Palo Alto Networks User Roles API
Manage your Prisma Cloud user roles.
Manage your Prisma Cloud user roles.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/palo-alto-networks-user-roles-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: Palo Alto Networks User Roles API
version: Latest
contact: {}
description: 'Operations tagged User Roles across 2 of this provider''s published API definitions: palo-alto-cspm-consolidated-spec-cspm-spec-openapi.json, palo-alto-cspm-userroles-openapi.json. Each path carries the servers of the definition it was published in.'
servers:
- url: https://api.prismacloud.io
- url: https://api2.prismacloud.io
- url: https://api3.prismacloud.io
- url: https://api4.prismacloud.io
- url: https://api.anz.prismacloud.io
- url: https://api.eu.prismacloud.io
- url: https://api2.eu.prismacloud.io
- url: https://api.gov.prismacloud.io
- url: https://api.prismacloud.cn
- url: https://api.ca.prismacloud.io
- url: https://api.sg.prismacloud.io
- url: https://api.uk.prismacloud.io
- url: https://api.ind.prismacloud.io
- url: https://api.jp.prismacloud.io
- url: https://api.fr.prismacloud.io
tags:
- description: "Manage your Prisma Cloud user roles. \n"
name: User Roles
paths:
/user/role:
get:
description: Returns an array of user roles.
operationId: get-user-roles
responses:
'200':
content:
application/json:
schema:
items:
$ref: '#/components/schemas/UserRoleViewModel'
type: array
description: successful operation
'403':
description: unauthorized_access
'500':
description: internal_error
security:
- x-redlock-auth: []
summary: List User Roles
tags:
- User Roles
post:
description: "Creates a new user role. \n\nSee [Prisma Cloud Administrator Permissions](https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/manage-prisma-cloud-administrators/prisma-cloud-admin-permissions.html) \nfor the permissions associated with each role.\n\nNote that the request body parameter **accountGroupIds** is required but can be an empty array.\n"
operationId: add-user-role
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/UserRoleModel'
description: User Role
required: true
responses:
'200':
description: successful operation
'400':
description: invalid_user_role_name / invalid_user_role_type / invalid_account_group_ids / user_role_name_already_exists
'403':
description: unauthorized_access
'500':
description: internal_error
security:
- x-redlock-auth: []
summary: Add User Role
tags:
- User Roles
servers:
- url: https://api.prismacloud.io
- url: https://api2.prismacloud.io
- url: https://api3.prismacloud.io
- url: https://api4.prismacloud.io
/user/role/name:
get:
description: Returns list of user role IDs and names.
operationId: get-user-role-name
responses:
'200':
content:
application/json:
schema:
items:
additionalProperties:
type: string
type: object
type: array
description: successful operation
'403':
description: unauthorized_access
'500':
description: internal_error
security:
- x-redlock-auth: []
summary: List User Role Names
tags:
- User Roles
servers:
- url: https://api.prismacloud.io
- url: https://api2.prismacloud.io
- url: https://api3.prismacloud.io
- url: https://api4.prismacloud.io
/user/role/type:
get:
description: Returns a list of permission groups to which users can belong.
operationId: get-user-role-types
responses:
'200':
content:
application/json:
schema:
items:
enum:
- SYSTEM_ADMIN
- ACCOUNT_ADMIN
- ACCOUNT_READ_ONLY
- SSO_ADMIN
- CLOUD_PROVISIONING_ADMIN
- TENANT_PROVISIONING_ADMIN
- PRISMA_SERVICE_USER
- ACCOUNT_AND_CLOUD_PROVISIONING_ADMIN
- BUILD_AND_DEPLOY_SECURITY
- BUILD_AND_DEPLOY_SECURITY_CI
- COMPUTE_ADMIN
- NETWORK_SECURITY_OPERATOR
- NETWORK_SECURITY_OPERATOR_READ_ONLY
- COMPUTE_ACCOUNT_ADMIN
- DEVELOPER
- COMPUTE_ACCOUNT_READ_ONLY
type: string
type: array
description: successful operation
security:
- x-redlock-auth: []
summary: List User Role Types
tags:
- User Roles
servers:
- url: https://api.prismacloud.io
- url: https://api2.prismacloud.io
- url: https://api3.prismacloud.io
- url: https://api4.prismacloud.io
/user/role/{id}:
get:
description: Returns user role information for a specified ID.
operationId: get-user-role
parameters:
- description: User Role ID
in: path
name: id
required: true
schema:
type: string
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/UserRoleViewModel'
description: successful operation
'400':
description: invalid_id
'403':
description: unauthorized_access
'500':
description: internal_error
security:
- x-redlock-auth: []
summary: User Role Info
tags:
- User Roles
put:
description: Updates information for an existing user role.
operationId: update-user-role
parameters:
- description: User Role ID
in: path
name: id
required: true
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/UserRoleModel'
description: User Role
required: true
responses:
'200':
description: successful operation
'400':
description: invalid_id / invalid_user_role_name / invalid_user_role_type / invalid_account_group_ids / user_role_name_already_exists
'403':
description: unauthorized_access
'500':
description: internal_error
security:
- x-redlock-auth: []
summary: Update User Role
tags:
- User Roles
delete:
description: Deletes a user role with the specified ID.
operationId: delete-user-role
parameters:
- description: User Role ID
in: path
name: id
required: true
schema:
type: string
responses:
'200':
description: successful operation
'400':
description: invalid_id / cannot_delete_role_users_associated / invalid_id
'403':
description: unauthorized_access
'500':
description: internal_error
security:
- x-redlock-auth: []
summary: Delete User Role
tags:
- User Roles
servers:
- url: https://api.prismacloud.io
- url: https://api2.prismacloud.io
- url: https://api3.prismacloud.io
- url: https://api4.prismacloud.io
components:
schemas:
Attributes1:
description: Additional attributes of the the user role
properties:
hasDefenderPermissions:
description: User has compute defender permissions
type: boolean
onlyAllowCIAccess:
description: User can only use access keys to use Prisma Cloud. UI access will be unavailable.
type: boolean
onlyAllowComputeAccess:
description: User can only access the Prisma Cloud Compute Console
type: boolean
type: object
UserRoleViewModel:
description: Model for User Role View
properties:
accountGroupIds:
description: Accessible Account Group IDs
items:
type: string
type: array
accountGroups:
description: Associated Account Groups
items:
additionalProperties:
type: string
type: object
readOnly: true
type: array
additionalAttributes:
allOf:
- $ref: '#/components/schemas/Attributes1'
- description: Additional attributes of the the user role
associatedUsers:
description: Associated application users which cannot exist in the system without the user role
items:
type: string
readOnly: true
type: array
codeRepositories:
description: Associated Code Repositories
items:
additionalProperties:
type: string
type: object
readOnly: true
type: array
codeRepositoryIds:
description: Accessible Code Repository IDs
items:
type: string
type: array
description:
description: Description
type: string
id:
description: User Role ID
readOnly: true
type: string
lastModifiedBy:
description: Last Modified By
readOnly: true
type: string
lastModifiedTs:
description: Last Modified Time
format: int64
readOnly: true
type: integer
name:
description: Name
type: string
resourceListIds:
description: Accessible Resource List IDs
items:
type: string
type: array
resourceLists:
description: Associated Resource Lists
items:
additionalProperties:
type: string
type: object
readOnly: true
type: array
restrictDismissalAccess:
type: boolean
roleType:
description: User Role Type (Default or Custom Permission Group Name).
type: string
required:
- name
- roleType
type: object
UserRoleModel:
description: Model for User Role
properties:
accountGroupIds:
description: Accessible Account Group IDs
items:
type: string
type: array
additionalAttributes:
allOf:
- $ref: '#/components/schemas/Attributes1'
- description: Additional attributes of the the user role
associatedUsers:
description: Associated application users which cannot exist in the system without the user role
items:
type: string
readOnly: true
type: array
codeRepositoryIds:
description: Accessible Code Repository IDs
items:
type: string
type: array
description:
description: Description
type: string
id:
description: User Role ID
readOnly: true
type: string
lastModifiedBy:
description: Last Modified By
readOnly: true
type: string
lastModifiedTs:
description: Last Modified Time
format: int64
readOnly: true
type: integer
name:
description: Name
type: string
resourceListIds:
description: Accessible Resource List IDs
items:
type: string
type: array
restrictDismissalAccess:
type: boolean
roleType:
description: User Role Type (Default or Custom Permission Group Name).
type: string
required:
- name
- roleType
type: object
Attributes:
description: Additional attributes of the the user role
properties:
hasDefenderPermissions:
description: User has compute defender permissions
type: boolean
onlyAllowCIAccess:
description: User can only use access keys to use Prisma Cloud. UI access will be unavailable.
type: boolean
onlyAllowComputeAccess:
description: User can only access the Prisma Cloud Compute Console
type: boolean
type: object
UserRoleViewModel_2:
description: Model for User Role View
properties:
accountGroupIds:
description: Accessible Account Group IDs
items:
type: string
type: array
accountGroups:
description: Associated Account Groups
items:
additionalProperties:
type: string
type: object
readOnly: true
type: array
additionalAttributes:
allOf:
- $ref: '#/components/schemas/Attributes'
- description: Additional attributes of the the user role
associatedUsers:
description: Associated application users which cannot exist in the system without the user role
items:
type: string
readOnly: true
type: array
codeRepositories:
description: Associated Code Repositories
items:
additionalProperties:
type: string
type: object
readOnly: true
type: array
codeRepositoryIds:
description: Accessible Code Repository IDs
items:
type: string
type: array
description:
description: Description
type: string
id:
description: User Role ID
readOnly: true
type: string
lastModifiedBy:
description: Last Modified By
readOnly: true
type: string
lastModifiedTs:
description: Last Modified Time
format: int64
readOnly: true
type: integer
name:
description: Name
type: string
resourceListIds:
description: Accessible Resource List IDs
items:
type: string
type: array
resourceLists:
description: Associated Resource Lists
items:
additionalProperties:
type: string
type: object
readOnly: true
type: array
restrictDismissalAccess:
type: boolean
roleType:
description: User Role Type (Default or Custom Permission Group Name).
type: string
required:
- name
- roleType
type: object
UserRoleModel_2:
description: Model for User Role
properties:
accountGroupIds:
description: Accessible Account Group IDs
items:
type: string
type: array
additionalAttributes:
allOf:
- $ref: '#/components/schemas/Attributes'
- description: Additional attributes of the the user role
associatedUsers:
description: Associated application users which cannot exist in the system without the user role
items:
type: string
readOnly: true
type: array
codeRepositoryIds:
description: Accessible Code Repository IDs
items:
type: string
type: array
description:
description: Description
type: string
id:
description: User Role ID
readOnly: true
type: string
lastModifiedBy:
description: Last Modified By
readOnly: true
type: string
lastModifiedTs:
description: Last Modified Time
format: int64
readOnly: true
type: integer
name:
description: Name
type: string
resourceListIds:
description: Accessible Resource List IDs
items:
type: string
type: array
restrictDismissalAccess:
type: boolean
roleType:
description: User Role Type (Default or Custom Permission Group Name).
type: string
required:
- name
- roleType
type: object
securitySchemes:
x-redlock-auth:
description: The x-redlock-auth value is a JSON Web Token (JWT).
in: header
name: x-redlock-auth
type: apiKey
x-refined-from:
- palo-alto-cspm-consolidated-spec-cspm-spec-openapi.json
- palo-alto-cspm-userroles-openapi.json