# Aeris > Aeris Communications is a cellular IoT connectivity company (founded 1992, San Jose, California) that > operates a global network and connectivity management platform built for machines rather than phones. > It provides SIM and eSIM/eUICC lifecycle management, device provisioning, rate-plan and bundle > management, usage and signalling analytics, SMS messaging and IoT security monitoring. In February 2023 > Aeris acquired Ericsson's IoT Accelerator and Connected Vehicle Cloud businesses; the IoT Accelerator > platform now runs under the Aeris name and carries most of the published API surface. This file was generated by API Evangelist from Aeris's own published artifacts. Aeris serves no llms.txt of its own — all ten Aeris hosts return 404 for /llms.txt (probed 2026-09-10). ## What is actually published - 28 first-party OpenAPI 3.0 definitions — 278 paths, 331 operations. Linked from the IoT Developer Portal and served from https://storage.googleapis.com/iota_devportal/yaml/ - 16 WSDL 1.1 documents — 117 SOAP operations. 15 for the IoT Accelerator Service Portal (declared deprecated by Aeris), and the AerAdmin 5.0 WSDL served live at https://aeradminapi.aeris.com/AerAdmin_WS_5_0/ws?wsdl (47 operations). - Published per-endpoint rate limits with response headers, for 44 API paths. - Two first-party Python SDKs on PyPI, both stale (2020 and 2022). ## Documentation - IoT Developer Portal: https://iotdeveloper.aeris.net/hc/en-us - IoT Accelerator REST API overview: https://iotdeveloper.aeris.net/hc/en-us/articles/25348533091228-IoT-Accelerator-REST-API - API reference index (27 versioned APIs): https://iotdeveloper.aeris.net/hc/en-us/sections/25346615432988-IoT-Accelerator-APIs - Quick start guide (authentication per API group): https://iotdeveloper.aeris.net/hc/en-us/articles/25348523998748-API-Quick-start-guide - JWT authentication best practices: https://iotdeveloper.aeris.net/hc/en-us/articles/25348574275868-JWT-Authentication-Best-Practices - Rate limits: https://iotdeveloper.aeris.net/hc/en-us/articles/25348588280220-IoT-Accelerator-REST-API-Request-Rate-Limits - SOAP API (deprecated): https://iotdeveloper.aeris.net/hc/en-us/articles/25348517998364-IoT-Accelerator-SOAP-API - STOMP push notifications: https://iotdeveloper.aeris.net/hc/en-us/articles/25348570968732-Working-with-STOMP-notifications - Legacy connectivity API docs (AerAdmin, AerFrame, AerTraffic): https://support.aeris.net/hc/en-us/categories/360002203434-APIs Note for crawlers: both documentation hosts are Zendesk help centres that return HTTP 403 to non-browser clients. The article content is readable unauthenticated through the Zendesk Help Center API at /api/v2/help_center/en-us/articles.json on each host. ## APIs - Aeris IoT Accelerator REST API — https://iot-api.aeris.com — subscriptions, SIM and eUICC inventory, subscription search and change history, eSIM localization, eUICC setup and eIM/ECO operations, enterprise management, order management, number management, custom fields, shared bundles, business automation, signalling events and usage, business analytics reports and invoices, consumer connectivity purchases, resource inventory, incident management. - Aeris IoT Accelerator SMS Messaging API — https://sms.iot-api.aeris.com/dcpapi/smsmessaging/v1 — based on the OneAPI SMS interface and OMA REST NetAPIs v1. HTTP Basic auth. - Aeris IoT Watchtower API — https://watchtower-api-prd.aeriscloud.com — IoT security: device groups, gateways, flows, event policies, enforcement rules, protection policies, security reports. - Aeris IoT Accelerator SOAP API — https://iot-api.aeris.net — deprecated, still published. - Aeris AerAdmin Device Management API — https://aeradminapi.aeris.com — SOAP device provisioning. - Aeris AerFrame Device Communication and Control API — https://api.aerframe.aeris.com — SMS and device control. - Aeris AerTraffic Reports API — https://aertrafficapi.aeris.com/v1 — traffic and billing reports. ## Authentication There is no single mechanism. Six coexist, chosen by API group: OAuth 2.0 password and client-credentials flows returning a JWT bearer token from https://iot-api.aeris.com/iot/api/auth/token; an X-Access-Token header from a per-group POST /login; HTTP Basic for SMS Messaging; WS-Security UsernameToken for SOAP; and an ?apiKey= query parameter for the Aeris-native AerAdmin, AerFrame and AerTraffic APIs. There is no self-serve signup. Credentials are issued by a Connectivity Service Provider on subscription, and the API base URL is supplied at the same time. Reuse tokens. Read the JWT exp claim and re-authenticate only when it passes — /iot/api/auth is itself limited to 5 requests per second. ## Rate limits Per-endpoint, per-second and per-minute. Response headers on both 200 and 429: X-RateLimit-Limit-Second, X-RateLimit-Limit-Minute, X-RateLimit-Remaining-Second, X-RateLimit-Remaining-Minute. Exhaustion returns 429 with no Retry-After. Tightest published limits: iot/api/activation-codes at 2/s and iot/api/xdr/* at 5/s, 25/min. ## Errors 261 error responses across the estate use application/problem+json (RFC 7807 / RFC 9457); the IoT Watchtower contract names the RFC 7807 envelope explicitly. Other operations return bespoke JSON errors. There is no shared component library — Problem, ErrorResponse and Error are defined separately per service. ## Agent-relevant limitations - No MCP server, hosted or local. - No A2A agent card. All ten hosts 404 on /.well-known/agent-card.json and /.well-known/agent.json. - No /.well-known document of any kind on any host (50 probes, 0 documents). - No public status page, no published SLA, no dated changelog. - No public pricing. Enterprise and Connectivity Service Provider sales only. - No dry-run or preview mode on any of the 331 operations. - Idempotency is partial: 4 of 173 mutating operations accept an Idempotency-Key header, all of them IoT Watchtower gateway operations. Subscription state changes, SIM orders and bulk provisioning have no replay protection. - Reversal operations exist (refundPurchase, executeCancelSimOrder, deactivateSubscriptionPackage, suspend/unsuspend) but Aeris publishes no time window for any of them. - Three operations carry deprecated: true and the entire SOAP estate is declared deprecated, but no Sunset or Deprecation header and no retirement date are published. - Event surfaces exist (STOMP 1.2 over WSS, a CloudEvents 1.0 AerSight stream, AerFrame notification channels) but no AsyncAPI document is published for any of them, and STOMP broker credentials are issued manually during onboarding. ## Compliance ISO/IEC 27001:2022 and ISO 9001:2015, plus M2M Service Provider registration with the Department of Telecommunications, Government of India. Published at https://www.aeris.com/trust-center/aeris-certifications/ No security.txt, no bug bounty and no responsible-disclosure policy were found. ## Company - Website: https://www.aeris.com/ - Trust center: https://www.aeris.com/trust-center/ - Terms of service: https://www.aeris.com/legal/services-terms-of-use/ - Privacy policy: https://www.aeris.com/legal/privacy-policy/ - GitHub: https://github.com/aeristhings and https://github.com/aerisiot - Postman collections (IoT Accelerator REST, zip): https://storage.googleapis.com/iota_devportal/assets/dev_app_pmcoll_iota_rest_api.zip