openapi: 3.2.0 info: title: SASE 5G Manage Service Cie Token Resource API API version: '1.0' description: "The SASE 5G Management Service provides the administrative framework required to provision, \nconfigure, and oversee 5G security infrastructure within the Strata Cloud Manager (SCM) ecosystem. \nArchitects and administrators utilize these APIs during the activation and lifecycle management \nphases to bridge enterprise 5G networks with Prisma Access security.\n\nBy leveraging these endpoints, organizations implement robust hardware-to-tenant mapping using \nIMSI and IMEI identifiers, ensuring precise traffic attribution and policy enforcement. \nThe service manages critical control plane components—including certificate handling and \nRadius server integration—directly through the SCM management plane. This centralized \napproach allows technical teams to scale 5G connectivity across global compute regions \nwhile maintaining granular visibility into subscriber groups and regional interconnect health. This spec was created on February 11, 2026. © 2026 Palo Alto Networks, Inc." servers: - url: https://stratacloudmanager.paloaltonetworks.com security: - JWT: [] tags: - name: Cie Token Resource API paths: /mt/manage/5g/cie/token: post: tags: - Cie Token Resource API summary: Store Tenant Token description: "Saves the Cloud Identity Engine (CIE) token to the management plane for leaf tenants. \nAdministrators perform this during initial setup to authorize secure identity \nsynchronization between tenant directories and Strata Cloud Manager. This process \nestablishes the trust relationship required for identity-based security policies." requestBody: content: application/json: schema: $ref: '#/components/schemas/CieTokenRequest' responses: '200': description: Success '400': description: Bad Request '404': description: Data Not Found '500': description: Server Error operationId: PostMtManage5gCieToken /mt/manage/5g/cie/token/details: post: tags: - Cie Token Resource API summary: Fetch Token Metadata description: "Displays configuration metadata and validity status for an existing leaf tenant CIE token. \nEngineers use this during connection health audits to verify that identity integrations \nremain active within the management plane. It utilizes the tenant's TSG ID to locate \nspecific metadata records for verification." requestBody: content: application/json: schema: $ref: '#/components/schemas/JsonObject' responses: '200': description: Success '400': description: Bad Request '404': description: Data Not Found '500': description: Server Error operationId: PostMtManage5gCieTokenDetails components: schemas: CieTokenRequest: type: object properties: tsg_id: type: string access_token: type: string created_by: type: string created_at: type: string cie_directory: type: string JsonObject: type: array items: type: string