> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/restore-distributions/restore-distributions.md).

# Restore Distributions

Restore a previously deleted agent installation package by its distribution ID.

## Restore a deleted agent installation package

> Restores a previously deleted agent installation package (distribution), re-enabling agent registration for agents that reference it.\
> \
> A distribution can be deleted via the \[Delete agent installation packages]\(<https://app.gitbook.com/s/ZuJbX2x7VQJhNovscCwE/cortex-platform/endpoint-management#post-public\\_api-v1-distributions-delete>) API or from the \*\*Agent Installations\*\* screen in Cortex Cloud. Restoring the distribution re-enables agent registration.\
> \
> If the distribution is already in an active (non-deleted) state, the API returns a message indicating it is already restored rather than returning an error.\
> \
> \*\*Required license:\*\* Cortex Cloud Runtime Security. In Cortex Cloud Posture Security, you need the Cortex Cloud Runtime Security add-on.

```json
{"openapi":"3.0.3","info":{"title":"Restore Distributions Public API","version":"Cortex Cloud"},"tags":[{"name":"RestoreDistributions","description":"Restore a previously deleted agent installation package by its distribution ID."}],"servers":[{"url":"https://api-yourfqdn"}],"security":[{"ApiKeyAuth":[],"ApiKeyIdAuth":[]}],"components":{"securitySchemes":{"ApiKeyAuth":{"type":"apiKey","in":"header","name":"Authorization","description":"API key for authenticating requests. Pass the API key in the `Authorization` header."}},"schemas":{"RestoreDistributionRequest":{"type":"object","description":"Request body for restoring a deleted distribution.","required":["request_data"],"properties":{"request_data":{"type":"object","description":"Container for the restore request parameters.","required":["distribution_id"],"properties":{"distribution_id":{"type":"string","description":"The unique identifier of the distribution to restore. You can find this ID in the [Create distributions](https://app.gitbook.com/s/ZuJbX2x7VQJhNovscCwE/cortex-platform/endpoint-management#post-public_api-v1-distributions-create) API response, the [Get distributions](https://app.gitbook.com/s/ZuJbX2x7VQJhNovscCwE/cortex-platform/endpoint-management#post-public_api-v1-distributions-get_distributions) API response, or in the **Agent Installations** screen in Cortex Cloud.","minLength":1}}}}},"RestoreDistributionResponse":{"type":"object","description":"Response returned after a restore operation is processed.","properties":{"reply":{"type":"string","description":"A human-readable message describing the outcome of the restore operation. Returns `\"Successfully restored distribution <id>\"` when the distribution was restored, or `\"Distribution <id> is already restored\"` when the distribution was already in an active state."}}},"ErrorResponse":{"type":"object","description":"Standard error response returned when the request cannot be processed.","properties":{"reply":{"type":"object","description":"Error details.","properties":{"err_code":{"type":"integer","description":"HTTP status code of the error."},"err_msg":{"type":"string","description":"Human-readable description of the error."},"err_extra":{"type":"string","description":"Additional context or diagnostic information about the error."}}}}}}},"paths":{"/public_api/v1/distributions/restore":{"post":{"operationId":"restoreDistribution","summary":"Restore a deleted agent installation package","description":"Restores a previously deleted agent installation package (distribution), re-enabling agent registration for agents that reference it.\n\nA distribution can be deleted via the [Delete agent installation packages](https://app.gitbook.com/s/ZuJbX2x7VQJhNovscCwE/cortex-platform/endpoint-management#post-public_api-v1-distributions-delete) API or from the **Agent Installations** screen in Cortex Cloud. Restoring the distribution re-enables agent registration.\n\nIf the distribution is already in an active (non-deleted) state, the API returns a message indicating it is already restored rather than returning an error.\n\n**Required license:** Cortex Cloud Runtime Security. In Cortex Cloud Posture Security, you need the Cortex Cloud Runtime Security add-on.","tags":["RestoreDistributions"],"parameters":[{"name":"Authorization","in":"header","description":"API key for authentication.","required":true,"schema":{"type":"string"}},{"name":"x-xdr-auth-id","in":"header","description":"API key ID for authentication.","required":true,"schema":{"type":"string"}}],"requestBody":{"required":true,"description":"Request body containing the distribution ID to restore.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/RestoreDistributionRequest"}}}},"responses":{"200":{"description":"The restore operation was processed. The `reply` field contains a message indicating whether the distribution was successfully restored or was already in an active state.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/RestoreDistributionResponse"}}}},"400":{"description":"Bad request. The `distribution_id` is missing or malformed.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}},"401":{"description":"Unauthorized. The API key or key ID is missing or invalid.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}},"403":{"description":"Forbidden. The API key does not have permission to restore distributions.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}},"404":{"description":"Not found. No distribution exists with the specified `distribution_id`.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}},"500":{"description":"Internal server error. An unexpected error occurred while processing the restore request.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}}}}}}}
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/restore-distributions/restore-distributions.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
