Add address group members
Action ID:tools.pan_strata.add_address_group_members
Add members of a static address group in the candidate configuration. Reads the group by ID or by name with GET /config/objects/v1/address-groups, and writes it with PUT /config/objects/v1/address-groups/{id} only when membership changes, so repeated calls are idempotent. Push the candidate configuration to apply the change.
Reference: https://pan.dev/scm/api/config/ngfw/objects/update-address-groups-by-id/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
array[string]
required
Names of address objects or address groups.
string | null
Address group UUID.Default:
null.string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Address group name. Requires exactly one of folder, snippet, or device. Ignored when address_group_id is set.Default:
null.string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.Block CIDR
Action ID:tools.pan_strata.block_cidr
Block a CIDR range by adding an address object to a static address group referenced by a deny rule. Looks up the address object by name, creates it with POST /config/objects/v1/addresses if missing, then adds it to the group with PUT /config/objects/v1/address-groups/{id} if it is not already a member, so repeated calls do not create duplicates. Changes stay in the candidate configuration; run push_candidate_config to enforce them.
Reference: https://pan.dev/scm/api/config/ngfw/objects/create-addresses/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Static address group that a deny rule references, e.g. tracecat-blocklist.
string
required
IPv4 or IPv6 network in CIDR notation to block, e.g. 198.51.100.0/24.
string | null
Address object name to use instead of the generated name.Default:
null.string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string | null
Description for a newly created address object, e.g. the case ID.Default:
null.string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default:
null.string
Prefix for generated address object names.Default:
"tc-block-".string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.array[string] | null
Tags for a newly created address object.Default:
null.Block FQDN
Action ID:tools.pan_strata.block_fqdn
Block an FQDN by adding an address object to a static address group referenced by a deny rule. Looks up the address object by name, creates it with POST /config/objects/v1/addresses if missing, then adds it to the group with PUT /config/objects/v1/address-groups/{id} if it is not already a member, so repeated calls do not create duplicates. Changes stay in the candidate configuration; run push_candidate_config to enforce them.
Reference: https://pan.dev/scm/api/config/ngfw/objects/create-addresses/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Static address group that a deny rule references, e.g. tracecat-blocklist.
string
required
Fully qualified domain name to block.
string | null
Address object name to use instead of the generated name.Default:
null.string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string | null
Description for a newly created address object, e.g. the case ID.Default:
null.string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default:
null.string
Prefix for generated address object names.Default:
"tc-block-".string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.array[string] | null
Tags for a newly created address object.Default:
null.Block IP
Action ID:tools.pan_strata.block_ip
Block an IP address by adding an address object to a static address group referenced by a deny rule. Looks up the address object by name, creates it with POST /config/objects/v1/addresses if missing, then adds it to the group with PUT /config/objects/v1/address-groups/{id} if it is not already a member, so repeated calls do not create duplicates. Changes stay in the candidate configuration; run push_candidate_config to enforce them.
Reference: https://pan.dev/scm/api/config/ngfw/objects/create-addresses/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Static address group that a deny rule references, e.g. tracecat-blocklist.
string
required
IPv4 or IPv6 address to block.
string | null
Address object name to use instead of the generated name.Default:
null.string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string | null
Description for a newly created address object, e.g. the case ID.Default:
null.string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default:
null.string
Prefix for generated address object names.Default:
"tc-block-".string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.array[string] | null
Tags for a newly created address object.Default:
null.Create address
Action ID:tools.pan_strata.create_address
Create an address object in the candidate configuration with POST /config/objects/v1/addresses. Provide exactly one of ip_netmask, ip_range, ip_wildcard, or fqdn. Push the candidate configuration to apply the change.
Reference: https://pan.dev/scm/api/config/ngfw/objects/create-addresses/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Address object name (max 63 characters).
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string | null
Address object description.Default:
null.string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Fully qualified domain name, e.g. malicious.example.com.Default:
null.string | null
IP address with or without CIDR mask, e.g. 203.0.113.10 or 10.0.0.0/24.Default:
null.string | null
IP range, e.g. 10.0.0.1-10.0.0.20.Default:
null.string | null
IP wildcard mask, e.g. 10.20.1.0/0.0.248.255.Default:
null.string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.array[string] | null
Tags to apply. Tags must already exist in the container.Default:
null.Create address group
Action ID:tools.pan_strata.create_address_group
Create a static or dynamic address group in the candidate configuration with POST /config/objects/v1/address-groups. Provide exactly one of static_members or dynamic_filter. Push the candidate configuration to apply the change.
Reference: https://pan.dev/scm/api/config/ngfw/objects/create-address-groups/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Address group name (max 63 characters).
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string | null
Address group description.Default:
null.string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Tag filter for a dynamic group, e.g. ‘quarantine’ or ‘malicious’ and ‘external’.Default:
null.string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.array[string] | null
Names of address objects or groups for a static group.Default:
null.array[string] | null
Tags to apply to the group.Default:
null.Create security rule
Action ID:tools.pan_strata.create_security_rule
Create a security rule in the candidate configuration with POST /config/security/v1/security-rules?position=. The rule is added at the bottom of the rulebase; use move_security_rule to place it. Push the candidate configuration to apply the change.
Reference: https://pan.dev/scm/api/config/ngfw/security/create-security-rules/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Action to take when the rule matches. Allowed values: allow, deny, drop, reset-client, reset-server, reset-both.
string
required
Security rule name.
array[string]
Applications. Defaults to any.Default:
[ "any" ].string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.array[string]
URL categories. Defaults to any.Default:
[ "any" ].string | null
Rule description.Default:
null.array[string]
Destination addresses, address groups, or EDLs. Defaults to any.Default:
[ "any" ].string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.boolean
Create the rule disabled.Default:
false.object | null
Additional API-native rule fields, e.g. negate_source or schedule.Default:
null.string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default:
null.array[string]
Source zones. Defaults to any.Default:
[ "any" ].string | null
Log forwarding profile.Default:
null.string
Rulebase position of the rule. Allowed values: pre, post.Default:
"pre".string | null
Security profile group to attach.Default:
null.array[string]
Services, e.g. application-default or any. Defaults to any.Default:
[ "any" ].string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.array[string]
Source addresses, address groups, or EDLs. Defaults to any.Default:
[ "any" ].array[string]
Source users or groups. Defaults to any.Default:
[ "any" ].array[string] | null
Tags to apply to the rule.Default:
null.array[string]
Destination zones. Defaults to any.Default:
[ "any" ].Create tag
Action ID:tools.pan_strata.create_tag
Create a tag in the candidate configuration with POST /config/objects/v1/tags. Tags drive dynamic address group membership. Push the candidate configuration to apply the change.
Reference: https://pan.dev/scm/api/config/ngfw/objects/create-tags/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Tag name (max 127 characters).
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string | null
Tag color name, e.g. Red or Orange.Default:
null.string | null
Tag comments.Default:
null.string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.Delete address
Action ID:tools.pan_strata.delete_address
Delete a address object from the candidate configuration with DELETE /config/objects/v1/addresses/{id}. Push the candidate configuration to apply the change.
Reference: https://pan.dev/scm/api/config/ngfw/objects/delete-addresses-by-id/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Address object UUID.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.Delete address group
Action ID:tools.pan_strata.delete_address_group
Delete a address group from the candidate configuration with DELETE /config/objects/v1/address-groups/{id}. Push the candidate configuration to apply the change.
Reference: https://pan.dev/scm/api/config/ngfw/objects/delete-address-groups-by-id/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Address group UUID.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.Delete security rule
Action ID:tools.pan_strata.delete_security_rule
Delete a security rule from the candidate configuration with DELETE /config/security/v1/security-rules/{id}. Push the candidate configuration to apply the change.
Reference: https://pan.dev/scm/api/config/ngfw/security/delete-security-rules-by-id/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Security rule UUID.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string
Rulebase position of the rule. Allowed values: pre, post.Default:
"pre".Disable security rule
Action ID:tools.pan_strata.disable_security_rule
Disable a security rule in the candidate configuration. Reads it with GET /config/security/v1/security-rules/{id} and writes it with PUT /config/security/v1/security-rules/{id} only when the state changes, so repeated calls are idempotent. Push the candidate configuration to apply the change.
Reference: https://pan.dev/scm/api/config/ngfw/security/update-security-rules-by-id/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Security rule UUID.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string
Rulebase position of the rule. Allowed values: pre, post.Default:
"pre".Enable security rule
Action ID:tools.pan_strata.enable_security_rule
Enable a security rule in the candidate configuration. Reads it with GET /config/security/v1/security-rules/{id} and writes it with PUT /config/security/v1/security-rules/{id} only when the state changes, so repeated calls are idempotent. Push the candidate configuration to apply the change.
Reference: https://pan.dev/scm/api/config/ngfw/security/update-security-rules-by-id/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Security rule UUID.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string
Rulebase position of the rule. Allowed values: pre, post.Default:
"pre".Get address
Action ID:tools.pan_strata.get_address
Get a address object by ID with GET /config/objects/v1/addresses/{id}, or by name and container with GET /config/objects/v1/addresses?name=.
Reference: https://pan.dev/scm/api/config/ngfw/objects/get-addresses-by-id/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string | null
Address object UUID.Default:
null.string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Name of the address object. Requires exactly one of folder, snippet, or device. Ignored when the ID is set.Default:
null.string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.Get address group
Action ID:tools.pan_strata.get_address_group
Get a address group by ID with GET /config/objects/v1/address-groups/{id}, or by name and container with GET /config/objects/v1/address-groups?name=.
Reference: https://pan.dev/scm/api/config/ngfw/objects/get-address-groups-by-id/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string | null
Address group UUID.Default:
null.string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Name of the address group. Requires exactly one of folder, snippet, or device. Ignored when the ID is set.Default:
null.string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.Get device
Action ID:tools.pan_strata.get_device
Get a device onboarded to Strata Cloud Manager with GET /config/setup/v1/devices/{id}.
Reference: https://pan.dev/scm/api/config/ngfw/setup/get-device-by-id/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Device ID (serial number).
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.Get incident
Action ID:tools.pan_strata.get_incident
Get the details of a Strata Cloud Manager incident with GET /incidents/v1/details/{incident-id}.
Reference: https://pan.dev/scm/api/config/incidents/get-incident-details/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Incident ID.
string
required
Tenant region sent as the X-PANW-Region header, e.g. americas, europe, uk, or au.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.Get job
Action ID:tools.pan_strata.get_job
Get a configuration job with GET /config/operations/v1/jobs/{id}. Returns normalized status, result, done, and succeeded fields along with the raw job.
Reference: https://pan.dev/scm/api/config/ngfw/operations/get-jobs-by-id/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Job ID, e.g. the job_id returned by push_candidate_config.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.Get security rule
Action ID:tools.pan_strata.get_security_rule
Get a security rule by ID with GET /config/security/v1/security-rules/{id}, or by name and container with GET /config/security/v1/security-rules?name=.
Reference: https://pan.dev/scm/api/config/ngfw/security/get-security-rules-by-id/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Name of the security rule. Requires exactly one of folder, snippet, or device. Ignored when the ID is set.Default:
null.string
Rulebase position of the rule. Allowed values: pre, post.Default:
"pre".string | null
Security rule UUID.Default:
null.string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.List address groups
Action ID:tools.pan_strata.list_address_groups
List address groups. Calls GET /config/objects/v1/address-groups directly; page with limit and offset.
Reference: https://pan.dev/scm/api/config/ngfw/objects/list-address-groups/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default:
null.integer | null
Maximum number of results per page. SCM defaults to 200.Default:
null.integer | null
Number of results to skip before the first returned result. Use the response’s total to page.Default:
null.string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.List addresses
Action ID:tools.pan_strata.list_addresses
List address objects. Calls GET /config/objects/v1/addresses directly; page with limit and offset.
Reference: https://pan.dev/scm/api/config/ngfw/objects/list-addresses/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default:
null.integer | null
Maximum number of results per page. SCM defaults to 200.Default:
null.integer | null
Number of results to skip before the first returned result. Use the response’s total to page.Default:
null.string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.List devices
Action ID:tools.pan_strata.list_devices
List devices onboarded to Strata Cloud Manager. Calls GET /config/setup/v1/devices directly; page with limit and offset.
Reference: https://pan.dev/scm/api/config/ngfw/setup/list-devices/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.integer | null
Maximum number of results per page. SCM defaults to 200.Default:
null.integer | null
Number of results to skip before the first returned result. Use the response’s total to page.Default:
null.List external dynamic lists
Action ID:tools.pan_strata.list_external_dynamic_lists
List external dynamic lists. Calls GET /config/objects/v1/external-dynamic-lists directly; page with limit and offset.
Reference: https://pan.dev/scm/api/config/ngfw/objects/list-external-dynamic-lists/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default:
null.integer | null
Maximum number of results per page. SCM defaults to 200.Default:
null.integer | null
Number of results to skip before the first returned result. Use the response’s total to page.Default:
null.string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.List folders
Action ID:tools.pan_strata.list_folders
List folders. Calls GET /config/setup/v1/folders directly; page with limit and offset.
Reference: https://pan.dev/scm/api/config/ngfw/setup/list-folders/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.integer | null
Maximum number of results per page. SCM defaults to 200.Default:
null.integer | null
Number of results to skip before the first returned result. Use the response’s total to page.Default:
null.List jobs
Action ID:tools.pan_strata.list_jobs
List configuration jobs. Calls GET /config/operations/v1/jobs directly; page with limit and offset.
Reference: https://pan.dev/scm/api/config/ngfw/operations/list-jobs/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.integer | null
Maximum number of results per page. SCM defaults to 200.Default:
null.integer | null
Number of results to skip before the first returned result. Use the response’s total to page.Default:
null.List quarantined devices
Action ID:tools.pan_strata.list_quarantined_devices
List GlobalProtect devices on the quarantine list with GET /config/objects/v1/quarantined-devices, optionally filtered by host ID or serial number.
Reference: https://pan.dev/scm/api/config/ngfw/objects/list-quarantined-devices/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string | null
Filter by device host ID.Default:
null.string | null
Filter by device serial number.Default:
null.List security rules
Action ID:tools.pan_strata.list_security_rules
List security rules. Calls GET /config/security/v1/security-rules directly; page with limit and offset.
Reference: https://pan.dev/scm/api/config/ngfw/security/list-rules/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default:
null.integer | null
Maximum number of results per page. SCM defaults to 200.Default:
null.integer | null
Number of results to skip before the first returned result. Use the response’s total to page.Default:
null.string
Rulebase position of the rule. Allowed values: pre, post.Default:
"pre".string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.List snippets
Action ID:tools.pan_strata.list_snippets
List snippets. Calls GET /config/setup/v1/snippets directly; page with limit and offset.
Reference: https://pan.dev/scm/api/config/ngfw/setup/list-snippets/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.integer | null
Maximum number of results per page. SCM defaults to 200.Default:
null.integer | null
Number of results to skip before the first returned result. Use the response’s total to page.Default:
null.List tags
Action ID:tools.pan_strata.list_tags
List tags. Calls GET /config/objects/v1/tags directly; page with limit and offset.
Reference: https://pan.dev/scm/api/config/ngfw/objects/list-tags/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default:
null.integer | null
Maximum number of results per page. SCM defaults to 200.Default:
null.integer | null
Number of results to skip before the first returned result. Use the response’s total to page.Default:
null.string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.Move security rule
Action ID:tools.pan_strata.move_security_rule
Move a security rule within its rulebase with POST /config/security/v1/security-rules/{id}:move. Push the candidate configuration to apply the change.
Reference: https://pan.dev/scm/api/config/ngfw/security/move-security-rules-by-id/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Where to move the rule. Allowed values: top, bottom, before, after.
string
required
Security rule UUID.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string | null
UUID of the reference rule. Required when destination is before or after.Default:
null.string
Rulebase of the rule. Allowed values: pre, post.Default:
"pre".Push candidate configuration
Action ID:tools.pan_strata.push_candidate_config
Push the candidate configuration of one or more folders to devices with POST /config/operations/v1/config-versions/candidate:push. Returns the job ID; use wait_for_job to wait for completion. Put this behind an approval step in containment workflows.
Reference: https://pan.dev/scm/api/config/ngfw/operations/push-candidate-config-versions/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
array[string]
required
Folders to push, e.g. [“All Firewalls”] or [“Mobile Users”, “Remote Networks”].
array[string] | null
Push only changes made by these administrators or service accounts, e.g. the client ID of this integration. Omit to push all changes in the folders.Default:
null.string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string | null
Description of the change, e.g. the case or incident ID.Default:
null.Quarantine device
Action ID:tools.pan_strata.create_quarantined_device
Add a GlobalProtect device to the quarantine list with POST /config/objects/v1/quarantined-devices. Quarantined devices can be blocked by security rules that match the quarantine list.
Reference: https://pan.dev/scm/api/config/ngfw/objects/create-quarantined-devices/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Device host ID.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string | null
Device serial number.Default:
null.Remove address group members
Action ID:tools.pan_strata.remove_address_group_members
Remove members of a static address group in the candidate configuration. Reads the group by ID or by name with GET /config/objects/v1/address-groups, and writes it with PUT /config/objects/v1/address-groups/{id} only when membership changes, so repeated calls are idempotent. Push the candidate configuration to apply the change.
Reference: https://pan.dev/scm/api/config/ngfw/objects/update-address-groups-by-id/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
array[string]
required
Names of address objects or address groups.
string | null
Address group UUID.Default:
null.string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Address group name. Requires exactly one of folder, snippet, or device. Ignored when address_group_id is set.Default:
null.string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.Remove device from quarantine
Action ID:tools.pan_strata.delete_quarantined_device
Remove a GlobalProtect device from the quarantine list with DELETE /config/objects/v1/quarantined-devices?host_id=.
Reference: https://pan.dev/scm/api/config/ngfw/objects/delete-quarantined-devices/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Device host ID.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.Search incidents
Action ID:tools.pan_strata.search_incidents
Search Strata Cloud Manager incidents with POST /incidents/v1/search. Filter rules use property, operator, and values, e.g. {“property”: “status”, “operator”: “in”, “values”: [“Raised”]}.
Reference: https://pan.dev/scm/api/config/incidents/search-incidents/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Tenant region sent as the X-PANW-Region header, e.g. americas, europe, uk, or au.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.array[object] | null
Filter rules with property, operator, and values.Default:
null.array[object] | null
Sort order, e.g. [{“property”: “updated_time”, “order”: “desc”}].Default:
null.integer
Page number, starting at 1.Default:
1.integer
Number of incidents per page.Default:
25.Unblock FQDN
Action ID:tools.pan_strata.unblock_fqdn
Unblock an FQDN blocked with the matching block action. Removes the address object from the static address group with PUT /config/objects/v1/address-groups/{id} if it is a member, then deletes the address object with DELETE /config/objects/v1/addresses/{id} if it exists. Repeated calls are no-ops. Changes stay in the candidate configuration; run push_candidate_config to enforce them.
Reference: https://pan.dev/scm/api/config/ngfw/objects/update-address-groups-by-id/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Static address group that a deny rule references, e.g. tracecat-blocklist.
string
required
Fully qualified domain name to unblock.
string | null
Address object name to use instead of the generated name.Default:
null.string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.boolean
Delete the address object after removing it from the group. Fails if other rules or groups still reference it.Default:
true.string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default:
null.string
Prefix for generated address object names.Default:
"tc-block-".string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.Unblock IP
Action ID:tools.pan_strata.unblock_ip
Unblock an IP address or CIDR range blocked with the matching block action. Removes the address object from the static address group with PUT /config/objects/v1/address-groups/{id} if it is a member, then deletes the address object with DELETE /config/objects/v1/addresses/{id} if it exists. Repeated calls are no-ops. Changes stay in the candidate configuration; run push_candidate_config to enforce them.
Reference: https://pan.dev/scm/api/config/ngfw/objects/update-address-groups-by-id/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Static address group that a deny rule references, e.g. tracecat-blocklist.
string
required
IPv4 or IPv6 address, or CIDR range, to unblock.
string | null
Address object name to use instead of the generated name.Default:
null.string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.boolean
Delete the address object after removing it from the group. Fails if other rules or groups still reference it.Default:
true.string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default:
null.string
Prefix for generated address object names.Default:
"tc-block-".string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default:
null.Update address
Action ID:tools.pan_strata.update_address
Update an address object in the candidate configuration. Reads it with GET /config/objects/v1/addresses/{id}, applies only the provided fields, and writes it with PUT /config/objects/v1/addresses/{id}. Push the candidate configuration to apply the change.
Reference: https://pan.dev/scm/api/config/ngfw/objects/update-addresses-by-id/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Address object UUID.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string | null
New description.Default:
null.string | null
Fully qualified domain name, e.g. malicious.example.com.Default:
null.string | null
IP address with or without CIDR mask, e.g. 203.0.113.10 or 10.0.0.0/24.Default:
null.string | null
IP range, e.g. 10.0.0.1-10.0.0.20.Default:
null.string | null
IP wildcard mask, e.g. 10.20.1.0/0.0.248.255.Default:
null.string | null
New name.Default:
null.array[string] | null
Replacement tag list.Default:
null.Update address group
Action ID:tools.pan_strata.update_address_group
Update an address group in the candidate configuration. Reads it with GET /config/objects/v1/address-groups/{id}, applies only the provided fields, and writes it with PUT /config/objects/v1/address-groups/{id}. static_members replaces the whole member list; use add_address_group_members or remove_address_group_members for incremental changes.
Reference: https://pan.dev/scm/api/config/ngfw/objects/update-address-groups-by-id/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Address group UUID.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string | null
New description.Default:
null.string | null
Tag filter for a dynamic group, e.g. ‘quarantine’ or ‘malicious’ and ‘external’.Default:
null.string | null
New name.Default:
null.array[string] | null
Names of address objects or groups for a static group.Default:
null.array[string] | null
Replacement tag list.Default:
null.Update security rule
Action ID:tools.pan_strata.update_security_rule
Update a security rule in the candidate configuration. Reads it with GET /config/security/v1/security-rules/{id}, merges the provided API-native fields, and writes it with PUT /config/security/v1/security-rules/{id}. Push the candidate configuration to apply the change.
Reference: https://pan.dev/scm/api/config/ngfw/security/update-security-rules-by-id/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Security rule UUID.
object
required
API-native fields to replace, e.g. {“action”: “deny”, “source”: [“blocked-ips”]}.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.string
Rulebase position of the rule. Allowed values: pre, post.Default:
"pre".Wait for job
Action ID:tools.pan_strata.wait_for_job
Poll GET /config/operations/v1/jobs/{id} until the job finishes, then return normalized status, result, done, and succeeded fields. Fails when the job fails, unless raise_on_failure is false, or when it does not finish within poll_max_attempts.
Reference: https://pan.dev/scm/api/config/ngfw/operations/get-jobs-by-id/
Secrets
Required secrets:pan_strata_oauth: OAuth tokenPAN_STRATA_SERVICE_TOKEN.
Input fields
string
required
Job ID, e.g. the job_id returned by push_candidate_config.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default:
null.number
Seconds between polls.Default:
10.integer
Maximum number of polls.Default:
60.boolean
Fail the action when the job finishes unsuccessfully.Default:
true.