generated: '2026-07-25' method: searched source: https://open.iot.10086.cn/doc/iot_platform/book/api/introduce.html docs: - https://open.iot.10086.cn/doc/iot_platform/book/api/introduce.html - https://open.iot.10086.cn/doc/iot_platform/book/api/auth.html - https://open.iot.10086.cn/doc/iot_platform/book/api/code.html - https://open.iot.10086.cn/doc/iot_platform/book/vcs/vcs_api/request.html - https://api.iot.10086.cn/apiDocuments/cusInfo/codeInfoQuery.html summary: >- China Mobile runs four unrelated API estates with four unrelated conventions. The one with a published, coherent contract is OneNET (CMIOT): an action-dispatched gateway at openapi.heclouds.com where the namespace is the path, the operation is the `action` query parameter and the contract is pinned by a `version` query parameter. Every response is a uniform envelope carrying a platform-generated requestId. Authentication is a signed, time-boxed `authorization` header. There is no idempotency contract, no documented rate-limit signalling, no cursor pagination standard and no RFC 9457 problem+json anywhere in the estate. request_style: dispatch: action-in-query pattern: https://openapi.heclouds.com/{namespace}?action={Action}&version={version} namespaces: - name: application label: 应用开发类 — application development version: '1' - name: common label: 设备管理类 — device management version: '1' - name: lwm2m-online label: LwM2M IPSO real-time commands version: '1' - name: lwm2m-offline label: LwM2M IPSO cached commands version: '1' - name: vcs label: 语音通话 — Voice Call Service version: '2' content_type: application/json;charset=utf-8 methods: GET for queries, POST for mutations; the same action name is used in both cases authentication: style: signed time-boxed header token header: authorization artifact: authentication/china-mobile-authentication.yml note: >- authorization: version=2020-05-29&res=userid/{userid}&et={epoch}&method={md5|sha1|sha256}&sign={signature}. The signature is base64(hmac_(base64decode(accessKey), StringForSignature)) where StringForSignature = et + "\n" + method + "\n" + res + "\n" + version. Values in the header are URL-encoded. Resource scope is either userid/{userid} (master user) or projectid/{projectid}/groupid/{groupid} (project group, limited to that group's devices). idempotency: supported: false note: >- No Idempotency-Key header, no client-supplied request key and no replay window is documented anywhere in the OneNET, IoT Card or communication-capability references. Retries of a POST action are not deduplicated by the platform. The one place OneNET does define retry semantics is in the opposite direction — its outbound HTTP data push retries with exponential backoff, so receivers must be idempotent themselves (see the webhook artifact). no_pointer_reason: >- Deliberately no `Idempotency` pointer in apis.yml — China Mobile publishes no idempotency contract, and asserting one would misrepresent the provider. pagination: documented: partial note: >- List actions take documented page parameters and the VCS error registry includes invalidPageParams (不合法的分页参数), confirming offset/limit-style paging, but no cross-cutting pagination convention (cursor, link headers, response envelope fields) is published for the estate. request_tracing: supported: true response_field: requestId note: >- Every OneNET Studio and VCS response carries requestId, "a unique request identifier generated by the platform when the API is called". The new-generation device API at iot-api.heclouds.com uses request_id, and the callback acknowledgement envelope also uses request_id. There is no inbound correlation header the client can set. versioning: scheme: query-parameter parameter: version current: onenet_platform_api: '1' onenet_vcs_api: '2' iot_card_platform: v2 (URI path segment, https://api.iot.10086.cn/v2/) auth_signature_algorithm: '2020-05-29 (the only supported signature version)' artifact: lifecycle/china-mobile-lifecycle.yml error_envelope: format: proprietary artifact: errors/china-mobile-error-codes.yml note: >- HTTP 200 with a business envelope; failure is signalled by success:false plus a string code and msg. Four distinct envelope shapes exist across the estate (see the error artifact). No application/problem+json. rate_limits: documented: false note: >- No published quota, burst limit or 429 semantics for the OneNET APIs. Adjacent limits that are documented: a maximum of 10 HTTP push instances per user, a maximum of 500 devices per BatchCreateDevices call, and a talkTimeIsLimit / overTheExperienceNumber error pair on the Voice Call Service. metadata_and_expansion: supported: false note: >- No sparse-fieldset, field-expansion or free-form metadata convention is published. Device extensibility is modelled through the OneNET 物模型 (thing model) instead. cross_links: authentication: authentication/china-mobile-authentication.yml errors: errors/china-mobile-error-codes.yml lifecycle: lifecycle/china-mobile-lifecycle.yml webhooks: asyncapi/china-mobile-onenet-webhooks.yml sandbox: sandbox/china-mobile-sandbox.yml other_estates: - name: IoT Card Capability Open Platform host: https://api.iot.10086.cn/v2 dispatch: path-per-interface (e.g. /v2/cardinfo, interface code CMIOT_API2003) auth: proprietary signed request — appid, transid, ebid and a SHA-256 token derived from appid + password + transid envelope: '{"status":"","message":"","result":[]}' - name: Communication Capability Open Platform host: https://ct.open.10086.cn/ dispatch: not published anonymously note: Developer guide names the products (语音通知, 语音验证码, 点击拨号, 中间号, QoS保障) but publishes no endpoint reference or base URL to anonymous visitors. - name: Internet Capability Open Platform host: https://dev.10086.cn/ dispatch: not published anonymously note: Enterprise procurement console; every documentation route resolves to the same single-page-app shell for anonymous visitors.