{
  "openapi": "3.0.3",
  "x-hideTryItPanel": true,
  "info": {
    "title": "Restore Distributions Public API",
    "version": "Cortex Cloud",
    "description": "API for restoring deleted agent installation packages (distributions) in Cortex Cloud.",
    "contact": {
      "email": "docs-cortex@paloaltonetworks.com",
      "name": "Cortex Documentation Team",
      "url": "https://cortex-docs.paloaltonetworks.com/"
    },
    "license": {
      "name": "Palo Alto Networks",
      "url": "https://www.paloaltonetworks.com/"
    }
  },
  "servers": [
    {
      "url": "https://api-yourfqdn"
    }
  ],
  "tags": [
    {
      "name": "RestoreDistributions",
      "x-page-title": "Restore Distributions",
      "x-page-icon": "arrow-counterclockwise",
      "description": "Restore a previously deleted agent installation package by its distribution ID."
    }
  ],
  "paths": {
    "/public_api/v1/distributions/restore": {
      "post": {
        "operationId": "restoreDistribution",
        "summary": "Restore a deleted agent installation package",
        "description": "Restores a previously deleted agent installation package (distribution), re-enabling agent registration for agents that reference it.\n\nA distribution can be deleted via the [Delete agent installation packages](https://app.gitbook.com/s/ZuJbX2x7VQJhNovscCwE/cortex-platform/endpoint-management#post-public_api-v1-distributions-delete) API or from the **Agent Installations** screen in Cortex Cloud. Restoring the distribution re-enables agent registration.\n\nIf the distribution is already in an active (non-deleted) state, the API returns a message indicating it is already restored rather than returning an error.\n\n**Required license:** Cortex Cloud Runtime Security. In Cortex Cloud Posture Security, you need the Cortex Cloud Runtime Security add-on.",
        "tags": [
          "RestoreDistributions"
        ],
        "parameters": [
          {
            "name": "Authorization",
            "in": "header",
            "description": "API key for authentication.",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "x-xdr-auth-id",
            "in": "header",
            "description": "API key ID for authentication.",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "required": true,
          "description": "Request body containing the distribution ID to restore.",
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/RestoreDistributionRequest"
              },
              "examples": {
                "RestoreDistribution": {
                  "summary": "Restore a distribution by ID",
                  "value": {
                    "request_data": {
                      "distribution_id": "e1c8a20d9d2c4ae6b4e7e6b7437847bc"
                    }
                  }
                }
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "The restore operation was processed. The `reply` field contains a message indicating whether the distribution was successfully restored or was already in an active state.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/RestoreDistributionResponse"
                },
                "examples": {
                  "SuccessfulRestore": {
                    "summary": "Distribution successfully restored",
                    "value": {
                      "reply": "Successfully restored distribution e1c8a20d9d2c4ae6b4e7e6b7437847bc"
                    }
                  },
                  "AlreadyRestored": {
                    "summary": "Distribution was already active",
                    "value": {
                      "reply": "Distribution e1c8a20d9d2c4ae6b4e7e6b7437847bc is already restored"
                    }
                  }
                }
              }
            }
          },
          "400": {
            "description": "Bad request. The `distribution_id` is missing or malformed.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          },
          "401": {
            "description": "Unauthorized. The API key or key ID is missing or invalid.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          },
          "403": {
            "description": "Forbidden. The API key does not have permission to restore distributions.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          },
          "404": {
            "description": "Not found. No distribution exists with the specified `distribution_id`.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          },
          "500": {
            "description": "Internal server error. An unexpected error occurred while processing the restore request.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          }
        }
      }
    }
  },
  "components": {
    "schemas": {
      "RestoreDistributionRequest": {
        "type": "object",
        "description": "Request body for restoring a deleted distribution.",
        "required": [
          "request_data"
        ],
        "properties": {
          "request_data": {
            "type": "object",
            "description": "Container for the restore request parameters.",
            "required": [
              "distribution_id"
            ],
            "properties": {
              "distribution_id": {
                "type": "string",
                "description": "The unique identifier of the distribution to restore. You can find this ID in the [Create distributions](https://app.gitbook.com/s/ZuJbX2x7VQJhNovscCwE/cortex-platform/endpoint-management#post-public_api-v1-distributions-create) API response, the [Get distributions](https://app.gitbook.com/s/ZuJbX2x7VQJhNovscCwE/cortex-platform/endpoint-management#post-public_api-v1-distributions-get_distributions) API response, or in the **Agent Installations** screen in Cortex Cloud.",
                "example": "e1c8a20d9d2c4ae6b4e7e6b7437847bc",
                "minLength": 1
              }
            }
          }
        }
      },
      "RestoreDistributionResponse": {
        "type": "object",
        "description": "Response returned after a restore operation is processed.",
        "properties": {
          "reply": {
            "type": "string",
            "description": "A human-readable message describing the outcome of the restore operation. Returns `\"Successfully restored distribution <id>\"` when the distribution was restored, or `\"Distribution <id> is already restored\"` when the distribution was already in an active state.",
            "example": "Successfully restored distribution e1c8a20d9d2c4ae6b4e7e6b7437847bc"
          }
        }
      },
      "ErrorResponse": {
        "type": "object",
        "description": "Standard error response returned when the request cannot be processed.",
        "properties": {
          "reply": {
            "type": "object",
            "description": "Error details.",
            "properties": {
              "err_code": {
                "type": "integer",
                "description": "HTTP status code of the error.",
                "example": 400
              },
              "err_msg": {
                "type": "string",
                "description": "Human-readable description of the error.",
                "example": "Invalid distribution_id format."
              },
              "err_extra": {
                "type": "string",
                "description": "Additional context or diagnostic information about the error.",
                "example": "distribution_id must be a 32-character hexadecimal string."
              }
            }
          }
        }
      }
    },
    "securitySchemes": {
      "ApiKeyAuth": {
        "type": "apiKey",
        "in": "header",
        "name": "Authorization",
        "description": "API key for authenticating requests. Pass the API key in the `Authorization` header."
      },
      "ApiKeyIdAuth": {
        "type": "apiKey",
        "in": "header",
        "name": "x-xdr-auth-id",
        "description": "API key ID for authenticating requests. Pass the API key ID in the `x-xdr-auth-id` header."
      }
    }
  },
  "security": [
    {
      "ApiKeyAuth": [],
      "ApiKeyIdAuth": []
    }
  ]
}
