Mist Orgs Security Policies API

Security Policy is designed to audit / catch discrepancies between "what's intended to be running" versus "what's actually running" in a network. Many big organizations have separated Security and IT team (for good reasons). Each site can be assigned a security policy. Whenever an AP is provisioned, the configuration will be checked against the security policy. Any violations will be flagged in [Device Config History](/#operations/searchSiteDeviceConfigHistory) where you can search for the when and where the violation occurs.

OpenAPI Specification

mist-orgs-security-policies-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  contact:
    email: tmunzer@juniper.net
    name: Thomas Munzer
  description: '> Version: **2606.1.1**

    >

    > Date: **July 10, 2026**

    <div class="notification"> NOTE:<br>Some important API changes will be introduced. Please make sure to read the <a href="https://www.juniper.net/documentation/us/en/software/mist/api/http/guides/important-api-changes">announcements</a> </div>


    ---

    ## Additional Documentation

    * [Mist Automation Guide](https://www.juniper.net/documentation/us/en/software/mist/automation-integration/index.html)

    * [Mist Location SDK](https://www.juniper.net/documentation/us/en/software/mist/location-services/topics/concept/mist-how-get-mist-sdk.html)

    * [Mist Product Updates](https://www.juniper.net/documentation/us/en/software/mist/product-updates/)


    ## Helpful Resources

    * [API Sandbox and Exercises](https://api-class.mist.com/)

    * [Postman Collection, Runners and Webhook Samples](https://www.postman.com/juniper-mist/workspace/mist-systems-s-public-workspace)

    * [Python Script Examples](https://github.com/tmunzer/mist_library)

    * [API Demo Apps](https://apps.mist-lab.fr/)

    * [Juniper Blog](https://blogs.juniper.net/)


    ## Mist Web Browser Extension:

    * Google Chrome, Microsoft Edge and other Chromium-based browser: [Chrome Web Store](https://chromewebstore.google.com/detail/mist-extension/ejhpdcljeamillfhdihkkmoakanpbplh)

    * Firefox: [Firefox Add-ons](https://addons.mozilla.org/en-US/firefox/addon/mist-extension/)


    ---'
  license:
    name: MIT
    url: https://raw.githubusercontent.com/tmunzer/Mist-OAS3.0/main/LICENSE
  title: Mist Admins Orgs Security Policies API
  version: 2606.1.1
  x-logo:
    altText: Juniper-MistAI
    backgroundColor: '#FFFFFF'
    url: https://www.mist.com/wp-content/uploads/logo.png
servers:
- description: Mist Global 01
  url: https://api.mist.com
- description: Mist Global 02
  url: https://api.gc1.mist.com
- description: Mist Global 03
  url: https://api.ac2.mist.com
- description: Mist Global 04
  url: https://api.gc2.mist.com
- description: Mist Global 05
  url: https://api.gc4.mist.com
- description: Mist EMEA 01
  url: https://api.eu.mist.com
- description: Mist EMEA 02
  url: https://api.gc3.mist.com
- description: Mist EMEA 03
  url: https://api.ac6.mist.com
- description: Mist EMEA 04
  url: https://api.gc6.mist.com
- description: Mist APAC 01
  url: https://api.ac5.mist.com
- description: Mist APAC 02
  url: https://api.gc5.mist.com
- description: Mist APAC 03
  url: https://api.gc7.mist.com
security:
- apiToken: []
- csrfToken: []
tags:
- description: "Security Policy is designed to audit / catch discrepancies between\n\"what's intended to be running\" versus \"what's actually running\" in a network. \n\nMany big organizations have separated Security and IT team (for good reasons). Each site can be assigned a security policy.\n Whenever an AP is provisioned, the configuration will be checked against the security policy.\n Any violations will be flagged in [Device Config History](/#operations/searchSiteDeviceConfigHistory) where you can search for the when and where the violation occurs."
  name: Orgs Security Policies
paths:
  /api/v1/orgs/{org_id}/secpolicies:
    parameters:
    - $ref: '#/components/parameters/org_id'
    get:
      description: List organization security policies. Security policies define WLAN configuration baselines used to audit intended wireless settings against actual AP configuration.
      operationId: listOrgSecPolicies
      parameters:
      - $ref: '#/components/parameters/limit'
      - $ref: '#/components/parameters/page'
      responses:
        '200':
          $ref: '#/components/responses/SecpoliciesArray'
        '400':
          $ref: '#/components/responses/HTTP400'
        '401':
          $ref: '#/components/responses/HTTP401'
        '403':
          $ref: '#/components/responses/HTTP403'
        '404':
          $ref: '#/components/responses/HTTP404'
        '429':
          $ref: '#/components/responses/HTTP429'
      summary: listOrgSecPolicies
      tags:
      - Orgs Security Policies
    post:
      description: Create an organization security policy containing WLAN configuration baselines for auditing site and AP configuration compliance.
      operationId: createOrgSecPolicy
      requestBody:
        content:
          application/json:
            examples:
              Example:
                value:
                  name: string
                  wlans:
                  - acct_immediate_update: false
                    acct_interim_interval: 0
                    acct_servers:
                    - host: 1.2.3.4
                      keywrap_enabled: true
                      keywrap_format: hex
                      keywrap_kek: '1122334455'
                      keywrap_mack: '1122334455'
                      port: 1813
                      secret: testing123
                    allow_ipv6_ndp: true
                    allow_mdns: false
                    allow_ssdp: false
                    app_limit:
                      apps:
                        dropbox: 300
                        netflix: 60
                      enabled: false
                      wxtag_ids:
                        f99862d9-2726-931f-7559-3dfdf5d070d3: 30
                    app_qos:
                      apps:
                        skype-business-video:
                          dscp: 32
                          dst_subnet: 10.2.0.0/16
                          src_subnet: 10.2.0.0/16
                      enabled: true
                      others:
                      - dscp: 32
                        dst_subnet: 10.2.0.0/16
                        port_ranges: 80,1024-6553
                        protocol: udp
                        src_subnet: 10.2.0.0/16
                    arp_filter: false
                    auth:
                      anticlog_threshold: 16
                      eap_reauth: false
                      enable_mac_auth: false
                      key_idx: 1
                      keys:
                      - string
                      multi_psk_only: false
                      pairwise:
                      - wpa2-ccmp
                      private_wlan: true
                      psk: foryoureyesonly
                      type: psk
                      wep_as_secondary_auth: true
                    auth_server_selection: ordered
                    auth_servers:
                    - host: 1.2.3.4
                      keywrap_enabled: true
                      keywrap_format: hex
                      keywrap_kek: '1122334455'
                      keywrap_mack: '1122334455'
                      port: 1812
                      secret: testing123
                    auth_servers_nas_id: 5c5b350e0101-nas
                    auth_servers_nas_ip: 15.3.1.5
                    auth_servers_retries: 5
                    auth_servers_timeout: 5
                    band: string
                    band_steer: false
                    band_steer_force_band5: false
                    bands:
                    - '24'
                    - '5'
                    block_blacklist_clients: false
                    bonjour:
                      additional_vlan_ids: 10,20
                      enabled: false
                      services:
                        airplay:
                          radius_groups:
                          - teachers
                          scope: same_ap
                    cisco_cwa:
                      allowed_hostnames:
                      - snapchat.com
                      allowed_subnets:
                      - 63.5.3.0/24
                      blocked_subnets:
                      - 192.168.0.0/16
                      enabled: false
                    client_limit_down: 1000
                    client_limit_down_enabled: false
                    client_limit_up: 512
                    client_limit_up_enabled: false
                    coa_servers:
                    - disable_event_timestamp_check: false
                      enabled: false
                      ip: 1.2.3.4
                      port: 3799
                      secret: testing456
                    disable_11ax: false
                    disable_ht_vht_rates: false
                    disable_uapsd: false
                    disable_v1_roam_notify: false
                    disable_v2_roam_notify: false
                    disable_wmm: false
                    dns_server_rewrite:
                      enabled: false
                      radius_groups:
                        contractor: 172.1.1.1
                        guest: 8.8.8.8
                    dtim: 2
                    dynamic_psk:
                      default_psk: foryoureyesonly
                      default_vlan_id: 999
                      enabled: false
                      source: cloud_psks
                    dynamic_vlan:
                      default_vlan_id: 999
                      enabled: false
                      local_vlan_ids:
                      - 1
                      type: airespace-interface-name
                      vlans:
                        '131': default
                        '322': fast,video
                    enable_local_keycaching: false
                    enable_wireless_bridging: false
                    enabled: true
                    fast_dot1x_timers: false
                    hide_ssid: false
                    hostname_ie: false
                    hotspot20:
                      domain_name:
                      - mist.com
                      enabled: true
                      nai_realms:
                      - string
                      operators:
                      - google
                      - att
                      rcoi:
                      - 5A03BA0000
                      venue_name: some_name
                    interface: all
                    isolation: false
                    l2_isolation: false
                    legacy_overds: false
                    limit_bcast: false
                    limit_probe_response: true
                    max_idletime: 1800
                    mist_nac:
                      enabled: false
                    no_static_dns: false
                    no_static_ip: false
                    portal:
                      amazon_client_id: string
                      amazon_client_secret: string
                      amazon_email_domains:
                      - string
                      amazon_enabled: false
                      auth: none
                      azure_client_id: string
                      azure_client_secret: string
                      azure_enabled: false
                      azure_tenant_id: string
                      broadnet_password: password
                      broadnet_sid: MIST
                      broadnet_user_id: juniper
                      bypass_when_cloud_down: false
                      clickatell_api_key: string
                      cross_site: false
                      email_enabled: true
                      enabled: false
                      expire: 1440
                      external_portal_url: string
                      facebook_client_id: string
                      facebook_client_secret: string
                      facebook_email_domains:
                      - string
                      facebook_enabled: false
                      forward: false
                      forward_url: https://abc.com/promotions
                      google_client_id: string
                      google_client_secret: string
                      google_email_domains:
                      - mydomain.edu
                      - mydomain.org
                      google_enabled: false
                      gupshup_password: string
                      gupshup_userid: string
                      microsoft_client_id: string
                      microsoft_client_secret: string
                      microsoft_email_domains:
                      - string
                      microsoft_enabled: false
                      passphrase_enabled: false
                      password: let me in
                      predefined_sponsors_enabled: true
                      privacy: true
                      puzzel_password: string
                      puzzel_service_id: string
                      puzzel_username: string
                      smsMessageFormat: string
                      sms_enabled: false
                      sms_provider: twilio
                      sponsor_auto_approve: false
                      sponsor_email_domains:
                      - reserved.net
                      - reserved.org
                      sponsor_enabled: false
                      sponsor_link_validity_duration: '30'
                      sponsor_notify_all: false
                      sponsor_status_notify: false
                      sponsors:
                        sponsor1@company.com: FirstName1 LastName1
                        sponsor2@company.com: FirstName2 LastName2
                      sso_default_role: string
                      sso_forced_role: string
                      sso_idp_cert: string
                      sso_idp_sign_algo: sha256
                      sso_idp_sso_url: string
                      sso_issuer: string
                      sso_nameid_format: email
                      telstra_client_id: string
                      telstra_client_secret: string
                      twilio_auth_token: af9dac44c344a875ab5d31cb7abcdefg
                      twilio_phone_number: '+18548888888'
                      twilio_sid: AC72ec6ba0ec5af30e6731c5e47abcdefgh
                    portal_allowed_hostnames:
                    - snapchat.com
                    - ibm.com
                    portal_allowed_subnets:
                    - 63.5.3.0/24
                    portal_denied_hostnames:
                    - msg.snapchat.com
                    qos:
                      class: best_effort
                      overwrite: false
                    radsec:
                      enabled: true
                      idle_timeout: 60
                      mxcluster_ids:
                      - 572586b7-f97b-a22b-526c-8b97a3f609c4
                      proxy_hosts:
                      - mxedge1.local
                      server_name: radsec.abc.com
                      servers:
                      - host: 1.1.1.1
                        port: 1812
                      use_mxedge: true
                      use_site_mxedge: false
                    rateset:
                      '24':
                        ht: 00ff00ff00ff
                        legacy:
                        - '6'
                        - '9'
                        - '12'
                        - '18'
                        - 24b
                        - '36'
                        - '48'
                        - '54'
                        min_rssi: -70
                        template: custom
                        vht: 03ff03ff03ff01ff
                      '5':
                        ht: 00ff00ff00ff
                        legacy:
                        - '6'
                        - '9'
                        - '12'
                        - '18'
                        - 24b
                        - '36'
                        - '48'
                        - '54'
                        min_rssi: -70
                        template: custom
                        vht: 03ff03ff03ff01ff
                    roam_mode: NONE
                    schedule:
                      enabled: false
                      hours:
                        fri: 09:00-17:00
                        mon: 09:00-17:00
                    sle_excluded: false
                    ssid: corporate
                    use_eapol_v1: false
                    vlan_enabled: false
                    vlan_ids:
                    - 3
                    - 4
                    - 5
                    vlan_pooling: false
                    wxtag_ids:
                    - 497f6eca-6276-4993-bfeb-53e4bbba6f08
                    wxtunnel_id: string
                    wxtunnel_remote_id: string
            schema:
              $ref: '#/components/schemas/secpolicy'
      responses:
        '200':
          $ref: '#/components/responses/Secpolicy'
        '400':
          $ref: '#/components/responses/HTTP400'
        '401':
          $ref: '#/components/responses/HTTP401'
        '403':
          $ref: '#/components/responses/HTTP403'
        '404':
          $ref: '#/components/responses/HTTP404'
        '429':
          $ref: '#/components/responses/HTTP429'
      summary: createOrgSecPolicy
      tags:
      - Orgs Security Policies
  /api/v1/orgs/{org_id}/secpolicies/{secpolicy_id}:
    parameters:
    - $ref: '#/components/parameters/org_id'
    - $ref: '#/components/parameters/secpolicy_id'
    delete:
      description: Remove an organization security policy from the set available for assignment and configuration compliance checks.
      operationId: deleteOrgSecPolicy
      responses:
        '200':
          $ref: '#/components/responses/OK'
        '400':
          $ref: '#/components/responses/HTTP400'
        '401':
          $ref: '#/components/responses/HTTP401'
        '403':
          $ref: '#/components/responses/HTTP403'
        '404':
          $ref: '#/components/responses/HTTP404'
        '429':
          $ref: '#/components/responses/HTTP429'
      summary: deleteOrgSecPolicy
      tags:
      - Orgs Security Policies
    get:
      description: Return an organization security policy, including the WLAN configuration baselines used for compliance auditing.
      operationId: getOrgSecPolicy
      responses:
        '200':
          $ref: '#/components/responses/Secpolicy'
        '400':
          $ref: '#/components/responses/HTTP400'
        '401':
          $ref: '#/components/responses/HTTP401'
        '403':
          $ref: '#/components/responses/HTTP403'
        '404':
          $ref: '#/components/responses/HTTP404'
        '429':
          $ref: '#/components/responses/HTTP429'
      summary: getOrgSecPolicy
      tags:
      - Orgs Security Policies
    put:
      description: Update an organization security policy, including its name and WLAN configuration baselines for compliance auditing.
      operationId: updateOrgSecPolicy
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/secpolicy'
        description: Request Body
      responses:
        '200':
          $ref: '#/components/responses/Secpolicy'
        '400':
          $ref: '#/components/responses/HTTP400'
        '401':
          $ref: '#/components/responses/HTTP401'
        '403':
          $ref: '#/components/responses/HTTP403'
        '404':
          $ref: '#/components/responses/HTTP404'
        '429':
          $ref: '#/components/responses/HTTP429'
      summary: updateOrgSecPolicy
      tags:
      - Orgs Security Policies
components:
  schemas:
    vlan_id_with_variable:
      description: VLAN ID, either numeric or expressed as a template variable string
      oneOf:
      - type: string
      - maximum: 4094
        minimum: 1
        type: integer
    wlan_portal_sponsors:
      description: Object of allowed sponsors email with name. Required if `sponsor_enabled` is `true` and `sponsor_email_domains` is empty. Property key is the sponsor email, Property value is the sponsor name. List of email allowed for backward compatibility
      oneOf:
      - $ref: '#/components/schemas/wlan_portal_sponsors_list'
      - $ref: '#/components/schemas/wlan_portal_sponsors_object'
    wlan_limit:
      anyOf:
      - maximum: 999000
        minimum: 1
        type: integer
      - type: string
      description: In kbps, value from 1 to 999000
    wlan_airwatch:
      additionalProperties: false
      description: AirWatch integration settings for the WLAN
      properties:
        api_key:
          default: ''
          description: API key used to authenticate to the AirWatch service
          examples:
          - aHhlbGxvYXNkZmFzZGZhc2Rmc2RmCg=="
          type: string
        console_url:
          default: ''
          description: Base console URL of the AirWatch deployment
          examples:
          - https://hs1.airwatchportals.com
          type: string
        enabled:
          default: false
          description: Whether AirWatch integration is enabled for the WLAN
          type: boolean
        password:
          default: ''
          description: AirWatch integration account password for this WLAN
          examples:
          - user1
          format: password
          type: string
        username:
          default: ''
          description: AirWatch integration account username for this WLAN
          examples:
          - test123
          type: string
      type: object
    wlan_auth_owe:
      default: disabled
      description: 'if `type`==`open`. enum: `disabled`, `enabled` (means transition mode), `required`'
      enum:
      - disabled
      - enabled
      - required
      type: string
    id:
      description: Unique ID of the object instance in the Mist Organization
      examples:
      - 53f10664-3ce8-4c27-b382-0ef66432349f
      format: uuid
      readOnly: true
      type: string
    secpolicy_wlans:
      description: WLAN configurations audited by a security policy
      items:
        $ref: '#/components/schemas/wlan'
      type: array
      uniqueItems: true
    wlan_vlan_ids_string:
      description: If `vlan_enabled`==`true` and `vlan_pooling`==`true`. List of VLAN IDs to be used in the VLAN Pool
      examples:
      - 1,2
      type: string
    wlan_datarates_legacy:
      description: If `template`==`custom`. List of supported rates (IE=1) and extended supported rates (IE=50) for custom template, append ‘b’ at the end to indicate a rate being basic/mandatory. If `template`==`custom` is configured and legacy does not define at least one basic rate, it will use `no-legacy` default values
      examples:
      - - '6'
        - '9'
        - '12'
        - '18'
        - 24b
        - '36'
        - '48'
        - '54'
      items:
        $ref: '#/components/schemas/wlan_datarates_legacy_item'
      type: array
    wlan_bands:
      default:
      - '24'
      - '5'
      - '6'
      description: 'List of radios that the wlan should apply to. enum: `24`, `5`, `5-dedicated`, `5-selectable`, `6`, `6-dedicated`, `6-selectable`'
      items:
        $ref: '#/components/schemas/dot11_band'
      type: array
    wlan_portal_sponsor_email_domains:
      description: List of domain allowed for sponsor email. Required if `sponsor_enabled` is `true` and `sponsors` is empty.
      examples:
      - - reserved.net
        - reserved.org
      items:
        type: string
      type: array
    secpolicy:
      description: Security Policy is designed to audit / catch discrepancies between "what’s intended to be running" versus "what’s actually running" in a network. Many big organizations have separated Security and IT team (for good reasons). Each site can be assigned a security policy. Whenever an AP is provisioned, the configuration will be checked against the security policy. Any violations will be flagged in Device Config History where you can search for the when and where the violation occurs.
      properties:
        created_time:
          $ref: '#/components/schemas/created_time'
          description: Timestamp when the security policy was created, in epoch seconds
        id:
          $ref: '#/components/schemas/id'
          description: Unique value identifying the security policy
        modified_time:
          $ref: '#/components/schemas/modified_time'
          description: Timestamp when the security policy was last modified, in epoch seconds
        name:
          description: Display name of the security policy
          type: string
        org_id:
          $ref: '#/components/schemas/org_id'
          description: Organization identifier associated with the security policy
        site_id:
          $ref: '#/components/schemas/site_id'
          description: Site identifier associated with the security policy, when scoped to a site
        wlans:
          $ref: '#/components/schemas/secpolicy_wlans'
          description: WLAN configurations audited by this security policy
      type: object
    wlan_qos:
      additionalProperties: false
      description: QoS override settings for WLAN client traffic
      properties:
        class:
          $ref: '#/components/schemas/wlan_qos_class'
          description: QoS traffic class applied when WLAN QoS override is enabled
        overwrite:
          default: false
          description: Whether to overwrite QoS
          type: boolean
      type: object
    radius_acct_server:
      additionalProperties: false
      description: RADIUS accounting server settings
      properties:
        host:
          description: Address or hostname of the RADIUS accounting server
          examples:
          - 1.2.3.4
          type: string
        keywrap_enabled:
          description: Whether RADIUS keywrap is enabled for messages sent to this accounting server
          type: boolean
        keywrap_format:
          $ref: '#/components/schemas/radius_keywrap_format'
          description: Encoding format for RADIUS keywrap KEK and MACK values
        keywrap_kek:
          description: RADIUS keywrap key encryption key (KEK)
          examples:
          - '1122334455'
          type: string
        keywrap_mack:
          description: RADIUS keywrap message authentication code key (MACK)
          examples:
          - '1122334455'
          type: string
        port:
          $ref: '#/components/schemas/radius_acct_port'
          description: UDP port used by the RADIUS accounting server
        secret:
          description: Shared secret used with this RADIUS accounting server
          examples:
          - testing123
          format: password
          type: string
      required:
      - host
      - secret
      type: object
    wlan_portal_sms_provider:
      default: manual
      description: 'Optional if `sms_enabled`==`true`. enum: `broadnet`, `clickatell`, `gupshup`, `manual`, `puzzel`, `smsglobal`, `telstra`, `twilio`'
      enum:
      - broadnet
      - clickatell
      - gupshup
      - manual
      - puzzel
      - telstra
      - twilio
      - smsglobal
      examples:
      - twilio
      type: string
    radsec_proxy_hosts:
      description: Default is site.mxedge.radsec.proxy_hosts which must be a superset of all `wlans[*].radsec.proxy_hosts`. When `radsec.proxy_hosts` are not used, tunnel peers (org or site Mist Edges) are used irrespective of `use_site_mxedge`
      items:
        examples:
        - mxedge1.local
        type: string
      type: array
    response_http400:
      additionalProperties: false
      description: Standard HTTP 400 bad request error response
      properties:
        detail:
          description: Human-readable explanation of the bad request error
          examples:
          - 'JSON parse error - Expecting value: line 5 column 8 (char 56)'
          type: string
      type: object
    wlan_hotspot20_operators_item:
      description: 'enum: `ameriband`, `att`, `boingo`, `charter`, `eduroam`, `global_reach`, `google`, `hughes_systique`, `openroaming_legacy`, `openroaming_settled`, `openroaming_settlement_free`, `single_digits`, `tmobile`, `verizon`'
      enum:
      - ameriband
      - att
      - boingo
      - charter
      - eduroam
      - global_reach
      - google
      - hughes_systique
      - openroaming_legacy
      - openroaming_settled
      - openroaming_settlement_free
      - single_digits
      - tmobile
      - verizon
      type: string
    dscp:
      anyOf:
      - type: string
      - maximum: 63
        minimum: 0
        type: integer
      description: DSCP value range between 0 and 63
    additional_vlan_ids_array:
      description: Additional VLAN IDs represented as an array
      items:
        $ref: '#/components/schemas/vlan_id_with_variable'
      type: array
    wlan_hotspot20_operators:
      description: List of operators to support
      examples:
      - - google
        - att
      items:
        $ref: '#/components/schemas/wlan_hotspot20_operators_item'
      type: array
    wlan_app_limit:
      additionalProperties: false
      description: Bandwidth limiting for apps (applies to up/down)
      properties:
        apps:
          additionalProperties:
            type: integer
          default: {}
          description: "Map from app key to bandwidth in kbps. \nProperty key is the app key, defined in Get Application List"
          examples:
          - dropbox: 300
            netflix: 60
          type: object
        enabled:
          default: false
          description: Whether application bandwidth limits are enabled for this WLAN
          type: boolean
        wxtag_ids:
          additionalProperties:
            type: integer
          default: {}
          description: Map from wxtag_id of Hostname Wxlan Tags to bandwidth in kbps. Property key is the `wxtag_id`
          examples:
          - f99862d9-2726-931f-7559-3dfdf5d070d3: 30
          type: object
      type: object
    radsec_server:
      additionalProperties: false
      description: External RadSec server settings
      properties:
        host:
          description: Address or hostname of the RadSec server
          examples:
          - 1.1.1.1
          type: string
        port:
          description: TCP port used by the RadSec server
          examples:
          - 1812
          maximum: 65535
          minimum: 1
          type: integer
      type: object
    site_id:
      description: Unique identifier of a Mist site
      examples:
      - 441a1214-6928-442a-8e92-e1d34b8ec6a6
      format: uuid
      readOnly: true
      type: string
    msp_id:
      description: Managed service provider identifier
      examples:
      - b9d42c2e-88ee-41f8-b798-f009ce7fe909
      format: uuid
      readOnly: true
      type: string
    wlan_vlan_id_with_variable:
      description: WLAN VLAN ID, either numeric, a variable string, or null
      oneOf:
      - type: string
      - maximum: 4094
        minimum: 1
        type: integer
      - type: 'null'
    wlan_datarates_template:
      default: compatible
      description: "Data Rates template to apply. enum: \n  * `no-legacy`: no 11b\n  * `compatible`: all, like before, default setting that Broadcom/Atheros used\n  * `legacy-only`: disable 802.11n and 802.11ac\n  * `high-density`: no 11b, no low rates\n  * `custom`: user defined"
      enum:
      - compatible
      - legacy-only
      - custom
      - no-legacy
      - high-density
      type:
      - string
      - 'null'
    wlan_auth:
      additionalProperties: false
      description: WLAN client authentication settings
      properties:
        anticlog_threshold:
          default: 16
          description: SAE anti-clogging token threshold
          examples:
          - 16
          maximum: 32
          minimum: 16
          type: integer
        eap_reauth:
          default: false
          description: Whether to trigger EAP reauth when the session ends
          type: boolean
        enable_beacon_protection:
          default: false
          description: Enable Beacon Protection; default is false for better compatibility
          type: boolean
        enable_gcmp256:
          default: false
          description: Enable GCMP-256 encryption suite; default is false for better compatibility
          type: boolean
        enable_mac_auth:
          default: false
          description: Whether to enable MAC Auth, uses the same auth_servers
          type: boolean
        key_idx:
          default: 1
          description: When `type`==`wep`, index of the WEP key used as the default transmit key
          maximum: 4
          minimum: 1
          type: integer
        keys:
          $ref: '#/components/schemas/wlan_auth_keys'
          description: When `type`==`wep`, WEP keys configured for this WLAN
        multi_psk_only:
          default: false
          description: When `type`==`psk`, whether to only use multi_psk
          type: boolean
        owe:
          $ref: '#/components/schemas/wlan_auth_owe'
          description: When `type`==`open`, Opportunistic Wireless Encryption mode 

# --- truncated at 32 KB (110 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/mist/refs/heads/main/openapi/mist-orgs-security-policies-api-openapi.yml