Onboard one or more organizations under a single read-only API key.
const url = 'https://example.com/api/v1/meraki/orgs';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"api_key":"example","base_url":"example","credential_id":"2489E9AD-2EE2-8E00-8EC9-32D5F69181C0","org_ids":["example"]}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/api/v1/meraki/orgs \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "api_key": "example", "base_url": "example", "credential_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "org_ids": [ "example" ] }'The key is validated by listing orgs. A typed key is then sealed once as a shared
credential — each org row holds a reference plus its own org id, so onboarding twenty orgs
stores one secret, not twenty copies of the same one. A saved key (credential_id,
ADR-164 Inc.6) seals nothing: the new rows point at the credential that is already there, which
is how an organization is added later under a key nobody has to find and paste again.
An organization that is already monitored here is skipped and counted. A per-org create failure is logged and skipped rather than failing the batch: the counts say what landed, and retrying is harmless.
Authorizations
Section titled “Authorizations”Request Bodyrequired
Section titled “Request Bodyrequired”object
A key typed by the operator; sealed as a new credential. Send this or credential_id.
A meraki_api credential already stored here. The new organizations share it, and no new
credential is created.
Examplegenerated
{ "api_key": "example", "base_url": "example", "credential_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "org_ids": [ "example" ]}Responses
Section titled “Responses”How many organizations the batch created, and how many it named were here already; a per-org failure is skipped, not fatal
What an onboarding batch did.
object
Organizations it named that were monitored here already, and were left as they are.
Organizations this request added.
Examplegenerated
{ "already_added": 1, "created": 1}The org list is empty or both api_key and credential_id were sent (invalid_request), no key was named (invalid_api_key), credential_id is not a stored Meraki API key (invalid_credential), base_url is not an https allow-listed Meraki host, or an org id is not one the key can see (unknown_org)
The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI
document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies
undescribed — a client that has to guess the failure shape ends up parsing the success shape and
reading undefined.
object
object
Stable machine-readable code. Clients branch on this, never on the message.
Operator-facing sentence. Safe to display; never carries an internal error’s own text.
Examplegenerated
{ "error": { "code": "example", "message": "example" }}No valid bearer token
The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI
document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies
undescribed — a client that has to guess the failure shape ends up parsing the success shape and
reading undefined.
object
object
Stable machine-readable code. Clients branch on this, never on the message.
Operator-facing sentence. Safe to display; never carries an internal error’s own text.
Examplegenerated
{ "error": { "code": "example", "message": "example" }}Role lacks ManageConfig, or the account is restricted to folders (scope_unsupported)
The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI
document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies
undescribed — a client that has to guess the failure shape ends up parsing the success shape and
reading undefined.
object
object
Stable machine-readable code. Clients branch on this, never on the message.
Operator-facing sentence. Safe to display; never carries an internal error’s own text.
Examplegenerated
{ "error": { "code": "example", "message": "example" }}The Dashboard API rejected the key or was unreachable
The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI
document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies
undescribed — a client that has to guess the failure shape ends up parsing the success shape and
reading undefined.
object
object
Stable machine-readable code. Clients branch on this, never on the message.
Operator-facing sentence. Safe to display; never carries an internal error’s own text.
Examplegenerated
{ "error": { "code": "example", "message": "example" }}Inventory storage is unavailable (skeleton mode)
The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI
document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies
undescribed — a client that has to guess the failure shape ends up parsing the success shape and
reading undefined.
object
object
Stable machine-readable code. Clients branch on this, never on the message.
Operator-facing sentence. Safe to display; never carries an internal error’s own text.
Examplegenerated
{ "error": { "code": "example", "message": "example" }}