openapi: 3.2.0 info: title: TLS Protect Cloud API for Strata Cloud Manager Credential Management API description: Use the TLS Protect Cloud APIs to manage certificates, certificate requests, applications, machine identities, users, teams, event logs, and more. This Open API spec file was created on June 04, 2026. © 2026 Palo Alto Networks, Inc. Palo Alto Networks is a registered trademark of Palo Alto Networks. A list of our trademarks can be found at https://www.paloaltonetworks.com/company/trademarks.html. All other marks mentioned herein may be trademarks of their respective companies. version: 1.0.0 license: name: MIT url: https://opensource.org/license/mit servers: - url: https://api.strata.paloaltonetworks.com/ngts description: Strata Cloud Manager API security: - scmToken: [] tags: - name: Credential Management description: APIs for Credential Management. paths: /v1/credentialmanagerconfigurations: get: description: Retrieves a set of stored Credential Manager Service configurations. operationId: get-public-cms-conf parameters: - $ref: '#/components/parameters/CMSTypesParam' responses: '200': $ref: '#/components/responses/200GetCMSConfigurations' '400': $ref: '#/components/responses/400BadRequest' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '500': $ref: '#/components/responses/500InternalServerErrorContent' summary: Retrieves a set of Credential Manager tags: - Credential Management post: description: Adds a set of new Credential Manager Service configurations. Only one Credential Manager Service configuration per `cmsType` per company can exist. operationId: post-public-cms-conf requestBody: $ref: '#/components/requestBodies/CreateCMSConfigurationsBodyRequest' responses: '201': $ref: '#/components/responses/201CreateCMSConfigurations' '400': $ref: '#/components/responses/400BadRequest' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '500': $ref: '#/components/responses/500InternalServerErrorContent' summary: Add a set of Credential Manager tags: - Credential Management put: description: Updates the information of an existing Credential Manager Service configuration. operationId: put-public-cms-conf requestBody: $ref: '#/components/requestBodies/UpdateCMSConfigurationsBodyRequest' responses: '200': $ref: '#/components/responses/200UpdateCMSConfiguration' '400': $ref: '#/components/responses/400BadRequest' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '500': $ref: '#/components/responses/500InternalServerErrorContent' summary: Update a Credential Manager Service configuration tags: - Credential Management /v1/credentialmanagerconfigurations/{id}: get: description: Retrieves a Credential Manager Service configuration by the specified `id`. operationId: get-public-cms-conf-id responses: '200': $ref: '#/components/responses/200GetCMSConfiguration' '400': $ref: '#/components/responses/400BadRequest' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '500': $ref: '#/components/responses/500InternalServerErrorContent' summary: Retrieves a Credential Manager Service configurati tags: - Credential Management parameters: - $ref: '#/components/parameters/CMSConfigIdParam' delete: description: Deletes a Credential Manager Service configuration by the specified `id`. operationId: delete-public-cms-conf-id responses: '204': description: The returned HTTP code if the Credential Manager Service configuration was deleted successfully. '400': $ref: '#/components/responses/400BadRequest' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '500': $ref: '#/components/responses/500InternalServerErrorContent' summary: Delete a Credential Manager Service configuration tags: - Credential Management parameters: - $ref: '#/components/parameters/CMSConfigIdParam' /v1/credentialmanagerconfigurations/test: post: description: Tests the connection to a configured privileged access management through selected VSatellites. operationId: post-public-cms-conf-test requestBody: $ref: '#/components/requestBodies/TestCMSConfigurationBodyRequest' responses: '200': $ref: '#/components/responses/200TestCMSConfiguration' '400': $ref: '#/components/responses/400BadRequest' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '500': $ref: '#/components/responses/500InternalServerErrorContent' summary: Test the connection to a privileged tags: - Credential Management /v1/credentialmanagerconfigurations/{id}/test: post: description: Tests the connection to a configured privileged access management through selected VSatellites using a specified `id`. operationId: post-public-cms-conf-test-id responses: '200': $ref: '#/components/responses/200TestCMSConfiguration' '400': $ref: '#/components/responses/400BadRequest' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '500': $ref: '#/components/responses/500InternalServerErrorContent' summary: Test the connection to an external tags: - Credential Management parameters: - $ref: '#/components/parameters/CMSConfigIdParam' /v1/credentials: get: description: Retrieves a list of shared credentials for a company. operationId: get-public-cms-credential parameters: - $ref: '#/components/parameters/CMSCredentialDetailsParam' - $ref: '#/components/parameters/CMSTypesParam' - $ref: '#/components/parameters/CredentialIdsParam' - $ref: '#/components/parameters/TeamIdsParam' - $ref: '#/components/parameters/AuthTypesParam' responses: '200': $ref: '#/components/responses/200GetCredentials' '400': $ref: '#/components/responses/400BadRequest' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '422': $ref: '#/components/responses/404NotFound' '500': $ref: '#/components/responses/500InternalServerErrorContent' summary: Retrieves credentials for a company tags: - Credential Management post: description: Adds a set of new shared credentials. The `name` for each credential must be unique. operationId: post-public-cms-credential requestBody: $ref: '#/components/requestBodies/AddCredentialsBodyRequest' responses: '201': $ref: '#/components/responses/201AddCredentials' '400': $ref: '#/components/responses/400BadRequest' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '422': $ref: '#/components/responses/404NotFound' '500': $ref: '#/components/responses/500InternalServerErrorContent' summary: Add a set of new shared tags: - Credential Management put: description: Updates the information of an existing shared credential. operationId: put-public-cms-credential requestBody: $ref: '#/components/requestBodies/UpdateCredentialBodyRequest' responses: '200': $ref: '#/components/responses/200UpdateCredential' '400': $ref: '#/components/responses/400BadRequest' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '422': $ref: '#/components/responses/404NotFound' '500': $ref: '#/components/responses/500InternalServerErrorContent' summary: Update a shared credential tags: - Credential Management delete: description: Deletes existing shared credentials specified in the query parameter list of `ids`. operationId: delete-public-cms-credential parameters: - $ref: '#/components/parameters/CredentialIdsParam' responses: '200': $ref: '#/components/responses/200DeleteCredentials' '400': $ref: '#/components/responses/400BadRequest' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '422': $ref: '#/components/responses/404NotFound' '500': $ref: '#/components/responses/500InternalServerErrorContent' summary: Delete shared credentials tags: - Credential Management /v1/credentials/{id}: get: description: Retrieves the credential matching with provided `id`. operationId: get-public-cms-credential-id parameters: - name: id in: path required: true description: Credential ID. schema: type: string format: uuid - $ref: '#/components/parameters/CMSCredentialDetailsParam' responses: '200': $ref: '#/components/responses/200GetCredential' '400': $ref: '#/components/responses/400BadRequest' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '422': $ref: '#/components/responses/404NotFound' '500': $ref: '#/components/responses/500InternalServerErrorContent' summary: Retrieves shared credential by ID tags: - Credential Management delete: description: Deletes the shared credential by the specified `id`. operationId: delete-public-cms-credential-id responses: '204': description: The returned http code if the credential was deleted successfully. '400': $ref: '#/components/responses/400BadRequest' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '422': $ref: '#/components/responses/404NotFound' '500': $ref: '#/components/responses/500InternalServerErrorContent' summary: Delete shared credential by ID tags: - Credential Management parameters: - $ref: '#/components/parameters/CredentialIdParam' /v1/credentials/test: post: description: Tests the access to a shared credential using a specified `id` or by providing credential values. If both an `id` and parameters are provided, parameters override existing credential values. operationId: post-public-cms-credential-test-id requestBody: $ref: '#/components/requestBodies/TestCredentialBodyRequest' responses: '200': $ref: '#/components/responses/200TestCredential' '400': $ref: '#/components/responses/400BadRequest' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '500': $ref: '#/components/responses/500InternalServerErrorContent' summary: Test the access to shared credential tags: - Credential Management components: schemas: TokenAuthenticationData: properties: token: description: The token used for authentication with the underlying credentials provider. type: string type: object TestCredentialResponse: description: The result of testing access to the credential. properties: workflowId: format: uuid type: string workflowName: type: string required: - workflowId - workflowName type: object TestCredentialRequest: description: The properties representing a credential to test. properties: authType: $ref: '#/components/schemas/AuthType' cmsType: $ref: '#/components/schemas/CMSType' credentialDetails: $ref: '#/components/schemas/TestCredentialDetails' id: $ref: '#/components/schemas/CredentialId' wsClientId: description: An ID where you can subscribe to receive the response of the workflow. type: string required: - wsClientId type: object ResponseHashiCorpCredDetails: allOf: - $ref: '#/components/schemas/HashiCorpDetailsRequiredProp' CyberArkDetails: description: The CyberArk Credential information. properties: folder: description: The folder property into the CyberArk Safe. type: string objectName: description: The account's name which represents the credential in the CyberArk instance. type: string safe: description: The CyberArk Safe property. type: string type: object CertificateCredentialData: properties: certificateBundle: description: The Base64 encoding certificate bundle encrypted content. format: byte type: string certificateId: description: The Id of the certificate selected from the Certificate Inventory format: uuid type: string certificatePassword: description: The password to decrypt the certificate bundle. format: password type: string fingerprint: description: The fingerprint of the certificate selected from the Certificate Inventory type: string type: object TeamsIds: description: The ID's of teams. items: $ref: '#/components/schemas/TeamId' type: array uniqueItems: true ErrorResponse10: description: Holds the response body returned for errors. properties: errors: description: List of encountered errors. items: $ref: '#/components/schemas/Error' type: array type: object UpdateHashiCorpCredDetails: allOf: - $ref: '#/components/schemas/HashiCorpDetails' ResponseCredentialDetails: oneOf: - $ref: '#/components/schemas/ResponseCyberArkCredDetails' - $ref: '#/components/schemas/ResponseHashiCorpCredDetails' Error: description: Hold the error details. properties: args: description: List of arguments used to generate the error message. items: type: object type: array code: description: The error code. type: integer message: description: The error message. type: string required: - code - message type: object ResponseCMSDetails: description: An string containing the JSON content representing the details of the specific privileged access management. oneOf: - $ref: '#/components/schemas/ResponseCyberArkDetails' - $ref: '#/components/schemas/ResponseHashiCorpDetails' CreatedBy: description: The ID of the user whom created the credential. type: string HashiCorpDetailsRequiredProp: allOf: - $ref: '#/components/schemas/HashiCorpDetails' required: - secretPath - secretKeyName TestCyberArkCredDetails: allOf: - $ref: '#/components/schemas/CyberArkDetails' HashiCorpConfigurationRequiredProp: allOf: - $ref: '#/components/schemas/HashiCorpConfiguration' description: The configuration for the HashiCorp app. It's required to set the value for the `cmsType` property to `hashicorp`. required: - url AuthType: description: "The type of the authentication:\n * `password`\n * `username_password`\n" enum: - password - username_password type: string CMSConfigurationResponse: description: The information representing a Credential Manager Service configuration for response. properties: cmsDetails: $ref: '#/components/schemas/ResponseCMSDetails' cmsType: $ref: '#/components/schemas/CMSType' companyId: $ref: '#/components/schemas/CompanyId' consumerTsgIds: description: List of sub-TSG IDs the configuration is explicitly shared with. Mutually exclusive with shareWithAll=true. items: type: string type: array createdBy: $ref: '#/components/schemas/CreatedBy' createdOn: $ref: '#/components/schemas/CreatedOn' id: $ref: '#/components/schemas/CMSConfId' lastModifiedBy: $ref: '#/components/schemas/LastModifiedBy' lastModifiedOn: $ref: '#/components/schemas/LastModifiedOn' name: $ref: '#/components/schemas/Name' shareWithAll: description: When true, the configuration is shared with all sub-TSGs. type: boolean vSatelliteIds: $ref: '#/components/schemas/VSatelliteIds' type: object CyberArkConfigurationRequiredProp: allOf: - $ref: '#/components/schemas/CyberArkConfiguration' description: The configuration for the CyberArk app. It's required to set the value for the `cmsType` property to `cyberark`. required: - appID - baseUrl TestCyberArkDetails: allOf: - $ref: '#/components/schemas/CyberArkConfigurationRequiredProp' UpdateCredentialDetails: oneOf: - $ref: '#/components/schemas/UpdateCyberArkCredDetails' - $ref: '#/components/schemas/UpdateHashiCorpCredDetails' TestCredentialDetails: oneOf: - $ref: '#/components/schemas/TestCyberArkCredDetails' - $ref: '#/components/schemas/TestHashiCorpCredDetails' CyberArkDetailsRequiredProp: allOf: - $ref: '#/components/schemas/CyberArkDetails' required: - objectName - safe CMSConfId: description: The Credential Manager Service configuration ID. example: 72e4c1f6-d85f-11ed-afa1-0242ac120002 format: uuid type: string TeamId: description: The ID of a team. example: 3fa85f64-5717-4562-b3fc-2c963f66afa6 format: uuid type: string CreateCyberArkDetails: allOf: - $ref: '#/components/schemas/CyberArkConfigurationRequiredProp' References: description: The machines referenced. items: $ref: '#/components/schemas/Reference' type: array uniqueItems: true UpdateCredentialRequest: description: The properties representing a credential to update. properties: cmsConfigId: $ref: '#/components/schemas/CMSConfId' credentialDetails: $ref: '#/components/schemas/UpdateCredentialDetails' id: $ref: '#/components/schemas/CredentialId' name: $ref: '#/components/schemas/CredentialName' teamsIds: $ref: '#/components/schemas/TeamsIds' required: - id type: object CMSAuthenticationType: description: "The authentication type for the privileged access management:\n * `certificate` - For authentication with a Certificate bundle\n * `userPassword` - For authentication with user and password\n * `token` - For authentication with token\n * `appRole` - For authentication with AppRole\n" enum: - certificate - userPassword - token - appRole type: string ResponseCyberArkCredDetails: allOf: - $ref: '#/components/schemas/CyberArkDetailsRequiredProp' CreatedOn: description: The date in ISO 8601 full-date format when the credential was created. format: date type: string CyberArkConfiguration: allOf: - properties: appID: $ref: '#/components/schemas/AppId' baseUrl: $ref: '#/components/schemas/CMSURL' type: object - $ref: '#/components/schemas/CertificateCredentialData' description: The configuration for the CyberArk app. It's required to set the value for the `cmsType` property to `cyberark`. UpdateCMSDetails: oneOf: - $ref: '#/components/schemas/UpdateCyberArkDetails' - $ref: '#/components/schemas/UpdateHashiCorpDetails' ResponseCyberArkDetails: allOf: - $ref: '#/components/schemas/CyberArkConfiguration' ResponseHashiCorpDetails: allOf: - $ref: '#/components/schemas/HashiCorpConfiguration' CreateCMSConfigurationsRequest: description: The array of Credential Manager Service configurations to create. properties: cmsConfigurations: items: $ref: '#/components/schemas/CreateCMSConfigurationRequest' minItems: 1 type: array required: - cmsConfigurations type: object VSatelliteId: description: The VSatellite ID format: uuid type: string AddCredentialsRequest: description: Array of credentials to add. properties: credentials: items: $ref: '#/components/schemas/AddCredentialRequest' minItems: 1 type: array required: - credentials type: object Name: description: The Name of CMS configuration type: string HashiCorpDetails: description: The HashiCorp Credential information. properties: secretKeyName: description: The HashiCorp secret key name property. type: string secretPath: description: The HashiCorp secret path property. type: string type: object UserPasswordAuthenticationData: properties: password: description: The user's password of the underlying credentials provider. format: password type: string userName: description: The user's name of the underlying credentials provider. type: string type: object CredentialResponse: description: The properties representing a Credential for response purposes. properties: authType: $ref: '#/components/schemas/AuthType' cmsConfigId: $ref: '#/components/schemas/CMSConfId' cmsType: $ref: '#/components/schemas/CMSType' createdBy: $ref: '#/components/schemas/CreatedBy' createdOn: $ref: '#/components/schemas/CreatedOn' credentialDetails: $ref: '#/components/schemas/ResponseCredentialDetails' id: $ref: '#/components/schemas/CredentialId' lastModifiedBy: $ref: '#/components/schemas/LastModifiedBy' lastModifiedOn: $ref: '#/components/schemas/LastModifiedOn' name: $ref: '#/components/schemas/CredentialName' references: $ref: '#/components/schemas/References' teamsIds: $ref: '#/components/schemas/TeamsIds' tsgId: $ref: '#/components/schemas/TSGId' required: - id - name - cmsConfigId - authType - cmsType type: object UpdateCyberArkDetails: allOf: - $ref: '#/components/schemas/CyberArkConfiguration' CreateCredentialDetails: oneOf: - $ref: '#/components/schemas/CreateCyberArkCredDetails' - $ref: '#/components/schemas/CreateHashiCorpCredDetails' Reference: description: The machine referenced. properties: id: format: uuid type: string type: $ref: '#/components/schemas/ReferenceType' required: - id - type type: object AppId: description: The application ID from the CyberArk provider. type: string TestCMSDetails: oneOf: - $ref: '#/components/schemas/TestCyberArkDetails' - $ref: '#/components/schemas/TestHashiCorpDetails' HashiCorpConfiguration: allOf: - properties: authType: $ref: '#/components/schemas/CMSAuthenticationType' namespace: description: The namespace in HashiCorp Vault to connect to. type: string url: $ref: '#/components/schemas/CMSURL' required: - authType type: object - oneOf: - $ref: '#/components/schemas/CertificateCredentialData' - $ref: '#/components/schemas/UserPasswordAuthenticationData' - $ref: '#/components/schemas/TokenAuthenticationData' - $ref: '#/components/schemas/AppRoleAuthenticationData' description: The configuration for the HashiCorp app. It's required to set the value for the `cmsType` property to `hashicorp`. AppRoleAuthenticationData: properties: roleId: description: The Role ID used for authentication with the underlying credentials provider. type: string secretId: description: The Secret ID used for authentication with the underlying credentials provider. type: string type: object CreateHashiCorpCredDetails: allOf: - $ref: '#/components/schemas/HashiCorpDetailsRequiredProp' TestCMSConfigurationResponse: description: The result of testing the Credential Manager Service configuration. properties: workflowId: format: uuid type: string workflowName: type: string required: - workflowId - workflowName type: object AddCredentialRequest: description: The properties representing a credential to add. properties: authType: $ref: '#/components/schemas/AuthType' cmsConfigId: $ref: '#/components/schemas/CMSConfId' cmsType: $ref: '#/components/schemas/CMSType' credentialDetails: $ref: '#/components/schemas/CreateCredentialDetails' name: $ref: '#/components/schemas/CredentialName' teamsIds: $ref: '#/components/schemas/TeamsIds' required: - name - cmsType - authType - credentialDetails type: object UpdateCMSConfigurationRequest: description: The information representing a Credential Manager Service configuration for update. properties: cmsDetails: $ref: '#/components/schemas/UpdateCMSDetails' consumerTsgIds: description: List of sub-TSG IDs the configuration is explicitly shared with. Mutually exclusive with shareWithAll=true. items: type: string type: array id: $ref: '#/components/schemas/CMSConfId' name: $ref: '#/components/schemas/Name' shareWithAll: description: When true, the configuration is shared with all sub-TSGs. type: boolean vSatelliteIds: $ref: '#/components/schemas/VSatelliteIds' required: - id type: object LastModifiedOn: description: The date in ISO 8601 full-date format when the credential was modified. format: date type: string CreateHashiCorpDetails: allOf: - $ref: '#/components/schemas/HashiCorpConfigurationRequiredProp' UpdateCyberArkCredDetails: allOf: - $ref: '#/components/schemas/CyberArkDetails' LastModifiedBy: description: The ID of the user whom modified the credential. type: string TestCMSConfigurationRequest: description: The information representing a Credential Manager Service configuration for test purposes. properties: cmsDetails: $ref: '#/components/schemas/TestCMSDetails' cmsType: $ref: '#/components/schemas/CMSType' id: $ref: '#/components/schemas/CMSConfId' name: $ref: '#/components/schemas/Name' vSatelliteIds: $ref: '#/components/schemas/VSatelliteIds' wsClientId: description: An ID where you can subscribe to receive the response of the workflow. type: string required: - wsClientId type: object DeleteCredentialsResponse: description: The response for the delete credentials action. properties: count: type: integer idsCredentialsDeleted: items: $ref: '#/components/schemas/CredentialId' minItems: 1 type: array required: - idsCredentialsDeleted - count type: object CreateCyberArkCredDetails: allOf: - $ref: '#/components/schemas/CyberArkDetailsRequiredProp' CredentialId: description: The ID of the Credential in our System. example: 94e86140-d85f-11ed-afa1-0242ac120002 format: uuid type: string VSatelliteIds: description: An array of the VSatellite Ids which are connected to the CMS provider. items: $ref: '#/components/schemas/VSatelliteId' minItems: 1 type: array uniqueItems: true CreateCMSDetails: oneOf: - $ref: '#/components/schemas/CreateCyberArkDetails' - $ref: '#/components/schemas/CreateHashiCorpDetails' CreateCMSConfigurationRequest: description: The information representing a Credential Manager Service configuration for creation purpose. properties: cmsDetails: $ref: '#/components/schemas/CreateCMSDetails' cmsType: $ref: '#/components/schemas/CMSType' consumerTsgIds: description: List of sub-TSG IDs the configuration is explicitly shared with. Mutually exclusive with shareWithAll=true. items: type: string type: array name: $ref: '#/components/schemas/Name' shareWithAll: description: When true, the configuration is shared with all sub-TSGs. type: boolean vSatelliteIds: $ref: '#/components/schemas/VSatelliteIds' required: - cmsType - vSatelliteIds - cmsDetails type: object CompanyId: description: The company ID format: uuid readOnly: true type: string CredentialName: description: The name of the Credential in our System. type: string TestHashiCorpCredDetails: allOf: - $ref: '#/components/schemas/HashiCorpDetails' CMSURL: description: The baseUrl of the privileged access management provider. format: uri type: string CMSType: description: "The type of the privileged access management:\n * `cyberark` - For CyberArk privileged access management\n * `hashicorp` - For HashiCorp privileged access management\n" enum: - cyberark - hashicorp type: string UpdateHashiCorpDetails: allOf: - $ref: '#/components/schemas/HashiCorpConfiguration' AddCredentialsResponse: description: The response for the add credentials action. properties: count: type: integer credentialsAdded: items: $ref: '#/components/schemas/CredentialResponse' minItems: 1 type: array required: - credentialsAdded - count type: object TestHashiCorpDetails: allOf: - $ref: '#/components/schemas/HashiCorpConfigurationRequiredProp' GetCMSConfigurationsResponse: description: The array of Credential Manager Service configurations received. properties: cmsConfigurations: items: $ref: '#/components/schemas/CMSConfigurationResponse' minItems: 1 type: array count: type: integer required: - cmsConfigurations - count type: object GetCredentialsResponse: description: Array of credentials received. properties: count: type: integer credentials: items: $ref: '#/components/schemas/CredentialResponse' type: array required: - credentials - count type: object TSGId: description: The TSG identifier the credential belongs to. type: string ReferenceType: description: "The type of the reference:\n * `machine`\n" enum: - machine type: string CreateCMSConfigurationsResponse: description: The array of Credential Manager Service configurations created. properties: cmsConfigurationsCreated: items: $ref: '#/components/schemas/CMSConfigurationResponse' minItems: 1 type: array count: type: integer required: - cmsConfigurationsCreated - count type: object responses: 200UpdateCredential: content: application/json: schema: $ref: '#/components/schemas/CredentialResponse' description: The credentials updated successfully. 400BadRequest: content: application/json: schema: $ref: '#/components/schemas/ErrorResponse10' description: Bad request. 200DeleteCredentials: content: application/json: schema: $ref: '#/components/schemas/DeleteCredentialsResponse' description: The credentials deleted successfully. 200TestCredential: content: application/json: schema: $ref: '#/components/schemas/TestCredentialResponse' description: Connection test to credential successful. 200GetCredentials: content: application/json: schema: $ref: '#/components/schemas/GetCredentialsResponse' description: The retrieved credentials for a company. 200GetCMSConfigurations: content: application/json: schema: $ref: '#/components/schemas/GetCMSConfigurationsResponse' description: The Credential Manager Service configurations received. 200GetCMSConfiguration: content: application/json: schema: $ref: '#/components/schemas/CMSConfigurationResponse' description: The Credential Manager Service configuration received. 200TestCMSConfiguration: content: application/json: schema: $ref: '#/components/schemas/TestCMSConfigurationResponse' description: Ok. Contains the result of testing the Credential Manager Service configuration. 401Unauthorized: content: application/json: schema: $ref: '#/components/schemas/ErrorResponse10' description: Unauthorized. Missing or invalid credentials. 200GetCredential: content: application/json: schema: $ref: '#/components/schemas/CredentialResponse' description: The retrieved credential. 404NotFound: content: application/json: schema: $ref: '#/components/schemas/ErrorResponse10' description: Not found. The resource was not found. 201AddCredentials: content: application/json: schema: $ref: '#/components/schemas/AddCredentialsResponse' description: The credentials added successfully. 201CreateCMSConfigurations: content: application/json: schema: $ref: '#/components/schemas/CreateCMSConfigurationsResponse' description: The Credential Manager Service configurations created. 500InternalServerErrorContent: content: application/json: schema: $ref: '#/components/schemas/ErrorResponse10' description: Internal Server Error. 403Forbidden: content: application/json: schema: $ref: '#/components/schemas/ErrorResponse10' description: Forbidden. The user does not have the permission to do this action. 200UpdateCMSConfiguration: content: application/json: schema: $ref: '#/components/schemas/CMSConfigurationResponse' description: The Credential Manager Service configurations updated. requestBodies: TestCredentialBodyRequest: content: application/json: schema: $ref: '#/components/schemas/TestCredentialRequest' description: The body request to test the given credential. AddCredentialsBodyRequest: content: application/json: schema: $ref: '#/components/schemas/AddCredentialsRequest' description: The body request to add credentials to existing Credential Manager Service configurations. CreateCMSConfigurationsBodyRequest: content: application/json: schema: $ref: '#/components/schemas/CreateCMSConfigurationsRequest' description: The body request to create the given Credential Manager Service configuration using their details. UpdateCMSConfigurationsBodyRequest: content: application/json: schema: $ref: '#/components/schemas/UpdateCMSConfigurationRequest' description: The body request to update the given Credential Manager Service configuration using their details. UpdateCredentialBodyRequest: content: application/json: schema: $ref: '#/components/schemas/UpdateCredentialRequest' description: The body request to update the given credential. TestCMSConfigurationBodyRequest: content: application/json: schema: $ref: '#/components/schemas/TestCMSConfigurationRequest' description: The body request to test the given Credential Manager Service configuration using their details. parameters: CMSConfigIdParam: description: The id of the Credential Manager Service configuration. in: path name: id required: true schema: $ref: '#/components/schemas/CMSConfId' CredentialIdParam: description: The credential Id. in: path name: id required: true schema: $ref: '#/components/schemas/CredentialId' CredentialIdsParam: description: The credential Ids separated by commas. explode: false in: query name: ids schema: items: $ref: '#/components/schemas/CredentialId' minItems: 1 type: array TeamIdsParam: description: The team Ids separated by commas. explode: false in: query name: teamIds schema: items: $ref: '#/components/schemas/TeamId' minItems: 1 type: array CMSTypesParam: description: The privileged access management types separated by commas. explode: false in: query name: cmsTypes schema: items: $ref: '#/components/schemas/CMSType' minItems: 1 type: array AuthTypesParam: description: The authentication types separated by commas. explode: false in: query name: authTypes schema: items: $ref: '#/components/schemas/AuthType' minItems: 1 type: array CMSCredentialDetailsParam: description: The option of whether or not return full credential details. Only Admin users can use this parameter. in: query name: details schema: type: boolean securitySchemes: scmOAuth: type: oauth2 description: 'Strata Cloud Manager APIs authenticate client requests using the OAuth 2.0 Client Credentials flow. Please use the `client_id`, `client_secret` values associated with an IAM service account along with a scope value of `tsg_id:XXXXXXXXXX`, where `XXXXXXXXXX` is the Tenant Service Group (TSG) ID. The resulting JWT access token should be attached to all API calls as a `Bearer` token in the `Authorization` header (ex. `Authorization: Bearer tokenstring`).' flows: clientCredentials: tokenUrl: https://auth.apps.paloaltonetworks.com/oauth2/access_token scopes: {} scmToken: type: http description: 'Strata Cloud Manager APIs authenticate client requests using the OAuth 2.0 Client Credentials flow. Please use the `client_id`, `client_secret` values associated with an IAM service account along with a scope value of `tsg_id:XXXXXXXXXX`, where `XXXXXXXXXX` is the Tenant Service Group (TSG) ID. The resulting JWT access token should be attached to all API calls as a `Bearer` token in the `Authorization` header (ex. `Authorization: Bearer tokenstring`).' scheme: bearer bearerFormat: JWT