Palo Alto Networks IoT Public API

The IoT Public APIs are listed below.

Business capability
Cybersecurity Management BC-620

Operations 56

GET /iot/pub/v1/device Get Device Details per MAC Address #
GET /iot/pub/v1/device/ip Get Device Details per IP Address #
GET /iot/pub/v1/device/list Get the Device Inventory #
GET /iot/pub/v2/device/list Get the Device Inventory V2 #
GET /iot/pub/v1/profile/mapping Get Profile Mapping #
GET /iot/pub/v1/tag/list Get a List of User-defined Tags #
POST /iot/pub/v1/tag Adding Manual Tag to Devices #
DELETE /iot/pub/v1/tag Removing Manual Tag From The Devices #
GET /iot/pub/v1/alert/list Get Security Alerts #
PUT /iot/pub/v1/alert/update Resolve a Security Alert #
GET /iot/pub/v1/vulnerability/list Get Vulnerabilities #
PUT /iot/pub/v1/vulnerability/update Resolve Vulnerabilty Instances #
PUT /iot/pub/v1/device/bulkUpdate Bulk Device Updates - Cisco DNAC and Prime #
PUT /iot/pub/v1/device/bulkUpdate?updateSource=cisco_wlc Bulk Device Updates - Cisco WLC #
PUT /iot/pub/v1/device/bulkUpdate?updateSource=aruba_wlc Bulk Device Updates - Aruba WLC #
PUT /iot/pub/v1/device/bulkUpdate?updateSource=snmp Bulk Device Updates - SNMP #
PUT /iot/pub/v1/device/bulkUpdate?updateSource=cellular Bulk Device Updates - Cellular Devices #
PUT /iot/pub/v1/device/bulkUpdate?updateSource=sccm Bulk Device Updates - SCCM Devices #
PUT /iot/pub/v1/device/bulkUpdate?updateSource=crowdstrike_falcon Bulk Device Updates - Crowdstrike Falcon Devices #
PUT /iot/pub/v1/network/subnetBulkUpdate?updateSource=ipam_infoblox Bulk Subnet Updates - IPAM Infoblox #
PUT /iot/pub/v1/device/bulkUpdate?updateSource=customAttribute Bulk Device Updates - Custom Attribute #
GET /iot/pub/v1/policy/recommendation Get Activated Policy Rule Recommendations #
GET /iot/pub/v1/alertVuln/capability Get Alert or Vulnerability Capabilities #
PUT /iot/pub/v1/network/ndNodeGraphBulkUpdate Network Discovery Bulk Device Node Graph Updates #
PUT /iot/pub/v1/network/ndNodeL2L3BulkUpdate Network Discovery Bulk Device L2L3 Updates #
PUT /iot/pub/v1/network/ndNodeEndpointBulkUpdate Network Discovery Bulk Device Endpoint Updates #
GET /iot/pub/v1/xsoar/integrations Get a list of active integrations #
POST /iot/pub/v1/xsoar/device/reportUpload Collect Device Vulnerability Scan report from Xsoar Server #
POST /iot/pub/v1/xsoar/profile/aclSync/status Collect Profile ACL Sync Job Status #
POST /iot/pub/v1/xsoar/device/scanDetails Collect 3rd party scanner details from Xsoar Server #
PUT /iot/pub/v1/network/securityRules update a list of firewall security rules #
DELETE /iot/pub/v1/network/purgeRules retain the incoming list of rules while remove everything else #
PUT /iot/pub/v1/thirdPartyScan update device CVE from 3rd party integration and join with enxisting IoT device… #
POST /iot/pub/v1/xsoar/status sync xsoar integration playbook status to IoT #
GET /iot/pub/v1/xsoar/heartbeat IoT uses a heartbeat to track xsoar instance health #
GET /iot/pub/v1/filters Get a list of saved filters #
GET /iot/pub/v1/customAttributes Get a list of custom attributes #
POST /iot/pub/v1/customAttribute Create a custom attribute #
PUT /iot/pub/v1/customAttribute Update a custom attribute #
DELETE /iot/pub/v1/customAttribute Delete a custom attribute #
POST /iot/pub/v1/site Create Site Definitions #
GET /iot/pub/v1/site Get Site Definitions #
PUT /iot/pub/v1/site Update Site Definitions #
DELETE /iot/pub/v1/site Delete Site Definitions #
POST /iot/pub/v1/networkSegment Create Network Segment Definition #
GET /iot/pub/v1/networkSegment Get Network Segment Definitions #
PUT /iot/pub/v1/networkSegment Update Network Segment Definition #
DELETE /iot/pub/v1/networkSegment Delete Network Segment Definition #
POST /iot/pub/v1/subnet Create Subnet Definition #
GET /iot/pub/v1/subnet Get Subnet Definitions #
PUT /iot/pub/v1/subnet Update Subnet Definition #
DELETE /iot/pub/v1/subnet Delete Subnet Definition #
PUT /iot/pub/v1/subnet/transfer Transfer to Shared IP Block #
PUT /iot/pub/v1/subnet/revert Revert to an Unshared IP Block #
GET /iot/pub/v2/device/attributes Get Device Attributes #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/palo-alto-networks-iot-public-api-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

palo-alto-networks-iot-public-api-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  description: Please refer IoT Public API Authentication to know how to get API Bearer token
  title: Overview IoT Public API
  version: v1
  contact: {}
servers:
- url: https://api.strata.paloaltonetworks.com
tags:


# --- truncated at 32 KB (33 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/refs/heads/main/openapi/palo-alto-networks-iot-public-api-api-openapi.yml