Meraki
Cisco Meraki Dashboard API v1 integration model for swamp.
Reads organization inventory and status and stores every record as a separately addressable resource using the factory pattern — enabling CEL queries, cross-model composition, and drift detection via versioned snapshots. All methods are read-only.
One model instance covers many Meraki organizations. profiles maps a
friendly name to an organization ID plus its own API key, and every method
fans out over all profiles in a single run (or one profile via
--input profile=<name>), so a multi-org fleet needs one model and one lock
acquisition rather than N of each.
Methods: sync_organizations, sync_networks, sync_devices,
sync_device_statuses, sync_licenses, sync_uplink_statuses, sync_clients, and
request — a read-only escape hatch for any other v1 path.
Organizations on co-termination licensing fall back automatically from the per-device licenses endpoint to the license overview endpoint, so sync_licenses works on both licensing models.
RFC5988 Link pagination is followed to completion under a page cap, and the
documented 10 req/s per-organization rate limit is respected by honoring
Retry-After on HTTP 429 with exponential backoff.
Quick Start
swamp extension pull @tagur/meraki
swamp vault create local_encryption meraki
printf '%s' "$MERAKI_KEY" | swamp vault put meraki CORP_API_KEY
swamp model create @tagur/meraki meraki
# then set globalArguments.profiles in the model YAML:
# profiles:
# corp:
# organizationId: "549236"
# apiKey: ${{ vault.get("meraki", "CORP_API_KEY") }}
swamp model @tagur/meraki method run sync_devices meraki
swamp data query 'modelName == "meraki" && specName == "device"' \
--select '{"serial": attributes.serial, "model": attributes.model}'First stable release.
Read-only Cisco Meraki Dashboard API v1 model. A profiles map lets one model instance cover several organizations that do not share an API key — each profile carries its own key and an optional organization ID, and every method fans out over all profiles in a single run, so a multi-org fleet takes one lock acquisition rather than N. Omit the organization ID and a profile covers every organization its key can see.
Methods: sync_organizations, sync_networks, sync_devices, sync_device_statuses, sync_licenses, sync_uplink_statuses, sync_clients, and request — a read-only escape hatch for any v1 path, with {organizationId} substitution.
Both licensing models are supported: sync_licenses reads per-device licenses and falls back automatically to the license overview endpoint for co-termination organizations, storing the summary as a licenseOverview record.
RFC5988 Link pagination under a configurable page cap, Retry-After-aware backoff for 429 and 5xx, repeated key[] array filters as the API requires, and per-profile snapshots recording counts, truncation and per-organization errors so partial failures are assertable without discarding the records that did come back.
API keys are vault-sourced and sensitive-marked, never logged; URLs are stripped of query parameters in logs and errors; license keys are withheld unless explicitly enabled.
Validated end to end against a live six-organization fleet — 348 networks, 346 devices and statuses, 340 uplink statuses, and license data for all six — alongside 21 unit tests over a mocked API covering pagination, truncation, rate-limit retry, the licensing fallback and its negative case, redaction and both pre-flight checks.
Global Arguments
| Argument | Type | Description |
|---|---|---|
| profiles | record | Named organization profiles — each with its own API key and optional organization ID |
| baseUrl | string | Default API base URL for profiles that do not override it |
| perPage | number | Entries requested per page for paginated endpoints |
| maxPages | number | Page cap per endpoint per organization — guards against unbounded fetches |
| maxRetries | number | Retry attempts for rate-limited (429) and transient (5xx) responses |
| includeLicenseKeys | boolean | Store the licenseKey field on license records — off by default, license keys are credentials |
| Argument | Type | Description |
|---|---|---|
| profile? | string | Limit the run to a single configured profile |
| Argument | Type | Description |
|---|---|---|
| profile? | string | Limit the run to a single configured profile |
| tags? | array | Only return networks carrying these tags |
| Argument | Type | Description |
|---|---|---|
| profile? | string | Limit the run to a single configured profile |
| productTypes? | array | Filter by product type (appliance, switch, wireless, camera, sensor, cellularGateway) |
| Argument | Type | Description |
|---|---|---|
| profile? | string | Limit the run to a single configured profile |
| statuses? | array | Filter to specific statuses (online, alerting, offline, dormant) |
| Argument | Type | Description |
|---|---|---|
| profile? | string | Limit the run to a single configured profile |
| state? | string | Filter by license state (active, expired, expiring, recentlyQueued, unused, unusedActive) |
| Argument | Type | Description |
|---|---|---|
| profile? | string | Limit the run to a single configured profile |
| networkIds? | array | Restrict results to specific network IDs |
| Argument | Type | Description |
|---|---|---|
| profile? | string | Limit the run to a single configured profile |
| networkIds | array | Network IDs to fetch clients for |
| timespan | number | Lookback window in seconds — the API caps this at 2678400 (31 days) |
| Argument | Type | Description |
|---|---|---|
| path | string | API path relative to /api/v1 (e.g. organizations/{organizationId}/admins) |
| query? | record | Query parameters to append |
| profile? | string | Limit the run to a single configured profile |
| paginate | boolean | Follow Link headers and store the combined array instead of a single page |
Resources
- Has README or module doc2/2earned
- README has a code example1/1earned
- README is substantive1/1earned
- Most symbols documented1/1earned
- No slow types (deprecated)1/1earned
- Dependencies pass trust audit2/2earned
- Has description1/1earned
- Platform support declared (or universal)2/2earned
- License declared1/1earned
- Verified public repository2/2earned