Skip to main content

CLI Reference

The pan-scm-cli command-line interface provides a structured set of commands for managing resources in Palo Alto Networks Strata Cloud Manager.

Command Structure​

All commands follow this pattern:

scm <action> <category> <resource> [name] [options]
ComponentDescriptionExamples
<action>Operation to performset, delete, load, show, backup, move
<category>Category of resourceobject, network, security, sase
<resource>Specific resource typeaddress, zone, rule
[name]Positional resource name (required for set/delete/move; optional for show)web-server, Allow-Web
[options]Resource-specific parameters--folder, --file
note

All show commands default to listing all items when no NAME argument is provided.

Objects​

Commands for managing configuration objects.

ResourcePageOperations
Addressaddressset, delete, load, show, backup
Address Groupaddress-groupset, delete, load, show, backup
Applicationapplicationset, delete, load, show, backup
Application Filterapplication-filterset, delete, load, show, backup
Application Groupapplication-groupset, delete, load, show, backup
Dynamic User Groupdynamic-user-groupset, delete, load, show, backup
External Dynamic Listexternal-dynamic-listset, delete, load, show, backup
HIP Objecthip-objectset, delete, load, show, backup
HIP Profilehip-profileset, delete, load, show, backup
HTTP Server Profilehttp-server-profileset, delete, load, show, backup
Log Forwarding Profilelog-forwarding-profileset, delete, load, show, backup
Quarantined Devicequarantined-deviceshow
Regionregionshow
Schedulescheduleshow
Serviceserviceset, delete, load, show, backup
Service Groupservice-groupset, delete, load, show, backup
Syslog Server Profilesyslog-server-profileset, delete, load, show, backup
Tagtagset, delete, load, show, backup
tip

Bulk operations (load, backup) use YAML files. See individual resource pages for file format details.

Security​

Commands for managing security policies and profiles.

ResourcePageOperations
Security Ruleruleset, delete, load, show
Anti-Spyware Profileanti-spyware-profileset, delete, load, show, backup
App Override Ruleapp-override-ruleshow
Authentication Ruleauthentication-ruleshow
Decryption Profiledecryption-profileset, delete, load, show, backup
Decryption Ruledecryption-ruleshow
DNS Security Profiledns-security-profileshow
URL Access Profileurl-access-profileshow
URL Categoryurl-categoryshow
Vulnerability Protection Profilevulnerability-protection-profileshow
Wildfire Antivirus Profilewildfire-antivirus-profileshow

Network​

Commands for managing network configurations.

ResourcePageOperations
Security Zonesecurity-zoneset, delete, load, show, backup
Aggregate Interfaceaggregate-interfaceshow
BGP Address Family Profilebgp-address-family-profileshow
BGP Auth Profilebgp-auth-profileshow
BGP Filtering Profilebgp-filtering-profileshow
BGP Redistribution Profilebgp-redistribution-profileshow
BGP Route Mapbgp-route-mapshow
BGP Route Map Redistributionbgp-route-map-redistributionshow
DHCP Interfacedhcp-interfaceshow
Ethernet Interfaceethernet-interfaceshow
IKE Crypto Profileike-crypto-profileshow
IKE Gatewayike-gatewayshow
IPsec Crypto Profileipsec-crypto-profileshow
Layer2 Subinterfacelayer2-subinterfaceshow
Layer3 Subinterfacelayer3-subinterfaceshow
Loopback Interfaceloopback-interfaceshow
NAT Rulenat-ruleshow
OSPF Auth Profileospf-auth-profileshow
Route Access Listroute-access-listshow
Route Prefix Listroute-prefix-listshow
Tunnel Interfacetunnel-interfaceshow
VLAN Interfacevlan-interfaceshow

SASE / Deployment​

Commands for managing SASE deployment configurations.

ResourcePageOperations
Bandwidth Allocationbandwidthset, delete, load, show
BGP Routingbgp-routingshow
Internal DNS Serverinternal-dns-servershow
Network Locationnetwork-locationshow
Remote Networkremote-networkset, delete, load, show, backup
Service Connectionservice-connectionset, delete, load, show, backup

Identity​

Commands for managing identity and authentication configurations.

ResourcePageOperations
Authentication Profileauthentication-profileshow
Kerberos Server Profilekerberos-server-profileshow
LDAP Server Profileldap-server-profileshow
RADIUS Server Profileradius-server-profileshow
SAML Server Profilesaml-server-profileshow
TACACS Server Profiletacacs-server-profileshow

Mobile Agent​

Commands for managing GlobalProtect mobile agent configurations.

ResourcePageOperations
Agent Versionagent-versionshow
Auth Settingauth-settingshow

Setup​

Commands for managing setup and organizational configurations.

ResourcePageOperations
Devicedeviceshow
Folderfoldershow
Labellabelshow
Snippetsnippetshow
Variablevariableshow

Operational Commands​

CommandPageDescription
CommitcommitPush candidate configurations to running
JobsjobsMonitor and manage configuration jobs
InsightsinsightsQuery SASE health and connectivity data
ContextcontextManage authentication contexts

Global Options​

Options that apply to all commands:

OptionDescription
--helpShow help message for any command
--version, -VShow the CLI version information
--regionOverride the SCM API region for this invocation

Output Formats​

Every show command accepts --output / -o to choose the rendering:

FormatDescription
table (default)Human-readable rich table or detail view
jsonMachine-readable JSON on stdout (pipe-safe)
yamlMachine-readable YAML on stdout (pipe-safe)

Data goes to stdout and status messages go to stderr, so machine formats pipe cleanly:

scm show object address --folder Texas --output json | jq '.[].name'

Mock Mode​

Set SCM_MOCK=1 to run without credentials or API calls (testing/demos). Missing credentials without explicit mock mode fail with exit code 1.