Skip to main content
Tools Reference

WatchGuard Cloud Tools

Written By Christopher Scaminaci

Last updated 7 days ago

WatchGuard Cloud Tools

wg_ · 232 tools · Free 130 · Pro 102 All sixteen WatchGuard APIs: ThreatSync incidents, Endpoint Security inventory, risk, tasks and isolation (Aether or WES), Firebox Management and FireCloud configuration (policies, exceptions, networking, certificates, deployments), Firebox dashboards, NDR assets and alerts, accounts, operators, subscriptions, orders, licenses, activations and AuthPoint MFA. Auth is OAuth2 client_credentials, TWO credentials per request: a 3,600-second bearer from POST /oauth/token (host root, not /rest) with Basic base64(AccessID:Password), no refresh token, plus a static WatchGuard-API-Key header on EVERY call. A managed account is reached by binding it INTO the token - an opaque audience minted per account - and repeating that id in the URL. Three regional hosts by code (usa, deu, jpn), /rest in the authority. Paging differs per family (OData top/skip, offset/limit, startAfter, rowCount), capped at 100; Firebox Management and FireCloud lists are unpaginated and answer whole collections.

All connector tools · WatchGuard Cloud setup guide

WatchGuard Cloud tool groups

ThreatSync Incidents

ToolPlanAccessSummary
wg_create_incident_commentProWriteAdds a comment to a ThreatSync incident.
wg_delete_incident_commentProDestructiveDESTRUCTIVE.
wg_get_incidentFreeRead-onlyReturns one ThreatSync incident by ID, optionally with its actions and comments inline.
wg_get_incident_actionFreeRead-onlyReturns one response action on one ThreatSync incident, with its full detail.
wg_list_incident_actionsFreeRead-onlyLists the response actions recorded against one ThreatSync incident — what was attempted, by whom and how it ended.
wg_list_incident_commentsFreeRead-onlyLists the analyst comments on one ThreatSync incident — the written record of what a human concluded, which is usually the fastest way to understand an incident that has already been worked.
wg_list_incidentsFreeRead-onlyLists ThreatSync incidents — the correlated detections WatchGuard raises across Firebox, Endpoint Security and NDR together, which makes this the first place to look when asking what is happening on a…
wg_update_incident_commentProWriteReplaces the text of one comment on a ThreatSync incident.
wg_update_incident_statusProWriteMoves a ThreatSync incident to a different status, with an optional note.

[WatchGuard Cloud] Adds a comment to a ThreatSync incident. Purely additive — it creates a new comment and changes nothing that exists — so it is not marked destructive.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the incident belongs to. Leave empty for your own account.
commentstringyesThe comment text.
incidentIdstringyesThe ThreatSync incident ID.

[WatchGuard Cloud] DESTRUCTIVE. Permanently removes one comment from a ThreatSync incident. The comment trail is the written record of how an incident was handled, and WatchGuard has no undo for this — an incident that later becomes evidence loses that record. Prefer wg_update_incident_comment when the text is simply wrong.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the incident belongs to. Leave empty for your own account.
commentIdstringyesThe comment ID to delete.
incidentIdstringyesThe ThreatSync incident ID.

[WatchGuard Cloud] Returns one ThreatSync incident by ID, optionally with its actions and comments inline. Get incident IDs from wg_list_incidents. Reading the incident with its actions is the cheapest way to see what has already been tried before performing another one.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the incident belongs to. Leave empty for your own account.
incidentIdstringyesThe ThreatSync incident ID.
includeActionsbooleannonullOptional. Set true to include the incident's actions.
includeCommentsbooleannonullOptional. Set true to include the incident's comments.

[WatchGuard Cloud] Returns one response action on one ThreatSync incident, with its full detail. Get action IDs from wg_list_incident_actions.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the incident belongs to. Leave empty for your own account.
actionIdstringyesThe action ID.
incidentIdstringyesThe ThreatSync incident ID.

[WatchGuard Cloud] Lists the response actions recorded against one ThreatSync incident — what was attempted, by whom and how it ended. Read this before performing another action, so a remediation is not run twice.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the incident belongs to. Leave empty for your own account.
countOnlybooleannonullOptional. Set true to return only a count of matching records.
durationstringnonullOptional. Window to retrieve, as a number of days followed by D — for example 7D.
fieldsstringnonullOptional. Response parameters to return, comma-separated.
groupBystringnonullOptional. Response parameter to group the data by.
incidentIdstringyesThe ThreatSync incident ID.
limitintegernonullOptional. Maximum records to return. StackJack caps this at 100 per call.
querystringnonullOptional. Search expression: parameter names and values that a record must match.
sortBystringnonullOptional. Response parameter names to sort by, comma-separated.
sortOrderstringnonullOptional. Sort direction. Accepted values are exactly: asc, desc.
startAfterstringnonullOptional. Cursor from the previous page.
ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the incident belongs to. Leave empty for your own account.
durationstringnonullOptional. Window to retrieve, as a number of days followed by D — for example 7D.
fieldsstringnonullOptional. Response parameters to return, comma-separated.
groupBystringnonullOptional. Response parameter to group the data by.
incidentIdstringyesThe ThreatSync incident ID.
limitintegernonullOptional. Maximum records to return. StackJack caps this at 100 per call.
sortBystringnonullOptional. Response parameter names to sort by, comma-separated.
sortOrderstringnonullOptional. Sort direction. Accepted values are exactly: asc, desc.
startAfterstringnonullOptional. Cursor from the previous page.

[WatchGuard Cloud] Lists ThreatSync incidents — the correlated detections WatchGuard raises across Firebox, Endpoint Security and NDR together, which makes this the first place to look when asking what is happening on a customer's estate. Page with limit plus startAfter, using the cursor value from the last record of the previous page. Use duration (a number followed by D, e.g. 7D) to bound the window rather than paging through history. As a Service Provider, pass accountId to work in a managed account — list them with wg_list_managed_accounts — or set tenants true to include managed accounts alongside your own.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to read, e.g. ACC-1234567. Leave empty for your own account.
countOnlybooleannonullOptional. Set true to return only a count of matching records instead of the records.
durationstringnonullOptional. Window to retrieve, as a number of days followed by D — for example 7D.
fieldsstringnonullOptional. Response parameters to return, comma-separated. Omit to return them all.
groupBystringnonullOptional. Response parameter to group the data by.
includeActionsbooleannonullOptional. Set true to include each incident's actions inline.
includeCommentsbooleannonullOptional. Set true to include each incident's comments inline.
limitintegernonullOptional. Maximum records to return. StackJack caps this at 100 per call even though WatchGuard allows more.
querystringnonullOptional. Search expression: parameter names and values that a record must match.
sortBystringnonullOptional. Response parameter names to sort by, comma-separated.
sortOrderstringnonullOptional. Sort direction. Accepted values are exactly: asc, desc.
startAfterstringnonullOptional. Cursor from the previous page: the value of the record you want to continue after.
tenantsbooleannonullOptional. Set true to include managed accounts' incidents alongside your own.

[WatchGuard Cloud] Replaces the text of one comment on a ThreatSync incident. It rewrites that comment and nothing else, and the comment trail keeps its own history, so it is not marked destructive. Get comment IDs from wg_list_incident_comments.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the incident belongs to. Leave empty for your own account.
commentstringyesThe replacement comment text.
commentIdstringyesThe comment ID.
incidentIdstringyesThe ThreatSync incident ID.

[WatchGuard Cloud] Moves a ThreatSync incident to a different status, with an optional note. This is triage bookkeeping — it changes nothing on any device and the status can be moved back — so it is not marked destructive. Read the incident first with wg_get_incident to see which statuses it has already been through.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the incident belongs to. Leave empty for your own account.
commentstringnonullOptional. A note recorded with the status change.
incidentIdstringyesThe ThreatSync incident ID.
statusstringyesThe new status value, as ThreatSync names it.

ThreatSync Response Actions

ToolPlanAccessSummary
wg_list_actionsFreeRead-onlyLists ThreatSync response actions across the whole account rather than for one incident — the record of every remediation ThreatSync has run, which is what a monthly security review is built from.
wg_perform_actionProDestructiveDESTRUCTIVE.
wg_perform_incident_actionProDestructiveDESTRUCTIVE.
wg_submit_transactionProDestructiveDESTRUCTIVE.

[WatchGuard Cloud] Lists ThreatSync response actions across the whole account rather than for one incident — the record of every remediation ThreatSync has run, which is what a monthly security review is built from. Bound it with duration (a number of days followed by D) rather than paging through history.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to read. Leave empty for your own account.
countOnlybooleannonullOptional. Set true to return only a count of matching records.
durationstringnonullOptional. Window to retrieve, as a number of days followed by D — for example 7D.
fieldsstringnonullOptional. Response parameters to return, comma-separated.
groupBystringnonullOptional. Response parameter to group the data by.
limitintegernonullOptional. Maximum records to return. StackJack caps this at 100 per call.
querystringnonullOptional. Search expression: parameter names and values that a record must match.
sortBystringnonullOptional. Response parameter names to sort by, comma-separated.
sortOrderstringnonullOptional. Sort direction. Accepted values are exactly: asc, desc.
startAfterstringnonullOptional. Cursor from the previous page.

[WatchGuard Cloud] DESTRUCTIVE. Runs a ThreatSync response action outside any one incident — block, quarantine or stop something on a live estate, with no incident record tying it to a detection and no undo. Prefer wg_perform_incident_action when the action belongs to an incident, so the remediation is recorded against it.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to act in. Leave empty for your own account.
commandstringyesThe ThreatSync command to run, as ThreatSync names it.
entityIdstringnonullOptional. The entity to act on.
parametersJsonstringyesThe command's arguments as a JSON object, e.g. {"key":"value"}. Pass when the command takes none.

[WatchGuard Cloud] DESTRUCTIVE. Runs a ThreatSync response action against a live incident — this is the remediation lane, so the command can block a connection, quarantine a file or stop a process on a real machine, and WatchGuard offers no undo for it. Read wg_list_incident_actions first to see what the incident already accepts and what has been tried. The parameters object is the command's own argument set, exactly as ThreatSync documents it for that command.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the incident belongs to. Leave empty for your own account.
commandstringyesThe ThreatSync command to run, as ThreatSync names it.
commentstringnonullOptional. A note recorded with the action.
entityIdstringnonullOptional. The specific entity within the incident to act on.
incidentIdstringyesThe ThreatSync incident ID.
parametersJsonstringyesThe command's arguments as a JSON object, e.g. {"key":"value"}. Pass when the command takes none.

[WatchGuard Cloud] DESTRUCTIVE. Submits several ThreatSync requests together as one transaction. Each entry names its own path, method and body, so this can reach ANY ThreatSync write — including the remediation actions and the comment delete — in a single call, and nothing in the batch is reviewed tool by tool. Use the individual tools unless you genuinely need one transaction, and read WatchGuard's transaction documentation before composing the body.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the batch acts in. Leave empty for your own account.
requestsJsonstringyesA JSON ARRAY of requests, each an object with path, method and data — for example [{"path":"/v1/ACC-1234567/incidents/42","method":"PATCH","data":{"status":"closed"}}].

Endpoint Devices and Inventory

ToolPlanAccessSummary
wg_get_endpoint_hardware_inventoryFreeRead-onlyReturns the BIOS and hardware characteristics of one managed device.
wg_get_endpoint_installer_urlFreeRead-onlyReturns a download URL for an endpoint installation package built with a specific managed configuration.
wg_get_endpoint_licensesFreeRead-onlyReturns the endpoint license position for an account — what is owned, what is used and what is left.
wg_link_endpoint_devices_to_configurationProDestructiveDESTRUCTIVE.
wg_list_endpoint_devicesFreeRead-onlyLists the devices WatchGuard Endpoint Security manages, with their addresses and operating systems.
wg_list_endpoint_managed_configurationsFreeRead-onlyLists the managed configurations of one type — the protection profiles devices are assigned to.
wg_list_endpoint_missing_patchesFreeRead-onlyLists published patches that are not installed on the customer's devices — the patch-gap report.
wg_list_endpoint_protection_statusFreeRead-onlyLists devices with their protection status — which agents are installed, up to date and actually protecting the machine.
wg_list_endpoint_software_inventoryFreeRead-onlyLists the software installed across the customer's managed devices.
wg_list_unmanaged_endpoint_devicesFreeRead-onlyLists devices discovered on the customer's network that WatchGuard does NOT manage — the gap between what is on the network and what is protected.
wg_scan_endpoint_devices_nowProWriteStarts an immediate malware scan on the named devices.
wg_send_endpoint_device_actionProDestructiveDESTRUCTIVE.
wg_uninstall_endpoint_protectionProDestructiveDESTRUCTIVE.

[WatchGuard Cloud] Returns the BIOS and hardware characteristics of one managed device. Get device IDs from wg_list_endpoint_devices.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the device belongs to. Leave empty for your own account.
deviceIdstringyesThe device ID, from wg_list_endpoint_devices.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.

[WatchGuard Cloud] Returns a download URL for an endpoint installation package built with a specific managed configuration. It reads a URL and installs nothing by itself. Get configuration IDs from wg_list_endpoint_managed_configurations.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to build the installer for. Leave empty for your own account.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.
managedConfigurationIdstringyesThe managed configuration ID the installer should apply, from wg_list_endpoint_managed_configurations.
platformIdintegeryesPlatform. Accepted values are exactly: 1 (Windows), 2 (Linux), 3 (macOS), 4 (Android), 5 (iOS).
useActiveDirectorybooleanyesWhether the installed device should be integrated into Active Directory.

[WatchGuard Cloud] Returns the endpoint license position for an account — what is owned, what is used and what is left. Read this before deploying to new devices.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to read. Leave empty for your own account.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.

[WatchGuard Cloud] Lists the devices WatchGuard Endpoint Security manages, with their addresses and operating systems. This is where device IDs come from for every other endpoint tool. Page with top and skip; WatchGuard caps the response at 3,000 records however you ask, so narrow with search rather than paging past that. As a Service Provider, pass accountId to read a managed account.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to read, e.g. ACC-1234567. Leave empty for your own account.
configbooleannonullOptional. Set false to omit each device's security configuration name and ID. WatchGuard's default is true.
countbooleannonullOptional. Set true to include a total_items count in the response.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.
orderbystringnonullOptional. Response parameter to order by, with an optional direction.
searchstringnonullOptional. Free-text filter; only records containing this text are returned.
skipintegernonullOptional. How many records to skip before returning any — the paging offset.
topintegernonullOptional. How many records to return. StackJack caps this at 100 per call.

[WatchGuard Cloud] Lists the managed configurations of one type — the protection profiles devices are assigned to. Read this before linking any device to a configuration, so the profile is the one you meant.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to read. Leave empty for your own account.
countbooleannonullOptional. Set true to include a total_items count.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.
orderbystringnonullOptional. Response parameter to order by.
searchstringnonullOptional. Free-text filter.
skipintegernonullOptional. How many records to skip — the paging offset.
topintegernonullOptional. How many records to return. StackJack caps this at 100 per call.
typeintegeryesConfiguration type. Accepted values are exactly: 1 (deployment settings), 2 (workstations and servers), 3 (Android), 12 (iOS).

[WatchGuard Cloud] Lists published patches that are not installed on the customer's devices — the patch-gap report. Narrow with filter by patch type or criticality rather than reading the whole estate.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to read. Leave empty for your own account.
countbooleannonullOptional. Set true to include a total_items count.
filterstringnonullOptional. WatchGuard filter expression, for example by patch type.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.
skipintegernonullOptional. How many records to skip — the paging offset.
topintegernonullOptional. How many records to return. StackJack caps this at 100 per call.

[WatchGuard Cloud] Lists devices with their protection status — which agents are installed, up to date and actually protecting the machine. This is the read that answers whether a customer's endpoint coverage is real, rather than whether the devices exist. Capped by WatchGuard at 3,000 records.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to read. Leave empty for your own account.
countbooleannonullOptional. Set true to include a total_items count.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.
orderbystringnonullOptional. Response parameter to order by.
searchstringnonullOptional. Free-text filter.
skipintegernonullOptional. How many records to skip — the paging offset.
topintegernonullOptional. How many records to return. StackJack caps this at 100 per call.

[WatchGuard Cloud] Lists the software installed across the customer's managed devices. Use filter with WatchGuard's own filter syntax to narrow to one device or one product — an unfiltered estate-wide read is large.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to read. Leave empty for your own account.
countbooleannonullOptional. Set true to include a total_items count.
filterstringnonullOptional. WatchGuard filter expression, for example a host-name match.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.
skipintegernonullOptional. How many records to skip — the paging offset.
topintegernonullOptional. How many records to return. StackJack caps this at 100 per call.

[WatchGuard Cloud] Lists devices discovered on the customer's network that WatchGuard does NOT manage — the gap between what is on the network and what is protected. Capped by WatchGuard at 3,000 records.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to read. Leave empty for your own account.
countbooleannonullOptional. Set true to include a total_items count.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.
orderbystringnonullOptional. Response parameter to order by.
skipintegernonullOptional. How many records to skip — the paging offset.
topintegernonullOptional. How many records to return. StackJack caps this at 100 per call.

[WatchGuard Cloud] Starts an immediate malware scan on the named devices. It creates a scan task and removes nothing, so it is not marked destructive — it is the safest first response to a suspicion. It does use the devices' processors while it runs, so an estate-wide scan in working hours will be noticed. Track it afterwards with wg_list_endpoint_tasks. Acts on the Aether generation unless you set generation to wes.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the devices belong to. Leave empty for your own account.
applyExclusionsOnScanbooleannonullOptional. Set true to apply the account's configured exclusions to this scan.
detectHackingToolsbooleannonullOptional. Set true to detect hacking tools as well as malware.
detectSuspiciousFilesbooleannonullOptional. Set true to detect suspicious files.
deviceIdsstringyesDevice IDs to scan, comma-separated, from wg_list_endpoint_devices. At least one is required.
executionWindowExpirationstringnonullOptional. How LONG the scan has to run before it times out — a duration, not a date. WatchGuard's format is days.hours:minutes:seconds, so 8.07:06:05 means 8 days, 7 hours, 6 minutes and 5 seconds. Leave unset for WatchGuard's default of 7 days.
extensionsToExcludestringnonullOptional. File extensions to exclude, comma-separated.
filesToExcludestringnonullOptional. Files to exclude, comma-separated.
foldersToExcludestringnonullOptional. Folders to exclude, comma-separated.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.
scanCompressedFilesbooleannonullOptional. Set true to scan inside compressed files.
scanScopeintegernonullOptional. Scan scope. Accepted values are exactly: 0, 1, 2 — WatchGuard's own codes for the whole computer, critical areas, or specific items.
specifiedItemsToScanstringnonullOptional. Paths to scan when the scope names specific items, comma-separated.
taskDescriptionstringnonullOptional. Description for the scan task.
taskNamestringnonullOptional. Name for the scan task, so it can be recognized in the task list.

[WatchGuard Cloud] DESTRUCTIVE. Sends an action to the named devices — today that means a restart, which closes whatever the person at the keyboard had open. The countdown gives them warning; without one the machine restarts immediately. Name the exact device IDs. Acts on the Aether generation unless you set generation to wes.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the devices belong to. Leave empty for your own account.
actionTypeintegeryesAction type. The only value WatchGuard documents is exactly 1 (restart).
countDownTypeintegernonullOptional. Countdown before the action runs, as WatchGuard's own code — an accepted value between 1 and 7. Omit to run with no countdown.
deviceIdsstringyesDevice IDs to act on, comma-separated, from wg_list_endpoint_devices. At least one is required.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.

[WatchGuard Cloud] DESTRUCTIVE. Removes WatchGuard protection from the named devices, leaving them unprotected and no longer reporting. Re-protecting a device means building an installer and running it on the machine, so this is not something an assistant should do to tidy up an inventory. Use it only when a device is genuinely being retired or moved off the product. Acts on the Aether generation unless you set generation to wes.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the devices belong to. Leave empty for your own account.
deviceIdsstringyesDevice IDs to uninstall protection from, comma-separated. At least one is required.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.

Endpoint Isolation

ToolPlanAccessSummary
wg_isolate_endpoint_devicesProDestructiveDESTRUCTIVE.
wg_stop_endpoint_device_isolationProDestructiveDESTRUCTIVE.

[WatchGuard Cloud] DESTRUCTIVE. Takes the named devices OFF the network. Isolation is the right answer to a live compromise and the wrong answer to almost everything else: an isolated machine loses shared drives, line-of-business applications and remote access, and the person using it will notice within seconds. Name the exact device IDs — never a whole estate — and reverse it with wg_stop_endpoint_device_isolation. Acts on the Aether generation unless you set generation to wes.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the devices belong to. Leave empty for your own account.
customizedMessagestringnonullOptional. Message shown on the isolated device, so the person using it knows what happened.
deviceIdsstringyesDevice IDs to isolate, comma-separated, from wg_list_endpoint_devices. At least one is required.
exclusionProgramsstringnonullOptional. Programs that keep network access while the device is isolated, comma-separated — for example a remote-support tool you still need.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.
hideCustomizedAlertbooleannonullOptional. Set true to hide the alert on the device.

[WatchGuard Cloud] DESTRUCTIVE. Returns isolated devices to the network. It reads like an undo, and it is marked destructive for the same reason isolation is: a machine was quarantined because something was found on it, and putting it back before that is resolved re-exposes the network to it. Confirm the threat is cleared first — wg_list_incidents will show whether the incident that isolated it is closed. Acts on the Aether generation unless you set generation to wes.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the devices belong to. Leave empty for your own account.
deviceIdsstringyesDevice IDs to return to the network, comma-separated. At least one is required.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.

Endpoint Risk and Security Events

ToolPlanAccessSummary
wg_get_endpoint_company_risk_summaryFreeRead-onlyReturns the company-wide risk summary — the one-screen posture answer for an account, and the right place to start a quarterly review before drilling into individual risks.
wg_get_endpoint_risk_configurationFreeRead-onlyReturns the current risk configuration: which risk factors are switched on and at what severity.
wg_get_endpoint_risk_statisticsFreeRead-onlyReturns risk detections over time — how many of each type were detected across the period, which is the trend line a customer wants beside a point-in-time summary.
wg_get_endpoint_security_event_countersFreeRead-onlyReturns counts of detected security events by type.
wg_get_endpoint_security_overviewFreeRead-onlyReturns the security overview counters for a period — the headline detection numbers for an account, and the natural companion to the company risk summary in a customer report.
wg_list_endpoint_detected_risksFreeRead-onlyReturns a count of affected devices for each type of risk detected — which risks exist and how widespread each one is.
wg_list_endpoint_device_risksFreeRead-onlyLists devices with the risks detected on each, by risk level — the device-level view behind the company risk summary.
wg_list_endpoint_security_eventsFreeRead-onlyLists security events of one type over a period — malware, exploits, blocked programs and the rest, one code per type.
wg_update_endpoint_risk_configurationProDestructiveDESTRUCTIVE.
ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to read, e.g. ACC-1234567. Leave empty for your own account.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.

[WatchGuard Cloud] Returns the current risk configuration: which risk factors are switched on and at what severity. Read this before changing it — the update replaces the whole list, so this response is the only record of what to put back.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to read. Leave empty for your own account.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.
ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to read. Leave empty for your own account.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.
periodintegeryesPeriod in days. Accepted values are exactly: 7, 30.

[WatchGuard Cloud] Returns counts of detected security events by type. The type parameter is a MASK: add the codes of the event types you want, so 3 asks for types 1 and 2 together and 255 asks for all of them.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to read. Leave empty for your own account.
filterstringnonullOptional. Date filter, in WatchGuard's own filter syntax.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.
typeintegeryesEvent-type mask. Accepted values are exactly: 1, 2, 4, 8, 16, 32, 255 — or their sum, because the parameter is a mask.
ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to read. Leave empty for your own account.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.
periodintegeryesPeriod in days. Accepted values are exactly: 1, 7, 30.

[WatchGuard Cloud] Returns a count of affected devices for each type of risk detected — which risks exist and how widespread each one is. Use wg_list_endpoint_device_risks to see which devices are behind a number.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to read. Leave empty for your own account.
filterstringnonullOptional. WatchGuard filter expression narrowing to a device or a device type.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.

[WatchGuard Cloud] Lists devices with the risks detected on each, by risk level — the device-level view behind the company risk summary. Capped by WatchGuard at 3,000 records, so narrow with filter or search.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to read. Leave empty for your own account.
countbooleannonullOptional. Set true to include a total_items count.
filterstringnonullOptional. WatchGuard filter expression, for example by device type.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.
searchstringnonullOptional. Free-text filter on the device host name.
skipintegernonullOptional. How many records to skip — the paging offset.
topintegernonullOptional. How many records to return. StackJack caps this at 100 per call.

[WatchGuard Cloud] Lists security events of one type over a period — malware, exploits, blocked programs and the rest, one code per type. The host name filter must be base-64 encoded, which is WatchGuard's own requirement rather than ours. Capped by WatchGuard at 3,000 records.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to read. Leave empty for your own account.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.
hostnamestringnonullOptional. Device host name, BASE-64 ENCODED — WatchGuard requires the encoding on this parameter.
periodintegeryesPeriod in days. Accepted values are exactly: 1, 7.
skipintegernonullOptional. How many records to skip — the paging offset.
topintegernonullOptional. How many records to return. StackJack caps this at 100 per call.
typeintegeryesSecurity event type. Accepted values are exactly the codes 1 through 19 — for example 1 (malware), 2 (potentially unwanted programs), 3 (blocked programs), 4 (exploits).

[WatchGuard Cloud] DESTRUCTIVE. REPLACES the whole risk-settings list for an account. A factor left out of the list you send is not preserved, and switching a factor off stops WatchGuard reporting that risk at all — the customer's posture looks better while nothing has changed on any device. Read wg_get_endpoint_risk_configuration first and send back the complete list with only your intended change. Acts on the Aether generation unless you set generation to wes.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to change. Leave empty for your own account.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.
riskSettingsJsonstringyesA JSON ARRAY of risk-setting objects, matching what wg_get_endpoint_risk_configuration returned, with your change applied. Each entry carries the factor code and its enable, severity and threshold values.

Endpoint Tasks

ToolPlanAccessSummary
wg_get_endpoint_task_detailsFreeRead-onlyReturns the definition of one endpoint task — what it was set up to do and against which devices.
wg_get_endpoint_task_job_resultsFreeRead-onlyReturns what one repetition of an endpoint task actually found — the detections from a scan, the patches applied by an installation.
wg_get_endpoint_task_job_statusFreeRead-onlyReturns the per-device status of one repetition of an endpoint task — which devices the run reached, which are still pending and which failed.
wg_list_endpoint_task_jobsFreeRead-onlyLists the repetitions of one endpoint task — a recurring task runs many times, and each run has its own job ID.
wg_list_endpoint_tasksFreeRead-onlyLists the endpoint tasks created in an account — scans, disinfections, patch installations and IOC searches.

[WatchGuard Cloud] Returns the definition of one endpoint task — what it was set up to do and against which devices. Get the task ID and type from wg_list_endpoint_tasks; the type is part of the address, so a right ID with the wrong type will not be found.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the task belongs to. Leave empty for your own account.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.
taskIdstringyesThe task ID, from wg_list_endpoint_tasks.
typeintegeryesTask type code, from wg_list_endpoint_tasks — for example 1 (antimalware scan), 6 (patch installation), 7 (patch uninstallation), 10 (IOC search).

[WatchGuard Cloud] Returns what one repetition of an endpoint task actually found — the detections from a scan, the patches applied by an installation. Status says whether it ran; this says what it did.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the task belongs to. Leave empty for your own account.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.
jobIdstringyesThe repetition (job) ID, from wg_list_endpoint_task_jobs.
skipintegernonullOptional. How many records to skip — the paging offset.
taskIdstringyesThe task ID.
topintegernonullOptional. How many records to return. StackJack caps this at 100 per call.
typeintegeryesTask type code, from wg_list_endpoint_tasks.

[WatchGuard Cloud] Returns the per-device status of one repetition of an endpoint task — which devices the run reached, which are still pending and which failed. This is the read that answers whether a scan you started has finished.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the task belongs to. Leave empty for your own account.
countbooleannonullOptional. Set true to include a total_items count.
filterstringnonullOptional. WatchGuard filter expression.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.
jobIdstringyesThe repetition (job) ID, from wg_list_endpoint_task_jobs.
skipintegernonullOptional. How many records to skip — the paging offset.
taskIdstringyesThe task ID.
topintegernonullOptional. How many records to return. StackJack caps this at 100 per call.
typeintegeryesTask type code, from wg_list_endpoint_tasks.

[WatchGuard Cloud] Lists the repetitions of one endpoint task — a recurring task runs many times, and each run has its own job ID. Use a job ID from here with the status and results tools.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the task belongs to. Leave empty for your own account.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.
taskIdstringyesThe task ID, from wg_list_endpoint_tasks.
typeintegeryesTask type code, from wg_list_endpoint_tasks.

[WatchGuard Cloud] Lists the endpoint tasks created in an account — scans, disinfections, patch installations and IOC searches. Start here after running a scan: the task ID and type from this list are what every other task tool needs.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to read, e.g. ACC-1234567. Leave empty for your own account.
countbooleannonullOptional. Set true to include a total_items count.
filterstringnonullOptional. WatchGuard filter expression, for example by task type.
generationstringnonullOptional. Which WatchGuard Endpoint Security generation this account runs: aether (the default) or wes. WatchGuard ships the two generations with identical surfaces on different base paths and a tenant runs one of them; an unrecognized value is refused rather than guessed.
skipintegernonullOptional. How many records to skip — the paging offset.
topintegernonullOptional. How many records to return. StackJack caps this at 100 per call.

Accounts and Managed Accounts

ToolPlanAccessSummary
wg_create_managed_accountProDestructiveDESTRUCTIVE.
wg_delete_managed_accountProDestructiveDESTRUCTIVE.
wg_get_accountFreeRead-onlyReturns one WatchGuard Cloud account's information.
wg_list_managed_accountsFreeRead-onlyLists the accounts you manage.
wg_update_managed_accountProDestructiveDESTRUCTIVE.

[WatchGuard Cloud] DESTRUCTIVE. Creates a real managed account under yours — a new customer tenancy in WatchGuard Cloud, with commercial consequences. WatchGuard requires EVERY field: type, name, contact first and last name, email, phone, industry, and both the billing and mailing addresses in full. Confirm the details with whoever owns the relationship before calling this; there is no draft state.

ParamTypeRequiredDefaultDescription
accountJsonstringyesThe complete account as a JSON object. Required fields: type (1 for Service Provider, 2 for subscriber), name, firstName, lastName, email, phone, industry, billingAddress and mailingAddress — each address with address1, city, country and zipcode.
parentAccountIdstringnonullOptional. The parent account to create it under. Leave empty for your own account.

[WatchGuard Cloud] DESTRUCTIVE. Deletes an entire managed account. This is the single most dangerous operation in the WatchGuard connector: it removes a customer's whole tenancy, and with force set true it removes every account beneath it as well. There is no undo. Confirm the account ID against wg_list_managed_accounts and confirm the intent with a human before calling this.

ParamTypeRequiredDefaultDescription
accountIdstringyesThe managed account to delete, e.g. ACC-1234567. Confirm it against wg_list_managed_accounts first.
forcebooleannonullOptional. Set true to delete the account even when it manages other accounts — which deletes those too. Leave unset unless that is exactly what you intend.

[WatchGuard Cloud] Returns one WatchGuard Cloud account's information. Called with no account ID it reads your own account, which is also how StackJack tests this connection. Use the fields parameter to ask for specific account fields rather than the whole record.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The account to read, e.g. ACC-1234567 or WGC-1-123abc456. Leave empty for your own account.
fieldsstringnonullOptional. Account field names to return, comma-separated. Omit for the whole record.

[WatchGuard Cloud] Lists the accounts you manage. START HERE when working across customers: every other WatchGuard tool takes an optional account ID, and this is the only place those IDs come from. Filter by name for a partial match, or by type to separate Service Provider accounts from subscribers.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The parent account whose managed accounts you want. Leave empty for your own.
includeDelegatedAccountsbooleannonullOptional. Set true to include delegated accounts.
limitintegernonullOptional. How many accounts to return. StackJack caps this at 100 per call.
namestringnonullOptional. Account name to search for; partial matches are supported.
offsetintegernonullOptional. How many records to skip — the paging offset.
sortBystringnonullOptional. Field to sort by. Accepted values are exactly: name, type.
sortOrderstringnonullOptional. Sort direction. Accepted values are exactly: asc, desc.
typeintegernonullOptional. Account type. Accepted values are exactly: 0 (all), 1 (Service Provider accounts), 2 (subscriber accounts).

[WatchGuard Cloud] DESTRUCTIVE. REPLACES a managed account's record. WatchGuard requires every field on this call, so anything you leave out is not preserved — a partial update wipes the contact details or an address rather than leaving them alone. Read the account with wg_get_account first and send the complete record back with only your intended change.

ParamTypeRequiredDefaultDescription
accountIdstringyesThe managed account to update, e.g. ACC-1234567.
accountJsonstringyesThe COMPLETE account record as a JSON object: name, firstName, lastName, email, phone, industry, billingAddress and mailingAddress. Omitted fields are not preserved.

Firebox Reports

ToolPlanAccessSummary
wg_get_firebox_executive_reportFreeRead-onlyReturns one view of the Firebox Executive Dashboard — the traffic-side report a customer sees in a quarterly review: top applications, top destinations, top clients and so on.
wg_get_firebox_security_reportFreeRead-onlyReturns one view of the Firebox Security Dashboard — what the firewall BLOCKED over the period: blocked countries, botnet sites, malware, attacks and the rest.

[WatchGuard Cloud] Returns one view of the Firebox Executive Dashboard — the traffic-side report a customer sees in a quarterly review: top applications, top destinations, top clients and so on. One view per call, so ask for the views you need in turn. Leave devices empty to cover every Firebox in the account.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to report on, e.g. ACC-1234567. Leave empty for your own account.
devicesstringnonullOptional. Device IDs of the Fireboxes and FireClusters to include, comma-separated. Omit for all of them.
endDatestringyesEnd of the period, in WatchGuard's own date-time format.
filterstringnonullOptional. A second view name to filter the results on, used together with filterValue. Accepted values are the same list as view.
filterValuestringnonullOptional. The value to filter by, for the view named in filter.
rowCountintegernonullOptional. How many rows to return. StackJack caps this at 100 per call; WatchGuard's own default is 10.
startDatestringyesStart of the period, in WatchGuard's own date-time format.
viewstringyesWhich view to return. Accepted values are exactly: top_countries, top_zero_day_malware_apt, top_clients, top_mobile_devices, top_domains, top_url_categories, top_destinations, top_applications, top_application_categories, top_protocols.

[WatchGuard Cloud] Returns one view of the Firebox Security Dashboard — what the firewall BLOCKED over the period: blocked countries, botnet sites, malware, attacks and the rest. This is the report that shows a customer what their firewall stopped. One view per call.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to report on. Leave empty for your own account.
devicesstringnonullOptional. Device IDs of the Fireboxes and FireClusters to include, comma-separated. Omit for all of them.
endDatestringyesEnd of the period, in WatchGuard's own date-time format.
filterstringnonullOptional. A second view name to filter the results on, used together with filterValue.
filterValuestringnonullOptional. The value to filter by, for the view named in filter.
rowCountintegernonullOptional. How many rows to return. StackJack caps this at 100 per call; WatchGuard's own default is 10.
startDatestringyesStart of the period, in WatchGuard's own date-time format.
viewstringyesWhich view to return. Accepted values are exactly: top_blocked_countries, top_blocked_advanced_malware_apt, top_blocked_botnet_sites, top_blocked_clients, top_blocked_mobile_devices, top_blocked_destinations, top_blocked_url_categories, top_blocked_applications, top_blocked_application_categories, top_blocked_protocols, top_blocked_attacks, top_blocked_malware.

NDR Assets

ToolPlanAccessSummary
wg_create_ndr_assetProWriteRecords a new asset in WatchGuard NDR — typically something NDR has not discovered by itself, such as a device on a segment it cannot see.
wg_delete_ndr_assetProDestructiveDESTRUCTIVE.
wg_get_ndr_assetFreeRead-onlyReturns one WatchGuard NDR asset in full — its addresses, roles, importance, threat score and when it was first and last seen.
wg_list_ndr_assetsFreeRead-onlyLists the assets WatchGuard NDR knows about on the customer's network — what it has seen, what it believes each thing is, and each asset's threat score.
wg_update_ndr_assetProDestructiveDESTRUCTIVE.

[WatchGuard Cloud] Records a new asset in WatchGuard NDR — typically something NDR has not discovered by itself, such as a device on a segment it cannot see. Purely additive: it creates a record and changes nothing that exists, so it is not marked destructive. WatchGuard accepts only IP_V4 addresses on create.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to create the asset in. Leave empty for your own account.
addressesJsonstringyesA JSON ARRAY of addresses, for example [{"type":"IP_V4","value":"10.0.0.15"}]. WatchGuard accepts only IP_V4 here.
descriptionstringnonullOptional. A description of the asset.
deviceTypestringyesDevice types, comma-separated. Accepted values include exactly: Server, Printer, Computer, Router, Network, Database Server, Email Gateway, Firewall, Domain Controller, Switch, Storage Device, Access Point, Gateway.
importanceintegeryesHow important the asset is. Accepted values are exactly: 1, 2, 3, 4, 5.
namestringyesThe asset name or identifier, for example a host name or an IP address.
rolesstringnonullOptional. Roles the asset performs, comma-separated — for example DNS Server, DHCP Server, Web Server.
tagsstringnonullOptional. Tags, comma-separated.
tenantNamestringnonullOptional. The target account. Leave empty to use the account above.

[WatchGuard Cloud] DESTRUCTIVE. Permanently removes an asset from WatchGuard NDR, with its history and its link to past Smart Alerts. NDR may rediscover the device later, but it comes back as a new asset with none of the context — the importance, roles and tags someone set are gone. There is no undo.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the asset belongs to. Leave empty for your own account.
assetIdstringyesThe asset ID to delete, from wg_list_ndr_assets.
tenantNamestringnonullOptional. The target account. Leave empty to use the account above.

[WatchGuard Cloud] Returns one WatchGuard NDR asset in full — its addresses, roles, importance, threat score and when it was first and last seen. Get asset IDs from wg_list_ndr_assets. Read this before updating an asset: the update replaces the record.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the asset belongs to. Leave empty for your own account.
assetIdstringyesThe asset ID, from wg_list_ndr_assets.
tenantNamestringnonullOptional. The target account for the read. Leave empty to use the account above.

[WatchGuard Cloud] Lists the assets WatchGuard NDR knows about on the customer's network — what it has seen, what it believes each thing is, and each asset's threat score. Filter by naming both field and value together; sorting by threatScore descending is the fastest route to what deserves attention.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account to read, e.g. ACC-1234567. Leave empty for your own account.
fieldstringnonullOptional. Field to filter on. Accepted values are exactly: name, deviceType, addresses, roles, assetInformationSources, operatingSystem. Requires value.
offsetintegernonullOptional. How many assets to skip — the paging offset.
orderintegernonullOptional. Sort direction. Accepted values are exactly: 0 (ascending), 1 (descending).
sizeintegernonullOptional. How many assets to return. WatchGuard's own minimum is 10 and StackJack caps it at 100, so a smaller number is raised to 10.
sortstringnonullOptional. Field to sort by. Accepted values are exactly: name, description, deviceType, importance, firstSeen, lastSeen, smartAlertCount, threatScore.
tenantNamestringnonullOptional. The target account for the read. Leave empty to use the account above, which is what WatchGuard's own examples do.
valuestringnonullOptional. The value to match for the named field. Required when field is given.

[WatchGuard Cloud] DESTRUCTIVE. REPLACES a WatchGuard NDR asset record. WatchGuard requires the name, addresses, device type and importance on every call, so anything you leave out — the description, the roles, the tags — is cleared rather than kept. Read the asset with wg_get_ndr_asset first and send the complete record back with only your intended change.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the asset belongs to. Leave empty for your own account.
addressesJsonstringyesA JSON ARRAY of addresses, for example [{"type":"IP_V4","value":"10.0.0.15"}]. Required on every update.
assetIdstringyesThe asset ID to update, from wg_list_ndr_assets.
descriptionstringnonullOptional — but omitting it CLEARS the stored description.
deviceTypestringyesDevice types, comma-separated. Required on every update.
importanceintegeryesHow important the asset is. Accepted values are exactly: 1, 2, 3, 4, 5. Required on every update.
namestringyesThe asset name or identifier. Required by WatchGuard on every update.
rolesstringnonullOptional — but omitting it CLEARS the stored roles. Comma-separated.
tagsstringnonullOptional — but omitting it CLEARS the stored tags. Comma-separated.
tenantNamestringnonullOptional. The target account. Leave empty to use the account above.

NDR Smart Alerts

ToolPlanAccessSummary
wg_close_ndr_smart_alertProWriteCloses a WatchGuard NDR Smart Alert with a documented reason.
wg_get_ndr_smart_alertFreeRead-onlyReturns one WatchGuard NDR Smart Alert in full — the network detection, what it was raised on and why.

[WatchGuard Cloud] Closes a WatchGuard NDR Smart Alert with a documented reason. This is triage: the alert is resolved, nothing is deleted, and it is not marked destructive. BUT two of its options change what NDR does in future — allowInFuture authorizes the activity so similar traffic stops raising alerts, and includeSimilar closes other matching alerts in the same call. Leave both unset unless you mean them, because a mistaken authorization quietly suppresses a real detection later.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the alert belongs to. Leave empty for your own account.
additionalInformationstringnonullOptional. Free-text additional information.
allowInFuturestringnonullOptional. SUPPRESSES FUTURE ALERTS for this activity. Accepted values are exactly: AUTHORIZED, AUTHORIZED_ONCE. Leave unset to change nothing about future detection.
authorizedActivitiesstringnonullOptional. What is being authorized, comma-separated. Accepted values are exactly: AUTHORIZED_TIMES_FREQUENCIES, AUTHORIZED_ACTORS.
commentstringnonullOptional. A comment recorded with the close.
falsePositivebooleannonullOptional. Set true to record the alert as a false positive.
includeSimilarbooleannonullOptional. Set true to close other alerts matching this one as well. Leave unset to close only this alert.
otherReasonForClosestringnonullOptional, for the OTHER close reason. Accepted values are exactly: UI_NOT_INTERESTING, UI_NOT_CLEAR, UI_NOT_HELPFUL, OTHER.
reasonForAuthorizedAbnormalstringnonullOptional, for ABNORMAL_AUTHORIZED. Accepted values are exactly: PENETRATION_TESTING, SCANNING_APPLICATION, AD_HOC_TESTING, OTHER.
reasonForClosestringnonullOptional. Why the alert is being closed. Accepted values are exactly: ABNORMAL_UNAUTHORIZED, ABNORMAL_AUTHORIZED, NORMAL, OTHER.
reasonForIncorrectInterpretationstringnonullOptional. Why NDR's interpretation was incorrect, comma-separated.
reasonForUnauthorizedAbnormalstringnonullOptional, for ABNORMAL_UNAUTHORIZED. Accepted values are exactly: KNOWN_THREAT, UNKNOWN_THREAT, MISCONFIG, OTHER.
smartAlertIdstringyesThe Smart Alert ID to close.
tenantNamestringnonullOptional. The target account. Leave empty to use the account above.

[WatchGuard Cloud] Returns one WatchGuard NDR Smart Alert in full — the network detection, what it was raised on and why. Smart Alert IDs appear on the assets they concern and in ThreatSync incidents that correlate them.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account the alert belongs to. Leave empty for your own account.
smartAlertIdstringyesThe Smart Alert ID.
tenantNamestringnonullOptional. The target account. Leave empty to use the account above.

Platform

ToolPlanAccessSummary
wg_check_service_healthFreeRead-onlyReturns the health probe of one WatchGuard Cloud API.

[WatchGuard Cloud] Returns the health probe of one WatchGuard Cloud API. All sixteen WatchGuard APIs publish the same probe and this one tool reaches every one of them through the service selector. It proves the SERVICE is up; it does NOT prove your credential works — a revoked API key still gets a healthy answer here, so use Test Connection in StackJack, or any ordinary read, to check the credential.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account whose session the probe runs under, for example ACC-1234567. The probe itself is not account-scoped; naming a managed account checks the service through that account's session, which is what you want when one customer's calls are failing.
servicestringyesWhich WatchGuard API to probe. Accepted values are exactly: accounts, activations, allocations, authorization, authpoint, endpoint-security-aether, endpoint-security-wes, firebox-management, firebox-reports, firecloud-management, ndr-assets, ndr-smart-alerts, operator-management, orders, portal-accounts, threatsync.

Firebox Deployments

ToolPlanAccessSummary
wg_delete_firebox_deployment_transactionProDestructiveDESTRUCTIVE.
wg_deploy_firebox_configurationProDestructiveDESTRUCTIVE.
wg_disable_firebox_global_exceptionsProDestructiveDESTRUCTIVE.
wg_enable_firebox_global_exceptionsProDestructiveDESTRUCTIVE.
wg_get_firebox_deployment_transactionFreeRead-onlyReads one deployment transaction record by its id, the status of a single configuration push to a single Firebox.
wg_list_firebox_deployment_transactionsFreeRead-onlyLists the deployment transaction records for the account, one record per Firebox per configuration push, each with its status.
wg_update_firebox_deployment_transactionProDestructiveDESTRUCTIVE.

[WatchGuard Cloud] DESTRUCTIVE. Deletes one deployment transaction record, selected by its transaction id. There is no undo: WatchGuard removes the record outright and answers with the deleted object. This is NOT a cancel button - the specification publishes no cancel verb and does not say whether a scheduled push still runs once its record is gone - so move an unwanted deployment with wg_update_firebox_deployment_transaction instead of deleting its record. Confirm the record with wg_get_firebox_deployment_transaction before deleting it: a transaction whose status is complete or failed is a finished deployment, and this removes that deployment's record from the transaction list. The id comes from wg_list_firebox_deployment_transactions, or from the transaction objects wg_deploy_firebox_configuration answers with.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesThe transaction id to delete, for example ddply_12345_J2VwPbXuek3CRGN1, as answered in the id field by wg_list_firebox_deployment_transactions.

[WatchGuard Cloud] DESTRUCTIVE. Deploys the global exceptions saved in WatchGuard Cloud onto the Fireboxes you name, or the full configuration when full_config is true. This is the one Firebox Management call that leaves WatchGuard Cloud: every other configuration write in this connector is saved as pending until this runs, and what it pushes takes effect on live traffic. Name the devices explicitly instead of the whole estate. full_config decides WHAT is pushed and WatchGuard defaults it to false, which deploys global exceptions only, so a policy, network, alias, schedule or certificate change needs full_config set to true or this call succeeds and ships nothing. start_date takes the literal value now to deploy immediately or a UTC timestamp to queue it, and a queued push can be moved afterwards with wg_update_firebox_deployment_transaction. devices holds at most 50 Fireboxes, so a larger estate is more than one call, and WatchGuard creates one transaction PER DEVICE. The two success shapes differ: 201 answers a bare array of transaction objects, while 200 answers an object carrying ok, the transactions it created, and errors, a map of device id to the reason that device was SKIPPED - the vendor's own example reason is global exceptions not enabled for the device, which wg_enable_firebox_global_exceptions fixes - so read errors before reporting success. Reach for wg_list_firebox_deployment_transactions first to see what is already queued, and read each transaction back with wg_get_firebox_deployment_transaction rather than treating this answer as a finished deployment. The body is a JSON object whose fields are description, devices, full_config, start_date, version; required: devices, start_date.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe deployment request as JSON. It is a JSON object with five fields: devices, the required array of at most 50 Fireboxes to deploy to, each either the numeric WatchGuard Cloud device id shown in the URL of the Device Summary page or the FBCL-style id, for example [12345, FBCL-12345]; start_date, required, either the literal value now or a UTC timestamp such as 2020-04-19T21:23:46Z, up to 128 characters; full_config, which WatchGuard defaults to false so that only global exceptions are deployed, set to true to deploy the full configuration of a cloud-managed Firebox; description, up to 128 characters; and version, the version number of an earlier deployment, sent only to redeploy that deployment to the device. Required: devices, start_date.

[WatchGuard Cloud] DESTRUCTIVE. Disables management and deployment of global exceptions through the Firebox Management API for the Fireboxes you name, and deletes the exceptions already on them unless retain_device_configuration is true. WatchGuard defaults retain_device_configuration to false, so leaving it out DELETES the exceptions currently on every Firebox you name; send it as true to keep them, because enabling global exceptions again later does not restore what this removed. WatchGuard answers 204 No Content here, so this tool returns a short success acknowledgement rather than a transaction and there is nothing to read back. wg_enable_firebox_global_exceptions is the other half of the same switch, and it takes no retain flag. devices holds at most 50 Fireboxes. The body is a JSON object whose fields are devices, retain_device_configuration; required: devices.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe request body as JSON. It is a JSON object with two fields: devices, the required array of at most 50 Fireboxes to disable global exceptions for, each either the numeric WatchGuard Cloud device id shown in the URL of the Device Summary page or the FBCL-style id, for example [12345, FBCL-12345]; and retain_device_configuration, a boolean WatchGuard defaults to false, where false DELETES the exceptions already on those Fireboxes and true keeps them. Required: devices.

[WatchGuard Cloud] DESTRUCTIVE. Enables management and deployment of global exceptions through the Firebox Management API for the Fireboxes you name. This is the switch that lets exception changes made through this API reach those Fireboxes at the next deployment, and its other half, wg_disable_firebox_global_exceptions, can delete the exceptions already on a device. It is the prerequisite of wg_deploy_firebox_configuration: a deployment does not fail for a Firebox that has global exceptions disabled, it SKIPS that device and names it in the response's errors map. WatchGuard answers 204 No Content here, so this tool returns a short success acknowledgement rather than a transaction and there is nothing to read back. devices holds at most 50 Fireboxes. The body is a JSON object whose fields are devices; required: devices.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe request body as JSON. It is a JSON object with one field, devices: the required array of at most 50 Fireboxes to enable global exceptions for, each either the numeric WatchGuard Cloud device id shown in the URL of the Device Summary page or the FBCL-style id, for example [12345, FBCL-12345]. Required: devices.

[WatchGuard Cloud] Reads one deployment transaction record by its id, the status of a single configuration push to a single Firebox. This is the read-back for every write in this family: wg_deploy_firebox_configuration answers the transaction objects it created, and this tool re-reads one of them by id until its status settles. WatchGuard answers an ARRAY here even for a single record. status is one of scheduled, imaged, pending, in_progress, complete or failed, so a transaction that has not reached complete is not a deployed configuration, and original_author_username is always empty for transactions the Firebox Management API created. The id comes from wg_list_firebox_deployment_transactions, or from the transaction objects wg_deploy_firebox_configuration answers with.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesThe transaction id to read, for example ddply_12345_J2VwPbXuek3CRGN1, as answered in the id field by wg_list_firebox_deployment_transactions or by wg_deploy_firebox_configuration.

[WatchGuard Cloud] Lists the deployment transaction records for the account, one record per Firebox per configuration push, each with its status. Reach for this first in this family: it shows what is already queued or running before another push is added with wg_deploy_firebox_configuration. Each record carries id, device, account, inception_time, start_date and status, where status is one of scheduled, imaged, pending, in_progress, complete or failed, so a transaction that has not reached complete is not a deployed configuration. original_author_username is always empty for transactions the Firebox Management API created, so a blank operator is expected rather than missing data. The id returned here is what wg_get_firebox_deployment_transaction, wg_update_firebox_deployment_transaction and wg_delete_firebox_deployment_transaction take. WatchGuard declares no paging on this route - no page size, no offset and no cursor - so one call returns the WHOLE collection for the account; on a large estate expect a large result, and narrow it with device.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
deviceintegernonullOptional. Narrows the list to one Firebox. WatchGuard types this filter as an integer, so it takes the numeric device id shown in the URL of the Device Summary page; the FBCL-style id that the devices array of wg_deploy_firebox_configuration also accepts is not accepted here.
txTypestringyesThe kind of transaction record to retrieve. It is required, and WatchGuard accepts exactly one value today: deployment.

[WatchGuard Cloud] DESTRUCTIVE. Reschedules one deployment transaction, selected by its transaction id, by replacing its start date. start_date is required, so one call replaces the schedule of a pending deployment: the literal value now brings a queued configuration push FORWARD onto live Fireboxes immediately. WatchGuard documents this as a replace, so send description back alongside it to keep it - the transaction object in the answer carries no description field to read a lost one back from. Read the record first with wg_get_firebox_deployment_transaction: a transaction whose status has already left scheduled is a push that has started or finished. WatchGuard answers with the updated transaction record, as an ARRAY, and publishes no separate cancel verb for a queued deployment. The id comes from wg_list_firebox_deployment_transactions, or from the transaction objects wg_deploy_firebox_configuration answers with. The body is a JSON object whose fields are description, start_date; required: start_date.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe replacement transaction record as JSON. It is a JSON object with two fields: start_date, required, either the literal value now to deploy immediately or a UTC timestamp such as 2020-04-19T21:23:46Z, up to 128 characters; and description, up to 128 characters. Required: start_date.
objectidstringyesThe transaction id to update, for example ddply_12345_J2VwPbXuek3CRGN1, as answered in the id field by wg_list_firebox_deployment_transactions.

Firebox Authentication

ToolPlanAccessSummary
wg_get_firebox_auth_groupFreeRead-onlyReads one Firebox authentication group, the umbrella group a firewall policy matches users against, by object id.
wg_get_firebox_authpoint_user_groupFreeRead-onlyReads one AuthPoint user or group reference held in Firebox configuration, by object id.
wg_get_firebox_saml_user_groupFreeRead-onlyReads one SAML user or group reference held in Firebox configuration, by object id.
wg_get_firebox_userFreeRead-onlyReads one Firebox local user account by object id.
wg_get_firebox_user_groupFreeRead-onlyReads one Firebox local user group by object id.
wg_list_firebox_auth_groupsFreeRead-onlyLists the Firebox authentication groups, the umbrella groups a firewall policy matches users against, for the account, or for one Firebox or one template.
wg_list_firebox_authpoint_user_groupsFreeRead-onlyLists the AuthPoint users and groups this Firebox configuration references, for the account, or for one Firebox or one template.
wg_list_firebox_saml_user_groupsFreeRead-onlyLists the SAML users and groups this Firebox configuration references, for the account, or for one Firebox or one template.
wg_list_firebox_user_groupsFreeRead-onlyLists the Firebox local user groups, whose members are Firebox users, for the account, or for one Firebox or one template.
wg_list_firebox_usersFreeRead-onlyLists the Firebox local user accounts for the account, or for one Firebox or one template.

[WatchGuard Cloud] Reads one Firebox authentication group, the umbrella group a firewall policy matches users against, by object id. Answers the typed domains array (firebox_domain, authentication_domain, authpoint_domain or saml_settings) and the typed members array (firebox_user, firebox_group, shared_user_group, authpoint_user_group or saml_user_group), which together resolve a policy's user match. Object ids come from wg_list_firebox_auth_groups.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesThe auth group's object id, as answered in the id member of wg_list_firebox_auth_groups.

[WatchGuard Cloud] Reads one AuthPoint user or group reference held in Firebox configuration, by object id. Answers the pointer WatchGuard stores, which is name, type (user or group) and the AuthPoint domain reference, not the AuthPoint object itself. Object ids come from wg_list_firebox_authpoint_user_groups.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesThe AuthPoint user group's object id, as answered in the id member of wg_list_firebox_authpoint_user_groups.

[WatchGuard Cloud] Reads one SAML user or group reference held in Firebox configuration, by object id. Answers name, which the vendor constrains to an email address or a user name, type (user or group), the SAML domain reference and movpn_enforcement. Object ids come from wg_list_firebox_saml_user_groups.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesThe SAML user group's object id, as answered in the id member of wg_list_firebox_saml_user_groups.

[WatchGuard Cloud] Reads one Firebox local user account by object id. THE RESPONSE IS CREDENTIAL MATERIAL: password is a required member of WatchGuard's firebox_user schema, so this body carries the user's Firebox password in the clear. Treat it as a secret and never paste it into a ticket, a chat or a document. The body also carries name, description, the session and idle timeouts in seconds, the authentication domain and the groups the user belongs to. Object ids come from wg_list_firebox_users.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesThe user's object id, as answered in the id member of wg_list_firebox_users.

[WatchGuard Cloud] Reads one Firebox local user group by object id. Answers name, description, the optional authentication domain and the members array of references to Firebox users. Object ids come from wg_list_firebox_user_groups; wg_get_firebox_auth_group reads the umbrella authentication group kind instead.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesThe group's object id, as answered in the id member of wg_list_firebox_user_groups.

[WatchGuard Cloud] Lists the Firebox authentication groups, the umbrella groups a firewall policy matches users against, for the account, or for one Firebox or one template. An auth group is the one kind that spans identity sources: its domains array names firebox_domain, authentication_domain, authpoint_domain or saml_settings entries, and its members array is typed firebox_user, firebox_group, shared_user_group, authpoint_user_group or saml_user_group. That is where a policy's user match is actually resolved, so reach here first when tracing which users a policy applies to; the four other lists in this group read the individual member kinds. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
devicestringnonullOptional. The Firebox ID in WatchGuard Cloud, for example FBCL-136162 or 136162, to read only that Firebox's auth groups. Mutually exclusive with templateid; omit both and the account's own auth groups are returned.
templateidstringnonullOptional. The account-level template ID, for example tmpl_ABCDEFG, to read only that template's auth groups. Mutually exclusive with device; omit both and the account's own auth groups are returned.

[WatchGuard Cloud] Lists the AuthPoint users and groups this Firebox configuration references, for the account, or for one Firebox or one template. Each entry is a POINTER into an AuthPoint domain rather than the AuthPoint object itself: name, type (user or group) and the domain reference. It says which AuthPoint identities this Firebox configuration can match, not what AuthPoint holds. The policy side is wg_list_firebox_auth_groups, and wg_list_firebox_saml_user_groups is the same shape for a SAML identity provider. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
devicestringnonullOptional. The Firebox ID in WatchGuard Cloud, for example FBCL-136162 or 136162, to read only that Firebox's AuthPoint user groups. Mutually exclusive with templateid; omit both and the account's own AuthPoint user groups are returned.
templateidstringnonullOptional. The account-level template ID, for example tmpl_ABCDEFG, to read only that template's AuthPoint user groups. Mutually exclusive with device; omit both and the account's own AuthPoint user groups are returned.

[WatchGuard Cloud] Lists the SAML users and groups this Firebox configuration references, for the account, or for one Firebox or one template. Each entry is a POINTER into a SAML identity provider: name, which the vendor constrains to an email address or a user name, type (user or group), the domain reference, and movpn_enforcement, the one member the AuthPoint equivalent does not carry. Use wg_list_firebox_authpoint_user_groups for the AuthPoint side and wg_list_firebox_auth_groups for the groups a policy matches on. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
devicestringnonullOptional. The Firebox ID in WatchGuard Cloud, for example FBCL-136162 or 136162, to read only that Firebox's SAML user groups. Mutually exclusive with templateid; omit both and the account's own SAML user groups are returned.
templateidstringnonullOptional. The account-level template ID, for example tmpl_ABCDEFG, to read only that template's SAML user groups. Mutually exclusive with device; omit both and the account's own SAML user groups are returned.

[WatchGuard Cloud] Lists the Firebox local user groups, whose members are Firebox users, for the account, or for one Firebox or one template. Each group carries name, description, an optional authentication domain and a members array of references to Firebox users, which wg_list_firebox_users reads. This is the LOCAL group kind: wg_list_firebox_auth_groups reads the umbrella authentication groups a firewall policy matches users against, and the AuthPoint and SAML lists read pointers into those identity providers. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
devicestringnonullOptional. The Firebox ID in WatchGuard Cloud, for example FBCL-136162 or 136162, to read only that Firebox's groups. Mutually exclusive with templateid; omit both and the account's own groups are returned.
templateidstringnonullOptional. The account-level template ID, for example tmpl_ABCDEFG, to read only that template's groups. Mutually exclusive with device; omit both and the account's own groups are returned.

[WatchGuard Cloud] Lists the Firebox local user accounts for the account, or for one Firebox or one template. THE RESPONSE IS CREDENTIAL MATERIAL: password is a required member of WatchGuard's firebox_user schema, so every object in this list carries that user's Firebox password in the clear. Treat the result as a secret and never paste it into a ticket, a chat or a document. Reach here first for who can authenticate to a Firebox; wg_get_firebox_user reads one account back by id and wg_list_firebox_user_groups shows their group membership. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
devicestringnonullOptional. The Firebox ID in WatchGuard Cloud, for example FBCL-136162 or 136162, to read only that Firebox's users. Mutually exclusive with templateid; omit both and the account's own users are returned.
templateidstringnonullOptional. The account-level template ID, for example tmpl_ABCDEFG, to read only that template's users. Mutually exclusive with device; omit both and the account's own users are returned.

Firebox Exceptions

ToolPlanAccessSummary
wg_create_firebox_blocked_site_exceptionProDestructiveDESTRUCTIVE.
wg_create_firebox_botnet_site_exceptionProWriteCreates a new botnet site exception.
wg_create_firebox_file_exceptionProWriteCreates a new file exception.
wg_create_firebox_geolocation_exceptionProWriteCreates a new Geolocation exception.
wg_create_firebox_ips_signature_exceptionProWriteCreates a new IPS signature exception.
wg_create_firebox_webblocker_exceptionProDestructiveDESTRUCTIVE.
wg_delete_firebox_blocked_site_exceptionProDestructiveDESTRUCTIVE.
wg_delete_firebox_botnet_site_exceptionProDestructiveDESTRUCTIVE.
wg_delete_firebox_file_exceptionProDestructiveDESTRUCTIVE.
wg_delete_firebox_geolocation_exceptionProDestructiveDESTRUCTIVE.
wg_delete_firebox_ips_signature_exceptionProDestructiveDESTRUCTIVE.
wg_delete_firebox_webblocker_exceptionProDestructiveDESTRUCTIVE.
wg_get_firebox_blocked_site_exceptionFreeRead-onlyRetrieves the specified blocked sites exception.
wg_get_firebox_botnet_site_exceptionFreeRead-onlyRetrieves the specified botnet site exception.
wg_get_firebox_file_exceptionFreeRead-onlyRetrieves the specified file exception.
wg_get_firebox_geolocation_exceptionFreeRead-onlyRetrieves the specified Geolocation exception.
wg_get_firebox_ips_signature_exceptionFreeRead-onlyRetrieves the specified IPS signature exception.
wg_get_firebox_webblocker_exceptionFreeRead-onlyRetrieves the specified WebBlocker exception.
wg_list_firebox_blocked_site_exceptionsFreeRead-onlyLists the blocked sites exceptions saved in the WatchGuard Cloud account.
wg_list_firebox_blocked_site_exceptions_v1FreeRead-onlyDEPRECATED by WatchGuard: use wg_list_firebox_blocked_site_exceptions instead, which reads the same saved blocked sites exceptions.
wg_list_firebox_botnet_site_exceptionsFreeRead-onlyLists the botnet site exceptions saved in the WatchGuard Cloud account.
wg_list_firebox_botnet_site_exceptions_v1FreeRead-onlyDEPRECATED by WatchGuard: use wg_list_firebox_botnet_site_exceptions instead, which reads the same saved botnet site exceptions.
wg_list_firebox_exceptionsFreeRead-onlyLists every exception saved in the WatchGuard Cloud account in one response - blocked sites, botnet sites, files, Geolocation, IPS signatures and WebBlocker together.
wg_list_firebox_exceptions_v1FreeRead-onlyDEPRECATED by WatchGuard: use wg_list_firebox_exceptions instead, which reads the same saved exceptions of all six kinds.
wg_list_firebox_file_exceptionsFreeRead-onlyLists the file exceptions saved in the WatchGuard Cloud account.
wg_list_firebox_file_exceptions_v1FreeRead-onlyDEPRECATED by WatchGuard: use wg_list_firebox_file_exceptions instead, which reads the same saved file exceptions.
wg_list_firebox_geolocation_exceptionsFreeRead-onlyLists the Geolocation exceptions saved in the WatchGuard Cloud account.
wg_list_firebox_geolocation_exceptions_v1FreeRead-onlyDEPRECATED by WatchGuard: use wg_list_firebox_geolocation_exceptions instead, which reads the same saved Geolocation exceptions.
wg_list_firebox_ips_signature_exceptionsFreeRead-onlyLists the IPS signature exceptions saved in the WatchGuard Cloud account.
wg_list_firebox_ips_signature_exceptions_v1FreeRead-onlyDEPRECATED by WatchGuard: use wg_list_firebox_ips_signature_exceptions instead, which reads the same saved IPS signature exceptions.
wg_list_firebox_webblocker_exceptionsFreeRead-onlyLists the WebBlocker exceptions saved in the WatchGuard Cloud account.
wg_list_firebox_webblocker_exceptions_v1FreeRead-onlyDEPRECATED by WatchGuard: use wg_list_firebox_webblocker_exceptions instead, which reads the same saved WebBlocker exceptions.
wg_update_firebox_blocked_site_exceptionProDestructiveDESTRUCTIVE.
wg_update_firebox_botnet_site_exceptionProDestructiveDESTRUCTIVE.
wg_update_firebox_file_exceptionProDestructiveDESTRUCTIVE.
wg_update_firebox_geolocation_exceptionProDestructiveDESTRUCTIVE.
wg_update_firebox_ips_signature_exceptionProDestructiveDESTRUCTIVE.
wg_update_firebox_webblocker_exceptionProDestructiveDESTRUCTIVE.

[WatchGuard Cloud] DESTRUCTIVE. Creates a new blocked sites exception. The value of the action parameter specifies whether the Firebox allows or blocks traffic for the site. The action field decides whether the Firebox ALLOWS or BLOCKS the site - allow puts the address on the Blocked Sites Exception list, block puts it on the Blocked Sites list - and it DEFAULTS TO allow when omitted, so a create that names no action opens traffic an administrator may have meant to stop. It is saved in WatchGuard Cloud only: no Firebox enforces it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. That deployment answers global_exceptions not enabled for device for any Firebox that wg_enable_firebox_global_exceptions has not enabled first. The response carries the new exception's id and version. The body is a JSON object whose fields are action, address, description, device; required: address.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe new blocked sites exception as a JSON object. address is required and is an object with type and value, where type is ipv4_host, ipv4_range, ipv4_network or fqdn (for example type fqdn with value example.com, or type ipv4_range with value 192.0.2.1-192.0.2.5). action is allow or block and DEFAULTS TO allow when omitted - allow puts the address on the Blocked Sites Exception list, block puts it on the Blocked Sites list. description is free text up to 127 characters, and device scopes the exception to one Firebox and takes the ID that appears in the URL of that device's Summary page; leave it out for a global exception.

[WatchGuard Cloud] Creates a new botnet site exception. It is saved in WatchGuard Cloud only: no Firebox enforces it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. That deployment answers global_exceptions not enabled for device for any Firebox that wg_enable_firebox_global_exceptions has not enabled first. The response carries the new exception's id and version. The body is a JSON object whose fields are address, description, device; required: address.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe new botnet site exception as a JSON object. address is required and is an object with type and value, where type is ipv4_host, ipv4_range, ipv4_network or fqdn (for example type fqdn with value example.com, or type ipv4_range with value 192.0.2.1-192.0.2.5). There is no action field on this schema - a botnet site exception names an address only. description is free text up to 127 characters, and device scopes the exception to one Firebox and takes the ID that appears in the URL of that device's Summary page; leave it out for a global exception.

[WatchGuard Cloud] Creates a new file exception. It is saved in WatchGuard Cloud only: no Firebox enforces it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. That deployment answers global_exceptions not enabled for device for any Firebox that wg_enable_firebox_global_exceptions has not enabled first. The response carries the new exception's id and version. The body is a JSON object whose fields are action, description, device, md5; required: action, md5.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe new file exception as a JSON object. action is required and is allow or drop. md5 is required and is the file's MD5 hash as exactly 32 lowercase hexadecimal characters. description is free text up to 127 characters, and device scopes the exception to one Firebox and takes the ID that appears in the URL of that device's Summary page; leave it out for a global exception.

[WatchGuard Cloud] Creates a new Geolocation exception. It is saved in WatchGuard Cloud only: no Firebox enforces it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. That deployment answers global_exceptions not enabled for device for any Firebox that wg_enable_firebox_global_exceptions has not enabled first. The response carries the new exception's id and version. The body is a JSON object whose fields are address, description, device; required: address.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe new Geolocation exception as a JSON object. address is required and is an object with type and value, where type is ipv4_host, ipv4_range, ipv4_network or fqdn (for example type fqdn with value example.com, or type ipv4_range with value 192.0.2.1-192.0.2.5). There is no country field on this schema - the exception is named by address. description is free text up to 127 characters, and device scopes the exception to one Firebox and takes the ID that appears in the URL of that device's Summary page; leave it out for a global exception.

[WatchGuard Cloud] Creates a new IPS signature exception. It is saved in WatchGuard Cloud only: no Firebox enforces it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. That deployment answers global_exceptions not enabled for device for any Firebox that wg_enable_firebox_global_exceptions has not enabled first. The response carries the new exception's id and version. The body is a JSON object whose fields are action, alarm, description, device, signature_id; required: action, signature_id.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe new IPS signature exception as a JSON object. action is required and is allow, block or drop. signature_id is required and is ONE numeric signature ID of up to 31 digits, for example 1054265 - one exception covers one signature. alarm is a boolean that defaults to false. description is free text up to 127 characters, and device scopes the exception to one Firebox and takes the ID that appears in the URL of that device's Summary page; leave it out for a global exception.

[WatchGuard Cloud] DESTRUCTIVE. Creates a new WebBlocker exception. The action field decides whether the exception allows or denies every URL its rule matches, so a wrong value either opens web traffic the customer's policy refuses or blocks a site the customer needs. It is saved in WatchGuard Cloud only: no Firebox enforces it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. That deployment answers global_exceptions not enabled for device for any Firebox that wg_enable_firebox_global_exceptions has not enabled first. The response carries the new exception's id and version. The body is a JSON object whose fields are action, alarm, device, name, rule, rule_type; required: action, name, rule, rule_type.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe new WebBlocker exception as a JSON object. action is required and is allow or deny. name is required, up to 58 characters. rule_type is required and is string (exact match), pattern (pattern match) or regexp (regular expression), and rule is required and is the URL value or expression it matches, up to 255 characters - the vendor's own example object pairs rule_type string with rule www.example.com/*. alarm is a boolean that defaults to false, and device scopes the exception to one Firebox and takes the ID that appears in the URL of that device's Summary page; leave it out for a global exception.

[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified blocked sites exception. There is no undo: WatchGuard publishes no restore for a deleted exception and recreating it with wg_create_firebox_blocked_site_exception mints a new id, so confirm the id with wg_get_firebox_blocked_site_exception before you call this. WatchGuard answers with the deleted exception, marked inactive. The removal is saved in WatchGuard Cloud only: no Firebox stops enforcing the exception until wg_deploy_firebox_configuration pushes the account's exceptions to the devices.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the blocked sites exception to delete, as returned by wg_list_firebox_blocked_site_exceptions (for example bse_12345_ARBHLJ70Y78rGOIGBS).

[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified botnet site exception. There is no undo: WatchGuard publishes no restore for a deleted exception and recreating it with wg_create_firebox_botnet_site_exception mints a new id, so confirm the id with wg_get_firebox_botnet_site_exception before you call this. WatchGuard answers with the deleted exception, marked inactive. The removal is saved in WatchGuard Cloud only: no Firebox stops enforcing the exception until wg_deploy_firebox_configuration pushes the account's exceptions to the devices.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the botnet site exception to delete, as returned by wg_list_firebox_botnet_site_exceptions (for example bote_CjBY92ourN7Izaa1jJu3eH5).

[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified file exception. There is no undo: WatchGuard publishes no restore for a deleted exception and recreating it with wg_create_firebox_file_exception mints a new id, so confirm the id with wg_get_firebox_file_exception before you call this. WatchGuard answers with the deleted exception, marked inactive. The removal is saved in WatchGuard Cloud only: no Firebox stops enforcing the exception until wg_deploy_firebox_configuration pushes the account's exceptions to the devices.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the file exception to delete, as returned by wg_list_firebox_file_exceptions (for example file_12345_UqhDVIdx8D5iwivAX).

[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified Geolocation exception. There is no undo: WatchGuard publishes no restore for a deleted exception and recreating it with wg_create_firebox_geolocation_exception mints a new id, so confirm the id with wg_get_firebox_geolocation_exception before you call this. WatchGuard answers with the deleted exception, marked inactive. The removal is saved in WatchGuard Cloud only: no Firebox stops enforcing the exception until wg_deploy_firebox_configuration pushes the account's exceptions to the devices.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the Geolocation exception to delete, as returned by wg_list_firebox_geolocation_exceptions (for example geoe_12345_aHbWC5IuWO3qzyV2t).

[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified IPS signature exception. There is no undo: WatchGuard publishes no restore for a deleted exception and recreating it with wg_create_firebox_ips_signature_exception mints a new id, so confirm the id with wg_get_firebox_ips_signature_exception before you call this. WatchGuard answers with the deleted exception, marked inactive. The removal is saved in WatchGuard Cloud only: no Firebox stops enforcing the exception until wg_deploy_firebox_configuration pushes the account's exceptions to the devices.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the IPS signature exception to delete, as returned by wg_list_firebox_ips_signature_exceptions (for example ipse_12345_eY5Jwxv1nE3Xlk3zx).

[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified WebBlocker exception. There is no undo: WatchGuard publishes no restore for a deleted exception and recreating it with wg_create_firebox_webblocker_exception mints a new id, so confirm the id with wg_get_firebox_webblocker_exception before you call this. WatchGuard answers with the deleted exception, marked inactive. The removal is saved in WatchGuard Cloud only: no Firebox stops enforcing the exception until wg_deploy_firebox_configuration pushes the account's exceptions to the devices.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the WebBlocker exception to delete, as returned by wg_list_firebox_webblocker_exceptions (for example wbe_12124_7HM70EvrifZ7rSfXSA).

[WatchGuard Cloud] Retrieves the specified blocked sites exception. The id comes from wg_list_firebox_blocked_site_exceptions and looks like bse_12345_ARBHLJ70Y78rGOIGBS. The response carries the version that wg_update_firebox_blocked_site_exception requires, so read the exception before you replace it.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the blocked sites exception to retrieve, as returned by wg_list_firebox_blocked_site_exceptions (for example bse_12345_ARBHLJ70Y78rGOIGBS).

[WatchGuard Cloud] Retrieves the specified botnet site exception. The id comes from wg_list_firebox_botnet_site_exceptions and looks like bote_CjBY92ourN7Izaa1jJu3eH5. The response carries the version that wg_update_firebox_botnet_site_exception requires, so read the exception before you replace it.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the botnet site exception to retrieve, as returned by wg_list_firebox_botnet_site_exceptions (for example bote_CjBY92ourN7Izaa1jJu3eH5).

[WatchGuard Cloud] Retrieves the specified file exception. The id comes from wg_list_firebox_file_exceptions and looks like file_12345_UqhDVIdx8D5iwivAX. The response carries the version that wg_update_firebox_file_exception requires, so read the exception before you replace it.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the file exception to retrieve, as returned by wg_list_firebox_file_exceptions (for example file_12345_UqhDVIdx8D5iwivAX).

[WatchGuard Cloud] Retrieves the specified Geolocation exception. The id comes from wg_list_firebox_geolocation_exceptions and looks like geoe_12345_aHbWC5IuWO3qzyV2t. The response carries the version that wg_update_firebox_geolocation_exception requires, so read the exception before you replace it.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the Geolocation exception to retrieve, as returned by wg_list_firebox_geolocation_exceptions (for example geoe_12345_aHbWC5IuWO3qzyV2t).

[WatchGuard Cloud] Retrieves the specified IPS signature exception. The id comes from wg_list_firebox_ips_signature_exceptions and looks like ipse_12345_eY5Jwxv1nE3Xlk3zx. The response carries the version that wg_update_firebox_ips_signature_exception requires, so read the exception before you replace it.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the IPS signature exception to retrieve, as returned by wg_list_firebox_ips_signature_exceptions (for example ipse_12345_eY5Jwxv1nE3Xlk3zx).

[WatchGuard Cloud] Retrieves the specified WebBlocker exception. The id comes from wg_list_firebox_webblocker_exceptions and looks like wbe_12124_7HM70EvrifZ7rSfXSA. The response carries the version that wg_update_firebox_webblocker_exception requires, so read the exception before you replace it.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the WebBlocker exception to retrieve, as returned by wg_list_firebox_webblocker_exceptions (for example wbe_12124_7HM70EvrifZ7rSfXSA).

[WatchGuard Cloud] Lists the blocked sites exceptions saved in the WatchGuard Cloud account. This is the blocked sites kind only; wg_list_firebox_exceptions returns all six kinds in one call. The response is an object with count, more, objects and start_after, so when more is true call again with start_after set to the value the response returned. Each object carries the id that wg_get_firebox_blocked_site_exception, wg_update_firebox_blocked_site_exception and wg_delete_firebox_blocked_site_exception take, and the version that an update has to send back.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
limitintegernonullOptional. Maximum number of blocked sites exceptions to return in one response. WatchGuard publishes no maximum of its own; StackJack always sends this parameter, at 50 when you omit it, and caps it at 100 per call.
querystringnonullOptional. Lucene query that selects which blocked sites exceptions to return. WatchGuard's own example is action:"block" AND address.type:"ipv4_range".
startAfterstringnonullOptional. Paging cursor. WatchGuard documents it as the ID of the first blocked sites exception to return; pass the start_after value the previous response returned (for example bse_12345_ARBHLJ70Y78rGOIGBS).

[WatchGuard Cloud] DEPRECATED by WatchGuard: use wg_list_firebox_blocked_site_exceptions instead, which reads the same saved blocked sites exceptions. This v1 route declares no paging at all, so one call returns the WHOLE collection for the account and on a large estate that is a large result. It also answers a bare JSON array where the v2 read answers an object with count, more, objects and start_after.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
querystringnonullOptional. Lucene query that selects which blocked sites exceptions to return. WatchGuard's own example is action:"block" AND address.type:"ipv4_range".

[WatchGuard Cloud] Lists the botnet site exceptions saved in the WatchGuard Cloud account. This is the botnet site kind only; wg_list_firebox_exceptions returns all six kinds in one call. The response is an object with count, more, objects and start_after, so when more is true call again with start_after set to the value the response returned. Each object carries the id that wg_get_firebox_botnet_site_exception, wg_update_firebox_botnet_site_exception and wg_delete_firebox_botnet_site_exception take, and the version that an update has to send back.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
limitintegernonullOptional. Maximum number of botnet site exceptions to return in one response. WatchGuard publishes no maximum of its own; StackJack always sends this parameter, at 50 when you omit it, and caps it at 100 per call.
querystringnonullOptional. Lucene query that selects which botnet site exceptions to return. WatchGuard's own example is device:12345 AND address.type:"ipv4_range".
startAfterstringnonullOptional. Paging cursor. WatchGuard documents it as the ID of the first botnet site exception to return; pass the start_after value the previous response returned (for example bote_CjBY92ourN7Izaa1jJu3eH5).

[WatchGuard Cloud] DEPRECATED by WatchGuard: use wg_list_firebox_botnet_site_exceptions instead, which reads the same saved botnet site exceptions. This v1 route declares no paging at all, so one call returns the WHOLE collection for the account and on a large estate that is a large result. It also answers a bare JSON array where the v2 read answers an object with count, more, objects and start_after.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
querystringnonullOptional. Lucene query that selects which botnet site exceptions to return. WatchGuard's own example is device:12345 AND address.type:"ipv4_range".

[WatchGuard Cloud] Lists every exception saved in the WatchGuard Cloud account in one response - blocked sites, botnet sites, files, Geolocation, IPS signatures and WebBlocker together. Start here rather than with the six per-kind lists, and narrow the result with query. The response is an object with count, more, objects and start_after, so when more is true call again with start_after set to the value the response returned. Each object carries the id that the get, update and delete tools take and the version that an update has to send back. These are saved objects: a Firebox enforces them only after wg_deploy_firebox_configuration pushes them.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
limitintegernonullOptional. Maximum number of exceptions to return in one response. WatchGuard publishes no maximum of its own; StackJack always sends this parameter, at 50 when you omit it, and caps it at 100 per call.
querystringnonullOptional. Lucene query that selects which exceptions to return. WatchGuard's own example is object:"botnet_exception" AND address.value:"www.example.com".
startAfterstringnonullOptional. Paging cursor. WatchGuard documents it as the ID of the first exception to return; pass the start_after value the previous response returned (for example bse_12345_ARBHLJ70Y78rGOIGBS).

[WatchGuard Cloud] DEPRECATED by WatchGuard: use wg_list_firebox_exceptions instead, which reads the same saved exceptions of all six kinds. This v1 route declares no paging at all, so one call returns the WHOLE collection for the account and on a large estate that is a large result. It also answers a bare JSON array where the v2 read answers an object with count, more, objects and start_after.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
querystringnonullOptional. Lucene query that selects which exceptions to return. WatchGuard's own example is object:"botnet_exception" AND address.value:"www.example.com".

[WatchGuard Cloud] Lists the file exceptions saved in the WatchGuard Cloud account. This is the file kind only; wg_list_firebox_exceptions returns all six kinds in one call. The response is an object with count, more, objects and start_after, so when more is true call again with start_after set to the value the response returned. Each object carries the id that wg_get_firebox_file_exception, wg_update_firebox_file_exception and wg_delete_firebox_file_exception take, and the version that an update has to send back.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
limitintegernonullOptional. Maximum number of file exceptions to return in one response. WatchGuard publishes no maximum of its own; StackJack always sends this parameter, at 50 when you omit it, and caps it at 100 per call.
querystringnonullOptional. Lucene query that selects which file exceptions to return. WatchGuard's own example is device:12345 AND action:"allow".
startAfterstringnonullOptional. Paging cursor. WatchGuard documents it as the ID of the first file exception to return; pass the start_after value the previous response returned (for example file_12345_UqhDVIdx8D5iwivAX).

[WatchGuard Cloud] DEPRECATED by WatchGuard: use wg_list_firebox_file_exceptions instead, which reads the same saved file exceptions. This v1 route declares no paging at all, so one call returns the WHOLE collection for the account and on a large estate that is a large result. It also answers a bare JSON array where the v2 read answers an object with count, more, objects and start_after.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
querystringnonullOptional. Lucene query that selects which file exceptions to return. WatchGuard's own example is device:12345 AND action:"allow".

[WatchGuard Cloud] Lists the Geolocation exceptions saved in the WatchGuard Cloud account. This is the Geolocation kind only; wg_list_firebox_exceptions returns all six kinds in one call. The response is an object with count, more, objects and start_after, so when more is true call again with start_after set to the value the response returned. Each object carries the id that wg_get_firebox_geolocation_exception, wg_update_firebox_geolocation_exception and wg_delete_firebox_geolocation_exception take, and the version that an update has to send back.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
limitintegernonullOptional. Maximum number of Geolocation exceptions to return in one response. WatchGuard publishes no maximum of its own; StackJack always sends this parameter, at 50 when you omit it, and caps it at 100 per call.
querystringnonullOptional. Lucene query that selects which Geolocation exceptions to return. WatchGuard's own example is device:12345 AND address.type:"ipv4_range".
startAfterstringnonullOptional. Paging cursor. WatchGuard documents it as the ID of the first Geolocation exception to return; pass the start_after value the previous response returned (for example geoe_12345_aHbWC5IuWO3qzyV2t).

[WatchGuard Cloud] DEPRECATED by WatchGuard: use wg_list_firebox_geolocation_exceptions instead, which reads the same saved Geolocation exceptions. This v1 route declares no paging at all, so one call returns the WHOLE collection for the account and on a large estate that is a large result. It also answers a bare JSON array where the v2 read answers an object with count, more, objects and start_after.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
querystringnonullOptional. Lucene query that selects which Geolocation exceptions to return. WatchGuard's own example is device:12345 AND address.type:"ipv4_range".

[WatchGuard Cloud] Lists the IPS signature exceptions saved in the WatchGuard Cloud account. This is the IPS signature kind only; wg_list_firebox_exceptions returns all six kinds in one call. The response is an object with count, more, objects and start_after, so when more is true call again with start_after set to the value the response returned. Each object carries the id that wg_get_firebox_ips_signature_exception, wg_update_firebox_ips_signature_exception and wg_delete_firebox_ips_signature_exception take, and the version that an update has to send back.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
limitintegernonullOptional. Maximum number of IPS signature exceptions to return in one response. WatchGuard publishes no maximum of its own; StackJack always sends this parameter, at 50 when you omit it, and caps it at 100 per call.
querystringnonullOptional. Lucene query that selects which IPS signature exceptions to return. WatchGuard's own example is device:12345 AND signature_id:"1054265".
startAfterstringnonullOptional. Paging cursor. WatchGuard documents it as the ID of the first IPS signature exception to return; pass the start_after value the previous response returned (for example ipse_12345_eY5Jwxv1nE3Xlk3zx).

[WatchGuard Cloud] DEPRECATED by WatchGuard: use wg_list_firebox_ips_signature_exceptions instead, which reads the same saved IPS signature exceptions. This v1 route declares no paging at all, so one call returns the WHOLE collection for the account and on a large estate that is a large result. It also answers a bare JSON array where the v2 read answers an object with count, more, objects and start_after.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
querystringnonullOptional. Lucene query that selects which IPS signature exceptions to return. WatchGuard's own example is device:12345 AND signature_id:"1054265".

[WatchGuard Cloud] Lists the WebBlocker exceptions saved in the WatchGuard Cloud account. This is the WebBlocker kind only; wg_list_firebox_exceptions returns all six kinds in one call. The response is an object with count, more, objects and start_after, so when more is true call again with start_after set to the value the response returned. Each object carries the id that wg_get_firebox_webblocker_exception, wg_update_firebox_webblocker_exception and wg_delete_firebox_webblocker_exception take, and the version that an update has to send back.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
limitintegernonullOptional. Maximum number of WebBlocker exceptions to return in one response. WatchGuard publishes no maximum of its own; StackJack always sends this parameter, at 50 when you omit it, and caps it at 100 per call.
querystringnonullOptional. Lucene query that selects which WebBlocker exceptions to return. WatchGuard's own example is device:12345 AND rule_type:"string".
startAfterstringnonullOptional. Paging cursor. WatchGuard documents it as the ID of the first WebBlocker exception to return; pass the start_after value the previous response returned (for example wbe_12124_7HM70EvrifZ7rSfXSA).

[WatchGuard Cloud] DEPRECATED by WatchGuard: use wg_list_firebox_webblocker_exceptions instead, which reads the same saved WebBlocker exceptions. This v1 route declares no paging at all, so one call returns the WHOLE collection for the account and on a large estate that is a large result. It also answers a bare JSON array where the v2 read answers an object with count, more, objects and start_after.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
querystringnonullOptional. Lucene query that selects which WebBlocker exceptions to return. WatchGuard's own example is device:12345 AND rule_type:"string".

[WatchGuard Cloud] DESTRUCTIVE. Updates the specified blocked sites exception. This replaces the exception wholesale - every field you leave out is cleared, and an omitted action falls back to the schema default allow, which moves the address onto the Blocked Sites Exception list and lets the traffic through. Read the current object with wg_get_firebox_blocked_site_exception and send it back complete. version is required and must be the version the exception carries now; a stale version comes back as a conflict. The change is saved in WatchGuard Cloud only: no Firebox sees it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. The body is a JSON object whose fields are action, address, description, version; required: address, version.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe complete replacement exception as a JSON object. version is required and must be the version the exception carries now - read it with wg_get_firebox_blocked_site_exception. address is required and is an object with type and value, where type is ipv4_host, ipv4_range, ipv4_network or fqdn (for example type fqdn with value example.com, or type ipv4_range with value 192.0.2.1-192.0.2.5). action is allow or block and falls back to allow when omitted. description is free text up to 127 characters. There is no device field on the update schema, so this cannot move the exception to another Firebox.
objectidstringyesID of the blocked sites exception to replace, as returned by wg_list_firebox_blocked_site_exceptions (for example bse_12345_ARBHLJ70Y78rGOIGBS).

[WatchGuard Cloud] DESTRUCTIVE. Updates the specified botnet site exception. This replaces the exception wholesale - every field you leave out is cleared rather than kept, so an omitted description is erased and a changed address re-points the exception at a different site. Read the current object with wg_get_firebox_botnet_site_exception and send it back complete. version is required and must be the version the exception carries now; a stale version comes back as a conflict. The change is saved in WatchGuard Cloud only: no Firebox sees it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. The body is a JSON object whose fields are address, description, version; required: address, version.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe complete replacement exception as a JSON object. version is required and must be the version the exception carries now - read it with wg_get_firebox_botnet_site_exception. address is required and is an object with type and value, where type is ipv4_host, ipv4_range, ipv4_network or fqdn (for example type fqdn with value example.com, or type ipv4_range with value 192.0.2.1-192.0.2.5). description is free text up to 127 characters. There is no device field on the update schema, so this cannot move the exception to another Firebox.
objectidstringyesID of the botnet site exception to replace, as returned by wg_list_firebox_botnet_site_exceptions (for example bote_CjBY92ourN7Izaa1jJu3eH5).

[WatchGuard Cloud] DESTRUCTIVE. Updates the specified file exception. This replaces the exception wholesale - every field you leave out is cleared, and action decides whether the Firebox allows the file or drops it, so a wrong value here delivers a file the customer meant to stop. Read the current object with wg_get_firebox_file_exception and send it back complete. version is required and must be the version the exception carries now; a stale version comes back as a conflict. The change is saved in WatchGuard Cloud only: no Firebox sees it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. The body is a JSON object whose fields are action, description, md5, version; required: action, md5, version.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe complete replacement exception as a JSON object. version is required and must be the version the exception carries now - read it with wg_get_firebox_file_exception. action is required and is allow or drop, and md5 is required and is exactly 32 lowercase hexadecimal characters. description is free text up to 127 characters. There is no device field on the update schema, so this cannot move the exception to another Firebox.
objectidstringyesID of the file exception to replace, as returned by wg_list_firebox_file_exceptions (for example file_12345_UqhDVIdx8D5iwivAX).

[WatchGuard Cloud] DESTRUCTIVE. Updates the specified Geolocation exception. This replaces the exception wholesale - every field you leave out is cleared rather than kept, and the address is the whole exception, so a changed value exempts a different site from the Geolocation block. Read the current object with wg_get_firebox_geolocation_exception and send it back complete. version is required and must be the version the exception carries now; a stale version comes back as a conflict. The change is saved in WatchGuard Cloud only: no Firebox sees it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. The body is a JSON object whose fields are address, description, version; required: address, version.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe complete replacement exception as a JSON object. version is required and must be the version the exception carries now - read it with wg_get_firebox_geolocation_exception. address is required and is an object with type and value, where type is ipv4_host, ipv4_range, ipv4_network or fqdn (for example type fqdn with value example.com, or type ipv4_range with value 192.0.2.1-192.0.2.5). description is free text up to 127 characters. There is no device field on the update schema, so this cannot move the exception to another Firebox.
objectidstringyesID of the Geolocation exception to replace, as returned by wg_list_firebox_geolocation_exceptions (for example geoe_12345_aHbWC5IuWO3qzyV2t).

[WatchGuard Cloud] DESTRUCTIVE. Updates the specified IPS signature exception. This replaces the exception wholesale - every field you leave out is cleared, an omitted alarm falls back to false so the Firebox stops alarming on the signature, and action decides whether the signature is allowed, blocked or dropped. Read the current object with wg_get_firebox_ips_signature_exception and send it back complete. version is required and must be the version the exception carries now; a stale version comes back as a conflict. The change is saved in WatchGuard Cloud only: no Firebox sees it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. The body is a JSON object whose fields are action, alarm, description, signature_id, version; required: action, signature_id, version.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe complete replacement exception as a JSON object. version is required and must be the version the exception carries now - read it with wg_get_firebox_ips_signature_exception. action is required and is allow, block or drop, and signature_id is required and is ONE numeric signature ID of up to 31 digits. alarm is a boolean that falls back to false when omitted. description is free text up to 127 characters. There is no device field on the update schema, so this cannot move the exception to another Firebox.
objectidstringyesID of the IPS signature exception to replace, as returned by wg_list_firebox_ips_signature_exceptions (for example ipse_12345_eY5Jwxv1nE3Xlk3zx).

[WatchGuard Cloud] DESTRUCTIVE. Updates the specified WebBlocker exception. This replaces the exception wholesale - every field you leave out is cleared, and action decides whether the matching URLs are allowed or denied, so a wrong value either opens web traffic the customer's policy refuses or blocks a site the customer needs. Read the current object with wg_get_firebox_webblocker_exception and send it back complete. version is required and must be the version the exception carries now; a stale version comes back as a conflict. The change is saved in WatchGuard Cloud only: no Firebox sees it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. The body is a JSON object whose fields are action, alarm, name, rule, rule_type, version; required: action, name, rule, rule_type, version.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe complete replacement exception as a JSON object. version is required and must be the version the exception carries now - read it with wg_get_firebox_webblocker_exception. action (allow or deny), name, rule_type (string, pattern or regexp) and rule are all required. alarm is a boolean that falls back to false when omitted. There is no device field on the update schema, so this cannot move the exception to another Firebox.
objectidstringyesID of the WebBlocker exception to replace, as returned by wg_list_firebox_webblocker_exceptions (for example wbe_12124_7HM70EvrifZ7rSfXSA).

Firebox Networking

ToolPlanAccessSummary
wg_create_firebox_bovpn_p1_shared_settingsProWriteCreates the shared Phase 1 (IKE) settings object for one Firebox.
wg_create_firebox_bovpn_tunnelProDestructiveDESTRUCTIVE.
wg_delete_firebox_bovpn_tunnelProDestructiveDESTRUCTIVE.
wg_delete_firebox_bovpn_tunnel_by_nameProDestructiveDESTRUCTIVE.
wg_get_firebox_bovpn_p1_shared_settingsFreeRead-onlyRetrieves the shared Phase 1 (IKE) settings that a Firebox's branch office VPN tunnels inherit.
wg_get_firebox_bovpn_tunnelFreeRead-onlyRetrieves one branch office VPN IPSec tunnel, selected by its object id in the path.
wg_get_firebox_networkFreeRead-onlyRetrieves one network configuration object of a Firebox, selected by its object id.
wg_get_firebox_sdwanFreeRead-onlyRetrieves one SD-WAN configuration object of a Firebox, selected by its object id.
wg_list_firebox_bovpn_tunnelsFreeRead-onlyLists the branch office VPN (BOVPN) IPSec tunnels of the account, or of one Firebox.
wg_list_firebox_networksFreeRead-onlyLists the network configuration objects of the account, or of one Firebox or one account-level template.
wg_list_firebox_sdwansFreeRead-onlyLists the SD-WAN configuration objects of the account, or of one Firebox or one account-level template.
wg_patch_firebox_bovpn_tunnelProWriteUpdates only the routes list or the endpoint certificates of one branch office VPN IPSec tunnel, selected by its object id in the path.
wg_patch_firebox_bovpn_tunnel_by_nameProWriteUpdates only the routes list or the endpoint certificates of one branch office VPN IPSec tunnel, selected by the id or the name in the body.
wg_update_firebox_bovpn_p1_shared_settingsProDestructiveDESTRUCTIVE.
wg_update_firebox_bovpn_tunnelProDestructiveDESTRUCTIVE.
wg_update_firebox_bovpn_tunnel_by_nameProDestructiveDESTRUCTIVE.

[WatchGuard Cloud] Creates the shared Phase 1 (IKE) settings object for one Firebox. The Firebox is named by the body's device field, not by a path or query parameter. One object can exist per Firebox, so a second create for the same device is refused as a conflict rather than replacing the existing object; change an existing one with wg_update_firebox_bovpn_p1_shared_settings. Every branch office VPN tunnel on that Firebox inherits these settings. The change is saved in WatchGuard Cloud and reaches no Firebox until wg_deploy_firebox_configuration pushes it. The body is a JSON object whose fields are device, ike_proposals, natt_interval; required: ike_proposals.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe Phase 1 settings as JSON. It is a JSON object with three fields: device, the WatchGuard Cloud id of the Firebox this object applies to; ike_proposals, the required array of 1 to 8 IKE phase 1 proposals, each with encryption, authentication, dh_group, lifetime and lifetime_unit; and natt_interval, the IKE NAT-T keep-alive interval in seconds, default 20. Required: ike_proposals.

[WatchGuard Cloud] DESTRUCTIVE. Creates a branch office VPN (BOVPN) IPSec tunnel in the account. The body carries psk, the tunnel pre-shared key, in clear text, so this stores credential material, and WatchGuard echoes the key back in the response. At least one endpoint must be a cloud-managed Firebox, named in endpoint_a; both route-based and policy-based tunnels are supported. The change is saved in WatchGuard Cloud and reaches no Firebox until wg_deploy_firebox_configuration pushes it. The body is a JSON object whose fields are address_family, auth_method, certs, disabled, endpoint_a, endpoint_b, endpoint_b_name, interfaces, ipsec_tunnel_core, local_remote_pairs, name, psk, psk_encrypted, routes and 3 more; required: endpoint_a, interfaces, name, routes.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe tunnel as JSON. It is a JSON object with these fields: name, endpoint_a (the cloud-managed Firebox device id), endpoint_b, endpoint_b_name, interfaces (the gateway endpoints), routes, vpn_type (route-based or policy-based), address_family (4 or 6), auth_method (psk or certificate), psk (the pre-shared key, in clear text), psk_encrypted, certs, ipsec_tunnel_core (the IKE and IPSec proposals, PFS group, NAT-T interval and dead-peer detection), local_remote_pairs, shared_p1_settings, vif and disabled. Required: endpoint_a, interfaces, name, routes.

[WatchGuard Cloud] DESTRUCTIVE. Deletes one branch office VPN IPSec tunnel, selected by its object id in the path. There is no undo: WatchGuard removes the tunnel outright and the branch office connection it carries drops once the change is deployed, so confirm the object id first. WatchGuard answers with the deleted tunnel, pre-shared key included. The object id comes from wg_list_firebox_bovpn_tunnels. The sibling wg_delete_firebox_bovpn_tunnel_by_name deletes by name instead. The change is saved in WatchGuard Cloud and reaches no Firebox until wg_deploy_firebox_configuration pushes it.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesThe BOVPN IPSec tunnel object id, as returned in the id field by wg_list_firebox_bovpn_tunnels.

[WatchGuard Cloud] DESTRUCTIVE. Deletes one branch office VPN IPSec tunnel, selected by the tunnel name. This selects the tunnel by NAME rather than by object id, so a wrong name deletes a different tunnel rather than failing, and there is no undo: the branch office connection that tunnel carries drops once the change is deployed. WatchGuard answers with the deleted tunnel, pre-shared key included. Prefer wg_delete_firebox_bovpn_tunnel, which takes the tunnel's object id in the path. The change is saved in WatchGuard Cloud and reaches no Firebox until wg_deploy_firebox_configuration pushes it.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
namestringyesThe BOVPN IPSec tunnel name, as returned in the name field by wg_list_firebox_bovpn_tunnels. StackJack requires it even though WatchGuard's specification marks it optional: without it the request addresses the whole tunnel COLLECTION, and WatchGuard documents no meaning for a delete sent that way. A blank value is refused before anything is sent.

[WatchGuard Cloud] Retrieves the shared Phase 1 (IKE) settings that a Firebox's branch office VPN tunnels inherit. Name a device to read that Firebox's single object; omit device and WatchGuard returns every Phase 1 shared settings object in the account, with no paging. One object can exist per Firebox. Read this before wg_update_firebox_bovpn_p1_shared_settings: the version field it returns is what that update must send back.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
devicestringnonullOptional. The Firebox device id in WatchGuard Cloud, for example 136162 or FBCL-136162; it appears in the URL of the device summary page in the portal. Omit it to cover every device in the account.

[WatchGuard Cloud] Retrieves one branch office VPN IPSec tunnel, selected by its object id in the path. Read this before any wholesale update: the object's version field is what wg_update_firebox_bovpn_tunnel must send back, and the fields you do not send to that tool are cleared. The response carries psk, the tunnel's pre-shared key, in clear text.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesThe BOVPN IPSec tunnel object id, as returned in the id field by wg_list_firebox_bovpn_tunnels.

[WatchGuard Cloud] Retrieves one network configuration object of a Firebox, selected by its object id. The object id comes from the id field of wg_list_firebox_networks. The response carries credentials in clear text: pppoe_client.password, dynamic_dns.password and each wireless interface's passphrase.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesThe network object id, as returned in the id field by wg_list_firebox_networks.

[WatchGuard Cloud] Retrieves one SD-WAN configuration object of a Firebox, selected by its object id. The object id comes from the id field of wg_list_firebox_sdwans.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesThe SD-WAN object id, as returned in the id field by wg_list_firebox_sdwans.

[WatchGuard Cloud] Lists the branch office VPN (BOVPN) IPSec tunnels of the account, or of one Firebox. This is the reach-first read for every other BOVPN tool: it is where a tunnel's id, its name and its version number come from. The response carries each tunnel's psk, the pre-shared key, in clear text. WatchGuard declares no paging on this route, so one call returns the whole collection; filter with device to keep the result small.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
devicestringnonullOptional. The Firebox device id in WatchGuard Cloud, for example 136162 or FBCL-136162; it appears in the URL of the device summary page in the portal. Omit it to cover every device in the account.

[WatchGuard Cloud] Lists the network configuration objects of the account, or of one Firebox or one account-level template. Start here for interface, VLAN, bridge, PPPoE, dynamic DNS and wireless settings, then read a single object with wg_get_firebox_network. The response carries credentials in clear text: pppoe_client.password, dynamic_dns.password and each wireless interface's passphrase. WatchGuard declares no paging on this route, so one call returns the whole collection; filter with device or templateid to keep the result small.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
devicestringnonullOptional. The Firebox device id in WatchGuard Cloud, for example 136162 or FBCL-136162; it appears in the URL of the device summary page in the portal. Omit it to cover every device in the account. Mutually exclusive with templateid.
templateidstringnonullOptional. An account-level template id, for example tmpl_ABCDEFG, to read that template's objects instead of a device's. Mutually exclusive with device.

[WatchGuard Cloud] Lists the SD-WAN configuration objects of the account, or of one Firebox or one account-level template. This is the reach-first read for SD-WAN actions and their link-monitoring settings; read a single object with wg_get_firebox_sdwan. WatchGuard declares no paging on this route, so one call returns the whole collection; filter with device or templateid to keep the result small.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
devicestringnonullOptional. The Firebox device id in WatchGuard Cloud, for example 136162 or FBCL-136162; it appears in the URL of the device summary page in the portal. Omit it to cover every device in the account. Mutually exclusive with templateid.
templateidstringnonullOptional. An account-level template id, for example tmpl_ABCDEFG, to read that template's objects instead of a device's. Mutually exclusive with device.

[WatchGuard Cloud] Updates only the routes list or the endpoint certificates of one branch office VPN IPSec tunnel, selected by its object id in the path. Every other field of the tunnel, its pre-shared key included, is preserved: this is the partial sibling of wg_update_firebox_bovpn_tunnel, which replaces the whole object. The response is the updated tunnel and carries psk, the pre-shared key, in clear text. The change is saved in WatchGuard Cloud and reaches no Firebox until wg_deploy_firebox_configuration pushes it. The body is a JSON object whose fields are certs, routes.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe partial update as JSON. It is a JSON object with two fields: routes, the local route lists for endpoint_a and endpoint_b; and certs, the certificate name for each endpoint, where endpoint_a is required inside certs. The schema marks neither field required.
objectidstringyesThe BOVPN IPSec tunnel object id, as returned in the id field by wg_list_firebox_bovpn_tunnels.

[WatchGuard Cloud] Updates only the routes list or the endpoint certificates of one branch office VPN IPSec tunnel, selected by the id or the name in the body. This route takes no path or query selector, so the tunnel is chosen by the body's id or name field and a wrong name updates a different tunnel rather than failing. Prefer wg_patch_firebox_bovpn_tunnel, which takes the tunnel's object id in the path. Every other field of the tunnel, its pre-shared key included, is preserved, and the response is the updated tunnel and carries psk, the pre-shared key, in clear text. The change is saved in WatchGuard Cloud and reaches no Firebox until wg_deploy_firebox_configuration pushes it. The body is a JSON object whose fields are certs, id, name, routes.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe partial update as JSON. It is a JSON object with four fields: id and name, either of which selects the tunnel this call updates; routes, the local route lists for endpoint_a and endpoint_b; and certs, the certificate name for each endpoint, where endpoint_a is required inside certs. The schema marks none of them required, so send id or name or the call has nothing to select.

[WatchGuard Cloud] DESTRUCTIVE. Replaces the shared Phase 1 (IKE) settings that a Firebox's branch office VPN tunnels inherit. Every branch office VPN tunnel on the Firebox inherits these Phase 1 settings, so one call can renegotiate every branch tunnel on that device at once. It replaces the object wholesale: any field you leave out is cleared rather than kept. Read the current object with wg_get_firebox_bovpn_p1_shared_settings first and send its version back; WatchGuard refuses a stale version as a conflict. WatchGuard's prose says the Firebox is named by the body's device attribute, and its own example sends id and device as well, although the update schema documents only ike_proposals, natt_interval and version. The change is saved in WatchGuard Cloud and reaches no Firebox until wg_deploy_firebox_configuration pushes it. The body is a JSON object whose fields are ike_proposals, natt_interval, version; required: ike_proposals, version.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe replacement Phase 1 settings as JSON. It is a JSON object with three documented fields: ike_proposals, the required array of 1 to 8 IKE phase 1 proposals, each with encryption, authentication, dh_group, lifetime and lifetime_unit; natt_interval, the NAT-T keep-alive interval in seconds; and version, the version number of the object you are updating. Required: ike_proposals and version. WatchGuard's own example also sends id and device.

[WatchGuard Cloud] DESTRUCTIVE. Replaces one branch office VPN IPSec tunnel, selected by its object id in the path. This replaces the tunnel wholesale, including its pre-shared key: every field you leave out is cleared rather than kept, so read the tunnel with wg_get_firebox_bovpn_tunnel and send it back complete. WatchGuard echoes the key back in the response. version must be the version you just read, and WatchGuard refuses a stale one as a conflict. The sibling wg_update_firebox_bovpn_tunnel_by_name takes no object id and selects the tunnel from the body instead; wg_patch_firebox_bovpn_tunnel changes the routes or the certificates without touching anything else. The change is saved in WatchGuard Cloud and reaches no Firebox until wg_deploy_firebox_configuration pushes it. The body is a JSON object whose fields are address_family, auth_method, certs, disabled, endpoint_a, endpoint_b, endpoint_b_name, interfaces, ipsec_tunnel_core, local_remote_pairs, name, psk, psk_encrypted, routes and 4 more; required: endpoint_a, interfaces, name, routes, version.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe complete replacement tunnel as JSON. It is a JSON object with these fields: name, endpoint_a (the cloud-managed Firebox device id), endpoint_b, endpoint_b_name, interfaces (the gateway endpoints), routes, vpn_type (route-based or policy-based), address_family (4 or 6), auth_method (psk or certificate), psk (the pre-shared key, in clear text), psk_encrypted, certs, ipsec_tunnel_core (the IKE and IPSec proposals, PFS group, NAT-T interval and dead-peer detection), local_remote_pairs, shared_p1_settings, vif and disabled, plus version, the version number of the tunnel you are updating. Required: endpoint_a, interfaces, name, routes and version. Every field you omit is cleared.
objectidstringyesThe BOVPN IPSec tunnel object id, as returned in the id field by wg_list_firebox_bovpn_tunnels.

[WatchGuard Cloud] DESTRUCTIVE. Replaces one branch office VPN IPSec tunnel, selected by the tunnel name in the body. This selects the tunnel by NAME from the body and replaces it wholesale, so a wrong name edits a different tunnel rather than failing, and every field you leave out is cleared rather than kept. The body carries the pre-shared key and WatchGuard echoes it back in the response. WatchGuard's prose calls the name a URL parameter, but the specification declares no path or query parameter on this route: the name travels in the body. Prefer wg_update_firebox_bovpn_tunnel, which takes the tunnel's object id in the path. version must be the version you read with wg_get_firebox_bovpn_tunnel or wg_list_firebox_bovpn_tunnels. The change is saved in WatchGuard Cloud and reaches no Firebox until wg_deploy_firebox_configuration pushes it. The body is a JSON object whose fields are address_family, auth_method, certs, disabled, endpoint_a, endpoint_b, endpoint_b_name, interfaces, ipsec_tunnel_core, local_remote_pairs, name, psk, psk_encrypted, routes and 4 more; required: endpoint_a, interfaces, name, routes, version.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe complete replacement tunnel as JSON. It is a JSON object with these fields: name, endpoint_a (the cloud-managed Firebox device id), endpoint_b, endpoint_b_name, interfaces (the gateway endpoints), routes, vpn_type (route-based or policy-based), address_family (4 or 6), auth_method (psk or certificate), psk (the pre-shared key, in clear text), psk_encrypted, certs, ipsec_tunnel_core (the IKE and IPSec proposals, PFS group, NAT-T interval and dead-peer detection), local_remote_pairs, shared_p1_settings, vif and disabled, plus version, the version number of the tunnel you are updating. name is what selects the tunnel this call replaces. Required: endpoint_a, interfaces, name, routes and version. Every field you omit is cleared.

Firebox Policies

ToolPlanAccessSummary
wg_create_firebox_policyProWriteCreates a firewall policy on a Firebox.
wg_delete_firebox_policyProDestructiveDESTRUCTIVE.
wg_get_firebox_aliasFreeRead-onlyReturns one firewall alias and the members it resolves to.
wg_get_firebox_content_filtering_ruleFreeRead-onlyReturns one content filtering rule with its application control and WebBlocker category actions.
wg_get_firebox_policyFreeRead-onlyReturns one firewall policy in full, including the version number an update has to send back.
wg_get_firebox_policy_groupFreeRead-onlyReturns one firewall policy group with the ordered list of policies inside it.
wg_get_firebox_snat_actionFreeRead-onlyReturns one static NAT (SNAT) action with its external-to-internal address rules.
wg_get_firebox_traffic_shaping_ruleFreeRead-onlyReturns one traffic shaping rule with the bandwidth it limits or guarantees.
wg_get_firebox_traffic_typeFreeRead-onlyReturns one traffic type with the protocols and ports it matches.
wg_list_firebox_aliasesFreeRead-onlyLists the firewall aliases defined for the account, or for one Firebox or template.
wg_list_firebox_content_filtering_rulesFreeRead-onlyLists the content filtering rules, the application control and WebBlocker category actions, for the account or for one Firebox or template.
wg_list_firebox_policiesFreeRead-onlyLists the firewall policies WatchGuard Cloud holds for the account, or for one Firebox when you name a device.
wg_list_firebox_policy_groupsFreeRead-onlyLists the firewall policy groups defined for the account, or for one Firebox or template.
wg_list_firebox_snat_actionsFreeRead-onlyLists the static NAT (SNAT) actions defined for the account, or for one Firebox or template.
wg_list_firebox_traffic_shaping_rulesFreeRead-onlyLists the traffic shaping rules defined for the account, or for one Firebox or template.
wg_list_firebox_traffic_typesFreeRead-onlyLists the traffic types, the named protocol and port sets, available for the account or for one Firebox or template.
wg_set_firebox_policy_enabledProDestructiveDESTRUCTIVE.
wg_update_firebox_policyProDestructiveDESTRUCTIVE.

[WatchGuard Cloud] Creates a firewall policy on a Firebox. Saved in WatchGuard Cloud only: the new rule reaches no device until wg_deploy_firebox_configuration pushes the configuration. Read wg_list_firebox_policy_groups, wg_list_firebox_traffic_types and wg_list_firebox_aliases first, because group, traffic_types, sources and destinations all name objects that must already exist. The body is a JSON object whose fields are action, connection_rate_limit, content_filtering, content_scanning, description, destinations, device, enabled, geolocation, group, hidden, idle_timeout, immutable, name and 18 more; required: action, destinations, device, enabled, group, name, sources, traffic_types, type.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe new firewall policy as a JSON object. Required: device (the Firebox ID), name (58 characters or fewer), enabled, action (allow or deny), type (first, last, outbound, inbound or custom, and the type decides which type-specific fields the rule accepts, for example web_traffic only on outbound), group (First Run Policies, Core Policies or Last Run Policies, or a reference to a policy group), traffic_types (names or references from wg_list_firebox_traffic_types, and the array must not be empty unless the policy is outbound with web_traffic enabled), sources and destinations (typed match objects, at least one each, for example type system_alias with value Any-External). Optional: description (127 characters or fewer), schedule, nat, sdwan, traffic_shaping, content_filtering, content_scanning, web_traffic, web_action_setting, qos, idle_timeout, sticky_connection, connection_rate_limit, geolocation, tor_nodes, websocket, notifications, smtp_setting, traffic_direction (custom policies only, bidirectional or unidirectional), immutable, permanent and togglable. WatchGuard marks hidden deprecated: policy visibility is a user preference now.

[WatchGuard Cloud] DESTRUCTIVE. Deletes one firewall policy. There is no undo, and the id is all this call takes: confirm the rule with wg_get_firebox_policy first, because a wrong id removes a rule that is filtering traffic today. WatchGuard refuses to delete a policy marked permanent. WatchGuard answers 201, not 204, and the body is the deleted policy with inactive set to true - that is success, not a failure. The deletion is saved in WatchGuard Cloud; the Firebox stops enforcing the rule at the next wg_deploy_firebox_configuration.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesThe firewall policy to delete, as returned by wg_list_firebox_policies, for example fpol_12345_ARBHLJ70Y78rGOIGBS.

[WatchGuard Cloud] Returns one firewall alias and the members it resolves to. Use it to see exactly which hosts, networks, ranges, FQDNs, users or groups a policy matches when its sources or destinations name this alias. Each member is a typed object: type says what kind it is and value carries the address or the referenced object.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesThe alias's object ID, as returned by wg_list_firebox_aliases.

[WatchGuard Cloud] Returns one content filtering rule with its application control and WebBlocker category actions. CREDENTIAL IN THE ANSWER: webblocker_override.password is the cleartext password an end user types to override a blocked category, so treat this result as a secret and do not forward or store it, and note that WatchGuard only fills it when webblocker_override.wbo_method is password rather than user_group. The appcontrol array carries one entry per application, each allow or block; the webblocker array carries one entry per URL category, each allow, bypass, deny or warn with its own log and alarm flags; and deny_uncategorized decides what happens to a site in no category.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesThe content filtering rule's object ID, as returned by wg_list_firebox_content_filtering_rules.

[WatchGuard Cloud] Returns one firewall policy in full, including the version number an update has to send back. Read this before wg_update_firebox_policy: that call replaces the rule wholesale and requires the object's current version, and this is where both the version and the complete rule come from. The record carries the rule's action, type, group, sources, destinations, traffic_types, schedule and NAT settings, wrapped in WatchGuard's object metadata: id, object, version, account, device and created.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesThe firewall policy's object ID, as returned by wg_list_firebox_policies, for example fpol_12345_ARBHLJ70Y78rGOIGBS.

[WatchGuard Cloud] Returns one firewall policy group with the ordered list of policies inside it. The policies array is the order WatchGuard runs the member rules in, and each reference in it resolves through wg_get_firebox_policy. WatchGuard requires only the group's name, so a group with no members can answer without the array at all.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesThe policy group's object ID, as returned by wg_list_firebox_policy_groups.

[WatchGuard Cloud] Returns one static NAT (SNAT) action with its external-to-internal address rules. Each rule pairs an external_address - an IPv4 host, a reference to an external network, or the Any-External system alias - with the internal_address the traffic is sent to, and may narrow the match with destination_port and source_address. A policy uses the action by naming it in a destination of type firewall_snat_action.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesThe SNAT action's object ID, as returned by wg_list_firebox_snat_actions.

[WatchGuard Cloud] Returns one traffic shaping rule with the bandwidth it limits or guarantees. behavior is limit or guarantee, method is all_users or per_user (with max_users when it is per_user), rule_type says which traffic the rule applies to - outbound, inbound, custom, first, last, content_filtering or mixed - and the bandwidth is carried as upload and download in Kbps.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesThe traffic shaping rule's object ID, as returned by wg_list_firebox_traffic_shaping_rules.

[WatchGuard Cloud] Returns one traffic type with the protocols and ports it matches. The type field says whether WatchGuard predefined it or the account created it, category is the vendor grouping - Auth, Custom, Database, Email, File, General, Network, RemoteAccess, Tunneling, VoIP/Chat, WatchGuard or Web - and protocols lists one entry per matched protocol, each typed any (the protocol with no port restriction), single_port or port_range for TCP and UDP, or icmp.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesThe traffic type's object ID, as returned by wg_list_firebox_traffic_types.

[WatchGuard Cloud] Lists the firewall aliases defined for the account, or for one Firebox or template. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result. An alias is a named set of at least one member - IPv4 or IPv6 hosts, networks and ranges, FQDNs, WatchGuard's own system aliases such as Any-External, or references to another alias, a network, a Firebox user or group, an authentication group, or an AuthPoint or SAML user group - that a policy's sources and destinations point at by name, so read this before you write a policy that names one. Each entry's id is the objectid wg_get_firebox_alias takes.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
devicestringnonullOptional. Returns only the objects of one Firebox. The device ID is the number WatchGuard Cloud shows in the URL of that Firebox's Device Summary page, for example 12345 or FBCL-12345. Mutually exclusive with templateid; omit both to read what the account holds.
templateidstringnonullOptional. Returns only the objects of one account-level Firebox template, for example tmpl_ABCDEFG. Mutually exclusive with device; omit both to read what the account holds.

[WatchGuard Cloud] Lists the content filtering rules, the application control and WebBlocker category actions, for the account or for one Firebox or template. CREDENTIAL IN THE ANSWER: each rule's webblocker_override.password is the cleartext password an end user types to override a blocked category, so treat this result as a secret and do not forward or store it. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result. Every rule carries its whole appcontrol array (one entry per application, allow or block) and webblocker array (one entry per URL category, allow, bypass, deny or warn), so this answer is large on a tuned account. Each entry's id is the objectid wg_get_firebox_content_filtering_rule takes.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
devicestringnonullOptional. Returns only the objects of one Firebox. The device ID is the number WatchGuard Cloud shows in the URL of that Firebox's Device Summary page, for example 12345 or FBCL-12345. Mutually exclusive with templateid; omit both to read what the account holds.
templateidstringnonullOptional. Returns only the objects of one account-level Firebox template, for example tmpl_ABCDEFG. Mutually exclusive with device; omit both to read what the account holds.

[WatchGuard Cloud] Lists the firewall policies WatchGuard Cloud holds for the account, or for one Firebox when you name a device. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result. Start here for anything policy-shaped: the answer is a count plus an objects array, and each entry's id is the objectid that wg_get_firebox_policy, wg_update_firebox_policy, wg_set_firebox_policy_enabled and wg_delete_firebox_policy take. Send full=1 when you need whole rules rather than the id, name, group and device summary.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
devicestringnonullOptional. Returns only the firewall policies of one Firebox. The device ID is the number WatchGuard Cloud shows in the URL of that Firebox's Device Summary page, for example 12345 or FBCL-12345. This route takes no template filter; omit this to read every policy the account holds.
fullintegernonullOptional. Send 1 for the complete policy objects and 0 for the summary of id, name, group and device. WatchGuard's parameter text and its operation text disagree about what omitting this does, so send it explicitly when the shape of the answer matters.

[WatchGuard Cloud] Lists the firewall policy groups defined for the account, or for one Firebox or template. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result. A policy group is the ordered container a firewall policy's group field names, and WatchGuard's own groups are First Run Policies, Core Policies and Last Run Policies. Each entry's policies array lists its member policies in the order they run, and each entry's id is the objectid wg_get_firebox_policy_group takes.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
devicestringnonullOptional. Returns only the objects of one Firebox. The device ID is the number WatchGuard Cloud shows in the URL of that Firebox's Device Summary page, for example 12345 or FBCL-12345. Mutually exclusive with templateid; omit both to read what the account holds.
templateidstringnonullOptional. Returns only the objects of one account-level Firebox template, for example tmpl_ABCDEFG. Mutually exclusive with device; omit both to read what the account holds.

[WatchGuard Cloud] Lists the static NAT (SNAT) actions defined for the account, or for one Firebox or template. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result. A SNAT action maps an external address to an internal one and a firewall policy's nat settings name it. Each entry's id is the objectid wg_get_firebox_snat_action takes.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
devicestringnonullOptional. Returns only the objects of one Firebox. The device ID is the number WatchGuard Cloud shows in the URL of that Firebox's Device Summary page, for example 12345 or FBCL-12345. Mutually exclusive with templateid; omit both to read what the account holds.
templateidstringnonullOptional. Returns only the objects of one account-level Firebox template, for example tmpl_ABCDEFG. Mutually exclusive with device; omit both to read what the account holds.

[WatchGuard Cloud] Lists the traffic shaping rules defined for the account, or for one Firebox or template. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result. A traffic shaping rule limits or guarantees bandwidth for the policies that name it in their traffic_shaping field. Each entry's id is the objectid wg_get_firebox_traffic_shaping_rule takes.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
devicestringnonullOptional. Returns only the objects of one Firebox. The device ID is the number WatchGuard Cloud shows in the URL of that Firebox's Device Summary page, for example 12345 or FBCL-12345. Mutually exclusive with templateid; omit both to read what the account holds.
templateidstringnonullOptional. Returns only the objects of one account-level Firebox template, for example tmpl_ABCDEFG. Mutually exclusive with device; omit both to read what the account holds.

[WatchGuard Cloud] Lists the traffic types, the named protocol and port sets, available for the account or for one Firebox or template. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result. A firewall policy's traffic_types field names these, both WatchGuard's predefined ones such as All TCP and UDP or FTP and any the account created, so read this to find valid names before you create or update a policy. Each entry's id is the objectid wg_get_firebox_traffic_type takes.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
devicestringnonullOptional. Returns only the objects of one Firebox. The device ID is the number WatchGuard Cloud shows in the URL of that Firebox's Device Summary page, for example 12345 or FBCL-12345. Mutually exclusive with templateid; omit both to read what the account holds.
templateidstringnonullOptional. Returns only the objects of one account-level Firebox template, for example tmpl_ABCDEFG. Mutually exclusive with device; omit both to read what the account holds.

[WatchGuard Cloud] DESTRUCTIVE. Enables or disables one firewall policy without touching any of its other settings. Disabling a firewall policy stops it enforcing without deleting it, so the rule looks present in the configuration while it is no longer applied; the same call with enabled true puts it back. The body needs device as well as enabled: the Firebox ID the policy belongs to, which wg_get_firebox_policy returns. No other field is read, so the rule's version is not required here. WatchGuard answers 201 with the whole updated policy, not an empty body. The change is saved in WatchGuard Cloud and takes effect on the Firebox at the next wg_deploy_firebox_configuration. The body is a JSON object whose fields are device, enabled; required: device, enabled.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesA JSON object with exactly two fields, both required: device (the Firebox ID the policy belongs to) and enabled (true to enforce the policy, false to stop enforcing it). Nothing else about the rule is changed.
objectidstringyesThe firewall policy to enable or disable, as returned by wg_list_firebox_policies, for example fpol_12345_ARBHLJ70Y78rGOIGBS.

[WatchGuard Cloud] DESTRUCTIVE. Replaces one firewall policy with the object you send. This replaces the rule wholesale - every field you leave out is CLEARED rather than kept, so read the rule with wg_get_firebox_policy and send it back complete; a partial body silently drops sources, destinations or traffic_types from a rule that is filtering traffic today. The body must carry version, the object's current version number from wg_get_firebox_policy; a 409 means the id and version you sent conflict with what WatchGuard holds, so re-read the rule and send its current version. WatchGuard answers 201 with the rewritten policy and the incremented version. The rewritten rule is saved in WatchGuard Cloud and reaches the Firebox at the next wg_deploy_firebox_configuration. The body is a JSON object whose fields are action, connection_rate_limit, content_filtering, content_scanning, description, destinations, device, enabled, geolocation, group, hidden, idle_timeout, immutable, name and 19 more; required: action, destinations, device, enabled, group, name, sources, traffic_types, type, version.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe COMPLETE firewall policy as a JSON object: this is a replace, not a merge. Required: version (the current version from wg_get_firebox_policy), device, name, enabled, action, type, group, traffic_types, sources and destinations. Every optional field you omit - description, schedule, nat, sdwan, traffic_shaping, content_filtering, content_scanning, web_traffic, web_action_setting, qos, idle_timeout, sticky_connection, connection_rate_limit, geolocation, tor_nodes, websocket, notifications, smtp_setting, traffic_direction (custom policies only), immutable, permanent, togglable - is cleared or falls back to its schema default.
objectidstringyesThe firewall policy to replace, as returned by wg_list_firebox_policies, for example fpol_12345_ARBHLJ70Y78rGOIGBS.

Firebox System

ToolPlanAccessSummary
wg_create_firebox_certificateProDestructiveDESTRUCTIVE.
wg_delete_firebox_certificateProDestructiveDESTRUCTIVE.
wg_get_firebox_certificateFreeRead-onlyRetrieves one certificate, selected by its object id in the path.
wg_get_firebox_scheduleFreeRead-onlyRetrieves one time schedule, selected by its object id in the path.
wg_install_firebox_certificateProDestructiveDESTRUCTIVE.
wg_list_firebox_certificatesFreeRead-onlyLists the certificates stored for the account, or the certificates on one Firebox when you name a device.
wg_list_firebox_schedulesFreeRead-onlyLists the time schedules defined for the account, for one Firebox, or for one Firebox template.
wg_list_firebox_template_subscriptionsFreeRead-onlyLists the Firebox templates available to the account, the templates one Firebox subscribes to, or the Fireboxes subscribed to one template.
wg_set_firebox_template_subscriptionProDestructiveDESTRUCTIVE.

[WatchGuard Cloud] DESTRUCTIVE. Creates a certificate in the account, either by importing one with its private key or by pointing one Firebox at a certificate the account already holds. The body carries a private key in pvt_key, or a PFX in pfx with its password, so this stores credential material in the WatchGuard Cloud account, and WatchGuard echoes the created certificate object back in the response. WatchGuard documents two shapes for the body: an import, which sends name plus pem and pvt_key, or pfx and its password; and a device-level reference, which sends alias plus device and no key material at all. Omit device for an account-level certificate. This only stores the certificate: putting it on a Firebox is the separate command wg_install_firebox_certificate. The change is saved in WatchGuard Cloud and reaches no Firebox until wg_deploy_firebox_configuration pushes it. The body is a JSON object whose fields are alias, description, device, name, password, pem, pfx, pvt_key.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe certificate as JSON. It is a JSON object in one of two shapes. To import a certificate: name, the certificate name, maximum 58 characters; description, maximum 127 characters; pem, the certificate in PEM form, with pvt_key, the private key in clear text; or pfx, the PFX in place of pem and pvt_key, with password, the PFX password. To point a Firebox at a certificate the account already holds: alias, that account certificate, with device. device names the Firebox for a device-level certificate and is omitted for an account-level one. WatchGuard marks no field required at the top level because the two shapes require different ones: name for an import, alias for a reference.

[WatchGuard Cloud] DESTRUCTIVE. Deletes one certificate from the account, selected by its object id in the path. There is no undo: WatchGuard removes the certificate outright, so confirm the object id with wg_get_firebox_certificate first. Anything that presents that certificate, from HTTPS inspection to the device web server, loses it once the change is deployed. WatchGuard answers with the deleted certificate object, private key included. The object id comes from wg_list_firebox_certificates. The change is saved in WatchGuard Cloud and reaches no Firebox until wg_deploy_firebox_configuration pushes it.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesObject ID.

[WatchGuard Cloud] Retrieves one certificate, selected by its object id in the path. The object id comes from wg_list_firebox_certificates. WatchGuard's certificate object has two shapes: a device-level reference, which carries only the alias of the account certificate it points at, and an imported certificate, which carries pem and can carry pvt_key, pfx and the PFX password in clear text. Treat the response as credential material.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesThe certificate object id, as returned in the id field by wg_list_firebox_certificates, for example crt_34425_jf3904ukdj94.

[WatchGuard Cloud] Retrieves one time schedule, selected by its object id in the path. The object id comes from wg_list_firebox_schedules. The response carries the schedule name, its enabled flag, schedule_type (0 always on, 1 daily, 2 weekly) and members, which lists each day of the week as day_of_week 0 (Sunday) through 6 (Saturday) with that day's time periods as from_hour, from_min, to_hour and to_min.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesThe schedule object id, as returned in the id field by wg_list_firebox_schedules.

[WatchGuard Cloud] DESTRUCTIVE. Installs a stored certificate on one Firebox or on a list of Fireboxes. This installs the certificate onto live Fireboxes, replacing what those devices present to clients. An expired or wrong certificate breaks HTTPS inspection and the device web UI, so confirm the certificate with wg_list_firebox_certificates and check the device ids before you call it. Name the certificate either by name in certificate or by object id in certificate_id, and the target either by device, one Firebox id, or by devices, a list of 1 to 100 Firebox ids; devices is accepted even though it is missing from the field list at the end of this description, because WatchGuard declares it as a bare array in the second branch of the body's oneOf. This is a command rather than a saved configuration change, so it does not wait for wg_deploy_firebox_configuration. The 201 is the id of the certificate object WatchGuard created, a crt_ id, and NOT a deployment transaction: wg_list_firebox_deployment_transactions takes tx_type=deployment only, so this call has no transaction to read back. The body is a JSON object whose fields are certificate, certificate_id, device.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe install request as JSON. It is a JSON object that names one certificate and one or more targets. The certificate: either certificate, its name, or certificate_id, its object id from wg_list_firebox_certificates. The target: either device, a single Firebox id, or devices, an array of 1 to 100 Firebox ids.

[WatchGuard Cloud] Lists the certificates stored for the account, or the certificates on one Firebox when you name a device. Start here: every other certificate tool takes the object id this list returns in each object's id field. Name a device for that Firebox's certificates; omit it for the account's own. An imported certificate can carry pvt_key, pfx and the PFX password in clear text, so treat the response as credential material. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
devicestringnonullOptional. The Firebox device id in WatchGuard Cloud, for example 136162 or FBCL-136162, to list that Firebox's certificates. Omit it for the account's own certificates. This route takes no templateid filter.

[WatchGuard Cloud] Lists the time schedules defined for the account, for one Firebox, or for one Firebox template. Schedules are the named time windows that firewall policies and other objects reference, and the Firebox Management API publishes reads for them only: there is no create, update or delete. Start here: wg_get_firebox_schedule takes the object id this list returns. device and templateid are mutually exclusive. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
devicestringnonullOptional. The Firebox device id in WatchGuard Cloud, for example 136162 or FBCL-136162, to list only that Firebox's schedules. Mutually exclusive with templateid; omit both for the account's schedules.
templateidstringnonullOptional. The account-level Firebox template id, for example tmpl_266318_QtD0zFYL5k28tUsg, to list only that template's schedules. Mutually exclusive with device; omit both for the account's schedules.

[WatchGuard Cloud] Lists the Firebox templates available to the account, the templates one Firebox subscribes to, or the Fireboxes subscribed to one template. One route with three answers, chosen by the query: with neither filter it returns the templates available to the account, inherited ones included; with device it returns the templates that Firebox subscribes to; with templateid it returns the Fireboxes subscribed to that template. device and templateid are mutually exclusive. Read this before wg_set_firebox_template_subscription, which replaces a Firebox's whole subscription list with what you send. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
devicestringnonullOptional. The Firebox device id in WatchGuard Cloud, for example 136162 or FBCL-136162, to list the templates that Firebox subscribes to. Mutually exclusive with templateid; omit both to list the templates available to the account.
templateidstringnonullOptional. The Firebox template id, for example tmpl_266318_QtD0zFYL5k28tUsg, to list the Fireboxes subscribed to that template. Mutually exclusive with device; omit both to list the templates available to the account.

[WatchGuard Cloud] DESTRUCTIVE. Sets the complete list of Firebox templates that one Firebox subscribes to. The Firebox is UNSUBSCRIBED from every template you do not list, and an empty templates array unsubscribes it from all of them. Send the complete list you want, in priority order. Read the current list with wg_list_firebox_template_subscriptions and send it back complete, plus or minus the change you want. The order of the templates array is the order the templates are applied on the Firebox, so sending the same ids in a different order is how you change which one wins. Maximum 50 template ids per request. The change is saved in WatchGuard Cloud and reaches no Firebox until wg_deploy_firebox_configuration pushes it. The body is a JSON object whose fields are device, templates; required: device, templates.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe subscription as JSON. It is a JSON object with two required fields: device, the WatchGuard Cloud id of the Firebox whose subscription you are setting, and templates, the COMPLETE array of template ids that Firebox should subscribe to, in priority order, 0 to 50 entries. An empty templates array unsubscribes the Firebox from every template.

FireCloud Exceptions

ToolPlanAccessSummary
wg_create_firecloud_blocked_site_exceptionProDestructiveDESTRUCTIVE.
wg_create_firecloud_botnet_site_exceptionProWriteCreates a new FireCloud botnet site exception.
wg_create_firecloud_file_exceptionProWriteCreates a new FireCloud file exception.
wg_create_firecloud_geolocation_exceptionProWriteCreates a new FireCloud Geolocation exception.
wg_create_firecloud_https_exceptionProWriteCreates a new FireCloud HTTPS decryption exception.
wg_create_firecloud_ips_signature_exceptionProWriteCreates a new FireCloud IPS signature exception.
wg_create_firecloud_webblocker_exceptionProDestructiveDESTRUCTIVE.
wg_delete_firecloud_blocked_site_exceptionProDestructiveDESTRUCTIVE.
wg_delete_firecloud_botnet_site_exceptionProDestructiveDESTRUCTIVE.
wg_delete_firecloud_file_exceptionProDestructiveDESTRUCTIVE.
wg_delete_firecloud_geolocation_exceptionProDestructiveDESTRUCTIVE.
wg_delete_firecloud_https_exceptionProDestructiveDESTRUCTIVE.
wg_delete_firecloud_ips_signature_exceptionProDestructiveDESTRUCTIVE.
wg_delete_firecloud_webblocker_exceptionProDestructiveDESTRUCTIVE.
wg_get_firecloud_blocked_site_exceptionFreeRead-onlyRetrieves the specified FireCloud blocked sites exception.
wg_get_firecloud_botnet_site_exceptionFreeRead-onlyRetrieves the specified FireCloud botnet site exception.
wg_get_firecloud_file_exceptionFreeRead-onlyRetrieves the specified FireCloud file exception.
wg_get_firecloud_geolocation_exceptionFreeRead-onlyRetrieves the specified FireCloud Geolocation exception.
wg_get_firecloud_https_exceptionFreeRead-onlyRetrieves the specified FireCloud HTTPS decryption exception.
wg_get_firecloud_ips_signature_exceptionFreeRead-onlyRetrieves the specified FireCloud IPS signature exception.
wg_get_firecloud_webblocker_exceptionFreeRead-onlyRetrieves the specified FireCloud WebBlocker exception.
wg_list_firecloud_blocked_site_exceptionsFreeRead-onlyRetrieves all blocked sites exceptions in the specified FireCloud account.
wg_list_firecloud_botnet_site_exceptionsFreeRead-onlyRetrieves all botnet site exceptions in the specified FireCloud account.
wg_list_firecloud_exceptionsFreeRead-onlyRetrieves all exceptions in the specified FireCloud account.
wg_list_firecloud_file_exceptionsFreeRead-onlyRetrieves all file exceptions in the specified FireCloud account.
wg_list_firecloud_geolocation_exceptionsFreeRead-onlyRetrieves all Geolocation exceptions in the specified FireCloud account.
wg_list_firecloud_https_exceptionsFreeRead-onlyRetrieves all HTTPS decryption exceptions in the specified FireCloud account.
wg_list_firecloud_ips_signature_exceptionsFreeRead-onlyRetrieves all IPS signature exceptions in the specified FireCloud account.
wg_list_firecloud_webblocker_exceptionsFreeRead-onlyRetrieves all WebBlocker exceptions in the specified FireCloud account.
wg_update_firecloud_blocked_site_exceptionProDestructiveDESTRUCTIVE.
wg_update_firecloud_botnet_site_exceptionProDestructiveDESTRUCTIVE.
wg_update_firecloud_file_exceptionProDestructiveDESTRUCTIVE.
wg_update_firecloud_geolocation_exceptionProDestructiveDESTRUCTIVE.
wg_update_firecloud_https_exceptionProDestructiveDESTRUCTIVE.
wg_update_firecloud_ips_signature_exceptionProDestructiveDESTRUCTIVE.
wg_update_firecloud_webblocker_exceptionProDestructiveDESTRUCTIVE.

[WatchGuard Cloud] DESTRUCTIVE. Creates a new FireCloud blocked sites exception. A FireCloud blocked sites exception ALLOWS the address it names - action takes the single value allow on this schema and accepts no other - so it can only open traffic the Blocked Sites list would otherwise stop. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the created exception, including the id that wg_get_firecloud_blocked_site_exception, wg_update_firecloud_blocked_site_exception and wg_delete_firecloud_blocked_site_exception take. The body is a JSON object whose fields are action, address, description; required: address.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe new blocked sites exception as a JSON object. address is required and is an object with type and value, where type is ipv4_host, ipv4_range, ipv4_network or fqdn (for example type fqdn with value example.com, or type ipv4_network with value 192.0.2.0/24). action takes the single value allow - this schema accepts no other action. description is free text up to 127 characters. There is no device field: unlike the Firebox Management exception of the same name, a FireCloud exception is account-wide.

[WatchGuard Cloud] Creates a new FireCloud botnet site exception. A botnet site exception can only allow: it exempts the address it names from botnet site blocking, so it opens traffic FireCloud would otherwise stop. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the created exception, including the id that wg_get_firecloud_botnet_site_exception, wg_update_firecloud_botnet_site_exception and wg_delete_firecloud_botnet_site_exception take. The body is a JSON object whose fields are action, address, description; required: address.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe new botnet site exception as a JSON object. address is required and is an object with type and value, where type is ipv4_host, ipv4_range, ipv4_network or fqdn (for example type fqdn with value example.com, or type ipv4_network with value 192.0.2.0/24). action takes the single value allow - this schema accepts no other action. description is free text up to 127 characters. There is no device field: unlike the Firebox Management exception of the same name, a FireCloud exception is account-wide.

[WatchGuard Cloud] Creates a new FireCloud file exception. action decides the direction: allow lets a file with that MD5 through, block stops it. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the created exception, including the id that wg_get_firecloud_file_exception, wg_update_firecloud_file_exception and wg_delete_firecloud_file_exception take. The body is a JSON object whose fields are action, description, md5; required: action, md5.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe new file exception as a JSON object. action is required and is allow or block. md5 is required and is the file's MD5 hash as exactly 32 lowercase hexadecimal characters. description is free text up to 127 characters. There is no device field: unlike the Firebox Management exception of the same name, a FireCloud exception is account-wide.

[WatchGuard Cloud] Creates a new FireCloud Geolocation exception. A Geolocation exception can only allow: it exempts the address it names from the account's Geolocation blocking, so it opens traffic FireCloud would otherwise stop. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the created exception, including the id that wg_get_firecloud_geolocation_exception, wg_update_firecloud_geolocation_exception and wg_delete_firecloud_geolocation_exception take. The body is a JSON object whose fields are action, address, description; required: address.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe new Geolocation exception as a JSON object. address is required and is an object with type and value, where type is ipv4_host, ipv4_range, ipv4_network or fqdn (for example type fqdn with value example.com, or type ipv4_network with value 192.0.2.0/24). action takes the single value allow - this schema accepts no other action. description is free text up to 127 characters. There is no device field: unlike the Firebox Management exception of the same name, a FireCloud exception is account-wide.

[WatchGuard Cloud] Creates a new FireCloud HTTPS decryption exception. An HTTPS decryption exception can only allow: it EXCLUDES the traffic it names from HTTPS inspection, so FireCloud stops decrypting it. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the created exception, including the id that wg_get_firecloud_https_exception, wg_update_firecloud_https_exception and wg_delete_firecloud_https_exception take. The body is a JSON object whose fields are action, description, rule, type; required: rule, type.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe new HTTPS decryption exception as a JSON object. rule is required and is the FQDN or IPv4 address to match; for the ipv4_network type use an address other than 0.0.0.0/x. type is required and is fqdn, ipv4_host or ipv4_network. action takes the single value allow - this schema accepts no other action. description is free text up to 127 characters. There is no device field: unlike the Firebox Management exception of the same name, a FireCloud exception is account-wide.

[WatchGuard Cloud] Creates a new FireCloud IPS signature exception. action decides the direction: allow exempts the signature from enforcement, block enforces it. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the created exception, including the id that wg_get_firecloud_ips_signature_exception, wg_update_firecloud_ips_signature_exception and wg_delete_firecloud_ips_signature_exception take. The body is a JSON object whose fields are action, alarm, description, signature_id; required: action, signature_id.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe new IPS signature exception as a JSON object. action is required and is allow or block. signature_id is required and is the IPS signature ID as digits only, up to 31 characters. alarm is a boolean that defaults to false and decides whether FireCloud sends an alarm for the exception. description is free text up to 127 characters. There is no device field: unlike the Firebox Management exception of the same name, a FireCloud exception is account-wide.

[WatchGuard Cloud] DESTRUCTIVE. Creates a new FireCloud WebBlocker exception. action decides the direction and is required: allow opens a URL the WebBlocker categories block and block refuses one they permit, so a wrong value either exposes the customer to a blocked category or cuts off a site they rely on. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the created exception, including the id that wg_get_firecloud_webblocker_exception, wg_update_firecloud_webblocker_exception and wg_delete_firecloud_webblocker_exception take. The body is a JSON object whose fields are action, alarm, name, rule, rule_type; required: action, name, rule, rule_type.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe new WebBlocker exception as a JSON object. action is required and is allow or block. name is required and is up to 58 characters. rule_type is required and is string (exact match), pattern (pattern match) or regexp (regular expression). rule is required and is the URL value, pattern or expression to match, up to 255 characters, for example www.example.com/*. alarm is a boolean that defaults to false. There is no device field: unlike the Firebox Management exception of the same name, a FireCloud exception is account-wide.

[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified FireCloud blocked sites exception. WatchGuard answers 201 with the deleted exception marked inactive true and publishes no way to reactivate it, so recreate it with wg_create_firecloud_blocked_site_exception if you need it back; once it is gone the address it named goes back under the Blocked Sites list. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the FireCloud blocked sites exception to delete, for example bse_12345_ARBHLJ70Y78rGOIGBS. Get it from wg_list_firecloud_blocked_site_exceptions or wg_list_firecloud_exceptions.

[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified FireCloud botnet site exception. WatchGuard answers 201 with the deleted exception marked inactive true and publishes no way to reactivate it, so recreate it with wg_create_firecloud_botnet_site_exception if you need it back; once it is gone the address it named goes back under botnet site blocking. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the FireCloud botnet site exception to delete, for example bote_CjBY92ourN7Izaa1jJu3eH5. Get it from wg_list_firecloud_botnet_site_exceptions or wg_list_firecloud_exceptions.

[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified FireCloud file exception. WatchGuard answers 201 with the deleted exception marked inactive true and publishes no way to reactivate it, so recreate it with wg_create_firecloud_file_exception if you need it back; once it is gone the MD5 it named goes back to the account's default file handling, so a block exception stops stopping that file. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the FireCloud file exception to delete, for example file_12345_UqhDVIdx8D5iwivAX. Get it from wg_list_firecloud_file_exceptions or wg_list_firecloud_exceptions.

[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified FireCloud Geolocation exception. WatchGuard answers 201 with the deleted exception marked inactive true and publishes no way to reactivate it, so recreate it with wg_create_firecloud_geolocation_exception if you need it back; once it is gone the address it named goes back under the account's Geolocation blocking. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the FireCloud Geolocation exception to delete, for example geoe_12345_aHbWC5IuWO3qzyV2t. Get it from wg_list_firecloud_geolocation_exceptions or wg_list_firecloud_exceptions.

[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified FireCloud HTTPS decryption exception. WatchGuard answers 201 with the deleted exception marked inactive true and publishes no way to reactivate it, so recreate it with wg_create_firecloud_https_exception if you need it back; once it is gone the traffic it excluded goes back under HTTPS decryption, so content an administrator deliberately kept out of inspection is decrypted again. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the FireCloud HTTPS decryption exception to delete, for example hte_12345_ARBHLJ70Y78rGOIGBS. Get it from wg_list_firecloud_https_exceptions or wg_list_firecloud_exceptions.

[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified FireCloud IPS signature exception. WatchGuard answers 201 with the deleted exception marked inactive true and publishes no way to reactivate it, so recreate it with wg_create_firecloud_ips_signature_exception if you need it back; once it is gone the signature goes back to its default enforcement, so a block exception stops stopping that signature. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the FireCloud IPS signature exception to delete, for example ipse_12345_eY5Jwxv1nE3Xlk3zx. Get it from wg_list_firecloud_ips_signature_exceptions or wg_list_firecloud_exceptions.

[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified FireCloud WebBlocker exception. WatchGuard answers 201 with the deleted exception marked inactive true and publishes no way to reactivate it, so recreate it with wg_create_firecloud_webblocker_exception if you need it back; once it is gone the URL goes back to its WebBlocker category action, so an allow exception stops opening it and a block exception stops refusing it. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the FireCloud WebBlocker exception to delete, for example wbe_12124_7HM70EvrifZ7rSfXSA. Get it from wg_list_firecloud_webblocker_exceptions or wg_list_firecloud_exceptions.

[WatchGuard Cloud] Retrieves the specified FireCloud blocked sites exception. WatchGuard answers 404 when the account holds no blocked sites exception with that id. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the FireCloud blocked sites exception to retrieve, for example bse_12345_ARBHLJ70Y78rGOIGBS. Get it from wg_list_firecloud_blocked_site_exceptions or wg_list_firecloud_exceptions.

[WatchGuard Cloud] Retrieves the specified FireCloud botnet site exception. WatchGuard answers 404 when the account holds no botnet site exception with that id. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the FireCloud botnet site exception to retrieve, for example bote_CjBY92ourN7Izaa1jJu3eH5. Get it from wg_list_firecloud_botnet_site_exceptions or wg_list_firecloud_exceptions.

[WatchGuard Cloud] Retrieves the specified FireCloud file exception. WatchGuard answers 404 when the account holds no file exception with that id. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the FireCloud file exception to retrieve, for example file_12345_UqhDVIdx8D5iwivAX. Get it from wg_list_firecloud_file_exceptions or wg_list_firecloud_exceptions.

[WatchGuard Cloud] Retrieves the specified FireCloud Geolocation exception. WatchGuard answers 404 when the account holds no Geolocation exception with that id. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the FireCloud Geolocation exception to retrieve, for example geoe_12345_aHbWC5IuWO3qzyV2t. Get it from wg_list_firecloud_geolocation_exceptions or wg_list_firecloud_exceptions.

[WatchGuard Cloud] Retrieves the specified FireCloud HTTPS decryption exception. WatchGuard answers 404 when the account holds no HTTPS decryption exception with that id. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the FireCloud HTTPS decryption exception to retrieve, for example hte_12345_ARBHLJ70Y78rGOIGBS. Get it from wg_list_firecloud_https_exceptions or wg_list_firecloud_exceptions.

[WatchGuard Cloud] Retrieves the specified FireCloud IPS signature exception. WatchGuard answers 404 when the account holds no IPS signature exception with that id. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the FireCloud IPS signature exception to retrieve, for example ipse_12345_eY5Jwxv1nE3Xlk3zx. Get it from wg_list_firecloud_ips_signature_exceptions or wg_list_firecloud_exceptions.

[WatchGuard Cloud] Retrieves the specified FireCloud WebBlocker exception. WatchGuard answers 404 when the account holds no WebBlocker exception with that id. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
objectidstringyesID of the FireCloud WebBlocker exception to retrieve, for example wbe_12124_7HM70EvrifZ7rSfXSA. Get it from wg_list_firecloud_webblocker_exceptions or wg_list_firecloud_exceptions.

[WatchGuard Cloud] Retrieves all blocked sites exceptions in the specified FireCloud account. The response is a JSON array of blocked sites exception objects; each item's id is the objectid wg_get_firecloud_blocked_site_exception, wg_update_firecloud_blocked_site_exception and wg_delete_firecloud_blocked_site_exception take, and wg_list_firecloud_exceptions returns every kind in one call. This route takes no paging argument - WatchGuard defines limit and start_after in this specification's components but references them from no operation - so one call returns the whole collection for the account. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.

[WatchGuard Cloud] Retrieves all botnet site exceptions in the specified FireCloud account. The response is a JSON array of botnet site exception objects; each item's id is the objectid wg_get_firecloud_botnet_site_exception, wg_update_firecloud_botnet_site_exception and wg_delete_firecloud_botnet_site_exception take, and wg_list_firecloud_exceptions returns every kind in one call. This route takes no paging argument - WatchGuard defines limit and start_after in this specification's components but references them from no operation - so one call returns the whole collection for the account. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.

[WatchGuard Cloud] Retrieves all exceptions in the specified FireCloud account. Start here for FireCloud: the response is one JSON array mixing all seven exception kinds - blocked sites, botnet sites, file, Geolocation, HTTPS decryption, IPS signature and WebBlocker - where each item's object field names its kind and its id is the objectid the get, update and delete tools take. This route takes no paging argument - WatchGuard defines limit and start_after in this specification's components but references them from no operation - so one call returns the whole collection for the account. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.

[WatchGuard Cloud] Retrieves all file exceptions in the specified FireCloud account. The response is a JSON array of file exception objects; each item's id is the objectid wg_get_firecloud_file_exception, wg_update_firecloud_file_exception and wg_delete_firecloud_file_exception take, and wg_list_firecloud_exceptions returns every kind in one call. This route takes no paging argument - WatchGuard defines limit and start_after in this specification's components but references them from no operation - so one call returns the whole collection for the account. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.

[WatchGuard Cloud] Retrieves all Geolocation exceptions in the specified FireCloud account. The response is a JSON array of Geolocation exception objects; each item's id is the objectid wg_get_firecloud_geolocation_exception, wg_update_firecloud_geolocation_exception and wg_delete_firecloud_geolocation_exception take, and wg_list_firecloud_exceptions returns every kind in one call. This route takes no paging argument - WatchGuard defines limit and start_after in this specification's components but references them from no operation - so one call returns the whole collection for the account. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.

[WatchGuard Cloud] Retrieves all HTTPS decryption exceptions in the specified FireCloud account. The response is a JSON array of HTTPS decryption exception objects; each item's id is the objectid wg_get_firecloud_https_exception, wg_update_firecloud_https_exception and wg_delete_firecloud_https_exception take, and wg_list_firecloud_exceptions returns every kind in one call. This route takes no paging argument - WatchGuard defines limit and start_after in this specification's components but references them from no operation - so one call returns the whole collection for the account. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.

[WatchGuard Cloud] Retrieves all IPS signature exceptions in the specified FireCloud account. The response is a JSON array of IPS signature exception objects; each item's id is the objectid wg_get_firecloud_ips_signature_exception, wg_update_firecloud_ips_signature_exception and wg_delete_firecloud_ips_signature_exception take, and wg_list_firecloud_exceptions returns every kind in one call. This route takes no paging argument - WatchGuard defines limit and start_after in this specification's components but references them from no operation - so one call returns the whole collection for the account. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.

[WatchGuard Cloud] Retrieves all WebBlocker exceptions in the specified FireCloud account. The response is a JSON array of WebBlocker exception objects; each item's id is the objectid wg_get_firecloud_webblocker_exception, wg_update_firecloud_webblocker_exception and wg_delete_firecloud_webblocker_exception take, and wg_list_firecloud_exceptions returns every kind in one call. This route takes no paging argument - WatchGuard defines limit and start_after in this specification's components but references them from no operation - so one call returns the whole collection for the account. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.

[WatchGuard Cloud] DESTRUCTIVE. Updates the specified FireCloud blocked sites exception. This replaces the blocked sites exception wholesale: every field you leave out is cleared rather than kept, and the body must also carry the object's own id, object, version, account, created, device and author, so read it back with wg_get_firecloud_blocked_site_exception and send it complete. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the updated object with its version incremented; WatchGuard answers 409 with type object_exists_error when an object already exists with the same id and version. The body is a JSON object whose fields are account, action, address, author, created, description, device, id, object, version; required: account, address, author, created, device, id, object, version.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe complete blocked sites exception as a JSON object - this is a wholesale replace, so read the current object with wg_get_firecloud_blocked_site_exception and send it back with your edits rather than sending the changed fields alone. id, object, version, account, created, device and author are all required: id is the objectid in the path, object is blockedsite_exception, version is the object's current version number, account is the WatchGuard Cloud account ID, created is the Unix epoch time the object was created, device takes the single value firewan, and author is always empty for objects written through the FireCloud Management API - send an empty string. address is required and is an object with type and value, where type is ipv4_host, ipv4_range, ipv4_network or fqdn (for example type fqdn with value example.com, or type ipv4_network with value 192.0.2.0/24), action takes the single value allow and description is free text up to 127 characters.
objectidstringyesID of the FireCloud blocked sites exception to update, for example bse_12345_ARBHLJ70Y78rGOIGBS. It must match the id field in the body; get it from wg_list_firecloud_blocked_site_exceptions.

[WatchGuard Cloud] DESTRUCTIVE. Updates the specified FireCloud botnet site exception. This replaces the botnet site exception wholesale: every field you leave out is cleared rather than kept, and the body must also carry the object's own id, object, version, account, created, device and author, so read it back with wg_get_firecloud_botnet_site_exception and send it complete. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the updated object with its version incremented; WatchGuard answers 409 with type object_exists_error when an object already exists with the same id and version. The body is a JSON object whose fields are account, action, address, author, created, description, device, id, object, version; required: account, address, author, created, device, id, object, version.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe complete botnet site exception as a JSON object - this is a wholesale replace, so read the current object with wg_get_firecloud_botnet_site_exception and send it back with your edits rather than sending the changed fields alone. id, object, version, account, created, device and author are all required: id is the objectid in the path, object is botnet_exception, version is the object's current version number, account is the WatchGuard Cloud account ID, created is the Unix epoch time the object was created, device takes the single value firewan, and author is always empty for objects written through the FireCloud Management API - send an empty string. address is required and is an object with type and value, where type is ipv4_host, ipv4_range, ipv4_network or fqdn (for example type fqdn with value example.com, or type ipv4_network with value 192.0.2.0/24), action takes the single value allow and description is free text up to 127 characters.
objectidstringyesID of the FireCloud botnet site exception to update, for example bote_CjBY92ourN7Izaa1jJu3eH5. It must match the id field in the body; get it from wg_list_firecloud_botnet_site_exceptions.

[WatchGuard Cloud] DESTRUCTIVE. Updates the specified FireCloud file exception. This replaces the file exception wholesale: every field you leave out is cleared rather than kept, and the body must also carry the object's own id, object, version, account, created, device and author, so read it back with wg_get_firecloud_file_exception and send it complete. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the updated object with its version incremented; WatchGuard answers 409 with type object_exists_error when an object already exists with the same id and version. The body is a JSON object whose fields are account, action, author, created, description, device, id, md5, object, version; required: account, action, author, created, device, id, md5, object, version.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe complete file exception as a JSON object - this is a wholesale replace, so read the current object with wg_get_firecloud_file_exception and send it back with your edits rather than sending the changed fields alone. id, object, version, account, created, device and author are all required: id is the objectid in the path, object is file_exception, version is the object's current version number, account is the WatchGuard Cloud account ID, created is the Unix epoch time the object was created, device takes the single value firewan, and author is always empty for objects written through the FireCloud Management API - send an empty string. action and md5 are required as well: action is allow or block, and md5 is the file's MD5 hash as exactly 32 lowercase hexadecimal characters. description is free text up to 127 characters.
objectidstringyesID of the FireCloud file exception to update, for example file_12345_UqhDVIdx8D5iwivAX. It must match the id field in the body; get it from wg_list_firecloud_file_exceptions.

[WatchGuard Cloud] DESTRUCTIVE. Updates the specified FireCloud Geolocation exception. This replaces the Geolocation exception wholesale: every field you leave out is cleared rather than kept, and the body must also carry the object's own id, object, version, account, created, device and author, so read it back with wg_get_firecloud_geolocation_exception and send it complete. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the updated object with its version incremented; WatchGuard answers 409 with type object_exists_error when an object already exists with the same id and version. The body is a JSON object whose fields are account, action, address, author, created, description, device, id, object, version; required: account, address, author, created, device, id, object, version.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe complete Geolocation exception as a JSON object - this is a wholesale replace, so read the current object with wg_get_firecloud_geolocation_exception and send it back with your edits rather than sending the changed fields alone. id, object, version, account, created, device and author are all required: id is the objectid in the path, object is geolocation_exception, version is the object's current version number, account is the WatchGuard Cloud account ID, created is the Unix epoch time the object was created, device takes the single value firewan, and author is always empty for objects written through the FireCloud Management API - send an empty string. address is required and is an object with type and value, where type is ipv4_host, ipv4_range, ipv4_network or fqdn (for example type fqdn with value example.com, or type ipv4_network with value 192.0.2.0/24), action takes the single value allow and description is free text up to 127 characters.
objectidstringyesID of the FireCloud Geolocation exception to update, for example geoe_12345_aHbWC5IuWO3qzyV2t. It must match the id field in the body; get it from wg_list_firecloud_geolocation_exceptions.

[WatchGuard Cloud] DESTRUCTIVE. Updates the specified FireCloud HTTPS decryption exception. This replaces the HTTPS decryption exception wholesale: every field you leave out is cleared rather than kept, and the body must also carry the object's own id, object, version, account, created, device and author, so read it back with wg_get_firecloud_https_exception and send it complete. Clearing a field here turns HTTPS decryption back on for traffic an administrator deliberately excluded. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the updated object with its version incremented; WatchGuard answers 409 with type object_exists_error when an object already exists with the same id and version. The body is a JSON object whose fields are account, action, author, created, description, device, id, object, rule, type, version; required: account, author, created, device, id, object, rule, type, version.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe complete HTTPS decryption exception as a JSON object - this is a wholesale replace, so read the current object with wg_get_firecloud_https_exception and send it back with your edits rather than sending the changed fields alone. id, object, version, account, created, device and author are all required: id is the objectid in the path, object is https_exception, version is the object's current version number, account is the WatchGuard Cloud account ID, created is the Unix epoch time the object was created, device takes the single value firewan, and author is always empty for objects written through the FireCloud Management API - send an empty string. rule and type are required as well: rule is the FQDN or IPv4 address to match and type is fqdn, ipv4_host or ipv4_network. action takes the single value allow and description is free text up to 127 characters.
objectidstringyesID of the FireCloud HTTPS decryption exception to update, for example hte_12345_ARBHLJ70Y78rGOIGBS. It must match the id field in the body; get it from wg_list_firecloud_https_exceptions.

[WatchGuard Cloud] DESTRUCTIVE. Updates the specified FireCloud IPS signature exception. This replaces the IPS signature exception wholesale: every field you leave out is cleared rather than kept, and the body must also carry the object's own id, object, version, account, created, device and author, so read it back with wg_get_firecloud_ips_signature_exception and send it complete. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the updated object with its version incremented; WatchGuard answers 409 with type object_exists_error when an object already exists with the same id and version. The body is a JSON object whose fields are account, action, alarm, author, created, description, device, id, object, signature_id, version; required: account, action, author, created, device, id, object, signature_id, version.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe complete IPS signature exception as a JSON object - this is a wholesale replace, so read the current object with wg_get_firecloud_ips_signature_exception and send it back with your edits rather than sending the changed fields alone. id, object, version, account, created, device and author are all required: id is the objectid in the path, object is ips_exception, version is the object's current version number, account is the WatchGuard Cloud account ID, created is the Unix epoch time the object was created, device takes the single value firewan, and author is always empty for objects written through the FireCloud Management API - send an empty string. action and signature_id are required as well: action is allow or block and signature_id is the signature ID as digits only. alarm is a boolean that defaults to false and description is free text up to 127 characters.
objectidstringyesID of the FireCloud IPS signature exception to update, for example ipse_12345_eY5Jwxv1nE3Xlk3zx. It must match the id field in the body; get it from wg_list_firecloud_ips_signature_exceptions.

[WatchGuard Cloud] DESTRUCTIVE. Updates the specified FireCloud WebBlocker exception. This replaces the WebBlocker exception wholesale: every field you leave out is cleared rather than kept, and the body must also carry the object's own id, object, version, account, created, device and author, so read it back with wg_get_firecloud_webblocker_exception and send it complete. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the updated object with its version incremented; WatchGuard answers 409 with type object_exists_error when an object already exists with the same id and version. The body is a JSON object whose fields are account, action, alarm, author, created, device, id, name, object, rule, rule_type, version; required: account, action, author, created, device, id, name, object, rule, rule_type, version.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe complete WebBlocker exception as a JSON object - this is a wholesale replace, so read the current object with wg_get_firecloud_webblocker_exception and send it back with your edits rather than sending the changed fields alone. id, object, version, account, created, device and author are all required: id is the objectid in the path, object is webblocker_exception, version is the object's current version number, account is the WatchGuard Cloud account ID, created is the Unix epoch time the object was created, device takes the single value firewan, and author is always empty for objects written through the FireCloud Management API - send an empty string. action, name, rule_type and rule are required as well: action is allow or block, name is up to 58 characters, rule_type is string, pattern or regexp, and rule is the URL value, pattern or expression to match, up to 255 characters. alarm is a boolean that defaults to false.
objectidstringyesID of the FireCloud WebBlocker exception to update, for example wbe_12124_7HM70EvrifZ7rSfXSA. It must match the id field in the body; get it from wg_list_firecloud_webblocker_exceptions.

Product Catalog

ToolPlanAccessSummary
wg_list_product_classificationsFreeRead-onlyReturns all product classifications from the WatchGuard Product Catalog.
wg_list_product_familiesFreeRead-onlyReturns all product families from the WatchGuard Product Catalog.
wg_list_product_modelsFreeRead-onlyReturns device models from the WatchGuard Product Catalog that match the specified filters.
wg_list_product_service_suitesFreeRead-onlyReturns a list of all WatchGuard service suites.
wg_list_productsFreeRead-onlyReturns products from the WatchGuard Product Catalog that match the specified filters.

[WatchGuard Cloud] Returns all product classifications from the WatchGuard Product Catalog. Classifications are different types of contracts, such as Subscription. The response is a JSON object with results, an array of classification names as plain strings. These are the values the classification filter of wg_list_products takes. WatchGuard declares no paging on this route, so one call returns the whole list.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.

[WatchGuard Cloud] Returns all product families from the WatchGuard Product Catalog. Product families are different groups of WatchGuard devices in a product category. For example, M Series and T Series are families of Fireboxes. The response is a JSON object with results, an array of family names as plain strings. These are the values the family filter of wg_list_products and of wg_list_product_models take. WatchGuard declares no paging on this route, so one call returns the whole list.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.

[WatchGuard Cloud] Returns device models from the WatchGuard Product Catalog that match the specified filters. Models are different types of Fireboxes. For example, the Firebox M370. The response is a JSON object with results, an array of model names as plain strings, and those are the values the model filter of wg_list_products takes. WatchGuard declares no paging on this route, so one call returns the whole list.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
familystringnonullOptional. Filter results to one product family, named exactly as wg_list_product_families returns it. Example: M Series.

[WatchGuard Cloud] Returns a list of all WatchGuard service suites. Service suites define which subscription services are available for a device or product. The response is a JSON object with results, an array of service suite names as plain strings — Basic Security, Standard Support or Total Security — and those are the values the serviceSuite filter of wg_list_products takes. WatchGuard declares no paging on this route, so one call returns the whole list.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.

[WatchGuard Cloud] Returns products from the WatchGuard Product Catalog that match the specified filters. Start here for the product catalog. The response is a JSON object with results, one entry per product, carrying the sku that wg_create_purchase_order takes in its lineItems, plus the description, category, family, model, service suite, classification, contract term, invoicing frequency, region, suggested retail price and the product type. Every filter below takes a value from one of the companion lists: wg_list_product_classifications, wg_list_product_families, wg_list_product_models and wg_list_product_service_suites.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
classificationstringnonullOptional. Filter results by the type of contract, named exactly as wg_list_product_classifications returns it. Example: Subscription.
familystringnonullOptional. Filter results by the product family, named exactly as wg_list_product_families returns it. Example: M Series.
modelstringnonullOptional. Filter results by the device model, named exactly as wg_list_product_models returns it. Example: M370.
serviceSuitestringnonullOptional. Filter results by the service suite that defines which WatchGuard subscription services are available on a device, named exactly as wg_list_product_service_suites returns it. Example: Total Security.
skipintegernonullOptional. The number of products to skip before the API returns results. StackJack always sends it, as 0 when you leave it empty; set it to the number of products you have already read to get the next page.
takeintegernonullOptional. The number of products to return in the response. WatchGuard's own default is every product, but StackJack always sends a page size — 50 when you leave this empty — and caps it at 100 per call, so walk the catalog with skip.

Subscriptions and Orders

ToolPlanAccessSummary
wg_cancel_subscription_contractProDestructiveDESTRUCTIVE.
wg_create_purchase_orderProDestructiveDESTRUCTIVE.
wg_get_contract_drop_ship_infoFreeRead-onlyReturns drop-ship information for the specified subscription contract.
wg_get_invoiceFreeRead-onlyReturns the invoice with the specified invoice number.
wg_get_subscription_contractFreeRead-onlyReturns details of the subscription contract with the specified ID.
wg_list_contract_usage_detailsFreeRead-onlyReturns license usage information for tenant accounts.
wg_list_invoicesFreeRead-onlyReturns summaries of all consolidated invoices generated between the specified dates.
wg_list_subscription_contractsFreeRead-onlyReturns summaries of subscription contracts created between the specified dates.
wg_resume_subscription_contractProDestructiveDESTRUCTIVE.
wg_set_contract_serial_numberProDestructiveDESTRUCTIVE.
wg_suspend_subscription_contractProDestructiveDESTRUCTIVE.

[WatchGuard Cloud] DESTRUCTIVE. Cancels the specified subscription contract. This ends a live subscription contract: service on the products it covers stops and WatchGuard publishes no re-instatement call. The resume verb is deprecated and only restarts a SUSPENDED contract, so it will not bring this one back. The subscriptionContractId comes from wg_list_subscription_contracts. WatchGuard answers 204 No Content on success, which StackJack returns as {"success":true}, so confirm the outcome by reading the contract back with wg_get_subscription_contract — its status leaves Active. The body is a JSON object whose fields are cancelReason; required: cancelReason.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe cancellation reason as JSON. It is a JSON object with one required field, cancelReason, which WatchGuard accepts as one of CustomerRequest, ResellerRequest, ShippingIssue, NonPayment or OrderError.
subscriptionContractIdstringyesID of an existing subscription contract resource. Must be 1 to 12 characters and include only uppercase letters and numbers. Examples: SB000015439 or 10345.

[WatchGuard Cloud] DESTRUCTIVE. Creates a new purchase order for WatchGuard products. This places a real purchase order with WatchGuard, generates a subscription contract for every SKU on it and commits the account to the cost; WatchGuard publishes no call that withdraws an order, so a mistake is unwound one contract at a time with wg_cancel_subscription_contract. Every SKU comes from wg_list_products. The response echoes the purchase order number and the reseller, and its lineItems array pairs each SKU with the subscriptionContractId WatchGuard generated for it; each of those contracts then needs a device serial number through wg_set_contract_serial_number. Setting isDropShipOrder means dropShipOrderInfo has to carry the shipping details, and wg_get_contract_drop_ship_info reads them back with the tracking number once the order ships. The body is a JSON object whose fields are dropShipOrderInfo, isDropShipOrder, lineItems, purchaseOrderNumber, resellerId; required: lineItems, purchaseOrderNumber, resellerId.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe purchase order as JSON. It is a JSON object. Required: purchaseOrderNumber, your own unique number for the order, up to 20 characters of letters, numbers and dashes; resellerId, the partner or reseller that ordered the products, 11 to 13 characters in the form ACC-1234567; and lineItems, an array of objects each with a required sku, the 8-character SKU of one ordered product. Optional: isDropShipOrder, a boolean, and dropShipOrderInfo, an object holding companyName, contactName, carrierAccountNumber, shipMethod, phoneNumber, phoneExtension, emailAddress and shipToAddress with streetAddress1 to streetAddress3, city, state, postalCode and country. shipMethod takes one of WatchGuard's carrier codes, for example UPS GROUND or FEDEX 2 DAY.

[WatchGuard Cloud] Returns drop-ship information for the specified subscription contract. Only an order placed with isDropShipOrder set has this. The response carries the shipping tracking number, the ship method, the company and contact the order ships to, the carrier account number it ships on, the device serial number, the purchase order number and the ship-to address. WatchGuard capitalizes four of those field names — PhoneNumber, PhoneExtension, SerialNumber and OrderNumber — beside camel-case siblings such as shippingTrackingNumber and shipToAddress, so match them exactly. The subscriptionContractId comes from wg_list_subscription_contracts.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
subscriptionContractIdstringyesID of an existing subscription contract resource. Must be 1 to 12 characters and include only uppercase letters and numbers. Examples: SB000015439 or 10345.

[WatchGuard Cloud] Returns the invoice with the specified invoice number. The invoice number comes from wg_list_invoices and looks like INV_US01_0001. The full invoice adds the bill-to and WatchGuard addresses and a lineItems array with one entry per subscription contract on the invoice, each carrying the contract id, the reseller and its WatchGuardONE level, the SKU and its description, the device serial number, the unit price, the suggested retail price, any markdown and the extended price. A line item carries its billing start and end dates only after WatchGuard has processed the invoice.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
invoiceNumberstringyesNumber of an existing invoice resource. Must be at least 13 characters and include only uppercase letters, numbers, and underscores. Example: INV_US01_0001.

[WatchGuard Cloud] Returns details of the subscription contract with the specified ID. The subscriptionContractId comes from wg_list_subscription_contracts, from the lineItems array that wg_create_purchase_order answers, or from a line item of wg_get_invoice. This read is far richer than a list row: it adds the distributor and reseller ids, the status, the service and appliance SKUs, the term in months, the billing start and end dates, the invoices posted so far, the remaining balance and the total lifetime cost. The status leaves Active when the contract is canceled, and WatchGuard also retires a contract whose device serial number was never assigned before its grace period ended, which is what wg_set_contract_serial_number prevents.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
subscriptionContractIdstringyesID of an existing subscription contract resource. Must be 1 to 12 characters and include only uppercase letters and numbers. Examples: SB000015439 or 10345.

[WatchGuard Cloud] Returns license usage information for tenant accounts. It reports by MONTH: startDate and endDate are months in mmyyyy form, not the yyyy-mm-dd dates the rest of this API takes. The response is a JSON object with pagination, holding totalCount, skip and take, and contracts, each carrying the contract id, the reseller id and name, the product description and a usage array; every usage entry holds the date, a total user count and, while tenantUsage stays on, a customers array naming each customer account, its user count and whether the allocation is delegated.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
endDatestringyesLast month to retrieve license usage information for. Specify the month in the format mmyyyy. Example: 012022.
resellerIdstringnonullOptional. Return usage for one partner or reseller account, 11 to 13 characters in the form ACC-1234567. This filters on whose contracts are reported; it is not the account the call acts on, which is accountId.
skipintegernonullOptional. Number of license usage records to skip before the API returns results. StackJack always sends it, as 0 when you leave it empty; set it to the number of records you have already read to get the next page.
startDatestringyesFirst month to retrieve license usage information for. Specify the month in the format mmyyyy. Example: 012022.
subscriptionContractIdstringnonullOptional. ID of an existing subscription contract you want to retrieve license usage information for. Must be 1 to 12 characters and include only uppercase letters and numbers. Examples: SB000015439 or 10345.
takeintegernonullOptional. Number of license usage records to return in the response. WatchGuard accepts 1 to 1000 and defaults to 100. StackJack caps this at 100 per call and asks for 50 when you leave it empty, so read a large result in pages with skip.
tenantUsagebooleannonullOptional. Specifies whether to show license usage details for each customer (tenant) account in the response. Default: True.

[WatchGuard Cloud] Returns summaries of all consolidated invoices generated between the specified dates. The response is a JSON object with totalRowCount and summaries, and each summary carries the invoice number, the invoice and due dates, the purchase order number, the payment terms, the total and the currency. Read one invoice in full — the bill-to and WatchGuard addresses and a line item per subscription contract, with unit price, markdown and extended price — with wg_get_invoice.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
endDatestringnonullOptional. The last date to retrieve invoices for. Specify the date in the format yyyy-mm-dd. Example: 2019-03-01.
skipintegernonullOptional. The number of invoices to skip before the API returns results. StackJack always sends it, as 0 when you leave it empty; set it to the number of invoices you have already read to get the next page.
startDatestringnonullOptional. The first date to retrieve invoices for. Specify the date in the format yyyy-mm-dd. Example: 2019-03-01.
takeintegernonullOptional. The number of invoices to return in the response. WatchGuard accepts up to 1000 and defaults to 100. StackJack caps this at 100 per call and asks for 50 when you leave it empty, so read a large result in pages with skip.

[WatchGuard Cloud] Returns summaries of subscription contracts created between the specified dates. Start here for anything about a subscription. The response is a JSON object with results, the array of contract summaries, and totalCount, which WatchGuard types as a string rather than a number. Each summary carries the subscriptionContractId that every other tool in this group takes as its selector, plus the purchase order number, the SKU, its description, the device serial number assigned to the contract and the created, start and end dates. Read one contract in full — term, billing dates, invoices posted and remaining balance — with wg_get_subscription_contract.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
firstCreationDatestringnonullOptional. First date to retrieve subscription contracts for. Specify the date in the format yyyy-mm-dd. Example: 2019-03-01.
lastCreationDatestringnonullOptional. Last date to retrieve subscription contracts for. Specify the date in the format yyyy-mm-dd. Example: 2019-03-01.
purchaseOrderNumberstringnonullOptional. Return only the contracts generated by one purchase order — the same purchaseOrderNumber that was sent to wg_create_purchase_order.
resellerIdstringnonullOptional. Return only the contracts ordered by one partner or reseller, for example ACC-1234567. This filters on who ordered the products; it is not the account the call acts on, which is accountId.
skipintegernonullOptional. Number of subscription contracts to skip before the API returns results. StackJack always sends it, as 0 when you leave it empty; set it to the number of contracts you have already read to get the next page.
takeintegernonullOptional. Number of subscription contracts to return in the response. WatchGuard accepts 1 to 1000 and defaults to 100. StackJack caps this at 100 per call and asks for 50 when you leave it empty, so read a large result in pages with skip.

[WatchGuard Cloud] DESTRUCTIVE. DEPRECATED in WatchGuard's own specification, which names no replacement. Resumes the specified suspended subscription contract. This restarts billing on a suspended subscription contract. This call takes no request body at all — the contract is named in the path and WatchGuard documents nothing else, so there is nothing to send. The contract has to be suspended already; WatchGuard documents a 405 Method Not Allowed response on this route as well as a 404 for a contract it cannot find. On success it answers 204 No Content, which StackJack returns as {"success":true}, so read the contract back with wg_get_subscription_contract to confirm.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
subscriptionContractIdstringyesID of a suspended subscription contract resource. Must be 11 or 12 characters (uppercase letters and numbers only). Example: SB000015439.

[WatchGuard Cloud] DESTRUCTIVE. Assigns the specified device serial number to the specified subscription contract. This binds the serial number to the contract, replacing whatever was bound before: the device that held the subscription loses it, and WatchGuard publishes no call that undoes the swap. This is how a distributor fulfills an order: WatchGuard retires a subscription contract whose device serial number was never assigned before its grace period ended. The contract id comes from wg_list_subscription_contracts or from the lineItems that wg_create_purchase_order answers. On success WatchGuard answers 204 No Content, which StackJack returns as {"success":true}; read the contract back with wg_get_subscription_contract to see serialNumber and serialNumberReceivedDate. The body is a JSON object whose fields are serialNumber; required: serialNumber.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe device assignment as JSON. It is a JSON object with one required field, serialNumber: the 13-character serial number, letters and numbers only, of the Firebox to assign to this contract. WatchGuard requires that the device match the model of the product SKU on the contract, exist in your inventory, and not already be assigned to another active subscription contract. Example: 108302A94PT4H.
subscriptionContractIdstringyesID of an existing subscription contract resource. Must be 1 to 12 characters and include only uppercase letters and numbers. Examples: SB000015439 or 10345.

[WatchGuard Cloud] DESTRUCTIVE. DEPRECATED in WatchGuard's own specification, which names no replacement. Suspends the specified subscription contract. This suspends a live subscription contract, so service on the products it covers stops until it is resumed. WatchGuard still publishes the route but marks it retired and offers nothing to use in its place; the contract reads and wg_cancel_subscription_contract remain supported. This route documents a 405 Method Not Allowed response of its own, which is how a retired operation refuses. On success it answers 204 No Content, which StackJack returns as {"success":true}. Only wg_resume_subscription_contract reverses it, and that verb is deprecated too. The body is a JSON object whose fields are suspendReason; required: suspendReason.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe suspension reason as JSON. It is a JSON object with one required field, suspendReason, which WatchGuard accepts as one of CustomerRequest, ResellerRequest, ShippingIssue, NonPayment or OrderError.
subscriptionContractIdstringyesID of an existing subscription contract resource. Must be 11 or 12 characters (uppercase letters and numbers only). Example: SB000015439.

Licenses and Allocations

ToolPlanAccessSummary
wg_allocate_assetsProDestructiveDESTRUCTIVE.
wg_deallocate_assetsProDestructiveDESTRUCTIVE.
wg_get_asset_allocation_summaryFreeRead-onlyReturns your Service Provider inventory for one asset type, split by allocation status, so you can see what is still available to allocate.
wg_list_asset_allocationsFreeRead-onlyReturns what your Service Provider account has allocated out to the accounts you manage, one row per managed account and product.
wg_list_asset_licensesFreeRead-onlyReturns the licenses and devices one account owns, each with its serial number or license key.
wg_list_assigned_assetsFreeRead-onlyReturns the licenses and devices that have been allocated to one account, which is what that account can actually use.
wg_update_asset_allocation_typeProDestructiveDESTRUCTIVE.
wg_update_asset_by_serial_or_licenseProDestructiveDESTRUCTIVE.

[WatchGuard Cloud] DESTRUCTIVE. Allocates a license or a device out of your Service Provider inventory to one of the accounts you manage. The managed account that receives the allocation is the accountId INSIDE the body; the accountId argument is your own Service Provider account, so putting the managed account in the wrong one licenses the wrong customer out of your pool. wg_deallocate_assets is the inverse and takes the allocation back. Read what is still available with wg_get_asset_allocation_summary first, then confirm the result with wg_list_asset_allocations. A success answers only a bare success flag and nothing about the allocation, and WatchGuard reports export-compliance problems in a Warning response header this tool does not return. quantity is required for software products except linked_to_license allocations and takes a number above 0 or the string unlimited; serialOrLicense is required for firebox, fireboxRetention and accessPoint and for every linked_to_license allocation. WatchGuard stops accepting this call after 17 September 2026 for accounts that have no company name, industry, first name, last name and full mailing address. The body is a JSON object whose fields are accountId, allocationExpiryDate, allocationExpiryType, allocationType, modules, productName, quantity, serialOrLicense; required: accountId, productName.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe allocation as a JSON object. accountId is the MANAGED account that receives the allocation, never your own Service Provider account, which is the accountId argument. productName is the WatchGuard product; allocationType is term, subscription or linked_to_license and is required for software products; quantity is a number above 0 or the string unlimited; allocationExpiryType is never or custom, with allocationExpiryDate required when it is custom; serialOrLicense names the device or the linked license; modules carries the Endpoint Security modules. Required fields: accountId, productName.

[WatchGuard Cloud] DESTRUCTIVE. Takes an allocated license or device back from a managed account and returns it to your Service Provider inventory. This is the inverse of wg_allocate_assets: whatever the managed account was running under that allocation stops being licensed, and WatchGuard publishes no undo, so confirm the managed account and the product before you call it. The managed account is the managedAccountId argument; the accountId argument stays your own Service Provider account. WatchGuard marks allocationType and serialOrLicense optional, but allocationType is required for software products and serialOrLicense for hardware devices and for linked_to_license deallocations. A success answers HTTP 204 with no body, which StackJack reports as a bare success flag, so confirm the result with wg_list_asset_allocations.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
allocationTypestringnonullOptional. Allocation type. This parameter is required for software products. Accepted values: term, subscription, mixed, linked_to_license.
managedAccountIdstringyesThe WatchGuard Cloud managed account to take the license back FROM. This is not your own account: list the accounts you manage with wg_list_managed_accounts.
productNamestringyesProduct name. For Linked to License allocations, specify the name of the core product. Accepted values: accessPoint, firebox, fireboxRetention, AuthPoint_MFA, AuthPoint_TIS, WES_EDR_Core, WES_EPP, WES_EDR, WES_Prime, WES_EPDR, WES_AEPDR, WES_Module_Advanced_Reporting_Tool, WES_Module_Data_Control, WES_Module_Full_Encryption, WES_Module_Patch_Management, WES_Module_SIEMFeeder, WES_Module_MDR, WES_Module_Orion, WES_Module_Data_Retention, WatchGuard_NDR, WatchGuard_SaaSDR, FireCloud_InternetAccess, FireCloud_TotalAccess, WatchGuard_Compliance_Reporting, Total_NDR, ThreatSync_Open, MDR_CORE_Microsoft, Total_MDR, Open_MDR, NDR_for_Firebox, Cloud_DR.
serialOrLicensestringnonullOptional. License key or serial number. This parameter is required for hardware devices and for Linked to License deallocations.

[WatchGuard Cloud] Returns your Service Provider inventory for one asset type, split by allocation status, so you can see what is still available to allocate. Reach for this first: it is the pool wg_allocate_assets draws from. The account in the path is your own Service Provider account, so leave accountId empty unless you are acting for another Service Provider account you manage - this is not the read for a managed account's own inventory, which is wg_list_asset_licenses. Software rows carry quantityTotal, quantityAvailable and quantityAllocated; device rows carry one entry per device. WatchGuard pages devices only, so limit and offset do nothing on software rows.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
allocationStatusstringnonullOptional. For devices, whether to return allocated or unallocated assets. WatchGuard defaults to unallocated. Accepted values: allocated, unallocated.
limitintegernonullOptional. For devices, the number of records on each page. StackJack caps this at 100 per call and sends 50 when you omit it, so the vendor's -1 (return every record) is not reachable here; page with offset instead. Software rows are not paged at all.
offsetintegernonullOptional. For devices, the number of records to skip before the results start. A negative value is sent as 0. Page with it alongside limit; the response's pageControls reports totalItems.
resourceTypestringyesType of asset. Accepted values: accessPoint, authPoint, endPoint, firebox, fireboxRetention, fireCloud, managedServices, ndr, threatSync, cloudDR.

[WatchGuard Cloud] Returns what your Service Provider account has allocated out to the accounts you manage, one row per managed account and product. Reach for this first to find where a license went, and call it again after wg_allocate_assets, wg_deallocate_assets or either update verb to confirm the change - those writes answer only a success flag. The account in the path is your own Service Provider account, so leave accountId empty; accountType chooses which kind of managed account is listed. Each row carries the managed account's id and name with quantityTotal, subscriptionTotal and usage, so it is also the view that shows whether a customer is consuming more than it was allocated.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
accountTypeintegeryesWhich kind of managed account to list allocations for: 1 for managed Service Provider accounts, 2 for managed Subscriber accounts. No value returns both, so call this twice if you manage both kinds. Accepted values: 1, 2.
filterBystringnonullOptional. Narrows the results to managed accounts whose accountName contains this text.
limitintegernonullOptional. The number of records on each page. StackJack caps this at 100 per call and sends 50 when you omit it, so the vendor's -1 (return every record) is not reachable here; page with offset instead.
offsetintegernonullOptional. The number of records to skip before the results start. A negative value is sent as 0. Page with it alongside limit; the response's pageControls reports totalItems.
resourceTypestringyesType of asset. Accepted values: accessPoint, authPoint, endPoint, firebox, fireboxRetention, fireCloud, managedServices, ndr, threatSync, cloudDR.
sortBystringnonullOptional. Specifies how to sort results. Accepted values: accountName, licenseType, allocationExpiryDate, quantity.
sortOrderstringnonullOptional. The direction of the sort, ascending or descending. WatchGuard defaults to asc. Accepted values: asc, desc.

[WatchGuard Cloud] Returns the licenses and devices one account owns, each with its serial number or license key. This is the account's own inventory. Use wg_list_assigned_assets for what has been allocated to the account, and wg_list_asset_allocations for what your Service Provider account has allocated out to the accounts you manage. Unlike those two reads, the account in the path is the account being read, so name a managed account in accountId to read that customer's inventory and leave it empty for your own. Rows carry friendlyName, productName, licenseType, serialOrLicense and the expiry; serialOrLicense is the selector wg_deallocate_assets and wg_update_asset_by_serial_or_license take.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
filterBystringnonullOptional. Narrows the results to assets whose friendlyName, serialOrLicense or model contains this text.
limitintegernonullOptional. The number of records on each page. StackJack caps this at 100 per call and sends 50 when you omit it, so the vendor's -1 (return every record) is not reachable here; page with offset instead.
offsetintegernonullOptional. The number of records to skip before the results start. A negative value is sent as 0. Page with it alongside limit; the response's pageControls reports totalItems.
resourceTypestringyesType of asset. Accepted values: accessPoint, authPoint, endPoint, firebox, fireboxRetention, fireCloud, managedServices, ndr, threatSync, cloudDR.

[WatchGuard Cloud] Returns the licenses and devices that have been allocated to one account, which is what that account can actually use. The mirror of wg_list_asset_licenses, which reads what the account owns rather than what was allocated to it; the two answer the same shape, so name the tool you meant. The account in the path is the account being read, so name a managed account in accountId to see what that customer holds and leave it empty for your own Service Provider account. Software rows carry productName, licenseType, quantityTotal or subscriptionTotal and the expiry; device rows carry the serial number, MAC address and model.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
filterBystringnonullOptional. Narrows the results to assets whose friendlyName, serialOrLicense or model contains this text.
limitintegernonullOptional. The number of records on each page. StackJack caps this at 100 per call and sends 50 when you omit it, so the vendor's -1 (return every record) is not reachable here; page with offset instead.
offsetintegernonullOptional. The number of records to skip before the results start. A negative value is sent as 0. Page with it alongside limit; the response's pageControls reports totalItems.
resourceTypestringyesType of asset. Accepted values: accessPoint, authPoint, endPoint, firebox, fireboxRetention, fireCloud, managedServices, ndr, threatSync, cloudDR.

[WatchGuard Cloud] DESTRUCTIVE. Updates an existing software allocation - its quantity, its expiry, and the product or allocation type the entitlement sits on. The allocation being updated is selected entirely by the URL, and a different productName or allocationType in the body MOVES that allocation onto the new product or type rather than adding one; the body also replaces the quantity and the expiry outright, so read the current allocation with wg_list_asset_allocations first. The managed account whose allocation is being updated is the accountId INSIDE the body; the accountId argument is your own Service Provider account. Repeat the URL's productName and allocationType in the body to change only quantity and the expiry; send different ones to re-allocate. serialOrLicense is required when allocationType is linked_to_license. For Endpoint Security products that support modules you must include modules when you update a managed Subscriber account or your own Service Provider account, and for a managed Service Provider account you may send a single productName or a single module. A success answers only a bare success flag and nothing about the allocation, and WatchGuard reports export-compliance problems in a Warning response header this tool does not return. WatchGuard stops accepting this call after 17 September 2026 for accounts that have no company name, industry, first name, last name and full mailing address. The body is a JSON object whose fields are accountId, allocationExpiryDate, allocationExpiryType, allocationType, modules, productName, quantity, serialOrLicense; required: accountId, allocationType, productName.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
allocationTypestringyesThe allocation type of the EXISTING allocation being updated, which is half of its selector - the body decides what it becomes. Accepted values: term, subscription, mixed, linked_to_license.
bodyJsonstringyesThe updated allocation as a JSON object. accountId is the MANAGED account that holds the allocation, never your own Service Provider account, which is the accountId argument. productName and allocationType are required and re-allocate the entitlement when they differ from the URL; quantity is a number above 0 or the string unlimited; allocationExpiryType is never or custom, with allocationExpiryDate required when it is custom; serialOrLicense is required for linked_to_license; modules must be present for Endpoint Security products that support modules. Required fields: accountId, allocationType, productName.
productNamestringyesProduct name of the existing asset allocation to update. Accepted values: accessPoint, firebox, fireboxRetention, AuthPoint_MFA, AuthPoint_TIS, WES_EDR_Core, WES_EPP, WES_EDR, WES_Prime, WES_EPDR, WES_AEPDR, WES_Module_Advanced_Reporting_Tool, WES_Module_Data_Control, WES_Module_Full_Encryption, WES_Module_Patch_Management, WES_Module_SIEMFeeder, WES_Module_MDR, WES_Module_Orion, WES_Module_Data_Retention, WatchGuard_NDR, WatchGuard_SaaSDR, FireCloud_InternetAccess, FireCloud_TotalAccess, WatchGuard_Compliance_Reporting, Total_NDR, ThreatSync_Open, MDR_CORE_Microsoft, Total_MDR, Open_MDR, NDR_for_Firebox, Cloud_DR.

[WatchGuard Cloud] DESTRUCTIVE. Updates an existing hardware allocation, which for a device means when the allocation expires. This replaces the allocation's expiry outright: allocationExpiryType custom with an earlier allocationExpiryDate ends the managed account's device allocation sooner, and WatchGuard publishes no undo. It does not move the device to another account - wg_deallocate_assets followed by wg_allocate_assets does that. The device is selected entirely by the URL, by product name plus its serial number or license key, and the managed account holding the allocation is the accountId INSIDE the body, not the accountId argument, which stays your own Service Provider account. Read the serial from wg_list_asset_licenses or wg_list_assigned_assets. A success answers only a bare success flag and nothing about the allocation, and WatchGuard reports export-compliance problems in a Warning response header this tool does not return. WatchGuard stops accepting this call after 17 September 2026 for accounts that have no company name, industry, first name, last name and full mailing address. The body is a JSON object whose fields are accountId, allocationExpiryDate, allocationExpiryType; required: accountId, allocationExpiryType.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe updated allocation as a JSON object. accountId is the MANAGED account that holds the device allocation, never your own Service Provider account, which is the accountId argument. allocationExpiryType is never or custom, and allocationExpiryDate is required when it is custom. Required fields: accountId, allocationExpiryType.
productNamestringyesProduct name of the existing asset allocation to update. Accepted values: accessPoint, firebox.
serialOrLicensestringyesThe serial number or license key of the allocated device to update. It selects the allocation on its own, so a wrong value edits a different device rather than failing; read it from wg_list_asset_licenses or wg_list_assigned_assets.

AuthPoint MFA

ToolPlanAccessSummary
wg_authenticate_authpoint_otpProDestructiveDESTRUCTIVE.
wg_authenticate_authpoint_passwordProDestructiveDESTRUCTIVE.
wg_authenticate_authpoint_without_authenticatorProDestructiveDESTRUCTIVE.
wg_evaluate_authpoint_authentication_policyProDestructiveDESTRUCTIVE.
wg_get_authpoint_transactionFreeRead-onlyReads back an AuthPoint push transaction by its transaction id to see whether the person approved it.
wg_request_authpoint_qrcodeProDestructiveDESTRUCTIVE.
wg_start_authpoint_push_transactionProDestructiveDESTRUCTIVE.

[WatchGuard Cloud] DESTRUCTIVE. Validates the six-digit one-time password a person read from their AuthPoint authenticator, against the RESTful API Client resource you name. This submits a real person's one-time password - and their password when the policy pairs the two - as a live authentication attempt against their account, so never call it to test or guess a code. Call wg_evaluate_authpoint_authentication_policy first: its policyResponse.otp says whether this person is allowed to authenticate this way, and policyResponse.password says whether the same sign-in also needs their password. Only login and otp are required - the password is sent when the access policy pairs the two. Success is a 200 carrying authenticationResult AUTHORIZED and nothing else; a wrong code and an unknown resource or user both come back as errors rather than as a negative result. The body is a JSON object whose fields are login, originIpAddress, otp, password; required: login, otp.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe request body as JSON. It is a JSON object with four fields: login, required, the person's AuthPoint user name or email address; otp, required, the six-digit one-time password they read from their authenticator, digits only; password, their AuthPoint password in clear text, sent only when the access policy pairs the password with the OTP; and originIpAddress, the end user's IPv4 address, which WatchGuard evaluates against the safe locations configured for that person's AuthPoint group. Required: login, otp.
resourceIdstringyesThe AuthPoint RESTful API Client resource this call runs against - the NUMERIC resource id shown on the RESTful API Client resource page in the AuthPoint management UI. It is not an account id and StackJack cannot default it.

[WatchGuard Cloud] DESTRUCTIVE. Validates a person's AuthPoint password against the RESTful API Client resource you name. This submits a real person's password to AuthPoint as a live authentication attempt, so repeated calls count against that person and can lock them out. Never call it to test or guess a password. This is the password factor only. wg_evaluate_authpoint_authentication_policy reports which methods that person's access policy allows, and when it reports another method alongside the password, finish the sign-in with wg_authenticate_authpoint_otp or wg_start_authpoint_push_transaction. Success is a 200 carrying authenticationResult AUTHORIZED; a wrong password and an unknown resource or user both come back as errors rather than as a negative result. The body is a JSON object whose fields are login, originIpAddress, password; required: login, password.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe request body as JSON. It is a JSON object with three fields: login, required, the person's AuthPoint user name or email address; password, required, their AuthPoint password, which WatchGuard requires in clear text; and originIpAddress, the end user's IPv4 address, which WatchGuard evaluates against the safe locations configured for that person's AuthPoint group. Required: login, password.
resourceIdstringyesThe AuthPoint RESTful API Client resource this call runs against - the NUMERIC resource id shown on the RESTful API Client resource page in the AuthPoint management UI. It is not an account id and StackJack cannot default it.

[WatchGuard Cloud] DESTRUCTIVE. Validates the Forgot Token verification and activation codes for a person and turns Forgot Token mode ON, which lets them authenticate without their authenticator for the number of hours you send. This lowers a real person's multi-factor protection: for the whole interval you send, they can authenticate without their authenticator, and WatchGuard publishes no call to end it early. Confirm an operator actually issued the verification code before you call it. All five body fields are required. The verificationCode is the six-digit value an operator generates in the AuthPoint management UI and gives to the person; the activationCode is any six-digit number your side generates and shows to them so they can read it back to that operator; interval is the number of HOURS Forgot Token mode stays on, as the operator authorized it. Success is a 200 carrying authenticationResult AUTHORIZED. While Forgot Token mode is on, wg_evaluate_authpoint_authentication_policy reports isInForgotToken true for that person. WatchGuard publishes no call to switch it off again - it lapses when the interval runs out - so send the interval the operator actually authorized. The body is a JSON object whose fields are activationCode, interval, login, password, verificationCode; required: activationCode, interval, login, password, verificationCode.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe request body as JSON. It is a JSON object with five required fields: login, the person's AuthPoint user name or email address; password, their AuthPoint password in clear text; verificationCode, the six-digit value an operator generated in the AuthPoint management UI and gave to them; activationCode, a six-digit number your application generates and shows to them; and interval, a NUMBER OF HOURS that Forgot Token mode stays active. Required: activationCode, interval, login, password, verificationCode.
resourceIdstringyesThe AuthPoint RESTful API Client resource this call runs against - the NUMERIC resource id shown on the RESTful API Client resource page in the AuthPoint management UI. It is not an account id and StackJack cannot default it.

[WatchGuard Cloud] DESTRUCTIVE. Asks AuthPoint whether a named person can authenticate through the RESTful API Client resource you name, and which methods their access policy allows - password, OTP, QR code and push. It changes no configuration and reads no secret, and it is still marked destructive under this connector's human-reaching rule: every AuthPoint call names a real person and acts on their live ability to authenticate. Reach for this first: policyResponse.password, .otp, .qrCode and .push decide whether to follow with wg_authenticate_authpoint_password, wg_authenticate_authpoint_otp or wg_start_authpoint_push_transaction, and the rest of the answer says WHY someone cannot authenticate - hasPolicy, isAllowedToAuthenticate, isBlocked, isInQuarantine, isOverallocated, isInSafeLocation and isInForgotToken. Those four policy members are BOOLEANS about what is permitted; they never carry the person's password or one-time password. Send originIpAddress or WatchGuard cannot evaluate the safe locations configured for that person's group. A person or resource WatchGuard does not know answers 404. Every tool in this family names a RESTful API Client resource created in AuthPoint, so the family is reachable only on an account that has the AuthPoint product. The body is a JSON object whose fields are login, originIpAddress; required: login.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe request body as JSON. It is a JSON object with two fields: login, required, the person's AuthPoint user name or email address; and originIpAddress, the end user's IPv4 address, which WatchGuard evaluates against the safe locations configured for that person's AuthPoint group. Required: login.
resourceIdstringyesThe AuthPoint RESTful API Client resource this call runs against - the NUMERIC resource id shown on the RESTful API Client resource page in the AuthPoint management UI. It is not an account id and StackJack cannot default it.

[WatchGuard Cloud] Reads back an AuthPoint push transaction by its transaction id to see whether the person approved it. This is the read-back for wg_start_authpoint_push_transaction: keep the transactionId that call answered with, because WatchGuard publishes no way to list transactions. A 200 carrying pushResult AUTHORIZED means the person approved the notification. While they have not answered yet WatchGuard answers 202 - a SUCCESS whose body is a problem-details object rather than a result - so read that as still waiting and call again instead of treating it as a failure. A denial answers 403, an unknown transaction 404 and a failed push 412, and those three reach you as errors.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
resourceIdstringyesThe AuthPoint RESTful API Client resource this call runs against - the NUMERIC resource id shown on the RESTful API Client resource page in the AuthPoint management UI. It is not an account id and StackJack cannot default it.
transactionIdstringyesThe push transaction to check - the transactionId wg_start_authpoint_push_transaction answered with.

[WatchGuard Cloud] DESTRUCTIVE. Validates the six-digit verification code a person read back after scanning an AuthPoint QR code, which closes the QR code leg of a sign-in. This is a live authentication attempt against a real person's account, and the verification code it carries is single use: a failure counts against that person and the QR code has to be generated again. Despite this tool's name it does NOT generate a QR code. wg_start_authpoint_push_transaction with type QRCODE generates one and answers the transactionId and the command to render; this call validates what the person read back after scanning it, quoting that same transactionId. Success is a 200 carrying authenticationResult AUTHORIZED; a wrong or expired verification code comes back as an error. The body is a JSON object whose fields are login, originIpAddress, qrCodeResponse, transactionId; required: login, qrCodeResponse, transactionId.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe request body as JSON. It is a JSON object with four fields: login, required, the person's AuthPoint user name or email address; qrCodeResponse, required, the six-digit verification code they read from their authenticator after scanning the QR code; transactionId, required, the id of the QR code being validated, as answered by wg_start_authpoint_push_transaction when type is QRCODE; and originIpAddress, the end user's IPv4 address, which WatchGuard evaluates against the safe locations configured for that person's AuthPoint group. Required: login, qrCodeResponse, transactionId.
resourceIdstringyesThe AuthPoint RESTful API Client resource this call runs against - the NUMERIC resource id shown on the RESTful API Client resource page in the AuthPoint management UI. It is not an account id and StackJack cannot default it.

[WatchGuard Cloud] DESTRUCTIVE. Starts an AuthPoint multi-factor transaction for a person: type PUSH sends an approval notification to their phone, type QRCODE generates a QR code for them to scan. A PUSH interrupts a real person on their phone and asks them to approve a sign-in, so a repeated or mistaken call is an unexpected MFA prompt - send it only for a sign-in that person is actually making. It answers transactionId, plus command when the type is QRCODE - the value to render as the QR code, which is that person's challenge and belongs on their screen only. Follow a PUSH with wg_get_authpoint_transaction, which reads that transactionId back and answers 202 while the person has not responded; follow a QRCODE with wg_request_authpoint_qrcode, which validates the six-digit code they read back, quoting the same transactionId. clientInfoRequest is required and describes the device the person is authenticating FROM - machineName, osVersion and domain. The password is sent only when the access policy pairs it with this method, which wg_evaluate_authpoint_authentication_policy reports. The body is a JSON object whose fields are clientInfoRequest, login, originIpAddress, password, type; required: clientInfoRequest, login, type.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe request body as JSON. It is a JSON object with five fields: login, required, the person's AuthPoint user name or email address; type, required, either PUSH to send an approval notification or QRCODE to generate a QR code; clientInfoRequest, required, an object describing the device the person authenticates from with machineName, osVersion and domain; password, their AuthPoint password in clear text, sent only when the access policy pairs it with this method; and originIpAddress, the end user's IPv4 address, which WatchGuard evaluates against the safe locations configured for that person's AuthPoint group. Required: clientInfoRequest, login, type.
resourceIdstringyesThe AuthPoint RESTful API Client resource this call runs against - the NUMERIC resource id shown on the RESTful API Client resource page in the AuthPoint management UI. It is not an account id and StackJack cannot default it.

Operators

ToolPlanAccessSummary
wg_create_operatorsProDestructiveDESTRUCTIVE.
wg_delete_operatorsProDestructiveDESTRUCTIVE.
wg_get_operator_transaction_statusFreeRead-onlyReturns the per-operator outcome of an operator create, update or delete batch.
wg_list_operatorsFreeRead-onlyLists the operators of a WatchGuard Cloud account with their contact details and MFA status.
wg_update_operatorsProDestructiveDESTRUCTIVE.

[WatchGuard Cloud] DESTRUCTIVE. Creates one or more WatchGuard Cloud operators, each with a role, in the account its own element names. This creates real WatchGuard Cloud operators with the role you name and emails them, so it is a privilege grant as well as an account creation. The whole array is applied in one call and StackJack neither inspects nor filters what it carries, so send only the operators you mean to create. WatchGuard answers a transaction id rather than the affected operators; read the per-operator outcome back with wg_get_operator_transaction_status. The body is a JSON array whose fields are accountId, email, firstName, lastName, password, phone, role, username; required: accountId, email, firstName, lastName, phone, role, username.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe request body as JSON. Each element takes username, accountId, firstName, lastName, email, phone and role — all seven required — plus an optional password. accountId is per element and names the account the operator is created IN, which is not the same thing as this tool's accountId argument: that argument only selects the account the call is made against. role is one of OWNER, AUDITOR, SALES, HELPDESK, ADMINISTRATOR, ANALYST, OBSERVER or NO_ACCESS, upper case exactly as written. Leave password out and WatchGuard emails the operator a reset link instead; include one and it must be at least 12 characters with a lowercase letter, an uppercase letter, a number and a symbol, and must not contain angle brackets, emoji or spaces.

[WatchGuard Cloud] DESTRUCTIVE. Deletes operators from a WatchGuard Cloud account. This removes the named operators' access to the account. WatchGuard offers no undo. The whole array is applied in one call and StackJack neither inspects nor filters what it carries, so confirm every username with wg_list_operators first. WatchGuard answers a transaction id rather than the affected operators; read the per-operator outcome back with wg_get_operator_transaction_status. The route is a POST because WatchGuard models the batch in a request body, not because it is reversible. The body is a JSON array whose fields are accountId, username; required: accountId, username.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe request body as JSON. Each element requires username and accountId — the operator to remove and the account to remove it from — and WatchGuard reads nothing else, so the username is the only thing separating a right deletion from a wrong one.

[WatchGuard Cloud] Returns the per-operator outcome of an operator create, update or delete batch. This is the read-back for wg_create_operators, wg_update_operators and wg_delete_operators, each of which answers a transaction id rather than a result. The response carries transaction_status, one entry per operator in the batch with its own status, username and error, so a batch can succeed for some operators and fail for others — read every entry rather than the envelope's status.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
transactionIdstringyesThe transaction id an operator create, update or delete returned, for example 4eb735c2-7640-4aw2-43a3-f429382b8bax.

[WatchGuard Cloud] Lists the operators of a WatchGuard Cloud account with their contact details and MFA status. Start here: this is the only read that names an account's operators, and the usernames it returns are what wg_update_operators and wg_delete_operators select on. The account argument IS the account_id query parameter this API requires, so leaving it empty lists your own account's operators. Each entry carries accountId, email, firstName, lastName, phone, mfa and username — WatchGuard does not return the operator's ROLE here, so there is no read-back for a role set by wg_update_operators. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.

[WatchGuard Cloud] DESTRUCTIVE. Updates existing WatchGuard Cloud operators, including the role they hold in the account. The body carries the operator role, so one call can raise an existing operator's privileges. The whole array is applied in one call and StackJack neither inspects nor filters what it carries. WatchGuard answers a transaction id rather than the affected operators; read the per-operator outcome back with wg_get_operator_transaction_status. wg_list_operators does not return an operator's role, so there is no read-back for the role this sets. The body is a JSON array whose fields are accountId, firstName, lastName, phone, role, username; required: accountId, username.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe request body as JSON. Each element requires username and accountId — the operator to update and the account it holds the role in — and may carry firstName, lastName, phone and role. role is one of OWNER, AUDITOR, SALES, HELPDESK, ADMINISTRATOR, ANALYST, OBSERVER or NO_ACCESS, upper case exactly as written, and raises a privilege as readily as it lowers one. WatchGuard's specification defines no email field here and does not state what it does with a field you omit, so send the fields you mean to set.

Portal Accounts

ToolPlanAccessSummary
wg_create_portal_accountProDestructiveDESTRUCTIVE.
wg_get_portal_accountFreeRead-onlyRetrieves whether the specified account ID is an existing Partner account.

[WatchGuard Cloud] DESTRUCTIVE. Creates a new tier-1 partner account and an associated user. This provisions a real tier-1 partner account in the WatchGuard Portal together with its first user, and WatchGuard emails that person either way: supply userInfo.password and the 201 reports in emailSent whether the account email went out, omit it and WatchGuard sends a password reset email to userInfo.email. This API publishes no call that deletes the account or the user afterwards, so confirm the company and the person with whoever owns the relationship first. This is not the tool that adds a customer under you: wg_create_managed_account creates a managed account inside your own WatchGuard Cloud tenancy, while this one creates a top-level tier-1 partner account with its own first user. The accountId argument does not name the account being created and is not part of the URL — it only selects the account this call is authorized as — and the new account's ID comes back in the response beside accountCreated, regionSet and emailSent, where regionSet reports whether accountInfo.region (APAC, AMERICAS or EUROPE, the geographic region WatchGuard records for the company) was set on the new account. WatchGuard documents 409 Conflict beside the 201 and does not name the conflicting field, and the specification makes no idempotency promise, so do not repeat this call blind after an error. The body is a JSON object whose fields are accountInfo, userInfo; required: accountInfo, userInfo.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe new account and its first user as JSON. It is a JSON object with two required fields. userInfo requires email (4-80 characters), firstName and lastName (1-40 each), phoneNumber (6-40) and username (5-65 characters: alphanumeric without accent marks, underscore, plus sign, minus sign and dot); its password field is optional, and leaving it out makes WatchGuard email a password reset link to that address instead, so send one only to set the first password — minimum 12 characters including a lowercase letter, an uppercase letter, a number and a symbol, and no angle brackets, emoji or spaces. accountInfo requires companyName (up to 150 characters), industry (up to 50 characters; WatchGuard suggests values such as Finance, Government, Healthcare, ISP, Manufacturing, Retail and Others and accepts any string within those rules), region (exactly one of APAC, AMERICAS or EUROPE) and address, which itself requires street, city (up to 40 characters), postalCode (up to 20) and country spelled as one of WatchGuard's own country names, for example United States. address.state is required when country is Australia, Brazil, Canada, Spain or United States and takes WatchGuard's code for the state or province, for example CA or ON. accountInfo.optedInForEmail is an optional boolean that opts the user in to WatchGuard marketing email.

[WatchGuard Cloud] Retrieves whether the specified account ID is an existing Partner account. The whole answer is one field: WatchGuard replies {"isPartner": true} or {"isPartner": false} and returns nothing about the account itself, so read the account record — name, type, contacts, addresses — with wg_get_account and use this only to settle whether an ID belongs to a WatchGuard Partner. The ID is a WatchGuard Portal account ID of, in the vendor's own wording, at least 11 or 12 characters, letters, numbers and dashes only, beginning ACC-, for example ACC-12345678. WatchGuard documents 400 Bad Request and 404 Not Found beside the 200 and does not say which an unknown but well-formed ID gets, so read any error as no answer rather than as isPartner false. The ID you name is also the account this call is authorized as, so name your own account or one you manage — list them with wg_list_managed_accounts — and leave it empty to ask about your own.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.

Activations

ToolPlanAccessSummary
wg_activate_productsProDestructiveDESTRUCTIVE.
wg_get_activation_batch_statusFreeRead-onlyReturns every line item of one activation batch, with its status and the errors WatchGuard recorded, selected by the batch ID.
wg_list_recent_activationsFreeRead-onlyLists the account's activation batches from the last 30 days, one entry per batch.

[WatchGuard Cloud] DESTRUCTIVE. Redeems activation keys to activate hardware devices and software licenses on the account, and WatchGuard publishes no call that reverses it. An activation key is spent the moment WatchGuard accepts the batch: the call answers 202 Accepted and the activations then run asynchronously, so there is no later point at which an agent can stop one. Check every activationKey, parentSerialNumber and parentLicenseKey before you call this, and read the batch back with wg_get_activation_batch_status rather than posting it a second time - the specification publishes no idempotency key. WatchGuard answers with an activations array rather than a result: each entry carries batchId, the batch status (Created, Processing, Complete or CompleteWithErrors), a statusUrl and the batchItems it created, so a 202 means accepted, not activated. Take batchId into wg_get_activation_batch_status to see which line items succeeded and why one failed; wg_list_recent_activations finds the batch again later, inside its 30-day window. Each entry of the body takes either deviceDetails, for hardware and virtual appliances, or saasDetails, for software licenses. The body is a JSON object whose fields are activations.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
bodyJsonstringyesThe activation request as JSON. It is a JSON object with one field, activations, an array whose entries each carry activationKey - the serial number or license key to redeem - and then either deviceDetails or saasDetails. deviceDetails holds friendlyName, parentSerialNumber, initialServiceLicenseKey (a license activated with the device, such as a Wi-Fi access point license), instanceId (the VM ID of a Firebox Cloud or FireboxV instance), deviceLocation (address1, address2, city, stateOrProvince, country, zipCode; the vendor sends it for a Premium 4-Hour Replacement), tradeIn (serialNumber, competitorName, competitorModel) and tradeUp (serialNumber). saasDetails holds licenseName for a new software license, or parentLicenseKey with extendOrAddUsers set to Extend, AddUsers, UpgradeExtend or DoNotUpgrade to co-term the new license with an existing one. The specification marks no field required, so a mistyped or empty entry is refused upstream as a 400.

[WatchGuard Cloud] Returns every line item of one activation batch, with its status and the errors WatchGuard recorded, selected by the batch ID. The batchId comes from the activations[].batchId that wg_activate_products answered, or from results[].batchId in wg_list_recent_activations. Each entry of results is one line item: lineItemId, the activationKey it redeemed, status - the specification's line-item vocabulary is Created, Queued, Pending, Success and Failed - created, lastModified, and an errors array whose errorType names why a failed item failed. The batch runs asynchronously, so a batch still sitting at Created or Processing answers differently a moment later; poll this read instead of posting the activation again. The response is credential material: results[].activationKey is the redeemable license key itself, so keep the body out of anywhere you would not put a license key.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
batchIdstringyesThe activation batch to read, as answered in activations[].batchId by wg_activate_products or in results[].batchId by wg_list_recent_activations.
limitintegernonullOptional. Number of line items to return in one page. StackJack sends 50 when you omit it and caps it at 100 per call, so the vendor's own default of 100 never reaches the API; walk a larger batch with offset.
offsetintegernonullOptional. Number of line items to skip before the page starts, counting from 0. A negative value is sent as 0.
sortBystringnonullOptional. LastModified is the only sort key WatchGuard defines, and the specification names no direction; omit it to take the API's own order.

[WatchGuard Cloud] Lists the account's activation batches from the last 30 days, one entry per batch. This is the read to reach for first, and the only way to find a batchId after the fact: WatchGuard keeps a 30-day window and an older activation is not in this response at all. Each entry is a batch rather than a line item - activationStatus (Created, Processing, Complete or CompleteWithErrors), batchId, created, lastModified, lineItemCount and firstLineItem, which is only the FIRST item of the batch - so a batch whose lineItemCount is above 1 is incomplete here, and its remaining items come from wg_get_activation_batch_status with that batchId. The response is credential material: firstLineItem.activationKey is the redeemable license key itself.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. The WatchGuard Cloud account this call acts on, for example ACC-1234567. Leave empty for your own account; list the accounts you manage with wg_list_managed_accounts.
limitintegernonullOptional. Number of activation batches to return in one page. StackJack sends 50 when you omit it and caps it at 100 per call, so the vendor's own default of 100 never reaches the API; walk the rest with offset.
offsetintegernonullOptional. Number of activation batches to skip before the page starts, counting from 0. A negative value is sent as 0.
sortBystringnonullOptional. LastModified is the only sort key WatchGuard defines, and the specification names no direction; omit it to take the API's own order.