REST API

Available on: all plan levels

Firezone provides a REST API for programmatic access to your account. The API features endpoints for managing your entire Firezone account end-to-end, so you can achieve virtually any workflow you can perform in the admin portal.

OpenAPI spec

We publish an OpenAPI spec for the API that you can use to generate client libraries or explore the API interactively.

To generate an API token, see Get started with the REST API.

Device posture rules

The Policy endpoints accept device posture requirements in policy.postures, using the same JSON format as the admin portal. See the Device Posture JSON reference for the complete attribute list, operators, examples, and update behavior. Device posture requires a Business or Enterprise plan.

Rate limits

The API allows short bursts of requests, then enforces a sustained average rate. Each group of endpoints has a burst allowance — the most requests you can make back-to-back — and a sustained rate at which that allowance replenishes.

EndpointsScopeSustained rateBurst
All resource endpoints (actors, clients, policies, etc.)Per account1 req/sec20 requests

When a request is rate limited, the API responds with HTTP 429 Too Many Requests and a Retry-After header telling you how many seconds to wait before retrying. Code that calls the API should read this header and wait at least that long before issuing the next request.


Need help? See all support options.