properties:
name:
type: string
description: 'Name of the connector group.
It can only be 64 characters long
and contain unicode text, space, dash, or underscore, or period.'
maxLength: 64
minLength: 1
pattern: ^[\p{L}\p{N}\p{P}\s,.:_-]*$
description:
type: string
description: Description of the connector group.
maxLength: 64
pattern: ^[\p{L}\p{N}\p{P}\s,.:_-]*$
is_autoscale:
type: boolean
description: 'Whether the connector group is autoscaled.
If omitted, defaults to false.'
preserve_user_id:
type: boolean
description: 'Whether to preserve user ID for this connector group.
If omitted, defaults to false.'
is_ngfw:
type: boolean
description: 'Connector group type.
If false (default), the group is a ZTNA Connector group.
If true, the group is an NGFW Connector group.
If omitted, defaults to false.'
pba_project_name:
type: string
description: 'DPA project name that this connector group will serve.
This field must be provided when the tenant is DPA-enabled,
and must not be provided when the tenant is not DPA-enabled.'
required:
- name
connector.status:
type: object
properties:
cgnx_sw_version:
type: string
cgnx_vion_ip:
type: string
cgnx_location:
type: string
cidr:
type: string
local_ip:
type: string
sc_id:
description: Service Connection ID
type: string
sc_name:
type: string
token_active:
type: string
token_secret:
type: string
state_bits:
type: number
flags:
type: object
properties:
config_state:
type: string
tunnel_up:
type: boolean
token_state:
type: string
control_plane_up:
type: boolean
capabilities:
type: object
properties:
wildcard_supported:
type: boolean
ipsubnet_supported:
type: boolean
error:
type: object
cgnx_scheduled_sw_version:
type: string
cgnx_scheduled_download:
type: string
cgnx_scheduled_upgrade:
type: string
cgnx_upgrade_state:
description: When undefined, no upgrade is in progress.
type: string
enum:
- download_cancelled
- download_complete
- download_discovery
- download_failed
- download_init
- download_scheduled
- failed
- init
- installing
- install_failed
- upgrade_cancelled
- upgrade_init
- upgrade_scheduled
- upgrade_timeout
- upgrading
- verify
- verifying
cgnx_upgrade_description:
type: string
cgnx_upgrade_failure_info:
type: string
cgnx_upgrade_download_percent:
type: number
cgnx_upgrade_retry_count:
type: number
cgnx_upgrade_status_last_updated:
type: string
connector-existing:
type: object
properties:
oid:
type: string
description: Id of the entry.
readOnly: true
name:
type: string
description: 'Name of the connector.
It can only be 64 characters long
and contain unicode text, space, dash, or underscore, or period.'
maxLength: 64
minLength: 1
pattern: ^[\p{L}\p{N}\p{P}\s,.:_-]*$
readOnly: true
description:
type: string
description: Description of the connector.
maxLength: 64
pattern: ^[\p{L}\p{N}\p{P}\s,.:_-]*$
group:
type: string
description: The [connector group id](#tag/connector-group/operation/list.connector_group.v2)
readOnly: true
required:
- oid
- name
- group
connector_group.list:
type: object
description: 'Connector Group summary containing information needed to show connector groups in a tabular format.
'
properties:
data:
type: array
items:
allOf:
- $ref: '#/components/schemas/connector_group-existing'
- $ref: '#/components/schemas/connector_group.status'
- $ref: '#/components/schemas/entity_meta'
total:
$ref: '#/components/schemas/pagination.total'
limit:
$ref: '#/components/schemas/pagination.limit'
offset:
$ref: '#/components/schemas/pagination.offset'
required:
- data
- total
- offset
- limit
connector_group.connectors:
type: object
properties:
group:
$ref: '#/components/schemas/connector_group-existing'
connectors:
$ref: '#/components/schemas/connector.list'
subnet_rule.list:
type: object
properties:
data:
type: array
items:
allOf:
- $ref: '#/components/schemas/subnet_rule-existing'
- $ref: '#/components/schemas/entity_meta'
total:
$ref: '#/components/schemas/pagination.total'
limit:
$ref: '#/components/schemas/pagination.limit'
offset:
$ref: '#/components/schemas/pagination.offset'
required:
- data
- total
- offset
- limit
connector_group-existing:
type: object
properties:
oid:
description: Connector Group ID
type: string
readOnly: true
name:
type: string
description: 'Name of the connector group.
It can only be 64 characters long
and contain unicode text, space, dash, or underscore, or period.'
maxLength: 64
minLength: 1
pattern: ^[\p{L}\p{N}\p{P}\s,.:_-]*$
readOnly: true
description:
type: string
description: Description of the connector group.
maxLength: 64
pattern: ^[\p{L}\p{N}\p{P}\s,.:_-]*$
is_autoscale:
type: boolean
description: 'Whether the connector group is autoscaled.
If omitted, defaults to false.'
readOnly: true
preserve_user_id:
type: boolean
description: 'Whether to preserve user ID for this connector group.
If omitted, defaults to false.'
readOnly: true
is_ngfw:
type: boolean
description: 'Connector group type.
If false (default), the group is a ZTNA Connector group.
If true, the group is an NGFW Connector group.
If omitted, defaults to false.'
readOnly: true
pba_project_name:
type: string
description: 'DPA project name that this connector group will serve.
This field must be provided when the tenant is DPA-enabled,
and must not be provided when the tenant is not DPA-enabled.'
required:
- oid
error_detail:
type: object
description: Error detail information following Google Cloud API CauseInfo format
properties:
'@type':
type: string
description: Type identifier for the detail object
example: google-cloud-api/CauseInfo
message:
type: string
description: Detailed error message
causes:
type: array
description: Array of cause information objects
items:
type: object
properties:
message:
type: string
description: Cause message
module:
type: string
description: Module where the cause originated
fqdn_rule-existing:
type: object
properties:
oid:
type: string
description: Id of the entry.
readOnly: true
name:
type: string
description: 'Name of the FQDN rule.
It can only be 64 characters long
and contain unicode text, space, dash, or underscore, or period.'
maxLength: 64
minLength: 1
pattern: ^[\p{L}\p{N}\p{P}\s,.:_-]*$
description:
type: string
maxLength: 64
pattern: ^[\p{L}\p{N}\p{P}\s,.:_-]*$
group:
type: string
description: A comma separated list of [connector group id](#tag/connector-group/operation/list.connector_group.v2)
spec:
type: array
items:
type: object
properties:
fqdn:
type: string
description: FQDN of the rule.
pattern: (?=^.{4,253}$)(^((?!-)[a-zA-Z0-9-]{0,62}[a-zA-Z0-9]\.)+[a-zA-Z]{2,63}$)
readOnly: true
tcp_port:
type: string
description: 'TCP port number(s).
It can be a single port number, multiple port numbers separated by comma,
or a port range like 8000-9000.
If both tcp_port and udp_port are omitted, tcp_port defaults to 443.'
udp_port:
type: string
description: 'UDP port number(s).
It can be a single port number, multiple port numbers separated by comma,
or a port range like 8000-9000.
If both tcp_port and udp_port are omitted, tcp_port defaults to 443.'
probe_type:
type: string
enum:
- tcp_ping
- icmp_ping
description: 'The probing type.
The value can be `tcp_ping`, `icmp_ping`, or omitted.'
probe_port:
type: string
description: The probing port if the `probe_type` is `tcp_ping`.
required:
- fqdn
app_enabled:
type: boolean
description: 'Whether the FQDN rule is enabled.
If omitted, defaults to false.'
icmp_allowed:
type: boolean
description: 'Whether ICMP is allowed for this FQDN rule.
If omitted, defaults to true.'
use_dc_ip:
type: boolean
description: 'Whether to use datacenter IP for this FQDN rule.
If omitted, defaults to false.'
anycast_ip:
type: string
description: Anycast IP address assigned to this FQDN rule.
readOnly: true
required:
- oid
- name
- group
pagination.offset:
type: integer
title: The offset into the total number of objects
connector_group.wildcards:
type: object
properties:
group:
$ref: '#/components/schemas/connector_group-existing'
wildcards:
$ref: '#/components/schemas/wildcard.list'
filters:
type: array
items:
type: string
connector_group.upgrade_status:
type: object
properties:
name:
type: string
description: Connector group name
oid:
type: string
description: Connector group ID
rolling_upgrade:
type: boolean
description: Whether rolling upgrade is enabled for this connector group
upgrade_status:
type: string
description: Overall upgrade status for the connector group
data:
type: array
description: List of connector upgrade statuses within this group
items:
type: object
properties:
connector_name:
type: string
description: Connector name
connector_oid:
type: string
description: Connector ID
upgrade_status:
type: string
description: Current upgrade status of the connector
current_sw_version:
type: string
description: Current software version running on the connector
upgrade_sw_version:
type: string
description: Target software version for the upgrade
upgrade_time:
type: string
description: Scheduled upgrade time
sessions_count:
type: integer
description: Number of active sessions (present when connector is draining)
drain_time:
type: integer
description: Time remaining until drain completes in seconds (present when connector is draining)
failure_reason:
type: string
description: Reason for upgrade failure (if upgrade failed)
entity_meta:
type: object
properties:
created_time:
type: string
updated_time:
type: string
fqdn_rule.list:
type: object
properties:
data:
type: array
items:
allOf:
- $ref: '#/components/schemas/fqdn_rule-existing'
- $ref: '#/components/schemas/entity_meta'
total:
$ref: '#/components/schemas/pagination.total'
limit:
$ref: '#/components/schemas/pagination.limit'
offset:
$ref: '#/components/schemas/pagination.offset'
required:
- data
- total
- offset
- limit
connector_group.fqdn_rules:
type: object
properties:
group:
$ref: '#/components/schemas/connector_group-existing'
applications:
$ref: '#/components/schemas/fqdn_rule.list'
error_response:
type: object
description: Error response payload
properties:
error:
$ref: '#/components/schemas/error_object'
required:
- error
wildcard-existing:
type: object
properties:
id:
description: Id of the entry.
type: string
readOnly: true
name:
type: string
description: 'Name of the wildcard.
It can only be 64 characters long
and contain unicode text, space, dash, or underscore, or period.'
maxLength: 64
minLength: 1
pattern: ^[\p{L}\p{N}\p{P}\s,.:_-]*$
description:
type: string
maxLength: 64
pattern: ^[\p{L}\p{N}\p{P}\s,.:_-]*$
group:
type: string
description: A comma separated list of [connector group id](#tag/connector-group/operation/list.connector_group.v2)
fqdn:
type: string
description: The wildcard to match.
readOnly: true
tcp_port:
type: string
description: 'TCP port number(s).
It can be a single port number, multiple port numbers separated by comma,
or a port range like 8000-9000.
If both tcp_port and udp_port are omitted, tcp_port defaults to 443.'
udp_port:
type: string
description: 'UDP port number(s).
It can be a single port number, multiple port numbers separated by comma,
or a port range like 8000-9000.
If both tcp_port and udp_port are omitted, tcp_port defaults to 443.'
probe_type:
type: string
enum:
- tcp_ping
- icmp_ping
description: 'The probing type.
The value can be `tcp_ping`, `icmp_ping`, or omitted.'
probe_port:
type: string
description: The probing port if the `probe_type` is `tcp_ping`.
app_enabled:
type: boolean
description: 'Whether the wildcard is enabled.
If omitted, defaults to false.'
icmp_allowed:
type: boolean
description: 'Whether ICMP is allowed for this wildcard.
If omitted, defaults to true.'
enable_policy:
type: boolean
description: 'Whether policy is enabled for this wildcard.
If omitted, defaults to false.'
use_dc_ip:
type: boolean
description: 'Whether to use datacenter IP for this wildcard.
If omitted, defaults to false.'
applications:
type: object
description: Discovered Wildcard App oid to name mapping.
readOnly: true
additionalProperties:
type: string
required:
- id
- name
- group
- fqdn
connector_group.subnet_rules:
type: object
properties:
# --- truncated at 32 KB (39 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/refs/heads/main/openapi/palo-alto-networks-connector-group-api-openapi.yml