Skip to content

Get started with Sophos Firewall REST API

The Sophos Firewall REST API lets you automate configuration management for one or more firewalls. You can use scripts, third-party API clients, or enterprise systems to manage firewall configurations programmatically.

Create, read, update, and delete (CRUD) operations enable consistent and efficient management at scale.

REST API respources

Important considerations

Learn about the key requirements, limitations, and considerations for using REST API.

  • The REST API endpoint names generally match the terms used in the web admin console. Some endpoint names differ from UI terms to make the REST API more intuitive. However, the differences are recognizable and can be mapped to the corresponding UI terms.
  • Some API operations can take longer to complete. For example, retrieving IPS custom signatures can cause API client time-outs. Increase the default time-out value in your API client if necessary.
  • Familiarize yourself with the API schema, endpoints, and referenced objects. See Sophos Firewall API Reference.
  • Before you use the REST API, complete the following tasks:

    • Turn on API access and add the IP addresses of administrators' endpoint devices.
    • Administrators must generate an API key for their account.

      The API key is used as the bearer token for authentication and authorization.

Note

Sophos Support is available only for the official REST API and unmodified scripts. The technical support team doesn't provide advice or troubleshooting for custom integrations. For assistance with custom integrations, you can use one of the following options: