openapi: 3.1.0 info: contact: email: tmunzer@juniper.net name: Thomas Munzer description: '> Version: **2604.1.1** > > Date: **May 13, 2026**
NOTE:
Some important API changes will be introduced. Please make sure to read the announcements
--- ## Additional Documentation * [Mist Automation Guide](https://www.juniper.net/documentation/us/en/software/mist/automation-integration/index.html) * [Mist Location SDK](https://www.juniper.net/documentation/us/en/software/mist/location-services/topics/concept/mist-how-get-mist-sdk.html) * [Mist Product Updates](https://www.juniper.net/documentation/us/en/software/mist/product-updates/) ## Helpful Resources * [API Sandbox and Exercises](https://api-class.mist.com/) * [Postman Collection, Runners and Webhook Samples](https://www.postman.com/juniper-mist/workspace/mist-systems-s-public-workspace) * [Python Script Examples](https://github.com/tmunzer/mist_library) * [API Demo Apps](https://apps.mist-lab.fr/) * [Juniper Blog](https://blogs.juniper.net/) ## Mist Web Browser Extension: * Google Chrome, Microsoft Edge and other Chromium-based browser: [Chrome Web Store](https://chromewebstore.google.com/detail/mist-extension/ejhpdcljeamillfhdihkkmoakanpbplh) * Firefox: [Firefox Add-ons](https://addons.mozilla.org/en-US/firefox/addon/mist-extension/) ---' license: name: MIT url: https://raw.githubusercontent.com/tmunzer/Mist-OAS3.0/main/LICENSE title: Mist Admins Orgs MxTunnels API version: 2604.1.1 x-logo: altText: Juniper-MistAI backgroundColor: '#FFFFFF' url: https://www.mist.com/wp-content/uploads/logo.png servers: - description: Mist Global 01 url: https://api.mist.com - description: Mist Global 02 url: https://api.gc1.mist.com - description: Mist Global 03 url: https://api.ac2.mist.com - description: Mist Global 04 url: https://api.gc2.mist.com - description: Mist Global 05 url: https://api.gc4.mist.com - description: Mist EMEA 01 url: https://api.eu.mist.com - description: Mist EMEA 02 url: https://api.gc3.mist.com - description: Mist EMEA 03 url: https://api.ac6.mist.com - description: Mist EMEA 04 url: https://api.gc6.mist.com - description: Mist APAC 01 url: https://api.ac5.mist.com - description: Mist APAC 02 url: https://api.gc5.mist.com - description: Mist APAC 03 url: https://api.gc7.mist.com security: - apiToken: [] - basicAuth: [] - basicAuth: [] csrfToken: [] tags: - description: 'A Mist Tunnel (MxTunnel) is a configuration object that allows for the tunneling of user VLANs from the Access Points (APs) to a central point on the network. It specifies the VLAN IDs that need to be tunneled and assigns the tunnel to a primary or secondary mist edge cluster. The mist tunnel also includes settings for tunnel fail over, auto-preemption, and other parameters related to tunnel termination services.' name: Orgs MxTunnels paths: /api/v1/orgs/{org_id}/mxtunnels: parameters: - $ref: '#/components/parameters/org_id' get: description: Get List of Org MxTunnels operationId: listOrgMxTunnels parameters: - $ref: '#/components/parameters/limit' - $ref: '#/components/parameters/page' responses: '200': $ref: '#/components/responses/MxtunnelsArray' '400': $ref: '#/components/responses/HTTP400' '401': $ref: '#/components/responses/HTTP401' '403': $ref: '#/components/responses/HTTP403' '404': $ref: '#/components/responses/HTTP404' '429': $ref: '#/components/responses/HTTP429' summary: listOrgMxTunnels tags: - Orgs MxTunnels post: description: Create MxTunnel operationId: createOrgMxTunnel requestBody: content: application/json: examples: Example: value: cluster_ids: - string hello_interval: 60 hello_retries: 7 ipsec: dns_servers: - string enabled: true extra_routes: - dest: string next_hop: 192.168.0.1 split_tunnel: true use_mxedge: true vlan_ids: - 0 schema: $ref: '#/components/schemas/mxtunnel' description: Request Body responses: '200': $ref: '#/components/responses/Mxtunnel' '400': $ref: '#/components/responses/HTTP400' '401': $ref: '#/components/responses/HTTP401' '403': $ref: '#/components/responses/HTTP403' '404': $ref: '#/components/responses/HTTP404' '429': $ref: '#/components/responses/HTTP429' summary: createOrgMxTunnel tags: - Orgs MxTunnels /api/v1/orgs/{org_id}/mxtunnels/{mxtunnel_id}: parameters: - $ref: '#/components/parameters/org_id' - $ref: '#/components/parameters/mxtunnel_id' delete: description: Delete Org MxTunnel operationId: deleteOrgMxTunnel responses: '200': $ref: '#/components/responses/OK' '400': $ref: '#/components/responses/HTTP400' '401': $ref: '#/components/responses/HTTP401' '403': $ref: '#/components/responses/HTTP403' '404': $ref: '#/components/responses/HTTP404' '429': $ref: '#/components/responses/HTTP429' summary: deleteOrgMxTunnel tags: - Orgs MxTunnels get: description: Get Org MxTunnel Details operationId: getOrgMxTunnel responses: '200': $ref: '#/components/responses/Mxtunnel' '400': $ref: '#/components/responses/HTTP400' '401': $ref: '#/components/responses/HTTP401' '403': $ref: '#/components/responses/HTTP403' '404': $ref: '#/components/responses/HTTP404' '429': $ref: '#/components/responses/HTTP429' summary: getOrgMxTunnel tags: - Orgs MxTunnels put: description: Update Org MxTunnel operationId: updateOrgMxTunnel requestBody: content: application/json: schema: $ref: '#/components/schemas/mxtunnel' description: Request Body responses: '200': $ref: '#/components/responses/Mxtunnel' '400': $ref: '#/components/responses/HTTP400' '401': $ref: '#/components/responses/HTTP401' '403': $ref: '#/components/responses/HTTP403' '404': $ref: '#/components/responses/HTTP404' '429': $ref: '#/components/responses/HTTP429' summary: updateOrgMxTunnel tags: - Orgs MxTunnels components: schemas: id: description: Unique ID of the object instance in the Mist Organization examples: - 53f10664-3ce8-4c27-b382-0ef66432349f format: uuid readOnly: true type: string auto_preemption: additionalProperties: false description: Schedule to preempt ap’s which are not connected to preferred peer properties: day_of_week: $ref: '#/components/schemas/day_of_week' enabled: default: false description: Whether auto preemption should happen type: boolean time_of_day: $ref: '#/components/schemas/time_of_day' type: object time_of_day: default: any description: '`any` / HH:MM (24-hour format)' examples: - '12:00' type: string strings: items: type: string type: array uniqueItems: true day_of_week: description: 'enum: `any`, `fri`, `mon`, `sat`, `sun`, `thu`, `tue`, `wed`' enum: - any - fri - mon - sat - sun - thu - tue - wed type: string response_http403: additionalProperties: false properties: detail: examples: - You do not have permission to perform this action. type: string type: object mxtunnels: items: $ref: '#/components/schemas/mxtunnel' type: array mxtunnel_ipsec_extra_route: additionalProperties: false properties: dest: type: string next_hop: format: ipv4 type: string type: object site_id: examples: - 441a1214-6928-442a-8e92-e1d34b8ec6a6 format: uuid readOnly: true type: string mxtunnel_ipsec_extra_routes: items: $ref: '#/components/schemas/mxtunnel_ipsec_extra_route' type: array response_http404: additionalProperties: false properties: id: type: string type: object mxtunnel_anchor_mxtunnel_ids: description: List of anchor mxtunnels used for forming edge to edge tunnels items: examples: - 1e970fec-0a7a-4d73-a472-3ef3b6a456aa format: uuid type: string type: array modified_time: description: When the object has been modified for the last time, in epoch format: double readOnly: true type: number response_http400: additionalProperties: false properties: detail: examples: - 'JSON parse error - Expecting value: line 5 column 8 (char 56)' type: string type: object mxtunnel_protocol: default: udp description: 'enum: `ip`, `udp`' enum: - ip - udp type: string mxtunnel: description: MxTunnel properties: anchor_mxtunnel_ids: $ref: '#/components/schemas/mxtunnel_anchor_mxtunnel_ids' auto_preemption: $ref: '#/components/schemas/auto_preemption' created_time: $ref: '#/components/schemas/created_time' for_site: readOnly: true type: boolean hello_interval: default: 60 description: In seconds, used as heartbeat to detect if a tunnel is alive. AP will try another peer after missing N hellos specified by `hello_retries`. maximum: 300 minimum: 1 type: - integer - 'null' hello_retries: default: 7 maximum: 30 minimum: 2 type: - integer - 'null' id: $ref: '#/components/schemas/id' ipsec: $ref: '#/components/schemas/mxtunnel_ipsec' modified_time: $ref: '#/components/schemas/modified_time' mtu: default: 0 description: 0 to enable PMTU, 552-1500 to start PMTU with a lower MTU maximum: 1500 minimum: 0 type: integer mxcluster_ids: $ref: '#/components/schemas/mxtunnel_mxcluster_ids' name: type: - string - 'null' org_id: $ref: '#/components/schemas/org_id' protocol: $ref: '#/components/schemas/mxtunnel_protocol' site_id: $ref: '#/components/schemas/site_id' vlan_ids: $ref: '#/components/schemas/mxtunnel_vlan_ids' type: object response_http429: additionalProperties: false properties: detail: examples: - Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold type: string type: object mxtunnel_vlan_ids: description: List of vlan_ids that will be used items: type: integer type: array mxtunnel_mxcluster_ids: description: List of mxclusters to deploy this tunnel to items: format: uuid type: string type: array mxtunnel_ipsec_dns_servers: items: type: string type: - array - 'null' mxtunnel_ipsec: additionalProperties: false properties: dns_servers: $ref: '#/components/schemas/mxtunnel_ipsec_dns_servers' dns_suffix: $ref: '#/components/schemas/strings' enabled: type: boolean extra_routes: $ref: '#/components/schemas/mxtunnel_ipsec_extra_routes' split_tunnel: type: boolean use_mxedge: type: boolean type: object response_http401: additionalProperties: false properties: detail: examples: - Authentication credentials were not provided. type: string type: object org_id: examples: - a97c1b22-a4e9-411e-9bfd-d8695a0f9e61 format: uuid readOnly: true type: string created_time: description: When the object has been created, in epoch format: double readOnly: true type: number parameters: org_id: in: path name: org_id required: true schema: examples: - 000000ab-00ab-00ab-00ab-0000000000ab format: uuid type: string page: in: query name: page schema: default: 1 minimum: 1 type: integer mxtunnel_id: in: path name: mxtunnel_id required: true schema: examples: - 000000ab-00ab-00ab-00ab-0000000000ab format: uuid type: string limit: in: query name: limit schema: default: 100 minimum: 0 type: integer responses: Mxtunnel: content: application/json: examples: Example: $ref: '#/components/examples/MxtunnelExample' schema: $ref: '#/components/schemas/mxtunnel' application/vnd.api+json: examples: Example: $ref: '#/components/examples/MxtunnelExample' schema: $ref: '#/components/schemas/mxtunnel' description: OK MxtunnelsArray: content: application/json: examples: Example: $ref: '#/components/examples/MxtunnelsArrayExample' schema: $ref: '#/components/schemas/mxtunnels' application/vnd.api+json: examples: Example: $ref: '#/components/examples/MxtunnelsArrayExample' schema: $ref: '#/components/schemas/mxtunnels' description: OK HTTP404: content: application/json: schema: $ref: '#/components/schemas/response_http404' application/vnd.api+json: schema: $ref: '#/components/schemas/response_http404' description: Not found. The API endpoint doesn’t exist or resource doesn’ t exist HTTP429: content: application/json: examples: Example: $ref: '#/components/examples/HTTP429Example' schema: $ref: '#/components/schemas/response_http429' application/vnd.api+json: examples: Example: $ref: '#/components/examples/HTTP429Example' schema: $ref: '#/components/schemas/response_http429' description: Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold HTTP403: content: application/json: examples: Example: $ref: '#/components/examples/HTTP403Example' schema: $ref: '#/components/schemas/response_http403' application/vnd.api+json: examples: Example: $ref: '#/components/examples/HTTP403Example' schema: $ref: '#/components/schemas/response_http403' description: Permission Denied HTTP400: content: application/json: examples: Example: $ref: '#/components/examples/HTTP400Example' schema: $ref: '#/components/schemas/response_http400' application/vnd.api+json: examples: Example: $ref: '#/components/examples/HTTP400Example' schema: $ref: '#/components/schemas/response_http400' description: Bad Syntax OK: description: OK HTTP401: content: application/json: examples: Example: $ref: '#/components/examples/HTTP401Example' schema: $ref: '#/components/schemas/response_http401' application/vnd.api+json: examples: Example: $ref: '#/components/examples/HTTP401Example' schema: $ref: '#/components/schemas/response_http401' description: Unauthorized examples: MxtunnelsArrayExample: value: - hello_interval: 60 hello_retries: 3 ipsec: dns_servers: - 172.16.0.8 enabled: true extra_routes: - dest: 172.16.0.0/12 next_hop: 172.16.0.1 split_tunnel: true mxcluster_ids: - 572586b7-f97b-a22b-526c-8b97a3f609c4 name: HQ protocol: udp vlan_ids: - 3 - 4 - 5 HTTP400Example: value: detail: 'JSON parse error - Expecting value: line 5 column 8 (char 56)' HTTP403Example: value: detail: You do not have permission to perform this action. HTTP429Example: value: detail: Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold MxtunnelExample: value: cluster_ids: - string created_time: 0 for_site: true hello_interval: 60 hello_retries: 7 id: b069b358-4c97-5319-1f8c-7c5ca64d6ab1 ipsec: dns_servers: - string enabled: true extra_routes: - dest: string next_hop: 192.168.0.1 split_tunnel: true use_mxedge: true modified_time: 0 org_id: b069b358-4c97-5319-1f8c-7c5ca64d6ab1 site_id: b069b358-4c97-5319-1f8c-7c5ca64d6ab1 vlan_ids: - 0 HTTP401Example: value: detail: Authentication credentials were not provided. securitySchemes: apiToken: description: "Like many other API providers, it’s also possible to generate API Tokens to be used (in HTTP Header) for authentication. An API token ties to a Admin with equal or less privileges.\n\n**Format**:\n API Token value format is `Token {apitoken}`\n\n**Notes**:\n* an API token generated for a specific admin has the same privilege as the user\n* an API token will be automatically removed if not used for > 90 days\n* SSO admins cannot generate these API tokens. Refer Org level API tokens which can have privileges of a specific Org/Site for more information." in: header name: Authorization type: apiKey basicAuth: description: While our current UI uses Session / Cookie-based authentication, it’s also possible to do Basic Auth. scheme: basic type: http csrfToken: description: "This protects the website against [Cross Site Request Forgery](https://en.wikipedia.org/wiki/Cross-site_request_forgery), all the POST / PUT / DELETE APIs needs to have CSRF token in the AJAX Request header when using Login/Password authentication (with or without MFA)\n\n\nThe CSRF Token is sent back by Mist in the Cookies from the Login Response API Call:\n`cookies[csrftoken]` \n\nThe CSRF Token must be added in the HTTP Request Headers:\n```\nX-CSRFToken: vwvBuq9qkqaKh7lu8tNc0gkvBfEaLAmx\n```" in: header name: X-CSRFToken type: apiKey