Palo Alto Networks User Roles API

Manage your Prisma Cloud user roles.

Business capability
Identity & Access Management BC-620.20

Operations 7

GET /user/role List User Roles #
POST /user/role Add User Role #
GET /user/role/name List User Role Names #
GET /user/role/type List User Role Types #
GET /user/role/{id} User Role Info #
PUT /user/role/{id} Update User Role #
DELETE /user/role/{id} Delete User Role #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/palo-alto-networks-user-roles-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

palo-alto-networks-user-roles-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  contact: {}
  description: 'Access Keys are a secure way to enable programmatic access to the Prisma Cloud API. By default, only

    the System Admin has API access and can enable API access for other administrators. If you have API access,

    you can create up to two access keys. Create an access key for a limited time period and regenerate your API

    keys periodically to minimize exposure and follow security best practices.'
  title: Prisma Cloud Access Keys API Overview User Roles API
  version: Latest
servers:
- url: https://api.prismacloud.io
- url: https://api2.prismacloud.io
- url: https://api3.prismacloud.io
- url: https://api4.prismacloud.io
tags:
- description: Manage your Prisma Cloud user roles.
  name: User Roles
paths:
  /user/role:
    get:
      description: Returns an array of user roles.
      operationId: get-user-roles
      responses:
        '200':
          content:
            application/json:
              schema:
                items:
                  $ref: '#/components/schemas/UserRoleViewModel'
                type: array
          description: successful operation
        '403':
          description: unauthorized_access
        '500':
          description: internal_error
      security:
      - x-redlock-auth: []
      summary: List User Roles
      tags:
      - User Roles
    post:
      description: 'Creates a new user role.


        See Prisma Cloud Administrator Permissions

        for the permissions associated with each role.


        Note that the request body parameter **accountGroupIds** is required but can be an empty array.'
      operationId: add-user-role
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UserRoleModel'
        description: User Role
        required: true
      responses:
        '200':
          description: successful operation
        '400':
          description: invalid_user_role_name / invalid_user_role_type / invalid_account_group_ids / user_role_name_already_exists
        '403':
          description: unauthorized_access
        '500':
          description: internal_error
      security:
      - x-redlock-auth: []
      summary: Add User Role
      tags:
      - User Roles
  /user/role/name:
    get:
      description: Returns list of user role IDs and names.
      operationId: get-user-role-name
      responses:
        '200':
          content:
            application/json:
              schema:
                items:
                  additionalProperties:
                    type: string
                  type: object
                type: array
          description: successful operation
        '403':
          description: unauthorized_access
        '500':
          description: internal_error
      security:
      - x-redlock-auth: []
      summary: List User Role Names
      tags:
      - User Roles
  /user/role/type:
    get:
      description: Returns a list of permission groups to which users can belong.
      operationId: get-user-role-types
      responses:
        '200':
          content:
            application/json:
              schema:
                items:
                  enum:
                  - SYSTEM_ADMIN
                  - ACCOUNT_ADMIN
                  - ACCOUNT_READ_ONLY
                  - SSO_ADMIN
                  - CLOUD_PROVISIONING_ADMIN
                  - TENANT_PROVISIONING_ADMIN
                  - PRISMA_SERVICE_USER
                  - ACCOUNT_AND_CLOUD_PROVISIONING_ADMIN
                  - BUILD_AND_DEPLOY_SECURITY
                  - BUILD_AND_DEPLOY_SECURITY_CI
                  - COMPUTE_ADMIN
                  - NETWORK_SECURITY_OPERATOR
                  - NETWORK_SECURITY_OPERATOR_READ_ONLY
                  - COMPUTE_ACCOUNT_ADMIN
                  - DEVELOPER
                  - COMPUTE_ACCOUNT_READ_ONLY
                  type: string
                type: array
          description: successful operation
      security:
      - x-redlock-auth: []
      summary: List User Role Types
      tags:
      - User Roles
  /user/role/{id}:
    get:
      description: Returns user role information for a specified ID.
      operationId: get-user-role
      parameters:
      - description: User Role ID
        in: path
        name: id
        required: true
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UserRoleViewModel'
          description: successful operation
        '400':
          description: invalid_id
        '403':
          description: unauthorized_access
        '500':
          description: internal_error
      security:
      - x-redlock-auth: []
      summary: User Role Info
      tags:
      - User Roles
    put:
      description: Updates information for an existing user role.
      operationId: update-user-role
      parameters:
      - description: User Role ID
        in: path
        name: id
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UserRoleModel'
        description: User Role
        required: true
      responses:
        '200':
          description: successful operation
        '400':
          description: invalid_id / invalid_user_role_name / invalid_user_role_type / invalid_account_group_ids / user_role_name_already_exists
        '403':
          description: unauthorized_access
        '500':
          description: internal_error
      security:
      - x-redlock-auth: []
      summary: Update User Role
      tags:
      - User Roles
    delete:
      description: Deletes a user role with the specified ID.
      operationId: delete-user-role
      parameters:
      - description: User Role ID
        in: path
        name: id
        required: true
        schema:
          type: string
      responses:
        '200':
          description: successful operation
        '400':
          description: invalid_id / cannot_delete_role_users_associated / invalid_id
        '403':
          description: unauthorized_access
        '500':
          description: internal_error
      security:
      - x-redlock-auth: []
      summary: Delete User Role
      tags:
      - User Roles
components:
  schemas:
    UserRoleViewModel:
      description: Model for User Role View
      properties:
        accountGroupIds:
          description: Accessible Account Group IDs
          items:
            type: string
          type: array
        accountGroups:
          description: Associated Account Groups
          items:
            additionalProperties:
              type: string
            type: object
          readOnly: true
          type: array
        additionalAttributes:
          allOf:
          - $ref: '#/components/schemas/Attributes1'
          - description: Additional attributes of the the user role
        associatedUsers:
          description: Associated application users which cannot exist in the system without the user role
          items:
            type: string
          readOnly: true
          type: array
        codeRepositories:
          description: Associated Code Repositories
          items:
            additionalProperties:
              type: string
            type: object
          readOnly: true
          type: array
        codeRepositoryIds:
          description: Accessible Code Repository IDs
          items:
            type: string
          type: array
        description:
          description: Description
          type: string
        id:
          description: User Role ID
          readOnly: true
          type: string
        lastModifiedBy:
          description: Last Modified By
          readOnly: true
          type: string
        lastModifiedTs:
          description: Last Modified Time
          format: int64
          readOnly: true
          type: integer
        name:
          description: Name
          type: string
        resourceListIds:
          description: Accessible Resource List IDs
          items:
            type: string
          type: array
        resourceLists:
          description: Associated Resource Lists
          items:
            additionalProperties:
              type: string
            type: object
          readOnly: true
          type: array
        restrictDismissalAccess:
          type: boolean
        roleType:
          description: User Role Type (Default or Custom Permission Group Name).
          type: string
      required:
      - name
      - roleType
      type: object
    Attributes1:
      description: Additional attributes of the the user role
      properties:
        hasDefenderPermissions:
          description: User has compute defender permissions
          type: boolean
        onlyAllowCIAccess:
          description: User can only use access keys to use Prisma Cloud. UI access will be unavailable.
          type: boolean
        onlyAllowComputeAccess:
          description: User can only access the Prisma Cloud Compute Console
          type: boolean
      type: object
    UserRoleModel:
      description: Model for User Role
      properties:
        accountGroupIds:
          description: Accessible Account Group IDs
          items:
            type: string
          type: array
        additionalAttributes:
          allOf:
          - $ref: '#/components/schemas/Attributes1'
          - description: Additional attributes of the the user role
        associatedUsers:
          description: Associated application users which cannot exist in the system without the user role
          items:
            type: string
          readOnly: true
          type: array
        codeRepositoryIds:
          description: Accessible Code Repository IDs
          items:
            type: string
          type: array
        description:
          description: Description
          type: string
        id:
          description: User Role ID
          readOnly: true
          type: string
        lastModifiedBy:
          description: Last Modified By
          readOnly: true
          type: string
        lastModifiedTs:
          description: Last Modified Time
          format: int64
          readOnly: true
          type: integer
        name:
          description: Name
          type: string
        resourceListIds:
          description: Accessible Resource List IDs
          items:
            type: string
          type: array
        restrictDismissalAccess:
          type: boolean
        roleType:
          description: User Role Type (Default or Custom Permission Group Name).
          type: string
      required:
      - name
      - roleType
      type: object
  securitySchemes:
    x-redlock-auth:
      description: The x-redlock-auth value is a JSON Web Token (JWT).
      in: header
      name: x-redlock-auth
      type: apiKey