Skip to main content
Connector guides

Connect Cisco Umbrella

Cisco Umbrella is a cloud-delivered security platform: DNS-layer security, a secure web gateway, a cloud-delivered firewall, and — as a separately-licensed add-on — the Investigate threat-intelligence…

Written By Christopher Scaminaci

Last updated 6 days ago

Cisco Umbrella is a cloud-delivered security platform: DNS-layer security, a secure web gateway, a cloud-delivered firewall, and — as a separately-licensed add-on — the Investigate threat-intelligence dataset. MSPs use it to enforce web and DNS policy, inspect traffic, and hunt threats across their client organizations.

Connecting Umbrella to StackJack gives your AI assistant a broad family of umb_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Deploy and manage networks, IPsec tunnels, sites, virtual appliances, roaming computers, network devices, internal networks, and internal domains
  • Control policy — read and edit destination (allow/block) lists and application lists, and attach or detach identities on deployment policies
  • Report on DNS, proxy, and firewall activity — top destinations, identities, and threats, request/category/bandwidth aggregations and summaries, App Discovery (shadow IT), and your own API-key usage
  • Administer the org — users, roles, and API keys
  • Manage provider consoles — the Managed Providers (Multi-Org/MSP) console and the Service-Provider/MSSP console: partner customer CRUD, packages and subscriptions, trial lifecycle, delegated access-requests, console branding, and provider-wide reporting
  • Investigate (Pro, license-gated) domains, IPs, and files against Cisco's threat-intelligence graph: WHOIS (history, by-nameserver, by-email, search), passive DNS, BGP routes, subdomains, co-occurrences, risk scores, and sample analysis
  • Act (on Pro plans) — create, update, and delete the deployment, policy, admin, and provider-console objects above

How StackJack authenticates to Cisco Umbrella

Umbrella issues API credentials as a pair, created together in the Umbrella dashboard: an API Key (the public identifier) and an API Key Secret (the private secret). StackJack Basic-authenticates that pair to mint a short-lived bearer token from POST https://api.umbrella.com/auth/v2/token, then caches it and re-mints it automatically before it expires — nothing for you to manage. There is no refresh token — recovery is always a fresh token request, so a revoked key fails closed on the next mint.

The base URL is fixed at https://api.umbrella.com for commercial orgs. (Umbrella for Government customers are on a separate host.) StackJack stores that default for you, so you normally leave the URL field blank.

One configured key pair mints one parent/provider access token in StackJack. Cisco also supports minting a child-organization token from provider credentials by sending X-Umbrella-OrgId during token creation, but StackJack does not currently collect or send that child ID. Operational tools therefore act in the configured credential's own parent/provider organization. Provider endpoints whose tools take a customerId still work with a provider-tier key carrying the required admin/config/reporting scopes. Configure a separate credential context if you need direct operational access as a child organization.

Before you begin

  • In StackJack: you need a role that can manage connectors — tenant Owner, a co-owner, or an Administrator.
  • In Umbrella: you need the Full Admin role to create an API key.
  • Decide which scopes you need. The scopes you grant the key gate what StackJack can do — see "Scopes drive tool access" below. Grant at least Deployments (read) even if you do not use Deployment tools, so save-time validation and later Re-test can validate.
  • Review Cisco's current Umbrella API authentication, getting-started, pagination, and rate-limit guidance.

Step 1 — Generate API credentials in Cisco Umbrella

  1. Sign in with the Full Admin role. Go to Admin → API Keys; in a Multi-org, MSP, or MSSP console, use Console Settings → API Keys.
  2. Select API Keys → Add and give the key a recognizable name and description.
  3. Choose the required resource scopes and Read-Only or Read / Write access. Add Investigate only if you hold that license.
  4. Choose an Expiry Date (or Never expire). Optionally add Network Restrictions for the public IP addresses or CIDRs allowed to use the key; Cisco permits up to ten entries. If you restrict the key, open a support ticket first to get StackJack's current outbound addresses for your region: they are not published, and a region move changes them.
  5. Create the key and copy the API Key and API Key Secret immediately. Cisco does not show the secret again.

Scopes drive tool access

A key's scopes decide which tools work. A key granted Read-Only on a family can run that family's read tools (the Free-tier surface) but cannot call its Pro write tools — a write attempt returns 403. If a Pro write tool 403s, re-issue the API key with the family's write scope (for example edit:admin for user and API-key writes); it is not a "connector not configured" error.

Include the Deployments (read) scope even if you do not use Deployments tools. Save-time validation and Re-test call a Deployments endpoint, so a key scoped only to another family can show Needs Attention while its in-scope tools still work. Adding Deployments read produces a clean whole-connector validation result.

Investigate requires a separate license

The umb_investigate_* threat-intelligence family queries Cisco's Investigate graph, which is a separately-purchased Umbrella Investigate add-on (a paid, tiered subscription). Without it — and without the Investigate scope on your key — those tools return 403/404. umb_investigate_samples additionally requires a Cisco Secure Malware Analytics license. Every other tool works with a standard Umbrella subscription. Investigate tools are read-only but ship on the Pro tier.

Step 2 — Add the credentials in StackJack

  1. In the StackJack portal, open Connectors.
  2. Select the Cisco Umbrella tile to open its details. Choose How To Connect to review the inline setup guide, or Configure to reveal the credential form in the drawer.
  3. Paste the API Key into the API Key field and the API Key Secret into the API Key Secret field. Leave the URL blank to use the commercial cloud (https://api.umbrella.com); set it only for Umbrella for Government.
  4. Click Save.

What happens when you save

  • The key and secret are stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
  • If this is the first time you configure Umbrella, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
  • StackJack immediately live-validates the credentials by minting a token and calling a Deployments read. Validation never blocks the save.
  • After saving, the form collapses and the connector drawer stays open. It shows Connected / Valid on success, or Needs Attention with Re-test and recovery guidance if validation failed.

Plans and available tools

  • Free includes Deployments, Policies, Reports, and Admin reads — networks, tunnels, sites, devices, destination lists, application lists, deployment policies, activity/aggregation/summary reports, App Discovery, API usage, users, roles, API-key metadata, and the Managed-Provider / Service-Provider console reads (customers, packages, subscriptions, branding, provider reporting).
  • Pro adds write and action tools (creates, updates, deletes, tag/identity/destination changes, provider-console management, and key/credential rotations) plus the read-only Investigate intelligence family.
  • Business offers the same tool set as Pro with a higher monthly call quota — it unlocks no additional tools.

See the generated Cisco Umbrella tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

Umbrella has no per-user OAuth (PKCE) sign-in, so there is no per-user attribution — all AI traffic uses the shared key pair on every tier. Current pricing and quotas are shown in the portal's Billing page and at checkout.

Safety note: several Pro tools delete or detach state and are irreversible — for example umb_delete_destination_list, umb_delete_roaming_computer, umb_delete_user, and umb_remove_destinations. Scope your AI's access deliberately: use the tool selections on the MCP Setup page and the Permissions page to enable only the actions you want an AI to take, and consider a read-only-scoped key unless you specifically need write tools.

Rate limits

Umbrella publishes different limits by scope and resource. General Admin, Deployments, and provider-console operations can be limited to 14 requests per minute per key, while Policies permits much more; Investigate also varies by license tier and endpoint. StackJack applies a 60-call-per-minute tenant pace and records upstream 429 backoff, but one generic limiter cannot model every family. Narrow large requests and honor the upstream retry delay when a lower family-specific quota is reached.

Pagination

Collection endpoints generally use one-based page plus limit; the default is up to 200 records. Maximums vary — for example, networks allow 1,000 while roaming computers and destination-list entries allow 100, and some endpoints are not paginated. Use each tool's schema and returned page metadata rather than assuming a universal page size.

Rotating or replacing the credentials

Umbrella reveals the API Key Secret only at creation, so if you lose it you must rotate rather than look it up. The lowest-risk approach is:

  1. Create a new key with the required scopes, expiry, and network restrictions, and copy its secret once.
  2. Update Connectors → Cisco Umbrella → Configure, save, and confirm Valid.
  3. Delete the old key only after the replacement works. If you instead use Umbrella's Refresh Key action, the old pair stops working immediately, so update StackJack without delay.

Disconnecting Cisco Umbrella

StackJack's Disconnect action deletes its stored key pair and stops future calls. It does not delete or revoke the key in Umbrella. Remove that key separately under Admin → API Keys or Console Settings → API Keys if no other integration uses it. Subscription changes are separate from credential removal.

Several customers

Some MSPs need one Cisco Umbrella connection per customer, console or region. StackJack can hold several named connections of one connector, and your AI names the one it wants on each call. See Several connections of one connector.

Troubleshooting

SymptomLikely causeWhat to do
Needs Attention immediately after savingKey or Secret mis-pasted, Deployments read is absent, the key expired, or Network Restrictions reject StackJack's egressCorrect the key settings or pair, save, then use Re-test
Every Umbrella call fails after working previouslyThe key/secret was rotated, revoked, or expiredUpdate the credential in StackJack with a current pair
A write tool returns 403 while reads workThe API key is Read-Only for that familyRe-issue the key with the family's write scope (e.g. edit:deployments, edit:policies, edit:admin)
All umb_investigate_* tools return 403/404The Umbrella Investigate add-on isn't licensed, or the key lacks the Investigate scopePurchase the Investigate license and add the Investigate scope to the key
Write or Investigate tools missing from your AI's tool listConnector is on the Free tier, or the tools aren't selected for your clientUpgrade the Umbrella connector plan and check your tool selections on the MCP Setup page
Configuring for Umbrella for Government fails against the default hostThe Gov cloud uses a separate API hostEnter your Umbrella for Government host in the URL field instead of leaving it blank
Parent/provider tools work but operational calls target the wrong orgCisco's child-token flow requires X-Umbrella-OrgId, which StackJack does not currently collect during token mintingConfigure credentials for the organization the operational tools should act in; continue using customerId provider tools from the provider context

Cisco Umbrella tools

umb_ · 233 tools · Free 140 · Pro 93

Admin

ToolWhat it does
umb_create_user
Pro · Write
Create an administrator user in your Umbrella organization.
umb_delete_user
Pro · Destructive
Delete an administrator user from your Umbrella organization by userId (from umb_list_users).
umb_get_user
Free · Read-only
Get a single administrator user by id.
umb_list_roles
Free · Read-only
List the administrator roles available in your Umbrella organization.
umb_list_users
Free · Read-only
List the administrator users in your Umbrella organization.
umb_rotate_s3_bucket_key
Pro · Destructive
Rotate the S3 bucket access key for your organization's managed S3 log storage.

API Keys

ToolWhat it does
umb_create_api_key
Pro · Write
Create an API key.
umb_delete_api_key
Pro · Destructive
Delete an API key by apiKeyId (from umb_list_api_keys).
umb_get_api_key
Free · Read-only
Get a single API key by apiKeyId (from umb_list_api_keys).
umb_list_api_keys
Free · Read-only
List the API keys created by your organization.
umb_refresh_api_key
Pro · Destructive
Refresh an API key, rotating its secret.
umb_update_api_key
Pro · Write
Update an API key's name, description, scopes, and allowed IPs.

Networks

ToolWhat it does
umb_create_internal_network
Pro · Write
Create an internal network.
umb_create_network
Pro · Write
Create a network (external/egress IP range).
umb_delete_internal_network
Pro · Destructive
Delete an internal network by its origin id (internalNetworkId, from umb_list_internal_networks).
umb_delete_network
Pro · Destructive
Delete a network by networkId (from umb_list_networks).
umb_get_internal_network
Free · Read-only
Get a single internal network by its origin id (internalNetworkId, from umb_list_internal_networks).
umb_get_network
Free · Read-only
Get a single network by networkId (from umb_list_networks).
umb_list_internal_network_policies
Free · Read-only
List the policies applied to an internal network by its origin id (internalNetworkId, from umb_list_internal_networks).
umb_list_internal_networks
Free · Read-only
List the internal networks defined in your Umbrella deployment.
umb_list_network_policies
Free · Read-only
List the policies applied to a network by its networkId (from umb_list_networks).
umb_list_networks
Free · Read-only
List the networks (external/egress IP ranges) registered in your Umbrella deployment.
umb_update_internal_network
Pro · Write
Update an internal network.
umb_update_network
Pro · Write
Update a network.

Sites

ToolWhat it does
umb_create_site
Pro · Write
Create a site.
umb_delete_site
Pro · Destructive
Delete a site by siteId (from umb_list_sites).
umb_get_site
Free · Read-only
Get a single site by siteId (from umb_list_sites).
umb_list_sites
Free · Read-only
List the sites in your Umbrella organization.
umb_update_site
Pro · Write
Update a site.

Tunnels

ToolWhat it does
umb_create_tunnel
Pro · Write
Add a new network tunnel to the organization.
umb_delete_tunnel
Pro · Destructive
Permanently delete a network tunnel by its numeric id (from umb_list_tunnels).
umb_get_tunnel
Free · Read-only
Get a single network tunnel by its numeric id (from umb_list_tunnels).
umb_get_tunnel_events
Free · Read-only
Get recent events for a network tunnel by its numeric id (from umb_list_tunnels).
umb_get_tunnel_global_events
Free · Read-only
Get global events for a network tunnel (by numeric id, from umb_list_tunnels) filtered to a specific source IP.
umb_get_tunnel_state
Free · Read-only
Get the live state information for a single network tunnel by its numeric id (from umb_list_tunnels) — up/down status and connection detail for that one tunnel.
umb_list_tunnel_datacenters
Free · Read-only
List the IPsec-enabled Umbrella data centers available for tunnel termination.
umb_list_tunnel_policies
Free · Read-only
List the policies attached to a network tunnel by its numeric id (from umb_list_tunnels).
umb_list_tunnel_states
Free · Read-only
List the live state information for all network tunnels in the organization (up/down status and connection details across every tunnel).
umb_list_tunnels
Free · Read-only
List the network tunnels (IPsec) configured for the organization.
umb_rotate_tunnel_credentials
Pro · Destructive
Rotate the IPsec pre-shared key (PSK) credentials for a network tunnel by its numeric id (from umb_list_tunnels).
umb_update_tunnel
Pro · Write
Update a network tunnel by its numeric id (from umb_list_tunnels).

Internal Domains

ToolWhat it does
umb_add_internal_domains
Pro · Write
Add (create) an internal domain.
umb_delete_internal_domain
Pro · Destructive
Delete an internal domain by internalDomainId (from umb_list_internal_domains).
umb_get_internal_domain
Free · Read-only
Get a single internal domain by internalDomainId (from umb_list_internal_domains).
umb_list_internal_domains
Free · Read-only
List the internal domains configured for your Umbrella deployment (domains excluded from DNS redirection).
umb_update_internal_domain
Pro · Write
Update an internal domain.

Devices & Tags

ToolWhat it does
umb_add_tags_to_devices
Pro · Write
Associate a device tag with one or more devices.
umb_create_network_device
Pro · Write
Register a new network device (integrated router/firewall, e.g. Cisco ISR) in the organization.
umb_create_tag
Pro · Write
Create a new device tag in the organization.
umb_delete_network_device
Pro · Destructive
Permanently delete (deregister) a network device from the organization by its numeric originId (from umb_list_network_devices).
umb_delete_roaming_computer
Pro · Destructive
Permanently delete (deregister) a roaming computer from the organization by its deviceId (from umb_list_roaming_computers).
umb_delete_virtual_appliance
Pro · Destructive
Permanently delete a virtual appliance (VA) from the organization by its numeric originId (virtualApplianceId, from umb_list_virtual_appliances).
umb_get_network_device
Free · Read-only
Get a single network device by its numeric originId (from umb_list_network_devices).
umb_get_roaming_computer
Free · Read-only
Get a single roaming computer by its deviceId (from umb_list_roaming_computers).
umb_get_roaming_computers_orginfo
Free · Read-only
Get organization-level roaming-computer information (org-wide roaming deployment metadata).
umb_get_virtual_appliance
Free · Read-only
Get a single Umbrella virtual appliance by its numeric originId (from umb_list_virtual_appliances).
umb_list_network_device_policies
Free · Read-only
List the policies applied to a network device by its numeric originId (from umb_list_network_devices).
umb_list_network_devices
Free · Read-only
List the network devices (integrated routers/firewalls, e.g. Cisco ISR) registered in the organization.
umb_list_roaming_computers
Free · Read-only
List the roaming computers (Umbrella roaming client / SWG module devices) in the organization.
umb_list_tags
Free · Read-only
List the device tags defined in the organization.
umb_list_virtual_appliances
Free · Read-only
List the Umbrella virtual appliances (VAs) deployed in the organization.
umb_remove_tags_from_devices
Pro · Destructive
Remove a device tag association from one or more devices.
umb_update_network_device
Pro · Write
Update a network device by its numeric originId (from umb_list_network_devices).
umb_update_roaming_computer
Pro · Write
Update a roaming computer by its deviceId (a hex string, from umb_list_roaming_computers).
umb_update_virtual_appliance
Pro · Write
Update a virtual appliance (VA) by its numeric originId (virtualApplianceId, from umb_list_virtual_appliances).

Destination Lists

ToolWhat it does
umb_add_destinations
Pro · Write
Add destination entries to a destination list, identified by its numeric id (from umb_list_destination_lists).
umb_create_destination_list
Pro · Write
Create a destination list (allow or block list) in the organization.
umb_delete_destination_list
Pro · Destructive
Permanently delete a destination list from the organization by its numeric id (from umb_list_destination_lists).
umb_get_destination_list
Free · Read-only
Get a single destination list by its numeric id (from umb_list_destination_lists).
umb_list_destination_lists
Free · Read-only
List the destination lists (allow/block lists) in the organization.
umb_list_destinations
Free · Read-only
List the destination entries (domains, URLs, or IPs) inside a destination list, identified by its numeric id (from umb_list_destination_lists).
umb_remove_destinations
Pro · Destructive
Remove destination entries from a destination list, identified by its numeric id (from umb_list_destination_lists).
umb_update_destination_list
Pro · Write
Rename a destination list by its numeric id (from umb_list_destination_lists).

Deployment Policies

ToolWhat it does
umb_add_identity_to_policy
Pro · Write
Add an identity to a deployment policy.
umb_list_deployment_policies
Free · Read-only
List the Umbrella deployment policies.
umb_remove_identity_from_policy
Pro · Destructive
Remove an identity from a deployment policy.

Reports

ToolWhat it does
umb_list_identities
Free · Read-only
List the identities known to Umbrella reporting (used to interpret and filter other reports).
umb_report_activity
Free · Read-only
List all activity events (DNS, proxy, firewall, intrusion) within a time window.
umb_report_activity_amp_retrospective
Free · Read-only
List granular AMP retrospective (post-hoc malware detection) activity events within a time window.
umb_report_activity_dns
Free · Read-only
List DNS activity events within a time window.
umb_report_activity_firewall
Free · Read-only
List firewall activity events within a time window.
umb_report_activity_intrusion
Free · Read-only
List granular intrusion (IPS) activity events within a time window.
umb_report_activity_ip
Free · Read-only
List granular IP-layer activity events within a time window.
umb_report_activity_proxy
Free · Read-only
List proxy (secure web gateway) activity events within a time window.
umb_report_summary
Free · Read-only
Get an aggregate summary report (request totals with category and threat rollups) for a time window.
umb_report_threat_types
Free · Read-only
List the threat types Umbrella recognizes (a reference lookup; no time window or pagination).
umb_report_top_categories
Free · Read-only
List the content/security categories that received the most requests in a time window, in descending order.
umb_report_top_destinations_dns
Free · Read-only
List the top DNS destinations (domains) by request volume within a time window, in descending order.
umb_report_top_destinations_firewall
Free · Read-only
List the top firewall destinations by connection/request volume within a time window, in descending order.
umb_report_top_destinations_ip
Free · Read-only
List the top IP-layer (IP enforcement) destinations by request volume within a time window, in descending order.
umb_report_top_destinations_proxy
Free · Read-only
List the top proxy destinations by request volume within a time window, in descending order.
umb_report_top_identities
Free · Read-only
List the identities that made the most requests within a time window, in descending order.
umb_report_top_ips
Free · Read-only
List the top IP addresses by request volume within a time window.
umb_report_top_threats
Free · Read-only
Get the top threats (both DNS and proxy) within a time window, in descending order.
umb_report_total_requests
Free · Read-only
Get the total count of requests within a time window.
umb_report_total_requests_dns
Free · Read-only
Get the total count of DNS requests within a time window.
umb_report_total_requests_firewall
Free · Read-only
Get the total count of firewall events within a time window.
umb_report_total_requests_ip
Free · Read-only
Get the total count of IP-layer (IP enforcement) requests within a time window.
umb_report_total_requests_proxy
Free · Read-only
Get the total count of proxy requests within a time window.

App Discovery

ToolWhat it does
umb_appdiscovery_get_app_identities
Free · Read-only
List the identities (users/devices) observed using a discovered application.
umb_appdiscovery_get_app_risk
Free · Read-only
Get the risk assessment for a single discovered application: its risk score and the contributing risk attributes used to triage Shadow IT / SaaS exposure.
umb_appdiscovery_get_application
Free · Read-only
Get a single discovered cloud application by id, including its metadata used to triage Shadow IT / SaaS exposure.
umb_appdiscovery_get_protocol
Free · Read-only
Get a single application protocol by id.
umb_appdiscovery_list_application_attributes
Free · Read-only
List the attributes (security/compliance/business characteristics) of a discovered application.
umb_appdiscovery_list_application_categories
Free · Read-only
List the application categories used to classify discovered cloud apps.
umb_appdiscovery_list_applications
Free · Read-only
List cloud applications discovered in your Umbrella traffic (App Discovery / Shadow IT report).
umb_appdiscovery_list_protocol_identities
Free · Read-only
List the identities (users/devices) observed using a given application protocol.
umb_appdiscovery_list_protocols
Free · Read-only
List cloud application protocols observed in your Umbrella traffic.
umb_appdiscovery_update_app_label
Pro · Write
Set the review label / status on a discovered application (for example approve or tag it).
umb_appdiscovery_update_applications
Pro · Write
Bulk-set the review label / status on many discovered applications at once (collection-level PATCH — distinct from the single-item umb_appdiscovery_update_app_label).

API Usage

ToolWhat it does
umb_apiusage_keys
Free · Read-only
List Umbrella API usage attributed per API key over a date window (which keys made how many calls).
umb_apiusage_requests
Free · Read-only
List Umbrella API request counts over a date window, broken down by request.
umb_apiusage_responses
Free · Read-only
List Umbrella API response counts over a date window, broken down by HTTP response/status code.
umb_apiusage_summary
Free · Read-only
Get an aggregate summary of your organization's Umbrella API usage (total request counts and rollups) over a date window.

Investigate

ToolWhat it does
umb_investigate_bgp_routes_asn
Pro · Read-only
Get the CIDR prefixes and geo information advertised by an Autonomous System Number (ASN).
umb_investigate_bgp_routes_ip
Pro · Read-only
Get Autonomous-System information for an IPv4 address (ASN, CIDR, RIR, and owner/description).
umb_investigate_bulk_categorization
Pro · Read-only
Provide a list of domains and look up the status, and security and content category IDs for each domain.
umb_investigate_domain_categorization
Pro · Read-only
Look up the status, and security and content category IDs for the domain.
umb_investigate_domain_risk_score
Pro · Read-only
The Investigate Risk Score is based on an analysis of the lexical characteristics of the domain name and patterns in queries and requests to the domain.
umb_investigate_domain_security
Pro · Read-only
List multiple scores or security features for a domain.
umb_investigate_domain_volume
Pro · Read-only
List the query volume for a domain over the last 30 days.
umb_investigate_links
Pro · Read-only
List domains that co-occur within a small time window of the given domain (the true co-occurrence 'links' endpoint).
umb_investigate_pdns_domain
Pro · Read-only
The Passive DNS endpoint provides historical data from the Umbrella resolvers for domains, IPs, and other resource records.
umb_investigate_pdns_ip
Pro · Read-only
Get the Resource Record (RR) data for DNS responses, and categorization data, where the answer (or rdata) is the domain(s).
umb_investigate_pdns_raw
Pro · Read-only
Get Passive-DNS Resource Records matching raw rdata (for example TXT record contents).
umb_investigate_pdns_rr_domain
Pro · Read-only
Get Passive-DNS Resource Records (RRs) where the answer/rdata is the given domain — the answer-side view, distinct from umb_investigate_pdns_domain which returns query-side RRs on /pdns/name.
umb_investigate_related
Pro · Read-only
List the co-occurences for the specified domain.
umb_investigate_samples
Pro · Read-only
Specify a domain, IP, or URL.
umb_investigate_search
Pro · Read-only
List the newly seen domains that match a regular expression pattern.
umb_investigate_subdomains
Pro · Read-only
List known subdomains of a domain.
umb_investigate_timeline
Pro · Read-only
List the historical tagging timeline for a given IP, domain, or URL.
umb_investigate_top_million
Pro · Read-only
List the most seen domains in Umbrella.
umb_investigate_whois
Pro · Read-only
Get the WHOIS information for the specified email addresses, nameservers, and domains.
umb_investigate_whois_email
Pro · Read-only
List the domains registered by a registrant email address.
umb_investigate_whois_history
Pro · Read-only
List historical WHOIS records for a domain.
umb_investigate_whois_nameserver
Pro · Read-only
List the domains registered against a SINGLE nameserver (path parameter).
umb_investigate_whois_nameservers
Pro · Read-only
List the domains registered against a BATCH of nameservers.
umb_investigate_whois_search
Pro · Read-only
Regex-search WHOIS records by field (for example 'nameservers' or 'emails') matching a regular-expression pattern.

Managed Providers

ToolWhat it does
umb_create_managed_customer
Pro · Destructive
Create a customer under the Managed Providers (Multi-Org/MSP) console.
umb_delete_managed_customer
Pro · Destructive
Permanently delete a Managed Providers customer by customerId (from umb_list_managed_customers).
umb_get_managed_customer
Free · Read-only
Get a single Managed Providers customer by customerId (from umb_list_managed_customers).
umb_list_managed_customers
Free · Read-only
List the customers under your Umbrella Managed Providers (Multi-Org/MSP) console.
umb_update_managed_customer
Pro · Destructive
Update a Managed Providers customer by customerId (from umb_list_managed_customers).

Provider Customers

ToolWhat it does
umb_create_provider_customer
Pro · Destructive
Create a Service-Provider customer.
umb_delete_provider_customer
Pro · Destructive
Permanently delete a Service-Provider customer by customerId.
umb_get_provider_customer
Free · Read-only
Get one Service-Provider customer by customerId (from umb_list_provider_customers).
umb_get_provider_customer_packages
Free · Read-only
List the packages available when creating a Service-Provider customer.
umb_get_provider_customer_subscription
Free · Read-only
Get subscription details for a Service-Provider customer by customerId — package, seats, start/end dates, trial lifecycle, access-request state.
umb_list_provider_customers
Free · Read-only
List the customers under your Umbrella Service-Provider/MSSP console.
umb_update_provider_customer
Pro · Destructive
Update a Service-Provider customer by customerId (full replace).

Provider Trials & Access

ToolWhat it does
umb_convert_provider_customer_trial
Pro · Destructive
Irreversibly convert a trial to a paying customer by customerId.
umb_create_provider_access_request
Pro · Write
Request delegated access to a customer's Umbrella org by customerId.
umb_extend_provider_customer_trial
Pro · Write
Extend a customer's trial by customerId.
umb_get_provider_access_request
Free · Read-only
Get a delegated-access request by customerId and accessRequestId.
umb_get_provider_customer_trial_strength
Free · Read-only
Get a trial customer's engagement strength by customerId — customerLoggedIn, lastLoginDate, identitiesCreated, hasTraffic, trialStrength (Low/Medium/High/-).
umb_update_provider_access_request
Pro · Destructive
Advance a delegated-access request's state by customerId and accessRequestId.

Provider Deals & Organizations

ToolWhat it does
umb_get_provider_customer_deal
Free · Read-only
Get a customer deal by dealId.
umb_list_provider_customer_addresses
Free · Read-only
List Service-Provider customer addresses.
umb_list_provider_organizations
Free · Read-only
List the organizations visible to a provider-org member.
umb_reset_provider_customer_passwords
Pro · Destructive
Force a password reset for named admin accounts in a child (customer) org by customerId.
umb_update_provider_customer_deal
Pro · Write
Update a customer deal by dealId (full replace).

Provider Branding

ToolWhat it does
umb_create_provider_cname
Pro · Write
Create a console CNAME.
umb_create_provider_contact
Pro · Write
Create a console contact.
umb_create_provider_logo
Pro · Write
Upload a branding logo (multipart/form-data).
umb_delete_provider_cname
Pro · Destructive
Delete a console CNAME by cnameId.
umb_delete_provider_contact
Pro · Destructive
Delete a console contact by contactId.
umb_delete_provider_logo
Pro · Destructive
Delete a logo by logoId.
umb_get_provider_cname
Free · Read-only
Get one console CNAME by cnameId (from umb_list_provider_cnames).
umb_get_provider_contact
Free · Read-only
Get one console contact by contactId (from umb_list_provider_contacts).
umb_get_provider_logo
Free · Read-only
Get one logo's metadata by logoId (JSON, not binary).
umb_list_provider_cnames
Free · Read-only
List the console CNAMEs.
umb_list_provider_contacts
Free · Read-only
List console contacts (billing/support/report/…).
umb_list_provider_logos
Free · Read-only
List logo metadata (id, imageUrl, imageKey, token, enabled, brandingTypeId, timestamps) — JSON, not image bytes.
umb_update_provider_cname
Pro · Write
Update (full replace) a console CNAME by cnameId.
umb_update_provider_contact
Pro · Write
Update (full replace) a console contact by contactId.
umb_update_provider_logo
Pro · Write
Replace a logo by logoId (multipart/form-data, full replace).

Provider Reporting

ToolWhat it does
umb_create_provider_security_report
Pro · Write
Enqueue generation of a customer security report by customerId (Service-Provider/MSSP console).
umb_get_provider_console_data
Free · Read-only
Get the Service-Provider/MSSP console subscription summary — packageName, seatsTotal/seatsUsed, customerCount, status, rebillAt, expiresAt.
umb_get_provider_security_report
Free · Read-only
Fetch/poll the generated customer security report (Service-Provider/MSSP console).
umb_provider_report_categories
Free · Read-only
List the content categories available for provider (Service-Provider/MSSP console) reporting.
umb_provider_report_category_requests_by_org
Free · Read-only
Per-managed-customer content-category breakdown across all managed customer organizations (Service-Provider/MSSP console) over a from/to window.
umb_provider_report_deployments
Free · Read-only
Deployment status per managed customer organization over a from/to window (Service-Provider/MSSP console).
umb_provider_report_requests_by_category
Free · Read-only
Request totals by content category across all managed customer organizations (Service-Provider/MSSP console) over a from/to window.
umb_provider_report_requests_by_destination
Free · Read-only
Top destinations across all managed customer organizations (Service-Provider/MSSP console) over a from/to window.
umb_provider_report_requests_by_hour
Free · Read-only
Request totals bucketed by hour across all managed customer organizations (Service-Provider/MSSP console).
umb_provider_report_requests_by_org
Free · Read-only
Per-managed-customer request totals ({organization, counts:{total, totalblocked}}) over a from/to window (Service-Provider/MSSP console).
umb_provider_report_requests_by_timerange
Free · Read-only
Request totals bucketed by a timerange granularity across all managed customer organizations (Service-Provider/MSSP console).

Report Aggregations

ToolWhat it does
umb_report_bandwidth_by_hour
Free · Read-only
Get bandwidth usage bucketed by hour within a time window (secure web gateway / proxy traffic only).
umb_report_bandwidth_by_timerange
Free · Read-only
Get bandwidth usage bucketed by a configurable time range within a window (secure web gateway / proxy traffic only).
umb_report_categories_by_hour
Free · Read-only
Get request counts by hour and content/security category across all traffic types within a time window.
umb_report_categories_by_hour_by_type
Free · Read-only
Get request counts by hour and content/security category for a specific traffic type within a time window.
umb_report_categories_by_timerange
Free · Read-only
Get request counts by content/security category bucketed by a configurable time range across all traffic types within a window.
umb_report_categories_by_timerange_by_type
Free · Read-only
Get request counts by content/security category bucketed by a configurable time range for a specific traffic type within a window.
umb_report_requests_by_hour
Free · Read-only
Get request counts bucketed by hour across all traffic types within a time window.
umb_report_requests_by_hour_by_type
Free · Read-only
Get request counts bucketed by hour for a specific traffic type within a time window.
umb_report_requests_by_timerange
Free · Read-only
Get request counts bucketed by a configurable time range across all traffic types within a window.
umb_report_requests_by_timerange_by_type
Free · Read-only
Get request counts bucketed by a configurable time range for a specific traffic type within a window.
umb_report_top_categories_by_type
Free · Read-only
List the top content/security categories by request volume for a specific traffic type within a time window, in descending order.
umb_report_top_destinations
Free · Read-only
List the top destinations across all traffic types by request volume within a time window, in descending order.
umb_report_top_dns_query_types
Free · Read-only
List the top DNS query types (A, AAAA, MX, TXT, …) by request volume within a time window, in descending order.
umb_report_top_eventtypes
Free · Read-only
Get aggregated event-type counts within a time window (this endpoint takes no limit/offset).
umb_report_top_files
Free · Read-only
List the top files seen in proxy/SWG traffic by request volume within a time window, in descending order (proxy/SWG only).
umb_report_top_identities_by_type
Free · Read-only
List the identities that made the most requests for a specific traffic type within a time window, in descending order.
umb_report_top_ips_internal
Free · Read-only
List the top internal IP addresses by request volume within a time window (this endpoint takes no limit/offset).
umb_report_top_threat_types
Free · Read-only
List the top threat types across all traffic by volume within a time window, in descending order.
umb_report_top_threat_types_by_type
Free · Read-only
List the top threat types for a specific traffic type within a time window, in descending order.
umb_report_top_threats_by_type
Free · Read-only
List the top threats for a specific traffic type within a time window, in descending order.
umb_report_top_urls
Free · Read-only
List the top URLs (SWG/proxy traffic) by request volume within a time window, in descending order.

Report Summaries

ToolWhat it does
umb_report_applications
Free · Read-only
List the applications known to Umbrella reporting (a reference lookup used to interpret application fields in other reports).
umb_report_categories
Free · Read-only
List all content and security categories Umbrella recognizes (a reference lookup; no time window, no parameters, no pagination).
umb_report_deployment_status
Free · Read-only
Get deployment-status counts (how many requests came from fully vs partially protected identities) within a time window.
umb_report_get_identities_by_ids
Free · Read-only
Resolve a batch of identity IDs to their labels/metadata.
umb_report_get_identity
Free · Read-only
Get a single identity (label and metadata) by its identity ID.
umb_report_get_threat_name
Free · Read-only
Get a single threat name by its threat-name ID (for example 'WannaCry').
umb_report_get_threat_type
Free · Read-only
Get a single threat type by its threat-type ID (for example 'Ransomware').
umb_report_identity_distribution
Free · Read-only
Get the distribution of requests across identity types within a time window (all traffic types).
umb_report_identity_distribution_by_type
Free · Read-only
Get the distribution of requests across identity types within a time window, for a single traffic type (dns or proxy).
umb_report_summaries_by_category
Free · Read-only
Get per-category summaries (request totals with allowed/blocked rollups per content/security category) within a time window (all traffic types).
umb_report_summaries_by_category_by_type
Free · Read-only
Get per-category summaries within a time window, for a single traffic type (dns, proxy, or ip).
umb_report_summaries_by_destination
Free · Read-only
Get per-destination summaries (request totals with allowed/blocked rollups per destination) within a time window (all traffic types).
umb_report_summaries_by_destination_by_type
Free · Read-only
Get per-destination summaries within a time window, for a single traffic type (dns or proxy).
umb_report_summaries_by_rule_intrusion
Free · Read-only
Get intrusion (IPS) signature-list summaries within a time window — counts per signature list / rule.
umb_report_summary_by_type
Free · Read-only
Get a single aggregate summary object (request totals with allowed/blocked rollups) for a single traffic type (dns, proxy, firewall, or ip) within a time window.
umb_report_threat_names
Free · Read-only
List all threat names Umbrella recognizes (a reference lookup; no time window, no parameters, no pagination).

Application Lists

ToolWhat it does
umb_create_application_list
Pro · Write
Create an application list.
umb_delete_application_list
Pro · Destructive
Permanently delete an application list.
umb_get_application_list
Free · Read-only
Get a single application list by id, including its member application ids.
umb_get_applications_usage
Free · Read-only
Report where a set of applications is in use across policies.
umb_list_application_lists
Free · Read-only
List all application lists in the organization (named groupings of cloud applications used by web/SWG policies).
umb_update_application_list
Pro · Destructive
Replace an application list (full PUT, not a partial PATCH).

SWG Device Settings

ToolWhat it does
umb_list_swg_device_settings
Free · Read-only
List the per-device SWG (Secure Web Gateway) override settings for specific roaming devices.
umb_remove_swg_device_setting
Pro · Destructive
Remove the per-device SWG (Secure Web Gateway) override on specific roaming devices, reverting each device to the organization-level SWG setting.
umb_set_swg_device_setting
Pro · Write
Override the SWG (Secure Web Gateway) enablement on specific roaming devices, overriding the organization-level setting.