Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

Automate Check Point management with mgmt cli and Web API

From Tech-Wiki


Automate Check Point management objects and policy changes with mgmt_cli, Gaia management commands or the HTTPS Management API.

ⓘ
Validation status
Reviewed against the current Check Point Management API documentation and R81.20/R82-era management guidance on 27 September 2026.
!
Treat automation credentials and session IDs as secrets
Do not embed administrator passwords, API keys or session IDs in wiki pages, source repositories or shell history. Use approved credential storage and the least-privileged API administrator permissions required for the automation.

API workflow

A normal multi-command Management API workflow is:

  1. Log in and obtain a session.
  2. Make one or more changes.
  3. Review the results.
  4. Publish the session, or discard it if validation fails.
  5. Log out.

This is important because Management API changes made within a session are not committed until they are published.

mgmt_cli session example

The following interactive login avoids placing a password directly in the command line and writes the session response to a local file.

>_Create a management session
mgmt_cli login > id.txt

Use the session file for subsequent commands:

>_Create a host object in the current session
mgmt_cli add host name host1 ip-address 192.0.2.10 -s id.txt

Publish the changes:

>_Publish the session
mgmt_cli publish -s id.txt

Then log out:

>_Log out
mgmt_cli logout -s id.txt
!
Protect the session file
id.txt contains a usable session identifier. Restrict access to it and delete it securely when the automation completes.

Single-command behaviour

Check Point documents that when mgmt_cli is invoked with credentials rather than an existing session, it can perform login, the requested command, publish and logout as one operation.

For controlled automation involving multiple related changes, using an explicit session makes the publish/discard boundary clearer.

Gaia Clish management commands

On a management server, Check Point also supports management commands from Gaia Clish after a management login.

>_Gaia management API example
mgmt login
mgmt add host name myHost12 ip-address 192.0.2.12
mgmt publish

HTTPS Web API

The Management API is also available through HTTPS:

POST https://<management-server>/web_api/<command>

After the login request, subsequent requests include the returned session identifier in the X-chkp-sid HTTP header.

A typical sequence is:

  • login
  • add-host, set-host, policy or other API operations
  • publish
  • logout
✓
Use the API reference for the exact release
Management API capabilities and object parameters evolve between releases. Use the API reference exposed by the target management environment rather than assuming an old R80 example is still complete.

Official references

See also