openapi: 3.2.0 info: title: TLS Protect Cloud API for Strata Cloud Manager Certificate Request API description: Use the TLS Protect Cloud APIs to manage certificates, certificate requests, applications, machine identities, users, teams, event logs, and more. This Open API spec file was created on June 04, 2026. © 2026 Palo Alto Networks, Inc. Palo Alto Networks is a registered trademark of Palo Alto Networks. A list of our trademarks can be found at https://www.paloaltonetworks.com/company/trademarks.html. All other marks mentioned herein may be trademarks of their respective companies. version: 1.0.0 license: name: MIT url: https://opensource.org/license/mit servers: - url: https://api.strata.paloaltonetworks.com/ngts description: Strata Cloud Manager API security: - scmToken: [] tags: - name: Certificate Request description: APIs for Certificate Request. paths: /outagedetection/v1/certificaterequests: get: description: Retrieves the details of all certificate requests. operationId: certificaterequests_getAll responses: '200': content: application/json: schema: $ref: '#/components/schemas/CertificateRequestResponse' description: The response body contains the details of the certificate requests '400': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse4' description: Incomplete or malformed request. '412': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse4' description: Incomplete or malformed request. summary: Get the details of all certificate tags: - Certificate Request post: description: Creates a certificate request for the specified `applicationId` and using the specified `certificateIssuingTemplateId`. Indicate a renewal by specifying `existingCertificateId`. Set `isVaaSGenerated` to true, specify `csrAttributes` to request a certificate using *Automated Secure Keypair*. The `validityPeriod` value must be in the ISO8601 format for time duration. Examples of ISO8601 format time duration include _P1Y_ for one year, _P10D_ for ten days, and _PT12H_ for twelve hours. operationId: certificaterequests_create requestBody: content: application/json: schema: $ref: '#/components/schemas/CertificateRequestRequest' responses: '201': content: application/json: schema: $ref: '#/components/schemas/CertificateRequestResponse' description: A certificate request has been created, and its details can be found in the response body. '400': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse4' description: The request is either incomplete or malformed. '412': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse4' description: The request is either incomplete or malformed. summary: Create a certificate request tags: - Certificate Request /outagedetection/v1/certificaterequests/{id}: get: description: Retrieves the details of the certificate request with the specified `id`. operationId: certificaterequests_getById parameters: - description: UUID of a Certificate Request in: path name: id required: true schema: description: UUID of a Certificate Request format: uuid type: string responses: '200': content: application/json: schema: $ref: '#/components/schemas/CertificateRequestInformation2' description: A certificate request has been found, and its details are in the response body. '400': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse4' description: The request is either incomplete or malformed. '404': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse4' description: The certificate request was not found. '412': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse4' description: The request is either incomplete or malformed. summary: Get a certificate request details tags: - Certificate Request /outagedetection/v1/certificaterequests/{id}/resubmission: post: description: Resubmits the certificate request that has the specified `id`. operationId: certificaterequests_resubmitById parameters: - description: UUID of a Certificate Request in: path name: id required: true schema: description: UUID of a Certificate Request format: uuid type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/CertificateRequestResubmissionRequest' responses: '200': content: application/json: schema: $ref: '#/components/schemas/CertificateRequestResponse' description: Certificate Request was resubmitted; details in response body. '400': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse4' description: Incomplete or malformed request. '404': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse4' description: Certificate Request not found. '412': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse4' description: Incomplete or malformed request. summary: Resubmit a certificate request tags: - Certificate Request /outagedetection/v1/certificaterequests/validation: post: description: This operation validates a proposed certificate request without actually submitting it.Checks for compliance with the specified issuing template and verifies all other references are valid (e.g., `existingCertificateId` is the UUID of an inventory certificate). operationId: certificaterequests_validation requestBody: content: application/json: schema: $ref: '#/components/schemas/CertificateRequestRequest' responses: '201': content: application/json: schema: $ref: '#/components/schemas/CertificationRequestInformation' description: Certificate Request was validated. '400': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse4' description: Incomplete or malformed request. '412': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse4' description: Incomplete or malformed request. summary: Validate a certificate request tags: - Certificate Request /outagedetection/v1/certificaterequestssearch: post: description: Retrieves the details of certificate requests that match the specified [search expression](https://docs.venafi.cloud/CSH_api_search). operationId: getCertificateRequestsByExpression requestBody: content: application/json: schema: $ref: '#/components/schemas/Filter' responses: '200': content: application/json: schema: $ref: '#/components/schemas/CertificateRequestDocumentResponse' description: The response body contains the details of the certificate requests. '400': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse4' description: The request is either incomplete or malformed. '412': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse4' description: The request is either incomplete or malformed. summary: Get the details of certificate requests tags: - Certificate Request components: schemas: CertificateRequestDocumentInformation: properties: applicationId: description: UUID of an application ID example: dc6eb020-9131-11ed-9ce4-1d9554d648cd format: uuid type: string approvedIds: description: A collection of IDs of all users that have already approved items: format: uuid type: string type: array approverTeamIds: description: A collection of all team IDs that are configured as approvers items: format: uuid type: string type: array approverUserIds: description: A collection of all user IDs that are configured as approvers items: format: uuid type: string type: array caOrderId: description: A CA order ID example: '63364861' type: string certificateIds: description: A collection of certificate ids example: - 1441c6f0-9136-11ed-bd65-ed926a033704 - 12257370-9132-11ed-bd65-ed926a033704 items: format: uuid type: string type: array certificateIssuingTemplateId: description: UUID of certificate issuing template example: ce9c2cc0-9131-11ed-a8f1-bf0e7991f912 format: uuid type: string certificateOwnerUserId: description: UUID of the certificate request's owner example: 88932c30-8e14-11ed-87e3-755db050f29d format: uuid type: string companyId: description: UUID of a company example: 85595df0-8e14-11ed-87e3-755db050f29d format: uuid type: string creationDate: description: The date a certificate request was created example: '2022-01-20T09:12:28Z' format: date-time type: string customAttributes: $ref: '#/components/schemas/CustomAttributes2' errorInformation: $ref: '#/components/schemas/ErrorInformation4' finalApproverId: description: UUID of the final approver if configured example: dc6eb020-9131-11ed-9ce4-1d9554d648cd format: uuid type: string id: description: UUID of a certificate request example: fa4a2210-9135-11ed-a8f1-bf0e7991f912 format: uuid type: string keyCurve: description: Certificate request key curve enum: - P256 - P384 - P521 - ED25519 - UNKNOWN example: P521 type: string keyLength: description: Certificate request key length example: 2048 format: int32 type: integer keyType: description: Certificate request key type enum: - RSA - DSA - EC - GOST3410 - ECGOST3410 - RESERVED3 - UNKNOWN example: RSA type: string modificationDate: description: The date a certificate request was modified example: '2023-01-24T09:12:28Z' format: date-time type: string status: description: The status of the certificate request enum: - NEW - PENDING - PENDING_APPROVAL - PENDING_FINAL_APPROVAL - REJECTED_APPROVAL - REQUESTED - ISSUED - REJECTED - CANCELLED - REVOKED - FAILED - DELETED example: ISSUED type: string subjectAlternativeNamesByType: $ref: '#/components/schemas/GeneralNamesData2' subjectCN: description: Certificate request subject CN example: venafi.com type: string subjectDN: description: Certificate request subject DN example: cn=venafi.com,ou=devops,o=venafi,c=US,st=Utah,l=Salt Lake City type: string tags: description: A collection of tags example: - test - category:security items: type: string type: array validityPeriod: description: ISO8601 Period Format example: P10M type: string type: object FilterOperand: properties: operand: $ref: '#/components/schemas/Condition' operator: description: An operator for filtering enum: - NOT example: NOT type: string type: object CertificateRequestRequest: properties: apiClientInformation: $ref: '#/components/schemas/ApiClientInformation' applicationId: description: Application UUID example: b00701b0-886f-11ed-9f39-3d586ab80cf2 format: uuid type: string certificateIssuingTemplateId: description: Certificate issuing template UUID example: a305d810-886f-11ed-9ccf-0dbf748eb1ae format: uuid type: string certificateOwnerUserId: description: Certificate owner UUID example: a305d810-886f-11ed-9ccf-0dbf748eb1ae format: uuid type: string certificateSigningRequest: description: A certificate signing request(CSR) in PEM format. Required when reuseCSR and isVaaSGenerated are set to false. type: string certificateUsageMetadata: description: A collection of certificate request metadata example: - appName: venafi app1 automationMetadata: automation data 008 nodeName: venafi node 007 - appName: venafi app2 automationMetadata: automation data 0013 nodeName: venafi node 005 items: $ref: '#/components/schemas/CertificateUsageMetadata' type: array csrAttributes: $ref: '#/components/schemas/CSRAttributesInformation' customAttributes: $ref: '#/components/schemas/CustomAttributesInformation' existingCertificateId: description: Existing certificate UUID. Required when reuseCSR is set to true. example: b505d810-886f-11ed-9ccf-0dbf748eb1ae format: uuid type: string isVaaSGenerated: description: Specify whether VaaS should generate the request. example: true type: boolean reuseCSR: description: Specifies whether an existing CSR is reused example: true type: boolean tags: description: A collection of tags example: - test - category:security items: type: string type: array uniqueItems: true validityPeriod: description: ISO8601 Period Format example: P10M type: string required: - applicationId - certificateIssuingTemplateId - isVaaSGenerated type: object AnyValue4: description: Can be any value - string, number, boolean, array or object. CertificateRequestResponse: properties: certificateRequests: description: A collection of certificate information example: - applicationId: 813700b0-c357-11ed-aea1-99c5a9067cde caOrderId: 3a:5f:7e:9f:8c:e4:b6:f7:25:a7:81:0d:f0:ac:28:ec:fe:05:9b:30 certificateIds: - a27dfc10-c357-11ed-946f-7db55f9ae03e - a275beb0-c357-11ed-946f-7db55f9ae03e - a24c16a0-c357-11ed-946f-7db55f9ae03e certificateIssuingTemplateId: 73a22290-c357-11ed-a00c-e3953fcf04eb certificateOwnerUserId: 9bf1e760-b797-11ed-a508-c13aa0641666 companyId: 98996d90-b797-11ed-a508-c13aa0641666 creationDate: '2023-03-15T17:34:26.466+00:00' id: a1c0c690-c357-11ed-a00c-e3953fcf04eb keyLength: 4096 keyType: RSA modificationDate: '2023-03-15T17:34:27.479+00:00' status: ISSUED subjectAlternativeNamesByType: dNSName: - localhost subjectCN: localhost subjectDN: cn=localhost,ou=devops,o=venafi,c=MX,st=Yucatan,l=Merida validityPeriod: P10D - applicationId: 813700b0-c357-11ed-aea1-99c5a9067cde caOrderId: 6f:b7:27:c8:2c:bd:1a:b0:6f:43:fb:8a:6b:5b:a3:a6:c2:52:38:85 certificateIds: - b767aef0-c357-11ed-946f-7db55f9ae03e - a275beb0-c357-11ed-946f-7db55f9ae03e - a24c16a0-c357-11ed-946f-7db55f9ae03e certificateIssuingTemplateId: 73a22290-c357-11ed-a00c-e3953fcf04eb certificateOwnerUserId: 9bf1e760-b797-11ed-a508-c13aa0641666 companyId: 98996d90-b797-11ed-a508-c13aa0641666 creationDate: '2023-03-15T17:35:02.384+00:00' id: b7502f50-c357-11ed-a00c-e3953fcf04eb keyLength: 4096 keyType: RSA modificationDate: '2023-03-15T17:35:02.544+00:00' status: ISSUED subjectAlternativeNamesByType: dNSName: - venafi.com subjectCN: venafi.com subjectDN: cn=venafi.com,ou=devops,o=venafi,c=MX,st=Yucatan,l=Merida validityPeriod: P12D items: $ref: '#/components/schemas/CertificateRequestInformation2' type: array type: object Filter: properties: expression: $ref: '#/components/schemas/BaseFilter' ordering: $ref: '#/components/schemas/BaseOrdering' paging: $ref: '#/components/schemas/Page1' type: object ApiClientInformation: description: Represents the information of the client that is calling the API example: identifier: 192.168.1.63 type: Venafi VCert CLI properties: identifier: description: Client identifier example: 199.121.8.74 type: string type: description: Client type example: Venafi VCert CLI type: string type: object CertificateUsageMetadata: properties: appName: type: string automationMetadata: type: string nodeName: type: string type: object CustomAttributes2: description: Certificate request custom attributes example: dnsNames: - www.venafi.com - venafi.com properties: dnsNames: items: type: string type: array uniqueItems: true overwriteSans: type: boolean type: object KeyTypeParameters2: properties: keyCurve: enum: - P256 - P384 - P521 - ED25519 - UNKNOWN type: string keyLength: format: int32 type: integer keyType: enum: - RSA - EC type: string required: - keyCurve - keyLength - keyType type: object CertificateRequestResubmissionRequest: properties: certificateIssuingTemplateId: description: Certificate issuing template UUID example: a305d810-886f-11ed-9ccf-dbf748eb1ae0 format: uuid type: string certificateOwnerUserId: description: Certificate owner UUID example: a305d810-886f-11ed-4bbe-dbf748eb1ae0 format: uuid type: string certificateUsageMetadata: description: A collection of certificate request metadata example: - appName: venafi app1 automationMetadata: automation data 008 nodeName: venafi node 007 - appName: venafi app2 automationMetadata: automation data 0013 nodeName: venafi node 005 items: $ref: '#/components/schemas/CertificateUsageMetadata' type: array validityPeriod: description: ISO8601 Period Format example: P10M type: string type: object CSRAttributesInformation: description: Represents CSR attributes for certificate requests. Required when isVaaSGenerated is set to true and reuseCSR to false. example: commonName: localhost country: MX keyTypeParameters: keyCurve: P256 keyLength: 4096 keyType: RSA locality: Merida organization: venafi organizationalUnits: - devops state: Yucatan subjectAlternativeNamesByType: dnsNames: - localhost properties: commonName: type: string country: type: string keyTypeParameters: $ref: '#/components/schemas/KeyTypeParameters2' locality: type: string organization: type: string organizationalUnits: items: type: string type: array state: type: string subjectAlternativeNamesByType: $ref: '#/components/schemas/SubjectAlternativeNamesByType' type: object CertificationRequestInformation: properties: hashAlgorithm: description: A certificate request signature hash algorithm enum: - MD5 - SHA1 - MD2 - SHA224 - SHA256 - SHA384 - SHA512 - UNKNOWN - GOSTR3411_94 example: SHA256 type: string keyCurve: description: Certificate request key length enum: - P256 - P384 - P521 - ED25519 - UNKNOWN example: P256 type: string keyLength: description: Certificate request key length example: 2048 format: int32 type: integer keyType: description: Certificate request key type enum: - RSA - DSA - EC - GOST3410 - ECGOST3410 - RESERVED3 - UNKNOWN example: RSA type: string publicKeyHash: description: A certificate request public hash key example: 0048AA1D7E2F0017F9CA2E687D8776A1A340553D type: string signatureAlgorithm: description: A certificate request signature algorithm enum: - MD2_WITH_RSA_ENCRYPTION - MD5_WITH_RSA_ENCRYPTION - SHA1_WITH_RSA_ENCRYPTION - SHA1_WITH_RSA_ENCRYPTION2 - SHA256_WITH_RSA_ENCRYPTION - SHA384_WITH_RSA_ENCRYPTION - SHA512_WITH_RSA_ENCRYPTION - ID_DSA_WITH_SHA1 - dsaWithSHA1 - EC_DSA_WITH_SHA1 - EC_DSA_WITH_SHA224 - EC_DSA_WITH_SHA256 - EC_DSA_WITH_SHA384 - EC_DSA_WITH_SHA512 - UNKNOWN - SHA1_WITH_RSAandMGF1 - GOST_R3411_94_WITH_GOST_R3410_2001 - GOST_R3411_94_WITH_GOST_R3410_94 example: SHA256_WITH_RSA_ENCRYPTION type: string subjectAlternativeNamesByType: $ref: '#/components/schemas/GeneralNamesData2' subjectDN: description: A certificate request subject DN example: cn=www.venafi.com,o=Venafi, Inc.,c=US,st=Utah,l=Salt Lake City type: string type: object Order: properties: direction: description: An ordering direction enum: - ASC - DESC example: DESC type: string field: description: A field, that will be used for ordering example: modificationDate type: string type: object ErrorInformation4: properties: args: items: $ref: '#/components/schemas/AnyValue4' type: array code: format: int32 type: integer message: type: string type: object Condition: description: A Condition for filtering properties: field: description: Represents a field for filtering example: certificateName type: string operator: description: An operator for filtering enum: - EQ - LT - LTE - GT - GTE - MATCH - FIND - IN example: EQ type: string value: description: represents a field's value example: venafi.com type: string values: description: represents a field's values example: - venafi.com - www.venafi.com items: type: string type: array type: object Page1: description: Specify pagination on the search request properties: pageNumber: description: page number example: 0 format: int32 type: integer pageSize: description: page size example: 10 format: int32 type: integer type: object BaseFilter: description: Root expression for filtering oneOf: - $ref: '#/components/schemas/FilterOperands' - $ref: '#/components/schemas/FilterOperand' - $ref: '#/components/schemas/Condition' type: object ErrorResponse4: properties: errors: items: $ref: '#/components/schemas/ErrorInformation4' type: array type: object SubjectAlternativeNamesByType: properties: dnsNames: items: type: string type: array ipAddresses: items: type: string type: array rfc822Names: items: type: string type: array uniformResourceIdentifiers: items: type: string type: array type: object GeneralNamesData2: description: A certificate subject alternative name by type example: dNSName: - www.venafi.com - venafi.com properties: dNSName: items: type: string type: array directoryName: items: type: string type: array ediPartyName: items: type: string type: array iPAddress: items: type: string type: array otherName: items: type: string type: array registeredID: items: type: string type: array rfc822Name: items: type: string type: array uniformResourceIdentifier: items: type: string type: array x400Address: items: type: string type: array type: object CertificateRequestDocumentResponse: properties: certificateRequests: description: A collection of certificate request information example: - applicationId: 813700b0-c357-11ed-aea1-99c5a9067cde caOrderId: 3a:5f:7e:9f:8c:e4:b6:f7:25:a7:81:0d:f0:ac:28:ec:fe:05:9b:30 certificateIds: - a27dfc10-c357-11ed-946f-7db55f9ae03e - a275beb0-c357-11ed-946f-7db55f9ae03e - a24c16a0-c357-11ed-946f-7db55f9ae03e certificateIssuingTemplateId: 73a22290-c357-11ed-a00c-e3953fcf04eb certificateOwnerUserId: 9bf1e760-b797-11ed-a508-c13aa0641666 companyId: 98996d90-b797-11ed-a508-c13aa0641666 creationDate: '2023-03-15T17:34:26.466+00:00' id: a1c0c690-c357-11ed-a00c-e3953fcf04eb keyLength: 4096 keyType: RSA modificationDate: '2023-03-15T17:34:27.479+00:00' status: ISSUED subjectAlternativeNamesByType: dNSName: - localhost subjectCN: localhost subjectDN: cn=localhost,ou=devops,o=venafi,c=MX,st=Yucatan,l=Merida validityPeriod: P10D items: $ref: '#/components/schemas/CertificateRequestDocumentInformation' type: array numFound: description: The number of certificate requests that were found example: 10 format: int64 type: integer type: object CustomAttributesInformation: description: Represents custom attributes for certificate requests properties: dnsNames: items: type: string type: array uniqueItems: true overwriteSans: description: Defines if the csr sans should be overwritten by the custom attributes dns sans type: boolean required: - dnsNames type: object FilterOperands: properties: operands: description: A list of conditions that will be used for filtering example: - field: certificateStatus operator: EQ value: ACTIVE - field: certificateName operator: EQ value: venafi.com items: $ref: '#/components/schemas/BaseFilter' type: array operator: description: An operator for filtering enum: - AND - OR example: OR type: string type: object BaseOrdering: description: Specify the ordering of a search result properties: orders: items: $ref: '#/components/schemas/Order' type: array type: object CertificateRequestInformation2: properties: apiClientInformation: $ref: '#/components/schemas/ApiClientInformation' applicationId: description: UUID of an application ID example: dc6eb020-9131-11ed-9ce4-1d9554d648cd format: uuid type: string approvedIds: description: A collection of IDs of all users that have already approved items: format: uuid type: string type: array uniqueItems: true approverTeamIds: description: A collection of all team IDs that are configured as approvers items: format: uuid type: string type: array uniqueItems: true approverUserIds: description: A collection of all user IDs that are configured as approvers items: format: uuid type: string type: array uniqueItems: true caOrderId: description: A CA order ID example: '63364861' type: string certificateIds: description: A collection of certificate IDs example: - 1441c6f0-9136-11ed-bd65-ed926a033704 - 12257370-9132-11ed-bd65-ed926a033704 items: format: uuid type: string type: array certificateIssuingTemplateId: description: UUID of a certificate issuing template example: ce9c2cc0-9131-11ed-a8f1-bf0e7991f912 format: uuid type: string certificateOwnerUserId: description: UUID of the certificate request's owner example: 88932c30-8e14-11ed-87e3-755db050f29d format: uuid type: string certificateSigningRequest: description: A certificate signing request (CSR) in PEM format type: string certificateUsageMetadata: description: A collection of certificate request metadata example: - appName: venafi app1 automationMetadata: automation data 008 nodeName: venafi node 007 - appName: venafi app2 automationMetadata: automation data 0013 nodeName: venafi node 005 items: $ref: '#/components/schemas/CertificateUsageMetadata' type: array companyId: description: UUID of a company example: 85595df0-8e14-11ed-87e3-755db050f29d format: uuid type: string creationDate: description: The date a certificate request was created example: '2023-01-10T09:12:28Z' format: date-time type: string customAttributesInformation: $ref: '#/components/schemas/CustomAttributesInformation' errorInformation: $ref: '#/components/schemas/ErrorInformation4' finalApproverId: description: UUID of the final approver if configured example: dc6eb020-9131-11ed-9ce4-1d9554d648cd format: uuid type: string id: description: UUID of a certificate request example: fa4a2210-9135-11ed-a8f1-bf0e7991f912 format: uuid type: string keyCurve: description: Certificate request key curve enum: - P256 - P384 - P521 - ED25519 - UNKNOWN example: P521 type: string keyLength: description: Certificate request key length example: 2048 format: int32 type: integer keyType: description: Certificate request key type enum: - RSA - DSA - EC - GOST3410 - ECGOST3410 - RESERVED3 - UNKNOWN example: RSA type: string modificationDate: description: The date a certificate request was modified example: '2023-01-11T09:12:28Z' format: date-time type: string status: description: The status of a certificate request enum: - NEW - PENDING - PENDING_APPROVAL - PENDING_FINAL_APPROVAL - REJECTED_APPROVAL - REQUESTED - ISSUED - REJECTED - CANCELLED - REVOKED - FAILED - DELETED example: ISSUED type: string subjectAlternativeNamesByType: $ref: '#/components/schemas/GeneralNamesData2' subjectDN: description: Certificate request subject DN example: cn=venafi.com,ou=devops,o=venafi,c=US,st=Utah,l=Salt Lake City type: string tags: description: A collection of tags example: - test - category:security items: type: string type: array uniqueItems: true validityPeriod: description: ISO8601 Period Format example: P10M type: string type: object securitySchemes: scmOAuth: type: oauth2 description: 'Strata Cloud Manager APIs authenticate client requests using the OAuth 2.0 Client Credentials flow. Please use the `client_id`, `client_secret` values associated with an IAM service account along with a scope value of `tsg_id:XXXXXXXXXX`, where `XXXXXXXXXX` is the Tenant Service Group (TSG) ID. The resulting JWT access token should be attached to all API calls as a `Bearer` token in the `Authorization` header (ex. `Authorization: Bearer tokenstring`).' flows: clientCredentials: tokenUrl: https://auth.apps.paloaltonetworks.com/oauth2/access_token scopes: {} scmToken: type: http description: 'Strata Cloud Manager APIs authenticate client requests using the OAuth 2.0 Client Credentials flow. Please use the `client_id`, `client_secret` values associated with an IAM service account along with a scope value of `tsg_id:XXXXXXXXXX`, where `XXXXXXXXXX` is the Tenant Service Group (TSG) ID. The resulting JWT access token should be attached to all API calls as a `Bearer` token in the `Authorization` header (ex. `Authorization: Bearer tokenstring`).' scheme: bearer bearerFormat: JWT