Skip to main content
Version: 1.0.0

Sophos Firewall Configuration API

Programmatically manage and automate your Sophos Firewall — administration, authentication, objects, networking, routing, sd-wan, wireless, vpn, rules, nat, traffic shaping, active threat response, application control, intrusion prevention, tls inspection, web protection, waf, malware and zero-day protection, synchronized security, central management, logging, and monitoring — using the Firewall Configuration REST API. This reference is generated from the official OpenAPI 3.0 specification for the firewall appliance configuration.

Base URL​

All requests go to your firewall's configuration API host:

https://<firewall-hostname>:<port>/api/firewall-config/v1

Authentication​

The API uses token-based authentication. Send your API key as a bearer token:

Authorization: Bearer <api-key>

Generate and manage API keys from Administration › API access in the firewall web admin console.

Naming and object references​

SFOS control plane objects usually require a unique name to identify them in POST requests. However, when GET|PATCH|DELETE APIs are performed on them, they can be identified either by given unique name or an object ID (UUID). Two custom formats define how these values are validated:

  • sfos-object-name — an object name in valid UTF-8. No commas, semicolons, non-printable characters, or leading/trailing spaces, and it must never be a valid UUID.
  • sfos-object-name-or-id — sfos-object-name or UUID.

Partial updates (PATCH)​

Unless an operation explicitly documents different behavior, PATCH requests follow JSON Merge Patch semantics (RFC 7396): omitted properties retain their persisted values, and a property set to null is removed. Where an operation deviates from this — for example, treating an array as a full replacement rather than an atomic value, or using explicit add/remove lists — that operation's own documentation takes precedence.

When a field is one of a oneOf set of configurations, or otherwise selects between mutually exclusive branches, sending the new branch is sufficient to switch to it. Clients are not required to explicitly send null for the previously configured branch — the server clears it automatically as part of applying the new selection.

Authentication​

API key, typically used by non-browser clients.

Security Scheme Type:

http

HTTP Authorization Scheme:

bearer

Bearer format:

API key

Contact

Sophos Firewall APIs:

URL: https://developer.sophos.com