Skip to content
Current/ Help Center

Cisco Meraki: network devices, WAN uplinks, and licence expiry

6 min read · Updated Sep 5, 2026

Cisco Meraki is where your network lives: the MX appliances at the edge of each site, the MS switches behind them, and the MR access points on top. This connector reads four things out of it — your organizations and their networks, every device and whether it is online, the WAN uplink state at each site, and how your licences are tracking — and hangs each one off the matching Current company so it feeds your business reviews and the company posture panel. Current reads Meraki and can never change anything in it.

Note
Network gear is not endpoints
A Meraki switch is network infrastructure, not a managed workstation. It has no patch state and no antivirus state, so Current counts it alongside your endpoint numbers rather than inside them. Your device-compliance percentages do not move because an access point rebooted.

What Current syncs

Data setWhat Current storesWhere it lands
OrganizationsEach Meraki organization by id and name, whether the dashboard API is switched on for it, which Meraki cloud and country it is hosted in, and which licensing model it runsThe mapping panel on the Meraki card
NetworksEach network — a site — with its name, the product types it carries, its time zone, and its tagsThe mapped company's network panel and SBR packs
DevicesPer device: serial, name, model where Meraki reports one, product type (appliance, switch, wireless, camera, sensor and the rest), its network, and its current statusThe company's network panel, the SBR fleet and network chapter, and dashboard device metrics
WAN uplinksOne row per WAN interface on each MX, MG, and Z-series device: which interface, its state, the internet provider, the connection type, and cellular signal where it applies. Dual-WAN and triple-WAN sites get a row per linkThe company's network panel — this is the site-connectivity picture
Licence posturePer organization: how many licences are expiring and expired, or the single co-termination date, depending on which licensing model that organization runsThe company's network panel and the renewal conversation
Note
Four device states, not two
Meraki reports a device as online, alerting, offline, or dormant, and Current keeps all four apart. Alerting means the device is reachable and reporting a problem — that is the one worth acting on this morning, and folding it into offline would overstate your outages. Dormant means a device deliberately out of service, usually a spare on a shelf, so counting it as offline would invent an outage that is not there.

Create the API key in Meraki

Heads up
Make the key from a read-only Meraki administrator
A Meraki API key inherits the permissions of the administrator who generates it, and Meraki states that a read-only administrator can only make GET requests. Generating the key from a read-only administrator means Meraki itself refuses every write, on top of the read-only limits already built into Current. Meraki's API can reboot devices, cycle switch ports, move licences, and delete an entire organization — this one setting takes all of it off the table before Current is even involved.
  1. 1
    1 · Sign in as a read-only administrator
    In the Meraki dashboard, sign in as an administrator whose access is read-only across the organizations you want Current to see. If you do not have one, create it under Organization → Configure → Administrators first — it takes a minute and it is the safest way to run this.
  2. 2
    2 · Open Organization ▸ Configure ▸ API & Webhooks
    Go to the API keys and access tab. You can also reach the same place from your avatar in the top right → My profile → API access.
  3. 3
    3 · Generate the key
    Press Generate API key. Meraki allows two keys per person, so if the button is greyed out this administrator already has two and you will need to revoke one first — check with whoever owns the other integration before you do.
  4. 4
    4 · Copy it before you leave the page
    Meraki shows the key once, at the moment you generate it. Copy it now — if you close the page you will have to generate another, and that counts against the two-key limit.

Connect it in Current

  1. 1
    Open the Meraki card
    In Current's left sidebar open Integrations (it sits under Admin, so Tenant Admins have the link) and find Cisco Meraki in the Monitoring & security section.
  2. 2
    Pick your Meraki cloud
    Meraki runs five separate clouds and a key only works against the one your organizations live on: Global (the default, covering North America, Europe, and Asia-Pacific), Canada, China, India, and US Government (FedRAMP). If your organizations are Canadian-hosted, pick Canada — a Canadian organization queried against the global address fails exactly like a wrong key.
  3. 3
    Paste the API key, then press Test connection
    Current reads a short organization list back to prove the key works and that the administrator it belongs to can actually see organizations, before it stores anything. If Meraki refuses, the card shows Meraki's own reason rather than a generic failure. On success the key is stored server-side only — the browser never sees it again.
Heads up
The wrong cloud looks like a bad key
A perfectly good key pointed at the wrong Meraki cloud is rejected the same way a mistyped one is. If Test connection refuses a key you just copied, check the cloud on the card against the address you sign in at before you generate another — you only get two.

How Meraki organizations map to your companies

Meraki supports two ways of running an MSP estate, and both are normal. Meraki calls them the Tailored Service model — one organization per partner — and the Standard Service model, where you run a small number of organizations and each partner is a network inside one. Meraki recommends the second for service providers and says it is the more common of the two.

Current supports both. The connection maps by organization out of the box; if your partners are networks inside one or two organizations, switch the card to map by network instead. After the first sync, the card tells you what it found — for example, one organization containing thirty-four networks — so you can confirm which shape you are on rather than guessing.

Heads up
Changing how it maps clears your existing mappings
Mapping by organization and mapping by network are mappings of different things, so switching between them re-keys every row and any pairing you set by hand is lost. Get it right on the first sync rather than switching six months in. Nothing switches on its own — Current reports what it found and leaves the decision to you.
  1. 1
    Let the auto-matcher run first
    Every sync links each organization (or network) to the one Current company whose normalized name matches — lowercased, with punctuation and Inc/LLC/Ltd-style suffixes stripped — and only when exactly one company matches. Two companies that both fit stay unmapped for you to decide.
  2. 2
    Open the mapping panel
    Integrations → Cisco Meraki → Manage → Customer mapping. It opens on the Unmapped tab. Expect more manual work here than with some other connectors: Meraki knows nothing about your PSA, so there is no customer id the two systems already share and names are all Current has to go on.
  3. 3
    Map a row to its company
    On an unmapped row press Map, type a few letters of the Current company, and pick it. That organization's devices and uplinks attach to the company right away, rather than waiting for the next 6-hour sync.
  4. 4
    Ignore internal or lab organizations
    For anything that should never map to a partner — your own office, a lab, a demo network — press Ignore. It moves to the Ignored tab and stops counting against the card's unmapped badge.
  5. 5
    Fix a wrong match later
    The Mapped tab lists every linked row; Unmap corrects a bad auto-match, and the Ignored tab's Un-ignore brings a dismissed one back. A mapping you set by hand is never overwritten by a later auto-match, and neither is a manual unlink.

How often it syncs

Meraki syncs every 6 hours on a schedule, plus whenever you press Sync now on the card. Each run walks your organizations one at a time — not all at once — reads their networks, devices, uplinks, and licence posture, and replaces the device and uplink sets. Meraki allows ten requests a second per organization; Current deliberately runs at under half that, because your PSA integration and your own scripts are drawing on the same allowance.

The read-only guarantee

Every request Current makes to Meraki passes through a read-only guard that permits five specific read endpoints and nothing else. Meraki's API is a full network management API — it can reboot a device, power-cycle a switch port, move licences between organizations, create administrators, and delete an entire organization — and none of those paths exist anywhere in the connector's code, so a bug cannot reach them either. Generating the key from a read-only Meraki administrator adds a second, independent layer on Meraki's own side. Meraki stays the source of truth; Current only reads.

Note
What Current deliberately does not store
Cellular uplinks report a SIM's phone number and subscriber identifiers alongside the signal strength. Current drops those the moment the response arrives rather than filtering them out of a screen later — they are carrier subscriber identity rather than device inventory, and no report needs them. Signal strength, the carrier's name, and the connection type are kept, because those are what a site conversation is actually about.

Where the data shows up

  • The company's network panel: device counts by product type, the four device states kept apart, and how many sites have their WAN up.
  • WAN uplink detail per site: which interface, its state, the internet provider, and cellular signal where a site is running on mobile backup.
  • Licence posture: how many licences are expiring and expired, or the co-termination date, depending on the organization's licensing model. This is your renewal list.
  • The Fleet & Network chapter of a Strategic Business Review, alongside your other network feeds.
  • Dashboard network metrics — device counts and site connectivity read from Meraki once it is connected and mapped.

When something looks wrong

What you seeWhat it means
"Meraki rejected the API key"Two causes, and the easier one first: the cloud picked on the card may not be where your organizations live — a Canadian, Chinese, Indian, or US Government organization only answers on its own address. If the cloud is right, the key was mistyped or has been revoked in Meraki. Generate a fresh one under Organization → Configure → API & Webhooks, remembering the two-key limit.
"Meraki accepted the key but refused the organization list"That is a permissions answer, not a wrong key. The administrator the key belongs to may have no organizations in their list, or an organization may be set to restrict which IP addresses can use the API. Check the administrator's organization access in Meraki first.
Some organizations synced and others refused the keyThe same permissions story, applied to part of your estate. Current keeps the organizations that worked and names how many refused, rather than failing the whole run. The card's note tells you the count.
"the dashboard API is switched off" on an organizationThat organization has API access turned off in Meraki, so nothing can be read from it. Turn it on in Meraki under Organization → Configure → API & Webhooks, then press Sync now.
A site shows no WAN stateMeraki reports uplinks only for MX, MG, and Z-series devices. A site built entirely from switches and access points has no uplink to report, which is correct rather than a fault. Current leaves it blank rather than claiming the site is up.
Licence counts read "not reported"Meraki answers the licence question differently depending on the licensing model an organization runs. A co-termination organization gets a single expiry date and no expiring counts; a per-device organization gets the counts and no single date; a subscription organization is not mirrored yet. Current shows what that organization actually reports rather than printing a zero it cannot stand behind.
A company shows no Meraki dataIts organization or network is not mapped yet, or it genuinely has no devices. Check the Unmapped tab on the card — Meraki maps by name only, so expect a few to need a hand.
"Meraki is rate-limiting the request"Something else is using the same allowance right now. Current backs off and picks up on the next scheduled sync; nothing is lost and the key is fine.
Note
Who can do this, and disconnecting
Connecting, testing, mapping, and disconnecting are Tenant Admin actions; sales leadership can run a manual sync and read status. Disconnect stops the sync and skips your workspace on the 6-hour sweep — the devices and uplinks already pulled stay put, and reconnecting resumes from where it left off. Partner (read-only) viewers never see any of this data; it is blocked at the database, not just hidden.
Was this helpful?