Mist Sites Service Policies API
The API Endpoints for the Service Policies at the site level can be used to get the site derived configuration, meaning the merge between the site level configuration and the org level configuration.
The API Endpoints for the Service Policies at the site level can be used to get the site derived configuration, meaning the merge between the site level configuration and the org level configuration.
openapi: 3.1.0
info:
contact:
email: tmunzer@juniper.net
name: Thomas Munzer
description: '> Version: **2606.1.1**
>
> Date: **July 10, 2026**
<div class="notification"> NOTE:<br>Some important API changes will be introduced. Please make sure to read the <a href="https://www.juniper.net/documentation/us/en/software/mist/api/http/guides/important-api-changes">announcements</a> </div>
---
## Additional Documentation
* [Mist Automation Guide](https://www.juniper.net/documentation/us/en/software/mist/automation-integration/index.html)
* [Mist Location SDK](https://www.juniper.net/documentation/us/en/software/mist/location-services/topics/concept/mist-how-get-mist-sdk.html)
* [Mist Product Updates](https://www.juniper.net/documentation/us/en/software/mist/product-updates/)
## Helpful Resources
* [API Sandbox and Exercises](https://api-class.mist.com/)
* [Postman Collection, Runners and Webhook Samples](https://www.postman.com/juniper-mist/workspace/mist-systems-s-public-workspace)
* [Python Script Examples](https://github.com/tmunzer/mist_library)
* [API Demo Apps](https://apps.mist-lab.fr/)
* [Juniper Blog](https://blogs.juniper.net/)
## Mist Web Browser Extension:
* Google Chrome, Microsoft Edge and other Chromium-based browser: [Chrome Web Store](https://chromewebstore.google.com/detail/mist-extension/ejhpdcljeamillfhdihkkmoakanpbplh)
* Firefox: [Firefox Add-ons](https://addons.mozilla.org/en-US/firefox/addon/mist-extension/)
---'
license:
name: MIT
url: https://raw.githubusercontent.com/tmunzer/Mist-OAS3.0/main/LICENSE
title: Mist Admins Sites Service Policies API
version: 2606.1.1
x-logo:
altText: Juniper-MistAI
backgroundColor: '#FFFFFF'
url: https://www.mist.com/wp-content/uploads/logo.png
servers:
- description: Mist Global 01
url: https://api.mist.com
- description: Mist Global 02
url: https://api.gc1.mist.com
- description: Mist Global 03
url: https://api.ac2.mist.com
- description: Mist Global 04
url: https://api.gc2.mist.com
- description: Mist Global 05
url: https://api.gc4.mist.com
- description: Mist EMEA 01
url: https://api.eu.mist.com
- description: Mist EMEA 02
url: https://api.gc3.mist.com
- description: Mist EMEA 03
url: https://api.ac6.mist.com
- description: Mist EMEA 04
url: https://api.gc6.mist.com
- description: Mist APAC 01
url: https://api.ac5.mist.com
- description: Mist APAC 02
url: https://api.gc5.mist.com
- description: Mist APAC 03
url: https://api.gc7.mist.com
security:
- apiToken: []
- csrfToken: []
tags:
- description: The API Endpoints for the Service Policies at the site level can be used to get the site derived configuration, meaning the merge between the site level configuration and the org level configuration.
name: Sites Service Policies
paths:
/api/v1/sites/{site_id}/servicepolicies/derived:
parameters:
- $ref: '#/components/parameters/site_id'
get:
description: Get the list of derived Service Policies for a Site
operationId: listSiteServicePoliciesDerived
parameters:
- description: Whether resolve the site variables
in: query
name: resolve
schema:
default: false
type: boolean
responses:
'200':
$ref: '#/components/responses/ServicePoliciesArray'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: listSiteServicePoliciesDerived
tags:
- Sites Service Policies
components:
schemas:
service_policy_secintel:
additionalProperties: false
description: SRX SecIntel settings for a service policy
properties:
enabled:
default: false
description: Whether SecIntel inspection is enabled for the service policy
type: boolean
profile:
$ref: '#/components/schemas/service_policy_secintel_profile'
description: Protection level applied by SecIntel inspection
secintelprofile_id:
description: Organization-level SecIntel profile ID; takes precedence over inline `profile` settings
type: string
type: object
service_policy_secintel_profile:
default: default
description: 'enum: `default`, `standard`, `strict`'
enum:
- default
- standard
- strict
type: string
strings:
description: Unique string values returned or accepted by this schema
items:
type: string
type: array
uniqueItems: true
id:
description: Unique ID of the object instance in the Mist Organization
examples:
- 53f10664-3ce8-4c27-b382-0ef66432349f
format: uuid
readOnly: true
type: string
response_http429:
additionalProperties: false
description: Standard HTTP 429 rate limit error response
properties:
detail:
description: Human-readable explanation of the rate limit error
examples:
- Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold
type: string
type: object
response_http401:
additionalProperties: false
description: Standard HTTP 401 authentication error response
properties:
detail:
description: Human-readable explanation of the authentication error
examples:
- Authentication credentials were not provided.
type: string
type: object
org_id:
description: Unique identifier of a Mist organization
examples:
- a97c1b22-a4e9-411e-9bfd-d8695a0f9e61
format: uuid
readOnly: true
type: string
created_time:
description: When the object has been created, in epoch
format: double
readOnly: true
type: number
service_policy_ewf_rule_profile:
default: strict
description: 'enum: `critical`, `standard`, `strict`'
enum:
- critical
- standard
- strict
type: string
ssl_proxy_ciphers_category:
default: strong
description: 'enum: `medium`, `strong`, `weak`'
enum:
- medium
- strong
- weak
type: string
response_http403:
additionalProperties: false
description: Standard HTTP 403 permission error response
properties:
detail:
description: Human-readable explanation of the permission error
examples:
- You do not have permission to perform this action.
type: string
type: object
idp_config:
additionalProperties: false
description: Intrusion detection and prevention settings for a service policy
properties:
alert_only:
description: Whether to alert without enforcing IDP prevention actions
type: boolean
enabled:
default: false
description: Whether IDP inspection is enabled for the policy
type: boolean
idpprofile_id:
description: org_level IDP Profile can be used, this takes precedence over `profile`
examples:
- 89b9d208-84a4-fa8f-af57-78f92c639cf2
format: uuid
type: string
profile:
default: strict
description: 'enum: `Custom`, `strict` (default), `standard` or keys from idp_profiles'
type: string
type: object
response_http400:
additionalProperties: false
description: Standard HTTP 400 bad request error response
properties:
detail:
description: Human-readable explanation of the bad request error
examples:
- 'JSON parse error - Expecting value: line 5 column 8 (char 56)'
type: string
type: object
service_policy_aamw_profile:
default: standard
description: 'enum: `docsonly`, `executables`, `standard`'
enum:
- docsonly
- executables
- standard
type: string
service_policy_aamw:
additionalProperties: false
description: SRX advanced anti-malware settings for a service policy
properties:
aamwprofile_id:
description: Organization-level advanced anti-malware profile ID; takes precedence over inline `profile` settings
format: uuid
type: string
enabled:
default: false
description: Whether advanced anti-malware inspection is enabled for the service policy
type: boolean
profile:
$ref: '#/components/schemas/service_policy_aamw_profile'
description: Built-in advanced anti-malware inspection profile to apply
type: object
service_policy_ewf:
description: Enhanced web filtering rules applied by a service policy
items:
$ref: '#/components/schemas/service_policy_ewf_rule'
type: array
service_policy_ssl_proxy:
additionalProperties: false
description: SRX SSL proxy inspection settings for a service policy
properties:
ciphers_category:
$ref: '#/components/schemas/ssl_proxy_ciphers_category'
description: Allowed cipher strength category for SSL proxy inspection
enabled:
default: false
description: Whether SSL proxy inspection is enabled for the service policy
type: boolean
type: object
service_policy_appqoe:
additionalProperties: false
description: SRX application QoE settings for a service policy
properties:
enabled:
default: false
description: Whether application QoE is enabled for the service policy
type: boolean
type: object
service_policy_antivirus:
additionalProperties: false
description: SRX antivirus inspection settings for a service policy
properties:
avprofile_id:
description: Organization-level antivirus profile ID; takes precedence over inline `profile` settings
format: uuid
type: string
enabled:
default: false
description: Whether antivirus inspection is enabled for the service policy
type: boolean
profile:
description: Antivirus profile name to apply, such as `default`, `noftp`, `httponly`, or an AV profile key
type: string
type: object
allow_deny:
description: 'Policy action value that either allows or denies matching traffic. enum: `allow`, `deny`'
enum:
- allow
- deny
type: string
org_service_policies:
description: List of organization-level service policies
items:
$ref: '#/components/schemas/org_service_policy'
type: array
service_policy_ewf_rule:
additionalProperties: false
description: Enhanced web filtering rule applied by a service policy
properties:
alert_only:
description: Whether matching enhanced web filtering traffic is logged without being blocked
type: boolean
block_message:
description: Message returned when enhanced web filtering blocks a request
examples:
- Access to this URL Category has been blocked
type: string
enabled:
default: false
description: Whether this enhanced web filtering rule is enabled
type: boolean
profile:
$ref: '#/components/schemas/service_policy_ewf_rule_profile'
description: Enhanced web filtering profile applied by this rule
type: object
modified_time:
description: When the object has been modified for the last time, in epoch
format: double
readOnly: true
type: number
response_http404:
additionalProperties: false
description: Standard HTTP 404 not found error response
properties:
id:
description: Missing resource identifier, when the API includes one
type: string
type: object
org_service_policy:
description: Organization-level service policy that allows or denies traffic for tenants and services
properties:
aamw:
$ref: '#/components/schemas/service_policy_aamw'
description: Advanced anti-malware settings applied by this service policy
action:
$ref: '#/components/schemas/allow_deny'
description: Allow or deny action for traffic matched by this service policy
antivirus:
$ref: '#/components/schemas/service_policy_antivirus'
description: Malware and virus inspection settings applied by this service policy
appqoe:
$ref: '#/components/schemas/service_policy_appqoe'
description: Application QoE settings applied by this service policy
created_time:
$ref: '#/components/schemas/created_time'
description: Epoch timestamp when the service policy was created
ewf:
$ref: '#/components/schemas/service_policy_ewf'
description: Enhanced web filtering rules applied by this service policy
id:
$ref: '#/components/schemas/id'
description: Unique identifier of the service policy
idp:
$ref: '#/components/schemas/idp_config'
description: Intrusion detection and prevention settings applied by this service policy
local_routing:
description: Whether the policy permits access within the same VRF
type: boolean
modified_time:
$ref: '#/components/schemas/modified_time'
description: Epoch timestamp when the service policy was last modified
name:
description: Display name of the service policy
type: string
org_id:
$ref: '#/components/schemas/org_id'
description: Organization that owns this service policy
path_preference:
description: By default, we derive all paths available and use them, optionally, you can customize by using `path_preference`
type: string
secintel:
$ref: '#/components/schemas/service_policy_secintel'
description: Juniper SecIntel threat intelligence settings applied by this service policy
services:
$ref: '#/components/schemas/strings'
description: Application services or groups matched by this policy
ssl_proxy:
$ref: '#/components/schemas/service_policy_ssl_proxy'
description: SSL proxy inspection settings applied by this service policy
tenants:
$ref: '#/components/schemas/strings'
description: Tenant names matched by this service policy
type: object
responses:
HTTP400:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/HTTP400Example'
schema:
$ref: '#/components/schemas/response_http400'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/HTTP400Example'
schema:
$ref: '#/components/schemas/response_http400'
description: Bad Syntax
HTTP403:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/HTTP403Example'
schema:
$ref: '#/components/schemas/response_http403'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/HTTP403Example'
schema:
$ref: '#/components/schemas/response_http403'
description: Permission Denied
ServicePoliciesArray:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/ServicePoliciesArrayExample'
schema:
$ref: '#/components/schemas/org_service_policies'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/ServicePoliciesArrayExample'
schema:
$ref: '#/components/schemas/org_service_policies'
description: Example response
HTTP404:
content:
application/json:
schema:
$ref: '#/components/schemas/response_http404'
application/vnd.api+json:
schema:
$ref: '#/components/schemas/response_http404'
description: Not found. The API endpoint doesn’t exist or resource doesn’ t exist
HTTP429:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/HTTP429Example'
schema:
$ref: '#/components/schemas/response_http429'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/HTTP429Example'
schema:
$ref: '#/components/schemas/response_http429'
description: Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold
HTTP401:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/HTTP401Example'
schema:
$ref: '#/components/schemas/response_http401'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/HTTP401Example'
schema:
$ref: '#/components/schemas/response_http401'
description: Unauthorized
examples:
HTTP403Example:
value:
detail: You do not have permission to perform this action.
HTTP400Example:
value:
detail: 'JSON parse error - Expecting value: line 5 column 8 (char 56)'
HTTP429Example:
value:
detail: Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold
HTTP401Example:
value:
detail: Authentication credentials were not provided.
ServicePoliciesArrayExample:
value:
- action: allow
created_time: 0
id: string
modified_time: 0
name: string
org_id: string
services:
- string
tenants:
- string
parameters:
site_id:
in: path
name: site_id
required: true
schema:
examples:
- 000000ab-00ab-00ab-00ab-0000000000ab
format: uuid
type: string
securitySchemes:
apiToken:
description: "Preferred authentication method for automation and integrations. Send the API token in the HTTP `Authorization` header.\n\n**Format**:\n `Authorization: Token {apitoken}`\n\n**Notes**:\n* An API token generated for a specific admin has the same privileges as that admin\n* An API token is automatically removed if it is not used for more than 90 days\n* SSO admins cannot generate admin API tokens. Use organization API tokens when scoped Org/Site privileges are needed."
in: header
name: Authorization
type: apiKey
csrfToken:
description: 'Session-based authentication for browser or login/password flows. After a successful [Login](/#operations/login) request, Mist returns a `csrftoken` cookie. Send that value in the `X-CSRFToken` header on later API requests that use the login session.
**Format**:
```
X-CSRFToken: vwvBuq9qkqaKh7lu8tNc0gkvBfEaLAmx
```
For automation, API Token authentication is preferred.'
in: header
name: X-CSRFToken
type: apiKey