Cisco Meraki: network devices, WAN uplinks, and licence expiry
Cisco Meraki is where your network lives: the MX appliances at the edge of each site, the MS switches behind them, and the MR access points on top. This connector reads four things out of it — your organizations and their networks, every device and whether it is online, the WAN uplink state at each site, and how your licences are tracking — and hangs each one off the matching Current company so it feeds your business reviews and the company posture panel. Current reads Meraki and can never change anything in it.
What Current syncs
| Data set | What Current stores | Where it lands |
|---|---|---|
| Organizations | Each Meraki organization by id and name, whether the dashboard API is switched on for it, which Meraki cloud and country it is hosted in, and which licensing model it runs | The mapping panel on the Meraki card |
| Networks | Each network — a site — with its name, the product types it carries, its time zone, and its tags | The mapped company's network panel and SBR packs |
| Devices | Per device: serial, name, model where Meraki reports one, product type (appliance, switch, wireless, camera, sensor and the rest), its network, and its current status | The company's network panel, the SBR fleet and network chapter, and dashboard device metrics |
| WAN uplinks | One row per WAN interface on each MX, MG, and Z-series device: which interface, its state, the internet provider, the connection type, and cellular signal where it applies. Dual-WAN and triple-WAN sites get a row per link | The company's network panel — this is the site-connectivity picture |
| Licence posture | Per organization: how many licences are expiring and expired, or the single co-termination date, depending on which licensing model that organization runs | The company's network panel and the renewal conversation |
Create the API key in Meraki
- 11 · Sign in as a read-only administratorIn the Meraki dashboard, sign in as an administrator whose access is read-only across the organizations you want Current to see. If you do not have one, create it under Organization → Configure → Administrators first — it takes a minute and it is the safest way to run this.
- 22 · Open Organization ▸ Configure ▸ API & WebhooksGo to the API keys and access tab. You can also reach the same place from your avatar in the top right → My profile → API access.
- 33 · Generate the keyPress Generate API key. Meraki allows two keys per person, so if the button is greyed out this administrator already has two and you will need to revoke one first — check with whoever owns the other integration before you do.
- 44 · Copy it before you leave the pageMeraki shows the key once, at the moment you generate it. Copy it now — if you close the page you will have to generate another, and that counts against the two-key limit.
Connect it in Current
- 1Open the Meraki cardIn Current's left sidebar open Integrations (it sits under Admin, so Tenant Admins have the link) and find Cisco Meraki in the Monitoring & security section.
- 2Pick your Meraki cloudMeraki runs five separate clouds and a key only works against the one your organizations live on: Global (the default, covering North America, Europe, and Asia-Pacific), Canada, China, India, and US Government (FedRAMP). If your organizations are Canadian-hosted, pick Canada — a Canadian organization queried against the global address fails exactly like a wrong key.
- 3Paste the API key, then press Test connectionCurrent reads a short organization list back to prove the key works and that the administrator it belongs to can actually see organizations, before it stores anything. If Meraki refuses, the card shows Meraki's own reason rather than a generic failure. On success the key is stored server-side only — the browser never sees it again.
How Meraki organizations map to your companies
Meraki supports two ways of running an MSP estate, and both are normal. Meraki calls them the Tailored Service model — one organization per partner — and the Standard Service model, where you run a small number of organizations and each partner is a network inside one. Meraki recommends the second for service providers and says it is the more common of the two.
Current supports both. The connection maps by organization out of the box; if your partners are networks inside one or two organizations, switch the card to map by network instead. After the first sync, the card tells you what it found — for example, one organization containing thirty-four networks — so you can confirm which shape you are on rather than guessing.
- 1Let the auto-matcher run firstEvery sync links each organization (or network) to the one Current company whose normalized name matches — lowercased, with punctuation and Inc/LLC/Ltd-style suffixes stripped — and only when exactly one company matches. Two companies that both fit stay unmapped for you to decide.
- 2Open the mapping panelIntegrations → Cisco Meraki → Manage → Customer mapping. It opens on the Unmapped tab. Expect more manual work here than with some other connectors: Meraki knows nothing about your PSA, so there is no customer id the two systems already share and names are all Current has to go on.
- 3Map a row to its companyOn an unmapped row press Map, type a few letters of the Current company, and pick it. That organization's devices and uplinks attach to the company right away, rather than waiting for the next 6-hour sync.
- 4Ignore internal or lab organizationsFor anything that should never map to a partner — your own office, a lab, a demo network — press Ignore. It moves to the Ignored tab and stops counting against the card's unmapped badge.
- 5Fix a wrong match laterThe Mapped tab lists every linked row; Unmap corrects a bad auto-match, and the Ignored tab's Un-ignore brings a dismissed one back. A mapping you set by hand is never overwritten by a later auto-match, and neither is a manual unlink.
How often it syncs
Meraki syncs every 6 hours on a schedule, plus whenever you press Sync now on the card. Each run walks your organizations one at a time — not all at once — reads their networks, devices, uplinks, and licence posture, and replaces the device and uplink sets. Meraki allows ten requests a second per organization; Current deliberately runs at under half that, because your PSA integration and your own scripts are drawing on the same allowance.
The read-only guarantee
Every request Current makes to Meraki passes through a read-only guard that permits five specific read endpoints and nothing else. Meraki's API is a full network management API — it can reboot a device, power-cycle a switch port, move licences between organizations, create administrators, and delete an entire organization — and none of those paths exist anywhere in the connector's code, so a bug cannot reach them either. Generating the key from a read-only Meraki administrator adds a second, independent layer on Meraki's own side. Meraki stays the source of truth; Current only reads.
Where the data shows up
- +The company's network panel: device counts by product type, the four device states kept apart, and how many sites have their WAN up.
- +WAN uplink detail per site: which interface, its state, the internet provider, and cellular signal where a site is running on mobile backup.
- +Licence posture: how many licences are expiring and expired, or the co-termination date, depending on the organization's licensing model. This is your renewal list.
- +The Fleet & Network chapter of a Strategic Business Review, alongside your other network feeds.
- +Dashboard network metrics — device counts and site connectivity read from Meraki once it is connected and mapped.
When something looks wrong
| What you see | What it means |
|---|---|
| "Meraki rejected the API key" | Two causes, and the easier one first: the cloud picked on the card may not be where your organizations live — a Canadian, Chinese, Indian, or US Government organization only answers on its own address. If the cloud is right, the key was mistyped or has been revoked in Meraki. Generate a fresh one under Organization → Configure → API & Webhooks, remembering the two-key limit. |
| "Meraki accepted the key but refused the organization list" | That is a permissions answer, not a wrong key. The administrator the key belongs to may have no organizations in their list, or an organization may be set to restrict which IP addresses can use the API. Check the administrator's organization access in Meraki first. |
| Some organizations synced and others refused the key | The same permissions story, applied to part of your estate. Current keeps the organizations that worked and names how many refused, rather than failing the whole run. The card's note tells you the count. |
| "the dashboard API is switched off" on an organization | That organization has API access turned off in Meraki, so nothing can be read from it. Turn it on in Meraki under Organization → Configure → API & Webhooks, then press Sync now. |
| A site shows no WAN state | Meraki reports uplinks only for MX, MG, and Z-series devices. A site built entirely from switches and access points has no uplink to report, which is correct rather than a fault. Current leaves it blank rather than claiming the site is up. |
| Licence counts read "not reported" | Meraki answers the licence question differently depending on the licensing model an organization runs. A co-termination organization gets a single expiry date and no expiring counts; a per-device organization gets the counts and no single date; a subscription organization is not mirrored yet. Current shows what that organization actually reports rather than printing a zero it cannot stand behind. |
| A company shows no Meraki data | Its organization or network is not mapped yet, or it genuinely has no devices. Check the Unmapped tab on the card — Meraki maps by name only, so expect a few to need a hand. |
| "Meraki is rate-limiting the request" | Something else is using the same allowance right now. Current backs off and picks up on the next scheduled sync; nothing is lost and the key is fine. |
