Mist Sites Service Policies API

The API Endpoints for the Service Policies at the site level can be used to get the site derived configuration, meaning the merge between the site level configuration and the org level configuration.

OpenAPI Specification

mist-sites-service-policies-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  contact:
    email: tmunzer@juniper.net
    name: Thomas Munzer
  description: '> Version: **2606.1.1**

    >

    > Date: **July 10, 2026**

    <div class="notification"> NOTE:<br>Some important API changes will be introduced. Please make sure to read the <a href="https://www.juniper.net/documentation/us/en/software/mist/api/http/guides/important-api-changes">announcements</a> </div>


    ---

    ## Additional Documentation

    * [Mist Automation Guide](https://www.juniper.net/documentation/us/en/software/mist/automation-integration/index.html)

    * [Mist Location SDK](https://www.juniper.net/documentation/us/en/software/mist/location-services/topics/concept/mist-how-get-mist-sdk.html)

    * [Mist Product Updates](https://www.juniper.net/documentation/us/en/software/mist/product-updates/)


    ## Helpful Resources

    * [API Sandbox and Exercises](https://api-class.mist.com/)

    * [Postman Collection, Runners and Webhook Samples](https://www.postman.com/juniper-mist/workspace/mist-systems-s-public-workspace)

    * [Python Script Examples](https://github.com/tmunzer/mist_library)

    * [API Demo Apps](https://apps.mist-lab.fr/)

    * [Juniper Blog](https://blogs.juniper.net/)


    ## Mist Web Browser Extension:

    * Google Chrome, Microsoft Edge and other Chromium-based browser: [Chrome Web Store](https://chromewebstore.google.com/detail/mist-extension/ejhpdcljeamillfhdihkkmoakanpbplh)

    * Firefox: [Firefox Add-ons](https://addons.mozilla.org/en-US/firefox/addon/mist-extension/)


    ---'
  license:
    name: MIT
    url: https://raw.githubusercontent.com/tmunzer/Mist-OAS3.0/main/LICENSE
  title: Mist Admins Sites Service Policies API
  version: 2606.1.1
  x-logo:
    altText: Juniper-MistAI
    backgroundColor: '#FFFFFF'
    url: https://www.mist.com/wp-content/uploads/logo.png
servers:
- description: Mist Global 01
  url: https://api.mist.com
- description: Mist Global 02
  url: https://api.gc1.mist.com
- description: Mist Global 03
  url: https://api.ac2.mist.com
- description: Mist Global 04
  url: https://api.gc2.mist.com
- description: Mist Global 05
  url: https://api.gc4.mist.com
- description: Mist EMEA 01
  url: https://api.eu.mist.com
- description: Mist EMEA 02
  url: https://api.gc3.mist.com
- description: Mist EMEA 03
  url: https://api.ac6.mist.com
- description: Mist EMEA 04
  url: https://api.gc6.mist.com
- description: Mist APAC 01
  url: https://api.ac5.mist.com
- description: Mist APAC 02
  url: https://api.gc5.mist.com
- description: Mist APAC 03
  url: https://api.gc7.mist.com
security:
- apiToken: []
- csrfToken: []
tags:
- description: The API Endpoints for the Service Policies at the site level can be used to get the site derived configuration, meaning the merge between the site level configuration and the org level configuration.
  name: Sites Service Policies
paths:
  /api/v1/sites/{site_id}/servicepolicies/derived:
    parameters:
    - $ref: '#/components/parameters/site_id'
    get:
      description: Get the list of derived Service Policies for a Site
      operationId: listSiteServicePoliciesDerived
      parameters:
      - description: Whether resolve the site variables
        in: query
        name: resolve
        schema:
          default: false
          type: boolean
      responses:
        '200':
          $ref: '#/components/responses/ServicePoliciesArray'
        '400':
          $ref: '#/components/responses/HTTP400'
        '401':
          $ref: '#/components/responses/HTTP401'
        '403':
          $ref: '#/components/responses/HTTP403'
        '404':
          $ref: '#/components/responses/HTTP404'
        '429':
          $ref: '#/components/responses/HTTP429'
      summary: listSiteServicePoliciesDerived
      tags:
      - Sites Service Policies
components:
  schemas:
    service_policy_secintel:
      additionalProperties: false
      description: SRX SecIntel settings for a service policy
      properties:
        enabled:
          default: false
          description: Whether SecIntel inspection is enabled for the service policy
          type: boolean
        profile:
          $ref: '#/components/schemas/service_policy_secintel_profile'
          description: Protection level applied by SecIntel inspection
        secintelprofile_id:
          description: Organization-level SecIntel profile ID; takes precedence over inline `profile` settings
          type: string
      type: object
    service_policy_secintel_profile:
      default: default
      description: 'enum: `default`, `standard`, `strict`'
      enum:
      - default
      - standard
      - strict
      type: string
    strings:
      description: Unique string values returned or accepted by this schema
      items:
        type: string
      type: array
      uniqueItems: true
    id:
      description: Unique ID of the object instance in the Mist Organization
      examples:
      - 53f10664-3ce8-4c27-b382-0ef66432349f
      format: uuid
      readOnly: true
      type: string
    response_http429:
      additionalProperties: false
      description: Standard HTTP 429 rate limit error response
      properties:
        detail:
          description: Human-readable explanation of the rate limit error
          examples:
          - Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold
          type: string
      type: object
    response_http401:
      additionalProperties: false
      description: Standard HTTP 401 authentication error response
      properties:
        detail:
          description: Human-readable explanation of the authentication error
          examples:
          - Authentication credentials were not provided.
          type: string
      type: object
    org_id:
      description: Unique identifier of a Mist organization
      examples:
      - a97c1b22-a4e9-411e-9bfd-d8695a0f9e61
      format: uuid
      readOnly: true
      type: string
    created_time:
      description: When the object has been created, in epoch
      format: double
      readOnly: true
      type: number
    service_policy_ewf_rule_profile:
      default: strict
      description: 'enum: `critical`, `standard`, `strict`'
      enum:
      - critical
      - standard
      - strict
      type: string
    ssl_proxy_ciphers_category:
      default: strong
      description: 'enum: `medium`, `strong`, `weak`'
      enum:
      - medium
      - strong
      - weak
      type: string
    response_http403:
      additionalProperties: false
      description: Standard HTTP 403 permission error response
      properties:
        detail:
          description: Human-readable explanation of the permission error
          examples:
          - You do not have permission to perform this action.
          type: string
      type: object
    idp_config:
      additionalProperties: false
      description: Intrusion detection and prevention settings for a service policy
      properties:
        alert_only:
          description: Whether to alert without enforcing IDP prevention actions
          type: boolean
        enabled:
          default: false
          description: Whether IDP inspection is enabled for the policy
          type: boolean
        idpprofile_id:
          description: org_level IDP Profile can be used, this takes precedence over `profile`
          examples:
          - 89b9d208-84a4-fa8f-af57-78f92c639cf2
          format: uuid
          type: string
        profile:
          default: strict
          description: 'enum: `Custom`, `strict` (default), `standard` or keys from idp_profiles'
          type: string
      type: object
    response_http400:
      additionalProperties: false
      description: Standard HTTP 400 bad request error response
      properties:
        detail:
          description: Human-readable explanation of the bad request error
          examples:
          - 'JSON parse error - Expecting value: line 5 column 8 (char 56)'
          type: string
      type: object
    service_policy_aamw_profile:
      default: standard
      description: 'enum: `docsonly`, `executables`, `standard`'
      enum:
      - docsonly
      - executables
      - standard
      type: string
    service_policy_aamw:
      additionalProperties: false
      description: SRX advanced anti-malware settings for a service policy
      properties:
        aamwprofile_id:
          description: Organization-level advanced anti-malware profile ID; takes precedence over inline `profile` settings
          format: uuid
          type: string
        enabled:
          default: false
          description: Whether advanced anti-malware inspection is enabled for the service policy
          type: boolean
        profile:
          $ref: '#/components/schemas/service_policy_aamw_profile'
          description: Built-in advanced anti-malware inspection profile to apply
      type: object
    service_policy_ewf:
      description: Enhanced web filtering rules applied by a service policy
      items:
        $ref: '#/components/schemas/service_policy_ewf_rule'
      type: array
    service_policy_ssl_proxy:
      additionalProperties: false
      description: SRX SSL proxy inspection settings for a service policy
      properties:
        ciphers_category:
          $ref: '#/components/schemas/ssl_proxy_ciphers_category'
          description: Allowed cipher strength category for SSL proxy inspection
        enabled:
          default: false
          description: Whether SSL proxy inspection is enabled for the service policy
          type: boolean
      type: object
    service_policy_appqoe:
      additionalProperties: false
      description: SRX application QoE settings for a service policy
      properties:
        enabled:
          default: false
          description: Whether application QoE is enabled for the service policy
          type: boolean
      type: object
    service_policy_antivirus:
      additionalProperties: false
      description: SRX antivirus inspection settings for a service policy
      properties:
        avprofile_id:
          description: Organization-level antivirus profile ID; takes precedence over inline `profile` settings
          format: uuid
          type: string
        enabled:
          default: false
          description: Whether antivirus inspection is enabled for the service policy
          type: boolean
        profile:
          description: Antivirus profile name to apply, such as `default`, `noftp`, `httponly`, or an AV profile key
          type: string
      type: object
    allow_deny:
      description: 'Policy action value that either allows or denies matching traffic. enum: `allow`, `deny`'
      enum:
      - allow
      - deny
      type: string
    org_service_policies:
      description: List of organization-level service policies
      items:
        $ref: '#/components/schemas/org_service_policy'
      type: array
    service_policy_ewf_rule:
      additionalProperties: false
      description: Enhanced web filtering rule applied by a service policy
      properties:
        alert_only:
          description: Whether matching enhanced web filtering traffic is logged without being blocked
          type: boolean
        block_message:
          description: Message returned when enhanced web filtering blocks a request
          examples:
          - Access to this URL Category has been blocked
          type: string
        enabled:
          default: false
          description: Whether this enhanced web filtering rule is enabled
          type: boolean
        profile:
          $ref: '#/components/schemas/service_policy_ewf_rule_profile'
          description: Enhanced web filtering profile applied by this rule
      type: object
    modified_time:
      description: When the object has been modified for the last time, in epoch
      format: double
      readOnly: true
      type: number
    response_http404:
      additionalProperties: false
      description: Standard HTTP 404 not found error response
      properties:
        id:
          description: Missing resource identifier, when the API includes one
          type: string
      type: object
    org_service_policy:
      description: Organization-level service policy that allows or denies traffic for tenants and services
      properties:
        aamw:
          $ref: '#/components/schemas/service_policy_aamw'
          description: Advanced anti-malware settings applied by this service policy
        action:
          $ref: '#/components/schemas/allow_deny'
          description: Allow or deny action for traffic matched by this service policy
        antivirus:
          $ref: '#/components/schemas/service_policy_antivirus'
          description: Malware and virus inspection settings applied by this service policy
        appqoe:
          $ref: '#/components/schemas/service_policy_appqoe'
          description: Application QoE settings applied by this service policy
        created_time:
          $ref: '#/components/schemas/created_time'
          description: Epoch timestamp when the service policy was created
        ewf:
          $ref: '#/components/schemas/service_policy_ewf'
          description: Enhanced web filtering rules applied by this service policy
        id:
          $ref: '#/components/schemas/id'
          description: Unique identifier of the service policy
        idp:
          $ref: '#/components/schemas/idp_config'
          description: Intrusion detection and prevention settings applied by this service policy
        local_routing:
          description: Whether the policy permits access within the same VRF
          type: boolean
        modified_time:
          $ref: '#/components/schemas/modified_time'
          description: Epoch timestamp when the service policy was last modified
        name:
          description: Display name of the service policy
          type: string
        org_id:
          $ref: '#/components/schemas/org_id'
          description: Organization that owns this service policy
        path_preference:
          description: By default, we derive all paths available and use them, optionally, you can customize by using `path_preference`
          type: string
        secintel:
          $ref: '#/components/schemas/service_policy_secintel'
          description: Juniper SecIntel threat intelligence settings applied by this service policy
        services:
          $ref: '#/components/schemas/strings'
          description: Application services or groups matched by this policy
        ssl_proxy:
          $ref: '#/components/schemas/service_policy_ssl_proxy'
          description: SSL proxy inspection settings applied by this service policy
        tenants:
          $ref: '#/components/schemas/strings'
          description: Tenant names matched by this service policy
      type: object
  responses:
    HTTP400:
      content:
        application/json:
          examples:
            Example:
              $ref: '#/components/examples/HTTP400Example'
          schema:
            $ref: '#/components/schemas/response_http400'
        application/vnd.api+json:
          examples:
            Example:
              $ref: '#/components/examples/HTTP400Example'
          schema:
            $ref: '#/components/schemas/response_http400'
      description: Bad Syntax
    HTTP403:
      content:
        application/json:
          examples:
            Example:
              $ref: '#/components/examples/HTTP403Example'
          schema:
            $ref: '#/components/schemas/response_http403'
        application/vnd.api+json:
          examples:
            Example:
              $ref: '#/components/examples/HTTP403Example'
          schema:
            $ref: '#/components/schemas/response_http403'
      description: Permission Denied
    ServicePoliciesArray:
      content:
        application/json:
          examples:
            Example:
              $ref: '#/components/examples/ServicePoliciesArrayExample'
          schema:
            $ref: '#/components/schemas/org_service_policies'
        application/vnd.api+json:
          examples:
            Example:
              $ref: '#/components/examples/ServicePoliciesArrayExample'
          schema:
            $ref: '#/components/schemas/org_service_policies'
      description: Example response
    HTTP404:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/response_http404'
        application/vnd.api+json:
          schema:
            $ref: '#/components/schemas/response_http404'
      description: Not found. The API endpoint doesn’t exist or resource doesn’ t exist
    HTTP429:
      content:
        application/json:
          examples:
            Example:
              $ref: '#/components/examples/HTTP429Example'
          schema:
            $ref: '#/components/schemas/response_http429'
        application/vnd.api+json:
          examples:
            Example:
              $ref: '#/components/examples/HTTP429Example'
          schema:
            $ref: '#/components/schemas/response_http429'
      description: Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold
    HTTP401:
      content:
        application/json:
          examples:
            Example:
              $ref: '#/components/examples/HTTP401Example'
          schema:
            $ref: '#/components/schemas/response_http401'
        application/vnd.api+json:
          examples:
            Example:
              $ref: '#/components/examples/HTTP401Example'
          schema:
            $ref: '#/components/schemas/response_http401'
      description: Unauthorized
  examples:
    HTTP403Example:
      value:
        detail: You do not have permission to perform this action.
    HTTP400Example:
      value:
        detail: 'JSON parse error - Expecting value: line 5 column 8 (char 56)'
    HTTP429Example:
      value:
        detail: Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold
    HTTP401Example:
      value:
        detail: Authentication credentials were not provided.
    ServicePoliciesArrayExample:
      value:
      - action: allow
        created_time: 0
        id: string
        modified_time: 0
        name: string
        org_id: string
        services:
        - string
        tenants:
        - string
  parameters:
    site_id:
      in: path
      name: site_id
      required: true
      schema:
        examples:
        - 000000ab-00ab-00ab-00ab-0000000000ab
        format: uuid
        type: string
  securitySchemes:
    apiToken:
      description: "Preferred authentication method for automation and integrations. Send the API token in the HTTP `Authorization` header.\n\n**Format**:\n  `Authorization: Token {apitoken}`\n\n**Notes**:\n* An API token generated for a specific admin has the same privileges as that admin\n* An API token is automatically removed if it is not used for more than 90 days\n* SSO admins cannot generate admin API tokens. Use organization API tokens when scoped Org/Site privileges are needed."
      in: header
      name: Authorization
      type: apiKey
    csrfToken:
      description: 'Session-based authentication for browser or login/password flows. After a successful [Login](/#operations/login) request, Mist returns a `csrftoken` cookie. Send that value in the `X-CSRFToken` header on later API requests that use the login session.


        **Format**:

        ```

        X-CSRFToken: vwvBuq9qkqaKh7lu8tNc0gkvBfEaLAmx

        ```


        For automation, API Token authentication is preferred.'
      in: header
      name: X-CSRFToken
      type: apiKey