# 7SIGNAL > Enterprise wireless and wired network experience monitoring. 7SIGNAL measures Wi-Fi and network > performance from the client's point of view using vendor-agnostic Sapphire Eye hardware sensors and > Mobile Eye software agents installed on endpoints, and exposes that telemetry through a public REST > API and a remote, OAuth-protected MCP server. Headquartered in Independence, Ohio. Generated by the API Evangelist enrichment pipeline on 2026-09-05 from 7SIGNAL's own published surfaces. 7SIGNAL does not publish an llms.txt of its own (probed 7signal.com/llms.txt: 404). ## Base URLs - REST API gateway: https://api-v2.7signal.com - MCP server (remote, OAuth): https://mcp-v2.7signal.com/mcp - Platform dashboard: https://start.7signal.com - Undocumented, gated: https://api.7signal.com/graphql answers a POST introspection query with 401 {"success":false,"message":"No token provided."}. 7SIGNAL documents no GraphQL API anywhere public; the endpoint is recorded as an observation, not as a product. ## Contract - OpenAPI 3.0.3, info.version 2.21.1, 215 operations across 32 tags - Served anonymously at https://api-v2.7signal.com/api/gateway-v2.json (assembled from 51 separately served JSON fragments; /v3/api-docs and /openapi.json return 401) - Interactive reference: https://api-v2.7signal.com/swagger-ui/index.html ## Authentication - OAuth 2.0 client credentials. Your "API Key" is the client_id and your "API Secret" is the client_secret. - POST https://api-v2.7signal.com/oauth2/token with grant_type=client_credentials (application/x-www-form-urlencoded) - Returns a JWT valid for exactly 24 hours (86400s). The lifetime is fixed. Reuse the token; do not request a new one per call. - Send it as: Authorization: Bearer - 401 = token missing/expired/invalid. 403 = valid token, insufficient permission. - Create keys at https://start.7signal.com under Users -> API Keys, scoped to an Organization, Role and Sapphire Group. ## Rate limiting Token bucket, enforced automatically, no configuration. Read these response headers: ratelimit-remaining, ratelimit-burst-capacity, ratelimit-replenish-rate, ratelimit-requested-tokens. (7SIGNAL's own example code reads them with an `x-` prefix; both spellings appear in their sources.) Exhaustion returns 429. No Retry-After is documented. Limits vary by account type and are not published. ## Conventions - Pagination: page + perPage query params; response envelope { pagination: {perPage, page, total, pages}, results: [...] }. Time-series endpoints paginate per METRIC, and a single series is capped at 120 data points. - Time ranges: `from` and `to` in epoch MILLISECONDS. Bucket with timeBucket (1_MIN, 10_MIN, 1_HOUR, 1_DAY, 1_MONTH). aggregateFunctions is required on time-series calls. - Errors: a Spring Boot envelope { timestamp, status, error, message, path, requestId } as application/json. NOT RFC 9457 problem+json. Quote requestId to support. - Enum values are lowercase on the alerting endpoints; "AVG" instead of "avg" returns 400. - NO idempotency mechanism exists. There is no Idempotency-Key header. A retried POST creates a second resource — read back before retrying a write. - NO dry-run or validate-only mode exists on any of the 62 write operations. - PUT is a FULL REPLACE, not a merge. Omitted optional fields fall back to defaults, which reads as settings being wiped. GET, edit, then PUT the complete object. ## Resource surface - Authentication and API keys: /oauth2/token, /apikeys - Users, roles, groups, organizations, permissions: /users, /roles, /groups, /organizations, /permissions - Eyes: /eyes/agents (Mobile Eye software agents), /eyes/sensors (Sapphire Eye hardware sensors) - Location hierarchy: /locations/agents, /locations/sensors, /service-areas/agents, /service-areas/sensors - Network topology: /networks, /access-points/agents, /access-points/sensors, /network-keys/sensors - Sensor configuration: /targets/sensors, /default-configurations/sensors - Metrics: /time-series/agents/*, /time-series/sensors/* (numeric, discrete, histogram, numeric-summary, metric-types) - On-demand tests: /on-demand-tests/* — ping, traceroute, HTTP/TCP/UDP throughput, speedtest, iPerf3, MOS, web download, and 802.11 packet capture (returns application/vnd.tcpdump.pcap) - RF scans: /scans/agents, /scans/sensors - Impact and experience: /impact/* - Incidents: /incidents/agents (platform-detected agent incidents) - Alerting: /alerting/alert-rules, /alerting/incidents - Eyeris AI analysis: /eyeris/agents/client-analysis (poll), /eyeris/analysis/stream (SSE) - Integrations: /integrations/meraki/configs, /integrations/servicenow/configs - Audit and summaries: /audit/agents, /summaries/users, /access/{userId}/summary - Adapter/driver reporting: /adapter-driver-report/* ## Events No AsyncAPI is published. Outbound notification is configured per ALERT RULE, not per account, in notificationConfig.deliveries[], discriminated by `kind`: - webhook — requires url and auth; format is `generic` (default) or `slack`. Authenticated webhook credentials are referenced by AWS Secrets Manager ARN and never sent or returned inline. - email — requires address. - servicenow — requires mdsConfigId and organizationName, with the ServiceNow integration configured. No webhook signature header, retry policy or delivery log is documented. The only push surface on the API itself is the Eyeris Server-Sent Events stream. ## Deprecations 19 operations carry deprecated: true, in two families. No Sunset or Deprecation header is sent, and no removal date is committed — the wording is "will be removed in a future release". - /kpis/* (11 operations) -> /time-series/*. Four of the eleven have NO replacement named ("TBD"), and /kpis/sensors/dest-nw-band-loc/{targetId} has no corresponding group-by dimension. - /topologies/* (8 operations) -> /locations/*, /service-areas/*, /access-points/*. 7SIGNAL says exact field parity "cannot be guaranteed". The v1 gateway host api-v1.7signal.com no longer resolves in DNS. ## MCP https://mcp-v2.7signal.com/mcp is live and speaks MCP over HTTP. An anonymous tools/list returns 401 invalid_token with a spec-correct RFC 9728 challenge pointing at https://mcp-v2.7signal.com/.well-known/oauth-protected-resource. Authorization is OAuth 2.1 authorization_code + PKCE (S256) with dynamic client registration and refresh tokens, discoverable at /.well-known/oauth-authorization-server. The tool list is auth-gated and is NOT enumerated here. 7SIGNAL documents Claude, ChatGPT and Microsoft Copilot as supported clients. ## Documentation - Reference chapters (22): https://github.com/7Signal/API-Examples/blob/develop/docs/README.md - Authentication: https://github.com/7Signal/API-Examples/blob/develop/docs/01-authentication.md - Rate limiting: https://github.com/7Signal/API-Examples/blob/develop/docs/02-rate-limiting.md - What's New: https://github.com/7Signal/API-Examples/blob/develop/docs/WHATS-NEW.md - Migration notes: https://github.com/7Signal/API-Examples/tree/develop/docs/migration - Example code (Python): https://github.com/7Signal/API-Examples - GitHub organization: https://github.com/7Signal - MCP overview: https://7signal.com/platform/mcp-wi-fi-monitoring/ - Integrations: https://www.7signal.com/integrations-api - Status: https://7signal.com/status/ - Academy: https://academy.7signal.com/ - Support portal: https://info.7signal.com/communityportal/ (Salesforce Experience Cloud; renders only in a browser) ## Commercial No public pricing tiers. Annual subscription with 1-3 year terms, usage-based and quoted per customer; every call to action routes to Contact Us or Schedule a Demo. There is no self-serve signup and no separately metered API plan. ## Compliance SOC 2 Type II (Security, Availability, Confidentiality; auditor Insight Assurance; announced 2025-07-07), an earlier SOC 2 Type 2 attestation, and a GDPR compliance claim covering all products. Announced via press releases only — there is no trust center and no security.txt on any 7SIGNAL host. ## Not published - No llms.txt, no /.well-known/api-catalog, no /.well-known/security.txt (probed on 8 hosts) - No A2A agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host - No AsyncAPI, no gRPC .proto and no WSDL (probed; GitHub org code search returns 0 .proto and 0 .wsdl) - No documented GraphQL API (an undocumented gated endpoint exists at api.7signal.com/graphql) - No SDK on npm, PyPI, RubyGems or crates.io, and no first-party CLI - No sandbox or test-mode credentials