# Cisco Secure Firewall > Cisco Secure Firewall is the firewall product line built on the Sourcefire technology Cisco acquired in > 2013 — Firepower/Secure Firewall appliances and Threat Defense (FTD) software, the Secure Firewall > Management Center (FMC), the on-box device manager (FDM), and the cloud-delivered Firewall Management > Center (cdFMC) operated under Cisco Security Cloud Control. Two REST contracts are published first-party: > the cdFMC API (1,311 operations) and the Security Cloud Control Firewall Manager API (160 operations). Generated by API Evangelist on 2026-08-19 from the provider's own published artifacts. Method: generated (Cisco publishes no llms.txt; https://developer.cisco.com/llms.txt returned 404). ## What you can call - Base URL (US): https://api.us.security.cisco.com/firewall - Also EU / APJ / AU / IN — https://api.{region}.security.cisco.com/firewall - Auth: `Authorization: Bearer $API_TOKEN` — a non-expiring JWT API token minted in the Security Cloud Control console under Settings -> User Management. Tokens are region-scoped and tenant-scoped. - Roles: ROLE_SUPER_ADMIN, ROLE_ADMIN, ROLE_READ_ONLY, ROLE_EDIT_ONLY, ROLE_DEPLOY_ONLY, ROLE_VPN_SESSION_MANAGER. There are no OAuth scopes. - Media type: application/json for both request and response. ## Specifications - cdFMC OpenAPI 3.0.1 — https://github.com/CiscoDevNet/scc-public-api-docs/blob/main/cdo/cdfmc-openapi.yaml - SCC Firewall Manager OpenAPI 3.0.1 — https://github.com/CiscoDevNet/scc-public-api-docs/blob/main/cdo/openapi.yaml ## Documentation - API documentation: https://developer.cisco.com/docs/cisco-security-cloud-control-firewall-manager/ - Getting started: https://developer.cisco.com/docs/cisco-security-cloud-control-firewall-manager/getting-started/ - Authentication: https://developer.cisco.com/docs/cisco-security-cloud-control-firewall-manager/authentication/ - API changelog: https://developer.cisco.com/docs/cisco-security-cloud-control-firewall-manager/api-changelog/ - Secure Firewall developer hub: https://developer.cisco.com/secure-firewall/ ## Tooling - Python SDK: https://pypi.org/project/scc-firewall-manager-sdk/ (`pip install scc-firewall-manager-sdk`) - Ansible collection: https://github.com/CiscoDevNet/FMCAnsible (`cisco.fmcansible`) - Terraform provider: https://registry.terraform.io/providers/CiscoDevNet/fmc/latest - Postman collections: https://github.com/CiscoDevNet/scc-public-api-docs/tree/main/cdo - DevNet sandbox (always-on FMC): https://fmcrestapisandbox.cisco.com/ ## Conventions an agent needs - Pagination is offset/limit; the list envelope is `{count, limit, offset, items}`. - Search uses Lucene syntax in the `q` query parameter. Searchable fields are NOT published — an unsupported field returns HTTP 400 with the list of searchable fields for that endpoint. - Modify with PATCH on the Firewall Manager surface, PUT on the cdFMC surface. This split is real and documented; do not assume one verb. - Action-verb POSTs are ASYNCHRONOUS. They return a transaction; poll `GET /v1/transactions/{transactionUid}` for completion. Do not treat a 202 as done. - There is NO idempotency key. Only DELETE is documented as idempotent. Do not blind-retry a POST that creates or deploys — check the transaction first. - Rate limits are undocumented. `TOO_MANY_REQUESTS` (429) exists in the error enum but no window, quota or `Retry-After`/`RateLimit-*` header is published. Back off conservatively. - Two error envelopes exist. The documented one is `{errorCode, errorMsg, details}`. The edge gateway returns `{timestamp, path, status, error, requestId}` on auth failures. Handle both. ## Marquee flows - Inventory the fleet: `getDevices` -> `getDevice` - Find the cloud FMC: `getDeviceManagers` with `q=deviceType:CDFMC` -> `getDeviceManager` - Read policy: `getAllAccessPolicy` -> `getAllAccessRule` -> `getAccessRule` - Deploy: `getDeployableDevice` -> `getPendingChanges` -> `createDeploymentRequest` -> `getTransaction` - Upgrade FTDs: `getCompatibleFtdVersions` -> `upgradeFtdDevices` -> `getTransaction` - Objects: `getAllNetworkObject` / `createMultipleNetworkObject` / `getObjectUsages` ## Agent surface — what does NOT exist - No hosted/remote MCP endpoint. Two community MCP servers live in the CiscoDevNet GitHub organization and are local-stdio only: https://github.com/CiscoDevNet/CiscoFMC-MCP-server-community and https://github.com/CiscoDevNet/cisco-scc-mcp-community. Both are read-only. - No A2A agent card at /.well-known/agent-card.json or /.well-known/agent.json (probed 404). - No /.well-known documents of any kind on the API host (all probed 404). - No llms.txt published by Cisco. ## Security and compliance - security.txt: https://www.cisco.com/.well-known/security.txt (PGP-signed, Cisco PSIRT) - Vulnerability policy: https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html - FedRAMP: all SCC Firewall Manager APIs except the MSP APIs are available at https://manage.secure.cisco/api/rest - Trust portal: https://trustportal.cisco.com/ - Status: https://status.security.cisco.com/ ## Support - Cisco TAC: https://mycase.cloudapps.cisco.com/ - Community: https://community.cisco.com/t5/network-security/bd-p/disc-network-security