> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/web-and-api-security-waas.md).

# Web and API Security (WAAS)

- [Overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/web-and-api-security-waas/overview.md): Protect APIs and web applications through discovery, posture management, and threat detection.
- [Personas workflow](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/web-and-api-security-waas/personas-workflow.md): Cortex API security distributes responsibilities across SOC analysts, security practitioners, and workload owners.
- [Secure your API landscape](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/web-and-api-security-waas/secure-your-api-landscape.md): Integrate API gateways to monitor API traffic, assess risks, and enforce security.
- [Gain visibility and assess risk of API endpoints](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/web-and-api-security-waas/secure-your-api-landscape/gain-visibility-and-assess-risk-of-api-endpoints.md): Discover API endpoints, assess risk, and investigate endpoint details across your environment.
- [Monitor and investigate API threats](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/web-and-api-security-waas/secure-your-api-landscape/monitor-and-investigate-api-threats.md): Detect, investigate, and respond to API threats with SOC analyst workflows.
- [Configure API security from end to end](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/web-and-api-security-waas/secure-your-api-landscape/configure-api-security-from-end-to-end.md): Secure your API landscape through third-party integrations and agent-based protection policies.
- [API specification inventory](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/web-and-api-security-waas/secure-your-api-landscape/api-specification-inventory.md): Import OpenAPI specifications, assess vulnerabilities, and validate live API traffic.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/web-and-api-security-waas.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
