openapi: 3.2.0 info: title: TLS Protect Cloud API for Strata Cloud Manager Certificate Discovery API description: Use the TLS Protect Cloud APIs to manage certificates, certificate requests, applications, machine identities, users, teams, event logs, and more. This Open API spec file was created on June 04, 2026. © 2026 Palo Alto Networks, Inc. Palo Alto Networks is a registered trademark of Palo Alto Networks. A list of our trademarks can be found at https://www.paloaltonetworks.com/company/trademarks.html. All other marks mentioned herein may be trademarks of their respective companies. version: 1.0.0 license: name: MIT url: https://opensource.org/license/mit servers: - url: https://api.strata.paloaltonetworks.com/ngts description: Strata Cloud Manager API security: - scmToken: [] tags: - name: Certificate Discovery description: APIs for Certificate Discovery. paths: /v1/integrationservices: get: description: 'Retrieves the details of all services (Ex: Discovery services and Automated key pair services).' operationId: integrationsservices_getAll parameters: - description: Total number of services. in: query name: totalCount schema: default: false type: boolean - description: UUID of VSatellite instance associated to the service if any. in: query name: edgeInstanceId schema: format: uuid type: string responses: '200': content: application/json: schema: $ref: '#/components/schemas/IntegrationServiceDetailsResponse' description: Details of all services in response body. '400': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse1' description: Incomplete or malformed request. '412': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse1' description: Incomplete or malformed request. summary: Get a list of services tags: - Certificate Discovery post: description: 'Create a new service ' operationId: integrationsservices_create requestBody: content: application/json: schema: $ref: '#/components/schemas/IntegrationServiceCreationRequest' description: Details of the service to be created required: true responses: '201': content: application/json: schema: $ref: '#/components/schemas/IntegrationServiceInformation' description: A service created. '400': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse1' description: Incomplete or malformed request. summary: Add a service tags: - Certificate Discovery /v1/integrationservices/{id}: get: description: Retrieves the details of the service that has the specified `id`. operationId: integrationsservices_getById parameters: - description: UUID of a service in: path name: id required: true schema: description: UUID of a service format: uuid type: string responses: '200': content: application/json: schema: $ref: '#/components/schemas/IntegrationServiceInformation' description: Service was found; details in response body. '400': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse1' description: Incomplete or malformed request. '404': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse1' description: Service not found. '412': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse1' description: Incomplete or malformed request. summary: Get service details tags: - Certificate Discovery delete: description: Deletes the service that has the specified `id`. operationId: integrationsservices_delete parameters: - description: UUID of a service in: path name: id required: true schema: description: UUID of a service format: uuid type: string - description: 'retireCertificates" (boolean): Number of certificates associated to the service that were retired when the service was deleted.' in: query name: retireCertificates schema: default: false type: boolean responses: '204': description: Integration Service Deleted '400': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse1' description: Incomplete or malformed request. '404': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse1' description: Service not found. '412': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse1' description: Incomplete or malformed request. summary: Remove a service tags: - Certificate Discovery patch: description: Can be used to update specific fields. Only fields specified in the request will be updated. An empty set of edgeInstancesIds value will clear the set. operationId: integrationsservices_update parameters: - description: Integration Service ID in: path name: id required: true schema: description: Integration Service ID format: uuid type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/IntegrationServiceUpdateRequest' description: Details of the service to be updated required: true responses: '200': content: application/json: schema: $ref: '#/components/schemas/IntegrationServiceInformation' description: Integration Service information '400': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse1' description: Request Conditions Failed '404': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse1' description: Integration Service Not Found '412': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse1' description: Request Conditions Failed summary: Update Service properties tags: - Certificate Discovery components: schemas: AnyValue1: description: Can be any value - string, number, boolean, array or object. TargetsInformation: discriminator: propertyName: serviceType properties: serviceType: type: string required: - serviceType type: object IntegrationServiceCreationRequest: properties: edgeInstancesIds: description: A collection of Vsatellite instance IDs items: format: uuid type: string type: array uniqueItems: true environmentId: description: UUID of an environment example: 2e8cfc70-74ce-11ed-9051-cfa579eae364 format: uuid type: string name: description: Integration service name example: Internet discovery minLength: 1 type: string scheduleEnabled: description: If a integration service is scheduled for execution example: true type: boolean schedulePattern: $ref: '#/components/schemas/SchedulerPatternInformation1' serviceType: description: The type of an integration service enum: - BASIC_DISCOVERY - ENHANCED_DISCOVERY - EXTERNAL_SCAN - INTERNET_DISCOVERY - SMART_DISCOVERY_EXTERNAL - KEY_GENERATION - MSCA - ACME example: ENHANCED_DISCOVERY type: string targets: $ref: '#/components/schemas/TargetsInformation' workTypes: description: A collection of work types items: enum: - DISCOVER - MANAGE type: string minItems: 1 type: array uniqueItems: true required: - environmentId - name - serviceType - workTypes type: object IntegrationServiceDetailsResponse: properties: integrationsServices: items: $ref: '#/components/schemas/IntegrationServiceInformation' type: array totalCount: description: The total number of integration services returned example: 10 format: int64 type: integer type: object IntegrationServiceUpdateRequest: properties: edgeInstancesIds: description: A collection of Vsatellite instance IDs items: format: uuid type: string type: array uniqueItems: true name: description: Integration service name example: Internet discovery type: string scheduleEnabled: description: If a integration service is scheduled for execution example: true type: boolean schedulePattern: $ref: '#/components/schemas/SchedulerPatternInformation1' targets: $ref: '#/components/schemas/TargetsInformation' workTypes: description: A collection of work types items: enum: - DISCOVER - MANAGE type: string maxItems: 2147483647 minItems: 1 type: array uniqueItems: true type: object SchedulerPatternInformation1: discriminator: propertyName: recurrenceType properties: recurrenceType: type: string required: - recurrenceType type: object IntegrationServiceInformation: properties: companyId: description: UUID of a company example: 2b391680-74ce-11ed-bf7a-a3d5ccdf275c format: uuid type: string edgeInstancesIds: description: A collection of Vsatellite instance IDs items: format: uuid type: string type: array uniqueItems: true encryptionKeyId: description: Encryption key UUID example: 41bb5280-7193-11ed-a059-a7f274bd0b5b format: uuid type: string environmentId: description: UUID of an environment example: 2e8cfc70-74ce-11ed-9051-cfa579eae364 format: uuid type: string id: description: UUID of an integration service example: 2e8d71a0-74ce-11ed-9051-cfa579eae364 format: uuid type: string name: description: Integration service name example: Internet discovery type: string schedulePattern: $ref: '#/components/schemas/SchedulerPatternInformation1' schedulerEnabled: description: If a integration service is scheduled for execution example: true type: boolean serviceType: description: The type of an integration service enum: - BASIC_DISCOVERY - ENHANCED_DISCOVERY - EXTERNAL_SCAN - INTERNET_DISCOVERY - SMART_DISCOVERY_EXTERNAL - KEY_GENERATION - MSCA - ACME example: ENHANCED_DISCOVERY type: string status: description: Integration service status enum: - ACTIVE - DISABLED - RUNNING - WARNING - DRAFT - ERROR example: DISABLED type: string statusMessage: description: Integration service status message example: Integration service is disable type: string systemGenerated: description: If an integration service was generated automatically example: true type: boolean targets: $ref: '#/components/schemas/TargetsInformation' workTypes: description: A collection of work types items: enum: - DISCOVER - MANAGE type: string type: array uniqueItems: true type: object ErrorResponse1: properties: errors: items: $ref: '#/components/schemas/ErrorInformation1' type: array type: object ErrorInformation1: properties: args: items: $ref: '#/components/schemas/AnyValue1' type: array code: format: int32 type: integer message: type: string type: object securitySchemes: scmOAuth: type: oauth2 description: 'Strata Cloud Manager APIs authenticate client requests using the OAuth 2.0 Client Credentials flow. Please use the `client_id`, `client_secret` values associated with an IAM service account along with a scope value of `tsg_id:XXXXXXXXXX`, where `XXXXXXXXXX` is the Tenant Service Group (TSG) ID. The resulting JWT access token should be attached to all API calls as a `Bearer` token in the `Authorization` header (ex. `Authorization: Bearer tokenstring`).' flows: clientCredentials: tokenUrl: https://auth.apps.paloaltonetworks.com/oauth2/access_token scopes: {} scmToken: type: http description: 'Strata Cloud Manager APIs authenticate client requests using the OAuth 2.0 Client Credentials flow. Please use the `client_id`, `client_secret` values associated with an IAM service account along with a scope value of `tsg_id:XXXXXXXXXX`, where `XXXXXXXXXX` is the Tenant Service Group (TSG) ID. The resulting JWT access token should be attached to all API calls as a `Bearer` token in the `Authorization` header (ex. `Authorization: Bearer tokenstring`).' scheme: bearer bearerFormat: JWT