Get started with Sophos Firewall REST API
The Sophos Firewall REST API lets you automate configuration management for one or more firewalls. You can use scripts, third-party API clients, or enterprise systems to manage firewall configurations programmatically.
Create, read, update, and delete (CRUD) operations enable consistent and efficient management at scale.
REST API respources
-
API access and keys
-
REST API guide
Important considerations
Learn about the key requirements, limitations, and considerations for using REST API.
- The REST API endpoint names generally match the terms used in the web admin console. Some endpoint names differ from UI terms to make the REST API more intuitive. However, the differences are recognizable and can be mapped to the corresponding UI terms.
- Some API operations can take longer to complete. For example, retrieving IPS custom signatures can cause API client time-outs. Increase the default time-out value in your API client if necessary.
- Familiarize yourself with the API schema, endpoints, and referenced objects. See Sophos Firewall API Reference.
-
Before you use the REST API, complete the following tasks:
- Turn on API access and add the IP addresses of administrators' endpoint devices.
-
Administrators must generate an API key for their account.
The API key is used as the bearer token for authentication and authorization.
Note
Sophos Support is available only for the official REST API and unmodified scripts. The technical support team doesn't provide advice or troubleshooting for custom integrations. For assistance with custom integrations, you can use one of the following options:
- Check with your Sophos partner.
- Use Sophos Professional Services. See Support Services and Teams.