WatchGuard Cloud Tools
Written By Christopher Scaminaci
Last updated 7 days ago
WatchGuard Cloud Tools
wg_ · 232 tools · Free 130 · Pro 102
All sixteen WatchGuard APIs: ThreatSync incidents, Endpoint Security inventory, risk, tasks and isolation (Aether or WES), Firebox Management and FireCloud configuration (policies, exceptions, networking, certificates, deployments), Firebox dashboards, NDR assets and alerts, accounts, operators, subscriptions, orders, licenses, activations and AuthPoint MFA. Auth is OAuth2 client_credentials, TWO credentials per request: a 3,600-second bearer from POST /oauth/token (host root, not /rest) with Basic base64(AccessID:Password), no refresh token, plus a static WatchGuard-API-Key header on EVERY call. A managed account is reached by binding it INTO the token - an opaque audience minted per account - and repeating that id in the URL. Three regional hosts by code (usa, deu, jpn), /rest in the authority. Paging differs per family (OData top/skip, offset/limit, startAfter, rowCount), capped at 100; Firebox Management and FireCloud lists are unpaginated and answer whole collections.
All connector tools · WatchGuard Cloud setup guide
WatchGuard Cloud tool groups
- ThreatSync Incidents — 9 tools
- ThreatSync Response Actions — 4 tools
- Endpoint Devices and Inventory — 13 tools
- Endpoint Isolation — 2 tools
- Endpoint Risk and Security Events — 9 tools
- Endpoint Tasks — 5 tools
- Accounts and Managed Accounts — 5 tools
- Firebox Reports — 2 tools
- NDR Assets — 5 tools
- NDR Smart Alerts — 2 tools
- Platform — 1 tool
- Firebox Deployments — 7 tools
- Firebox Authentication — 10 tools
- Firebox Exceptions — 38 tools
- Firebox Networking — 16 tools
- Firebox Policies — 18 tools
- Firebox System — 9 tools
- FireCloud Exceptions — 36 tools
- Product Catalog — 5 tools
- Subscriptions and Orders — 11 tools
- Licenses and Allocations — 8 tools
- AuthPoint MFA — 7 tools
- Operators — 5 tools
- Portal Accounts — 2 tools
- Activations — 3 tools
ThreatSync Incidents
wg_create_incident_comment details
wg_create_incident_comment details
[WatchGuard Cloud] Adds a comment to a ThreatSync incident. Purely additive — it creates a new comment and changes nothing that exists — so it is not marked destructive.
wg_delete_incident_comment details
wg_delete_incident_comment details
[WatchGuard Cloud] DESTRUCTIVE. Permanently removes one comment from a ThreatSync incident. The comment trail is the written record of how an incident was handled, and WatchGuard has no undo for this — an incident that later becomes evidence loses that record. Prefer wg_update_incident_comment when the text is simply wrong.
wg_get_incident details
wg_get_incident details
[WatchGuard Cloud] Returns one ThreatSync incident by ID, optionally with its actions and comments inline. Get incident IDs from wg_list_incidents. Reading the incident with its actions is the cheapest way to see what has already been tried before performing another one.
wg_get_incident_action details
wg_get_incident_action details
[WatchGuard Cloud] Returns one response action on one ThreatSync incident, with its full detail. Get action IDs from wg_list_incident_actions.
wg_list_incident_actions details
wg_list_incident_actions details
[WatchGuard Cloud] Lists the response actions recorded against one ThreatSync incident — what was attempted, by whom and how it ended. Read this before performing another action, so a remediation is not run twice.
wg_list_incident_comments details
wg_list_incident_comments details
wg_list_incidents details
wg_list_incidents details
[WatchGuard Cloud] Lists ThreatSync incidents — the correlated detections WatchGuard raises across Firebox, Endpoint Security and NDR together, which makes this the first place to look when asking what is happening on a customer's estate. Page with limit plus startAfter, using the cursor value from the last record of the previous page. Use duration (a number followed by D, e.g. 7D) to bound the window rather than paging through history. As a Service Provider, pass accountId to work in a managed account — list them with wg_list_managed_accounts — or set tenants true to include managed accounts alongside your own.
wg_update_incident_comment details
wg_update_incident_comment details
[WatchGuard Cloud] Replaces the text of one comment on a ThreatSync incident. It rewrites that comment and nothing else, and the comment trail keeps its own history, so it is not marked destructive. Get comment IDs from wg_list_incident_comments.
wg_update_incident_status details
wg_update_incident_status details
[WatchGuard Cloud] Moves a ThreatSync incident to a different status, with an optional note. This is triage bookkeeping — it changes nothing on any device and the status can be moved back — so it is not marked destructive. Read the incident first with wg_get_incident to see which statuses it has already been through.
ThreatSync Response Actions
wg_list_actions details
wg_list_actions details
[WatchGuard Cloud] Lists ThreatSync response actions across the whole account rather than for one incident — the record of every remediation ThreatSync has run, which is what a monthly security review is built from. Bound it with duration (a number of days followed by D) rather than paging through history.
wg_perform_action details
wg_perform_action details
[WatchGuard Cloud] DESTRUCTIVE. Runs a ThreatSync response action outside any one incident — block, quarantine or stop something on a live estate, with no incident record tying it to a detection and no undo. Prefer wg_perform_incident_action when the action belongs to an incident, so the remediation is recorded against it.
wg_perform_incident_action details
wg_perform_incident_action details
[WatchGuard Cloud] DESTRUCTIVE. Runs a ThreatSync response action against a live incident — this is the remediation lane, so the command can block a connection, quarantine a file or stop a process on a real machine, and WatchGuard offers no undo for it. Read wg_list_incident_actions first to see what the incident already accepts and what has been tried. The parameters object is the command's own argument set, exactly as ThreatSync documents it for that command.
wg_submit_transaction details
wg_submit_transaction details
[WatchGuard Cloud] DESTRUCTIVE. Submits several ThreatSync requests together as one transaction. Each entry names its own path, method and body, so this can reach ANY ThreatSync write — including the remediation actions and the comment delete — in a single call, and nothing in the batch is reviewed tool by tool. Use the individual tools unless you genuinely need one transaction, and read WatchGuard's transaction documentation before composing the body.
Endpoint Devices and Inventory
wg_get_endpoint_hardware_inventory details
wg_get_endpoint_hardware_inventory details
[WatchGuard Cloud] Returns the BIOS and hardware characteristics of one managed device. Get device IDs from wg_list_endpoint_devices.
wg_get_endpoint_installer_url details
wg_get_endpoint_installer_url details
[WatchGuard Cloud] Returns a download URL for an endpoint installation package built with a specific managed configuration. It reads a URL and installs nothing by itself. Get configuration IDs from wg_list_endpoint_managed_configurations.
wg_get_endpoint_licenses details
wg_get_endpoint_licenses details
[WatchGuard Cloud] Returns the endpoint license position for an account — what is owned, what is used and what is left. Read this before deploying to new devices.
wg_link_endpoint_devices_to_configuration details
wg_link_endpoint_devices_to_configuration details
[WatchGuard Cloud] DESTRUCTIVE. Re-points devices at a different managed configuration, which REPLACES the protection settings applied to those machines — a device moved to a weaker profile stops enforcing what its old profile enforced, silently and immediately. StackJack ships no unlink tool to reverse it, so read the device's current configuration with wg_list_endpoint_devices (config true) and the target profile with wg_list_endpoint_managed_configurations before calling this. Acts on the Aether generation unless you set generation to wes.
wg_list_endpoint_devices details
wg_list_endpoint_devices details
[WatchGuard Cloud] Lists the devices WatchGuard Endpoint Security manages, with their addresses and operating systems. This is where device IDs come from for every other endpoint tool. Page with top and skip; WatchGuard caps the response at 3,000 records however you ask, so narrow with search rather than paging past that. As a Service Provider, pass accountId to read a managed account.
wg_list_endpoint_managed_configurations details
wg_list_endpoint_managed_configurations details
[WatchGuard Cloud] Lists the managed configurations of one type — the protection profiles devices are assigned to. Read this before linking any device to a configuration, so the profile is the one you meant.
wg_list_endpoint_missing_patches details
wg_list_endpoint_missing_patches details
[WatchGuard Cloud] Lists published patches that are not installed on the customer's devices — the patch-gap report. Narrow with filter by patch type or criticality rather than reading the whole estate.
wg_list_endpoint_protection_status details
wg_list_endpoint_protection_status details
[WatchGuard Cloud] Lists devices with their protection status — which agents are installed, up to date and actually protecting the machine. This is the read that answers whether a customer's endpoint coverage is real, rather than whether the devices exist. Capped by WatchGuard at 3,000 records.
wg_list_endpoint_software_inventory details
wg_list_endpoint_software_inventory details
[WatchGuard Cloud] Lists the software installed across the customer's managed devices. Use filter with WatchGuard's own filter syntax to narrow to one device or one product — an unfiltered estate-wide read is large.
wg_list_unmanaged_endpoint_devices details
wg_list_unmanaged_endpoint_devices details
[WatchGuard Cloud] Lists devices discovered on the customer's network that WatchGuard does NOT manage — the gap between what is on the network and what is protected. Capped by WatchGuard at 3,000 records.
wg_scan_endpoint_devices_now details
wg_scan_endpoint_devices_now details
[WatchGuard Cloud] Starts an immediate malware scan on the named devices. It creates a scan task and removes nothing, so it is not marked destructive — it is the safest first response to a suspicion. It does use the devices' processors while it runs, so an estate-wide scan in working hours will be noticed. Track it afterwards with wg_list_endpoint_tasks. Acts on the Aether generation unless you set generation to wes.
wg_send_endpoint_device_action details
wg_send_endpoint_device_action details
[WatchGuard Cloud] DESTRUCTIVE. Sends an action to the named devices — today that means a restart, which closes whatever the person at the keyboard had open. The countdown gives them warning; without one the machine restarts immediately. Name the exact device IDs. Acts on the Aether generation unless you set generation to wes.
wg_uninstall_endpoint_protection details
wg_uninstall_endpoint_protection details
[WatchGuard Cloud] DESTRUCTIVE. Removes WatchGuard protection from the named devices, leaving them unprotected and no longer reporting. Re-protecting a device means building an installer and running it on the machine, so this is not something an assistant should do to tidy up an inventory. Use it only when a device is genuinely being retired or moved off the product. Acts on the Aether generation unless you set generation to wes.
Endpoint Isolation
wg_isolate_endpoint_devices details
wg_isolate_endpoint_devices details
[WatchGuard Cloud] DESTRUCTIVE. Takes the named devices OFF the network. Isolation is the right answer to a live compromise and the wrong answer to almost everything else: an isolated machine loses shared drives, line-of-business applications and remote access, and the person using it will notice within seconds. Name the exact device IDs — never a whole estate — and reverse it with wg_stop_endpoint_device_isolation. Acts on the Aether generation unless you set generation to wes.
wg_stop_endpoint_device_isolation details
wg_stop_endpoint_device_isolation details
[WatchGuard Cloud] DESTRUCTIVE. Returns isolated devices to the network. It reads like an undo, and it is marked destructive for the same reason isolation is: a machine was quarantined because something was found on it, and putting it back before that is resolved re-exposes the network to it. Confirm the threat is cleared first — wg_list_incidents will show whether the incident that isolated it is closed. Acts on the Aether generation unless you set generation to wes.
Endpoint Risk and Security Events
wg_get_endpoint_company_risk_summary details
wg_get_endpoint_company_risk_summary details
wg_get_endpoint_risk_configuration details
wg_get_endpoint_risk_configuration details
[WatchGuard Cloud] Returns the current risk configuration: which risk factors are switched on and at what severity. Read this before changing it — the update replaces the whole list, so this response is the only record of what to put back.
wg_get_endpoint_risk_statistics details
wg_get_endpoint_risk_statistics details
wg_get_endpoint_security_event_counters details
wg_get_endpoint_security_event_counters details
[WatchGuard Cloud] Returns counts of detected security events by type. The type parameter is a MASK: add the codes of the event types you want, so 3 asks for types 1 and 2 together and 255 asks for all of them.
wg_get_endpoint_security_overview details
wg_get_endpoint_security_overview details
wg_list_endpoint_detected_risks details
wg_list_endpoint_detected_risks details
[WatchGuard Cloud] Returns a count of affected devices for each type of risk detected — which risks exist and how widespread each one is. Use wg_list_endpoint_device_risks to see which devices are behind a number.
wg_list_endpoint_device_risks details
wg_list_endpoint_device_risks details
[WatchGuard Cloud] Lists devices with the risks detected on each, by risk level — the device-level view behind the company risk summary. Capped by WatchGuard at 3,000 records, so narrow with filter or search.
wg_list_endpoint_security_events details
wg_list_endpoint_security_events details
[WatchGuard Cloud] Lists security events of one type over a period — malware, exploits, blocked programs and the rest, one code per type. The host name filter must be base-64 encoded, which is WatchGuard's own requirement rather than ours. Capped by WatchGuard at 3,000 records.
wg_update_endpoint_risk_configuration details
wg_update_endpoint_risk_configuration details
[WatchGuard Cloud] DESTRUCTIVE. REPLACES the whole risk-settings list for an account. A factor left out of the list you send is not preserved, and switching a factor off stops WatchGuard reporting that risk at all — the customer's posture looks better while nothing has changed on any device. Read wg_get_endpoint_risk_configuration first and send back the complete list with only your intended change. Acts on the Aether generation unless you set generation to wes.
Endpoint Tasks
wg_get_endpoint_task_details details
wg_get_endpoint_task_details details
[WatchGuard Cloud] Returns the definition of one endpoint task — what it was set up to do and against which devices. Get the task ID and type from wg_list_endpoint_tasks; the type is part of the address, so a right ID with the wrong type will not be found.
wg_get_endpoint_task_job_results details
wg_get_endpoint_task_job_results details
[WatchGuard Cloud] Returns what one repetition of an endpoint task actually found — the detections from a scan, the patches applied by an installation. Status says whether it ran; this says what it did.
wg_get_endpoint_task_job_status details
wg_get_endpoint_task_job_status details
[WatchGuard Cloud] Returns the per-device status of one repetition of an endpoint task — which devices the run reached, which are still pending and which failed. This is the read that answers whether a scan you started has finished.
wg_list_endpoint_task_jobs details
wg_list_endpoint_task_jobs details
[WatchGuard Cloud] Lists the repetitions of one endpoint task — a recurring task runs many times, and each run has its own job ID. Use a job ID from here with the status and results tools.
wg_list_endpoint_tasks details
wg_list_endpoint_tasks details
[WatchGuard Cloud] Lists the endpoint tasks created in an account — scans, disinfections, patch installations and IOC searches. Start here after running a scan: the task ID and type from this list are what every other task tool needs.
Accounts and Managed Accounts
wg_create_managed_account details
wg_create_managed_account details
[WatchGuard Cloud] DESTRUCTIVE. Creates a real managed account under yours — a new customer tenancy in WatchGuard Cloud, with commercial consequences. WatchGuard requires EVERY field: type, name, contact first and last name, email, phone, industry, and both the billing and mailing addresses in full. Confirm the details with whoever owns the relationship before calling this; there is no draft state.
wg_delete_managed_account details
wg_delete_managed_account details
[WatchGuard Cloud] DESTRUCTIVE. Deletes an entire managed account. This is the single most dangerous operation in the WatchGuard connector: it removes a customer's whole tenancy, and with force set true it removes every account beneath it as well. There is no undo. Confirm the account ID against wg_list_managed_accounts and confirm the intent with a human before calling this.
wg_get_account details
wg_get_account details
[WatchGuard Cloud] Returns one WatchGuard Cloud account's information. Called with no account ID it reads your own account, which is also how StackJack tests this connection. Use the fields parameter to ask for specific account fields rather than the whole record.
wg_list_managed_accounts details
wg_list_managed_accounts details
[WatchGuard Cloud] Lists the accounts you manage. START HERE when working across customers: every other WatchGuard tool takes an optional account ID, and this is the only place those IDs come from. Filter by name for a partial match, or by type to separate Service Provider accounts from subscribers.
wg_update_managed_account details
wg_update_managed_account details
[WatchGuard Cloud] DESTRUCTIVE. REPLACES a managed account's record. WatchGuard requires every field on this call, so anything you leave out is not preserved — a partial update wipes the contact details or an address rather than leaving them alone. Read the account with wg_get_account first and send the complete record back with only your intended change.
Firebox Reports
wg_get_firebox_executive_report details
wg_get_firebox_executive_report details
[WatchGuard Cloud] Returns one view of the Firebox Executive Dashboard — the traffic-side report a customer sees in a quarterly review: top applications, top destinations, top clients and so on. One view per call, so ask for the views you need in turn. Leave devices empty to cover every Firebox in the account.
wg_get_firebox_security_report details
wg_get_firebox_security_report details
[WatchGuard Cloud] Returns one view of the Firebox Security Dashboard — what the firewall BLOCKED over the period: blocked countries, botnet sites, malware, attacks and the rest. This is the report that shows a customer what their firewall stopped. One view per call.
NDR Assets
wg_create_ndr_asset details
wg_create_ndr_asset details
[WatchGuard Cloud] Records a new asset in WatchGuard NDR — typically something NDR has not discovered by itself, such as a device on a segment it cannot see. Purely additive: it creates a record and changes nothing that exists, so it is not marked destructive. WatchGuard accepts only IP_V4 addresses on create.
wg_delete_ndr_asset details
wg_delete_ndr_asset details
[WatchGuard Cloud] DESTRUCTIVE. Permanently removes an asset from WatchGuard NDR, with its history and its link to past Smart Alerts. NDR may rediscover the device later, but it comes back as a new asset with none of the context — the importance, roles and tags someone set are gone. There is no undo.
wg_get_ndr_asset details
wg_get_ndr_asset details
[WatchGuard Cloud] Returns one WatchGuard NDR asset in full — its addresses, roles, importance, threat score and when it was first and last seen. Get asset IDs from wg_list_ndr_assets. Read this before updating an asset: the update replaces the record.
wg_list_ndr_assets details
wg_list_ndr_assets details
[WatchGuard Cloud] Lists the assets WatchGuard NDR knows about on the customer's network — what it has seen, what it believes each thing is, and each asset's threat score. Filter by naming both field and value together; sorting by threatScore descending is the fastest route to what deserves attention.
wg_update_ndr_asset details
wg_update_ndr_asset details
[WatchGuard Cloud] DESTRUCTIVE. REPLACES a WatchGuard NDR asset record. WatchGuard requires the name, addresses, device type and importance on every call, so anything you leave out — the description, the roles, the tags — is cleared rather than kept. Read the asset with wg_get_ndr_asset first and send the complete record back with only your intended change.
NDR Smart Alerts
wg_close_ndr_smart_alert details
wg_close_ndr_smart_alert details
[WatchGuard Cloud] Closes a WatchGuard NDR Smart Alert with a documented reason. This is triage: the alert is resolved, nothing is deleted, and it is not marked destructive. BUT two of its options change what NDR does in future — allowInFuture authorizes the activity so similar traffic stops raising alerts, and includeSimilar closes other matching alerts in the same call. Leave both unset unless you mean them, because a mistaken authorization quietly suppresses a real detection later.
wg_get_ndr_smart_alert details
wg_get_ndr_smart_alert details
[WatchGuard Cloud] Returns one WatchGuard NDR Smart Alert in full — the network detection, what it was raised on and why. Smart Alert IDs appear on the assets they concern and in ThreatSync incidents that correlate them.
Platform
wg_check_service_health details
wg_check_service_health details
[WatchGuard Cloud] Returns the health probe of one WatchGuard Cloud API. All sixteen WatchGuard APIs publish the same probe and this one tool reaches every one of them through the service selector. It proves the SERVICE is up; it does NOT prove your credential works — a revoked API key still gets a healthy answer here, so use Test Connection in StackJack, or any ordinary read, to check the credential.
Firebox Deployments
wg_delete_firebox_deployment_transaction details
wg_delete_firebox_deployment_transaction details
[WatchGuard Cloud] DESTRUCTIVE. Deletes one deployment transaction record, selected by its transaction id. There is no undo: WatchGuard removes the record outright and answers with the deleted object. This is NOT a cancel button - the specification publishes no cancel verb and does not say whether a scheduled push still runs once its record is gone - so move an unwanted deployment with wg_update_firebox_deployment_transaction instead of deleting its record. Confirm the record with wg_get_firebox_deployment_transaction before deleting it: a transaction whose status is complete or failed is a finished deployment, and this removes that deployment's record from the transaction list. The id comes from wg_list_firebox_deployment_transactions, or from the transaction objects wg_deploy_firebox_configuration answers with.
wg_deploy_firebox_configuration details
wg_deploy_firebox_configuration details
[WatchGuard Cloud] DESTRUCTIVE. Deploys the global exceptions saved in WatchGuard Cloud onto the Fireboxes you name, or the full configuration when full_config is true. This is the one Firebox Management call that leaves WatchGuard Cloud: every other configuration write in this connector is saved as pending until this runs, and what it pushes takes effect on live traffic. Name the devices explicitly instead of the whole estate. full_config decides WHAT is pushed and WatchGuard defaults it to false, which deploys global exceptions only, so a policy, network, alias, schedule or certificate change needs full_config set to true or this call succeeds and ships nothing. start_date takes the literal value now to deploy immediately or a UTC timestamp to queue it, and a queued push can be moved afterwards with wg_update_firebox_deployment_transaction. devices holds at most 50 Fireboxes, so a larger estate is more than one call, and WatchGuard creates one transaction PER DEVICE. The two success shapes differ: 201 answers a bare array of transaction objects, while 200 answers an object carrying ok, the transactions it created, and errors, a map of device id to the reason that device was SKIPPED - the vendor's own example reason is global exceptions not enabled for the device, which wg_enable_firebox_global_exceptions fixes - so read errors before reporting success. Reach for wg_list_firebox_deployment_transactions first to see what is already queued, and read each transaction back with wg_get_firebox_deployment_transaction rather than treating this answer as a finished deployment. The body is a JSON object whose fields are description, devices, full_config, start_date, version; required: devices, start_date.
wg_disable_firebox_global_exceptions details
wg_disable_firebox_global_exceptions details
[WatchGuard Cloud] DESTRUCTIVE. Disables management and deployment of global exceptions through the Firebox Management API for the Fireboxes you name, and deletes the exceptions already on them unless retain_device_configuration is true. WatchGuard defaults retain_device_configuration to false, so leaving it out DELETES the exceptions currently on every Firebox you name; send it as true to keep them, because enabling global exceptions again later does not restore what this removed. WatchGuard answers 204 No Content here, so this tool returns a short success acknowledgement rather than a transaction and there is nothing to read back. wg_enable_firebox_global_exceptions is the other half of the same switch, and it takes no retain flag. devices holds at most 50 Fireboxes. The body is a JSON object whose fields are devices, retain_device_configuration; required: devices.
wg_enable_firebox_global_exceptions details
wg_enable_firebox_global_exceptions details
[WatchGuard Cloud] DESTRUCTIVE. Enables management and deployment of global exceptions through the Firebox Management API for the Fireboxes you name. This is the switch that lets exception changes made through this API reach those Fireboxes at the next deployment, and its other half, wg_disable_firebox_global_exceptions, can delete the exceptions already on a device. It is the prerequisite of wg_deploy_firebox_configuration: a deployment does not fail for a Firebox that has global exceptions disabled, it SKIPS that device and names it in the response's errors map. WatchGuard answers 204 No Content here, so this tool returns a short success acknowledgement rather than a transaction and there is nothing to read back. devices holds at most 50 Fireboxes. The body is a JSON object whose fields are devices; required: devices.
wg_get_firebox_deployment_transaction details
wg_get_firebox_deployment_transaction details
[WatchGuard Cloud] Reads one deployment transaction record by its id, the status of a single configuration push to a single Firebox. This is the read-back for every write in this family: wg_deploy_firebox_configuration answers the transaction objects it created, and this tool re-reads one of them by id until its status settles. WatchGuard answers an ARRAY here even for a single record. status is one of scheduled, imaged, pending, in_progress, complete or failed, so a transaction that has not reached complete is not a deployed configuration, and original_author_username is always empty for transactions the Firebox Management API created. The id comes from wg_list_firebox_deployment_transactions, or from the transaction objects wg_deploy_firebox_configuration answers with.
wg_list_firebox_deployment_transactions details
wg_list_firebox_deployment_transactions details
[WatchGuard Cloud] Lists the deployment transaction records for the account, one record per Firebox per configuration push, each with its status. Reach for this first in this family: it shows what is already queued or running before another push is added with wg_deploy_firebox_configuration. Each record carries id, device, account, inception_time, start_date and status, where status is one of scheduled, imaged, pending, in_progress, complete or failed, so a transaction that has not reached complete is not a deployed configuration. original_author_username is always empty for transactions the Firebox Management API created, so a blank operator is expected rather than missing data. The id returned here is what wg_get_firebox_deployment_transaction, wg_update_firebox_deployment_transaction and wg_delete_firebox_deployment_transaction take. WatchGuard declares no paging on this route - no page size, no offset and no cursor - so one call returns the WHOLE collection for the account; on a large estate expect a large result, and narrow it with device.
wg_update_firebox_deployment_transaction details
wg_update_firebox_deployment_transaction details
[WatchGuard Cloud] DESTRUCTIVE. Reschedules one deployment transaction, selected by its transaction id, by replacing its start date. start_date is required, so one call replaces the schedule of a pending deployment: the literal value now brings a queued configuration push FORWARD onto live Fireboxes immediately. WatchGuard documents this as a replace, so send description back alongside it to keep it - the transaction object in the answer carries no description field to read a lost one back from. Read the record first with wg_get_firebox_deployment_transaction: a transaction whose status has already left scheduled is a push that has started or finished. WatchGuard answers with the updated transaction record, as an ARRAY, and publishes no separate cancel verb for a queued deployment. The id comes from wg_list_firebox_deployment_transactions, or from the transaction objects wg_deploy_firebox_configuration answers with. The body is a JSON object whose fields are description, start_date; required: start_date.
Firebox Authentication
wg_get_firebox_auth_group details
wg_get_firebox_auth_group details
[WatchGuard Cloud] Reads one Firebox authentication group, the umbrella group a firewall policy matches users against, by object id. Answers the typed domains array (firebox_domain, authentication_domain, authpoint_domain or saml_settings) and the typed members array (firebox_user, firebox_group, shared_user_group, authpoint_user_group or saml_user_group), which together resolve a policy's user match. Object ids come from wg_list_firebox_auth_groups.
wg_get_firebox_authpoint_user_group details
wg_get_firebox_authpoint_user_group details
[WatchGuard Cloud] Reads one AuthPoint user or group reference held in Firebox configuration, by object id. Answers the pointer WatchGuard stores, which is name, type (user or group) and the AuthPoint domain reference, not the AuthPoint object itself. Object ids come from wg_list_firebox_authpoint_user_groups.
wg_get_firebox_saml_user_group details
wg_get_firebox_saml_user_group details
[WatchGuard Cloud] Reads one SAML user or group reference held in Firebox configuration, by object id. Answers name, which the vendor constrains to an email address or a user name, type (user or group), the SAML domain reference and movpn_enforcement. Object ids come from wg_list_firebox_saml_user_groups.
wg_get_firebox_user details
wg_get_firebox_user details
[WatchGuard Cloud] Reads one Firebox local user account by object id. THE RESPONSE IS CREDENTIAL MATERIAL: password is a required member of WatchGuard's firebox_user schema, so this body carries the user's Firebox password in the clear. Treat it as a secret and never paste it into a ticket, a chat or a document. The body also carries name, description, the session and idle timeouts in seconds, the authentication domain and the groups the user belongs to. Object ids come from wg_list_firebox_users.
wg_get_firebox_user_group details
wg_get_firebox_user_group details
[WatchGuard Cloud] Reads one Firebox local user group by object id. Answers name, description, the optional authentication domain and the members array of references to Firebox users. Object ids come from wg_list_firebox_user_groups; wg_get_firebox_auth_group reads the umbrella authentication group kind instead.
wg_list_firebox_auth_groups details
wg_list_firebox_auth_groups details
[WatchGuard Cloud] Lists the Firebox authentication groups, the umbrella groups a firewall policy matches users against, for the account, or for one Firebox or one template. An auth group is the one kind that spans identity sources: its domains array names firebox_domain, authentication_domain, authpoint_domain or saml_settings entries, and its members array is typed firebox_user, firebox_group, shared_user_group, authpoint_user_group or saml_user_group. That is where a policy's user match is actually resolved, so reach here first when tracing which users a policy applies to; the four other lists in this group read the individual member kinds. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result.
wg_list_firebox_authpoint_user_groups details
wg_list_firebox_authpoint_user_groups details
[WatchGuard Cloud] Lists the AuthPoint users and groups this Firebox configuration references, for the account, or for one Firebox or one template. Each entry is a POINTER into an AuthPoint domain rather than the AuthPoint object itself: name, type (user or group) and the domain reference. It says which AuthPoint identities this Firebox configuration can match, not what AuthPoint holds. The policy side is wg_list_firebox_auth_groups, and wg_list_firebox_saml_user_groups is the same shape for a SAML identity provider. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result.
wg_list_firebox_saml_user_groups details
wg_list_firebox_saml_user_groups details
[WatchGuard Cloud] Lists the SAML users and groups this Firebox configuration references, for the account, or for one Firebox or one template. Each entry is a POINTER into a SAML identity provider: name, which the vendor constrains to an email address or a user name, type (user or group), the domain reference, and movpn_enforcement, the one member the AuthPoint equivalent does not carry. Use wg_list_firebox_authpoint_user_groups for the AuthPoint side and wg_list_firebox_auth_groups for the groups a policy matches on. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result.
wg_list_firebox_user_groups details
wg_list_firebox_user_groups details
[WatchGuard Cloud] Lists the Firebox local user groups, whose members are Firebox users, for the account, or for one Firebox or one template. Each group carries name, description, an optional authentication domain and a members array of references to Firebox users, which wg_list_firebox_users reads. This is the LOCAL group kind: wg_list_firebox_auth_groups reads the umbrella authentication groups a firewall policy matches users against, and the AuthPoint and SAML lists read pointers into those identity providers. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result.
wg_list_firebox_users details
wg_list_firebox_users details
[WatchGuard Cloud] Lists the Firebox local user accounts for the account, or for one Firebox or one template. THE RESPONSE IS CREDENTIAL MATERIAL: password is a required member of WatchGuard's firebox_user schema, so every object in this list carries that user's Firebox password in the clear. Treat the result as a secret and never paste it into a ticket, a chat or a document. Reach here first for who can authenticate to a Firebox; wg_get_firebox_user reads one account back by id and wg_list_firebox_user_groups shows their group membership. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result.
Firebox Exceptions
wg_create_firebox_blocked_site_exception details
wg_create_firebox_blocked_site_exception details
[WatchGuard Cloud] DESTRUCTIVE. Creates a new blocked sites exception. The value of the action parameter specifies whether the Firebox allows or blocks traffic for the site. The action field decides whether the Firebox ALLOWS or BLOCKS the site - allow puts the address on the Blocked Sites Exception list, block puts it on the Blocked Sites list - and it DEFAULTS TO allow when omitted, so a create that names no action opens traffic an administrator may have meant to stop. It is saved in WatchGuard Cloud only: no Firebox enforces it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. That deployment answers global_exceptions not enabled for device for any Firebox that wg_enable_firebox_global_exceptions has not enabled first. The response carries the new exception's id and version. The body is a JSON object whose fields are action, address, description, device; required: address.
wg_create_firebox_botnet_site_exception details
wg_create_firebox_botnet_site_exception details
[WatchGuard Cloud] Creates a new botnet site exception. It is saved in WatchGuard Cloud only: no Firebox enforces it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. That deployment answers global_exceptions not enabled for device for any Firebox that wg_enable_firebox_global_exceptions has not enabled first. The response carries the new exception's id and version. The body is a JSON object whose fields are address, description, device; required: address.
wg_create_firebox_file_exception details
wg_create_firebox_file_exception details
[WatchGuard Cloud] Creates a new file exception. It is saved in WatchGuard Cloud only: no Firebox enforces it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. That deployment answers global_exceptions not enabled for device for any Firebox that wg_enable_firebox_global_exceptions has not enabled first. The response carries the new exception's id and version. The body is a JSON object whose fields are action, description, device, md5; required: action, md5.
wg_create_firebox_geolocation_exception details
wg_create_firebox_geolocation_exception details
[WatchGuard Cloud] Creates a new Geolocation exception. It is saved in WatchGuard Cloud only: no Firebox enforces it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. That deployment answers global_exceptions not enabled for device for any Firebox that wg_enable_firebox_global_exceptions has not enabled first. The response carries the new exception's id and version. The body is a JSON object whose fields are address, description, device; required: address.
wg_create_firebox_ips_signature_exception details
wg_create_firebox_ips_signature_exception details
[WatchGuard Cloud] Creates a new IPS signature exception. It is saved in WatchGuard Cloud only: no Firebox enforces it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. That deployment answers global_exceptions not enabled for device for any Firebox that wg_enable_firebox_global_exceptions has not enabled first. The response carries the new exception's id and version. The body is a JSON object whose fields are action, alarm, description, device, signature_id; required: action, signature_id.
wg_create_firebox_webblocker_exception details
wg_create_firebox_webblocker_exception details
[WatchGuard Cloud] DESTRUCTIVE. Creates a new WebBlocker exception. The action field decides whether the exception allows or denies every URL its rule matches, so a wrong value either opens web traffic the customer's policy refuses or blocks a site the customer needs. It is saved in WatchGuard Cloud only: no Firebox enforces it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. That deployment answers global_exceptions not enabled for device for any Firebox that wg_enable_firebox_global_exceptions has not enabled first. The response carries the new exception's id and version. The body is a JSON object whose fields are action, alarm, device, name, rule, rule_type; required: action, name, rule, rule_type.
wg_delete_firebox_blocked_site_exception details
wg_delete_firebox_blocked_site_exception details
[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified blocked sites exception. There is no undo: WatchGuard publishes no restore for a deleted exception and recreating it with wg_create_firebox_blocked_site_exception mints a new id, so confirm the id with wg_get_firebox_blocked_site_exception before you call this. WatchGuard answers with the deleted exception, marked inactive. The removal is saved in WatchGuard Cloud only: no Firebox stops enforcing the exception until wg_deploy_firebox_configuration pushes the account's exceptions to the devices.
wg_delete_firebox_botnet_site_exception details
wg_delete_firebox_botnet_site_exception details
[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified botnet site exception. There is no undo: WatchGuard publishes no restore for a deleted exception and recreating it with wg_create_firebox_botnet_site_exception mints a new id, so confirm the id with wg_get_firebox_botnet_site_exception before you call this. WatchGuard answers with the deleted exception, marked inactive. The removal is saved in WatchGuard Cloud only: no Firebox stops enforcing the exception until wg_deploy_firebox_configuration pushes the account's exceptions to the devices.
wg_delete_firebox_file_exception details
wg_delete_firebox_file_exception details
[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified file exception. There is no undo: WatchGuard publishes no restore for a deleted exception and recreating it with wg_create_firebox_file_exception mints a new id, so confirm the id with wg_get_firebox_file_exception before you call this. WatchGuard answers with the deleted exception, marked inactive. The removal is saved in WatchGuard Cloud only: no Firebox stops enforcing the exception until wg_deploy_firebox_configuration pushes the account's exceptions to the devices.
wg_delete_firebox_geolocation_exception details
wg_delete_firebox_geolocation_exception details
[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified Geolocation exception. There is no undo: WatchGuard publishes no restore for a deleted exception and recreating it with wg_create_firebox_geolocation_exception mints a new id, so confirm the id with wg_get_firebox_geolocation_exception before you call this. WatchGuard answers with the deleted exception, marked inactive. The removal is saved in WatchGuard Cloud only: no Firebox stops enforcing the exception until wg_deploy_firebox_configuration pushes the account's exceptions to the devices.
wg_delete_firebox_ips_signature_exception details
wg_delete_firebox_ips_signature_exception details
[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified IPS signature exception. There is no undo: WatchGuard publishes no restore for a deleted exception and recreating it with wg_create_firebox_ips_signature_exception mints a new id, so confirm the id with wg_get_firebox_ips_signature_exception before you call this. WatchGuard answers with the deleted exception, marked inactive. The removal is saved in WatchGuard Cloud only: no Firebox stops enforcing the exception until wg_deploy_firebox_configuration pushes the account's exceptions to the devices.
wg_delete_firebox_webblocker_exception details
wg_delete_firebox_webblocker_exception details
[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified WebBlocker exception. There is no undo: WatchGuard publishes no restore for a deleted exception and recreating it with wg_create_firebox_webblocker_exception mints a new id, so confirm the id with wg_get_firebox_webblocker_exception before you call this. WatchGuard answers with the deleted exception, marked inactive. The removal is saved in WatchGuard Cloud only: no Firebox stops enforcing the exception until wg_deploy_firebox_configuration pushes the account's exceptions to the devices.
wg_get_firebox_blocked_site_exception details
wg_get_firebox_blocked_site_exception details
[WatchGuard Cloud] Retrieves the specified blocked sites exception. The id comes from wg_list_firebox_blocked_site_exceptions and looks like bse_12345_ARBHLJ70Y78rGOIGBS. The response carries the version that wg_update_firebox_blocked_site_exception requires, so read the exception before you replace it.
wg_get_firebox_botnet_site_exception details
wg_get_firebox_botnet_site_exception details
[WatchGuard Cloud] Retrieves the specified botnet site exception. The id comes from wg_list_firebox_botnet_site_exceptions and looks like bote_CjBY92ourN7Izaa1jJu3eH5. The response carries the version that wg_update_firebox_botnet_site_exception requires, so read the exception before you replace it.
wg_get_firebox_file_exception details
wg_get_firebox_file_exception details
[WatchGuard Cloud] Retrieves the specified file exception. The id comes from wg_list_firebox_file_exceptions and looks like file_12345_UqhDVIdx8D5iwivAX. The response carries the version that wg_update_firebox_file_exception requires, so read the exception before you replace it.
wg_get_firebox_geolocation_exception details
wg_get_firebox_geolocation_exception details
[WatchGuard Cloud] Retrieves the specified Geolocation exception. The id comes from wg_list_firebox_geolocation_exceptions and looks like geoe_12345_aHbWC5IuWO3qzyV2t. The response carries the version that wg_update_firebox_geolocation_exception requires, so read the exception before you replace it.
wg_get_firebox_ips_signature_exception details
wg_get_firebox_ips_signature_exception details
[WatchGuard Cloud] Retrieves the specified IPS signature exception. The id comes from wg_list_firebox_ips_signature_exceptions and looks like ipse_12345_eY5Jwxv1nE3Xlk3zx. The response carries the version that wg_update_firebox_ips_signature_exception requires, so read the exception before you replace it.
wg_get_firebox_webblocker_exception details
wg_get_firebox_webblocker_exception details
[WatchGuard Cloud] Retrieves the specified WebBlocker exception. The id comes from wg_list_firebox_webblocker_exceptions and looks like wbe_12124_7HM70EvrifZ7rSfXSA. The response carries the version that wg_update_firebox_webblocker_exception requires, so read the exception before you replace it.
wg_list_firebox_blocked_site_exceptions details
wg_list_firebox_blocked_site_exceptions details
[WatchGuard Cloud] Lists the blocked sites exceptions saved in the WatchGuard Cloud account. This is the blocked sites kind only; wg_list_firebox_exceptions returns all six kinds in one call. The response is an object with count, more, objects and start_after, so when more is true call again with start_after set to the value the response returned. Each object carries the id that wg_get_firebox_blocked_site_exception, wg_update_firebox_blocked_site_exception and wg_delete_firebox_blocked_site_exception take, and the version that an update has to send back.
wg_list_firebox_blocked_site_exceptions_v1 details
wg_list_firebox_blocked_site_exceptions_v1 details
[WatchGuard Cloud] DEPRECATED by WatchGuard: use wg_list_firebox_blocked_site_exceptions instead, which reads the same saved blocked sites exceptions. This v1 route declares no paging at all, so one call returns the WHOLE collection for the account and on a large estate that is a large result. It also answers a bare JSON array where the v2 read answers an object with count, more, objects and start_after.
wg_list_firebox_botnet_site_exceptions details
wg_list_firebox_botnet_site_exceptions details
[WatchGuard Cloud] Lists the botnet site exceptions saved in the WatchGuard Cloud account. This is the botnet site kind only; wg_list_firebox_exceptions returns all six kinds in one call. The response is an object with count, more, objects and start_after, so when more is true call again with start_after set to the value the response returned. Each object carries the id that wg_get_firebox_botnet_site_exception, wg_update_firebox_botnet_site_exception and wg_delete_firebox_botnet_site_exception take, and the version that an update has to send back.
wg_list_firebox_botnet_site_exceptions_v1 details
wg_list_firebox_botnet_site_exceptions_v1 details
[WatchGuard Cloud] DEPRECATED by WatchGuard: use wg_list_firebox_botnet_site_exceptions instead, which reads the same saved botnet site exceptions. This v1 route declares no paging at all, so one call returns the WHOLE collection for the account and on a large estate that is a large result. It also answers a bare JSON array where the v2 read answers an object with count, more, objects and start_after.
wg_list_firebox_exceptions details
wg_list_firebox_exceptions details
[WatchGuard Cloud] Lists every exception saved in the WatchGuard Cloud account in one response - blocked sites, botnet sites, files, Geolocation, IPS signatures and WebBlocker together. Start here rather than with the six per-kind lists, and narrow the result with query. The response is an object with count, more, objects and start_after, so when more is true call again with start_after set to the value the response returned. Each object carries the id that the get, update and delete tools take and the version that an update has to send back. These are saved objects: a Firebox enforces them only after wg_deploy_firebox_configuration pushes them.
wg_list_firebox_exceptions_v1 details
wg_list_firebox_exceptions_v1 details
[WatchGuard Cloud] DEPRECATED by WatchGuard: use wg_list_firebox_exceptions instead, which reads the same saved exceptions of all six kinds. This v1 route declares no paging at all, so one call returns the WHOLE collection for the account and on a large estate that is a large result. It also answers a bare JSON array where the v2 read answers an object with count, more, objects and start_after.
wg_list_firebox_file_exceptions details
wg_list_firebox_file_exceptions details
[WatchGuard Cloud] Lists the file exceptions saved in the WatchGuard Cloud account. This is the file kind only; wg_list_firebox_exceptions returns all six kinds in one call. The response is an object with count, more, objects and start_after, so when more is true call again with start_after set to the value the response returned. Each object carries the id that wg_get_firebox_file_exception, wg_update_firebox_file_exception and wg_delete_firebox_file_exception take, and the version that an update has to send back.
wg_list_firebox_file_exceptions_v1 details
wg_list_firebox_file_exceptions_v1 details
[WatchGuard Cloud] DEPRECATED by WatchGuard: use wg_list_firebox_file_exceptions instead, which reads the same saved file exceptions. This v1 route declares no paging at all, so one call returns the WHOLE collection for the account and on a large estate that is a large result. It also answers a bare JSON array where the v2 read answers an object with count, more, objects and start_after.
wg_list_firebox_geolocation_exceptions details
wg_list_firebox_geolocation_exceptions details
[WatchGuard Cloud] Lists the Geolocation exceptions saved in the WatchGuard Cloud account. This is the Geolocation kind only; wg_list_firebox_exceptions returns all six kinds in one call. The response is an object with count, more, objects and start_after, so when more is true call again with start_after set to the value the response returned. Each object carries the id that wg_get_firebox_geolocation_exception, wg_update_firebox_geolocation_exception and wg_delete_firebox_geolocation_exception take, and the version that an update has to send back.
wg_list_firebox_geolocation_exceptions_v1 details
wg_list_firebox_geolocation_exceptions_v1 details
[WatchGuard Cloud] DEPRECATED by WatchGuard: use wg_list_firebox_geolocation_exceptions instead, which reads the same saved Geolocation exceptions. This v1 route declares no paging at all, so one call returns the WHOLE collection for the account and on a large estate that is a large result. It also answers a bare JSON array where the v2 read answers an object with count, more, objects and start_after.
wg_list_firebox_ips_signature_exceptions details
wg_list_firebox_ips_signature_exceptions details
[WatchGuard Cloud] Lists the IPS signature exceptions saved in the WatchGuard Cloud account. This is the IPS signature kind only; wg_list_firebox_exceptions returns all six kinds in one call. The response is an object with count, more, objects and start_after, so when more is true call again with start_after set to the value the response returned. Each object carries the id that wg_get_firebox_ips_signature_exception, wg_update_firebox_ips_signature_exception and wg_delete_firebox_ips_signature_exception take, and the version that an update has to send back.
wg_list_firebox_ips_signature_exceptions_v1 details
wg_list_firebox_ips_signature_exceptions_v1 details
[WatchGuard Cloud] DEPRECATED by WatchGuard: use wg_list_firebox_ips_signature_exceptions instead, which reads the same saved IPS signature exceptions. This v1 route declares no paging at all, so one call returns the WHOLE collection for the account and on a large estate that is a large result. It also answers a bare JSON array where the v2 read answers an object with count, more, objects and start_after.
wg_list_firebox_webblocker_exceptions details
wg_list_firebox_webblocker_exceptions details
[WatchGuard Cloud] Lists the WebBlocker exceptions saved in the WatchGuard Cloud account. This is the WebBlocker kind only; wg_list_firebox_exceptions returns all six kinds in one call. The response is an object with count, more, objects and start_after, so when more is true call again with start_after set to the value the response returned. Each object carries the id that wg_get_firebox_webblocker_exception, wg_update_firebox_webblocker_exception and wg_delete_firebox_webblocker_exception take, and the version that an update has to send back.
wg_list_firebox_webblocker_exceptions_v1 details
wg_list_firebox_webblocker_exceptions_v1 details
[WatchGuard Cloud] DEPRECATED by WatchGuard: use wg_list_firebox_webblocker_exceptions instead, which reads the same saved WebBlocker exceptions. This v1 route declares no paging at all, so one call returns the WHOLE collection for the account and on a large estate that is a large result. It also answers a bare JSON array where the v2 read answers an object with count, more, objects and start_after.
wg_update_firebox_blocked_site_exception details
wg_update_firebox_blocked_site_exception details
[WatchGuard Cloud] DESTRUCTIVE. Updates the specified blocked sites exception. This replaces the exception wholesale - every field you leave out is cleared, and an omitted action falls back to the schema default allow, which moves the address onto the Blocked Sites Exception list and lets the traffic through. Read the current object with wg_get_firebox_blocked_site_exception and send it back complete. version is required and must be the version the exception carries now; a stale version comes back as a conflict. The change is saved in WatchGuard Cloud only: no Firebox sees it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. The body is a JSON object whose fields are action, address, description, version; required: address, version.
wg_update_firebox_botnet_site_exception details
wg_update_firebox_botnet_site_exception details
[WatchGuard Cloud] DESTRUCTIVE. Updates the specified botnet site exception. This replaces the exception wholesale - every field you leave out is cleared rather than kept, so an omitted description is erased and a changed address re-points the exception at a different site. Read the current object with wg_get_firebox_botnet_site_exception and send it back complete. version is required and must be the version the exception carries now; a stale version comes back as a conflict. The change is saved in WatchGuard Cloud only: no Firebox sees it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. The body is a JSON object whose fields are address, description, version; required: address, version.
wg_update_firebox_file_exception details
wg_update_firebox_file_exception details
[WatchGuard Cloud] DESTRUCTIVE. Updates the specified file exception. This replaces the exception wholesale - every field you leave out is cleared, and action decides whether the Firebox allows the file or drops it, so a wrong value here delivers a file the customer meant to stop. Read the current object with wg_get_firebox_file_exception and send it back complete. version is required and must be the version the exception carries now; a stale version comes back as a conflict. The change is saved in WatchGuard Cloud only: no Firebox sees it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. The body is a JSON object whose fields are action, description, md5, version; required: action, md5, version.
wg_update_firebox_geolocation_exception details
wg_update_firebox_geolocation_exception details
[WatchGuard Cloud] DESTRUCTIVE. Updates the specified Geolocation exception. This replaces the exception wholesale - every field you leave out is cleared rather than kept, and the address is the whole exception, so a changed value exempts a different site from the Geolocation block. Read the current object with wg_get_firebox_geolocation_exception and send it back complete. version is required and must be the version the exception carries now; a stale version comes back as a conflict. The change is saved in WatchGuard Cloud only: no Firebox sees it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. The body is a JSON object whose fields are address, description, version; required: address, version.
wg_update_firebox_ips_signature_exception details
wg_update_firebox_ips_signature_exception details
[WatchGuard Cloud] DESTRUCTIVE. Updates the specified IPS signature exception. This replaces the exception wholesale - every field you leave out is cleared, an omitted alarm falls back to false so the Firebox stops alarming on the signature, and action decides whether the signature is allowed, blocked or dropped. Read the current object with wg_get_firebox_ips_signature_exception and send it back complete. version is required and must be the version the exception carries now; a stale version comes back as a conflict. The change is saved in WatchGuard Cloud only: no Firebox sees it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. The body is a JSON object whose fields are action, alarm, description, signature_id, version; required: action, signature_id, version.
wg_update_firebox_webblocker_exception details
wg_update_firebox_webblocker_exception details
[WatchGuard Cloud] DESTRUCTIVE. Updates the specified WebBlocker exception. This replaces the exception wholesale - every field you leave out is cleared, and action decides whether the matching URLs are allowed or denied, so a wrong value either opens web traffic the customer's policy refuses or blocks a site the customer needs. Read the current object with wg_get_firebox_webblocker_exception and send it back complete. version is required and must be the version the exception carries now; a stale version comes back as a conflict. The change is saved in WatchGuard Cloud only: no Firebox sees it until wg_deploy_firebox_configuration pushes the account's exceptions to the devices. The body is a JSON object whose fields are action, alarm, name, rule, rule_type, version; required: action, name, rule, rule_type, version.
Firebox Networking
wg_create_firebox_bovpn_p1_shared_settings details
wg_create_firebox_bovpn_p1_shared_settings details
wg_create_firebox_bovpn_tunnel details
wg_create_firebox_bovpn_tunnel details
[WatchGuard Cloud] DESTRUCTIVE. Creates a branch office VPN (BOVPN) IPSec tunnel in the account. The body carries psk, the tunnel pre-shared key, in clear text, so this stores credential material, and WatchGuard echoes the key back in the response. At least one endpoint must be a cloud-managed Firebox, named in endpoint_a; both route-based and policy-based tunnels are supported. The change is saved in WatchGuard Cloud and reaches no Firebox until wg_deploy_firebox_configuration pushes it. The body is a JSON object whose fields are address_family, auth_method, certs, disabled, endpoint_a, endpoint_b, endpoint_b_name, interfaces, ipsec_tunnel_core, local_remote_pairs, name, psk, psk_encrypted, routes and 3 more; required: endpoint_a, interfaces, name, routes.
wg_delete_firebox_bovpn_tunnel details
wg_delete_firebox_bovpn_tunnel details
[WatchGuard Cloud] DESTRUCTIVE. Deletes one branch office VPN IPSec tunnel, selected by its object id in the path. There is no undo: WatchGuard removes the tunnel outright and the branch office connection it carries drops once the change is deployed, so confirm the object id first. WatchGuard answers with the deleted tunnel, pre-shared key included. The object id comes from wg_list_firebox_bovpn_tunnels. The sibling wg_delete_firebox_bovpn_tunnel_by_name deletes by name instead. The change is saved in WatchGuard Cloud and reaches no Firebox until wg_deploy_firebox_configuration pushes it.
wg_delete_firebox_bovpn_tunnel_by_name details
wg_delete_firebox_bovpn_tunnel_by_name details
[WatchGuard Cloud] DESTRUCTIVE. Deletes one branch office VPN IPSec tunnel, selected by the tunnel name. This selects the tunnel by NAME rather than by object id, so a wrong name deletes a different tunnel rather than failing, and there is no undo: the branch office connection that tunnel carries drops once the change is deployed. WatchGuard answers with the deleted tunnel, pre-shared key included. Prefer wg_delete_firebox_bovpn_tunnel, which takes the tunnel's object id in the path. The change is saved in WatchGuard Cloud and reaches no Firebox until wg_deploy_firebox_configuration pushes it.
wg_get_firebox_bovpn_p1_shared_settings details
wg_get_firebox_bovpn_p1_shared_settings details
wg_get_firebox_bovpn_tunnel details
wg_get_firebox_bovpn_tunnel details
[WatchGuard Cloud] Retrieves one branch office VPN IPSec tunnel, selected by its object id in the path. Read this before any wholesale update: the object's version field is what wg_update_firebox_bovpn_tunnel must send back, and the fields you do not send to that tool are cleared. The response carries psk, the tunnel's pre-shared key, in clear text.
wg_get_firebox_network details
wg_get_firebox_network details
[WatchGuard Cloud] Retrieves one network configuration object of a Firebox, selected by its object id. The object id comes from the id field of wg_list_firebox_networks. The response carries credentials in clear text: pppoe_client.password, dynamic_dns.password and each wireless interface's passphrase.
wg_get_firebox_sdwan details
wg_get_firebox_sdwan details
[WatchGuard Cloud] Retrieves one SD-WAN configuration object of a Firebox, selected by its object id. The object id comes from the id field of wg_list_firebox_sdwans.
wg_list_firebox_bovpn_tunnels details
wg_list_firebox_bovpn_tunnels details
[WatchGuard Cloud] Lists the branch office VPN (BOVPN) IPSec tunnels of the account, or of one Firebox. This is the reach-first read for every other BOVPN tool: it is where a tunnel's id, its name and its version number come from. The response carries each tunnel's psk, the pre-shared key, in clear text. WatchGuard declares no paging on this route, so one call returns the whole collection; filter with device to keep the result small.
wg_list_firebox_networks details
wg_list_firebox_networks details
[WatchGuard Cloud] Lists the network configuration objects of the account, or of one Firebox or one account-level template. Start here for interface, VLAN, bridge, PPPoE, dynamic DNS and wireless settings, then read a single object with wg_get_firebox_network. The response carries credentials in clear text: pppoe_client.password, dynamic_dns.password and each wireless interface's passphrase. WatchGuard declares no paging on this route, so one call returns the whole collection; filter with device or templateid to keep the result small.
wg_list_firebox_sdwans details
wg_list_firebox_sdwans details
[WatchGuard Cloud] Lists the SD-WAN configuration objects of the account, or of one Firebox or one account-level template. This is the reach-first read for SD-WAN actions and their link-monitoring settings; read a single object with wg_get_firebox_sdwan. WatchGuard declares no paging on this route, so one call returns the whole collection; filter with device or templateid to keep the result small.
wg_patch_firebox_bovpn_tunnel details
wg_patch_firebox_bovpn_tunnel details
[WatchGuard Cloud] Updates only the routes list or the endpoint certificates of one branch office VPN IPSec tunnel, selected by its object id in the path. Every other field of the tunnel, its pre-shared key included, is preserved: this is the partial sibling of wg_update_firebox_bovpn_tunnel, which replaces the whole object. The response is the updated tunnel and carries psk, the pre-shared key, in clear text. The change is saved in WatchGuard Cloud and reaches no Firebox until wg_deploy_firebox_configuration pushes it. The body is a JSON object whose fields are certs, routes.
wg_patch_firebox_bovpn_tunnel_by_name details
wg_patch_firebox_bovpn_tunnel_by_name details
[WatchGuard Cloud] Updates only the routes list or the endpoint certificates of one branch office VPN IPSec tunnel, selected by the id or the name in the body. This route takes no path or query selector, so the tunnel is chosen by the body's id or name field and a wrong name updates a different tunnel rather than failing. Prefer wg_patch_firebox_bovpn_tunnel, which takes the tunnel's object id in the path. Every other field of the tunnel, its pre-shared key included, is preserved, and the response is the updated tunnel and carries psk, the pre-shared key, in clear text. The change is saved in WatchGuard Cloud and reaches no Firebox until wg_deploy_firebox_configuration pushes it. The body is a JSON object whose fields are certs, id, name, routes.
wg_update_firebox_bovpn_p1_shared_settings details
wg_update_firebox_bovpn_p1_shared_settings details
wg_update_firebox_bovpn_tunnel details
wg_update_firebox_bovpn_tunnel details
[WatchGuard Cloud] DESTRUCTIVE. Replaces one branch office VPN IPSec tunnel, selected by its object id in the path. This replaces the tunnel wholesale, including its pre-shared key: every field you leave out is cleared rather than kept, so read the tunnel with wg_get_firebox_bovpn_tunnel and send it back complete. WatchGuard echoes the key back in the response. version must be the version you just read, and WatchGuard refuses a stale one as a conflict. The sibling wg_update_firebox_bovpn_tunnel_by_name takes no object id and selects the tunnel from the body instead; wg_patch_firebox_bovpn_tunnel changes the routes or the certificates without touching anything else. The change is saved in WatchGuard Cloud and reaches no Firebox until wg_deploy_firebox_configuration pushes it. The body is a JSON object whose fields are address_family, auth_method, certs, disabled, endpoint_a, endpoint_b, endpoint_b_name, interfaces, ipsec_tunnel_core, local_remote_pairs, name, psk, psk_encrypted, routes and 4 more; required: endpoint_a, interfaces, name, routes, version.
wg_update_firebox_bovpn_tunnel_by_name details
wg_update_firebox_bovpn_tunnel_by_name details
[WatchGuard Cloud] DESTRUCTIVE. Replaces one branch office VPN IPSec tunnel, selected by the tunnel name in the body. This selects the tunnel by NAME from the body and replaces it wholesale, so a wrong name edits a different tunnel rather than failing, and every field you leave out is cleared rather than kept. The body carries the pre-shared key and WatchGuard echoes it back in the response. WatchGuard's prose calls the name a URL parameter, but the specification declares no path or query parameter on this route: the name travels in the body. Prefer wg_update_firebox_bovpn_tunnel, which takes the tunnel's object id in the path. version must be the version you read with wg_get_firebox_bovpn_tunnel or wg_list_firebox_bovpn_tunnels. The change is saved in WatchGuard Cloud and reaches no Firebox until wg_deploy_firebox_configuration pushes it. The body is a JSON object whose fields are address_family, auth_method, certs, disabled, endpoint_a, endpoint_b, endpoint_b_name, interfaces, ipsec_tunnel_core, local_remote_pairs, name, psk, psk_encrypted, routes and 4 more; required: endpoint_a, interfaces, name, routes, version.
Firebox Policies
wg_create_firebox_policy details
wg_create_firebox_policy details
[WatchGuard Cloud] Creates a firewall policy on a Firebox. Saved in WatchGuard Cloud only: the new rule reaches no device until wg_deploy_firebox_configuration pushes the configuration. Read wg_list_firebox_policy_groups, wg_list_firebox_traffic_types and wg_list_firebox_aliases first, because group, traffic_types, sources and destinations all name objects that must already exist. The body is a JSON object whose fields are action, connection_rate_limit, content_filtering, content_scanning, description, destinations, device, enabled, geolocation, group, hidden, idle_timeout, immutable, name and 18 more; required: action, destinations, device, enabled, group, name, sources, traffic_types, type.
wg_delete_firebox_policy details
wg_delete_firebox_policy details
[WatchGuard Cloud] DESTRUCTIVE. Deletes one firewall policy. There is no undo, and the id is all this call takes: confirm the rule with wg_get_firebox_policy first, because a wrong id removes a rule that is filtering traffic today. WatchGuard refuses to delete a policy marked permanent. WatchGuard answers 201, not 204, and the body is the deleted policy with inactive set to true - that is success, not a failure. The deletion is saved in WatchGuard Cloud; the Firebox stops enforcing the rule at the next wg_deploy_firebox_configuration.
wg_get_firebox_alias details
wg_get_firebox_alias details
[WatchGuard Cloud] Returns one firewall alias and the members it resolves to. Use it to see exactly which hosts, networks, ranges, FQDNs, users or groups a policy matches when its sources or destinations name this alias. Each member is a typed object: type says what kind it is and value carries the address or the referenced object.
wg_get_firebox_content_filtering_rule details
wg_get_firebox_content_filtering_rule details
[WatchGuard Cloud] Returns one content filtering rule with its application control and WebBlocker category actions. CREDENTIAL IN THE ANSWER: webblocker_override.password is the cleartext password an end user types to override a blocked category, so treat this result as a secret and do not forward or store it, and note that WatchGuard only fills it when webblocker_override.wbo_method is password rather than user_group. The appcontrol array carries one entry per application, each allow or block; the webblocker array carries one entry per URL category, each allow, bypass, deny or warn with its own log and alarm flags; and deny_uncategorized decides what happens to a site in no category.
wg_get_firebox_policy details
wg_get_firebox_policy details
[WatchGuard Cloud] Returns one firewall policy in full, including the version number an update has to send back. Read this before wg_update_firebox_policy: that call replaces the rule wholesale and requires the object's current version, and this is where both the version and the complete rule come from. The record carries the rule's action, type, group, sources, destinations, traffic_types, schedule and NAT settings, wrapped in WatchGuard's object metadata: id, object, version, account, device and created.
wg_get_firebox_policy_group details
wg_get_firebox_policy_group details
[WatchGuard Cloud] Returns one firewall policy group with the ordered list of policies inside it. The policies array is the order WatchGuard runs the member rules in, and each reference in it resolves through wg_get_firebox_policy. WatchGuard requires only the group's name, so a group with no members can answer without the array at all.
wg_get_firebox_snat_action details
wg_get_firebox_snat_action details
[WatchGuard Cloud] Returns one static NAT (SNAT) action with its external-to-internal address rules. Each rule pairs an external_address - an IPv4 host, a reference to an external network, or the Any-External system alias - with the internal_address the traffic is sent to, and may narrow the match with destination_port and source_address. A policy uses the action by naming it in a destination of type firewall_snat_action.
wg_get_firebox_traffic_shaping_rule details
wg_get_firebox_traffic_shaping_rule details
[WatchGuard Cloud] Returns one traffic shaping rule with the bandwidth it limits or guarantees. behavior is limit or guarantee, method is all_users or per_user (with max_users when it is per_user), rule_type says which traffic the rule applies to - outbound, inbound, custom, first, last, content_filtering or mixed - and the bandwidth is carried as upload and download in Kbps.
wg_get_firebox_traffic_type details
wg_get_firebox_traffic_type details
[WatchGuard Cloud] Returns one traffic type with the protocols and ports it matches. The type field says whether WatchGuard predefined it or the account created it, category is the vendor grouping - Auth, Custom, Database, Email, File, General, Network, RemoteAccess, Tunneling, VoIP/Chat, WatchGuard or Web - and protocols lists one entry per matched protocol, each typed any (the protocol with no port restriction), single_port or port_range for TCP and UDP, or icmp.
wg_list_firebox_aliases details
wg_list_firebox_aliases details
[WatchGuard Cloud] Lists the firewall aliases defined for the account, or for one Firebox or template. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result. An alias is a named set of at least one member - IPv4 or IPv6 hosts, networks and ranges, FQDNs, WatchGuard's own system aliases such as Any-External, or references to another alias, a network, a Firebox user or group, an authentication group, or an AuthPoint or SAML user group - that a policy's sources and destinations point at by name, so read this before you write a policy that names one. Each entry's id is the objectid wg_get_firebox_alias takes.
wg_list_firebox_content_filtering_rules details
wg_list_firebox_content_filtering_rules details
[WatchGuard Cloud] Lists the content filtering rules, the application control and WebBlocker category actions, for the account or for one Firebox or template. CREDENTIAL IN THE ANSWER: each rule's webblocker_override.password is the cleartext password an end user types to override a blocked category, so treat this result as a secret and do not forward or store it. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result. Every rule carries its whole appcontrol array (one entry per application, allow or block) and webblocker array (one entry per URL category, allow, bypass, deny or warn), so this answer is large on a tuned account. Each entry's id is the objectid wg_get_firebox_content_filtering_rule takes.
wg_list_firebox_policies details
wg_list_firebox_policies details
[WatchGuard Cloud] Lists the firewall policies WatchGuard Cloud holds for the account, or for one Firebox when you name a device. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result. Start here for anything policy-shaped: the answer is a count plus an objects array, and each entry's id is the objectid that wg_get_firebox_policy, wg_update_firebox_policy, wg_set_firebox_policy_enabled and wg_delete_firebox_policy take. Send full=1 when you need whole rules rather than the id, name, group and device summary.
wg_list_firebox_policy_groups details
wg_list_firebox_policy_groups details
[WatchGuard Cloud] Lists the firewall policy groups defined for the account, or for one Firebox or template. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result. A policy group is the ordered container a firewall policy's group field names, and WatchGuard's own groups are First Run Policies, Core Policies and Last Run Policies. Each entry's policies array lists its member policies in the order they run, and each entry's id is the objectid wg_get_firebox_policy_group takes.
wg_list_firebox_snat_actions details
wg_list_firebox_snat_actions details
[WatchGuard Cloud] Lists the static NAT (SNAT) actions defined for the account, or for one Firebox or template. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result. A SNAT action maps an external address to an internal one and a firewall policy's nat settings name it. Each entry's id is the objectid wg_get_firebox_snat_action takes.
wg_list_firebox_traffic_shaping_rules details
wg_list_firebox_traffic_shaping_rules details
[WatchGuard Cloud] Lists the traffic shaping rules defined for the account, or for one Firebox or template. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result. A traffic shaping rule limits or guarantees bandwidth for the policies that name it in their traffic_shaping field. Each entry's id is the objectid wg_get_firebox_traffic_shaping_rule takes.
wg_list_firebox_traffic_types details
wg_list_firebox_traffic_types details
[WatchGuard Cloud] Lists the traffic types, the named protocol and port sets, available for the account or for one Firebox or template. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result. A firewall policy's traffic_types field names these, both WatchGuard's predefined ones such as All TCP and UDP or FTP and any the account created, so read this to find valid names before you create or update a policy. Each entry's id is the objectid wg_get_firebox_traffic_type takes.
wg_set_firebox_policy_enabled details
wg_set_firebox_policy_enabled details
[WatchGuard Cloud] DESTRUCTIVE. Enables or disables one firewall policy without touching any of its other settings. Disabling a firewall policy stops it enforcing without deleting it, so the rule looks present in the configuration while it is no longer applied; the same call with enabled true puts it back. The body needs device as well as enabled: the Firebox ID the policy belongs to, which wg_get_firebox_policy returns. No other field is read, so the rule's version is not required here. WatchGuard answers 201 with the whole updated policy, not an empty body. The change is saved in WatchGuard Cloud and takes effect on the Firebox at the next wg_deploy_firebox_configuration. The body is a JSON object whose fields are device, enabled; required: device, enabled.
wg_update_firebox_policy details
wg_update_firebox_policy details
[WatchGuard Cloud] DESTRUCTIVE. Replaces one firewall policy with the object you send. This replaces the rule wholesale - every field you leave out is CLEARED rather than kept, so read the rule with wg_get_firebox_policy and send it back complete; a partial body silently drops sources, destinations or traffic_types from a rule that is filtering traffic today. The body must carry version, the object's current version number from wg_get_firebox_policy; a 409 means the id and version you sent conflict with what WatchGuard holds, so re-read the rule and send its current version. WatchGuard answers 201 with the rewritten policy and the incremented version. The rewritten rule is saved in WatchGuard Cloud and reaches the Firebox at the next wg_deploy_firebox_configuration. The body is a JSON object whose fields are action, connection_rate_limit, content_filtering, content_scanning, description, destinations, device, enabled, geolocation, group, hidden, idle_timeout, immutable, name and 19 more; required: action, destinations, device, enabled, group, name, sources, traffic_types, type, version.
Firebox System
wg_create_firebox_certificate details
wg_create_firebox_certificate details
[WatchGuard Cloud] DESTRUCTIVE. Creates a certificate in the account, either by importing one with its private key or by pointing one Firebox at a certificate the account already holds. The body carries a private key in pvt_key, or a PFX in pfx with its password, so this stores credential material in the WatchGuard Cloud account, and WatchGuard echoes the created certificate object back in the response. WatchGuard documents two shapes for the body: an import, which sends name plus pem and pvt_key, or pfx and its password; and a device-level reference, which sends alias plus device and no key material at all. Omit device for an account-level certificate. This only stores the certificate: putting it on a Firebox is the separate command wg_install_firebox_certificate. The change is saved in WatchGuard Cloud and reaches no Firebox until wg_deploy_firebox_configuration pushes it. The body is a JSON object whose fields are alias, description, device, name, password, pem, pfx, pvt_key.
wg_delete_firebox_certificate details
wg_delete_firebox_certificate details
[WatchGuard Cloud] DESTRUCTIVE. Deletes one certificate from the account, selected by its object id in the path. There is no undo: WatchGuard removes the certificate outright, so confirm the object id with wg_get_firebox_certificate first. Anything that presents that certificate, from HTTPS inspection to the device web server, loses it once the change is deployed. WatchGuard answers with the deleted certificate object, private key included. The object id comes from wg_list_firebox_certificates. The change is saved in WatchGuard Cloud and reaches no Firebox until wg_deploy_firebox_configuration pushes it.
wg_get_firebox_certificate details
wg_get_firebox_certificate details
[WatchGuard Cloud] Retrieves one certificate, selected by its object id in the path. The object id comes from wg_list_firebox_certificates. WatchGuard's certificate object has two shapes: a device-level reference, which carries only the alias of the account certificate it points at, and an imported certificate, which carries pem and can carry pvt_key, pfx and the PFX password in clear text. Treat the response as credential material.
wg_get_firebox_schedule details
wg_get_firebox_schedule details
[WatchGuard Cloud] Retrieves one time schedule, selected by its object id in the path. The object id comes from wg_list_firebox_schedules. The response carries the schedule name, its enabled flag, schedule_type (0 always on, 1 daily, 2 weekly) and members, which lists each day of the week as day_of_week 0 (Sunday) through 6 (Saturday) with that day's time periods as from_hour, from_min, to_hour and to_min.
wg_install_firebox_certificate details
wg_install_firebox_certificate details
[WatchGuard Cloud] DESTRUCTIVE. Installs a stored certificate on one Firebox or on a list of Fireboxes. This installs the certificate onto live Fireboxes, replacing what those devices present to clients. An expired or wrong certificate breaks HTTPS inspection and the device web UI, so confirm the certificate with wg_list_firebox_certificates and check the device ids before you call it. Name the certificate either by name in certificate or by object id in certificate_id, and the target either by device, one Firebox id, or by devices, a list of 1 to 100 Firebox ids; devices is accepted even though it is missing from the field list at the end of this description, because WatchGuard declares it as a bare array in the second branch of the body's oneOf. This is a command rather than a saved configuration change, so it does not wait for wg_deploy_firebox_configuration. The 201 is the id of the certificate object WatchGuard created, a crt_ id, and NOT a deployment transaction: wg_list_firebox_deployment_transactions takes tx_type=deployment only, so this call has no transaction to read back. The body is a JSON object whose fields are certificate, certificate_id, device.
wg_list_firebox_certificates details
wg_list_firebox_certificates details
[WatchGuard Cloud] Lists the certificates stored for the account, or the certificates on one Firebox when you name a device. Start here: every other certificate tool takes the object id this list returns in each object's id field. Name a device for that Firebox's certificates; omit it for the account's own. An imported certificate can carry pvt_key, pfx and the PFX password in clear text, so treat the response as credential material. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result.
wg_list_firebox_schedules details
wg_list_firebox_schedules details
[WatchGuard Cloud] Lists the time schedules defined for the account, for one Firebox, or for one Firebox template. Schedules are the named time windows that firewall policies and other objects reference, and the Firebox Management API publishes reads for them only: there is no create, update or delete. Start here: wg_get_firebox_schedule takes the object id this list returns. device and templateid are mutually exclusive. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result.
wg_list_firebox_template_subscriptions details
wg_list_firebox_template_subscriptions details
[WatchGuard Cloud] Lists the Firebox templates available to the account, the templates one Firebox subscribes to, or the Fireboxes subscribed to one template. One route with three answers, chosen by the query: with neither filter it returns the templates available to the account, inherited ones included; with device it returns the templates that Firebox subscribes to; with templateid it returns the Fireboxes subscribed to that template. device and templateid are mutually exclusive. Read this before wg_set_firebox_template_subscription, which replaces a Firebox's whole subscription list with what you send. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result.
wg_set_firebox_template_subscription details
wg_set_firebox_template_subscription details
[WatchGuard Cloud] DESTRUCTIVE. Sets the complete list of Firebox templates that one Firebox subscribes to. The Firebox is UNSUBSCRIBED from every template you do not list, and an empty templates array unsubscribes it from all of them. Send the complete list you want, in priority order. Read the current list with wg_list_firebox_template_subscriptions and send it back complete, plus or minus the change you want. The order of the templates array is the order the templates are applied on the Firebox, so sending the same ids in a different order is how you change which one wins. Maximum 50 template ids per request. The change is saved in WatchGuard Cloud and reaches no Firebox until wg_deploy_firebox_configuration pushes it. The body is a JSON object whose fields are device, templates; required: device, templates.
FireCloud Exceptions
wg_create_firecloud_blocked_site_exception details
wg_create_firecloud_blocked_site_exception details
[WatchGuard Cloud] DESTRUCTIVE. Creates a new FireCloud blocked sites exception. A FireCloud blocked sites exception ALLOWS the address it names - action takes the single value allow on this schema and accepts no other - so it can only open traffic the Blocked Sites list would otherwise stop. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the created exception, including the id that wg_get_firecloud_blocked_site_exception, wg_update_firecloud_blocked_site_exception and wg_delete_firecloud_blocked_site_exception take. The body is a JSON object whose fields are action, address, description; required: address.
wg_create_firecloud_botnet_site_exception details
wg_create_firecloud_botnet_site_exception details
[WatchGuard Cloud] Creates a new FireCloud botnet site exception. A botnet site exception can only allow: it exempts the address it names from botnet site blocking, so it opens traffic FireCloud would otherwise stop. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the created exception, including the id that wg_get_firecloud_botnet_site_exception, wg_update_firecloud_botnet_site_exception and wg_delete_firecloud_botnet_site_exception take. The body is a JSON object whose fields are action, address, description; required: address.
wg_create_firecloud_file_exception details
wg_create_firecloud_file_exception details
[WatchGuard Cloud] Creates a new FireCloud file exception. action decides the direction: allow lets a file with that MD5 through, block stops it. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the created exception, including the id that wg_get_firecloud_file_exception, wg_update_firecloud_file_exception and wg_delete_firecloud_file_exception take. The body is a JSON object whose fields are action, description, md5; required: action, md5.
wg_create_firecloud_geolocation_exception details
wg_create_firecloud_geolocation_exception details
[WatchGuard Cloud] Creates a new FireCloud Geolocation exception. A Geolocation exception can only allow: it exempts the address it names from the account's Geolocation blocking, so it opens traffic FireCloud would otherwise stop. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the created exception, including the id that wg_get_firecloud_geolocation_exception, wg_update_firecloud_geolocation_exception and wg_delete_firecloud_geolocation_exception take. The body is a JSON object whose fields are action, address, description; required: address.
wg_create_firecloud_https_exception details
wg_create_firecloud_https_exception details
[WatchGuard Cloud] Creates a new FireCloud HTTPS decryption exception. An HTTPS decryption exception can only allow: it EXCLUDES the traffic it names from HTTPS inspection, so FireCloud stops decrypting it. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the created exception, including the id that wg_get_firecloud_https_exception, wg_update_firecloud_https_exception and wg_delete_firecloud_https_exception take. The body is a JSON object whose fields are action, description, rule, type; required: rule, type.
wg_create_firecloud_ips_signature_exception details
wg_create_firecloud_ips_signature_exception details
[WatchGuard Cloud] Creates a new FireCloud IPS signature exception. action decides the direction: allow exempts the signature from enforcement, block enforces it. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the created exception, including the id that wg_get_firecloud_ips_signature_exception, wg_update_firecloud_ips_signature_exception and wg_delete_firecloud_ips_signature_exception take. The body is a JSON object whose fields are action, alarm, description, signature_id; required: action, signature_id.
wg_create_firecloud_webblocker_exception details
wg_create_firecloud_webblocker_exception details
[WatchGuard Cloud] DESTRUCTIVE. Creates a new FireCloud WebBlocker exception. action decides the direction and is required: allow opens a URL the WebBlocker categories block and block refuses one they permit, so a wrong value either exposes the customer to a blocked category or cuts off a site they rely on. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the created exception, including the id that wg_get_firecloud_webblocker_exception, wg_update_firecloud_webblocker_exception and wg_delete_firecloud_webblocker_exception take. The body is a JSON object whose fields are action, alarm, name, rule, rule_type; required: action, name, rule, rule_type.
wg_delete_firecloud_blocked_site_exception details
wg_delete_firecloud_blocked_site_exception details
[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified FireCloud blocked sites exception. WatchGuard answers 201 with the deleted exception marked inactive true and publishes no way to reactivate it, so recreate it with wg_create_firecloud_blocked_site_exception if you need it back; once it is gone the address it named goes back under the Blocked Sites list. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change.
wg_delete_firecloud_botnet_site_exception details
wg_delete_firecloud_botnet_site_exception details
[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified FireCloud botnet site exception. WatchGuard answers 201 with the deleted exception marked inactive true and publishes no way to reactivate it, so recreate it with wg_create_firecloud_botnet_site_exception if you need it back; once it is gone the address it named goes back under botnet site blocking. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change.
wg_delete_firecloud_file_exception details
wg_delete_firecloud_file_exception details
[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified FireCloud file exception. WatchGuard answers 201 with the deleted exception marked inactive true and publishes no way to reactivate it, so recreate it with wg_create_firecloud_file_exception if you need it back; once it is gone the MD5 it named goes back to the account's default file handling, so a block exception stops stopping that file. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change.
wg_delete_firecloud_geolocation_exception details
wg_delete_firecloud_geolocation_exception details
[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified FireCloud Geolocation exception. WatchGuard answers 201 with the deleted exception marked inactive true and publishes no way to reactivate it, so recreate it with wg_create_firecloud_geolocation_exception if you need it back; once it is gone the address it named goes back under the account's Geolocation blocking. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change.
wg_delete_firecloud_https_exception details
wg_delete_firecloud_https_exception details
[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified FireCloud HTTPS decryption exception. WatchGuard answers 201 with the deleted exception marked inactive true and publishes no way to reactivate it, so recreate it with wg_create_firecloud_https_exception if you need it back; once it is gone the traffic it excluded goes back under HTTPS decryption, so content an administrator deliberately kept out of inspection is decrypted again. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change.
wg_delete_firecloud_ips_signature_exception details
wg_delete_firecloud_ips_signature_exception details
[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified FireCloud IPS signature exception. WatchGuard answers 201 with the deleted exception marked inactive true and publishes no way to reactivate it, so recreate it with wg_create_firecloud_ips_signature_exception if you need it back; once it is gone the signature goes back to its default enforcement, so a block exception stops stopping that signature. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change.
wg_delete_firecloud_webblocker_exception details
wg_delete_firecloud_webblocker_exception details
[WatchGuard Cloud] DESTRUCTIVE. Deletes the specified FireCloud WebBlocker exception. WatchGuard answers 201 with the deleted exception marked inactive true and publishes no way to reactivate it, so recreate it with wg_create_firecloud_webblocker_exception if you need it back; once it is gone the URL goes back to its WebBlocker category action, so an allow exception stops opening it and a block exception stops refusing it. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change.
wg_get_firecloud_blocked_site_exception details
wg_get_firecloud_blocked_site_exception details
[WatchGuard Cloud] Retrieves the specified FireCloud blocked sites exception. WatchGuard answers 404 when the account holds no blocked sites exception with that id. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.
wg_get_firecloud_botnet_site_exception details
wg_get_firecloud_botnet_site_exception details
[WatchGuard Cloud] Retrieves the specified FireCloud botnet site exception. WatchGuard answers 404 when the account holds no botnet site exception with that id. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.
wg_get_firecloud_file_exception details
wg_get_firecloud_file_exception details
[WatchGuard Cloud] Retrieves the specified FireCloud file exception. WatchGuard answers 404 when the account holds no file exception with that id. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.
wg_get_firecloud_geolocation_exception details
wg_get_firecloud_geolocation_exception details
[WatchGuard Cloud] Retrieves the specified FireCloud Geolocation exception. WatchGuard answers 404 when the account holds no Geolocation exception with that id. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.
wg_get_firecloud_https_exception details
wg_get_firecloud_https_exception details
[WatchGuard Cloud] Retrieves the specified FireCloud HTTPS decryption exception. WatchGuard answers 404 when the account holds no HTTPS decryption exception with that id. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.
wg_get_firecloud_ips_signature_exception details
wg_get_firecloud_ips_signature_exception details
[WatchGuard Cloud] Retrieves the specified FireCloud IPS signature exception. WatchGuard answers 404 when the account holds no IPS signature exception with that id. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.
wg_get_firecloud_webblocker_exception details
wg_get_firecloud_webblocker_exception details
[WatchGuard Cloud] Retrieves the specified FireCloud WebBlocker exception. WatchGuard answers 404 when the account holds no WebBlocker exception with that id. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.
wg_list_firecloud_blocked_site_exceptions details
wg_list_firecloud_blocked_site_exceptions details
[WatchGuard Cloud] Retrieves all blocked sites exceptions in the specified FireCloud account. The response is a JSON array of blocked sites exception objects; each item's id is the objectid wg_get_firecloud_blocked_site_exception, wg_update_firecloud_blocked_site_exception and wg_delete_firecloud_blocked_site_exception take, and wg_list_firecloud_exceptions returns every kind in one call. This route takes no paging argument - WatchGuard defines limit and start_after in this specification's components but references them from no operation - so one call returns the whole collection for the account. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.
wg_list_firecloud_botnet_site_exceptions details
wg_list_firecloud_botnet_site_exceptions details
[WatchGuard Cloud] Retrieves all botnet site exceptions in the specified FireCloud account. The response is a JSON array of botnet site exception objects; each item's id is the objectid wg_get_firecloud_botnet_site_exception, wg_update_firecloud_botnet_site_exception and wg_delete_firecloud_botnet_site_exception take, and wg_list_firecloud_exceptions returns every kind in one call. This route takes no paging argument - WatchGuard defines limit and start_after in this specification's components but references them from no operation - so one call returns the whole collection for the account. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.
wg_list_firecloud_exceptions details
wg_list_firecloud_exceptions details
[WatchGuard Cloud] Retrieves all exceptions in the specified FireCloud account. Start here for FireCloud: the response is one JSON array mixing all seven exception kinds - blocked sites, botnet sites, file, Geolocation, HTTPS decryption, IPS signature and WebBlocker - where each item's object field names its kind and its id is the objectid the get, update and delete tools take. This route takes no paging argument - WatchGuard defines limit and start_after in this specification's components but references them from no operation - so one call returns the whole collection for the account. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.
wg_list_firecloud_file_exceptions details
wg_list_firecloud_file_exceptions details
[WatchGuard Cloud] Retrieves all file exceptions in the specified FireCloud account. The response is a JSON array of file exception objects; each item's id is the objectid wg_get_firecloud_file_exception, wg_update_firecloud_file_exception and wg_delete_firecloud_file_exception take, and wg_list_firecloud_exceptions returns every kind in one call. This route takes no paging argument - WatchGuard defines limit and start_after in this specification's components but references them from no operation - so one call returns the whole collection for the account. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.
wg_list_firecloud_geolocation_exceptions details
wg_list_firecloud_geolocation_exceptions details
[WatchGuard Cloud] Retrieves all Geolocation exceptions in the specified FireCloud account. The response is a JSON array of Geolocation exception objects; each item's id is the objectid wg_get_firecloud_geolocation_exception, wg_update_firecloud_geolocation_exception and wg_delete_firecloud_geolocation_exception take, and wg_list_firecloud_exceptions returns every kind in one call. This route takes no paging argument - WatchGuard defines limit and start_after in this specification's components but references them from no operation - so one call returns the whole collection for the account. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.
wg_list_firecloud_https_exceptions details
wg_list_firecloud_https_exceptions details
[WatchGuard Cloud] Retrieves all HTTPS decryption exceptions in the specified FireCloud account. The response is a JSON array of HTTPS decryption exception objects; each item's id is the objectid wg_get_firecloud_https_exception, wg_update_firecloud_https_exception and wg_delete_firecloud_https_exception take, and wg_list_firecloud_exceptions returns every kind in one call. This route takes no paging argument - WatchGuard defines limit and start_after in this specification's components but references them from no operation - so one call returns the whole collection for the account. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.
wg_list_firecloud_ips_signature_exceptions details
wg_list_firecloud_ips_signature_exceptions details
[WatchGuard Cloud] Retrieves all IPS signature exceptions in the specified FireCloud account. The response is a JSON array of IPS signature exception objects; each item's id is the objectid wg_get_firecloud_ips_signature_exception, wg_update_firecloud_ips_signature_exception and wg_delete_firecloud_ips_signature_exception take, and wg_list_firecloud_exceptions returns every kind in one call. This route takes no paging argument - WatchGuard defines limit and start_after in this specification's components but references them from no operation - so one call returns the whole collection for the account. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.
wg_list_firecloud_webblocker_exceptions details
wg_list_firecloud_webblocker_exceptions details
[WatchGuard Cloud] Retrieves all WebBlocker exceptions in the specified FireCloud account. The response is a JSON array of WebBlocker exception objects; each item's id is the objectid wg_get_firecloud_webblocker_exception, wg_update_firecloud_webblocker_exception and wg_delete_firecloud_webblocker_exception take, and wg_list_firecloud_exceptions returns every kind in one call. This route takes no paging argument - WatchGuard defines limit and start_after in this specification's components but references them from no operation - so one call returns the whole collection for the account. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable.
wg_update_firecloud_blocked_site_exception details
wg_update_firecloud_blocked_site_exception details
[WatchGuard Cloud] DESTRUCTIVE. Updates the specified FireCloud blocked sites exception. This replaces the blocked sites exception wholesale: every field you leave out is cleared rather than kept, and the body must also carry the object's own id, object, version, account, created, device and author, so read it back with wg_get_firecloud_blocked_site_exception and send it complete. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the updated object with its version incremented; WatchGuard answers 409 with type object_exists_error when an object already exists with the same id and version. The body is a JSON object whose fields are account, action, address, author, created, description, device, id, object, version; required: account, address, author, created, device, id, object, version.
wg_update_firecloud_botnet_site_exception details
wg_update_firecloud_botnet_site_exception details
[WatchGuard Cloud] DESTRUCTIVE. Updates the specified FireCloud botnet site exception. This replaces the botnet site exception wholesale: every field you leave out is cleared rather than kept, and the body must also carry the object's own id, object, version, account, created, device and author, so read it back with wg_get_firecloud_botnet_site_exception and send it complete. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the updated object with its version incremented; WatchGuard answers 409 with type object_exists_error when an object already exists with the same id and version. The body is a JSON object whose fields are account, action, address, author, created, description, device, id, object, version; required: account, address, author, created, device, id, object, version.
wg_update_firecloud_file_exception details
wg_update_firecloud_file_exception details
[WatchGuard Cloud] DESTRUCTIVE. Updates the specified FireCloud file exception. This replaces the file exception wholesale: every field you leave out is cleared rather than kept, and the body must also carry the object's own id, object, version, account, created, device and author, so read it back with wg_get_firecloud_file_exception and send it complete. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the updated object with its version incremented; WatchGuard answers 409 with type object_exists_error when an object already exists with the same id and version. The body is a JSON object whose fields are account, action, author, created, description, device, id, md5, object, version; required: account, action, author, created, device, id, md5, object, version.
wg_update_firecloud_geolocation_exception details
wg_update_firecloud_geolocation_exception details
[WatchGuard Cloud] DESTRUCTIVE. Updates the specified FireCloud Geolocation exception. This replaces the Geolocation exception wholesale: every field you leave out is cleared rather than kept, and the body must also carry the object's own id, object, version, account, created, device and author, so read it back with wg_get_firecloud_geolocation_exception and send it complete. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the updated object with its version incremented; WatchGuard answers 409 with type object_exists_error when an object already exists with the same id and version. The body is a JSON object whose fields are account, action, address, author, created, description, device, id, object, version; required: account, address, author, created, device, id, object, version.
wg_update_firecloud_https_exception details
wg_update_firecloud_https_exception details
[WatchGuard Cloud] DESTRUCTIVE. Updates the specified FireCloud HTTPS decryption exception. This replaces the HTTPS decryption exception wholesale: every field you leave out is cleared rather than kept, and the body must also carry the object's own id, object, version, account, created, device and author, so read it back with wg_get_firecloud_https_exception and send it complete. Clearing a field here turns HTTPS decryption back on for traffic an administrator deliberately excluded. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the updated object with its version incremented; WatchGuard answers 409 with type object_exists_error when an object already exists with the same id and version. The body is a JSON object whose fields are account, action, author, created, description, device, id, object, rule, type, version; required: account, author, created, device, id, object, rule, type, version.
wg_update_firecloud_ips_signature_exception details
wg_update_firecloud_ips_signature_exception details
[WatchGuard Cloud] DESTRUCTIVE. Updates the specified FireCloud IPS signature exception. This replaces the IPS signature exception wholesale: every field you leave out is cleared rather than kept, and the body must also carry the object's own id, object, version, account, created, device and author, so read it back with wg_get_firecloud_ips_signature_exception and send it complete. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the updated object with its version incremented; WatchGuard answers 409 with type object_exists_error when an object already exists with the same id and version. The body is a JSON object whose fields are account, action, alarm, author, created, description, device, id, object, signature_id, version; required: account, action, author, created, device, id, object, signature_id, version.
wg_update_firecloud_webblocker_exception details
wg_update_firecloud_webblocker_exception details
[WatchGuard Cloud] DESTRUCTIVE. Updates the specified FireCloud WebBlocker exception. This replaces the WebBlocker exception wholesale: every field you leave out is cleared rather than kept, and the body must also carry the object's own id, object, version, account, created, device and author, so read it back with wg_get_firecloud_webblocker_exception and send it complete. FireCloud only: the wg_firebox_* exception tools serve the identical path on the Firebox Management API and are not interchangeable, and this API publishes no deployment endpoint - wg_deploy_firebox_configuration has no FireCloud counterpart, so there is no second call to push the change. The 201 response is the updated object with its version incremented; WatchGuard answers 409 with type object_exists_error when an object already exists with the same id and version. The body is a JSON object whose fields are account, action, alarm, author, created, device, id, name, object, rule, rule_type, version; required: account, action, author, created, device, id, name, object, rule, rule_type, version.
Product Catalog
wg_list_product_classifications details
wg_list_product_classifications details
[WatchGuard Cloud] Returns all product classifications from the WatchGuard Product Catalog. Classifications are different types of contracts, such as Subscription. The response is a JSON object with results, an array of classification names as plain strings. These are the values the classification filter of wg_list_products takes. WatchGuard declares no paging on this route, so one call returns the whole list.
wg_list_product_families details
wg_list_product_families details
[WatchGuard Cloud] Returns all product families from the WatchGuard Product Catalog. Product families are different groups of WatchGuard devices in a product category. For example, M Series and T Series are families of Fireboxes. The response is a JSON object with results, an array of family names as plain strings. These are the values the family filter of wg_list_products and of wg_list_product_models take. WatchGuard declares no paging on this route, so one call returns the whole list.
wg_list_product_models details
wg_list_product_models details
[WatchGuard Cloud] Returns device models from the WatchGuard Product Catalog that match the specified filters. Models are different types of Fireboxes. For example, the Firebox M370. The response is a JSON object with results, an array of model names as plain strings, and those are the values the model filter of wg_list_products takes. WatchGuard declares no paging on this route, so one call returns the whole list.
wg_list_product_service_suites details
wg_list_product_service_suites details
[WatchGuard Cloud] Returns a list of all WatchGuard service suites. Service suites define which subscription services are available for a device or product. The response is a JSON object with results, an array of service suite names as plain strings — Basic Security, Standard Support or Total Security — and those are the values the serviceSuite filter of wg_list_products takes. WatchGuard declares no paging on this route, so one call returns the whole list.
wg_list_products details
wg_list_products details
[WatchGuard Cloud] Returns products from the WatchGuard Product Catalog that match the specified filters. Start here for the product catalog. The response is a JSON object with results, one entry per product, carrying the sku that wg_create_purchase_order takes in its lineItems, plus the description, category, family, model, service suite, classification, contract term, invoicing frequency, region, suggested retail price and the product type. Every filter below takes a value from one of the companion lists: wg_list_product_classifications, wg_list_product_families, wg_list_product_models and wg_list_product_service_suites.
Subscriptions and Orders
wg_cancel_subscription_contract details
wg_cancel_subscription_contract details
[WatchGuard Cloud] DESTRUCTIVE. Cancels the specified subscription contract. This ends a live subscription contract: service on the products it covers stops and WatchGuard publishes no re-instatement call. The resume verb is deprecated and only restarts a SUSPENDED contract, so it will not bring this one back. The subscriptionContractId comes from wg_list_subscription_contracts. WatchGuard answers 204 No Content on success, which StackJack returns as {"success":true}, so confirm the outcome by reading the contract back with wg_get_subscription_contract — its status leaves Active. The body is a JSON object whose fields are cancelReason; required: cancelReason.
wg_create_purchase_order details
wg_create_purchase_order details
[WatchGuard Cloud] DESTRUCTIVE. Creates a new purchase order for WatchGuard products. This places a real purchase order with WatchGuard, generates a subscription contract for every SKU on it and commits the account to the cost; WatchGuard publishes no call that withdraws an order, so a mistake is unwound one contract at a time with wg_cancel_subscription_contract. Every SKU comes from wg_list_products. The response echoes the purchase order number and the reseller, and its lineItems array pairs each SKU with the subscriptionContractId WatchGuard generated for it; each of those contracts then needs a device serial number through wg_set_contract_serial_number. Setting isDropShipOrder means dropShipOrderInfo has to carry the shipping details, and wg_get_contract_drop_ship_info reads them back with the tracking number once the order ships. The body is a JSON object whose fields are dropShipOrderInfo, isDropShipOrder, lineItems, purchaseOrderNumber, resellerId; required: lineItems, purchaseOrderNumber, resellerId.
wg_get_contract_drop_ship_info details
wg_get_contract_drop_ship_info details
[WatchGuard Cloud] Returns drop-ship information for the specified subscription contract. Only an order placed with isDropShipOrder set has this. The response carries the shipping tracking number, the ship method, the company and contact the order ships to, the carrier account number it ships on, the device serial number, the purchase order number and the ship-to address. WatchGuard capitalizes four of those field names — PhoneNumber, PhoneExtension, SerialNumber and OrderNumber — beside camel-case siblings such as shippingTrackingNumber and shipToAddress, so match them exactly. The subscriptionContractId comes from wg_list_subscription_contracts.
wg_get_invoice details
wg_get_invoice details
[WatchGuard Cloud] Returns the invoice with the specified invoice number. The invoice number comes from wg_list_invoices and looks like INV_US01_0001. The full invoice adds the bill-to and WatchGuard addresses and a lineItems array with one entry per subscription contract on the invoice, each carrying the contract id, the reseller and its WatchGuardONE level, the SKU and its description, the device serial number, the unit price, the suggested retail price, any markdown and the extended price. A line item carries its billing start and end dates only after WatchGuard has processed the invoice.
wg_get_subscription_contract details
wg_get_subscription_contract details
[WatchGuard Cloud] Returns details of the subscription contract with the specified ID. The subscriptionContractId comes from wg_list_subscription_contracts, from the lineItems array that wg_create_purchase_order answers, or from a line item of wg_get_invoice. This read is far richer than a list row: it adds the distributor and reseller ids, the status, the service and appliance SKUs, the term in months, the billing start and end dates, the invoices posted so far, the remaining balance and the total lifetime cost. The status leaves Active when the contract is canceled, and WatchGuard also retires a contract whose device serial number was never assigned before its grace period ended, which is what wg_set_contract_serial_number prevents.
wg_list_contract_usage_details details
wg_list_contract_usage_details details
[WatchGuard Cloud] Returns license usage information for tenant accounts. It reports by MONTH: startDate and endDate are months in mmyyyy form, not the yyyy-mm-dd dates the rest of this API takes. The response is a JSON object with pagination, holding totalCount, skip and take, and contracts, each carrying the contract id, the reseller id and name, the product description and a usage array; every usage entry holds the date, a total user count and, while tenantUsage stays on, a customers array naming each customer account, its user count and whether the allocation is delegated.
wg_list_invoices details
wg_list_invoices details
[WatchGuard Cloud] Returns summaries of all consolidated invoices generated between the specified dates. The response is a JSON object with totalRowCount and summaries, and each summary carries the invoice number, the invoice and due dates, the purchase order number, the payment terms, the total and the currency. Read one invoice in full — the bill-to and WatchGuard addresses and a line item per subscription contract, with unit price, markdown and extended price — with wg_get_invoice.
wg_list_subscription_contracts details
wg_list_subscription_contracts details
[WatchGuard Cloud] Returns summaries of subscription contracts created between the specified dates. Start here for anything about a subscription. The response is a JSON object with results, the array of contract summaries, and totalCount, which WatchGuard types as a string rather than a number. Each summary carries the subscriptionContractId that every other tool in this group takes as its selector, plus the purchase order number, the SKU, its description, the device serial number assigned to the contract and the created, start and end dates. Read one contract in full — term, billing dates, invoices posted and remaining balance — with wg_get_subscription_contract.
wg_resume_subscription_contract details
wg_resume_subscription_contract details
[WatchGuard Cloud] DESTRUCTIVE. DEPRECATED in WatchGuard's own specification, which names no replacement. Resumes the specified suspended subscription contract. This restarts billing on a suspended subscription contract. This call takes no request body at all — the contract is named in the path and WatchGuard documents nothing else, so there is nothing to send. The contract has to be suspended already; WatchGuard documents a 405 Method Not Allowed response on this route as well as a 404 for a contract it cannot find. On success it answers 204 No Content, which StackJack returns as {"success":true}, so read the contract back with wg_get_subscription_contract to confirm.
wg_set_contract_serial_number details
wg_set_contract_serial_number details
[WatchGuard Cloud] DESTRUCTIVE. Assigns the specified device serial number to the specified subscription contract. This binds the serial number to the contract, replacing whatever was bound before: the device that held the subscription loses it, and WatchGuard publishes no call that undoes the swap. This is how a distributor fulfills an order: WatchGuard retires a subscription contract whose device serial number was never assigned before its grace period ended. The contract id comes from wg_list_subscription_contracts or from the lineItems that wg_create_purchase_order answers. On success WatchGuard answers 204 No Content, which StackJack returns as {"success":true}; read the contract back with wg_get_subscription_contract to see serialNumber and serialNumberReceivedDate. The body is a JSON object whose fields are serialNumber; required: serialNumber.
wg_suspend_subscription_contract details
wg_suspend_subscription_contract details
[WatchGuard Cloud] DESTRUCTIVE. DEPRECATED in WatchGuard's own specification, which names no replacement. Suspends the specified subscription contract. This suspends a live subscription contract, so service on the products it covers stops until it is resumed. WatchGuard still publishes the route but marks it retired and offers nothing to use in its place; the contract reads and wg_cancel_subscription_contract remain supported. This route documents a 405 Method Not Allowed response of its own, which is how a retired operation refuses. On success it answers 204 No Content, which StackJack returns as {"success":true}. Only wg_resume_subscription_contract reverses it, and that verb is deprecated too. The body is a JSON object whose fields are suspendReason; required: suspendReason.
Licenses and Allocations
wg_allocate_assets details
wg_allocate_assets details
[WatchGuard Cloud] DESTRUCTIVE. Allocates a license or a device out of your Service Provider inventory to one of the accounts you manage. The managed account that receives the allocation is the accountId INSIDE the body; the accountId argument is your own Service Provider account, so putting the managed account in the wrong one licenses the wrong customer out of your pool. wg_deallocate_assets is the inverse and takes the allocation back. Read what is still available with wg_get_asset_allocation_summary first, then confirm the result with wg_list_asset_allocations. A success answers only a bare success flag and nothing about the allocation, and WatchGuard reports export-compliance problems in a Warning response header this tool does not return. quantity is required for software products except linked_to_license allocations and takes a number above 0 or the string unlimited; serialOrLicense is required for firebox, fireboxRetention and accessPoint and for every linked_to_license allocation. WatchGuard stops accepting this call after 17 September 2026 for accounts that have no company name, industry, first name, last name and full mailing address. The body is a JSON object whose fields are accountId, allocationExpiryDate, allocationExpiryType, allocationType, modules, productName, quantity, serialOrLicense; required: accountId, productName.
wg_deallocate_assets details
wg_deallocate_assets details
[WatchGuard Cloud] DESTRUCTIVE. Takes an allocated license or device back from a managed account and returns it to your Service Provider inventory. This is the inverse of wg_allocate_assets: whatever the managed account was running under that allocation stops being licensed, and WatchGuard publishes no undo, so confirm the managed account and the product before you call it. The managed account is the managedAccountId argument; the accountId argument stays your own Service Provider account. WatchGuard marks allocationType and serialOrLicense optional, but allocationType is required for software products and serialOrLicense for hardware devices and for linked_to_license deallocations. A success answers HTTP 204 with no body, which StackJack reports as a bare success flag, so confirm the result with wg_list_asset_allocations.
wg_get_asset_allocation_summary details
wg_get_asset_allocation_summary details
[WatchGuard Cloud] Returns your Service Provider inventory for one asset type, split by allocation status, so you can see what is still available to allocate. Reach for this first: it is the pool wg_allocate_assets draws from. The account in the path is your own Service Provider account, so leave accountId empty unless you are acting for another Service Provider account you manage - this is not the read for a managed account's own inventory, which is wg_list_asset_licenses. Software rows carry quantityTotal, quantityAvailable and quantityAllocated; device rows carry one entry per device. WatchGuard pages devices only, so limit and offset do nothing on software rows.
wg_list_asset_allocations details
wg_list_asset_allocations details
[WatchGuard Cloud] Returns what your Service Provider account has allocated out to the accounts you manage, one row per managed account and product. Reach for this first to find where a license went, and call it again after wg_allocate_assets, wg_deallocate_assets or either update verb to confirm the change - those writes answer only a success flag. The account in the path is your own Service Provider account, so leave accountId empty; accountType chooses which kind of managed account is listed. Each row carries the managed account's id and name with quantityTotal, subscriptionTotal and usage, so it is also the view that shows whether a customer is consuming more than it was allocated.
wg_list_asset_licenses details
wg_list_asset_licenses details
[WatchGuard Cloud] Returns the licenses and devices one account owns, each with its serial number or license key. This is the account's own inventory. Use wg_list_assigned_assets for what has been allocated to the account, and wg_list_asset_allocations for what your Service Provider account has allocated out to the accounts you manage. Unlike those two reads, the account in the path is the account being read, so name a managed account in accountId to read that customer's inventory and leave it empty for your own. Rows carry friendlyName, productName, licenseType, serialOrLicense and the expiry; serialOrLicense is the selector wg_deallocate_assets and wg_update_asset_by_serial_or_license take.
wg_list_assigned_assets details
wg_list_assigned_assets details
[WatchGuard Cloud] Returns the licenses and devices that have been allocated to one account, which is what that account can actually use. The mirror of wg_list_asset_licenses, which reads what the account owns rather than what was allocated to it; the two answer the same shape, so name the tool you meant. The account in the path is the account being read, so name a managed account in accountId to see what that customer holds and leave it empty for your own Service Provider account. Software rows carry productName, licenseType, quantityTotal or subscriptionTotal and the expiry; device rows carry the serial number, MAC address and model.
wg_update_asset_allocation_type details
wg_update_asset_allocation_type details
[WatchGuard Cloud] DESTRUCTIVE. Updates an existing software allocation - its quantity, its expiry, and the product or allocation type the entitlement sits on. The allocation being updated is selected entirely by the URL, and a different productName or allocationType in the body MOVES that allocation onto the new product or type rather than adding one; the body also replaces the quantity and the expiry outright, so read the current allocation with wg_list_asset_allocations first. The managed account whose allocation is being updated is the accountId INSIDE the body; the accountId argument is your own Service Provider account. Repeat the URL's productName and allocationType in the body to change only quantity and the expiry; send different ones to re-allocate. serialOrLicense is required when allocationType is linked_to_license. For Endpoint Security products that support modules you must include modules when you update a managed Subscriber account or your own Service Provider account, and for a managed Service Provider account you may send a single productName or a single module. A success answers only a bare success flag and nothing about the allocation, and WatchGuard reports export-compliance problems in a Warning response header this tool does not return. WatchGuard stops accepting this call after 17 September 2026 for accounts that have no company name, industry, first name, last name and full mailing address. The body is a JSON object whose fields are accountId, allocationExpiryDate, allocationExpiryType, allocationType, modules, productName, quantity, serialOrLicense; required: accountId, allocationType, productName.
wg_update_asset_by_serial_or_license details
wg_update_asset_by_serial_or_license details
[WatchGuard Cloud] DESTRUCTIVE. Updates an existing hardware allocation, which for a device means when the allocation expires. This replaces the allocation's expiry outright: allocationExpiryType custom with an earlier allocationExpiryDate ends the managed account's device allocation sooner, and WatchGuard publishes no undo. It does not move the device to another account - wg_deallocate_assets followed by wg_allocate_assets does that. The device is selected entirely by the URL, by product name plus its serial number or license key, and the managed account holding the allocation is the accountId INSIDE the body, not the accountId argument, which stays your own Service Provider account. Read the serial from wg_list_asset_licenses or wg_list_assigned_assets. A success answers only a bare success flag and nothing about the allocation, and WatchGuard reports export-compliance problems in a Warning response header this tool does not return. WatchGuard stops accepting this call after 17 September 2026 for accounts that have no company name, industry, first name, last name and full mailing address. The body is a JSON object whose fields are accountId, allocationExpiryDate, allocationExpiryType; required: accountId, allocationExpiryType.
AuthPoint MFA
wg_authenticate_authpoint_otp details
wg_authenticate_authpoint_otp details
[WatchGuard Cloud] DESTRUCTIVE. Validates the six-digit one-time password a person read from their AuthPoint authenticator, against the RESTful API Client resource you name. This submits a real person's one-time password - and their password when the policy pairs the two - as a live authentication attempt against their account, so never call it to test or guess a code. Call wg_evaluate_authpoint_authentication_policy first: its policyResponse.otp says whether this person is allowed to authenticate this way, and policyResponse.password says whether the same sign-in also needs their password. Only login and otp are required - the password is sent when the access policy pairs the two. Success is a 200 carrying authenticationResult AUTHORIZED and nothing else; a wrong code and an unknown resource or user both come back as errors rather than as a negative result. The body is a JSON object whose fields are login, originIpAddress, otp, password; required: login, otp.
wg_authenticate_authpoint_password details
wg_authenticate_authpoint_password details
[WatchGuard Cloud] DESTRUCTIVE. Validates a person's AuthPoint password against the RESTful API Client resource you name. This submits a real person's password to AuthPoint as a live authentication attempt, so repeated calls count against that person and can lock them out. Never call it to test or guess a password. This is the password factor only. wg_evaluate_authpoint_authentication_policy reports which methods that person's access policy allows, and when it reports another method alongside the password, finish the sign-in with wg_authenticate_authpoint_otp or wg_start_authpoint_push_transaction. Success is a 200 carrying authenticationResult AUTHORIZED; a wrong password and an unknown resource or user both come back as errors rather than as a negative result. The body is a JSON object whose fields are login, originIpAddress, password; required: login, password.
wg_authenticate_authpoint_without_authenticator details
wg_authenticate_authpoint_without_authenticator details
[WatchGuard Cloud] DESTRUCTIVE. Validates the Forgot Token verification and activation codes for a person and turns Forgot Token mode ON, which lets them authenticate without their authenticator for the number of hours you send. This lowers a real person's multi-factor protection: for the whole interval you send, they can authenticate without their authenticator, and WatchGuard publishes no call to end it early. Confirm an operator actually issued the verification code before you call it. All five body fields are required. The verificationCode is the six-digit value an operator generates in the AuthPoint management UI and gives to the person; the activationCode is any six-digit number your side generates and shows to them so they can read it back to that operator; interval is the number of HOURS Forgot Token mode stays on, as the operator authorized it. Success is a 200 carrying authenticationResult AUTHORIZED. While Forgot Token mode is on, wg_evaluate_authpoint_authentication_policy reports isInForgotToken true for that person. WatchGuard publishes no call to switch it off again - it lapses when the interval runs out - so send the interval the operator actually authorized. The body is a JSON object whose fields are activationCode, interval, login, password, verificationCode; required: activationCode, interval, login, password, verificationCode.
wg_evaluate_authpoint_authentication_policy details
wg_evaluate_authpoint_authentication_policy details
[WatchGuard Cloud] DESTRUCTIVE. Asks AuthPoint whether a named person can authenticate through the RESTful API Client resource you name, and which methods their access policy allows - password, OTP, QR code and push. It changes no configuration and reads no secret, and it is still marked destructive under this connector's human-reaching rule: every AuthPoint call names a real person and acts on their live ability to authenticate. Reach for this first: policyResponse.password, .otp, .qrCode and .push decide whether to follow with wg_authenticate_authpoint_password, wg_authenticate_authpoint_otp or wg_start_authpoint_push_transaction, and the rest of the answer says WHY someone cannot authenticate - hasPolicy, isAllowedToAuthenticate, isBlocked, isInQuarantine, isOverallocated, isInSafeLocation and isInForgotToken. Those four policy members are BOOLEANS about what is permitted; they never carry the person's password or one-time password. Send originIpAddress or WatchGuard cannot evaluate the safe locations configured for that person's group. A person or resource WatchGuard does not know answers 404. Every tool in this family names a RESTful API Client resource created in AuthPoint, so the family is reachable only on an account that has the AuthPoint product. The body is a JSON object whose fields are login, originIpAddress; required: login.
wg_get_authpoint_transaction details
wg_get_authpoint_transaction details
[WatchGuard Cloud] Reads back an AuthPoint push transaction by its transaction id to see whether the person approved it. This is the read-back for wg_start_authpoint_push_transaction: keep the transactionId that call answered with, because WatchGuard publishes no way to list transactions. A 200 carrying pushResult AUTHORIZED means the person approved the notification. While they have not answered yet WatchGuard answers 202 - a SUCCESS whose body is a problem-details object rather than a result - so read that as still waiting and call again instead of treating it as a failure. A denial answers 403, an unknown transaction 404 and a failed push 412, and those three reach you as errors.
wg_request_authpoint_qrcode details
wg_request_authpoint_qrcode details
[WatchGuard Cloud] DESTRUCTIVE. Validates the six-digit verification code a person read back after scanning an AuthPoint QR code, which closes the QR code leg of a sign-in. This is a live authentication attempt against a real person's account, and the verification code it carries is single use: a failure counts against that person and the QR code has to be generated again. Despite this tool's name it does NOT generate a QR code. wg_start_authpoint_push_transaction with type QRCODE generates one and answers the transactionId and the command to render; this call validates what the person read back after scanning it, quoting that same transactionId. Success is a 200 carrying authenticationResult AUTHORIZED; a wrong or expired verification code comes back as an error. The body is a JSON object whose fields are login, originIpAddress, qrCodeResponse, transactionId; required: login, qrCodeResponse, transactionId.
wg_start_authpoint_push_transaction details
wg_start_authpoint_push_transaction details
[WatchGuard Cloud] DESTRUCTIVE. Starts an AuthPoint multi-factor transaction for a person: type PUSH sends an approval notification to their phone, type QRCODE generates a QR code for them to scan. A PUSH interrupts a real person on their phone and asks them to approve a sign-in, so a repeated or mistaken call is an unexpected MFA prompt - send it only for a sign-in that person is actually making. It answers transactionId, plus command when the type is QRCODE - the value to render as the QR code, which is that person's challenge and belongs on their screen only. Follow a PUSH with wg_get_authpoint_transaction, which reads that transactionId back and answers 202 while the person has not responded; follow a QRCODE with wg_request_authpoint_qrcode, which validates the six-digit code they read back, quoting the same transactionId. clientInfoRequest is required and describes the device the person is authenticating FROM - machineName, osVersion and domain. The password is sent only when the access policy pairs it with this method, which wg_evaluate_authpoint_authentication_policy reports. The body is a JSON object whose fields are clientInfoRequest, login, originIpAddress, password, type; required: clientInfoRequest, login, type.
Operators
wg_create_operators details
wg_create_operators details
[WatchGuard Cloud] DESTRUCTIVE. Creates one or more WatchGuard Cloud operators, each with a role, in the account its own element names. This creates real WatchGuard Cloud operators with the role you name and emails them, so it is a privilege grant as well as an account creation. The whole array is applied in one call and StackJack neither inspects nor filters what it carries, so send only the operators you mean to create. WatchGuard answers a transaction id rather than the affected operators; read the per-operator outcome back with wg_get_operator_transaction_status. The body is a JSON array whose fields are accountId, email, firstName, lastName, password, phone, role, username; required: accountId, email, firstName, lastName, phone, role, username.
wg_delete_operators details
wg_delete_operators details
[WatchGuard Cloud] DESTRUCTIVE. Deletes operators from a WatchGuard Cloud account. This removes the named operators' access to the account. WatchGuard offers no undo. The whole array is applied in one call and StackJack neither inspects nor filters what it carries, so confirm every username with wg_list_operators first. WatchGuard answers a transaction id rather than the affected operators; read the per-operator outcome back with wg_get_operator_transaction_status. The route is a POST because WatchGuard models the batch in a request body, not because it is reversible. The body is a JSON array whose fields are accountId, username; required: accountId, username.
wg_get_operator_transaction_status details
wg_get_operator_transaction_status details
[WatchGuard Cloud] Returns the per-operator outcome of an operator create, update or delete batch. This is the read-back for wg_create_operators, wg_update_operators and wg_delete_operators, each of which answers a transaction id rather than a result. The response carries transaction_status, one entry per operator in the batch with its own status, username and error, so a batch can succeed for some operators and fail for others — read every entry rather than the envelope's status.
wg_list_operators details
wg_list_operators details
[WatchGuard Cloud] Lists the operators of a WatchGuard Cloud account with their contact details and MFA status. Start here: this is the only read that names an account's operators, and the usernames it returns are what wg_update_operators and wg_delete_operators select on. The account argument IS the account_id query parameter this API requires, so leaving it empty lists your own account's operators. Each entry carries accountId, email, firstName, lastName, phone, mfa and username — WatchGuard does not return the operator's ROLE here, so there is no read-back for a role set by wg_update_operators. WatchGuard declares no paging on this route, so one call returns the WHOLE collection for the account; on a large estate expect a large result.
wg_update_operators details
wg_update_operators details
[WatchGuard Cloud] DESTRUCTIVE. Updates existing WatchGuard Cloud operators, including the role they hold in the account. The body carries the operator role, so one call can raise an existing operator's privileges. The whole array is applied in one call and StackJack neither inspects nor filters what it carries. WatchGuard answers a transaction id rather than the affected operators; read the per-operator outcome back with wg_get_operator_transaction_status. wg_list_operators does not return an operator's role, so there is no read-back for the role this sets. The body is a JSON array whose fields are accountId, firstName, lastName, phone, role, username; required: accountId, username.
Portal Accounts
wg_create_portal_account details
wg_create_portal_account details
[WatchGuard Cloud] DESTRUCTIVE. Creates a new tier-1 partner account and an associated user. This provisions a real tier-1 partner account in the WatchGuard Portal together with its first user, and WatchGuard emails that person either way: supply userInfo.password and the 201 reports in emailSent whether the account email went out, omit it and WatchGuard sends a password reset email to userInfo.email. This API publishes no call that deletes the account or the user afterwards, so confirm the company and the person with whoever owns the relationship first. This is not the tool that adds a customer under you: wg_create_managed_account creates a managed account inside your own WatchGuard Cloud tenancy, while this one creates a top-level tier-1 partner account with its own first user. The accountId argument does not name the account being created and is not part of the URL — it only selects the account this call is authorized as — and the new account's ID comes back in the response beside accountCreated, regionSet and emailSent, where regionSet reports whether accountInfo.region (APAC, AMERICAS or EUROPE, the geographic region WatchGuard records for the company) was set on the new account. WatchGuard documents 409 Conflict beside the 201 and does not name the conflicting field, and the specification makes no idempotency promise, so do not repeat this call blind after an error. The body is a JSON object whose fields are accountInfo, userInfo; required: accountInfo, userInfo.
wg_get_portal_account details
wg_get_portal_account details
[WatchGuard Cloud] Retrieves whether the specified account ID is an existing Partner account. The whole answer is one field: WatchGuard replies {"isPartner": true} or {"isPartner": false} and returns nothing about the account itself, so read the account record — name, type, contacts, addresses — with wg_get_account and use this only to settle whether an ID belongs to a WatchGuard Partner. The ID is a WatchGuard Portal account ID of, in the vendor's own wording, at least 11 or 12 characters, letters, numbers and dashes only, beginning ACC-, for example ACC-12345678. WatchGuard documents 400 Bad Request and 404 Not Found beside the 200 and does not say which an unknown but well-formed ID gets, so read any error as no answer rather than as isPartner false. The ID you name is also the account this call is authorized as, so name your own account or one you manage — list them with wg_list_managed_accounts — and leave it empty to ask about your own.
Activations
wg_activate_products details
wg_activate_products details
[WatchGuard Cloud] DESTRUCTIVE. Redeems activation keys to activate hardware devices and software licenses on the account, and WatchGuard publishes no call that reverses it. An activation key is spent the moment WatchGuard accepts the batch: the call answers 202 Accepted and the activations then run asynchronously, so there is no later point at which an agent can stop one. Check every activationKey, parentSerialNumber and parentLicenseKey before you call this, and read the batch back with wg_get_activation_batch_status rather than posting it a second time - the specification publishes no idempotency key. WatchGuard answers with an activations array rather than a result: each entry carries batchId, the batch status (Created, Processing, Complete or CompleteWithErrors), a statusUrl and the batchItems it created, so a 202 means accepted, not activated. Take batchId into wg_get_activation_batch_status to see which line items succeeded and why one failed; wg_list_recent_activations finds the batch again later, inside its 30-day window. Each entry of the body takes either deviceDetails, for hardware and virtual appliances, or saasDetails, for software licenses. The body is a JSON object whose fields are activations.
wg_get_activation_batch_status details
wg_get_activation_batch_status details
[WatchGuard Cloud] Returns every line item of one activation batch, with its status and the errors WatchGuard recorded, selected by the batch ID. The batchId comes from the activations[].batchId that wg_activate_products answered, or from results[].batchId in wg_list_recent_activations. Each entry of results is one line item: lineItemId, the activationKey it redeemed, status - the specification's line-item vocabulary is Created, Queued, Pending, Success and Failed - created, lastModified, and an errors array whose errorType names why a failed item failed. The batch runs asynchronously, so a batch still sitting at Created or Processing answers differently a moment later; poll this read instead of posting the activation again. The response is credential material: results[].activationKey is the redeemable license key itself, so keep the body out of anywhere you would not put a license key.
wg_list_recent_activations details
wg_list_recent_activations details
[WatchGuard Cloud] Lists the account's activation batches from the last 30 days, one entry per batch. This is the read to reach for first, and the only way to find a batchId after the fact: WatchGuard keeps a 30-day window and an older activation is not in this response at all. Each entry is a batch rather than a line item - activationStatus (Created, Processing, Complete or CompleteWithErrors), batchId, created, lastModified, lineItemCount and firstLineItem, which is only the FIRST item of the batch - so a batch whose lineItemCount is above 1 is incomplete here, and its remaining items come from wg_get_activation_batch_status with that batchId. The response is credential material: firstLineItem.activationKey is the redeemable license key itself.
More in Tools Reference
Atera ToolsAuvik ToolsAvanan (Check Point Harmony Email) ToolsConnectWise Sell ToolsStill need help? Ask the team