Skip to main content
Connector guides

Connect WatchGuard Cloud

WatchGuard Cloud is WatchGuard's single management plane for its whole product line — Firebox firewalls, FireCloud, Endpoint Security, AuthPoint multi-factor authentication, WatchGuard NDR, and…

Written By Christopher Scaminaci

Last updated 6 days ago

WatchGuard Cloud is WatchGuard's single management plane for its whole product line — Firebox firewalls, FireCloud, Endpoint Security, AuthPoint multi-factor authentication, WatchGuard NDR, and ThreatSync, the layer that correlates detections from all of them into one incident. It is also where your subscriptions, licenses and operators live. StackJack talks to it through WatchGuard's own public APIs, the same ones behind the console you already use, and covers all of them.

Connecting WatchGuard Cloud to StackJack gives your AI assistant a family of wg_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Work ThreatSync incidents — list and read the correlated incidents WatchGuard raises across Firebox, endpoints and the network together, read the comment trail and the response history, and add to both
  • Report on endpoints — device inventory, protection status, installed software, missing patches, license position, unmanaged devices found on the network, and the security events behind them
  • Show risk — the company risk summary, which risk factors are detected and on how many devices, and how detections have trended over the period
  • Follow up on work — the task history behind every scan, patch installation and IOC search, down to which devices a particular run reached
  • Report on Firebox — the Executive and Security dashboards: what went through the firewall and what it blocked, which is exactly the material for a quarterly review
  • Investigate the network — the WatchGuard NDR asset inventory with each asset's threat score, and the Smart Alerts raised against them
  • Work across customers — list the accounts you manage and run any of the above against one of them
  • Manage Firebox configuration — firewall policies, the exception lists (blocked sites, botnet sites, geolocation, files, intrusion-prevention signatures and WebBlocker), interfaces and branch-office VPN tunnels, the users and authentication servers a Firebox trusts, certificates, and the deployment that pushes saved changes out to the firewalls
  • Manage FireCloud — the same exception families for WatchGuard's cloud-delivered firewall
  • Handle subscriptions and licensing — your subscriptions and contracts, the product catalog, which customer a license is allocated to, and product activation
  • Administer accounts and operators — partner portal accounts, the operators who sign in to WatchGuard Cloud, and the roles they hold
  • Work with AuthPoint — read the multi-factor policy that applies to a user and drive the authentication flows themselves
  • Check whether a WatchGuard service is up — one tool covers every WatchGuard service; pick the service you are asking about. It reports the service's own status, not whether your credentials still work
  • Respond (on Pro plans) — run a ThreatSync response action, isolate an endpoint or return it to the network, start an immediate scan, restart a device, close a Smart Alert, and manage the accounts and assets themselves

How StackJack authenticates to WatchGuard Cloud

WatchGuard gives you three values rather than two: an Access ID, its Password, and a separate API Key. All three appear on the Managed Access page in WatchGuard Cloud once API access is switched on.

The Access ID and Password get StackJack a session. The API Key travels alongside it on every single request, and a request with a valid session and no API Key is refused. This is the one thing about WatchGuard that surprises people: the API Key is a different value from the Access ID, and putting the Access ID in the API Key box fails in exactly the same way as a wrong password.

Sessions last an hour and StackJack renews them for you. There is nothing to rotate on a schedule and nothing to re-authorize.

Pick your region

WatchGuard runs the Americas, Europe and Asia Pacific as separate services. Credentials issued in one are rejected by the others, and the rejection looks identical to a wrong password — so this is worth getting right first time.

Your region is in the base address shown on your Managed Access page. It carries one of three words: usa for the Americas, deu for Europe, jpn for Asia Pacific. Pick the matching option in StackJack. StackJack stores your choice rather than an address, so the connection cannot drift onto the wrong region later.

Steps

  1. Turn on API access in WatchGuard Cloud. It is off until you enable it, and nothing below exists until you do — the credentials and the base address only appear afterwards. You need to be an account owner or administrator.
  2. Open Administration, then Managed Access. This one page carries everything you need.
  3. Copy the Access ID and Password. WatchGuard issues read-write and read-only pairs. Choose read-only if you only want reporting. Choose read-write if you want your assistant to close incidents, isolate endpoints or manage accounts — a read-only pair refuses every write no matter which tools you allow.
  4. Copy the API Key. Same page, different value. Check it twice.
  5. Note your account ID. It looks like ACC-1234567 or WGC-1-123abc456. StackJack checks the connection by reading this account back, and it is the starting point for finding the accounts you manage.
  6. Enter everything in StackJack. Open Connectors, choose WatchGuard Cloud, paste the Access ID, Password, API Key and account ID, pick your region, and run Test Connection. StackJack checks all of them together, so a failure means one of the five is wrong.

What to know before your AI uses this connector

Working across the accounts you manage

If you are a Service Provider, every WatchGuard tool takes an optional account ID. Leave it out and the tool works on your own account; supply one and it works on that customer's.

WatchGuard asks for permission per account before StackJack can act on one, and StackJack does that for you and holds a separate session per account — so one customer's session can never be used for another customer's request. The practical effect is only that the first call to a new customer is slightly slower than the rest.

Start with the managed-accounts list. It is the only place those account IDs come from, and it is a Free-tier read.

Some tools change live security

These need the Pro tier and are marked destructive, which means your AI application may ask you to confirm before running one — whether it does depends on that application's own settings. See Destructive tools and confirmation.

  • Isolating an endpoint takes the machine off the network. It is the right answer to a live compromise and the wrong answer to almost everything else: shared drives, line-of-business applications and remote access all stop, and the person using it notices within seconds.
  • Stopping isolation is also marked destructive, and deliberately. It reads like an undo, but the machine was quarantined because something was found on it, and putting it back before that is resolved re-exposes the network.
  • Uninstalling protection leaves a device unprotected and no longer reporting. Re-protecting it means building an installer and running it on the machine.
  • A ThreatSync response action runs real remediation — blocking, quarantining, stopping a process — on live systems, and there is no undo.
  • Restarting a device closes whatever the person at the keyboard had open. Use the countdown.
  • Deleting a managed account removes that customer's whole tenancy, and there is an option that removes every account beneath it as well. This is the most dangerous thing in the connector.
  • Deploying a Firebox configuration is the moment changes reach real firewalls. Everything else you edit on a Firebox is saved in WatchGuard Cloud and changes nothing until this runs — which is also why the deployment is the call to be careful with, not the edit before it.
  • Installing a certificate replaces what your firewalls present to clients, and adding one stores a private key in the account.
  • Creating or updating an operator grants someone access to WatchGuard Cloud and emails them. Updating one can also raise the role they already hold.
  • Creating a portal account provisions a real partner account and emails its first user.
  • Activating products consumes activation keys against serial numbers. WatchGuard publishes no way to reverse it.
  • Setting a Firebox's template subscriptions unsubscribes it from every template you leave out — an empty list unsubscribes it from all of them.

Starting a scan is the exception: it creates a scan task and destroys nothing, so it is not marked destructive. It is the safest first response to a suspicion. It does use the devices' processors while it runs, so an estate-wide scan during working hours will be noticed.

Some updates replace the whole record

Updating a managed account, a WatchGuard NDR asset, the endpoint risk configuration, a firewall policy, an exception, a branch-office VPN tunnel or a deployment's schedule replaces what is stored rather than merging into it. A field left out is cleared, not kept, and for the risk configuration a factor left out of the list stops being reported at all — so the posture looks better while nothing has changed on any device.

Ask your assistant to read the current record first and send it back complete with only the intended change. Each of these tools says so in its own description.

Closing a Smart Alert is worth one more look. It is ordinary triage and is not marked destructive, but two of its options change what happens in future: one authorizes the activity so similar traffic stops raising alerts, and another closes every matching alert at the same time. Leave both alone unless you mean them.

Some answers contain secrets

A handful of WatchGuard records carry a working credential inside them, and WatchGuard returns the whole record. Reading your Firebox users returns their passwords. Reading a branch-office VPN tunnel returns its pre-shared key — and so does creating, changing or deleting one, because WatchGuard answers those with the tunnel it just saved or removed. Certificates behave the same way and can carry a private key. Networks can carry a broadband or dynamic-DNS password, activation records carry a redeemable license key, and a content-filtering rule can carry its override password.

StackJack knows which tools those are and keeps their answers out of the places results are otherwise kept: they are never saved to a file and handed back as a link, and they are never recorded for troubleshooting. What StackJack cannot control is what happens after your AI application receives the answer. Treat a reply from one of those tools the way you would treat the password itself — do not paste it into a ticket, a chat channel or a document. Each of those tools says so in its own description.

Reports come one view at a time

The Firebox dashboards return one view per call — top blocked countries, top applications, and so on. Ask for the views you want in turn rather than expecting one call to return the whole dashboard.

Tool reference

See the generated WatchGuard Cloud tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

WatchGuard publishes no rate limit for its API, so StackJack paces requests conservatively on its own and backs off when WatchGuard asks it to, which usually makes a wide report slower rather than failed. Pacing smooths a burst; it does not guarantee that every call arrives. Gathering a report across many managed accounts at once is the shape most likely to meet it, because each account needs its own session — ask for one account at a time. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.

Large lists are returned in pages of up to 100 records. Some WatchGuard reads stop at 3,000 records however you ask, so narrow by device, date or search text rather than paging through an entire estate.

Most of the Firebox and FireCloud configuration lists are the exception: WatchGuard offers no paging on them, so a list returns the whole collection in one answer, and StackJack does not invent a page size WatchGuard would ignore. The current Firebox exception lists are the ones that do page, with a row limit and a "start after this exception" marker. On a large firewall a policy or network list can be big enough that StackJack hands your assistant a temporary download link instead of the text — ask for one Firebox at a time where you can.

Troubleshooting

"Credentials rejected" or a sign-in failure. Check the API Key box first — it is a different value from the Access ID, WatchGuard needs both on every request, and the two mistakes look identical. Then check the region matches the base address on your Managed Access page. Re-copy all three values before re-issuing anything.

Reads work, writes are refused. You copied the read-only pair. A read-only credential refuses every write no matter which tools you allow in StackJack. Copy the read-write pair from the Managed Access page instead.

A managed account is refused. Check the account ID came from your managed-accounts list rather than being typed by hand, and that it is an account you actually manage. An account that has been moved to a different Service Provider stops being reachable immediately.

Nothing works and the credentials look right. Confirm API access is still enabled in WatchGuard Cloud. It can be switched off, and when it is, the credentials stop working without changing.

Changing the region asks for the secrets again. That is deliberate. Every value is required each time you save this connector, so a save can never quietly replace a stored key with a blank one.

WatchGuard Cloud tools

wg_ · 232 tools · Free 130 · Pro 102

ThreatSync Incidents

ToolWhat it does
wg_create_incident_comment
Pro · Write
Adds a comment to a ThreatSync incident.
wg_delete_incident_comment
Pro · Destructive
DESTRUCTIVE.
wg_get_incident
Free · Read-only
Returns one ThreatSync incident by ID, optionally with its actions and comments inline.
wg_get_incident_action
Free · Read-only
Returns one response action on one ThreatSync incident, with its full detail.
wg_list_incident_actions
Free · Read-only
Lists the response actions recorded against one ThreatSync incident — what was attempted, by whom and how it ended.
wg_list_incident_comments
Free · Read-only
Lists the analyst comments on one ThreatSync incident — the written record of what a human concluded, which is usually the fastest way to understand an incident that has already been worked.
wg_list_incidents
Free · Read-only
Lists ThreatSync incidents — the correlated detections WatchGuard raises across Firebox, Endpoint Security and NDR together, which makes this the first place to look when asking what is happening on a customer's estate.
wg_update_incident_comment
Pro · Write
Replaces the text of one comment on a ThreatSync incident.
wg_update_incident_status
Pro · Write
Moves a ThreatSync incident to a different status, with an optional note.

ThreatSync Response Actions

ToolWhat it does
wg_list_actions
Free · Read-only
Lists ThreatSync response actions across the whole account rather than for one incident — the record of every remediation ThreatSync has run, which is what a monthly security review is built from.
wg_perform_action
Pro · Destructive
DESTRUCTIVE.
wg_perform_incident_action
Pro · Destructive
DESTRUCTIVE.
wg_submit_transaction
Pro · Destructive
DESTRUCTIVE.

Endpoint Devices and Inventory

ToolWhat it does
wg_get_endpoint_hardware_inventory
Free · Read-only
Returns the BIOS and hardware characteristics of one managed device.
wg_get_endpoint_installer_url
Free · Read-only
Returns a download URL for an endpoint installation package built with a specific managed configuration.
wg_get_endpoint_licenses
Free · Read-only
Returns the endpoint license position for an account — what is owned, what is used and what is left.
wg_link_endpoint_devices_to_configuration
Pro · Destructive
DESTRUCTIVE.
wg_list_endpoint_devices
Free · Read-only
Lists the devices WatchGuard Endpoint Security manages, with their addresses and operating systems.
wg_list_endpoint_managed_configurations
Free · Read-only
Lists the managed configurations of one type — the protection profiles devices are assigned to.
wg_list_endpoint_missing_patches
Free · Read-only
Lists published patches that are not installed on the customer's devices — the patch-gap report.
wg_list_endpoint_protection_status
Free · Read-only
Lists devices with their protection status — which agents are installed, up to date and actually protecting the machine.
wg_list_endpoint_software_inventory
Free · Read-only
Lists the software installed across the customer's managed devices.
wg_list_unmanaged_endpoint_devices
Free · Read-only
Lists devices discovered on the customer's network that WatchGuard does NOT manage — the gap between what is on the network and what is protected.
wg_scan_endpoint_devices_now
Pro · Write
Starts an immediate malware scan on the named devices.
wg_send_endpoint_device_action
Pro · Destructive
DESTRUCTIVE.
wg_uninstall_endpoint_protection
Pro · Destructive
DESTRUCTIVE.

Endpoint Isolation

ToolWhat it does
wg_isolate_endpoint_devices
Pro · Destructive
DESTRUCTIVE.
wg_stop_endpoint_device_isolation
Pro · Destructive
DESTRUCTIVE.

Endpoint Risk and Security Events

ToolWhat it does
wg_get_endpoint_company_risk_summary
Free · Read-only
Returns the company-wide risk summary — the one-screen posture answer for an account, and the right place to start a quarterly review before drilling into individual risks.
wg_get_endpoint_risk_configuration
Free · Read-only
Returns the current risk configuration: which risk factors are switched on and at what severity.
wg_get_endpoint_risk_statistics
Free · Read-only
Returns risk detections over time — how many of each type were detected across the period, which is the trend line a customer wants beside a point-in-time summary.
wg_get_endpoint_security_event_counters
Free · Read-only
Returns counts of detected security events by type.
wg_get_endpoint_security_overview
Free · Read-only
Returns the security overview counters for a period — the headline detection numbers for an account, and the natural companion to the company risk summary in a customer report.
wg_list_endpoint_detected_risks
Free · Read-only
Returns a count of affected devices for each type of risk detected — which risks exist and how widespread each one is.
wg_list_endpoint_device_risks
Free · Read-only
Lists devices with the risks detected on each, by risk level — the device-level view behind the company risk summary.
wg_list_endpoint_security_events
Free · Read-only
Lists security events of one type over a period — malware, exploits, blocked programs and the rest, one code per type.
wg_update_endpoint_risk_configuration
Pro · Destructive
DESTRUCTIVE.

Endpoint Tasks

ToolWhat it does
wg_get_endpoint_task_details
Free · Read-only
Returns the definition of one endpoint task — what it was set up to do and against which devices.
wg_get_endpoint_task_job_results
Free · Read-only
Returns what one repetition of an endpoint task actually found — the detections from a scan, the patches applied by an installation.
wg_get_endpoint_task_job_status
Free · Read-only
Returns the per-device status of one repetition of an endpoint task — which devices the run reached, which are still pending and which failed.
wg_list_endpoint_task_jobs
Free · Read-only
Lists the repetitions of one endpoint task — a recurring task runs many times, and each run has its own job ID.
wg_list_endpoint_tasks
Free · Read-only
Lists the endpoint tasks created in an account — scans, disinfections, patch installations and IOC searches.

Accounts and Managed Accounts

ToolWhat it does
wg_create_managed_account
Pro · Destructive
DESTRUCTIVE.
wg_delete_managed_account
Pro · Destructive
DESTRUCTIVE.
wg_get_account
Free · Read-only
Returns one WatchGuard Cloud account's information.
wg_list_managed_accounts
Free · Read-only
Lists the accounts you manage.
wg_update_managed_account
Pro · Destructive
DESTRUCTIVE.

Firebox Reports

ToolWhat it does
wg_get_firebox_executive_report
Free · Read-only
Returns one view of the Firebox Executive Dashboard — the traffic-side report a customer sees in a quarterly review: top applications, top destinations, top clients and so on.
wg_get_firebox_security_report
Free · Read-only
Returns one view of the Firebox Security Dashboard — what the firewall BLOCKED over the period: blocked countries, botnet sites, malware, attacks and the rest.

NDR Assets

ToolWhat it does
wg_create_ndr_asset
Pro · Write
Records a new asset in WatchGuard NDR — typically something NDR has not discovered by itself, such as a device on a segment it cannot see.
wg_delete_ndr_asset
Pro · Destructive
DESTRUCTIVE.
wg_get_ndr_asset
Free · Read-only
Returns one WatchGuard NDR asset in full — its addresses, roles, importance, threat score and when it was first and last seen.
wg_list_ndr_assets
Free · Read-only
Lists the assets WatchGuard NDR knows about on the customer's network — what it has seen, what it believes each thing is, and each asset's threat score.
wg_update_ndr_asset
Pro · Destructive
DESTRUCTIVE.

NDR Smart Alerts

ToolWhat it does
wg_close_ndr_smart_alert
Pro · Write
Closes a WatchGuard NDR Smart Alert with a documented reason.
wg_get_ndr_smart_alert
Free · Read-only
Returns one WatchGuard NDR Smart Alert in full — the network detection, what it was raised on and why.

Platform

ToolWhat it does
wg_check_service_health
Free · Read-only
Returns the health probe of one WatchGuard Cloud API.

Firebox Deployments

ToolWhat it does
wg_delete_firebox_deployment_transaction
Pro · Destructive
DESTRUCTIVE.
wg_deploy_firebox_configuration
Pro · Destructive
DESTRUCTIVE.
wg_disable_firebox_global_exceptions
Pro · Destructive
DESTRUCTIVE.
wg_enable_firebox_global_exceptions
Pro · Destructive
DESTRUCTIVE.
wg_get_firebox_deployment_transaction
Free · Read-only
Reads one deployment transaction record by its id, the status of a single configuration push to a single Firebox.
wg_list_firebox_deployment_transactions
Free · Read-only
Lists the deployment transaction records for the account, one record per Firebox per configuration push, each with its status.
wg_update_firebox_deployment_transaction
Pro · Destructive
DESTRUCTIVE.

Firebox Authentication

ToolWhat it does
wg_get_firebox_auth_group
Free · Read-only
Reads one Firebox authentication group, the umbrella group a firewall policy matches users against, by object id.
wg_get_firebox_authpoint_user_group
Free · Read-only
Reads one AuthPoint user or group reference held in Firebox configuration, by object id.
wg_get_firebox_saml_user_group
Free · Read-only
Reads one SAML user or group reference held in Firebox configuration, by object id.
wg_get_firebox_user
Free · Read-only
Reads one Firebox local user account by object id.
wg_get_firebox_user_group
Free · Read-only
Reads one Firebox local user group by object id.
wg_list_firebox_auth_groups
Free · Read-only
Lists the Firebox authentication groups, the umbrella groups a firewall policy matches users against, for the account, or for one Firebox or one template.
wg_list_firebox_authpoint_user_groups
Free · Read-only
Lists the AuthPoint users and groups this Firebox configuration references, for the account, or for one Firebox or one template.
wg_list_firebox_saml_user_groups
Free · Read-only
Lists the SAML users and groups this Firebox configuration references, for the account, or for one Firebox or one template.
wg_list_firebox_user_groups
Free · Read-only
Lists the Firebox local user groups, whose members are Firebox users, for the account, or for one Firebox or one template.
wg_list_firebox_users
Free · Read-only
Lists the Firebox local user accounts for the account, or for one Firebox or one template.

Firebox Exceptions

ToolWhat it does
wg_create_firebox_blocked_site_exception
Pro · Destructive
DESTRUCTIVE.
wg_create_firebox_botnet_site_exception
Pro · Write
Creates a new botnet site exception.
wg_create_firebox_file_exception
Pro · Write
Creates a new file exception.
wg_create_firebox_geolocation_exception
Pro · Write
Creates a new Geolocation exception.
wg_create_firebox_ips_signature_exception
Pro · Write
Creates a new IPS signature exception.
wg_create_firebox_webblocker_exception
Pro · Destructive
DESTRUCTIVE.
wg_delete_firebox_blocked_site_exception
Pro · Destructive
DESTRUCTIVE.
wg_delete_firebox_botnet_site_exception
Pro · Destructive
DESTRUCTIVE.
wg_delete_firebox_file_exception
Pro · Destructive
DESTRUCTIVE.
wg_delete_firebox_geolocation_exception
Pro · Destructive
DESTRUCTIVE.
wg_delete_firebox_ips_signature_exception
Pro · Destructive
DESTRUCTIVE.
wg_delete_firebox_webblocker_exception
Pro · Destructive
DESTRUCTIVE.
wg_get_firebox_blocked_site_exception
Free · Read-only
Retrieves the specified blocked sites exception.
wg_get_firebox_botnet_site_exception
Free · Read-only
Retrieves the specified botnet site exception.
wg_get_firebox_file_exception
Free · Read-only
Retrieves the specified file exception.
wg_get_firebox_geolocation_exception
Free · Read-only
Retrieves the specified Geolocation exception.
wg_get_firebox_ips_signature_exception
Free · Read-only
Retrieves the specified IPS signature exception.
wg_get_firebox_webblocker_exception
Free · Read-only
Retrieves the specified WebBlocker exception.
wg_list_firebox_blocked_site_exceptions
Free · Read-only
Lists the blocked sites exceptions saved in the WatchGuard Cloud account.
wg_list_firebox_blocked_site_exceptions_v1
Free · Read-only
DEPRECATED by WatchGuard: use wg_list_firebox_blocked_site_exceptions instead, which reads the same saved blocked sites exceptions.
wg_list_firebox_botnet_site_exceptions
Free · Read-only
Lists the botnet site exceptions saved in the WatchGuard Cloud account.
wg_list_firebox_botnet_site_exceptions_v1
Free · Read-only
DEPRECATED by WatchGuard: use wg_list_firebox_botnet_site_exceptions instead, which reads the same saved botnet site exceptions.
wg_list_firebox_exceptions
Free · Read-only
Lists every exception saved in the WatchGuard Cloud account in one response - blocked sites, botnet sites, files, Geolocation, IPS signatures and WebBlocker together.
wg_list_firebox_exceptions_v1
Free · Read-only
DEPRECATED by WatchGuard: use wg_list_firebox_exceptions instead, which reads the same saved exceptions of all six kinds.
wg_list_firebox_file_exceptions
Free · Read-only
Lists the file exceptions saved in the WatchGuard Cloud account.
wg_list_firebox_file_exceptions_v1
Free · Read-only
DEPRECATED by WatchGuard: use wg_list_firebox_file_exceptions instead, which reads the same saved file exceptions.
wg_list_firebox_geolocation_exceptions
Free · Read-only
Lists the Geolocation exceptions saved in the WatchGuard Cloud account.
wg_list_firebox_geolocation_exceptions_v1
Free · Read-only
DEPRECATED by WatchGuard: use wg_list_firebox_geolocation_exceptions instead, which reads the same saved Geolocation exceptions.
wg_list_firebox_ips_signature_exceptions
Free · Read-only
Lists the IPS signature exceptions saved in the WatchGuard Cloud account.
wg_list_firebox_ips_signature_exceptions_v1
Free · Read-only
DEPRECATED by WatchGuard: use wg_list_firebox_ips_signature_exceptions instead, which reads the same saved IPS signature exceptions.
wg_list_firebox_webblocker_exceptions
Free · Read-only
Lists the WebBlocker exceptions saved in the WatchGuard Cloud account.
wg_list_firebox_webblocker_exceptions_v1
Free · Read-only
DEPRECATED by WatchGuard: use wg_list_firebox_webblocker_exceptions instead, which reads the same saved WebBlocker exceptions.
wg_update_firebox_blocked_site_exception
Pro · Destructive
DESTRUCTIVE.
wg_update_firebox_botnet_site_exception
Pro · Destructive
DESTRUCTIVE.
wg_update_firebox_file_exception
Pro · Destructive
DESTRUCTIVE.
wg_update_firebox_geolocation_exception
Pro · Destructive
DESTRUCTIVE.
wg_update_firebox_ips_signature_exception
Pro · Destructive
DESTRUCTIVE.
wg_update_firebox_webblocker_exception
Pro · Destructive
DESTRUCTIVE.

Firebox Networking

ToolWhat it does
wg_create_firebox_bovpn_p1_shared_settings
Pro · Write
Creates the shared Phase 1 (IKE) settings object for one Firebox.
wg_create_firebox_bovpn_tunnel
Pro · Destructive
DESTRUCTIVE.
wg_delete_firebox_bovpn_tunnel
Pro · Destructive
DESTRUCTIVE.
wg_delete_firebox_bovpn_tunnel_by_name
Pro · Destructive
DESTRUCTIVE.
wg_get_firebox_bovpn_p1_shared_settings
Free · Read-only
Retrieves the shared Phase 1 (IKE) settings that a Firebox's branch office VPN tunnels inherit.
wg_get_firebox_bovpn_tunnel
Free · Read-only
Retrieves one branch office VPN IPSec tunnel, selected by its object id in the path.
wg_get_firebox_network
Free · Read-only
Retrieves one network configuration object of a Firebox, selected by its object id.
wg_get_firebox_sdwan
Free · Read-only
Retrieves one SD-WAN configuration object of a Firebox, selected by its object id.
wg_list_firebox_bovpn_tunnels
Free · Read-only
Lists the branch office VPN (BOVPN) IPSec tunnels of the account, or of one Firebox.
wg_list_firebox_networks
Free · Read-only
Lists the network configuration objects of the account, or of one Firebox or one account-level template.
wg_list_firebox_sdwans
Free · Read-only
Lists the SD-WAN configuration objects of the account, or of one Firebox or one account-level template.
wg_patch_firebox_bovpn_tunnel
Pro · Write
Updates only the routes list or the endpoint certificates of one branch office VPN IPSec tunnel, selected by its object id in the path.
wg_patch_firebox_bovpn_tunnel_by_name
Pro · Write
Updates only the routes list or the endpoint certificates of one branch office VPN IPSec tunnel, selected by the id or the name in the body.
wg_update_firebox_bovpn_p1_shared_settings
Pro · Destructive
DESTRUCTIVE.
wg_update_firebox_bovpn_tunnel
Pro · Destructive
DESTRUCTIVE.
wg_update_firebox_bovpn_tunnel_by_name
Pro · Destructive
DESTRUCTIVE.

Firebox Policies

ToolWhat it does
wg_create_firebox_policy
Pro · Write
Creates a firewall policy on a Firebox.
wg_delete_firebox_policy
Pro · Destructive
DESTRUCTIVE.
wg_get_firebox_alias
Free · Read-only
Returns one firewall alias and the members it resolves to.
wg_get_firebox_content_filtering_rule
Free · Read-only
Returns one content filtering rule with its application control and WebBlocker category actions.
wg_get_firebox_policy
Free · Read-only
Returns one firewall policy in full, including the version number an update has to send back.
wg_get_firebox_policy_group
Free · Read-only
Returns one firewall policy group with the ordered list of policies inside it.
wg_get_firebox_snat_action
Free · Read-only
Returns one static NAT (SNAT) action with its external-to-internal address rules.
wg_get_firebox_traffic_shaping_rule
Free · Read-only
Returns one traffic shaping rule with the bandwidth it limits or guarantees.
wg_get_firebox_traffic_type
Free · Read-only
Returns one traffic type with the protocols and ports it matches.
wg_list_firebox_aliases
Free · Read-only
Lists the firewall aliases defined for the account, or for one Firebox or template.
wg_list_firebox_content_filtering_rules
Free · Read-only
Lists the content filtering rules, the application control and WebBlocker category actions, for the account or for one Firebox or template.
wg_list_firebox_policies
Free · Read-only
Lists the firewall policies WatchGuard Cloud holds for the account, or for one Firebox when you name a device.
wg_list_firebox_policy_groups
Free · Read-only
Lists the firewall policy groups defined for the account, or for one Firebox or template.
wg_list_firebox_snat_actions
Free · Read-only
Lists the static NAT (SNAT) actions defined for the account, or for one Firebox or template.
wg_list_firebox_traffic_shaping_rules
Free · Read-only
Lists the traffic shaping rules defined for the account, or for one Firebox or template.
wg_list_firebox_traffic_types
Free · Read-only
Lists the traffic types, the named protocol and port sets, available for the account or for one Firebox or template.
wg_set_firebox_policy_enabled
Pro · Destructive
DESTRUCTIVE.
wg_update_firebox_policy
Pro · Destructive
DESTRUCTIVE.

Firebox System

ToolWhat it does
wg_create_firebox_certificate
Pro · Destructive
DESTRUCTIVE.
wg_delete_firebox_certificate
Pro · Destructive
DESTRUCTIVE.
wg_get_firebox_certificate
Free · Read-only
Retrieves one certificate, selected by its object id in the path.
wg_get_firebox_schedule
Free · Read-only
Retrieves one time schedule, selected by its object id in the path.
wg_install_firebox_certificate
Pro · Destructive
DESTRUCTIVE.
wg_list_firebox_certificates
Free · Read-only
Lists the certificates stored for the account, or the certificates on one Firebox when you name a device.
wg_list_firebox_schedules
Free · Read-only
Lists the time schedules defined for the account, for one Firebox, or for one Firebox template.
wg_list_firebox_template_subscriptions
Free · Read-only
Lists the Firebox templates available to the account, the templates one Firebox subscribes to, or the Fireboxes subscribed to one template.
wg_set_firebox_template_subscription
Pro · Destructive
DESTRUCTIVE.

FireCloud Exceptions

ToolWhat it does
wg_create_firecloud_blocked_site_exception
Pro · Destructive
DESTRUCTIVE.
wg_create_firecloud_botnet_site_exception
Pro · Write
Creates a new FireCloud botnet site exception.
wg_create_firecloud_file_exception
Pro · Write
Creates a new FireCloud file exception.
wg_create_firecloud_geolocation_exception
Pro · Write
Creates a new FireCloud Geolocation exception.
wg_create_firecloud_https_exception
Pro · Write
Creates a new FireCloud HTTPS decryption exception.
wg_create_firecloud_ips_signature_exception
Pro · Write
Creates a new FireCloud IPS signature exception.
wg_create_firecloud_webblocker_exception
Pro · Destructive
DESTRUCTIVE.
wg_delete_firecloud_blocked_site_exception
Pro · Destructive
DESTRUCTIVE.
wg_delete_firecloud_botnet_site_exception
Pro · Destructive
DESTRUCTIVE.
wg_delete_firecloud_file_exception
Pro · Destructive
DESTRUCTIVE.
wg_delete_firecloud_geolocation_exception
Pro · Destructive
DESTRUCTIVE.
wg_delete_firecloud_https_exception
Pro · Destructive
DESTRUCTIVE.
wg_delete_firecloud_ips_signature_exception
Pro · Destructive
DESTRUCTIVE.
wg_delete_firecloud_webblocker_exception
Pro · Destructive
DESTRUCTIVE.
wg_get_firecloud_blocked_site_exception
Free · Read-only
Retrieves the specified FireCloud blocked sites exception.
wg_get_firecloud_botnet_site_exception
Free · Read-only
Retrieves the specified FireCloud botnet site exception.
wg_get_firecloud_file_exception
Free · Read-only
Retrieves the specified FireCloud file exception.
wg_get_firecloud_geolocation_exception
Free · Read-only
Retrieves the specified FireCloud Geolocation exception.
wg_get_firecloud_https_exception
Free · Read-only
Retrieves the specified FireCloud HTTPS decryption exception.
wg_get_firecloud_ips_signature_exception
Free · Read-only
Retrieves the specified FireCloud IPS signature exception.
wg_get_firecloud_webblocker_exception
Free · Read-only
Retrieves the specified FireCloud WebBlocker exception.
wg_list_firecloud_blocked_site_exceptions
Free · Read-only
Retrieves all blocked sites exceptions in the specified FireCloud account.
wg_list_firecloud_botnet_site_exceptions
Free · Read-only
Retrieves all botnet site exceptions in the specified FireCloud account.
wg_list_firecloud_exceptions
Free · Read-only
Retrieves all exceptions in the specified FireCloud account.
wg_list_firecloud_file_exceptions
Free · Read-only
Retrieves all file exceptions in the specified FireCloud account.
wg_list_firecloud_geolocation_exceptions
Free · Read-only
Retrieves all Geolocation exceptions in the specified FireCloud account.
wg_list_firecloud_https_exceptions
Free · Read-only
Retrieves all HTTPS decryption exceptions in the specified FireCloud account.
wg_list_firecloud_ips_signature_exceptions
Free · Read-only
Retrieves all IPS signature exceptions in the specified FireCloud account.
wg_list_firecloud_webblocker_exceptions
Free · Read-only
Retrieves all WebBlocker exceptions in the specified FireCloud account.
wg_update_firecloud_blocked_site_exception
Pro · Destructive
DESTRUCTIVE.
wg_update_firecloud_botnet_site_exception
Pro · Destructive
DESTRUCTIVE.
wg_update_firecloud_file_exception
Pro · Destructive
DESTRUCTIVE.
wg_update_firecloud_geolocation_exception
Pro · Destructive
DESTRUCTIVE.
wg_update_firecloud_https_exception
Pro · Destructive
DESTRUCTIVE.
wg_update_firecloud_ips_signature_exception
Pro · Destructive
DESTRUCTIVE.
wg_update_firecloud_webblocker_exception
Pro · Destructive
DESTRUCTIVE.

Product Catalog

ToolWhat it does
wg_list_product_classifications
Free · Read-only
Returns all product classifications from the WatchGuard Product Catalog.
wg_list_product_families
Free · Read-only
Returns all product families from the WatchGuard Product Catalog.
wg_list_product_models
Free · Read-only
Returns device models from the WatchGuard Product Catalog that match the specified filters.
wg_list_product_service_suites
Free · Read-only
Returns a list of all WatchGuard service suites.
wg_list_products
Free · Read-only
Returns products from the WatchGuard Product Catalog that match the specified filters.

Subscriptions and Orders

ToolWhat it does
wg_cancel_subscription_contract
Pro · Destructive
DESTRUCTIVE.
wg_create_purchase_order
Pro · Destructive
DESTRUCTIVE.
wg_get_contract_drop_ship_info
Free · Read-only
Returns drop-ship information for the specified subscription contract.
wg_get_invoice
Free · Read-only
Returns the invoice with the specified invoice number.
wg_get_subscription_contract
Free · Read-only
Returns details of the subscription contract with the specified ID.
wg_list_contract_usage_details
Free · Read-only
Returns license usage information for tenant accounts.
wg_list_invoices
Free · Read-only
Returns summaries of all consolidated invoices generated between the specified dates.
wg_list_subscription_contracts
Free · Read-only
Returns summaries of subscription contracts created between the specified dates.
wg_resume_subscription_contract
Pro · Destructive
DESTRUCTIVE.
wg_set_contract_serial_number
Pro · Destructive
DESTRUCTIVE.
wg_suspend_subscription_contract
Pro · Destructive
DESTRUCTIVE.

Licenses and Allocations

ToolWhat it does
wg_allocate_assets
Pro · Destructive
DESTRUCTIVE.
wg_deallocate_assets
Pro · Destructive
DESTRUCTIVE.
wg_get_asset_allocation_summary
Free · Read-only
Returns your Service Provider inventory for one asset type, split by allocation status, so you can see what is still available to allocate.
wg_list_asset_allocations
Free · Read-only
Returns what your Service Provider account has allocated out to the accounts you manage, one row per managed account and product.
wg_list_asset_licenses
Free · Read-only
Returns the licenses and devices one account owns, each with its serial number or license key.
wg_list_assigned_assets
Free · Read-only
Returns the licenses and devices that have been allocated to one account, which is what that account can actually use.
wg_update_asset_allocation_type
Pro · Destructive
DESTRUCTIVE.
wg_update_asset_by_serial_or_license
Pro · Destructive
DESTRUCTIVE.

AuthPoint MFA

ToolWhat it does
wg_authenticate_authpoint_otp
Pro · Destructive
DESTRUCTIVE.
wg_authenticate_authpoint_password
Pro · Destructive
DESTRUCTIVE.
wg_authenticate_authpoint_without_authenticator
Pro · Destructive
DESTRUCTIVE.
wg_evaluate_authpoint_authentication_policy
Pro · Destructive
DESTRUCTIVE.
wg_get_authpoint_transaction
Free · Read-only
Reads back an AuthPoint push transaction by its transaction id to see whether the person approved it.
wg_request_authpoint_qrcode
Pro · Destructive
DESTRUCTIVE.
wg_start_authpoint_push_transaction
Pro · Destructive
DESTRUCTIVE.

Operators

ToolWhat it does
wg_create_operators
Pro · Destructive
DESTRUCTIVE.
wg_delete_operators
Pro · Destructive
DESTRUCTIVE.
wg_get_operator_transaction_status
Free · Read-only
Returns the per-operator outcome of an operator create, update or delete batch.
wg_list_operators
Free · Read-only
Lists the operators of a WatchGuard Cloud account with their contact details and MFA status.
wg_update_operators
Pro · Destructive
DESTRUCTIVE.

Portal Accounts

ToolWhat it does
wg_create_portal_account
Pro · Destructive
DESTRUCTIVE.
wg_get_portal_account
Free · Read-only
Retrieves whether the specified account ID is an existing Partner account.

Activations

ToolWhat it does
wg_activate_products
Pro · Destructive
DESTRUCTIVE.
wg_get_activation_batch_status
Free · Read-only
Returns every line item of one activation batch, with its status and the errors WatchGuard recorded, selected by the batch ID.
wg_list_recent_activations
Free · Read-only
Lists the account's activation batches from the last 30 days, one entry per batch.