> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tracecat.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Palo Alto Networks (Strata Cloud Manager)

> Reference for the Tracecat Palo Alto Networks (Strata Cloud Manager) integration: registered actions, required secrets, expected inputs, and example workflow usage.

## Add address group members

Action ID: `tools.pan_strata.add_address_group_members`

Add members of a static address group in the candidate configuration. Reads the group by ID or by name with GET /config/objects/v1/address-groups, and writes it with PUT /config/objects/v1/address-groups/\{id} only when membership changes, so repeated calls are idempotent. Push the candidate configuration to apply the change.

Reference: [https://pan.dev/scm/api/config/ngfw/objects/update-address-groups-by-id/](https://pan.dev/scm/api/config/ngfw/objects/update-address-groups-by-id/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="members" type="array[string]" required>
  Names of address objects or address groups.
</ParamField>

<ParamField path="address_group_id" type="string | null">
  Address group UUID.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="device" type="string | null">
  Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="folder" type="string | null">
  Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="name" type="string | null">
  Address group name. Requires exactly one of folder, snippet, or device. Ignored when address\_group\_id is set.

  Default: `null`.
</ParamField>

<ParamField path="snippet" type="string | null">
  Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

## Block CIDR

Action ID: `tools.pan_strata.block_cidr`

Block a CIDR range by adding an address object to a static address group referenced by a deny rule. Looks up the address object by name, creates it with POST /config/objects/v1/addresses if missing, then adds it to the group with PUT /config/objects/v1/address-groups/\{id} if it is not already a member, so repeated calls do not create duplicates. Changes stay in the candidate configuration; run push\_candidate\_config to enforce them.

Reference: [https://pan.dev/scm/api/config/ngfw/objects/create-addresses/](https://pan.dev/scm/api/config/ngfw/objects/create-addresses/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="address_group" type="string" required>
  Static address group that a deny rule references, e.g. tracecat-blocklist.
</ParamField>

<ParamField path="value" type="string" required>
  IPv4 or IPv6 network in CIDR notation to block, e.g. 198.51.100.0/24.
</ParamField>

<ParamField path="address_name" type="string | null">
  Address object name to use instead of the generated name.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="description" type="string | null">
  Description for a newly created address object, e.g. the case ID.

  Default: `null`.
</ParamField>

<ParamField path="device" type="string | null">
  Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="folder" type="string | null">
  Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="name_prefix" type="string">
  Prefix for generated address object names.

  Default: `"tc-block-"`.
</ParamField>

<ParamField path="snippet" type="string | null">
  Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="tags" type="array[string] | null">
  Tags for a newly created address object.

  Default: `null`.
</ParamField>

## Block FQDN

Action ID: `tools.pan_strata.block_fqdn`

Block an FQDN by adding an address object to a static address group referenced by a deny rule. Looks up the address object by name, creates it with POST /config/objects/v1/addresses if missing, then adds it to the group with PUT /config/objects/v1/address-groups/\{id} if it is not already a member, so repeated calls do not create duplicates. Changes stay in the candidate configuration; run push\_candidate\_config to enforce them.

Reference: [https://pan.dev/scm/api/config/ngfw/objects/create-addresses/](https://pan.dev/scm/api/config/ngfw/objects/create-addresses/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="address_group" type="string" required>
  Static address group that a deny rule references, e.g. tracecat-blocklist.
</ParamField>

<ParamField path="value" type="string" required>
  Fully qualified domain name to block.
</ParamField>

<ParamField path="address_name" type="string | null">
  Address object name to use instead of the generated name.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="description" type="string | null">
  Description for a newly created address object, e.g. the case ID.

  Default: `null`.
</ParamField>

<ParamField path="device" type="string | null">
  Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="folder" type="string | null">
  Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="name_prefix" type="string">
  Prefix for generated address object names.

  Default: `"tc-block-"`.
</ParamField>

<ParamField path="snippet" type="string | null">
  Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="tags" type="array[string] | null">
  Tags for a newly created address object.

  Default: `null`.
</ParamField>

## Block IP

Action ID: `tools.pan_strata.block_ip`

Block an IP address by adding an address object to a static address group referenced by a deny rule. Looks up the address object by name, creates it with POST /config/objects/v1/addresses if missing, then adds it to the group with PUT /config/objects/v1/address-groups/\{id} if it is not already a member, so repeated calls do not create duplicates. Changes stay in the candidate configuration; run push\_candidate\_config to enforce them.

Reference: [https://pan.dev/scm/api/config/ngfw/objects/create-addresses/](https://pan.dev/scm/api/config/ngfw/objects/create-addresses/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="address_group" type="string" required>
  Static address group that a deny rule references, e.g. tracecat-blocklist.
</ParamField>

<ParamField path="value" type="string" required>
  IPv4 or IPv6 address to block.
</ParamField>

<ParamField path="address_name" type="string | null">
  Address object name to use instead of the generated name.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="description" type="string | null">
  Description for a newly created address object, e.g. the case ID.

  Default: `null`.
</ParamField>

<ParamField path="device" type="string | null">
  Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="folder" type="string | null">
  Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="name_prefix" type="string">
  Prefix for generated address object names.

  Default: `"tc-block-"`.
</ParamField>

<ParamField path="snippet" type="string | null">
  Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="tags" type="array[string] | null">
  Tags for a newly created address object.

  Default: `null`.
</ParamField>

## Create address

Action ID: `tools.pan_strata.create_address`

Create an address object in the candidate configuration with POST /config/objects/v1/addresses. Provide exactly one of ip\_netmask, ip\_range, ip\_wildcard, or fqdn. Push the candidate configuration to apply the change.

Reference: [https://pan.dev/scm/api/config/ngfw/objects/create-addresses/](https://pan.dev/scm/api/config/ngfw/objects/create-addresses/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="name" type="string" required>
  Address object name (max 63 characters).
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="description" type="string | null">
  Address object description.

  Default: `null`.
</ParamField>

<ParamField path="device" type="string | null">
  Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="folder" type="string | null">
  Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="fqdn" type="string | null">
  Fully qualified domain name, e.g. malicious.example.com.

  Default: `null`.
</ParamField>

<ParamField path="ip_netmask" type="string | null">
  IP address with or without CIDR mask, e.g. 203.0.113.10 or 10.0.0.0/24.

  Default: `null`.
</ParamField>

<ParamField path="ip_range" type="string | null">
  IP range, e.g. 10.0.0.1-10.0.0.20.

  Default: `null`.
</ParamField>

<ParamField path="ip_wildcard" type="string | null">
  IP wildcard mask, e.g. 10.20.1.0/0.0.248.255.

  Default: `null`.
</ParamField>

<ParamField path="snippet" type="string | null">
  Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="tags" type="array[string] | null">
  Tags to apply. Tags must already exist in the container.

  Default: `null`.
</ParamField>

## Create address group

Action ID: `tools.pan_strata.create_address_group`

Create a static or dynamic address group in the candidate configuration with POST /config/objects/v1/address-groups. Provide exactly one of static\_members or dynamic\_filter. Push the candidate configuration to apply the change.

Reference: [https://pan.dev/scm/api/config/ngfw/objects/create-address-groups/](https://pan.dev/scm/api/config/ngfw/objects/create-address-groups/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="name" type="string" required>
  Address group name (max 63 characters).
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="description" type="string | null">
  Address group description.

  Default: `null`.
</ParamField>

<ParamField path="device" type="string | null">
  Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="dynamic_filter" type="string | null">
  Tag filter for a dynamic group, e.g. 'quarantine' or 'malicious' and 'external'.

  Default: `null`.
</ParamField>

<ParamField path="folder" type="string | null">
  Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="snippet" type="string | null">
  Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="static_members" type="array[string] | null">
  Names of address objects or groups for a static group.

  Default: `null`.
</ParamField>

<ParamField path="tags" type="array[string] | null">
  Tags to apply to the group.

  Default: `null`.
</ParamField>

## Create security rule

Action ID: `tools.pan_strata.create_security_rule`

Create a security rule in the candidate configuration with POST /config/security/v1/security-rules?position=. The rule is added at the bottom of the rulebase; use move\_security\_rule to place it. Push the candidate configuration to apply the change.

Reference: [https://pan.dev/scm/api/config/ngfw/security/create-security-rules/](https://pan.dev/scm/api/config/ngfw/security/create-security-rules/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="action" type="string" required>
  Action to take when the rule matches. Allowed values: allow, deny, drop, reset-client, reset-server, reset-both.
</ParamField>

<ParamField path="name" type="string" required>
  Security rule name.
</ParamField>

<ParamField path="application" type="array[string]">
  Applications. Defaults to any.

  Default: `[
      "any"
    ]`.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="category" type="array[string]">
  URL categories. Defaults to any.

  Default: `[
      "any"
    ]`.
</ParamField>

<ParamField path="description" type="string | null">
  Rule description.

  Default: `null`.
</ParamField>

<ParamField path="destination" type="array[string]">
  Destination addresses, address groups, or EDLs. Defaults to any.

  Default: `[
      "any"
    ]`.
</ParamField>

<ParamField path="device" type="string | null">
  Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="disabled" type="boolean">
  Create the rule disabled.

  Default: `false`.
</ParamField>

<ParamField path="extra_fields" type="object | null">
  Additional API-native rule fields, e.g. negate\_source or schedule.

  Default: `null`.
</ParamField>

<ParamField path="folder" type="string | null">
  Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="from_zones" type="array[string]">
  Source zones. Defaults to any.

  Default: `[
      "any"
    ]`.
</ParamField>

<ParamField path="log_setting" type="string | null">
  Log forwarding profile.

  Default: `null`.
</ParamField>

<ParamField path="position" type="string">
  Rulebase position of the rule. Allowed values: pre, post.

  Default: `"pre"`.
</ParamField>

<ParamField path="profile_group" type="string | null">
  Security profile group to attach.

  Default: `null`.
</ParamField>

<ParamField path="service" type="array[string]">
  Services, e.g. application-default or any. Defaults to any.

  Default: `[
      "any"
    ]`.
</ParamField>

<ParamField path="snippet" type="string | null">
  Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="source" type="array[string]">
  Source addresses, address groups, or EDLs. Defaults to any.

  Default: `[
      "any"
    ]`.
</ParamField>

<ParamField path="source_user" type="array[string]">
  Source users or groups. Defaults to any.

  Default: `[
      "any"
    ]`.
</ParamField>

<ParamField path="tags" type="array[string] | null">
  Tags to apply to the rule.

  Default: `null`.
</ParamField>

<ParamField path="to_zones" type="array[string]">
  Destination zones. Defaults to any.

  Default: `[
      "any"
    ]`.
</ParamField>

## Create tag

Action ID: `tools.pan_strata.create_tag`

Create a tag in the candidate configuration with POST /config/objects/v1/tags. Tags drive dynamic address group membership. Push the candidate configuration to apply the change.

Reference: [https://pan.dev/scm/api/config/ngfw/objects/create-tags/](https://pan.dev/scm/api/config/ngfw/objects/create-tags/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="name" type="string" required>
  Tag name (max 127 characters).
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="color" type="string | null">
  Tag color name, e.g. Red or Orange.

  Default: `null`.
</ParamField>

<ParamField path="comments" type="string | null">
  Tag comments.

  Default: `null`.
</ParamField>

<ParamField path="device" type="string | null">
  Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="folder" type="string | null">
  Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="snippet" type="string | null">
  Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

## Delete address

Action ID: `tools.pan_strata.delete_address`

Delete a address object from the candidate configuration with DELETE /config/objects/v1/addresses/\{id}. Push the candidate configuration to apply the change.

Reference: [https://pan.dev/scm/api/config/ngfw/objects/delete-addresses-by-id/](https://pan.dev/scm/api/config/ngfw/objects/delete-addresses-by-id/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="address_id" type="string" required>
  Address object UUID.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

## Delete address group

Action ID: `tools.pan_strata.delete_address_group`

Delete a address group from the candidate configuration with DELETE /config/objects/v1/address-groups/\{id}. Push the candidate configuration to apply the change.

Reference: [https://pan.dev/scm/api/config/ngfw/objects/delete-address-groups-by-id/](https://pan.dev/scm/api/config/ngfw/objects/delete-address-groups-by-id/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="address_group_id" type="string" required>
  Address group UUID.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

## Delete security rule

Action ID: `tools.pan_strata.delete_security_rule`

Delete a security rule from the candidate configuration with DELETE /config/security/v1/security-rules/\{id}. Push the candidate configuration to apply the change.

Reference: [https://pan.dev/scm/api/config/ngfw/security/delete-security-rules-by-id/](https://pan.dev/scm/api/config/ngfw/security/delete-security-rules-by-id/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="rule_id" type="string" required>
  Security rule UUID.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="position" type="string">
  Rulebase position of the rule. Allowed values: pre, post.

  Default: `"pre"`.
</ParamField>

## Disable security rule

Action ID: `tools.pan_strata.disable_security_rule`

Disable a security rule in the candidate configuration. Reads it with GET /config/security/v1/security-rules/\{id} and writes it with PUT /config/security/v1/security-rules/\{id} only when the state changes, so repeated calls are idempotent. Push the candidate configuration to apply the change.

Reference: [https://pan.dev/scm/api/config/ngfw/security/update-security-rules-by-id/](https://pan.dev/scm/api/config/ngfw/security/update-security-rules-by-id/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="rule_id" type="string" required>
  Security rule UUID.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="position" type="string">
  Rulebase position of the rule. Allowed values: pre, post.

  Default: `"pre"`.
</ParamField>

## Enable security rule

Action ID: `tools.pan_strata.enable_security_rule`

Enable a security rule in the candidate configuration. Reads it with GET /config/security/v1/security-rules/\{id} and writes it with PUT /config/security/v1/security-rules/\{id} only when the state changes, so repeated calls are idempotent. Push the candidate configuration to apply the change.

Reference: [https://pan.dev/scm/api/config/ngfw/security/update-security-rules-by-id/](https://pan.dev/scm/api/config/ngfw/security/update-security-rules-by-id/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="rule_id" type="string" required>
  Security rule UUID.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="position" type="string">
  Rulebase position of the rule. Allowed values: pre, post.

  Default: `"pre"`.
</ParamField>

## Get address

Action ID: `tools.pan_strata.get_address`

Get a address object by ID with GET /config/objects/v1/addresses/\{id}, or by name and container with GET /config/objects/v1/addresses?name=.

Reference: [https://pan.dev/scm/api/config/ngfw/objects/get-addresses-by-id/](https://pan.dev/scm/api/config/ngfw/objects/get-addresses-by-id/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="address_id" type="string | null">
  Address object UUID.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="device" type="string | null">
  Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="folder" type="string | null">
  Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="name" type="string | null">
  Name of the address object. Requires exactly one of folder, snippet, or device. Ignored when the ID is set.

  Default: `null`.
</ParamField>

<ParamField path="snippet" type="string | null">
  Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

## Get address group

Action ID: `tools.pan_strata.get_address_group`

Get a address group by ID with GET /config/objects/v1/address-groups/\{id}, or by name and container with GET /config/objects/v1/address-groups?name=.

Reference: [https://pan.dev/scm/api/config/ngfw/objects/get-address-groups-by-id/](https://pan.dev/scm/api/config/ngfw/objects/get-address-groups-by-id/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="address_group_id" type="string | null">
  Address group UUID.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="device" type="string | null">
  Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="folder" type="string | null">
  Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="name" type="string | null">
  Name of the address group. Requires exactly one of folder, snippet, or device. Ignored when the ID is set.

  Default: `null`.
</ParamField>

<ParamField path="snippet" type="string | null">
  Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

## Get device

Action ID: `tools.pan_strata.get_device`

Get a device onboarded to Strata Cloud Manager with GET /config/setup/v1/devices/\{id}.

Reference: [https://pan.dev/scm/api/config/ngfw/setup/get-device-by-id/](https://pan.dev/scm/api/config/ngfw/setup/get-device-by-id/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="device_id" type="string" required>
  Device ID (serial number).
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

## Get incident

Action ID: `tools.pan_strata.get_incident`

Get the details of a Strata Cloud Manager incident with GET /incidents/v1/details/\{incident-id}.

Reference: [https://pan.dev/scm/api/config/incidents/get-incident-details/](https://pan.dev/scm/api/config/incidents/get-incident-details/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="incident_id" type="string" required>
  Incident ID.
</ParamField>

<ParamField path="region" type="string" required>
  Tenant region sent as the X-PANW-Region header, e.g. americas, europe, uk, or au.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

## Get job

Action ID: `tools.pan_strata.get_job`

Get a configuration job with GET /config/operations/v1/jobs/\{id}. Returns normalized status, result, done, and succeeded fields along with the raw job.

Reference: [https://pan.dev/scm/api/config/ngfw/operations/get-jobs-by-id/](https://pan.dev/scm/api/config/ngfw/operations/get-jobs-by-id/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="job_id" type="string" required>
  Job ID, e.g. the job\_id returned by push\_candidate\_config.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

## Get security rule

Action ID: `tools.pan_strata.get_security_rule`

Get a security rule by ID with GET /config/security/v1/security-rules/\{id}, or by name and container with GET /config/security/v1/security-rules?name=.

Reference: [https://pan.dev/scm/api/config/ngfw/security/get-security-rules-by-id/](https://pan.dev/scm/api/config/ngfw/security/get-security-rules-by-id/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="device" type="string | null">
  Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="folder" type="string | null">
  Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="name" type="string | null">
  Name of the security rule. Requires exactly one of folder, snippet, or device. Ignored when the ID is set.

  Default: `null`.
</ParamField>

<ParamField path="position" type="string">
  Rulebase position of the rule. Allowed values: pre, post.

  Default: `"pre"`.
</ParamField>

<ParamField path="rule_id" type="string | null">
  Security rule UUID.

  Default: `null`.
</ParamField>

<ParamField path="snippet" type="string | null">
  Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

## List address groups

Action ID: `tools.pan_strata.list_address_groups`

List address groups. Calls GET /config/objects/v1/address-groups directly; page with limit and offset.

Reference: [https://pan.dev/scm/api/config/ngfw/objects/list-address-groups/](https://pan.dev/scm/api/config/ngfw/objects/list-address-groups/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="device" type="string | null">
  Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="folder" type="string | null">
  Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="limit" type="integer | null">
  Maximum number of results per page. SCM defaults to 200.

  Default: `null`.
</ParamField>

<ParamField path="offset" type="integer | null">
  Number of results to skip before the first returned result. Use the response's total to page.

  Default: `null`.
</ParamField>

<ParamField path="snippet" type="string | null">
  Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

## List addresses

Action ID: `tools.pan_strata.list_addresses`

List address objects. Calls GET /config/objects/v1/addresses directly; page with limit and offset.

Reference: [https://pan.dev/scm/api/config/ngfw/objects/list-addresses/](https://pan.dev/scm/api/config/ngfw/objects/list-addresses/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="device" type="string | null">
  Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="folder" type="string | null">
  Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="limit" type="integer | null">
  Maximum number of results per page. SCM defaults to 200.

  Default: `null`.
</ParamField>

<ParamField path="offset" type="integer | null">
  Number of results to skip before the first returned result. Use the response's total to page.

  Default: `null`.
</ParamField>

<ParamField path="snippet" type="string | null">
  Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

## List devices

Action ID: `tools.pan_strata.list_devices`

List devices onboarded to Strata Cloud Manager. Calls GET /config/setup/v1/devices directly; page with limit and offset.

Reference: [https://pan.dev/scm/api/config/ngfw/setup/list-devices/](https://pan.dev/scm/api/config/ngfw/setup/list-devices/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="limit" type="integer | null">
  Maximum number of results per page. SCM defaults to 200.

  Default: `null`.
</ParamField>

<ParamField path="offset" type="integer | null">
  Number of results to skip before the first returned result. Use the response's total to page.

  Default: `null`.
</ParamField>

## List external dynamic lists

Action ID: `tools.pan_strata.list_external_dynamic_lists`

List external dynamic lists. Calls GET /config/objects/v1/external-dynamic-lists directly; page with limit and offset.

Reference: [https://pan.dev/scm/api/config/ngfw/objects/list-external-dynamic-lists/](https://pan.dev/scm/api/config/ngfw/objects/list-external-dynamic-lists/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="device" type="string | null">
  Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="folder" type="string | null">
  Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="limit" type="integer | null">
  Maximum number of results per page. SCM defaults to 200.

  Default: `null`.
</ParamField>

<ParamField path="offset" type="integer | null">
  Number of results to skip before the first returned result. Use the response's total to page.

  Default: `null`.
</ParamField>

<ParamField path="snippet" type="string | null">
  Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

## List folders

Action ID: `tools.pan_strata.list_folders`

List folders. Calls GET /config/setup/v1/folders directly; page with limit and offset.

Reference: [https://pan.dev/scm/api/config/ngfw/setup/list-folders/](https://pan.dev/scm/api/config/ngfw/setup/list-folders/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="limit" type="integer | null">
  Maximum number of results per page. SCM defaults to 200.

  Default: `null`.
</ParamField>

<ParamField path="offset" type="integer | null">
  Number of results to skip before the first returned result. Use the response's total to page.

  Default: `null`.
</ParamField>

## List jobs

Action ID: `tools.pan_strata.list_jobs`

List configuration jobs. Calls GET /config/operations/v1/jobs directly; page with limit and offset.

Reference: [https://pan.dev/scm/api/config/ngfw/operations/list-jobs/](https://pan.dev/scm/api/config/ngfw/operations/list-jobs/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="limit" type="integer | null">
  Maximum number of results per page. SCM defaults to 200.

  Default: `null`.
</ParamField>

<ParamField path="offset" type="integer | null">
  Number of results to skip before the first returned result. Use the response's total to page.

  Default: `null`.
</ParamField>

## List quarantined devices

Action ID: `tools.pan_strata.list_quarantined_devices`

List GlobalProtect devices on the quarantine list with GET /config/objects/v1/quarantined-devices, optionally filtered by host ID or serial number.

Reference: [https://pan.dev/scm/api/config/ngfw/objects/list-quarantined-devices/](https://pan.dev/scm/api/config/ngfw/objects/list-quarantined-devices/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="host_id" type="string | null">
  Filter by device host ID.

  Default: `null`.
</ParamField>

<ParamField path="serial_number" type="string | null">
  Filter by device serial number.

  Default: `null`.
</ParamField>

## List security rules

Action ID: `tools.pan_strata.list_security_rules`

List security rules. Calls GET /config/security/v1/security-rules directly; page with limit and offset.

Reference: [https://pan.dev/scm/api/config/ngfw/security/list-rules/](https://pan.dev/scm/api/config/ngfw/security/list-rules/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="device" type="string | null">
  Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="folder" type="string | null">
  Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="limit" type="integer | null">
  Maximum number of results per page. SCM defaults to 200.

  Default: `null`.
</ParamField>

<ParamField path="offset" type="integer | null">
  Number of results to skip before the first returned result. Use the response's total to page.

  Default: `null`.
</ParamField>

<ParamField path="position" type="string">
  Rulebase position of the rule. Allowed values: pre, post.

  Default: `"pre"`.
</ParamField>

<ParamField path="snippet" type="string | null">
  Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

## List snippets

Action ID: `tools.pan_strata.list_snippets`

List snippets. Calls GET /config/setup/v1/snippets directly; page with limit and offset.

Reference: [https://pan.dev/scm/api/config/ngfw/setup/list-snippets/](https://pan.dev/scm/api/config/ngfw/setup/list-snippets/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="limit" type="integer | null">
  Maximum number of results per page. SCM defaults to 200.

  Default: `null`.
</ParamField>

<ParamField path="offset" type="integer | null">
  Number of results to skip before the first returned result. Use the response's total to page.

  Default: `null`.
</ParamField>

## List tags

Action ID: `tools.pan_strata.list_tags`

List tags. Calls GET /config/objects/v1/tags directly; page with limit and offset.

Reference: [https://pan.dev/scm/api/config/ngfw/objects/list-tags/](https://pan.dev/scm/api/config/ngfw/objects/list-tags/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="device" type="string | null">
  Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="folder" type="string | null">
  Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="limit" type="integer | null">
  Maximum number of results per page. SCM defaults to 200.

  Default: `null`.
</ParamField>

<ParamField path="offset" type="integer | null">
  Number of results to skip before the first returned result. Use the response's total to page.

  Default: `null`.
</ParamField>

<ParamField path="snippet" type="string | null">
  Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

## Move security rule

Action ID: `tools.pan_strata.move_security_rule`

Move a security rule within its rulebase with POST /config/security/v1/security-rules/\{id}:move. Push the candidate configuration to apply the change.

Reference: [https://pan.dev/scm/api/config/ngfw/security/move-security-rules-by-id/](https://pan.dev/scm/api/config/ngfw/security/move-security-rules-by-id/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="destination" type="string" required>
  Where to move the rule. Allowed values: top, bottom, before, after.
</ParamField>

<ParamField path="rule_id" type="string" required>
  Security rule UUID.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="destination_rule" type="string | null">
  UUID of the reference rule. Required when destination is before or after.

  Default: `null`.
</ParamField>

<ParamField path="rulebase" type="string">
  Rulebase of the rule. Allowed values: pre, post.

  Default: `"pre"`.
</ParamField>

## Push candidate configuration

Action ID: `tools.pan_strata.push_candidate_config`

Push the candidate configuration of one or more folders to devices with POST /config/operations/v1/config-versions/candidate:push. Returns the job ID; use wait\_for\_job to wait for completion. Put this behind an approval step in containment workflows.

Reference: [https://pan.dev/scm/api/config/ngfw/operations/push-candidate-config-versions/](https://pan.dev/scm/api/config/ngfw/operations/push-candidate-config-versions/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="folders" type="array[string]" required>
  Folders to push, e.g. \["All Firewalls"] or \["Mobile Users", "Remote Networks"].
</ParamField>

<ParamField path="admin" type="array[string] | null">
  Push only changes made by these administrators or service accounts, e.g. the client ID of this integration. Omit to push all changes in the folders.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="description" type="string | null">
  Description of the change, e.g. the case or incident ID.

  Default: `null`.
</ParamField>

## Quarantine device

Action ID: `tools.pan_strata.create_quarantined_device`

Add a GlobalProtect device to the quarantine list with POST /config/objects/v1/quarantined-devices. Quarantined devices can be blocked by security rules that match the quarantine list.

Reference: [https://pan.dev/scm/api/config/ngfw/objects/create-quarantined-devices/](https://pan.dev/scm/api/config/ngfw/objects/create-quarantined-devices/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="host_id" type="string" required>
  Device host ID.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="serial_number" type="string | null">
  Device serial number.

  Default: `null`.
</ParamField>

## Remove address group members

Action ID: `tools.pan_strata.remove_address_group_members`

Remove members of a static address group in the candidate configuration. Reads the group by ID or by name with GET /config/objects/v1/address-groups, and writes it with PUT /config/objects/v1/address-groups/\{id} only when membership changes, so repeated calls are idempotent. Push the candidate configuration to apply the change.

Reference: [https://pan.dev/scm/api/config/ngfw/objects/update-address-groups-by-id/](https://pan.dev/scm/api/config/ngfw/objects/update-address-groups-by-id/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="members" type="array[string]" required>
  Names of address objects or address groups.
</ParamField>

<ParamField path="address_group_id" type="string | null">
  Address group UUID.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="device" type="string | null">
  Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="folder" type="string | null">
  Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="name" type="string | null">
  Address group name. Requires exactly one of folder, snippet, or device. Ignored when address\_group\_id is set.

  Default: `null`.
</ParamField>

<ParamField path="snippet" type="string | null">
  Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

## Remove device from quarantine

Action ID: `tools.pan_strata.delete_quarantined_device`

Remove a GlobalProtect device from the quarantine list with DELETE /config/objects/v1/quarantined-devices?host\_id=.

Reference: [https://pan.dev/scm/api/config/ngfw/objects/delete-quarantined-devices/](https://pan.dev/scm/api/config/ngfw/objects/delete-quarantined-devices/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="host_id" type="string" required>
  Device host ID.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

## Search incidents

Action ID: `tools.pan_strata.search_incidents`

Search Strata Cloud Manager incidents with POST /incidents/v1/search. Filter rules use property, operator, and values, e.g. \{"property": "status", "operator": "in", "values": \["Raised"]}.

Reference: [https://pan.dev/scm/api/config/incidents/search-incidents/](https://pan.dev/scm/api/config/incidents/search-incidents/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="region" type="string" required>
  Tenant region sent as the X-PANW-Region header, e.g. americas, europe, uk, or au.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="filters" type="array[object] | null">
  Filter rules with property, operator, and values.

  Default: `null`.
</ParamField>

<ParamField path="order_by" type="array[object] | null">
  Sort order, e.g. \[\{"property": "updated\_time", "order": "desc"}].

  Default: `null`.
</ParamField>

<ParamField path="page_number" type="integer">
  Page number, starting at 1.

  Default: `1`.
</ParamField>

<ParamField path="page_size" type="integer">
  Number of incidents per page.

  Default: `25`.
</ParamField>

## Unblock FQDN

Action ID: `tools.pan_strata.unblock_fqdn`

Unblock an FQDN blocked with the matching block action. Removes the address object from the static address group with PUT /config/objects/v1/address-groups/\{id} if it is a member, then deletes the address object with DELETE /config/objects/v1/addresses/\{id} if it exists. Repeated calls are no-ops. Changes stay in the candidate configuration; run push\_candidate\_config to enforce them.

Reference: [https://pan.dev/scm/api/config/ngfw/objects/update-address-groups-by-id/](https://pan.dev/scm/api/config/ngfw/objects/update-address-groups-by-id/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="address_group" type="string" required>
  Static address group that a deny rule references, e.g. tracecat-blocklist.
</ParamField>

<ParamField path="value" type="string" required>
  Fully qualified domain name to unblock.
</ParamField>

<ParamField path="address_name" type="string | null">
  Address object name to use instead of the generated name.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="delete_address" type="boolean">
  Delete the address object after removing it from the group. Fails if other rules or groups still reference it.

  Default: `true`.
</ParamField>

<ParamField path="device" type="string | null">
  Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="folder" type="string | null">
  Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="name_prefix" type="string">
  Prefix for generated address object names.

  Default: `"tc-block-"`.
</ParamField>

<ParamField path="snippet" type="string | null">
  Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

## Unblock IP

Action ID: `tools.pan_strata.unblock_ip`

Unblock an IP address or CIDR range blocked with the matching block action. Removes the address object from the static address group with PUT /config/objects/v1/address-groups/\{id} if it is a member, then deletes the address object with DELETE /config/objects/v1/addresses/\{id} if it exists. Repeated calls are no-ops. Changes stay in the candidate configuration; run push\_candidate\_config to enforce them.

Reference: [https://pan.dev/scm/api/config/ngfw/objects/update-address-groups-by-id/](https://pan.dev/scm/api/config/ngfw/objects/update-address-groups-by-id/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="address_group" type="string" required>
  Static address group that a deny rule references, e.g. tracecat-blocklist.
</ParamField>

<ParamField path="value" type="string" required>
  IPv4 or IPv6 address, or CIDR range, to unblock.
</ParamField>

<ParamField path="address_name" type="string | null">
  Address object name to use instead of the generated name.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="delete_address" type="boolean">
  Delete the address object after removing it from the group. Fails if other rules or groups still reference it.

  Default: `true`.
</ParamField>

<ParamField path="device" type="string | null">
  Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="folder" type="string | null">
  Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

<ParamField path="name_prefix" type="string">
  Prefix for generated address object names.

  Default: `"tc-block-"`.
</ParamField>

<ParamField path="snippet" type="string | null">
  Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.

  Default: `null`.
</ParamField>

## Update address

Action ID: `tools.pan_strata.update_address`

Update an address object in the candidate configuration. Reads it with GET /config/objects/v1/addresses/\{id}, applies only the provided fields, and writes it with PUT /config/objects/v1/addresses/\{id}. Push the candidate configuration to apply the change.

Reference: [https://pan.dev/scm/api/config/ngfw/objects/update-addresses-by-id/](https://pan.dev/scm/api/config/ngfw/objects/update-addresses-by-id/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="address_id" type="string" required>
  Address object UUID.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="description" type="string | null">
  New description.

  Default: `null`.
</ParamField>

<ParamField path="fqdn" type="string | null">
  Fully qualified domain name, e.g. malicious.example.com.

  Default: `null`.
</ParamField>

<ParamField path="ip_netmask" type="string | null">
  IP address with or without CIDR mask, e.g. 203.0.113.10 or 10.0.0.0/24.

  Default: `null`.
</ParamField>

<ParamField path="ip_range" type="string | null">
  IP range, e.g. 10.0.0.1-10.0.0.20.

  Default: `null`.
</ParamField>

<ParamField path="ip_wildcard" type="string | null">
  IP wildcard mask, e.g. 10.20.1.0/0.0.248.255.

  Default: `null`.
</ParamField>

<ParamField path="name" type="string | null">
  New name.

  Default: `null`.
</ParamField>

<ParamField path="tags" type="array[string] | null">
  Replacement tag list.

  Default: `null`.
</ParamField>

## Update address group

Action ID: `tools.pan_strata.update_address_group`

Update an address group in the candidate configuration. Reads it with GET /config/objects/v1/address-groups/\{id}, applies only the provided fields, and writes it with PUT /config/objects/v1/address-groups/\{id}. static\_members replaces the whole member list; use add\_address\_group\_members or remove\_address\_group\_members for incremental changes.

Reference: [https://pan.dev/scm/api/config/ngfw/objects/update-address-groups-by-id/](https://pan.dev/scm/api/config/ngfw/objects/update-address-groups-by-id/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="address_group_id" type="string" required>
  Address group UUID.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="description" type="string | null">
  New description.

  Default: `null`.
</ParamField>

<ParamField path="dynamic_filter" type="string | null">
  Tag filter for a dynamic group, e.g. 'quarantine' or 'malicious' and 'external'.

  Default: `null`.
</ParamField>

<ParamField path="name" type="string | null">
  New name.

  Default: `null`.
</ParamField>

<ParamField path="static_members" type="array[string] | null">
  Names of address objects or groups for a static group.

  Default: `null`.
</ParamField>

<ParamField path="tags" type="array[string] | null">
  Replacement tag list.

  Default: `null`.
</ParamField>

## Update security rule

Action ID: `tools.pan_strata.update_security_rule`

Update a security rule in the candidate configuration. Reads it with GET /config/security/v1/security-rules/\{id}, merges the provided API-native fields, and writes it with PUT /config/security/v1/security-rules/\{id}. Push the candidate configuration to apply the change.

Reference: [https://pan.dev/scm/api/config/ngfw/security/update-security-rules-by-id/](https://pan.dev/scm/api/config/ngfw/security/update-security-rules-by-id/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="rule_id" type="string" required>
  Security rule UUID.
</ParamField>

<ParamField path="updates" type="object" required>
  API-native fields to replace, e.g. \{"action": "deny", "source": \["blocked-ips"]}.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="position" type="string">
  Rulebase position of the rule. Allowed values: pre, post.

  Default: `"pre"`.
</ParamField>

## Wait for job

Action ID: `tools.pan_strata.wait_for_job`

Poll GET /config/operations/v1/jobs/\{id} until the job finishes, then return normalized status, result, done, and succeeded fields. Fails when the job fails, unless raise\_on\_failure is false, or when it does not finish within poll\_max\_attempts.

Reference: [https://pan.dev/scm/api/config/ngfw/operations/get-jobs-by-id/](https://pan.dev/scm/api/config/ngfw/operations/get-jobs-by-id/)

### Secrets

Required secrets:

* `pan_strata_oauth`: OAuth token `PAN_STRATA_SERVICE_TOKEN`.

### Input fields

<ParamField path="job_id" type="string" required>
  Job ID, e.g. the job\_id returned by push\_candidate\_config.
</ParamField>

<ParamField path="base_url" type="string | null">
  SCM API base URL. Falls back to the workspace variable pan\_strata.base\_url, then [https://api.strata.paloaltonetworks.com](https://api.strata.paloaltonetworks.com). Set this for FedRAMP tenants.

  Default: `null`.
</ParamField>

<ParamField path="poll_interval" type="number">
  Seconds between polls.

  Default: `10`.
</ParamField>

<ParamField path="poll_max_attempts" type="integer">
  Maximum number of polls.

  Default: `60`.
</ParamField>

<ParamField path="raise_on_failure" type="boolean">
  Fail the action when the job finishes unsuccessfully.

  Default: `true`.
</ParamField>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.