pan-os-python
Framework for interacting with Palo Alto Networks devices via API
Decision gist · record as of 2026-08-14
Yes, if you manage Palo Alto Networks devices and need programmatic control. The package is stable, actively maintained, has low install friction, and carries a permissive license. No known security vulnerabilities. Only caveat: you must have network access to a compatible PAN-OS device with API credentials to use it meaningfully.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires network connectivity to a Palo Alto Networks device (physical or virtualized firewall or Panorama) with API access enabled and valid credentials.
- Low friction installation with a single pure-Python dependency.
- Actively maintained with recent releases; marked stable and used in production environments.
License · maintenance · safety
ISC (permissive) — ISC license is permissive, allowing commercial and private use with minimal restrictions.
last release 2026-07-22 (23 days) · last repo commit 2026-07-22 · 398 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 114,110 downloads/mo, #12,311 on PyPI
Alternatives
Verify before relying
pip install pan-os-python
import pan-os-python
from pan-os-python import firewall, network
fw = firewall.Firewall("10.0.0.1", api_username="admin", api_password="admin")
eth1 = network.EthernetInterface("ethernet1/1", mode="layer3")
fw.add(eth1)
eth1.create()
fw.commit()- Whether the package supports all current PAN-OS versions and device models.
- Performance characteristics when managing large-scale deployments or high-availability pairs.
- Compatibility with Panorama as a proxy for managing multiple firewalls at scale.
What it is and what it does
pan-os-python is an object-oriented SDK that lets you interact with Palo Alto Networks firewalls and Panorama appliances programmatically. Instead of logging into the web GUI or CLI, you write Python code to create, modify, and query device configurations and run operational commands. The SDK models the device's configuration hierarchy as Python objects and handles the underlying API calls for you.
It's designed for automation tasks: provisioning interfaces, managing security policies, running diagnostics, and orchestrating changes across single devices or Panorama-managed fleets. The package is stable, actively maintained, and already in production use. It depends only on pan-python for HTTP communication, keeping installation straightforward.
Use it for
- Automate firewall interface and network configuration during infrastructure provisioning.
- Batch-manage security policies and rules across multiple firewalls via Panorama.
- Query device status, system info, and operational metrics for monitoring or compliance audits.
- Integrate firewall configuration into CI/CD pipelines for infrastructure-as-code workflows.
- Implement high-availability failover logic or retry mechanisms during device maintenance.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you manage Palo Alto Networks devices and need programmatic control.
The package is stable, actively maintained, has low install friction, and carries a permissive license. No known security vulnerabilities. Only caveat: you must have network access to a compatible PAN-OS device with API credentials to use it meaningfully.
Install
pan-os-python on PyPI
Before you install
Low friction installation with a single pure-Python dependency. Actively maintained with recent releases; marked stable and used in production environments.
Requires network connectivity to a Palo Alto Networks device (physical or virtualized firewall or Panorama) with API access enabled and valid credentials.
License in practice
ISC license is permissive, allowing commercial and private use with minimal restrictions.
Quickstart
pip install pan-os-python
import pan-os-python
from pan-os-python import firewall, network
fw = firewall.Firewall("10.0.0.1", api_username="admin", api_password="admin")
eth1 = network.EthernetInterface("ethernet1/1", mode="layer3")
fw.add(eth1)
eth1.create()
fw.commit()
Verify before relying
- Whether the package supports all current PAN-OS versions and device models.
- Performance characteristics when managing large-scale deployments or high-availability pairs.
- Compatibility with Panorama as a proxy for managing multiple firewalls at scale.
Package facts
| License | ISC permissive |
| Python support | Supports the current Python release !=3.0.*,!=3.1.*,!=3.2.*,!=3.3.*,!=3.4.*,>=2.7 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packagepan-python |
| Maintenance | Actively maintained 23 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 114,110 / month, #12,311 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI ApprovedLicense :: OSI Approved :: ISC License (ISCL)Natural Language :: EnglishProgramming Language :: Python :: 2Programming Language :: Python :: 2.7Programming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.5Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9 |
Evidence: pan_os_python-1.13.1-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “palo alto networks firewall api”
- pan-os-pythonFramework for programmatically configuring and managing Palo Alto…
- pan-pythonProvides Python and command-line interfaces to Palo Alto Networks…
- prisma-saseLightweight Python SDK wrapper for the Palo Alto Networks Prisma SASE…
Give your agent the search over MCP, or paste the wish link into any chat.
More Networking packages
h11 is a pure-Python HTTP/1.1 protocol implementation that handles parsing and serializing HTTP messages without any built-in I/O, letting you integrate it with any network layer you choose.
psutil retrieves real-time information about running processes and system resources (CPU, memory, disks, network, sensors) across multiple operating systems, enabling system monitoring, process profiling, and resource management.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
uvloop is a drop-in replacement for Python's built-in asyncio event loop, implemented in Cython and using libuv, that accelerates async I/O operations.
execnet lets you spawn and communicate with Python interpreters across local processes, remote hosts, and different platforms, using a simple API for task distribution and inter-process messaging.
However, the aging maintenance status (275 days since last release) means you should verify it meets your concurrency and performance needs before committing to a…
PyZMQ provides Python bindings for ZeroMQ (ØMQ), a lightweight messaging library that enables fast, asynchronous communication between distributed processes and applications.
See also pan-python · prisma-sase · scc-firewall-manager-sdk · cvprac · azure-mgmt-iothubprovisioningservices · binho-host-adapter · azure-mgmt-network · sshtunnel · azure-mgmt-datalake-store · wafw00f