Palo Alto Networks Tenant API API
The Tenant API API from Palo Alto Networks — 6 operation(s) for tenant api.
The Tenant API API from Palo Alto Networks — 6 operation(s) for tenant api.
openapi: 3.2.0
info:
title: Prisma Browser for MSP Tenant API API
version: '1.0'
description: "The Prisma Browser for MSP API provides a suite of endpoints to automate the management of security services for the SMB market. \nThis API allows developers to programmatically create and configure new tenants, manage license allocation, and retrieve detailed security reports on blocked malware, \nmalicious websites, and unauthorized extensions. By using these services, MSPs can integrate multi-tenant visibility and lifecycle management directly into their \nown dashboards or third-party platforms like ServiceNow. This Open API spec file was created on February 23, 2026. © 2026 Palo Alto Networks, Inc. Palo Alto Networks is a registered trademark of Palo Alto Networks. A list of our trademarks can be found at [https://www.paloaltonetworks.com/company/trademarks.html](https://www.paloaltonetworks.com/company/trademarks.html). All other marks mentioned herein may be trademarks of their respective companies."
tags:
- name: Tenant API
paths:
/mt/pab/tenant:
post:
summary: Create a new tenant
description: Creates a new tenant with the specified configuration including region, identity provider, and user groups.
operationId: PostMtPabTenant
responses:
'200':
description: Tenant created successfully
content:
application/json: {}
'400':
description: Invalid request payload or validation failed
'404':
description: Required resource not found
'500':
description: Internal server error
parameters: []
tags:
- Tenant API
requestBody:
description: Tenant creation request payload with all required configuration details
content:
application/json:
examples:
MSP IDP Tenant:
description: Create a tenant using MSP Identity Provider
value:
tenant_vertical: High Tech
auth_profile_id: test_profile
directory: pab_standalone_test_directory
identity_provider_type: MSP IDP
region: us
root_tsg_id: '1868805847'
tenant_name: test_tenant_1
serial_number: SN12345678
user_groups:
- Everyone
user_quantity: 3
schema:
$ref: '#/components/schemas/CreateTenantRequest'
required: true
security:
- authKey: []
/mt/pab/tenant/auth_profile:
get:
summary: Get authentication profiles
description: Retrieves all available authentication profiles for the tenant service group.
operationId: GetMtPabTenantAuth_profile
responses:
'200':
description: Successfully retrieved authentication profiles
content:
application/json: {}
'400':
description: Invalid request
'404':
description: Authentication profiles not found
'500':
description: Internal server error
parameters: []
tags:
- Tenant API
security:
- authKey: []
/mt/pab/tenant/directories:
get:
summary: Get available directories
description: Retrieves a list of all available directories for the tenant service group.
operationId: GetMtPabTenantDirectories
responses:
'200':
description: Successfully retrieved directories
content:
application/json: {}
'400':
description: Invalid request
'404':
description: Directories not found
'500':
description: Internal server error
parameters: []
tags:
- Tenant API
security:
- authKey: []
/mt/pab/tenant/licenses:
get:
summary: Get license utilization information
description: Retrieves current license utilization metrics and availability for the tenant service group.
operationId: GetMtPabTenantLicenses
responses:
'200':
description: Successfully retrieved license utilization
content:
application/json: {}
'400':
description: Invalid request
'404':
description: License information not found
'500':
description: Internal server error
parameters: []
tags:
- Tenant API
security:
- authKey: []
/mt/pab/tenant/region:
get:
summary: Get available regions
description: Retrieves a list of all available regions for tenant deployment.
operationId: GetMtPabTenantRegion
responses:
'200':
description: Successfully retrieved regions
content:
application/json: {}
'400':
description: Invalid request
'404':
description: Regions not found
'500':
description: Internal server error
parameters: []
tags:
- Tenant API
security:
- authKey: []
/mt/pab/tenant/user_group:
post:
summary: Get user groups for a directory
description: Retrieves all user groups associated with the specified directory name.
operationId: PostMtPabTenantUser_group
responses:
'200':
description: Successfully retrieved user groups
content:
application/json: {}
'400':
description: Invalid request payload
'404':
description: Directory not found
'500':
description: Internal server error
parameters: []
tags:
- Tenant API
requestBody:
description: Directory name for which to retrieve user groups
content:
application/json:
examples:
Example Request:
description: Get user groups for the specified directory
value:
directory_name: pab_test_directory
schema:
$ref: '#/components/schemas/UserGroupRequest'
required: true
security:
- authKey: []
components:
schemas:
UserGroupRequest:
type: object
required:
- directory_name
examples:
- directory_name: pab_test_directory
description: Request payload for retrieving user groups from a directory
properties:
directory_name:
type: string
minLength: 1
examples:
- pab_test_directory
description: Name of the directory from which to retrieve user groups
CreateTenantRequest:
type: object
required:
- root_tsg_id
- tenant_name
- serial_number
- region
- user_quantity
- identity_provider_type
description: Request payload for creating a new PAB tenant
properties:
root_tsg_id:
type: string
minLength: 1
examples:
- '1868805847'
description: Root Tenant Service Group ID under which the new tenant will be created
tenant_name:
type: string
minLength: 1
examples:
- test_tenant_1
description: Name of the tenant to be created
tenant_vertical:
type: string
examples:
- High Tech
description: Vertical or industry type for the tenant
serial_number:
type: string
minLength: 1
examples:
- SN12345678
description: Serial number for the tenant deployment
region:
type: string
minLength: 1
examples:
- us
description: 'SLS region where the tenant will be deployed. Valid values: us, eu, jp, uk, in, sg, ca, id, au, de'
user_quantity:
type: integer
format: int32
examples:
- 3
description: Number of user licenses to allocate to this tenant
minimum: 1
identity_provider_type:
type: string
minLength: 1
examples:
- MSP IDP
description: 'Type of identity provider to use for authentication. Valid values: ''MSP IDP'', ''Tenant IDP'''
directory:
type: string
examples:
- pab_standalone_test_directory
description: Directory name for user authentication (required when using MSP IDP)
auth_profile_id:
type: string
examples:
- test_profile
description: Authentication profile ID to use for the tenant
user_groups:
type: array
examples:
- - Everyone
items:
type: string
description: Array of user group names to be assigned to the tenant
securitySchemes:
authKey: {}