openapi: 3.1.0 info: contact: email: tmunzer@juniper.net name: Thomas Munzer description: '> Version: **2604.1.1** > > Date: **May 13, 2026**
NOTE:
Some important API changes will be introduced. Please make sure to read the announcements
--- ## Additional Documentation * [Mist Automation Guide](https://www.juniper.net/documentation/us/en/software/mist/automation-integration/index.html) * [Mist Location SDK](https://www.juniper.net/documentation/us/en/software/mist/location-services/topics/concept/mist-how-get-mist-sdk.html) * [Mist Product Updates](https://www.juniper.net/documentation/us/en/software/mist/product-updates/) ## Helpful Resources * [API Sandbox and Exercises](https://api-class.mist.com/) * [Postman Collection, Runners and Webhook Samples](https://www.postman.com/juniper-mist/workspace/mist-systems-s-public-workspace) * [Python Script Examples](https://github.com/tmunzer/mist_library) * [API Demo Apps](https://apps.mist-lab.fr/) * [Juniper Blog](https://blogs.juniper.net/) ## Mist Web Browser Extension: * Google Chrome, Microsoft Edge and other Chromium-based browser: [Chrome Web Store](https://chromewebstore.google.com/detail/mist-extension/ejhpdcljeamillfhdihkkmoakanpbplh) * Firefox: [Firefox Add-ons](https://addons.mozilla.org/en-US/firefox/addon/mist-extension/) ---' license: name: MIT url: https://raw.githubusercontent.com/tmunzer/Mist-OAS3.0/main/LICENSE title: Mist Admins Sites Rogues API version: 2604.1.1 x-logo: altText: Juniper-MistAI backgroundColor: '#FFFFFF' url: https://www.mist.com/wp-content/uploads/logo.png servers: - description: Mist Global 01 url: https://api.mist.com - description: Mist Global 02 url: https://api.gc1.mist.com - description: Mist Global 03 url: https://api.ac2.mist.com - description: Mist Global 04 url: https://api.gc2.mist.com - description: Mist Global 05 url: https://api.gc4.mist.com - description: Mist EMEA 01 url: https://api.eu.mist.com - description: Mist EMEA 02 url: https://api.gc3.mist.com - description: Mist EMEA 03 url: https://api.ac6.mist.com - description: Mist EMEA 04 url: https://api.gc6.mist.com - description: Mist APAC 01 url: https://api.ac5.mist.com - description: Mist APAC 02 url: https://api.gc5.mist.com - description: Mist APAC 03 url: https://api.gc7.mist.com security: - apiToken: [] - basicAuth: [] - basicAuth: [] csrfToken: [] tags: - description: 'Rogues are unauthorized wireless access points that are installed on a network without authorization. They can be connected to the LAN via an ethernet cable, similar to a pc, and are typically set up by individuals with malicious intent or by employees trying to cover a dead spot with their own wi-fi hotspot.' name: Sites Rogues paths: /api/v1/sites/{site_id}/insights/rogues: parameters: - $ref: '#/components/parameters/site_id' get: description: Get List of Site Rogue/Neighbor APs operationId: listSiteRogueAPs parameters: - $ref: '#/components/parameters/rogue_type' - $ref: '#/components/parameters/limit' - $ref: '#/components/parameters/start' - $ref: '#/components/parameters/end' - $ref: '#/components/parameters/duration' - $ref: '#/components/parameters/interval' responses: '200': $ref: '#/components/responses/InsightRogue' '400': $ref: '#/components/responses/HTTP400' '401': $ref: '#/components/responses/HTTP401' '403': $ref: '#/components/responses/HTTP403' '404': $ref: '#/components/responses/HTTP404' '429': $ref: '#/components/responses/HTTP429' summary: listSiteRogueAPs tags: - Sites Rogues /api/v1/sites/{site_id}/insights/rogues/clients: parameters: - $ref: '#/components/parameters/site_id' get: description: Get List of Site Rogue Clients operationId: listSiteRogueClients parameters: - $ref: '#/components/parameters/limit' - $ref: '#/components/parameters/start' - $ref: '#/components/parameters/end' - $ref: '#/components/parameters/duration' - $ref: '#/components/parameters/interval' responses: '200': $ref: '#/components/responses/InsightRogueClients' '400': $ref: '#/components/responses/HTTP400' '401': $ref: '#/components/responses/HTTP401' '403': $ref: '#/components/responses/HTTP403' '404': $ref: '#/components/responses/HTTP404' '429': $ref: '#/components/responses/HTTP429' summary: listSiteRogueClients tags: - Sites Rogues /api/v1/sites/{site_id}/rogues/events/count: parameters: - $ref: '#/components/parameters/site_id' get: description: Count by Distinct Attributes of Rogue Events operationId: countSiteRogueEvents parameters: - in: query name: distinct schema: $ref: '#/components/schemas/site_rogue_events_count_distinct' - $ref: '#/components/parameters/rogue_type' - description: SSID of the network detected as threat in: query name: ssid schema: type: string - description: BSSID of the network detected as threat in: query name: bssid schema: type: string - description: MAC of the device that had strongest signal strength for ssid/bssid pair in: query name: ap_mac schema: type: string - description: Channel over which ap_mac heard ssid/bssid pair in: query name: channel schema: type: string - description: Whether the reporting AP see a wireless client (on LAN) connecting to it in: query name: seen_on_lan schema: type: boolean - $ref: '#/components/parameters/start' - $ref: '#/components/parameters/end' - $ref: '#/components/parameters/duration' - $ref: '#/components/parameters/limit' responses: '200': $ref: '#/components/responses/Count' '400': $ref: '#/components/responses/HTTP400' '401': $ref: '#/components/responses/HTTP401' '403': $ref: '#/components/responses/HTTP403' '404': $ref: '#/components/responses/HTTP404' '429': $ref: '#/components/responses/HTTP429' summary: countSiteRogueEvents tags: - Sites Rogues /api/v1/sites/{site_id}/rogues/events/search: parameters: - $ref: '#/components/parameters/site_id' get: description: Search Rogue Events operationId: searchSiteRogueEvents parameters: - $ref: '#/components/parameters/rogue_type' - description: SSID of the network detected as threat in: query name: ssid schema: type: string - description: BSSID of the network detected as threat in: query name: bssid schema: type: string - description: MAC of the device that had strongest signal strength for ssid/bssid pair in: query name: ap_mac schema: type: string - description: Channel over which ap_mac heard ssid/bssid pair in: query name: channel schema: type: integer - description: Whether the reporting AP see a wireless client (on LAN) connecting to it in: query name: seen_on_lan schema: type: boolean - $ref: '#/components/parameters/limit' - $ref: '#/components/parameters/start' - $ref: '#/components/parameters/end' - $ref: '#/components/parameters/duration' - $ref: '#/components/parameters/sort' - $ref: '#/components/parameters/search_after' responses: '200': $ref: '#/components/responses/RogueEventsSearch' '400': $ref: '#/components/responses/HTTP400' '401': $ref: '#/components/responses/HTTP401' '403': $ref: '#/components/responses/HTTP403' '404': $ref: '#/components/responses/HTTP404' '429': $ref: '#/components/responses/HTTP429' summary: searchSiteRogueEvents tags: - Sites Rogues /api/v1/sites/{site_id}/rogues/{rogue_bssid}: parameters: - $ref: '#/components/parameters/site_id' - $ref: '#/components/parameters/rogue_bssid' get: description: Get Rogue AP Details operationId: getSiteRogueAP responses: '200': $ref: '#/components/responses/RogueDetails' '400': $ref: '#/components/responses/HTTP400' '401': $ref: '#/components/responses/HTTP401' '403': $ref: '#/components/responses/HTTP403' '404': $ref: '#/components/responses/HTTP404' '429': $ref: '#/components/responses/HTTP429' summary: getSiteRogueAP tags: - Sites Rogues components: schemas: response_count: additionalProperties: false properties: distinct: type: string end: type: integer limit: type: integer results: $ref: '#/components/schemas/count_results' start: type: integer total: type: integer required: - distinct - end - limit - results - start - total type: object response_http403: additionalProperties: false properties: detail: examples: - You do not have permission to perform this action. type: string type: object count_results: items: $ref: '#/components/schemas/count_result' type: array uniqueItems: true response_events_rogue_search: additionalProperties: false properties: end: type: integer limit: type: integer next: type: string results: $ref: '#/components/schemas/response_events_rogue_search_results' start: type: integer total: type: integer required: - end - limit - results - start - total type: object count_result: additionalProperties: type: string properties: count: type: integer required: - count type: object rogue_details: additionalProperties: false properties: manufacture: type: string seen_as_client: type: boolean required: - seen_as_client - manufacture type: object site_rogue_events_count_distinct: default: bssid description: 'enum: `ap`, `bssid`, `ssid`, `type`' enum: - ap - bssid - ssid - type type: string insight_rogue_client: additionalProperties: false properties: annotation: type: string ap_mac: type: string avg_rssi: type: number band: type: string bssid: type: string client_mac: type: string num_aps: type: integer required: - bssid - ap_mac - client_mac - num_aps - band - avg_rssi - annotation type: object response_http404: additionalProperties: false properties: id: type: string type: object timestamp: description: Epoch (seconds) format: double readOnly: true type: number response_insight_rogue: additionalProperties: false properties: end: type: integer limit: type: integer next: description: Link to next set of results. If more results aren’t present, next is null. type: string results: $ref: '#/components/schemas/response_insight_rogue_results' start: type: integer required: - end - limit - results - start type: object response_http400: additionalProperties: false properties: detail: examples: - 'JSON parse error - Expecting value: line 5 column 8 (char 56)' type: string type: object response_http429: additionalProperties: false properties: detail: examples: - Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold type: string type: object response_insight_rogue_results: items: $ref: '#/components/schemas/insight_rogue_ap' type: array uniqueItems: true response_events_rogue_search_results: items: $ref: '#/components/schemas/events_rogue' type: array uniqueItems: true events_rogue: additionalProperties: false description: Rogue events properties: ap: type: string bssid: type: string channel: type: integer rssi: type: integer ssid: type: string timestamp: $ref: '#/components/schemas/timestamp' required: - ssid - bssid - timestamp - ap - rssi - channel type: object rogue_type: description: 'enum: `honeypot`, `lan`, `others`, `spoof`' enum: - honeypot - lan - others - spoof type: string insight_rogue_ap: additionalProperties: false properties: ap_mac: description: MAC of the device that had strongest signal strength for ssid/bssid pair type: string avg_rssi: description: Average signal strength of ap_mac for ssid/bssid pair type: number bssid: description: BSSID of the network detected as threat type: string channel: description: Channel over which ap_mac heard ssid/bssid pair type: string delta_x: description: X position relative to the reporting AP (`ap_mac`) type: number delta_y: description: Y position relative to the reporting AP (`ap_mac`) type: number num_aps: description: Num of aps that heard the ssid/bssid pair type: integer seen_on_lan: description: Whether the reporting AP see a wireless client (on LAN) connecting to it type: boolean ssid: description: SSID of the network detected as threat type: string times_heard: description: Represents number of times the pair was heard in the interval. Each count roughly corresponds to a minute. type: integer required: - ap_mac - avg_rssi - bssid - channel - num_aps type: object response_insight_rogue_client: additionalProperties: false properties: end: type: integer limit: type: integer next: type: string results: $ref: '#/components/schemas/response_insight_rogue_client_results' start: type: integer required: - start - end - limit - results type: object response_insight_rogue_client_results: items: $ref: '#/components/schemas/insight_rogue_client' type: array uniqueItems: true response_http401: additionalProperties: false properties: detail: examples: - Authentication credentials were not provided. type: string type: object examples: CountExample: value: distinct: string end: 0 limit: 0 results: - count: 0 property: string start: 0 total: 0 RogueEventsSearchExample: value: end: 1538074800 limit: 10 results: - ap: 5c5b350e10030 bssid: 38ff363c8c4c channel: 136 rssi: -54 ssid: MyHomeNetwork timestamp: 1538074612 - ap: 5c5b350e10030 bssid: 60d02c2394cc channel: 11 rssi: -59 ssid: Home-Office timestamp: 1538074612 start: 1538071200 total: 2 HTTP400Example: value: detail: 'JSON parse error - Expecting value: line 5 column 8 (char 56)' HTTP403Example: value: detail: You do not have permission to perform this action. HTTP429Example: value: detail: Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold RogueDetailsExample: value: manufacture: Intel Corporate seen_as_client: true HTTP401Example: value: detail: Authentication credentials were not provided. InsightRogueExample: value: end: 1428954000 limit: 100 next: /api/v1/sites/a3eda150-ab3f-11e4-aa18-13e21dd250cc/rogues?start=1498482000&end=1498485600&limit=10&interval=1h&type=others results: - ap_mac: 5c5b350e021c avg_rssi: -72 bssid: d8-97-ba-76-b5-aa channel: '11' num_aps: 4 ssid: xfinitywifi times_heard: 8 start: 1428939600 InsightRogueClientsExample: value: end: 1428954000 limit: 100 next: /api/v1/sites/a3eda150-ab3f-11e4-aa18-13e21dd250cc/rogues/clients?start=1498482000&end=1498485600&limit=10&interval=1h results: - annotation: whitelist ap_mac: 5c-5b-35-0e-02-1c avg_rssi: -63.9 band: '5' bssid: d8-97-ba-76-b5-aa client_mac: 34-f8-32-13-57-c2 num_aps: 2 start: 1428939600 parameters: interval: description: Aggregation works by giving a time range plus interval (e.g. 1d, 1h, 10m) where aggregation function would be applied to. in: query name: interval schema: examples: - 10m type: string rogue_type: in: query name: type schema: $ref: '#/components/schemas/rogue_type' start: description: Start time (epoch timestamp in seconds, or relative string like "-1d", "-1w") in: query name: start schema: type: string sort: description: On which field the list should be sorted, -prefix represents DESC order in: query name: sort schema: default: timestamp examples: - -site_id type: string duration: description: Duration like 7d, 2w in: query name: duration schema: default: 1d examples: - 10m type: string search_after: description: Pagination cursor for retrieving subsequent pages of results. This value is automatically populated by Mist in the `next` URL from the previous response and should not be manually constructed. in: query name: search_after schema: type: string end: description: End time (epoch timestamp in seconds, or relative string like "-1d", "-2h", "now") in: query name: end schema: type: string site_id: in: path name: site_id required: true schema: examples: - 000000ab-00ab-00ab-00ab-0000000000ab format: uuid type: string rogue_bssid: in: path name: rogue_bssid required: true schema: examples: - 0000000000ab pattern: ^[0-9a-fA-F]{12}$ type: string limit: in: query name: limit schema: default: 100 minimum: 0 type: integer responses: InsightRogueClients: content: application/json: examples: Example: $ref: '#/components/examples/InsightRogueClientsExample' schema: $ref: '#/components/schemas/response_insight_rogue_client' application/vnd.api+json: examples: Example: $ref: '#/components/examples/InsightRogueClientsExample' schema: $ref: '#/components/schemas/response_insight_rogue_client' description: OK InsightRogue: content: application/json: examples: Example: $ref: '#/components/examples/InsightRogueExample' schema: $ref: '#/components/schemas/response_insight_rogue' application/vnd.api+json: examples: Example: $ref: '#/components/examples/InsightRogueExample' schema: $ref: '#/components/schemas/response_insight_rogue' description: OK HTTP404: content: application/json: schema: $ref: '#/components/schemas/response_http404' application/vnd.api+json: schema: $ref: '#/components/schemas/response_http404' description: Not found. The API endpoint doesn’t exist or resource doesn’ t exist HTTP429: content: application/json: examples: Example: $ref: '#/components/examples/HTTP429Example' schema: $ref: '#/components/schemas/response_http429' application/vnd.api+json: examples: Example: $ref: '#/components/examples/HTTP429Example' schema: $ref: '#/components/schemas/response_http429' description: Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold RogueDetails: content: application/json: examples: Example: $ref: '#/components/examples/RogueDetailsExample' schema: $ref: '#/components/schemas/rogue_details' application/vnd.api+json: examples: Example: $ref: '#/components/examples/RogueDetailsExample' schema: $ref: '#/components/schemas/rogue_details' description: OK HTTP403: content: application/json: examples: Example: $ref: '#/components/examples/HTTP403Example' schema: $ref: '#/components/schemas/response_http403' application/vnd.api+json: examples: Example: $ref: '#/components/examples/HTTP403Example' schema: $ref: '#/components/schemas/response_http403' description: Permission Denied HTTP400: content: application/json: examples: Example: $ref: '#/components/examples/HTTP400Example' schema: $ref: '#/components/schemas/response_http400' application/vnd.api+json: examples: Example: $ref: '#/components/examples/HTTP400Example' schema: $ref: '#/components/schemas/response_http400' description: Bad Syntax RogueEventsSearch: content: application/json: examples: Example: $ref: '#/components/examples/RogueEventsSearchExample' schema: $ref: '#/components/schemas/response_events_rogue_search' application/vnd.api+json: examples: Example: $ref: '#/components/examples/RogueEventsSearchExample' schema: $ref: '#/components/schemas/response_events_rogue_search' description: OK HTTP401: content: application/json: examples: Example: $ref: '#/components/examples/HTTP401Example' schema: $ref: '#/components/schemas/response_http401' application/vnd.api+json: examples: Example: $ref: '#/components/examples/HTTP401Example' schema: $ref: '#/components/schemas/response_http401' description: Unauthorized Count: content: application/json: examples: Example: $ref: '#/components/examples/CountExample' schema: $ref: '#/components/schemas/response_count' application/vnd.api+json: examples: Example: $ref: '#/components/examples/CountExample' schema: $ref: '#/components/schemas/response_count' description: Result of Count securitySchemes: apiToken: description: "Like many other API providers, it’s also possible to generate API Tokens to be used (in HTTP Header) for authentication. An API token ties to a Admin with equal or less privileges.\n\n**Format**:\n API Token value format is `Token {apitoken}`\n\n**Notes**:\n* an API token generated for a specific admin has the same privilege as the user\n* an API token will be automatically removed if not used for > 90 days\n* SSO admins cannot generate these API tokens. Refer Org level API tokens which can have privileges of a specific Org/Site for more information." in: header name: Authorization type: apiKey basicAuth: description: While our current UI uses Session / Cookie-based authentication, it’s also possible to do Basic Auth. scheme: basic type: http csrfToken: description: "This protects the website against [Cross Site Request Forgery](https://en.wikipedia.org/wiki/Cross-site_request_forgery), all the POST / PUT / DELETE APIs needs to have CSRF token in the AJAX Request header when using Login/Password authentication (with or without MFA)\n\n\nThe CSRF Token is sent back by Mist in the Cookies from the Login Response API Call:\n`cookies[csrftoken]` \n\nThe CSRF Token must be added in the HTTP Request Headers:\n```\nX-CSRFToken: vwvBuq9qkqaKh7lu8tNc0gkvBfEaLAmx\n```" in: header name: X-CSRFToken type: apiKey