REST API
Available on: all plan levels
Firezone provides a REST API for programmatic access to your account. The API features endpoints for managing your entire Firezone account end-to-end, so you can achieve virtually any workflow you can perform in the admin portal.
OpenAPI spec
We publish an OpenAPI spec for the API that you can use to generate client libraries or explore the API interactively.
- Download the spec at https://rest-api.firezone.dev/openapi.json.
- View the spec with a Swagger UI web interface at https://rest-api.firezone.dev/swaggerui.
To generate an API token, see Get started with the REST API.
Device posture rules
The Policy endpoints accept device posture requirements in policy.postures,
using the same JSON format as the admin portal. See the
Device Posture JSON reference for the complete
attribute list, operators, examples, and update behavior. Device posture
requires a Business or Enterprise plan.
Rate limits
The API allows short bursts of requests, then enforces a sustained average rate. Each group of endpoints has a burst allowance — the most requests you can make back-to-back — and a sustained rate at which that allowance replenishes.
| Endpoints | Scope | Sustained rate | Burst |
|---|---|---|---|
| All resource endpoints (actors, clients, policies, etc.) | Per account | 1 req/sec | 20 requests |
When a request is rate limited, the API responds with HTTP
429 Too Many Requests and a Retry-After header telling you how many seconds
to wait before retrying. Code that calls the API should read this header and
wait at least that long before issuing the next request.
Need help? See all support options.