openapi: 3.1.0 info: title: Symantec Endpoint Protection Manager Administrators Authentication API description: The Symantec Endpoint Protection Manager (SEPM) REST API provides programmatic access to manage endpoint protection infrastructure. Enables management of computers (endpoints), groups, policies, server administrators, API versioning, and device lifecycle operations. Authentication uses OAuth 2.0 with username/password credentials via the identity endpoint, returning a Bearer token for subsequent calls. version: '14.0' contact: name: Broadcom Support url: https://support.broadcom.com termsOfService: https://www.broadcom.com/company/legal/terms-of-use servers: - url: https://{sepm-host}:8446/sepm/api/v1 description: Symantec Endpoint Protection Manager variables: sepm-host: default: localhost description: SEPM server hostname or IP address tags: - name: Authentication description: OAuth 2.0 authentication endpoints paths: /identity/authenticate: post: operationId: authenticate summary: Authenticate to SEPM description: Authenticates with SEPM using username, password, and domain credentials. Returns a Bearer token and refresh token for subsequent API calls. Requires SysAdmin role for full API access. tags: - Authentication requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AuthRequest' example: username: admin password: password123 domain: '' responses: '200': description: Authentication successful content: application/json: schema: $ref: '#/components/schemas/AuthResponse' '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' components: schemas: AuthResponse: type: object properties: token: type: string description: Bearer token for API authentication tokenExpiry: type: string format: date-time description: Token expiration timestamp refreshToken: type: string description: Refresh token for obtaining new access tokens AuthRequest: type: object required: - username - password properties: username: type: string description: SEPM administrator username password: type: string format: password description: SEPM administrator password domain: type: string description: Domain name (can be empty string for default domain) Error: type: object properties: errorCode: type: integer errorMessage: type: string responses: Unauthorized: description: Unauthorized - missing or expired Bearer token content: application/json: schema: $ref: '#/components/schemas/Error' BadRequest: description: Bad request - invalid parameters content: application/json: schema: $ref: '#/components/schemas/Error' securitySchemes: BearerAuth: type: http scheme: bearer description: Bearer token obtained from the /identity/authenticate endpoint externalDocs: description: Symantec Endpoint Protection Manager API Documentation url: https://techdocs.broadcom.com/us/en/symantec-security-software/endpoint-security-and-management/endpoint-protection/all/APIsSEP/Symantec-Endpoint-Security-API-commands1.html