For the complete documentation index, see llms.txt. This page is also available as Markdown.

Cortex API Documentation

Explore and integrate with the Cortex platform APIs

Welcome to the Cortex API documentation. This area is the central reference for APIs across the Cortex platform.

API Reference By Product

Choose a Cortex product below to jump to its API reference.

Developers use the Cortex APIs to:

  • Automate incident and case management - Retrieve, search, create, and update issues and cases, then push security findings into your SOAR, ticketing, or automation workflows.

  • Query your data with XQL - Run Cortex Query Language (XQL) queries programmatically for threat hunting and analytics, and pull results into custom reports and dashboards.

  • Ingest and stream security data - Ingest alerts, assets, and telemetry, and stream data to external destinations such as SIEMs, webhooks, and data lakes for centralized monitoring.

  • Manage cloud security posture - Onboard cloud accounts and evaluate posture across CSPM, CWP, DSPM, and CIEM, including vulnerability management across cloud, endpoints, and code.

  • Embed security into CI/CD - Manage applications, repositories, detection rules, and scans to shift application security (AppSec/ASPM) left into your development pipelines.

  • Administer identity and access - Programmatically manage roles, user groups, users, API keys, and scope-based access control (SBAC) across the Cortex platform.


Join the Discussion

Join the Palo Alto Networks Live Community to post questions, get help, and share resources with other Cortex developers.

Join the community