Sophos Firewall Configuration API
Programmatically manage and automate your Sophos Firewall — administration, authentication, objects, networking, routing, sd-wan, wireless, vpn, rules, nat, traffic shaping, active threat response, application control, intrusion prevention, tls inspection, web protection, waf, malware and zero-day protection, synchronized security, central management, logging, and monitoring — using the Firewall Configuration REST API. This reference is generated from the official OpenAPI 3.0 specification for the firewall appliance configuration.
Base URL
All requests go to your firewall's configuration API host:
https://<firewall-hostname>:<port>/api/firewall-config/v1
Authentication
The API uses token-based authentication. Send your API key as a bearer token:
Authorization: Bearer <api-key>
Generate and manage API keys from Administration › API access in the firewall web admin console.
Naming and object references
SFOS control plane objects usually require a unique name to identify them in POST requests. However, when GET|PATCH|DELETE APIs are performed on them, they can be identified either by given unique name or an object ID (UUID). Two custom formats define how these values are validated:
sfos-object-name— an object name in valid UTF-8. No commas, semicolons, non-printable characters, or leading/trailing spaces, and it must never be a valid UUID.sfos-object-name-or-id—sfos-object-nameor UUID.
Partial updates (PATCH)
Unless an operation explicitly documents different behavior, PATCH
requests follow JSON Merge Patch semantics
(RFC 7396): omitted
properties retain their persisted values, and a property set to null
is removed. Where an operation deviates from this — for example,
treating an array as a full replacement rather than an atomic value, or
using explicit add/remove lists — that operation's own documentation
takes precedence.
When a field is one of a oneOf set of configurations, or otherwise
selects between mutually exclusive branches, sending the new branch is
sufficient to switch to it. Clients are not required to explicitly send
null for the previously configured branch — the server clears it
automatically as part of applying the new selection.
Authentication
- HTTP: Bearer Auth
API key, typically used by non-browser clients.
Security Scheme Type: | http |
|---|---|
HTTP Authorization Scheme: | bearer |
Bearer format: | API key |