Skip to content
Current/ Help Center

UniFi: consoles, sites, devices and the WAN circuit

6 min read · Updated Sep 5, 2026

UniFi is where the network itself lives: the gateway at each location, the switches and access points behind it, and the internet circuit into the building. This connector reads four things out of Ubiquiti's Site Manager service — the consoles your UniFi account can see, the sites inside them, the devices on each site, and the hour-by-hour state of the WAN circuit — and hangs each one off the matching Current company. Current reads UniFi and can never change anything in it.

Note
What this connector is for
It is a value-signal feed, not a console. Current mirrors device counts, online and firmware state, the gateway's model and inspection posture, the carrier on the circuit and how much of the week that circuit was up. It does not adopt or restart devices, block a client, edit a firewall rule, change a network or an SSID, or issue a hotspot voucher — those endpoints are not in the connector's code at all.

One key covers every partner

Unlike a per-site network tool, UniFi's Site Manager service is account-wide: one API key created on your UniFi account reads every console that account can see. You paste it once. There is no region to choose and no second credential per location.

Heads up
"Every console this account can see" is not always every console you manage
Two things narrow what a key returns, and neither shows up as an error — the estate simply looks smaller and perfectly healthy. A key created on one technician's personal UniFi account reaches only the consoles that person owns, rather than every console in your organization. And a site still running a self-hosted UniFi Network application, rather than a cloud-adopted console, does not appear at all. If the console count Current reports looks low, compare it against what you expect before you assume anything is broken with the key.

What Current syncs

Data setWhat Current storesWhere it lands
ConsolesEvery UniFi console (a Dream Machine, a Cloud Key, a UniFi OS Server) by its id, with a display label, hardware and firmware details, whether your account owns it, and when it last changed connection state. A console is one partner premises, so this is the record you map to a Current company.The mapping panel on the UniFi card
SitesEach site inside a console: its name, total and offline device counts, offline gateways, devices awaiting firmware, UniFi's own critical-notification count, the gateway model, its IPS and inspection setting, the carrier name on the circuit and the WAN uptime percentage.The mapped company's network panel and business review packs
DevicesEvery gateway, switch, access point and camera: name, model, LAN address, firmware version, whether an update is offered, adoption and boot time, and its online state.The company's network estate card and dashboard device metrics
Circuit metricsHour-by-hour WAN readings for each site over the last seven days — latency, packet loss, up and down time, and throughput — kept for 90 days.WAN uptime trends in a Strategic Business Review
Note
What Current deliberately does not store
The console record UniFi returns includes the account details of the person who administers it — their name, their email address and their permission map. Current drops that at the point it reads the response, before anything is written: there is no column for it in Current's database and it never appears in a log or a diagnostic. A technician's free-text note on a device is dropped for the same reason.

Create the API key at UniFi

  1. 1
    1 · Sign in at unifi.ui.com
    Use the UniFi account that can see the consoles you manage. If your team's consoles are spread across several personal accounts, sign in with the account that reaches the most of them, or move them under one organization account first — see the warning above.
  2. 2
    2 · Open Settings → API Keys
    The direct link is unifi.ui.com/settings/api-keys.
  3. 3
    3 · Create a key and copy it immediately
    UniFi displays the key once, at creation, and never shows it again. Copy it before you leave the page; a lost key means creating a new one.
Note
The key is read-only at UniFi's end too
Ubiquiti's API keys are read-only today by design, and enabling write access on an existing key is a deliberate manual step somebody has to take. That is a good starting position rather than a guarantee: Ubiquiti has said write endpoints are coming. Current's own read-only guard is what actually holds the line, and it does not depend on the key's setting.

Connect it in Current

  1. 1
    Open the UniFi card
    In Current's left sidebar open Integrations (it sits under Admin, so Tenant Admins have the link) and find UniFi in the Monitoring & security section.
  2. 2
    Paste the API key and press Test connection
    That is the whole form — no region, no username, no client id. Current reads a single console back to prove the key works before it stores anything. If UniFi refuses, the card shows UniFi's own reason rather than a generic failure. On success the key is stored server-side only and the browser never sees it again.
  3. 3
    Wait for the first sync, then map
    The first run lists every console the key can see. Because those labels are hostnames and hardware names rather than company names, expect to map most of them by hand — that is normal here, not a fault.

How often it syncs

UniFi syncs every 6 hours on a schedule, plus whenever you press Sync now on the card. Each run walks the consoles first — so the mapping panel fills even if a later step runs out of time — then the sites, then the devices, then the last seven days of circuit readings.

The read-only guarantee

Every request Current makes to UniFi passes through a read-only guard that permits exactly four read endpoints: the console list, the site list, the device list and the circuit metrics. Nothing else is reachable, including UniFi's connector passthrough — the one route that can reach a console's own management interface, and therefore adopt or restart a device, shut a switch port, block a client, reorder a firewall rule or change an SSID. That route is absent from the list and no part of the connector can construct its address, so a bug cannot reach it either. UniFi stays the source of truth; Current only reads.

Map consoles to your companies

In UniFi, one console is normally one partner premises, so that is what Current maps. A partner with several locations under one console appears as one company with several site rows, which is exactly how the company card wants to read it.

Heads up
Expect to map most consoles by hand
Current still tries the automatic match — lowercased, punctuation and Inc/LLC/Ltd-style suffixes stripped, and only when exactly one company matches. But UniFi labels are things like unifi.northwind.example, UDM-Pro, or Main Office, and those rarely resemble a company name. Two or three will match themselves; plan to place the rest. It is a one-time job.
  1. 1
    Open the mapping panel
    Integrations → UniFi → Manage → Customer mapping. It opens on the Unmapped tab.
  2. 2
    Map a console to its company
    On an unmapped row press Map, type a few letters of the Current company, and pick it. That console's sites, devices and circuit readings attach to the company right away, rather than waiting for the next 6-hour sync.
  3. 3
    Ignore anything internal
    For a console that should never map to a company — your own office, a lab, a bench unit — press Ignore. It moves to the Ignored tab and stops counting against the card's unmapped badge.
  4. 4
    Fix a wrong match later
    The Mapped tab lists every linked console; Unmap corrects a bad automatic match, and the Ignored tab's Un-ignore brings a dismissed one back. A mapping you set by hand is never overwritten by a later automatic match, and neither is a manual unlink.

Where the data shows up

  • The company's network panel: sites, devices, how many are offline and how many are waiting on firmware.
  • The company's network estate card: each site with its carrier and WAN state, and devices worst-first — offline, then alerting, then pending firmware.
  • The Fleet & network chapter of a Strategic Business Review, where the WAN uptime figure and the carrier name are the parts a partner recognises about their own building.
  • The company alert band: a gateway offline reads critical, several other devices offline reads a warning, and both clear themselves once UniFi reports the site back to normal.

When something looks wrong

What you seeWhat it means
Test connection is rejectedUniFi did not accept the key. Create a fresh one at unifi.ui.com → Settings → API Keys, remembering it is shown only once, and paste that.
Connected, but fewer consoles than you expectedThe key's UniFi account cannot see the rest. That is the personal-key or the non-cloud-adopted case in the warning above, and it is the one failure UniFi reports as a normal, successful, smaller answer. Check the console count against what you manage.
A console shows sites but no devicesThe connected UniFi account is an admin on that console rather than its owner or a super admin, and UniFi only lists devices for the latter. Current says so on the card instead of showing a zero, because a zero there would be wrong. Raising that account's role on the console fixes it.
A site shows no device counts at allUniFi returned that site without its statistics block. Current shows unknown rather than assuming the site is fine — the numbers fill in on a later sync.
WAN uptime is blankUniFi did not report an uptime percentage for that site. Current leaves it blank rather than printing 100, because a missing figure is exactly what an unreadable site looks like.
No latency figure on the circuit lineThat is deliberate. UniFi publishes latency, packet loss and downtime without documenting what unit they are in, so Current stores the readings but will not print a number it cannot label correctly. WAN uptime is shown, because UniFi names that one as a percentage itself.
A console was removed from UniFi but is still listedIt leaves on the next complete sync. A sync that was cut short never removes anything, so a half-finished run cannot look like a partner decommissioning their network.
Note
Who can do this, and disconnecting
Connecting, testing, mapping and disconnecting are Tenant Admin actions; sales leadership can run a manual sync and read status. Disconnect stops the sync and skips your workspace on the 6-hour sweep — the consoles, sites and devices already pulled stay put, and reconnecting resumes from where it left off. Partner (read-only) viewers never see any of this data; it is blocked at the database, not just hidden.
Was this helpful?