> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/scripts.md).

# Scripts

APIs for managing scripts

## Get details about a specific script

> Retrieve detailed information about the specified script. You can use the script name or script ID as the path parameter to identify the script.

```json
{"openapi":"3.0.1","info":{"title":"Cortex XSOAR 8 API","version":"XSOAR 8 Cloud"},"tags":[{"name":"Scripts","description":"APIs for managing scripts"}],"servers":[{"url":"https://api-yourfqdn","description":""}],"paths":{"/xsoar/public/v1/automation/load/{script_id}":{"post":{"tags":["Scripts"],"summary":"Get details about a specific script","description":"Retrieve detailed information about the specified script. You can use the script name or script ID as the path parameter to identify the script.","operationId":"post-automation-load-script_id","parameters":[{"name":"script_id","in":"path","description":"Script name or ID","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"type":"object","properties":{"MainEngineInfo":{"type":"object","properties":{"engine":{"type":"string"},"engineGroup":{"type":"string"}}},"arguments":{"type":"array","items":{"type":"object","properties":{"default":{"type":"boolean"},"defaultValue":{"type":"string"},"deprecated":{"type":"boolean"},"description":{"type":"string"},"hidden":{"type":"boolean"},"name":{"type":"string"},"required":{"type":"boolean"},"secret":{"type":"boolean"},"type":{"type":"string"}}}},"cacheVersn":{"type":"integer"},"comment":{"type":"string"},"commitMessage":{"type":"string"},"contextKeys":{"type":"array","items":{"type":"object","properties":{}}},"definitionId":{"type":"string"},"deprecated":{"type":"boolean"},"detached":{"type":"boolean"},"dockerImage":{"type":"string"},"enabled":{"type":"boolean"},"engine":{"type":"string"},"engineGroup":{"type":"string"},"fromServerVersion":{"type":"string"},"id":{"type":"string"},"itemVersion":{"type":"string"},"locked":{"type":"boolean"},"modified":{"type":"string"},"name":{"type":"string"},"packID":{"type":"string"},"packName":{"type":"string"},"packPropagationLabels":{"type":"array","items":{"type":"string"}},"permitted":{"type":"boolean"},"prevName":{"type":"string"},"primaryTerm":{"type":"integer"},"propagationLabels":{"type":"array","items":{"type":"object","properties":{}}},"pswd":{"type":"string"},"pswdProtected":{"type":"boolean"},"rawTags":{"type":"array","items":{"type":"string"}},"runAs":{"type":"string"},"runOnce":{"type":"boolean"},"script":{"type":"string"},"scriptTarget":{"type":"integer"},"searchableName":{"type":"string"},"sensitive":{"type":"boolean"},"sequenceNumber":{"type":"integer"},"shouldCommit":{"type":"boolean"},"subtype":{"type":"string"},"system":{"type":"boolean"},"tags":{"type":"array","items":{"type":"string"}},"timeout":{"type":"integer"},"toServerVersion":{"type":"string"},"type":{"type":"string"},"user":{"type":"string"},"vcShouldIgnore":{"type":"boolean"},"vcShouldKeepItemLegacyProdMachine":{"type":"boolean"},"version":{"type":"integer"},"visualScript":{"type":"string"}}}}}}}}}}}
```

## Get metadata details about all scripts in this tenant

> Retrieve the metadata details for all scripts in this Cortex XSOAR tenant. Depending on the number of scripts in the instance, the response can be very large.

```json
{"openapi":"3.0.1","info":{"title":"Cortex XSOAR 8 API","version":"XSOAR 8 Cloud"},"tags":[{"name":"Scripts","description":"APIs for managing scripts"}],"servers":[{"url":"https://api-yourfqdn","description":""}],"paths":{"/xsoar/public/v1/automation/metadata":{"get":{"tags":["Scripts"],"summary":"Get metadata details about all scripts in this tenant","description":"Retrieve the metadata details for all scripts in this Cortex XSOAR tenant. Depending on the number of scripts in the instance, the response can be very large.","operationId":"get-xsoar-automation-metadata","responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"type":"array","items":{"type":"object","properties":{"id":{"type":"string"},"version":{"type":"integer"},"name":{"type":"string"},"type":{"type":"string"},"tags":{"type":"array","items":{"type":"string"}},"contextKeys":{"type":"array","items":{"type":"object","properties":{}}},"comment":{"type":"string"},"enabled":{"type":"boolean"},"system":{"type":"boolean"},"detached":{"type":"boolean"},"locked":{"type":"boolean"},"user":{"type":"string"},"dockerImage":{"type":"string"},"modified":{"type":"string"},"scriptTarget":{"type":"integer"},"arguments":{"type":"array","items":{"type":"object","properties":{"name":{"type":"string"},"required":{"type":"boolean"},"deprecated":{"type":"boolean"},"hidden":{"type":"boolean"},"default":{"type":"boolean"},"secret":{"type":"boolean"},"auto":{"type":"string"},"predefined":{"type":"array","items":{"type":"string"}},"description":{"type":"string"},"type":{"type":"string"}}}},"runAs":{"type":"string"},"outputs":{"type":"array","items":{"type":"object","properties":{"contentPath":{"type":"string"},"contextPath":{"type":"string"},"description":{"type":"string"},"type":{"type":"string"}}}},"permitted":{"type":"boolean"}}}}}}}}}}}}
```

## Search scripts

> Search scripts using a filter.

```json
{"openapi":"3.0.1","info":{"title":"Cortex XSOAR 8 API","version":"XSOAR 8 Cloud"},"tags":[{"name":"Scripts","description":"APIs for managing scripts"}],"servers":[{"url":"https://api-yourfqdn","description":""}],"paths":{"/xsoar/public/v1/automation/search":{"post":{"tags":["Scripts"],"summary":"Search scripts","description":"Search scripts using a filter.","operationId":"post-xsoar-automation-search","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/automationScriptFilter"}}},"required":false},"responses":{"200":{"description":"OK automationScriptResult","content":{"application/json":{"schema":{"$ref":"#/components/schemas/automationScriptResult"}}}}}}}},"components":{"schemas":{"automationScriptFilter":{"type":"object","properties":{"Cache":{"type":"object","additionalProperties":{"type":"array","items":{"type":"string"}},"description":"Cache of join functions"},"ignoreWorkers":{"type":"boolean","description":"Do not use workers mechanism while searching bleve"},"page":{"type":"integer","description":"0-based page","format":"int64"},"query":{"type":"string"},"searchAfter":{"type":"array","description":"Efficient next page, pass max sort value from previous page","items":{"type":"string"}},"searchAfterElastic":{"type":"array","description":"Efficient next page, pass max ES sort value from previous page","items":{"type":"string"}},"searchAfterMap":{"type":"object","additionalProperties":{"type":"array","items":{"type":"string"}},"description":"Map accounts search after values - stores next page sort values per account.\nThere is no need to store searchBeforeMap as [current page searchBefore] equals to [prev page searchAfter]\nMore, there is no way to generate correct searchBefore from current page as some tenants may not appear at all.\nThe map is relevant in proxy mode and used by tenants, each tenant extracts the searchAfter keys from the map."},"searchAfterMapOrder":{"type":"object","additionalProperties":{"type":"integer","format":"int64"}},"searchBefore":{"type":"array","description":"Efficient prev page, pass min sort value from next page","items":{"type":"string"}},"searchBeforeElastic":{"type":"array","description":"Efficient prev page, pass min ES sort value from next page","items":{"type":"string"}},"size":{"type":"integer","description":"Size is limited to 1000, if not passed it defaults to 0, and no results will return","format":"int64"},"sort":{"type":"array","description":"The sort order","items":{"$ref":"#/components/schemas/Order"}},"stripContext":{"type":"boolean"}},"description":"automationScriptFilter is a general filter that fetches entities using a query string query using the Query value"},"Order":{"title":"Order","type":"object","properties":{"asc":{"type":"boolean"},"field":{"type":"string"},"fieldType":{"type":"string"}},"description":"Order structure holds a sort field and the direction of sorting"},"automationScriptResult":{"title":"automationScriptResult ...","type":"object","properties":{"pythonEnabled":{"type":"boolean"},"scripts":{"type":"array","items":{"$ref":"#/components/schemas/ScriptAPI"}},"selectedScript":{"type":"object","additionalProperties":{"type":"object","properties":{}}},"suggestions":{"type":"array","items":{"type":"string"}}}},"ScriptAPI":{"title":"ScriptAPI ...","type":"object","properties":{"arguments":{"type":"array","items":{"$ref":"#/components/schemas/Argument"}},"comment":{"type":"string"},"contextKeys":{"type":"array","items":{"type":"string"}},"dependsOn":{"type":"object","additionalProperties":{"type":"array","items":{"type":"string"}}},"deprecated":{"type":"boolean"},"detached":{"type":"boolean"},"dockerImage":{"type":"string"},"enabled":{"type":"boolean"},"hidden":{"type":"boolean"},"id":{"type":"string"},"locked":{"type":"boolean"},"modified":{"type":"string","format":"date-time"},"name":{"type":"string"},"outputs":{"type":"array","items":{"$ref":"#/components/schemas/Output"}},"permitted":{"type":"boolean"},"polling":{"type":"boolean"},"propagationLabels":{"type":"array","items":{"type":"string"}},"roles":{"type":"array","items":{"type":"string"}},"runAs":{"type":"string"},"scriptTarget":{"$ref":"#/components/schemas/ScriptTarget"},"system":{"type":"boolean"},"tags":{"type":"array","items":{"type":"string"}},"type":{"$ref":"#/components/schemas/ScriptType"},"user":{"type":"string"},"version":{"type":"integer","format":"int64"}}},"Argument":{"type":"object","properties":{"auto":{"type":"string"},"default":{"type":"boolean"},"defaultValue":{"type":"string"},"deprecated":{"type":"boolean"},"description":{"type":"string"},"hidden":{"type":"boolean"},"isArray":{"type":"boolean"},"name":{"type":"string"},"predefined":{"type":"array","items":{"type":"string"}},"required":{"type":"boolean"},"secret":{"type":"boolean"},"type":{"$ref":"#/components/schemas/ArgumentType"}},"description":"Argument to a module command"},"ArgumentType":{"title":"ArgumentType ...","type":"string"},"Output":{"type":"object","properties":{"contentPath":{"type":"string"},"contextPath":{"type":"string"},"description":{"type":"object","properties":{},"description":"Description is either a string or a map from string to interface"},"type":{"$ref":"#/components/schemas/OutputType"}},"description":"Output of a module command"},"OutputType":{"title":"OutputType ...","type":"string"},"ScriptTarget":{"type":"integer","description":"ScriptTarget represents the module where this script should run","format":"int64"},"ScriptType":{"type":"string","description":"ScriptType holds the type of a script"}}}}
```

## Create or update a script

> Create or update a script.

```json
{"openapi":"3.0.1","info":{"title":"Cortex XSOAR 8 API","version":"XSOAR 8 Cloud"},"tags":[{"name":"Scripts","description":"APIs for managing scripts"}],"servers":[{"url":"https://api-yourfqdn","description":""}],"paths":{"/xsoar/public/v1/automation":{"post":{"summary":"Create or update a script","responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"$ref":"#/components/schemas/automationScriptResult"}}}}},"operationId":"post-auotmation","parameters":[{"schema":{"type":"string"},"in":"header","name":"authorization","description":"api_key","required":true},{"schema":{"type":"string"},"in":"header","name":"x-xdr-auth-id","description":"api_key_id","required":true}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/automationScriptFilterWrapper"}}}},"description":"Create or update a script.","tags":["Scripts"]}}},"components":{"schemas":{"automationScriptResult":{"title":"automationScriptResult ...","type":"object","properties":{"pythonEnabled":{"type":"boolean"},"scripts":{"type":"array","items":{"$ref":"#/components/schemas/ScriptAPI"}},"selectedScript":{"type":"object","additionalProperties":{"type":"object","properties":{}}},"suggestions":{"type":"array","items":{"type":"string"}}}},"ScriptAPI":{"title":"ScriptAPI ...","type":"object","properties":{"arguments":{"type":"array","items":{"$ref":"#/components/schemas/Argument"}},"comment":{"type":"string"},"contextKeys":{"type":"array","items":{"type":"string"}},"dependsOn":{"type":"object","additionalProperties":{"type":"array","items":{"type":"string"}}},"deprecated":{"type":"boolean"},"detached":{"type":"boolean"},"dockerImage":{"type":"string"},"enabled":{"type":"boolean"},"hidden":{"type":"boolean"},"id":{"type":"string"},"locked":{"type":"boolean"},"modified":{"type":"string","format":"date-time"},"name":{"type":"string"},"outputs":{"type":"array","items":{"$ref":"#/components/schemas/Output"}},"permitted":{"type":"boolean"},"polling":{"type":"boolean"},"propagationLabels":{"type":"array","items":{"type":"string"}},"roles":{"type":"array","items":{"type":"string"}},"runAs":{"type":"string"},"scriptTarget":{"$ref":"#/components/schemas/ScriptTarget"},"system":{"type":"boolean"},"tags":{"type":"array","items":{"type":"string"}},"type":{"$ref":"#/components/schemas/ScriptType"},"user":{"type":"string"},"version":{"type":"integer","format":"int64"}}},"Argument":{"type":"object","properties":{"auto":{"type":"string"},"default":{"type":"boolean"},"defaultValue":{"type":"string"},"deprecated":{"type":"boolean"},"description":{"type":"string"},"hidden":{"type":"boolean"},"isArray":{"type":"boolean"},"name":{"type":"string"},"predefined":{"type":"array","items":{"type":"string"}},"required":{"type":"boolean"},"secret":{"type":"boolean"},"type":{"$ref":"#/components/schemas/ArgumentType"}},"description":"Argument to a module command"},"ArgumentType":{"title":"ArgumentType ...","type":"string"},"Output":{"type":"object","properties":{"contentPath":{"type":"string"},"contextPath":{"type":"string"},"description":{"type":"object","properties":{},"description":"Description is either a string or a map from string to interface"},"type":{"$ref":"#/components/schemas/OutputType"}},"description":"Output of a module command"},"OutputType":{"title":"OutputType ...","type":"string"},"ScriptTarget":{"type":"integer","description":"ScriptTarget represents the module where this script should run","format":"int64"},"ScriptType":{"type":"string","description":"ScriptType holds the type of a script"},"automationScriptFilterWrapper":{"title":"automationScriptFilterWrapper ...","type":"object","properties":{"savePassword":{"type":"boolean","description":"To have this script password protected, set this to `true` and include the password value in the `pswd` field.\r\nTo leave this script without a password, set this to `false` and leave the value of the `pswd` field empty."},"script":{"$ref":"#/components/schemas/AutomationScript"}}},"AutomationScript":{"type":"object","properties":{"MainEngineInfo":{"$ref":"#/components/schemas/EngineInfo"},"allRead":{"type":"boolean"},"allReadWrite":{"type":"boolean"},"arguments":{"type":"array","items":{"$ref":"#/components/schemas/Argument"}},"cacheVersn":{"type":"integer","format":"int64"},"comment":{"type":"string"},"commitMessage":{"type":"string"},"contextKeys":{"type":"array","items":{"type":"string"}},"created":{"type":"string","format":"date-time"},"dbotCreatedBy":{"type":"string","description":"Who has created this event - relevant only for manual incidents"},"definitionId":{"type":"string"},"dependsOn":{"type":"object","additionalProperties":{"type":"array","items":{"type":"string"}},"description":"This fields indicates which commands this script depends on"},"deprecated":{"type":"boolean"},"detached":{"type":"boolean"},"dockerImage":{"type":"string"},"enabled":{"type":"boolean"},"engine":{"type":"string","description":"Engine that will run the script"},"engineGroup":{"type":"string","description":"EngineGroup that will run the script"},"fromServerVersion":{"$ref":"#/components/schemas/Version"},"hasRole":{"type":"boolean","description":"Internal field to make queries on role faster"},"hidden":{"type":"boolean"},"highlight":{"type":"object","additionalProperties":{"type":"array","items":{"type":"string"}}},"id":{"type":"string"},"important":{"type":"array","items":{"$ref":"#/components/schemas/Important"}},"indexName":{"type":"string"},"itemVersion":{"$ref":"#/components/schemas/Version"},"locked":{"type":"boolean"},"modified":{"type":"string","format":"date-time"},"name":{"type":"string"},"numericId":{"type":"integer","format":"int64"},"outputs":{"type":"array","items":{"$ref":"#/components/schemas/Output"}},"packID":{"type":"string"},"packName":{"type":"string"},"packPropagationLabels":{"type":"array","items":{"type":"string"}},"polling":{"type":"boolean"},"prevName":{"type":"string"},"previousAllRead":{"type":"boolean"},"previousAllReadWrite":{"type":"boolean"},"previousRoles":{"type":"array","description":"Do not change this field manually","items":{"type":"string"}},"primaryTerm":{"type":"integer","format":"int64"},"private":{"type":"boolean"},"propagationLabels":{"type":"array","items":{"type":"string"}},"pswd":{"type":"string"},"rawTags":{"type":"array","items":{"type":"string"}},"remote":{"type":"boolean"},"roles":{"type":"array","description":"The role assigned to this investigation","items":{"type":"string"}},"runAs":{"type":"string"},"runOnce":{"type":"boolean"},"script":{"type":"string"},"scriptTarget":{"$ref":"#/components/schemas/ScriptTarget"},"searchableName":{"type":"string"},"sensitive":{"type":"boolean"},"sequenceNumber":{"type":"integer","format":"int64"},"shouldCommit":{"type":"boolean"},"sizeInBytes":{"type":"integer","format":"int64"},"sortValues":{"type":"array","items":{"type":"string"}},"sourceScripID":{"type":"string"},"subtype":{"$ref":"#/components/schemas/ScriptSubType"},"syncHash":{"type":"string"},"system":{"type":"boolean"},"tags":{"type":"array","items":{"type":"string"}},"timeout":{"$ref":"#/components/schemas/Duration"},"toServerVersion":{"$ref":"#/components/schemas/Version"},"type":{"$ref":"#/components/schemas/ScriptType"},"user":{"type":"string"},"vcShouldIgnore":{"type":"boolean"},"vcShouldKeepItemLegacyProdMachine":{"type":"boolean"},"version":{"type":"integer","format":"int64"},"visualScript":{"type":"string"},"xsoarHasReadOnlyRole":{"type":"boolean"},"xsoarPreviousReadOnlyRoles":{"type":"array","items":{"type":"string"}},"xsoarReadOnlyRoles":{"type":"array","items":{"type":"string"}}},"description":"AutomationScript represents a script that will run on  the system"},"EngineInfo":{"title":"EngineInfo ...","type":"object","properties":{"engine":{"type":"string","description":"Engine that will run the script"},"engineGroup":{"type":"string","description":"EngineGroup that will run the script"}}},"Version":{"title":"Version","type":"object","properties":{"Digits":{"type":"array","description":"WARNING: when adding new attributes or changing the names\nof the existing ones, remember to add support in UnmarshalJSON\nfor items that were exported by msgpack.","items":{"type":"integer","format":"int64"}},"Label":{"type":"string"}},"description":"Version represents a version."},"Important":{"type":"object","properties":{"contextPath":{"type":"string"},"description":{"type":"string","description":"Description is either a string or a map from string to interface"},"related":{"type":"string","description":"To what other context path this output is related"}},"description":"Important The important outputs of a given command"},"ScriptSubType":{"type":"string","description":"ScriptSubType holds the script type version"},"Duration":{"title":"Duration","type":"integer","description":"A Duration represents the elapsed time between two instants as an int64 nanosecond count. The representation limits the largest representable duration to approximately 290 years.","format":"int64"}}}}
```

## Get an existing script

> Get an existing script (automation) from a Cortex XSOAR tenant.

```json
{"openapi":"3.0.1","info":{"title":"Cortex XSOAR 8 API","version":"XSOAR 8 Cloud"},"tags":[{"name":"Scripts","description":"APIs for managing scripts"}],"servers":[{"url":"https://api-yourfqdn","description":""}],"paths":{"/xsoar/public/v1/automation/load/{script_name}":{"post":{"summary":"Get an existing script","tags":["Scripts","Automations"],"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"type":"object","properties":{"MainEngineInfo":{"type":"object","properties":{"engine":{"type":"string"},"engineGroup":{"type":"string"}}},"arguments":{"type":"array","items":{"type":"object","properties":{"default":{"type":"boolean"},"defaultValue":{"type":"string"},"deprecated":{"type":"boolean"},"description":{"type":"string"},"hidden":{"type":"boolean"},"name":{"type":"string"},"required":{"type":"boolean"},"secret":{"type":"boolean"},"type":{"type":"string"}}}},"cacheVersn":{"type":"integer"},"comment":{"type":"string"},"commitMessage":{"type":"string"},"contextKeys":{"type":"array","items":{"type":"object","properties":{}}},"definitionId":{"type":"string"},"deprecated":{"type":"boolean"},"detached":{"type":"boolean"},"dockerImage":{"type":"string"},"enabled":{"type":"boolean"},"engine":{"type":"string"},"engineGroup":{"type":"string"},"fromServerVersion":{"type":"string"},"id":{"type":"string"},"important":{"type":"null"},"itemVersion":{"type":"string"},"locked":{"type":"boolean"},"modified":{"type":"string"},"name":{"type":"string"},"nativeImage":{"type":"null"},"outputs":{"type":"null"},"packID":{"type":"string"},"packName":{"type":"string"},"packPropagationLabels":{"type":"array","items":{"type":"string"}},"permitted":{"type":"boolean"},"prevName":{"type":"string"},"primaryTerm":{"type":"integer"},"propagationLabels":{"type":"array","items":{"type":"object","properties":{}}},"pswd":{"type":"string"},"pswdProtected":{"type":"boolean"},"rawTags":{"type":"array","items":{"type":"string"}},"runAs":{"type":"string"},"runOnce":{"type":"boolean"},"script":{"type":"string"},"scriptTarget":{"type":"integer"},"searchableName":{"type":"string"},"sensitive":{"type":"boolean"},"sequenceNumber":{"type":"integer"},"shouldCommit":{"type":"boolean"},"sizeInBytes":{"type":"integer"},"subtype":{"type":"string"},"system":{"type":"boolean"},"tags":{"type":"array","items":{"type":"string"}},"timeout":{"type":"integer"},"toServerVersion":{"type":"string"},"type":{"type":"string"},"user":{"type":"string"},"vcShouldIgnore":{"type":"boolean"},"vcShouldKeepItemLegacyProdMachine":{"type":"boolean"},"version":{"type":"integer"},"visualScript":{"type":"string"}}}}}}},"operationId":"post-automation-load-script_name","parameters":[{"schema":{"type":"string"},"in":"header","name":"authorization","description":"api_key","required":true},{"schema":{"type":"string"},"in":"header","name":"x-xdr-auth-id","description":"api_key_id","required":true}],"description":"Get an existing script (automation) from a Cortex XSOAR tenant.","requestBody":{"content":{"application/json":{"schema":{"type":"object","properties":{}}}}}}}}}
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/scripts.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
