Automation Tools and AI Agents
Alongside the REST API, we provide a set of tools to automate Security Cloud Control Firewall Manager: a Python SDK, a command-line interface, an Ansible collection, a Terraform provider, and an agent plugin for Claude Code and Codex.
All of these tools are built on top of the Security Cloud Control Firewall Manager API, and all of them authenticate with the same API token. See Authentication to create one.
Prefer to explore the API interactively before automating it? Start with our Postman Collections.
Python SDK
We provide a Software Development Kit (SDK) in Python to help you interact with the Security Cloud Control APIs.
The SDK can be downloaded from PyPI.
pip install scc-firewall-manager-sdk
You can find the SDK documentation here.
CLI
The sccfm-cli command lets you drive Security Cloud Control Firewall Manager from your shell and
from scripts. Install it from PyPI:
pipx install cisco-sccfm-devkit
Alternatively, install it with Homebrew:
brew tap CiscoDevNet/tap
brew trust --formula CiscoDevNet/tap/sccfm-cli # required once on Homebrew 6.0+
brew install CiscoDevNet/tap/sccfm-cli
Ansible Collection
The cisco.sccfm collection lets you manage Security Cloud Control Firewall Manager from Ansible
playbooks. Install it from
Ansible Galaxy:
ansible-galaxy collection install cisco.sccfm
Terraform Provider
The Security Cloud Control Firewall Manager Terraform Provider can be used to onboard and manage devices and other resources. Download it from the Terraform registry.
View examples of how to use the Terraform provider on GitHub.
Claude Code and Codex Plugin
An sccfm agent plugin bundles guided installation, authentication setup, and operational
skills for the CLI and Ansible collection into Claude Code and Codex.
Claude Code:
claude plugin marketplace add CiscoDevNet/sccfm-devkit
claude plugin install sccfm@sccfm-devkit
Codex:
codex plugin marketplace add CiscoDevNet/sccfm-devkit
codex plugin add sccfm@sccfm-devkit
Reference Documentation
Full CLI and Ansible reference documentation, along with source and examples, is available on GitHub and the generated reference site.
Reporting Issues
Please report bugs and feature requests for these tools on GitHub:
For questions, best practices, and general feedback, use the
Network Security forum
with the Cisco Security Cloud Control label. See
Developer Support for
all support options.