Symantec Authentication API

OAuth 2.0 authentication endpoints

OpenAPI Specification

symantec-authentication-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Symantec Endpoint Protection Manager Administrators Authentication API
  description: The Symantec Endpoint Protection Manager (SEPM) REST API provides programmatic access to manage endpoint protection infrastructure. Enables management of computers (endpoints), groups, policies, server administrators, API versioning, and device lifecycle operations. Authentication uses OAuth 2.0 with username/password credentials via the identity endpoint, returning a Bearer token for subsequent calls.
  version: '14.0'
  contact:
    name: Broadcom Support
    url: https://support.broadcom.com
  termsOfService: https://www.broadcom.com/company/legal/terms-of-use
servers:
- url: https://{sepm-host}:8446/sepm/api/v1
  description: Symantec Endpoint Protection Manager
  variables:
    sepm-host:
      default: localhost
      description: SEPM server hostname or IP address
tags:
- name: Authentication
  description: OAuth 2.0 authentication endpoints
paths:
  /identity/authenticate:
    post:
      operationId: authenticate
      summary: Authenticate to SEPM
      description: Authenticates with SEPM using username, password, and domain credentials. Returns a Bearer token and refresh token for subsequent API calls. Requires SysAdmin role for full API access.
      tags:
      - Authentication
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AuthRequest'
            example:
              username: admin
              password: password123
              domain: ''
      responses:
        '200':
          description: Authentication successful
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuthResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  schemas:
    AuthResponse:
      type: object
      properties:
        token:
          type: string
          description: Bearer token for API authentication
        tokenExpiry:
          type: string
          format: date-time
          description: Token expiration timestamp
        refreshToken:
          type: string
          description: Refresh token for obtaining new access tokens
    AuthRequest:
      type: object
      required:
      - username
      - password
      properties:
        username:
          type: string
          description: SEPM administrator username
        password:
          type: string
          format: password
          description: SEPM administrator password
        domain:
          type: string
          description: Domain name (can be empty string for default domain)
    Error:
      type: object
      properties:
        errorCode:
          type: integer
        errorMessage:
          type: string
  responses:
    Unauthorized:
      description: Unauthorized - missing or expired Bearer token
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    BadRequest:
      description: Bad request - invalid parameters
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: Bearer token obtained from the /identity/authenticate endpoint
externalDocs:
  description: Symantec Endpoint Protection Manager API Documentation
  url: https://techdocs.broadcom.com/us/en/symantec-security-software/endpoint-security-and-management/endpoint-protection/all/APIsSEP/Symantec-Endpoint-Security-API-commands1.html