Mist Orgs SDK Invites API
SDK Invites can be generated for (and belongs to) an Org. They can be generated by an Admin of an Org and can be revoked at anytime.
SDK Invites can be generated for (and belongs to) an Org. They can be generated by an Admin of an Org and can be revoked at anytime.
openapi: 3.1.0
info:
contact:
email: tmunzer@juniper.net
name: Thomas Munzer
description: '> Version: **2606.1.1**
>
> Date: **July 10, 2026**
<div class="notification"> NOTE:<br>Some important API changes will be introduced. Please make sure to read the <a href="https://www.juniper.net/documentation/us/en/software/mist/api/http/guides/important-api-changes">announcements</a> </div>
---
## Additional Documentation
* [Mist Automation Guide](https://www.juniper.net/documentation/us/en/software/mist/automation-integration/index.html)
* [Mist Location SDK](https://www.juniper.net/documentation/us/en/software/mist/location-services/topics/concept/mist-how-get-mist-sdk.html)
* [Mist Product Updates](https://www.juniper.net/documentation/us/en/software/mist/product-updates/)
## Helpful Resources
* [API Sandbox and Exercises](https://api-class.mist.com/)
* [Postman Collection, Runners and Webhook Samples](https://www.postman.com/juniper-mist/workspace/mist-systems-s-public-workspace)
* [Python Script Examples](https://github.com/tmunzer/mist_library)
* [API Demo Apps](https://apps.mist-lab.fr/)
* [Juniper Blog](https://blogs.juniper.net/)
## Mist Web Browser Extension:
* Google Chrome, Microsoft Edge and other Chromium-based browser: [Chrome Web Store](https://chromewebstore.google.com/detail/mist-extension/ejhpdcljeamillfhdihkkmoakanpbplh)
* Firefox: [Firefox Add-ons](https://addons.mozilla.org/en-US/firefox/addon/mist-extension/)
---'
license:
name: MIT
url: https://raw.githubusercontent.com/tmunzer/Mist-OAS3.0/main/LICENSE
title: Mist Admins Orgs SDK Invites API
version: 2606.1.1
x-logo:
altText: Juniper-MistAI
backgroundColor: '#FFFFFF'
url: https://www.mist.com/wp-content/uploads/logo.png
servers:
- description: Mist Global 01
url: https://api.mist.com
- description: Mist Global 02
url: https://api.gc1.mist.com
- description: Mist Global 03
url: https://api.ac2.mist.com
- description: Mist Global 04
url: https://api.gc2.mist.com
- description: Mist Global 05
url: https://api.gc4.mist.com
- description: Mist EMEA 01
url: https://api.eu.mist.com
- description: Mist EMEA 02
url: https://api.gc3.mist.com
- description: Mist EMEA 03
url: https://api.ac6.mist.com
- description: Mist EMEA 04
url: https://api.gc6.mist.com
- description: Mist APAC 01
url: https://api.ac5.mist.com
- description: Mist APAC 02
url: https://api.gc5.mist.com
- description: Mist APAC 03
url: https://api.gc7.mist.com
security:
- apiToken: []
- csrfToken: []
tags:
- description: SDK Invites can be generated for (and belongs to) an Org. They can be generated by an Admin of an Org and can be revoked at anytime.
name: Orgs SDK Invites
paths:
/api/v1/mobile/verify/{secret}:
parameters:
- $ref: '#/components/parameters/secret'
post:
description: Activate a mobile SDK invite by verifying the invite secret and binding it to the supplied device identifier. The response returns the device-specific secret used by the mobile SDK client.
operationId: activateSdkInvite
requestBody:
content:
application/json:
examples:
Example:
value:
device_id: b069b358-4c97-5319-1f8c-7c5ca64d6ab1
schema:
$ref: '#/components/schemas/device_id_string'
responses:
'200':
$ref: '#/components/responses/MobileVerifySecret'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: activateSdkInvite
tags:
- Orgs SDK Invites
/api/v1/orgs/{org_id}/sdkinvites:
parameters:
- $ref: '#/components/parameters/org_id'
get:
description: List SDK invites configured for the organization. SDK invites are used to onboard mobile SDK clients and can define whether an invite is enabled, limited by usage quota, or scoped to a site.
operationId: listSdkInvites
responses:
'200':
$ref: '#/components/responses/SdkinvitesArray'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: listSdkInvites
tags:
- Orgs SDK Invites
post:
description: Create an SDK invite that mobile SDK clients can use to onboard into the organization. The invite can be enabled or disabled, limited by usage quota, and associated with a site.
operationId: createSdkInvite
requestBody:
content:
application/json:
examples:
Example:
value:
enabled: true
name: string
quota: 0
quota_limited: true
schema:
$ref: '#/components/schemas/sdkinvite'
description: Request Body
responses:
'200':
$ref: '#/components/responses/Sdkinvite'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: createSdkInvite
tags:
- Orgs SDK Invites
/api/v1/orgs/{org_id}/sdkinvites/{sdkinvite_id}:
parameters:
- $ref: '#/components/parameters/org_id'
- $ref: '#/components/parameters/sdkinvite_id'
delete:
description: Revoke an SDK invite so it can no longer be used for mobile SDK client onboarding.
operationId: revokeSdkInvite
responses:
'200':
$ref: '#/components/responses/OK'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: revokeSdkInvite
tags:
- Orgs SDK Invites
get:
description: Return the configuration and status of an SDK invite, including enablement, expiration time, usage quota, and site scope.
operationId: getSdkInvite
responses:
'200':
$ref: '#/components/responses/Sdkinvite'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: getSdkInvite
tags:
- Orgs SDK Invites
put:
description: Update an SDK invite's onboarding settings, such as its display name, enabled state, expiration time, quota, or site association.
operationId: updateSdkInvite
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/sdkinvite'
description: Request Body
responses:
'200':
$ref: '#/components/responses/Sdkinvite'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: updateSdkInvite
tags:
- Orgs SDK Invites
/api/v1/orgs/{org_id}/sdkinvites/{sdkinvite_id}/email:
parameters:
- $ref: '#/components/parameters/org_id'
- $ref: '#/components/parameters/sdkinvite_id'
post:
description: Send the SDK invite to a recipient email address so the recipient can onboard a mobile SDK client.
operationId: sendSdkInviteEmail
requestBody:
content:
application/json:
examples:
Example:
value:
email: test@abc.com
schema:
$ref: '#/components/schemas/email_string'
description: Request Body
responses:
'200':
$ref: '#/components/responses/OK'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: sendSdkInviteEmail
tags:
- Orgs SDK Invites
/api/v1/orgs/{org_id}/sdkinvites/{sdkinvite_id}/qrcode:
parameters:
- $ref: '#/components/parameters/org_id'
- $ref: '#/components/parameters/sdkinvite_id'
get:
description: Download a QR code image for the SDK invite so it can be scanned by a mobile SDK client during onboarding.
operationId: getSdkInviteQrCode
responses:
'200':
$ref: '#/components/responses/File'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: getSdkInviteQrCode
tags:
- Orgs SDK Invites
/api/v1/orgs/{org_id}/sdkinvites/{sdkinvite_id}/sms:
parameters:
- $ref: '#/components/parameters/org_id'
- $ref: '#/components/parameters/sdkinvite_id'
post:
description: Send the SDK invite to a phone number by SMS so the recipient can onboard a mobile SDK client.
operationId: sendSdkInviteSms
requestBody:
content:
application/json:
examples:
Example:
value:
number: '14081234567'
schema:
$ref: '#/components/schemas/sdk_invite_sms'
description: Request Body
responses:
'200':
$ref: '#/components/responses/OK'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: sendSdkInviteSms
tags:
- Orgs SDK Invites
components:
responses:
MobileVerifySecret:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/MobileVerifySecretExample'
schema:
$ref: '#/components/schemas/response_mobile_verify_secret'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/MobileVerifySecretExample'
schema:
$ref: '#/components/schemas/response_mobile_verify_secret'
description: OK
OK:
description: OK
SdkinvitesArray:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/SdkinvitesArrayExample'
schema:
$ref: '#/components/schemas/sdkinvite_list'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/SdkinvitesArrayExample'
schema:
$ref: '#/components/schemas/sdkinvite_list'
description: OK
File:
content:
application/json:
schema:
contentMediaType: application/octet-stream
description: File
type: string
application/vnd.api+json:
schema:
contentMediaType: application/octet-stream
description: File
type: string
description: OK
HTTP400:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/HTTP400Example'
schema:
$ref: '#/components/schemas/response_http400'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/HTTP400Example'
schema:
$ref: '#/components/schemas/response_http400'
description: Bad Syntax
HTTP403:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/HTTP403Example'
schema:
$ref: '#/components/schemas/response_http403'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/HTTP403Example'
schema:
$ref: '#/components/schemas/response_http403'
description: Permission Denied
Sdkinvite:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/SdkinviteExample'
schema:
$ref: '#/components/schemas/sdkinvite'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/SdkinviteExample'
schema:
$ref: '#/components/schemas/sdkinvite'
description: OK
HTTP404:
content:
application/json:
schema:
$ref: '#/components/schemas/response_http404'
application/vnd.api+json:
schema:
$ref: '#/components/schemas/response_http404'
description: Not found. The API endpoint doesn’t exist or resource doesn’ t exist
HTTP429:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/HTTP429Example'
schema:
$ref: '#/components/schemas/response_http429'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/HTTP429Example'
schema:
$ref: '#/components/schemas/response_http429'
description: Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold
HTTP401:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/HTTP401Example'
schema:
$ref: '#/components/schemas/response_http401'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/HTTP401Example'
schema:
$ref: '#/components/schemas/response_http401'
description: Unauthorized
schemas:
sdkinvite_list:
description: SDK invite configurations returned by list operations
items:
$ref: '#/components/schemas/sdkinvite'
type: array
id:
description: Unique ID of the object instance in the Mist Organization
examples:
- 53f10664-3ce8-4c27-b382-0ef66432349f
format: uuid
readOnly: true
type: string
org_id:
description: Unique identifier of a Mist organization
examples:
- a97c1b22-a4e9-411e-9bfd-d8695a0f9e61
format: uuid
readOnly: true
type: string
response_http401:
additionalProperties: false
description: Standard HTTP 401 authentication error response
properties:
detail:
description: Human-readable explanation of the authentication error
examples:
- Authentication credentials were not provided.
type: string
type: object
response_http429:
additionalProperties: false
description: Standard HTTP 429 rate limit error response
properties:
detail:
description: Human-readable explanation of the rate limit error
examples:
- Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold
type: string
type: object
created_time:
description: When the object has been created, in epoch
format: double
readOnly: true
type: number
device_id_string:
description: Request body containing a device identifier
properties:
device_id:
description: Device identifier supplied by the request
format: uuid
type: string
required:
- device_id
type: object
response_http403:
additionalProperties: false
description: Standard HTTP 403 permission error response
properties:
detail:
description: Human-readable explanation of the permission error
examples:
- You do not have permission to perform this action.
type: string
type: object
sdkinvite:
description: SDK invite configuration used to onboard mobile SDK clients to an organization
properties:
created_time:
$ref: '#/components/schemas/created_time'
description: Timestamp when the SDK invite was created, in epoch seconds
enabled:
default: true
description: Whether the SDK invite can currently be used
type: boolean
expire_time:
description: Expiration time for the SDK invite, in epoch seconds
type: integer
id:
$ref: '#/components/schemas/id'
description: Unique value identifying the SDK invite
modified_time:
$ref: '#/components/schemas/modified_time'
description: Timestamp when the SDK invite was last modified, in epoch seconds
name:
description: Display name shown for the SDK invite in the mobile experience
type: string
org_id:
$ref: '#/components/schemas/org_id'
description: Organization identifier associated with the SDK invite
quota:
description: Number of times this SDK invite can be used
type: integer
quota_limited:
default: false
description: Whether use of the SDK invite is limited by the quota value
type: boolean
site_id:
$ref: '#/components/schemas/site_id'
description: Site identifier associated with the SDK invite, when scoped to a site
required:
- name
type: object
response_http400:
additionalProperties: false
description: Standard HTTP 400 bad request error response
properties:
detail:
description: Human-readable explanation of the bad request error
examples:
- 'JSON parse error - Expecting value: line 5 column 8 (char 56)'
type: string
type: object
sdk_invite_sms:
description: Request body for sending an SDK invite by SMS
properties:
number:
description: Destination phone number for the SDK invite SMS
type: string
required:
- number
type: object
site_id:
description: Unique identifier of a Mist site
examples:
- 441a1214-6928-442a-8e92-e1d34b8ec6a6
format: uuid
readOnly: true
type: string
email_string:
description: Request body containing an email address
properties:
email:
description: Request email address provided in the payload
format: email
type: string
required:
- email
type: object
response_mobile_verify_secret:
additionalProperties: false
description: Mobile SDK invite verification response
properties:
name:
description: Organization display name associated with the verified SDK invite
type: string
org_id:
$ref: '#/components/schemas/org_id'
description: Organization identifier associated with the verified SDK invite
secret:
description: Device-specific secret returned for mobile SDK activation
format: password
type: string
required:
- name
- org_id
- secret
type: object
modified_time:
description: When the object has been modified for the last time, in epoch
format: double
readOnly: true
type: number
response_http404:
additionalProperties: false
description: Standard HTTP 404 not found error response
properties:
id:
description: Missing resource identifier, when the API includes one
type: string
type: object
parameters:
org_id:
in: path
name: org_id
required: true
schema:
examples:
- 000000ab-00ab-00ab-00ab-0000000000ab
format: uuid
type: string
secret:
in: path
name: secret
required: true
schema:
type: string
sdkinvite_id:
in: path
name: sdkinvite_id
required: true
schema:
examples:
- 000000ab-00ab-00ab-00ab-0000000000ab
format: uuid
type: string
examples:
HTTP403Example:
value:
detail: You do not have permission to perform this action.
HTTP400Example:
value:
detail: 'JSON parse error - Expecting value: line 5 column 8 (char 56)'
SdkinvitesArrayExample:
value:
- created_time: 1428954000
enabled: true
expire_time: 1428954000
id: 5034b980-b49e-501c-66e0-9de4c38f18a2
name: Macy's
quota: -1
MobileVerifySecretExample:
value:
name: Macy's
org_id: b069b358-4c97-5319-1f8c-7c5ca64d6ab1
secret: device-specific-secret
HTTP429Example:
value:
detail: Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold
SdkinviteExample:
value:
created_time: 1428954000
enabled: true
expire_time: 1428954000
id: 5034b980-b49e-501c-66e0-9de4c38f18a2
name: Macy's
quota: -1
HTTP401Example:
value:
detail: Authentication credentials were not provided.
securitySchemes:
apiToken:
description: "Preferred authentication method for automation and integrations. Send the API token in the HTTP `Authorization` header.\n\n**Format**:\n `Authorization: Token {apitoken}`\n\n**Notes**:\n* An API token generated for a specific admin has the same privileges as that admin\n* An API token is automatically removed if it is not used for more than 90 days\n* SSO admins cannot generate admin API tokens. Use organization API tokens when scoped Org/Site privileges are needed."
in: header
name: Authorization
type: apiKey
csrfToken:
description: 'Session-based authentication for browser or login/password flows. After a successful [Login](/#operations/login) request, Mist returns a `csrftoken` cookie. Send that value in the `X-CSRFToken` header on later API requests that use the login session.
**Format**:
```
X-CSRFToken: vwvBuq9qkqaKh7lu8tNc0gkvBfEaLAmx
```
For automation, API Token authentication is preferred.'
in: header
name: X-CSRFToken
type: apiKey