Mist Sites Clients - NAC API

NAC Clients are devices connected to the network and authenticated by Juniper Mist Access Assurance.

OpenAPI Specification

mist-sites-clients-nac-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  contact:
    email: tmunzer@juniper.net
    name: Thomas Munzer
  description: '> Version: **2606.1.1**

    >

    > Date: **July 10, 2026**

    <div class="notification"> NOTE:<br>Some important API changes will be introduced. Please make sure to read the <a href="https://www.juniper.net/documentation/us/en/software/mist/api/http/guides/important-api-changes">announcements</a> </div>


    ---

    ## Additional Documentation

    * [Mist Automation Guide](https://www.juniper.net/documentation/us/en/software/mist/automation-integration/index.html)

    * [Mist Location SDK](https://www.juniper.net/documentation/us/en/software/mist/location-services/topics/concept/mist-how-get-mist-sdk.html)

    * [Mist Product Updates](https://www.juniper.net/documentation/us/en/software/mist/product-updates/)


    ## Helpful Resources

    * [API Sandbox and Exercises](https://api-class.mist.com/)

    * [Postman Collection, Runners and Webhook Samples](https://www.postman.com/juniper-mist/workspace/mist-systems-s-public-workspace)

    * [Python Script Examples](https://github.com/tmunzer/mist_library)

    * [API Demo Apps](https://apps.mist-lab.fr/)

    * [Juniper Blog](https://blogs.juniper.net/)


    ## Mist Web Browser Extension:

    * Google Chrome, Microsoft Edge and other Chromium-based browser: [Chrome Web Store](https://chromewebstore.google.com/detail/mist-extension/ejhpdcljeamillfhdihkkmoakanpbplh)

    * Firefox: [Firefox Add-ons](https://addons.mozilla.org/en-US/firefox/addon/mist-extension/)


    ---'
  license:
    name: MIT
    url: https://raw.githubusercontent.com/tmunzer/Mist-OAS3.0/main/LICENSE
  title: Mist Admins Sites Clients - NAC API
  version: 2606.1.1
  x-logo:
    altText: Juniper-MistAI
    backgroundColor: '#FFFFFF'
    url: https://www.mist.com/wp-content/uploads/logo.png
servers:
- description: Mist Global 01
  url: https://api.mist.com
- description: Mist Global 02
  url: https://api.gc1.mist.com
- description: Mist Global 03
  url: https://api.ac2.mist.com
- description: Mist Global 04
  url: https://api.gc2.mist.com
- description: Mist Global 05
  url: https://api.gc4.mist.com
- description: Mist EMEA 01
  url: https://api.eu.mist.com
- description: Mist EMEA 02
  url: https://api.gc3.mist.com
- description: Mist EMEA 03
  url: https://api.ac6.mist.com
- description: Mist EMEA 04
  url: https://api.gc6.mist.com
- description: Mist APAC 01
  url: https://api.ac5.mist.com
- description: Mist APAC 02
  url: https://api.gc5.mist.com
- description: Mist APAC 03
  url: https://api.gc7.mist.com
security:
- apiToken: []
- csrfToken: []
tags:
- description: NAC Clients are devices connected to the network and authenticated by Juniper Mist Access Assurance.
  name: Sites Clients - NAC
paths:
  /api/v1/sites/{site_id}/nac_clients/count:
    parameters:
    - $ref: '#/components/parameters/site_id'
    get:
      description: Count NAC clients for a site, optionally grouped by the `distinct` field and filtered by authentication, identity, endpoint, network, and time attributes. Use [Count Org NAC Clients](/#operations/countOrgNacClients) to count NAC clients across the organization.
      operationId: countSiteNacClients
      parameters:
      - description: 'Field used to group this count response. enum: `ap`, `auth_type`, `device_mac`, `edr_managed`, `edr_provider`, `edr_status`, `family`, `hostname`, `idp_id`, `mfg`, `mdm_compliance`, `mdm_managed`, `mdm_provider`, `model`, `mxedge_id`, `nacrule_matched`, `nacrule_name`, `nacrule_id`, `nas_ip`, `nas_vendor`, `os`, `ssid`, `status`, `type`, `usermac_label`, `username`, `vlan`'
        in: query
        name: distinct
        schema:
          $ref: '#/components/schemas/site_nac_clients_count_distinct'
      - description: NAC Policy Rule ID, if matched
        in: query
        name: last_nacrule_id
        schema:
          type: string
      - description: NAC Policy Rule Matched
        in: query
        name: nacrule_matched
        schema:
          type: boolean
      - description: Authentication type, e.g. "eap-tls", "eap-peap", "eap-ttls", "eap-teap", "mab", "psk", "device-auth"
        in: query
        name: auth_type
        schema:
          type: string
      - description: Filter results by last VLAN ID
        in: query
        name: last_vlan_id
        schema:
          type: string
      - description: Vendor of NAS device
        in: query
        name: last_nas_vendor
        schema:
          type: string
      - description: SSO ID, if present and used
        in: query
        name: idp_id
        schema:
          type: string
      - description: Filter results by last SSID
        in: query
        name: last_ssid
        schema:
          type: string
      - description: Username presented by the client
        in: query
        name: last_username
        schema:
          type: string
      - description: AP MAC connected to by client
        in: query
        name: last_ap
        schema:
          type: string
      - description: Filter results by MAC address
        in: query
        name: mac
        schema:
          type: string
      - description: Connection status of client i.e "permitted", "denied, "session_ended"
        in: query
        name: last_status
        schema:
          type: string
      - description: Client type i.e. "wireless", "wired" etc.
        in: query
        name: type
        schema:
          type: string
      - description: MDM compliance of client i.e "compliant", "not compliant"
        in: query
        name: mdm_compliance_status
        schema:
          type: string
      - description: MDM provider of client’s organisation eg "intune", "jamf"
        in: query
        name: mdm_provider
        schema:
          type: string
      - $ref: '#/components/parameters/start'
      - $ref: '#/components/parameters/end'
      - $ref: '#/components/parameters/duration'
      - $ref: '#/components/parameters/limit'
      responses:
        '200':
          $ref: '#/components/responses/Count'
        '400':
          $ref: '#/components/responses/HTTP400'
        '401':
          $ref: '#/components/responses/HTTP401'
        '403':
          $ref: '#/components/responses/HTTP403'
        '404':
          $ref: '#/components/responses/HTTP404'
        '429':
          $ref: '#/components/responses/HTTP429'
      summary: countSiteNacClients
      tags:
      - Sites Clients - NAC
  /api/v1/sites/{site_id}/nac_clients/events/count:
    parameters:
    - $ref: '#/components/parameters/site_id'
    get:
      description: Count NAC client events for a site, optionally grouped by the `distinct` field and filtered by event type and time range. Use [Count Org NAC Client Events](/#operations/countOrgNacClientEvents) to count NAC client events across the organization.
      operationId: countSiteNacClientEvents
      parameters:
      - description: 'Field used to group this count response. enum: `ap`, `auth_type`, `dryrun_nacrule_id`, `mac`, `nacrule_id`, `nas_vendor`, `ssid`, `type`, `username`, `vlan`'
        in: query
        name: distinct
        schema:
          $ref: '#/components/schemas/site_nac_client_events_count_distinct'
      - $ref: '#/components/parameters/nac_event_type'
      - $ref: '#/components/parameters/start'
      - $ref: '#/components/parameters/end'
      - $ref: '#/components/parameters/duration'
      - $ref: '#/components/parameters/limit'
      responses:
        '200':
          $ref: '#/components/responses/Count'
        '400':
          $ref: '#/components/responses/HTTP400'
        '401':
          $ref: '#/components/responses/HTTP401'
        '403':
          $ref: '#/components/responses/HTTP403'
        '404':
          $ref: '#/components/responses/HTTP404'
        '429':
          $ref: '#/components/responses/HTTP429'
      summary: countSiteNacClientEvents
      tags:
      - Sites Clients - NAC
  /api/v1/sites/{site_id}/nac_clients/events/search:
    parameters:
    - $ref: '#/components/parameters/site_id'
    get:
      description: Search NAC client events for a site with filters for authentication, NAC rule, identity provider, RADIUS, network, endpoint, and time attributes. Use [Search Org NAC Client Events](/#operations/searchOrgNacClientEvents) to search NAC client events across the organization.
      operationId: searchSiteNacClientEvents
      parameters:
      - $ref: '#/components/parameters/nac_event_type'
      - description: NAC Policy Rule ID, if matched
        in: query
        name: nacrule_id
        schema:
          format: uuid
          type: string
      - description: NAC Policy Rule Matched
        in: query
        name: nacrule_matched
        schema:
          type: boolean
      - description: NAC Policy Dry Run Rule ID, if present and matched
        in: query
        name: dryrun_nacrule_id
        schema:
          type: string
      - description: True - if dryrun rule present and matched with priority, False - if not matched or not present
        in: query
        name: dryrun_nacrule_matched
        schema:
          type: boolean
      - description: Authentication type, e.g. "eap-tls", "eap-peap", "eap-ttls", "eap-teap", "mab", "psk", "device-auth"
        in: query
        name: auth_type
        schema:
          type: string
      - description: Filter results by VLAN ID
        in: query
        name: vlan
        schema:
          type: integer
      - description: Vendor of NAS device
        in: query
        name: nas_vendor
        schema:
          type: string
      - description: Filter results by BSSID
        in: query
        name: bssid
        schema:
          type: string
      - description: SSO ID, if present and used
        in: query
        name: idp_id
        schema:
          format: uuid
          type: string
      - description: IDP returned roles/groups for the user
        in: query
        name: idp_role
        schema:
          type: string
      - description: Username presented to the Identity Provider
        in: query
        name: idp_username
        schema:
          type: string
      - description: RADIUS attributes returned by NAC to NAS Devive
        in: query
        name: resp_attrs
        schema:
          $ref: '#/components/schemas/resp_attrs'
      - description: Filter results by SSID
        in: query
        name: ssid
        schema:
          type: string
      - description: Filter results by username
        in: query
        name: username
        schema:
          type: string
      - description: Filter results by AP MAC address
        in: query
        name: ap
        schema:
          type: string
      - description: Filter results by whether the client is using a randomized MAC address
        in: query
        name: random_mac
        schema:
          type: boolean
      - description: Filter results by MAC address
        in: query
        name: mac
        schema:
          type: string
      - description: Labels derived from usermac entry
        in: query
        name: usermac_label
        schema:
          type: string
      - description: Partial / full MAC address, username, device_mac or ap. Use `prefix*` for prefix search or `*substring*` for contains search (e.g. `aabbcc*` and `*bbcc*` match `aabbccddeeff`). Suffix-only wildcards (e.g. `*bccddeeff`) are not supported
        in: query
        name: text
        schema:
          type: string
      - description: IP address of NAS device
        in: query
        name: nas_ip
        schema:
          type: string
      - description: Vendor specific VLAN ID in RADIUS requests
        in: query
        name: ingress_vlan
        schema:
          type: string
      - $ref: '#/components/parameters/start'
      - $ref: '#/components/parameters/end'
      - $ref: '#/components/parameters/duration'
      - $ref: '#/components/parameters/limit'
      - $ref: '#/components/parameters/sort_wcid'
      - $ref: '#/components/parameters/search_after'
      responses:
        '200':
          $ref: '#/components/responses/EventsNacClientSearch'
        '400':
          $ref: '#/components/responses/HTTP400'
        '401':
          $ref: '#/components/responses/HTTP401'
        '403':
          $ref: '#/components/responses/HTTP403'
        '404':
          $ref: '#/components/responses/HTTP404'
        '429':
          $ref: '#/components/responses/HTTP429'
      summary: searchSiteNacClientEvents
      tags:
      - Sites Clients - NAC
  /api/v1/sites/{site_id}/nac_clients/search:
    parameters:
    - $ref: '#/components/parameters/site_id'
    get:
      description: Search NAC clients for a site with filters for authentication, endpoint posture, identity, network, NAC rule, and time attributes. Use [Search Org NAC Clients](/#operations/searchOrgNacClients) to search NAC clients across the organization.
      operationId: searchSiteNacClients
      parameters:
      - description: MAC address of the AP the client is/was connected to
        in: query
        name: ap
        schema:
          type: string
      - description: Authentication type, e.g. "eap-tls", "eap-peap", "eap-ttls", "eap-teap", "mab", "psk", "device-auth"
        in: query
        name: auth_type
        schema:
          type: string
      - description: Filter by certificate expiry within a specific duration from now (e.g., "7d" for 7 days, "1m" for 1 month)
        in: query
        name: cert_expiry_duration
        schema:
          examples:
          - 7d
          - 1m
          type: string
      - description: Filters NAC clients that are integrated with EDR providers
        in: query
        name: edr_managed
        schema:
          type: boolean
      - description: 'EDR provider used to filter NAC clients. enum: `crowdstrike`, `sentinelone`'
        in: query
        name: edr_provider
        schema:
          $ref: '#/components/schemas/edr_provider'
      - description: 'EDR status used to filter NAC clients. enum: `sentinelone_healthy`, `sentinelone_infected`, `crowdstrike_low`, `crowdstrike_medium`, `crowdstrike_high`, `crowdstrike_critical`, `crowdstrike_informational`'
        in: query
        name: edr_status
        schema:
          $ref: '#/components/schemas/edr_status'
      - $ref: '#/components/parameters/partial_filter_family_client'
      - $ref: '#/components/parameters/partial_filter_hostname_client'
      - description: SSO ID, if present and used
        in: query
        name: idp_id
        schema:
          type: string
      - $ref: '#/components/parameters/partial_filter_mac_client'
      - description: MDM compliance of client i.e "compliant", "not compliant"
        in: query
        name: mdm_compliance
        schema:
          type: string
      - description: MDM provider of client’s organization eg "intune", "jamf"
        in: query
        name: mdm_provider
        schema:
          type: string
      - description: Filters NAC clients that are managed by MDM providers
        in: query
        name: mdm_managed
        schema:
          type: boolean
      - $ref: '#/components/parameters/partial_filter_mfg_client'
      - description: Client model, e.g. "iPhone 12", "MX100"
        in: query
        name: model
        schema:
          type: string
      - description: NAC Policy Rule Name matched
        in: query
        name: nacrule_name
        schema:
          type: string
      - description: NAC Policy Rule ID, if matched
        in: query
        name: nacrule_id
        schema:
          type: string
      - description: NAC Policy Rule Matched
        in: query
        name: nacrule_matched
        schema:
          type: boolean
      - description: Vendor of NAS device
        in: query
        name: nas_vendor
        schema:
          type: string
      - description: IP address of NAS device
        in: query
        name: nas_ip
        schema:
          type: string
      - description: Vendor specific VLAN ID in RADIUS requests
        in: query
        name: ingress_vlan
        schema:
          type: string
      - description: Client OS, e.g. "iOS 18.1", "Android", "Windows", "Linux"
        in: query
        name: os
        schema:
          type: string
      - description: Filter results by SSID
        in: query
        name: ssid
        schema:
          type: string
      - description: 'Client connection status used to filter results. enum: `permitted`, `session_started`, `session_stopped`, `denied`'
        in: query
        name: status
        schema:
          $ref: '#/components/schemas/nac_client_last_status'
      - description: partial / full MAC address, last_username, device_mac, nas_ip. Use `prefix*` for prefix search or `*substring*` for contains search (e.g. `aabbcc*` and `*bbcc*` match `aabbccddeeff`). Suffix-only wildcards (e.g. `*bccddeeff`) are not supported.
        in: query
        name: text
        schema:
          type: string
      - description: Client type i.e. "wireless", "wired" etc.
        in: query
        name: type
        schema:
          type: string
      - description: Labels derived from usermac entry
        in: query
        name: usermac_label
        schema:
          $ref: '#/components/schemas/strings'
      - description: Filter results by username
        in: query
        name: username
        schema:
          type: string
      - description: Filter results by VLAN ID
        in: query
        name: vlan
        schema:
          type: string
      - $ref: '#/components/parameters/limit'
      - $ref: '#/components/parameters/start'
      - $ref: '#/components/parameters/end'
      - $ref: '#/components/parameters/duration'
      - $ref: '#/components/parameters/sort_wcid'
      - $ref: '#/components/parameters/search_after'
      responses:
        '200':
          $ref: '#/components/responses/ClientNacSearch'
        '400':
          $ref: '#/components/responses/HTTP400'
        '401':
          $ref: '#/components/responses/HTTP401'
        '403':
          $ref: '#/components/responses/HTTP403'
        '404':
          $ref: '#/components/responses/HTTP404'
        '429':
          $ref: '#/components/responses/HTTP429'
      summary: searchSiteNacClients
      tags:
      - Sites Clients - NAC
  /api/v1/sites/{site_id}/nac_clients/{client_mac}/coa:
    parameters:
    - $ref: '#/components/parameters/site_id'
    - $ref: '#/components/parameters/client_mac'
    post:
      description: Sends CoA (Change of Authorization) command to a NAC client.
      operationId: sendSiteNacClientCoA
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/nac_client_coa'
        description: Request Body
      responses:
        '200':
          $ref: '#/components/responses/NacClientCoa'
        '400':
          $ref: '#/components/responses/HTTP400'
        '401':
          $ref: '#/components/responses/HTTP401'
        '403':
          $ref: '#/components/responses/HTTP403'
        '404':
          $ref: '#/components/responses/HTTP404'
        '429':
          $ref: '#/components/responses/HTTP429'
      summary: sendSiteNacClientCoA
      tags:
      - Sites Clients - NAC
components:
  schemas:
    nac_nacrule_name:
      description: Name of the NAC Rules used to authenticate the client for the specified duration
      examples:
      - - Wireless Cert Auth
      items:
        type: string
      readOnly: true
      type: array
    last_cert_expiry:
      description: When certificate based authentication is used, the expiration date from the latest certificate used
      examples:
      - 1746711240
      type: number
    nac_cert_cn:
      description: When certificate based authentication is used, the CN from the certificates used for the specified duration
      examples:
      - - john@mycorp.net
      items:
        type: string
      readOnly: true
      type: array
    timestamp:
      description: Epoch timestamp, in seconds
      format: double
      readOnly: true
      type: number
    nac_nacrule_id:
      description: IDs of the NAC Rules used to authenticate the client for the specified duration
      examples:
      - - 603b62db-d839-4152-9f7f-f2578443de8d
      items:
        type: string
      readOnly: true
      type: array
    last_cert_cn:
      description: When certificate based authentication is used, the CN from the latest certificate used
      examples:
      - john@mycorp.net
      type: string
    nac_client_coa:
      additionalProperties: false
      description: Change of Authorization request for a NAC client
      properties:
        coa_type:
          $ref: '#/components/schemas/nac_coa_type'
          description: Change of Authorization command to send to the NAC client
      type: object
    nac_access_type:
      description: 'Type of network access. enum: `wireless`, `wired`, `vty`'
      enum:
      - wireless
      - wired
      - vty
      examples:
      - wireless
      type: string
    nac_client_username:
      description: List of usernames that have been assigned to the client
      items:
        type: string
      readOnly: true
      type: array
    nac_nas_vendor:
      description: Vendor name of the NAS for the specified duration
      examples:
      - - juniper-mist
      items:
        type: string
      readOnly: true
      type: array
    nac_ssid:
      description: SSIDs the client was connected to for the specified duration
      examples:
      - - MyCorp-NAC
      items:
        type: string
      type: array
    response_http400:
      additionalProperties: false
      description: Standard HTTP 400 bad request error response
      properties:
        detail:
          description: Human-readable explanation of the bad request error
          examples:
          - 'JSON parse error - Expecting value: line 5 column 8 (char 56)'
          type: string
      type: object
    nac_client_mac:
      description: Client MAC address observed in the NAC event
      examples:
      - ac3eb179e535
      readOnly: true
      type: string
    site_nac_client_events_count_distinct:
      description: 'enum: `ap`, `auth_type`, `dryrun_nacrule_id`, `mac`, `nacrule_id`, `nas_vendor`, `ssid`, `type`, `username`, `vlan`'
      enum:
      - ap
      - auth_type
      - dryrun_nacrule_id
      - mac
      - nacrule_id
      - nas_vendor
      - ssid
      - type
      - username
      - vlan
      type: string
    nac_port_id:
      description: Port-ids the client was connected to for the specified duration
      examples:
      - - ge-0/0/17.0
      items:
        type: string
      readOnly: true
      type: array
    site_nac_clients_count_distinct:
      default: type
      description: 'enum: `ap`, `auth_type`, `device_mac`, `edr_managed`, `edr_provider`, `edr_status`, `family`, `hostname`, `idp_id`, `mfg`, `mdm_compliance`, `mdm_managed`, `mdm_provider`, `model`, `mxedge_id`, `nacrule_matched`, `nacrule_name`, `nacrule_id`, `nas_ip`, `nas_vendor`, `os`, `ssid`, `status`, `type`, `usermac_label`, `username`, `vlan`'
      enum:
      - ap
      - auth_type
      - device_mac
      - edr_managed
      - edr_provider
      - edr_status
      - family
      - hostname
      - idp_id
      - mfg
      - mdm_compliance
      - mdm_managed
      - mdm_provider
      - model
      - mxedge_id
      - nacrule_matched
      - nacrule_name
      - nacrule_id
      - nas_ip
      - nas_vendor
      - os
      - ssid
      - status
      - type
      - usermac_label
      - username
      - vlan
      type: string
    nac_coa_type:
      default: reauth
      description: 'CoA type to send. enum: `reauth`, `disconnect`'
      enum:
      - reauth
      - disconnect
      type: string
    last_cert_serial:
      description: When certificate based authentication is used, the Serial from the latest certificate used
      examples:
      - 2c63510123456789
      type: string
    site_id:
      description: Unique identifier of a Mist site
      examples:
      - 441a1214-6928-442a-8e92-e1d34b8ec6a6
      format: uuid
      readOnly: true
      type: string
    nac_event_port_id:
      description: Port ID where the NAC client event occurred
      examples:
      - ge-0/0/17.0
      readOnly: true
      type: string
    nac_client_last_status:
      description: 'Latest Authentication status of the client. enum: `denied`, `permitted`, `session_started`, `session_stopped`'
      enum:
      - permitted
      - session_started
      - session_stopped
      - denied
      examples:
      - permitted
      type: string
    nac_event_nacrule_matched:
      description: NAC Policy Rule Matched
      readOnly: true
      type: boolean
    nac_cert_issuer:
      description: When certificate based authentication is used, the Issuer from the certificates used for the specified duration
      examples:
      - - /C=US/ST=CA/CN=MyCorp
      items:
        type: string
      readOnly: true
      type: array
    nac_event_type:
      description: Event type, e.g. NAC_CLIENT_PERMIT. Use the [List NAC Events Definitions](/#operations/listNacEventsDefinitions) endpoint to get the full list of available values.
      examples:
      - NAC_CLIENT_PERMIT
      readOnly: true
      type: string
    nac_cert_subject:
      description: When certificate based authentication is used, the Subject from the certificates used for the specified duration
      examples:
      - - /C=US/O=MyCorp/CN=john@mycorp.net/emailAddress=john@mycorp.net
      items:
        type: string
      readOnly: true
      type: array
    nac_client_events:
      description: List of NAC authentication events
      items:
        $ref: '#/components/schemas/nac_client_event'
      type: array
    edr_status:
      description: 'EDR Status of the NAC client. enum: `sentinelone_healthy`, `sentinelone_infected`, `crowdstrike_low`, `crowdstrike_medium`, `crowdstrike_high`, `crowdstrike_critical`, `crowdstrike_informational`'
      enum:
      - sentinelone_healthy
      - sentinelone_infected
      - crowdstrike_low
      - crowdstrike_medium
      - crowdstrike_high
      - crowdstrike_critical
      - crowdstrike_informational
      type: string
    response_http429:
      additionalProperties: false
      description: Standard HTTP 429 rate limit error response
      properties:
        detail:
          description: Human-readable explanation of the rate limit error
          examples:
          - Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold
          type: string
      type: object
    response_http401:
      additionalProperties: false
      description: Standard HTTP 401 authentication error response
      properties:
        detail:
          description: Human-readable explanation of the authentication error
          examples:
          - Authentication credentials were not provided.
          type: string
      type: object
    resp_attrs:
      description: List of RADIUS AVP returned by the Authentication Server
      examples:
      - - Tunnel-Type=VLAN
        - Tunnel-Medium-Type=IEEE-802
        - Tunnel-Private-Group-Id=750
        - User-Name=anonymous
      items:
        type: string
      type: array
      uniqueItems: true
    nac_auth_type:
      description: 'enum: `cert`, `device-auth`, `eap-teap`, `eap-tls`, `eap-ttls`, `idp`, `mab`, `eap-peap`'
      enum:
      - cert
      - device-auth
      - eap-teap
      - eap-tls
      - eap-ttls
      - idp
      - mab
      - eap-peap
      examples:
      - eap-tls
      type: string
    nac_device_mac:
      description: MAC address of the AP or switch the client is connected to
      examples:
      - 60c78d8c7f6f
      readOnly: true
      type: string
    response_client_nac_search_results:
      description: NAC client records returned by a search response
      items:
        $ref: '#/components/schemas/client_nac'
      type: array
    last_client_ip:
      description: The last known IP address for the client
      examples:
      - 10.100.0.157
      type: string
    nac_event_username:
      description: username assigned to the client
      readOnly: true
      type: string
    nac_client_ip:
      description: The known IP addresses used by the client for the specified duration
      examples:
      - - 10.100.0.157
      items:
        type: string
      readOnly: true
      type: array
    count_result:
      additionalProperties:
        type: string
      description: Count result row with the matching distinct field values
      properties:
        count:
          description: Number of matching items for the distinct value or values in this result
          type: integer
      required:
      - count
      type: object
    nac_client_ap:
      description: AP MAC addresses observed for the NAC client during the selected time range
      examples:
      - - 5c5b35bf16bb
        - d4dc090041b4
      items:
        type: string
      readOnly: true
      type: array
    nac_client_event_usermac_labels:
      description: Labels derived from usermac entry
      examples:
      - - bldg5
        - printer
      items:
        type: string
      type: array
    random_mac:
      description: 'Whether the client is using randomized MAC address or not. enum: `true`, `false`'
      enum:
      - 'true'
      - 'false'
      type: string
    nac_event_dryrun_nacrule_id:
      description: NAC Policy Dry Run Rule ID, if present and matched
      examples:
      - 32f27e7d-ff26-4a9b-b3d1-ff9bcb264012
      format: uuid
      readOnly: true
      type: string
    last_ssid:
      description: If Wireless authentication, the latest SSID the client was connected to
      examples:
      - MyCorp-NAC
      type: string
    last_cert_issuer:
      description: When certificate based authentication is used, the Issuer from the latest certificate used
      examples:
      - /C=US/ST=CA/CN=MyCorp
      type: string
    org_id:
      description: Unique identifier of a Mist organization
      examples:
      - a97c1b22-a4e9-411e-9bfd-d8695a0f9e61
      format: uuid
      readOnly: true
      type: string
    nac_client_event_idp_role:
      description: Identity provider roles or groups returned for a NAC client event
      examples:
      - - itsuperusers
        - vip
      items:
        type: string
      type: array
    nac_event_nacrule_id:
      description: NAC Policy Rule ID, if matched
      examples:
      - 32f27e7d-ff26-4a9b-b3d1-ff9bcb264c62
      format: uuid
      readOnly: true
      type: string
    response_http403:
      additionalProperties: false
      description: Standard HTTP 403 permission error response
      properties:
        detail:
          description: Human-readable explanation of the permission error
          examples:
          - You do not have permission to perform this action.
          type: string
      type: object
    count_results:
      description: List of count result rows
      items:
        $ref: '#/components/schemas/count_result'
      type: array
      uniqueItems: true
    last_username:
      description: If dot1x authentication, the username used during the latest authentication. Otherwise, the MAC address of the client
      examples:
      - john@mycorp.net
      type: string
    last_nacrule_id:
      description: ID of the latest NAC Rule used to authenticate the client
      examples:
      - 603b62db-d839-4152-9f7f-f2578443de8d
      type: string
    nac_client_event:
      additionalProperties: false
      description: NAC authentication event for a wired or wireless client
      properties:
        ap:
          description: Access point MAC address for the client session
          examples:
          - 5c5b35513227
          type: string
        auth_type:
          $ref: '#/components/schemas/nac_auth_type'
          description: Authentication method used for the NAC event
        bssid:
          description: Wireless BSSID used for the client session
          examples:
          - 5c5b355fafcc
          type: string
        client_type:
          $ref: '#/components/schemas/nac_access_type'
          description: Access type for the NAC client event
        device_mac:
          $ref: '#/components/schemas/nac_device_mac'
          description: Network device MAC address for the AP or switch handling the client session
        dryrun_nacrule_id:
          $ref: '#/components/schemas/nac_event_dryrun_nacrule_id'
          description: Dry-run NAC rule ID that matched the event, when present
        dryrun_nacrule_matched:
          $ref: '#/components/schemas/nac_event_dryrun_nacrule_matched'
          descripti

# --- truncated at 32 KB (60 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/mist/refs/heads/main/openapi/mist-sites-clients-nac-api-openapi.yml