openapi: 3.1.0
info:
contact:
email: tmunzer@juniper.net
name: Thomas Munzer
description: '> Version: **2604.1.1**
>
> Date: **May 13, 2026**
NOTE:
Some important API changes will be introduced. Please make sure to read the
announcements
---
## Additional Documentation
* [Mist Automation Guide](https://www.juniper.net/documentation/us/en/software/mist/automation-integration/index.html)
* [Mist Location SDK](https://www.juniper.net/documentation/us/en/software/mist/location-services/topics/concept/mist-how-get-mist-sdk.html)
* [Mist Product Updates](https://www.juniper.net/documentation/us/en/software/mist/product-updates/)
## Helpful Resources
* [API Sandbox and Exercises](https://api-class.mist.com/)
* [Postman Collection, Runners and Webhook Samples](https://www.postman.com/juniper-mist/workspace/mist-systems-s-public-workspace)
* [Python Script Examples](https://github.com/tmunzer/mist_library)
* [API Demo Apps](https://apps.mist-lab.fr/)
* [Juniper Blog](https://blogs.juniper.net/)
## Mist Web Browser Extension:
* Google Chrome, Microsoft Edge and other Chromium-based browser: [Chrome Web Store](https://chromewebstore.google.com/detail/mist-extension/ejhpdcljeamillfhdihkkmoakanpbplh)
* Firefox: [Firefox Add-ons](https://addons.mozilla.org/en-US/firefox/addon/mist-extension/)
---'
license:
name: MIT
url: https://raw.githubusercontent.com/tmunzer/Mist-OAS3.0/main/LICENSE
title: Mist Admins Sites WxTunnels API
version: 2604.1.1
x-logo:
altText: Juniper-MistAI
backgroundColor: '#FFFFFF'
url: https://www.mist.com/wp-content/uploads/logo.png
servers:
- description: Mist Global 01
url: https://api.mist.com
- description: Mist Global 02
url: https://api.gc1.mist.com
- description: Mist Global 03
url: https://api.ac2.mist.com
- description: Mist Global 04
url: https://api.gc2.mist.com
- description: Mist Global 05
url: https://api.gc4.mist.com
- description: Mist EMEA 01
url: https://api.eu.mist.com
- description: Mist EMEA 02
url: https://api.gc3.mist.com
- description: Mist EMEA 03
url: https://api.ac6.mist.com
- description: Mist EMEA 04
url: https://api.gc6.mist.com
- description: Mist APAC 01
url: https://api.ac5.mist.com
- description: Mist APAC 02
url: https://api.gc5.mist.com
- description: Mist APAC 03
url: https://api.gc7.mist.com
security:
- apiToken: []
- basicAuth: []
- basicAuth: []
csrfToken: []
tags:
- description: 'A WxLan Tunnel (WxTunnel) are used to create a secure connection between Juniper Mist Access Points and third-party VPN concentrators using protocols such as L2TPv3 or dmvpn.
These tunnels allow for the aggregation of ethernet interfaces on access points, support dynamic or static tunnels, and provide options for IPSec encryption.'
name: Sites WxTunnels
paths:
/api/v1/sites/{site_id}/wxtunnels:
parameters:
- $ref: '#/components/parameters/site_id'
get:
description: Get List of Site WxLan Tunnels
operationId: listSiteWxTunnels
parameters:
- $ref: '#/components/parameters/limit'
- $ref: '#/components/parameters/page'
responses:
'200':
$ref: '#/components/responses/WxtunnelArray'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: listSiteWxTunnels
tags:
- Sites WxTunnels
post:
description: Create Site WxLan Tunnel
operationId: createSiteWxTunnel
requestBody:
content:
application/json:
examples:
Example:
value:
dmvpn:
enabled: true
holding_time: 0
host_routes:
- string
for_mgmt: true
hello_interval: 1
hello_retries: 3
hostname: string
ipsec:
enabled: true
psk: string123
is_static: true
mtu: 1500
name: string
peers:
- string
router_id: string
secret: string
sessions:
- ap_as_session_id: string
comment: string
enable_cookie: true
ethertype: ethernet
local_session_id: 1
pseudo_802.1ad_enabled: true
remote_id: string
remote_session_id: 1
use_ap_as_session_ids: true
udp_port: 0
use_udp: true
schema:
$ref: '#/components/schemas/wxlan_tunnel'
description: Request Body
responses:
'200':
$ref: '#/components/responses/Wxtunnel'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: createSiteWxTunnel
tags:
- Sites WxTunnels
/api/v1/sites/{site_id}/wxtunnels/{wxtunnel_id}:
parameters:
- $ref: '#/components/parameters/site_id'
- $ref: '#/components/parameters/wxtunnel_id'
delete:
description: Delete Site WxLan Tunnel
operationId: deleteSiteWxTunnel
responses:
'200':
$ref: '#/components/responses/OK'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: deleteSiteWxTunnel
tags:
- Sites WxTunnels
get:
description: Get Site WxLan tunnel Details
operationId: getSiteWxTunnel
responses:
'200':
$ref: '#/components/responses/Wxtunnel'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: getSiteWxTunnel
tags:
- Sites WxTunnels
put:
description: Update Site WxLan Tunnel
operationId: updateSiteWxTunnel
requestBody:
content:
application/json:
examples:
Example:
value:
dmvpn:
enabled: true
holding_time: 0
host_routes:
- string
for_mgmt: true
hello_interval: 1
hello_retries: 3
hostname: string
ipsec:
enabled: true
psk: string123
is_static: true
mtu: 1500
name: string
peers:
- string
router_id: string
secret: string
sessions:
- ap_as_session_id: string
comment: string
enable_cookie: true
ethertype: ethernet
local_session_id: 1
pseudo_802.1ad_enabled: true
remote_id: string
remote_session_id: 1
use_ap_as_session_ids: true
udp_port: 0
use_udp: true
schema:
$ref: '#/components/schemas/wxlan_tunnel'
description: Request Body
responses:
'200':
$ref: '#/components/responses/Wxtunnel'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: updateSiteWxTunnel
tags:
- Sites WxTunnels
components:
parameters:
wxtunnel_id:
in: path
name: wxtunnel_id
required: true
schema:
examples:
- 000000ab-00ab-00ab-00ab-0000000000ab
format: uuid
type: string
page:
in: query
name: page
schema:
default: 1
minimum: 1
type: integer
site_id:
in: path
name: site_id
required: true
schema:
examples:
- 000000ab-00ab-00ab-00ab-0000000000ab
format: uuid
type: string
limit:
in: query
name: limit
schema:
default: 100
minimum: 0
type: integer
schemas:
id:
description: Unique ID of the object instance in the Mist Organization
examples:
- 53f10664-3ce8-4c27-b382-0ef66432349f
format: uuid
readOnly: true
type: string
wxlan_tunnel_ipsec:
additionalProperties: false
description: IPSec-related configurations; requires DMVPN be enabled
properties:
enabled:
default: false
description: Whether ipsec is enabled, requires DMVPN be enabled
type: boolean
psk:
description: IPSec pre-shared key
type: string
required:
- psk
type: object
wxlan_tunnel_dmvpn_host_routes:
description: Optional; list of IPv4 DMVPN peer host ip-addresses to which traffic is forwarded
items:
type: string
type: array
response_http403:
additionalProperties: false
properties:
detail:
examples:
- You do not have permission to perform this action.
type: string
type: object
site_id:
examples:
- 441a1214-6928-442a-8e92-e1d34b8ec6a6
format: uuid
readOnly: true
type: string
wxlan_tunnel:
description: WxLAn Tunnel
properties:
created_time:
$ref: '#/components/schemas/created_time'
dmvpn:
$ref: '#/components/schemas/wxlan_tunnel_dmvpn'
for_mgmt:
default: false
description: Determined during creation time and cannot be toggled. A management tunnel cannot be used by wxlan rule or by wlan
type: boolean
for_site:
readOnly: true
type: boolean
hello_interval:
default: 60
description: In seconds, used as heartbeat to detect if a tunnel is alive. AP will try another peer after missing N hellos specified by hello_retries.
maximum: 300
minimum: 1
type: integer
hello_retries:
default: 7
maximum: 30
minimum: 2
type: integer
hostname:
description: "Optional, overwrite the hostname in SCCRQ control message, default is or null, %H and %M can be used, which will be replace with corresponding values:\n * %H: name of the ap if provided (and will be stripped so it can be used for hostname) and fallbacks to MAC\n * %M: MAC (e.g. 5c5b350e0060)"
type: string
id:
$ref: '#/components/schemas/id'
ipsec:
$ref: '#/components/schemas/wxlan_tunnel_ipsec'
is_static:
default: false
description: Whether it’s static/unmanaged (i.e. no control session). As the session configurations are not compatible, cannot be toggled.
type: boolean
modified_time:
$ref: '#/components/schemas/modified_time'
mtu:
default: 0
description: 0 to enable PMTU, 552-1500 to start PMTU with a lower MTU
maximum: 1500
minimum: 0
type: integer
name:
description: The name of the tunnel
type: string
org_id:
$ref: '#/components/schemas/org_id'
peers:
$ref: '#/components/schemas/wxlan_tunnel_peers'
router_id:
description: Optional, overwrite the router-id in SCCRQ control message, default is "" or null, can also be an IPv4 address
type: string
secret:
description: Secret, ‘’ if no auth is used
type: string
sessions:
$ref: '#/components/schemas/wxlan_tunnel_sessions'
site_id:
$ref: '#/components/schemas/site_id'
udp_port:
description: UDP port if `use_udp`==`true`
type: integer
use_udp:
default: false
description: Whether to use UDP instead of IP (proto=115, which is default of L2TPv3)
type: boolean
required:
- name
type: object
response_http404:
additionalProperties: false
properties:
id:
type: string
type: object
wxlan_tunnel_dmvpn:
additionalProperties: false
description: Dynamic Multipoint VPN configurations
properties:
enabled:
default: false
description: Whether DMVPN is enabled
type: boolean
holding_time:
description: Optional; the holding time for NHRP ‘registration requests’ and ‘resolution replies’ sent from the Mist AP (in seconds); default 600
type: integer
host_routes:
$ref: '#/components/schemas/wxlan_tunnel_dmvpn_host_routes'
type: object
modified_time:
description: When the object has been modified for the last time, in epoch
format: double
readOnly: true
type: number
response_http400:
additionalProperties: false
properties:
detail:
examples:
- 'JSON parse error - Expecting value: line 5 column 8 (char 56)'
type: string
type: object
wxlan_tunnel_sessions:
description: Sessions to be established with the tunnel. Has to be >= 1 in order for this tunnel to be useful. For management tunnel, it can only have 1
items:
$ref: '#/components/schemas/wxlan_tunnel_session'
type: array
uniqueItems: true
wxlan_tunnel_session:
additionalProperties: false
properties:
ap_as_session_id:
description: If `use_ap_as_session_ids`==`true`, only apmac is supported right now. This is the name WLAN should use for wxtunnel_remote_id
type: string
comment:
description: Optional, user-specified string for display purpose
type: string
enable_cookie:
type: boolean
ethertype:
$ref: '#/components/schemas/wxlan_tunnel_session_ethertype'
local_session_id:
description: 1-2147483647
maximum: 2147483647
minimum: 1
type: integer
pseudo_802.1ad_enabled:
default: false
description: Optional. Enables the pseudo 802.1ad QinQ mode where the AP device drops the outer vlan tag (QinQ). This mode is useful when tunneling Mist AP’s to some aggregation routers.
type: boolean
remote_id:
description: Remote-id of the session, has to be unique in the same tunnel
type: string
remote_session_id:
description: 1-2147483647
maximum: 2147483647
minimum: 1
type: integer
use_ap_as_session_ids:
default: false
description: Whether to use AP (last 4 bytes of MAC currently) as session ids
type: boolean
type: object
response_http429:
additionalProperties: false
properties:
detail:
examples:
- Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold
type: string
type: object
wxlan_tunnels:
items:
$ref: '#/components/schemas/wxlan_tunnel'
type: array
wxlan_tunnel_peers:
description: List of remote peers’ IP or hostname
items:
type: string
type: array
response_http401:
additionalProperties: false
properties:
detail:
examples:
- Authentication credentials were not provided.
type: string
type: object
wxlan_tunnel_session_ethertype:
description: 'enum: `ethernet`, `vlan`'
enum:
- ethernet
- vlan
type: string
org_id:
examples:
- a97c1b22-a4e9-411e-9bfd-d8695a0f9e61
format: uuid
readOnly: true
type: string
created_time:
description: When the object has been created, in epoch
format: double
readOnly: true
type: number
examples:
WxtunnelArrayExample:
value:
- created_time: 0
dmvpn:
enabled: true
holding_time: 0
host_routes:
- string
for_mgmt: true
hello_interval: 1
hello_retries: 3
hostname: string
id: b069b358-4c97-5319-1f8c-7c5ca64d6ab1
ipsec:
enabled: true
psk: string123
is_static: true
modified_time: 0
mtu: 1500
name: string
org_id: b069b358-4c97-5319-1f8c-7c5ca64d6ab1
peers:
- string
router_id: string
secret: string
sessions:
- ap_as_session_id: string
comment: string
enable_cookie: true
ethertype: ethernet
local_session_id: 1
pseudo_802.1ad_enabled: true
remote_id: string
remote_session_id: 1
use_ap_as_session_ids: true
site_id: b069b358-4c97-5319-1f8c-7c5ca64d6ab1
udp_port: 0
use_udp: true
HTTP400Example:
value:
detail: 'JSON parse error - Expecting value: line 5 column 8 (char 56)'
HTTP403Example:
value:
detail: You do not have permission to perform this action.
HTTP429Example:
value:
detail: Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold
WxtunnelExample:
value:
created_time: 0
dmvpn:
enabled: true
holding_time: 0
host_routes:
- string
for_mgmt: true
hello_interval: 1
hello_retries: 3
hostname: string
id: b069b358-4c97-5319-1f8c-7c5ca64d6ab1
ipsec:
enabled: true
psk: string123
is_static: true
modified_time: 0
mtu: 1500
name: string
org_id: b069b358-4c97-5319-1f8c-7c5ca64d6ab1
peers:
- string
router_id: string
secret: string
sessions:
- ap_as_session_id: string
comment: string
enable_cookie: true
ethertype: ethernet
local_session_id: 1
pseudo_802.1ad_enabled: true
remote_id: string
remote_session_id: 1
use_ap_as_session_ids: true
site_id: b069b358-4c97-5319-1f8c-7c5ca64d6ab1
udp_port: 0
use_udp: true
HTTP401Example:
value:
detail: Authentication credentials were not provided.
responses:
HTTP404:
content:
application/json:
schema:
$ref: '#/components/schemas/response_http404'
application/vnd.api+json:
schema:
$ref: '#/components/schemas/response_http404'
description: Not found. The API endpoint doesn’t exist or resource doesn’ t exist
HTTP429:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/HTTP429Example'
schema:
$ref: '#/components/schemas/response_http429'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/HTTP429Example'
schema:
$ref: '#/components/schemas/response_http429'
description: Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold
HTTP403:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/HTTP403Example'
schema:
$ref: '#/components/schemas/response_http403'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/HTTP403Example'
schema:
$ref: '#/components/schemas/response_http403'
description: Permission Denied
WxtunnelArray:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/WxtunnelArrayExample'
schema:
$ref: '#/components/schemas/wxlan_tunnels'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/WxtunnelArrayExample'
schema:
$ref: '#/components/schemas/wxlan_tunnels'
description: OK
Wxtunnel:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/WxtunnelExample'
schema:
$ref: '#/components/schemas/wxlan_tunnel'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/WxtunnelExample'
schema:
$ref: '#/components/schemas/wxlan_tunnel'
description: OK
HTTP400:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/HTTP400Example'
schema:
$ref: '#/components/schemas/response_http400'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/HTTP400Example'
schema:
$ref: '#/components/schemas/response_http400'
description: Bad Syntax
OK:
description: OK
HTTP401:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/HTTP401Example'
schema:
$ref: '#/components/schemas/response_http401'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/HTTP401Example'
schema:
$ref: '#/components/schemas/response_http401'
description: Unauthorized
securitySchemes:
apiToken:
description: "Like many other API providers, it’s also possible to generate API Tokens to be used (in HTTP Header) for authentication. An API token ties to a Admin with equal or less privileges.\n\n**Format**:\n API Token value format is `Token {apitoken}`\n\n**Notes**:\n* an API token generated for a specific admin has the same privilege as the user\n* an API token will be automatically removed if not used for > 90 days\n* SSO admins cannot generate these API tokens. Refer Org level API tokens which can have privileges of a specific Org/Site for more information."
in: header
name: Authorization
type: apiKey
basicAuth:
description: While our current UI uses Session / Cookie-based authentication, it’s also possible to do Basic Auth.
scheme: basic
type: http
csrfToken:
description: "This protects the website against [Cross Site Request Forgery](https://en.wikipedia.org/wiki/Cross-site_request_forgery), all the POST / PUT / DELETE APIs needs to have CSRF token in the AJAX Request header when using Login/Password authentication (with or without MFA)\n\n\nThe CSRF Token is sent back by Mist in the Cookies from the Login Response API Call:\n`cookies[csrftoken]` \n\nThe CSRF Token must be added in the HTTP Request Headers:\n```\nX-CSRFToken: vwvBuq9qkqaKh7lu8tNc0gkvBfEaLAmx\n```"
in: header
name: X-CSRFToken
type: apiKey