post
https://{region}.api.jamfcloud.com/securitycloud/v1/ztna/gateways
Create a dedicated Gateway. Returns 201 {id, href} + Location header.
tenantIds are validated against the caller's organization — returns 400 if any
tenant ID is not resolvable within the caller's organization.
Constraints:
- Exactly one of
dedicatedIps.enabled: trueoripsecmust be set — a plain gateway (neither)
or an availability-zones-only gateway (zones with noipsec) is rejected →400. dedicatedIps.enabled: trueand non-emptyavailabilityZonesare mutually exclusive →400- An
ipsecgateway requires at least oneavailabilityZonesaddress →400 - Only one gateway with
dedicatedIps.enabled: trueis permitted per tenant (quota = 1).
A second attempt returns409 DEDICATED_IPS_LIMIT. Contact your Jamf account team to increase this limit. - Sending
ipsec.left.secret: nullexplicitly returns400 IPSEC_SECRET_CLEAR_NOT_SUPPORTED.
The three rejected shapes above all return 400 INVALID_FIELD; field is the only way to
tell them apart:
| Request shape | field |
|---|---|
Neither dedicatedIps.enabled: true nor ipsec | dedicatedIps |
availabilityZones with no ipsec | ipsec — the fix is to add a tunnel, not remove the zones |
ipsec with no availabilityZones | availabilityZones |
No idempotency key. Gateway name is not unique-enforced — a timed-out POST that
succeeded server-side may create a duplicate gateway if retried. Verify via
GET /ztna/gateways before retrying a failed create.
Required Permissions: ztna:create
Recent Requests
Log in to see full request history
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||
Loading…