ZScaler OneAPI
The ZScaler OneAPI connector integrates Swimlane with the Zscaler OneAPI unified gateway to manage Zscaler Internet Access (ZIA) Cloud Firewall IP destination groups. IP destination groups let you group destination IP addresses, ranges, CIDRs, FQDNs, domains, countries, or URL categories so they can be referenced by Cloud Firewall filtering rules. This connector lets automation playbooks create, read, update, and delete those groups as part of enrichment and response workflows.
Prerequisites
You need a Zscaler Zidentity API client with a role granting access to the ZIA firewall policy resources. From the Zidentity Admin portal, add an API client and note the following:
- Vanity domain β your organization's vanity domain (the vanity part only, e.g. acme). The token endpoint is https://<vanity_domain>.zslogin.net/oauth2/v1/token.
- Client ID β the API client ID.
- One credential, depending on the authentication method you choose:
- Client Secret β the API client secret, or
- Private Key β a PEM-encoded RSA private key whose matching public key / certificate / JWKS is registered on the API client (signed JWT flow).
- API Base URL β https://api.zsapi.net for production, or https://api.<cloud>.zsapi.net for a non-production tenant.
Capabilities
This connector provides the following capabilities:
- List IP Destination Groups
- Add IP Destination Group
- Get IP Destination Group by ID
- Edit IP Destination Group
- Delete IP Destination Group
- List IP Source Groups
- Get IP Source Groups (Lite)
- Add IP Source Group
- Get IP Source Group by ID
- Edit IP Source Group
- Delete IP Source Group
- Get CTP Config
- Update CTP Config
- Get CTP Malicious URLs
- Update CTP Malicious URLs ... and so on
Limitations
- This connector currently covers ZIA Cloud Firewall IPv4 destination groups (/zia/api/v1/ipDestinationGroups), IP source groups (/zia/api/v1/ipSourceGroups), the Advanced Threat / Cyber Threat Protection (CTP) policy (/zia/api/v1/cyberThreatProtection), ZIA configuration activation (/zia/api/v1/status/activate), and ZPA application servers and sites (/zpa/mgmtconfig/v1/admin/customers/{customerId}/server and /site). Other ZIA and ZPA resources are out of scope.
- ZPA actions require the ZPA customerId (the unique identifier of the ZPA tenant) as a path parameter. Pass microtenantId as 0 when operating in the Default Microtenant.
- ZIA configuration changes made through the API may need to be activated before they take effect, depending on your tenant configuration.
Asset Setup
The connector ships with two authentication assets that map to the two Zscaler OneAPI credential types:
- OneAPI OAuth 2.0 (Client Secret) β supply url, vanity_domain, client_id, and client_secret. The connector performs an OAuth 2.0 client credentials grant against the Zidentity token endpoint using the audience https://api.zscaler.com.
- OneAPI OAuth 2.0 (Signed JWT / Private Key) β supply url, vanity_domain, client_id, and a PEM private_key. The connector builds and signs a JWT client assertion (RS256) and exchanges it for a bearer token. Use the optional key_id when your API client uses a JWKS URL with multiple keys.
For both assets you can optionally override the derived token endpoint with token_url, and the audience with audience. Set verify_ssl to true in production.
Tasks Setup
The type field on Add / Edit accepts: DSTN_IP, DSTN_FQDN, DSTN_DOMAIN, DSTN_OTHER. Use addresses for IP/FQDN/domain groups and countries / ipCategories for DSTN_OTHER groups. Country codes use the COUNTRY_ prefix (e.g. COUNTRY_US).
Notes
- Zscaler OneAPI reference: https://automate.zscaler.com/docs/getting-started/getting-started
- IP destination group API reference: https://automate.zscaler.com/docs/api-reference-and-guides/api-reference/zia/firewall-policies
Configurations
OneAPI OAuth 2.0 (Client Secret)
Authenticates to Zscaler OneAPI using the OAuth 2.0 client credentials flow with a Zidentity API client ID and client secret.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | The Zscaler OneAPI base URL. Production is https://api.zsapi.net. For a non-production tenant use https://api. ο»Ώ | string | Required |
vanity_domain | Your organization's Zidentity vanity domain (the vanity part only, e.g. "acme"). Used to build the token endpoint https://<vanity_domain>.zslogin.net/oauth2/v1/token. | string | Required |
token_url | Optional full token endpoint URL. Overrides the URL derived from the vanity domain when set. | string | Optional |
client_id | The Zidentity API client ID. | string | Required |
client_secret | The Zidentity API client secret. | string | Required |
audience | The OAuth 2.0 audience for the token request. | string | Optional |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
OneAPI OAuth 2.0 (Signed JWT / Private Key)
Authenticates to Zscaler OneAPI using the OAuth 2.0 client credentials flow with a signed JWT client assertion. Use this when your Zidentity API client is configured with a JWKS URL, certificate, or public key instead of a client secret.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | The Zscaler OneAPI base URL. Production is https://api.zsapi.net. For a non-production tenant use https://api. ο»Ώ | string | Required |
vanity_domain | Your organization's Zidentity vanity domain (the vanity part only, e.g. "acme"). Used to build the token endpoint https://<vanity_domain>.zslogin.net/oauth2/v1/token. | string | Required |
token_url | Optional full token endpoint URL. Overrides the URL derived from the vanity domain when set. | string | Optional |
client_id | The Zidentity API client ID. | string | Required |
private_key | The PEM-encoded RSA private key used to sign the JWT client assertion. The matching public key/certificate/JWKS must be registered on the Zidentity API client. | string | Required |
key_id | Optional key identifier placed in the JWT header. Set this when your Zidentity API client uses a JWKS URL with multiple keys. | string | Optional |
audience | The OAuth 2.0 audience for the token request. | string | Optional |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Activate Status
Activates the pending ZIA configuration changes made through the API.
Endpoint
- URL: zia/api/v1/status/activate
- Method: POST
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
Output Example
{"status":"active"}
Add Application Server
Adds a new ZPA application server for the specified customer.
Endpoint
- URL: zpa/mgmtconfig/v1/admin/customers/{{customerId}}/server
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.customerId | string | Required | The unique identifier of the ZPA tenant. |
parameters.microtenantId | string | Optional | The unique identifier of the Microtenant. Pass 0 for the Default Microtenant. |
name | string | Optional | The name of the application server. |
address | string | Optional | The domain or IP address of the server. |
enabled | boolean | Optional | Whether the server is enabled. |
description | string | Optional | A description of the server. |
appServerGroupIds | array | Optional | The list of server group IDs the server belongs to. |
configSpace | string | Optional | Parameter for Add Application Server |
microtenantId | string | Optional | Unique identifier |
Input Example
{"path_parameters":{"customerId":"string"},"parameters":{"microtenantId":"string"},"name":"Example Name","address":"string","enabled":true,"description":"string","appServerGroupIds":["string"],"configSpace":"string","microtenantId":"string"}
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
name | string | Name of the resource |
address | string | Output field: address |
enabled | boolean | Output field: enabled |
description | string | Output field: description |
appServerGroupIds | array | Unique identifier |
configSpace | string | Output field: configSpace |
microtenantId | string | Unique identifier |
microtenantName | string | Name of the resource |
creationTime | string | Time value |
modifiedTime | string | Time value |
modifiedBy | string | Output field: modifiedBy |
Output Example
{"id":"12345678-1234-1234-1234-123456789abc","name":"Example Name","address":"string","enabled":true,"description":"string","appServerGroupIds":["string"],"configSpace":"string","microtenantId":"string","microtenantName":"Example Name","creationTime":"string","modifiedTime":"string","modifiedBy":"string"}
Add IP Destination Group
Adds a new ZIA Cloud Firewall IP destination group.
Endpoint
- URL: zia/api/v1/ipDestinationGroups
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
name | string | Optional | The name of the IP destination group. |
type | string | Optional | The IP destination group type. DSTN_IP and DSTN_FQDN groups use the addresses field; DSTN_DOMAIN uses domain addresses; DSTN_OTHER uses countries and/or ipCategories. |
addresses | array | Optional | Destination IP addresses, ranges, CIDRs, FQDNs, or wildcard FQDNs. |
description | string | Optional | Additional information about the IP destination group. |
ipCategories | array | Optional | Destination IP address URL categories. |
countries | array | Optional | Destination countries (ISO 3166-1 alpha-2 with a COUNTRY_ prefix, e.g. COUNTRY_US). |
Input Example
{"name":"Example Name","type":"string","addresses":["string"],"description":"string","ipCategories":["string"],"countries":["string"]}
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
id | integer | Unique identifier |
name | string | Name of the resource |
type | string | Type of the resource |
addresses | array | Output field: addresses |
description | string | Output field: description |
ipCategories | array | Output field: ipCategories |
countries | array | Output field: countries |
isNonEditable | boolean | Output field: isNonEditable |
Output Example
{"id":123,"name":"Example Name","type":"string","addresses":["string"],"description":"string","ipCategories":["string"],"countries":["string"],"isNonEditable":true}
Add IP Source Group
Adds a new ZIA Cloud Firewall IP source group.
Endpoint
- URL: zia/api/v1/ipSourceGroups
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
name | string | Optional | The name of the IP source group. |
ipAddresses | array | Optional | Source IP addresses, ranges, or CIDRs in the group. |
description | string | Optional | Additional information about the IP source group. |
Input Example
{"name":"Example Name","ipAddresses":["string"],"description":"string"}
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
id | integer | Unique identifier |
name | string | Name of the resource |
ipAddresses | array | Output field: ipAddresses |
description | string | Output field: description |
isNonEditable | boolean | Output field: isNonEditable |
Output Example
{"id":123,"name":"Example Name","ipAddresses":["string"],"description":"string","isNonEditable":true}
Create Site
Creates a new ZPA site for the specified customer.
Endpoint
- URL: zpa/mgmtconfig/v1/admin/customers/{{customerId}}/site
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.customerId | string | Required | The unique identifier of the ZPA tenant. |
parameters.microtenantId | string | Optional | The unique identifier of the Microtenant. Pass 0 for the Default Microtenant. |
name | string | Optional | The name of the site. |
description | string | Optional | A description of the site. |
enabled | boolean | Optional | Whether the site is enabled. |
Input Example
{"path_parameters":{"customerId":"string"},"parameters":{"microtenantId":"string"},"name":"Example Name","description":"string","enabled":true}
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
name | string | Name of the resource |
description | string | Output field: description |
enabled | boolean | Output field: enabled |
microtenantId | string | Unique identifier |
microtenantName | string | Name of the resource |
creationTime | string | Time value |
modifiedTime | string | Time value |
modifiedBy | string | Output field: modifiedBy |
Output Example
{"id":"12345678-1234-1234-1234-123456789abc","name":"Example Name","description":"string","enabled":true,"microtenantId":"string","microtenantName":"Example Name","creationTime":"string","modifiedTime":"string","modifiedBy":"string"}
Delete Application Server
Deletes a ZPA application server by its ID.
Endpoint
- URL: zpa/mgmtconfig/v1/admin/customers/{{customerId}}/server/{{serverId}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.customerId | string | Required | The unique identifier of the ZPA tenant. |
path_parameters.serverId | string | Required | The unique identifier of the application server to delete. |
parameters.microtenantId | string | Optional | The unique identifier of the Microtenant. Pass 0 for the Default Microtenant. |
Input Example
{"path_parameters":{"customerId":"string","serverId":"string"},"parameters":{"microtenantId":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{}
Delete IP Destination Group
Deletes a ZIA Cloud Firewall IP destination group by its ID.
Endpoint
- URL: zia/api/v1/ipDestinationGroups/{{ipGroupId}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ipGroupId | integer | Required | The unique identifier of the IP destination group to delete. |
Input Example
{"path_parameters":{"ipGroupId":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{}
Delete IP Source Group
Deletes a ZIA Cloud Firewall IP source group by its ID.
Endpoint
- URL: zia/api/v1/ipSourceGroups/{{ipGroupId}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ipGroupId | integer | Required | The unique identifier of the IP source group to delete. |
Input Example
{"path_parameters":{"ipGroupId":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{}
Delete Site
Deletes a ZPA site by its ID.
Endpoint
- URL: zpa/mgmtconfig/v1/admin/customers/{{customerId}}/site/{{siteId}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.customerId | string | Required | The unique identifier of the ZPA tenant. |
path_parameters.siteId | string | Required | The unique identifier of the site to delete. |
parameters.microtenantId | string | Optional | The unique identifier of the Microtenant. Pass 0 for the Default Microtenant. |
Input Example
{"path_parameters":{"customerId":"string","siteId":"string"},"parameters":{"microtenantId":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{}
Edit IP Destination Group
Updates an existing ZIA Cloud Firewall IP destination group.
Endpoint
- URL: zia/api/v1/ipDestinationGroups/{{ipGroupId}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ipGroupId | integer | Required | The unique identifier of the IP destination group to update. |
name | string | Optional | The name of the IP destination group. |
type | string | Optional | The IP destination group type. |
addresses | array | Optional | Destination IP addresses, ranges, CIDRs, FQDNs, or wildcard FQDNs. |
description | string | Optional | Additional information about the IP destination group. |
ipCategories | array | Optional | Destination IP address URL categories. |
countries | array | Optional | Destination countries (ISO 3166-1 alpha-2 with a COUNTRY_ prefix, e.g. COUNTRY_US). |
Input Example
{"path_parameters":{"ipGroupId":123},"name":"Example Name","type":"string","addresses":["string"],"description":"string","ipCategories":["string"],"countries":["string"]}
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
id | integer | Unique identifier |
name | string | Name of the resource |
type | string | Type of the resource |
addresses | array | Output field: addresses |
description | string | Output field: description |
ipCategories | array | Output field: ipCategories |
countries | array | Output field: countries |
isNonEditable | boolean | Output field: isNonEditable |
Output Example
{"id":123,"name":"Example Name","type":"string","addresses":["string"],"description":"string","ipCategories":["string"],"countries":["string"],"isNonEditable":true}
Edit IP Source Group
Updates an existing ZIA Cloud Firewall IP source group.
Endpoint
- URL: zia/api/v1/ipSourceGroups/{{ipGroupId}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ipGroupId | integer | Required | The unique identifier of the IP source group to update. |
name | string | Optional | The name of the IP source group. |
ipAddresses | array | Optional | Source IP addresses, ranges, or CIDRs in the group. |
description | string | Optional | Additional information about the IP source group. |
Input Example
{"path_parameters":{"ipGroupId":123},"name":"Example Name","ipAddresses":["string"],"description":"string"}
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
id | integer | Unique identifier |
name | string | Name of the resource |
ipAddresses | array | Output field: ipAddresses |
description | string | Output field: description |
isNonEditable | boolean | Output field: isNonEditable |
Output Example
{"id":123,"name":"Example Name","ipAddresses":["string"],"description":"string","isNonEditable":true}
Get All Sites
Retrieves all ZPA sites for the specified customer.
Endpoint
- URL: zpa/mgmtconfig/v1/admin/customers/{{customerId}}/site
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.customerId | string | Required | The unique identifier of the ZPA tenant. |
parameters.microtenantId | string | Optional | The unique identifier of the Microtenant. Pass 0 for the Default Microtenant. |
parameters.search | string | Optional | Filter the results by matching against site fields. |
parameters.page | integer | Optional | The page number to return. |
parameters.pagesize | integer | Optional | The number of sites per page (default 20, max 500). |
Input Example
{"path_parameters":{"customerId":"string"},"parameters":{"microtenantId":"string","search":"string","page":123,"pagesize":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
totalPages | string | Output field: totalPages |
totalCount | string | Count value |
list | array | Output field: list |
list.id | string | Unique identifier |
list.name | string | Name of the resource |
list.description | string | Output field: list.description |
list.enabled | boolean | Output field: list.enabled |
list.microtenantId | string | Unique identifier |
list.microtenantName | string | Name of the resource |
list.creationTime | string | Time value |
list.modifiedTime | string | Time value |
list.modifiedBy | string | Output field: list.modifiedBy |
Output Example
{"totalPages":"string","totalCount":"string","list":[{"id":"12345678-1234-1234-1234-123456789abc","name":"Example Name","description":"string","enabled":true,"microtenantId":"string","microtenantName":"Example Name","creationTime":"string","modifiedTime":"string","modifiedBy":"string"}]}
Get Application Server
Retrieves the details of a ZPA application server by its ID.
Endpoint
- URL: zpa/mgmtconfig/v1/admin/customers/{{customerId}}/server/{{serverId}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.customerId | string | Required | The unique identifier of the ZPA tenant. |
path_parameters.serverId | string | Required | The unique identifier of the application server. |
parameters.microtenantId | string | Optional | The unique identifier of the Microtenant. Pass 0 for the Default Microtenant. |
Input Example
{"path_parameters":{"customerId":"string","serverId":"string"},"parameters":{"microtenantId":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
name | string | Name of the resource |
address | string | Output field: address |
enabled | boolean | Output field: enabled |
description | string | Output field: description |
appServerGroupIds | array | Unique identifier |
configSpace | string | Output field: configSpace |
microtenantId | string | Unique identifier |
microtenantName | string | Name of the resource |
creationTime | string | Time value |
modifiedTime | string | Time value |
modifiedBy | string | Output field: modifiedBy |
Output Example
{"id":"12345678-1234-1234-1234-123456789abc","name":"Example Name","address":"string","enabled":true,"description":"string","appServerGroupIds":["string"],"configSpace":"string","microtenantId":"string","microtenantName":"Example Name","creationTime":"string","modifiedTime":"string","modifiedBy":"string"}
Get CTP Config
Retrieves the ZIA Advanced Threat Protection (Cyber Threat Protection) policy configuration.
Endpoint
- URL: zia/api/v1/cyberThreatProtection/advancedThreatSettings
- Method: GET
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{}
Get CTP Malicious URLs
Retrieves the malicious URLs added to the denylist in the ZIA Cyber Threat Protection (ATP) policy.
Endpoint
- URL: zia/api/v1/cyberThreatProtection/maliciousUrls
- Method: GET
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
maliciousUrls | array | URL endpoint for the request |
Output Example
{"maliciousUrls":["string"]}
Get CTP Security Exceptions
Retrieves the URLs bypassed (allowlisted) by the ZIA Cyber Threat Protection (ATP) policy.
Endpoint
- URL: zia/api/v1/cyberThreatProtection/securityExceptions
- Method: GET
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
bypassUrls | array | URL endpoint for the request |
Output Example
{"bypassUrls":["string"]}
Get IP Destination Group by ID
Retrieves a ZIA Cloud Firewall IP destination group by its ID.
Endpoint
- URL: zia/api/v1/ipDestinationGroups/{{ipGroupId}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ipGroupId | integer | Required | The unique identifier of the IP destination group. |
Input Example
{"path_parameters":{"ipGroupId":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
id | integer | Unique identifier |
name | string | Name of the resource |
type | string | Type of the resource |
addresses | array | Output field: addresses |
description | string | Output field: description |
ipCategories | array | Output field: ipCategories |
countries | array | Output field: countries |
isNonEditable | boolean | Output field: isNonEditable |
Output Example
{"id":123,"name":"Example Name","type":"string","addresses":["string"],"description":"string","ipCategories":["string"],"countries":["string"],"isNonEditable":true}
Get IP Source Group by ID
Retrieves a ZIA Cloud Firewall IP source group by its ID.
Endpoint
- URL: zia/api/v1/ipSourceGroups/{{ipGroupId}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ipGroupId | integer | Required | The unique identifier of the IP source group. |
Input Example
{"path_parameters":{"ipGroupId":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
id | integer | Unique identifier |
name | string | Name of the resource |
ipAddresses | array | Output field: ipAddresses |
description | string | Output field: description |
isNonEditable | boolean | Output field: isNonEditable |
Output Example
{"id":123,"name":"Example Name","ipAddresses":["string"],"description":"string","isNonEditable":true}
Get IP Source Groups (Lite)
Retrieves a lightweight list of ZIA Cloud Firewall IP source groups (ID and name only).
Endpoint
- URL: zia/api/v1/ipSourceGroups/lite
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.search | string | Optional | Filter the results by matching against the group name. |
parameters.page | integer | Optional | The page offset to return. |
parameters.pageSize | integer | Optional | The number of groups per page (default 100, max 1000). |
Input Example
{"parameters":{"search":"string","page":123,"pageSize":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
[]
Get Site by ID
Retrieves the details of a ZPA site by its ID.
Endpoint
- URL: zpa/mgmtconfig/v1/admin/customers/{{customerId}}/site/{{siteId}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.customerId | string | Required | The unique identifier of the ZPA tenant. |
path_parameters.siteId | string | Required | The unique identifier of the site. |
parameters.microtenantId | string | Optional | The unique identifier of the Microtenant. Pass 0 for the Default Microtenant. |
Input Example
{"path_parameters":{"customerId":"string","siteId":"string"},"parameters":{"microtenantId":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
name | string | Name of the resource |
description | string | Output field: description |
enabled | boolean | Output field: enabled |
microtenantId | string | Unique identifier |
microtenantName | string | Name of the resource |
creationTime | string | Time value |
modifiedTime | string | Time value |
modifiedBy | string | Output field: modifiedBy |
Output Example
{"id":"12345678-1234-1234-1234-123456789abc","name":"Example Name","description":"string","enabled":true,"microtenantId":"string","microtenantName":"Example Name","creationTime":"string","modifiedTime":"string","modifiedBy":"string"}
List IP Destination Groups
Retrieves a list of ZIA Cloud Firewall IP destination groups.
Endpoint
- URL: zia/api/v1/ipDestinationGroups
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.type | string | Optional | Filter the groups by destination group type. |
parameters.page | integer | Optional | The page offset to return. |
parameters.pageSize | integer | Optional | The number of groups per page (default 100, max 1000). |
Input Example
{"parameters":{"type":"string","page":123,"pageSize":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
[]
List IP Source Groups
Retrieves a list of ZIA Cloud Firewall IP source groups.
Endpoint
- URL: zia/api/v1/ipSourceGroups
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.search | string | Optional | Filter the results by matching against the group name. |
parameters.page | integer | Optional | The page offset to return. |
parameters.pageSize | integer | Optional | The number of groups per page (default 100, max 1000). |
Input Example
{"parameters":{"search":"string","page":123,"pageSize":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
[]
Update Application Server
Updates the details of a ZPA application server by its ID.
Endpoint
- URL: zpa/mgmtconfig/v1/admin/customers/{{customerId}}/server/{{serverId}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.customerId | string | Required | The unique identifier of the ZPA tenant. |
path_parameters.serverId | string | Required | The unique identifier of the application server to update. |
parameters.microtenantId | string | Optional | The unique identifier of the Microtenant. Pass 0 for the Default Microtenant. |
name | string | Optional | The name of the application server. |
address | string | Optional | The domain or IP address of the server. |
enabled | boolean | Optional | Whether the server is enabled. |
description | string | Optional | A description of the server. |
appServerGroupIds | array | Optional | The list of server group IDs the server belongs to. |
configSpace | string | Optional | Parameter for Update Application Server |
microtenantId | string | Optional | Unique identifier |
Input Example
{"path_parameters":{"customerId":"string","serverId":"string"},"parameters":{"microtenantId":"string"},"name":"Example Name","address":"string","enabled":true,"description":"string","appServerGroupIds":["string"],"configSpace":"string","microtenantId":"string"}
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
name | string | Name of the resource |
address | string | Output field: address |
enabled | boolean | Output field: enabled |
description | string | Output field: description |
appServerGroupIds | array | Unique identifier |
configSpace | string | Output field: configSpace |
microtenantId | string | Unique identifier |
microtenantName | string | Name of the resource |
creationTime | string | Time value |
modifiedTime | string | Time value |
modifiedBy | string | Output field: modifiedBy |
Output Example
{"id":"12345678-1234-1234-1234-123456789abc","name":"Example Name","address":"string","enabled":true,"description":"string","appServerGroupIds":["string"],"configSpace":"string","microtenantId":"string","microtenantName":"Example Name","creationTime":"string","modifiedTime":"string","modifiedBy":"string"}
Update CTP Config
Updates the ZIA Advanced Threat Protection (Cyber Threat Protection) policy configuration. Send the full settings object; retrieve it first with Get CTP Config and modify the fields you need.
Endpoint
- URL: zia/api/v1/cyberThreatProtection/advancedThreatSettings
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
riskTolerance | integer | Optional | The maximum risk score allowed. |
riskToleranceCapture | boolean | Optional | Parameter for Update CTP Config |
cmdCtlServerBlocked | boolean | Optional | Parameter for Update CTP Config |
cmdCtlServerCapture | boolean | Optional | Parameter for Update CTP Config |
cmdCtlTrafficBlocked | boolean | Optional | Parameter for Update CTP Config |
cmdCtlTrafficCapture | boolean | Optional | Parameter for Update CTP Config |
malwareSitesBlocked | boolean | Optional | Parameter for Update CTP Config |
malwareSitesCapture | boolean | Optional | Parameter for Update CTP Config |
activeXBlocked | boolean | Optional | Parameter for Update CTP Config |
activeXCapture | boolean | Optional | Parameter for Update CTP Config |
browserExploitsBlocked | boolean | Optional | Parameter for Update CTP Config |
browserExploitsCapture | boolean | Optional | Parameter for Update CTP Config |
fileFormatVunerabilitesBlocked | boolean | Optional | Parameter for Update CTP Config |
fileFormatVunerabilitesCapture | boolean | Optional | Parameter for Update CTP Config |
knownPhishingSitesBlocked | boolean | Optional | Parameter for Update CTP Config |
knownPhishingSitesCapture | boolean | Optional | Parameter for Update CTP Config |
suspectedPhishingSitesBlocked | boolean | Optional | Parameter for Update CTP Config |
suspectedPhishingSitesCapture | boolean | Optional | Parameter for Update CTP Config |
suspectAdwareSpywareSitesBlocked | boolean | Optional | Parameter for Update CTP Config |
suspectAdwareSpywareSitesCapture | boolean | Optional | Parameter for Update CTP Config |
webspamBlocked | boolean | Optional | Parameter for Update CTP Config |
webspamCapture | boolean | Optional | Parameter for Update CTP Config |
ircTunnellingBlocked | boolean | Optional | Parameter for Update CTP Config |
ircTunnellingCapture | boolean | Optional | Parameter for Update CTP Config |
anonymizerBlocked | boolean | Optional | Parameter for Update CTP Config |
Input Example
{"riskTolerance":123,"riskToleranceCapture":true,"cmdCtlServerBlocked":true,"cmdCtlServerCapture":true,"cmdCtlTrafficBlocked":true,"cmdCtlTrafficCapture":true,"malwareSitesBlocked":true,"malwareSitesCapture":true,"activeXBlocked":true,"activeXCapture":true,"browserExploitsBlocked":true,"browserExploitsCapture":true,"fileFormatVunerabilitesBlocked":true,"fileFormatVunerabilitesCapture":true,"knownPhishingSitesBlocked":true,"knownPhishingSitesCapture":true,"suspectedPhishingSitesBlocked":true,"suspectedPhishingSitesCapture":true,"suspectAdwareSpywareSitesBlocked":true,"suspectAdwareSpywareSitesCapture":true,"webspamBlocked":true,"webspamCapture":true,"ircTunnellingBlocked":true,"ircTunnellingCapture":true,"anonymizerBlocked":true,"anonymizerCapture":true,"cookieStealingBlocked":true,"cookieStealingCapture":true,"potentialMaliciousRequestsBlocked":true,"potentialMaliciousRequestsCapture":true,"blockedCountries":["string"],"bitTorrentBlocked":true,"bitTorrentCapture":true,"torBlocked":true,"torCapture":true,"googleTalkBlocked":true,"googleTalkCapture":true,"sshTunnellingBlocked":true,"sshTunnellingCapture":true,"cryptoMiningBlocked":true,"cryptoMiningCapture":true,"adSpywareSitesBlocked":true,"adSpywareSitesCapture":true,"dgaDomainsBlocked":true,"dgaDomainsCapture":true,"alertForUnknownOrSuspiciousC2Traffic":true,"maliciousUrlsCapture":true}
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{}
Update CTP Malicious URLs
Updates the malicious URLs added to the denylist in the ZIA Cyber Threat Protection (ATP) policy. Use the action query parameter to add or remove URLs.
Endpoint
- URL: zia/api/v1/cyberThreatProtection/maliciousUrls
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.action | string | Optional | Whether to add the URLs to or remove them from the denylist. |
maliciousUrls | array | Optional | List of URLs treated as malicious by the ATP policy. |
Input Example
{"parameters":{"action":"string"},"maliciousUrls":["string"]}
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
maliciousUrls | array | URL endpoint for the request |
Output Example
{"maliciousUrls":["string"]}
Update CTP Security Exceptions
Updates the list of URLs bypassed (allowlisted) by the ZIA Cyber Threat Protection (ATP) policy. Send the full list of bypass URLs.
Endpoint
- URL: zia/api/v1/cyberThreatProtection/securityExceptions
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
bypassUrls | array | Optional | Allowlist URLs that are not inspected by the ATP policy. |
Input Example
{"bypassUrls":["string"]}
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
bypassUrls | array | URL endpoint for the request |
Output Example
{"bypassUrls":["string"]}
Update Site
Updates the details of a ZPA site by its ID.
Endpoint
- URL: zpa/mgmtconfig/v1/admin/customers/{{customerId}}/site/{{siteId}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.customerId | string | Required | The unique identifier of the ZPA tenant. |
path_parameters.siteId | string | Required | The unique identifier of the site to update. |
parameters.microtenantId | string | Optional | The unique identifier of the Microtenant. Pass 0 for the Default Microtenant. |
name | string | Optional | The name of the site. |
description | string | Optional | A description of the site. |
enabled | boolean | Optional | Whether the site is enabled. |
Input Example
{"path_parameters":{"customerId":"string","siteId":"string"},"parameters":{"microtenantId":"string"},"name":"Example Name","description":"string","enabled":true}
Output
Parameter | Type | Description |
|---|---|---|
status_code | integer | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
name | string | Name of the resource |
description | string | Output field: description |
enabled | boolean | Output field: enabled |
microtenantId | string | Unique identifier |
microtenantName | string | Name of the resource |
creationTime | string | Time value |
modifiedTime | string | Time value |
modifiedBy | string | Output field: modifiedBy |
Output Example
{"id":"12345678-1234-1234-1234-123456789abc","name":"Example Name","description":"string","enabled":true,"microtenantId":"string","microtenantName":"Example Name","creationTime":"string","modifiedTime":"string","modifiedBy":"string"}
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |