openapi: 3.2.0 info: title: Prisma Browser for MSP Tenant API API version: '1.0' description: "The Prisma Browser for MSP API provides a suite of endpoints to automate the management of security services for the SMB market. \nThis API allows developers to programmatically create and configure new tenants, manage license allocation, and retrieve detailed security reports on blocked malware, \nmalicious websites, and unauthorized extensions. By using these services, MSPs can integrate multi-tenant visibility and lifecycle management directly into their \nown dashboards or third-party platforms like ServiceNow. This Open API spec file was created on February 23, 2026. © 2026 Palo Alto Networks, Inc. Palo Alto Networks is a registered trademark of Palo Alto Networks. A list of our trademarks can be found at [https://www.paloaltonetworks.com/company/trademarks.html](https://www.paloaltonetworks.com/company/trademarks.html). All other marks mentioned herein may be trademarks of their respective companies." tags: - name: Tenant API paths: /mt/pab/tenant: post: summary: Create a new tenant description: Creates a new tenant with the specified configuration including region, identity provider, and user groups. operationId: PostMtPabTenant responses: '200': description: Tenant created successfully content: application/json: {} '400': description: Invalid request payload or validation failed '404': description: Required resource not found '500': description: Internal server error parameters: [] tags: - Tenant API requestBody: description: Tenant creation request payload with all required configuration details content: application/json: examples: MSP IDP Tenant: description: Create a tenant using MSP Identity Provider value: tenant_vertical: High Tech auth_profile_id: test_profile directory: pab_standalone_test_directory identity_provider_type: MSP IDP region: us root_tsg_id: '1868805847' tenant_name: test_tenant_1 serial_number: SN12345678 user_groups: - Everyone user_quantity: 3 schema: $ref: '#/components/schemas/CreateTenantRequest' required: true security: - authKey: [] /mt/pab/tenant/auth_profile: get: summary: Get authentication profiles description: Retrieves all available authentication profiles for the tenant service group. operationId: GetMtPabTenantAuth_profile responses: '200': description: Successfully retrieved authentication profiles content: application/json: {} '400': description: Invalid request '404': description: Authentication profiles not found '500': description: Internal server error parameters: [] tags: - Tenant API security: - authKey: [] /mt/pab/tenant/directories: get: summary: Get available directories description: Retrieves a list of all available directories for the tenant service group. operationId: GetMtPabTenantDirectories responses: '200': description: Successfully retrieved directories content: application/json: {} '400': description: Invalid request '404': description: Directories not found '500': description: Internal server error parameters: [] tags: - Tenant API security: - authKey: [] /mt/pab/tenant/licenses: get: summary: Get license utilization information description: Retrieves current license utilization metrics and availability for the tenant service group. operationId: GetMtPabTenantLicenses responses: '200': description: Successfully retrieved license utilization content: application/json: {} '400': description: Invalid request '404': description: License information not found '500': description: Internal server error parameters: [] tags: - Tenant API security: - authKey: [] /mt/pab/tenant/region: get: summary: Get available regions description: Retrieves a list of all available regions for tenant deployment. operationId: GetMtPabTenantRegion responses: '200': description: Successfully retrieved regions content: application/json: {} '400': description: Invalid request '404': description: Regions not found '500': description: Internal server error parameters: [] tags: - Tenant API security: - authKey: [] /mt/pab/tenant/user_group: post: summary: Get user groups for a directory description: Retrieves all user groups associated with the specified directory name. operationId: PostMtPabTenantUser_group responses: '200': description: Successfully retrieved user groups content: application/json: {} '400': description: Invalid request payload '404': description: Directory not found '500': description: Internal server error parameters: [] tags: - Tenant API requestBody: description: Directory name for which to retrieve user groups content: application/json: examples: Example Request: description: Get user groups for the specified directory value: directory_name: pab_test_directory schema: $ref: '#/components/schemas/UserGroupRequest' required: true security: - authKey: [] components: schemas: UserGroupRequest: type: object required: - directory_name examples: - directory_name: pab_test_directory description: Request payload for retrieving user groups from a directory properties: directory_name: type: string minLength: 1 examples: - pab_test_directory description: Name of the directory from which to retrieve user groups CreateTenantRequest: type: object required: - root_tsg_id - tenant_name - serial_number - region - user_quantity - identity_provider_type description: Request payload for creating a new PAB tenant properties: root_tsg_id: type: string minLength: 1 examples: - '1868805847' description: Root Tenant Service Group ID under which the new tenant will be created tenant_name: type: string minLength: 1 examples: - test_tenant_1 description: Name of the tenant to be created tenant_vertical: type: string examples: - High Tech description: Vertical or industry type for the tenant serial_number: type: string minLength: 1 examples: - SN12345678 description: Serial number for the tenant deployment region: type: string minLength: 1 examples: - us description: 'SLS region where the tenant will be deployed. Valid values: us, eu, jp, uk, in, sg, ca, id, au, de' user_quantity: type: integer format: int32 examples: - 3 description: Number of user licenses to allocate to this tenant minimum: 1 identity_provider_type: type: string minLength: 1 examples: - MSP IDP description: 'Type of identity provider to use for authentication. Valid values: ''MSP IDP'', ''Tenant IDP''' directory: type: string examples: - pab_standalone_test_directory description: Directory name for user authentication (required when using MSP IDP) auth_profile_id: type: string examples: - test_profile description: Authentication profile ID to use for the tenant user_groups: type: array examples: - - Everyone items: type: string description: Array of user group names to be assigned to the tenant securitySchemes: authKey: {}