Palo Alto Networks · JSON Structure

Prisma Airs Api Scan Request Structure

ScanRequest schema from Palo Alto Networks Prisma AIRS API

Type: object Properties: 3 Required: 2
Cloud SecurityCybersecurityFirewallNetwork SecuritySASESOARThreat IntelligenceXDR

ScanRequest is a JSON Structure definition published by Palo Alto Networks, describing 3 properties, of which 2 are required. It conforms to the https://json-structure.org/meta/core/v0/# meta-schema.

Properties

ai_profile contents tr_id

Meta-schema: https://json-structure.org/meta/core/v0/#

JSON Structure

Raw ↑
{
  "$schema": "https://json-structure.org/meta/core/v0/#",
  "$id": "https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/refs/heads/main/json-structure/prisma-airs-api-scan-request-structure.json",
  "name": "ScanRequest",
  "description": "ScanRequest schema from Palo Alto Networks Prisma AIRS API",
  "type": "object",
  "properties": {
    "ai_profile": {
      "type": "object",
      "description": "Reference to the AI security profile to apply during scanning.",
      "properties": {
        "profile_name": {
          "type": "string",
          "description": "Name of the AI security profile to use for this scan. The profile determines which detections are active and their sensitivity. Must reference an existing profile configured for the tenant."
        }
      },
      "required": [
        "profile_name"
      ]
    },
    "contents": {
      "type": "array",
      "description": "Array of prompt/response pairs to scan. Each item represents one LLM interaction. For batch scanning, include multiple items.",
      "items": {
        "type": "object",
        "properties": {
          "prompt": {
            "type": "string",
            "description": "The user prompt or input text sent to the AI model. Evaluated for prompt injection, jailbreak attempts, and other input-side threats.",
            "maxLength": 32000
          },
          "response": {
            "type": "string",
            "description": "The AI model response or output text. When provided, also evaluated for data leakage, toxic content, and other output-side threats. May be omitted to scan only the prompt.",
            "maxLength": 64000
          }
        }
      },
      "minItems": 1
    },
    "tr_id": {
      "type": "string",
      "description": "Optional caller-supplied transaction ID for correlating scan requests with application-side records."
    }
  },
  "required": [
    "ai_profile",
    "contents"
  ]
}