Skip to main content
PacketMentor logo
Open menu
← All topics
Automation & Programmability Foundational

Catalyst SD-WAN API: Login, CSRF, GET Devices

The Catalyst SD-WAN (ex-Viptela) vManage REST API in exam shape: login + CSRF token, then GET /dataservice/device for the fleet. Covers 3.9.a for Catalyst SD-WAN.

Quick summary
  • Catalyst SD-WAN is managed by one or more vManage controllers. API lives under /dataservice.
  • Auth is two-step: POST /j_security_check with user:pass (session cookie), then GET /dataservice/client/token to get an X-XSRF-TOKEN header.
  • List devices: GET /dataservice/device. Returns vEdges / cEdges / vSmart / vBond / vManage with status and up/down state.

Mental model

Cisco objective 3.9.a names Catalyst SD-WAN. Catalyst SD-WAN (previously SD-WAN by Cisco / Viptela) uses vManage as its controller. API base: https://vmanage.example.com/dataservice/....

Auth is more involved than Catalyst Center or Meraki — two steps, session cookie + CSRF token.

Step 1 — login

curl -k -c cookies.jar \
     -X POST -d 'j_username=admin&j_password=password' \
     https://vmanage.example.com/j_security_check
  • URL ends in /j_security_check (JAAS-style auth endpoint, not JSON).
  • Body is URL-encoded form, NOT JSON.
  • Response: empty if success. HTTP 200.
  • Set-Cookie: JSESSIONID=... saved in cookies.jar.

Failure returns a HTML page with <title>login</title> instead of an error code — check the body on first attempt.

Step 2 — CSRF token

curl -k -b cookies.jar \
     https://vmanage.example.com/dataservice/client/token

Response body is the raw token string (not JSON). Save it as $CSRF.

From here on, every write (POST/PUT/DELETE) requires -H "X-XSRF-TOKEN: $CSRF". Reads work with just the cookie.

3.9.a — List devices

curl -k -b cookies.jar https://vmanage.example.com/dataservice/device

Response (abbreviated):

{
  "data": [
    {
      "deviceId": "10.1.1.1",
      "system-ip": "1.1.1.1",
      "host-name": "vmanage-01",
      "device-type": "vmanage",
      "device-model": "vmanage",
      "reachability": "reachable",
      "status": "normal"
    },
    {
      "deviceId": "10.2.2.1",
      "system-ip": "2.2.2.1",
      "host-name": "edge-site-01",
      "device-type": "vedge",
      "device-model": "vedge-cloud",
      "reachability": "reachable",
      "status": "normal"
    }
  ],
  "header": {"columns": [...]}
}

device-type tells you what kind: vmanage / vsmart / vbond (controllers), vedge / cedge (data-plane edges).

Other common endpoints

EndpointReturns
GET /dataservice/deviceAll devices (controllers + edges)
GET /dataservice/device/countersPer-device counters (reachable, warning, invalid)
GET /dataservice/device/interface?deviceId=10.2.2.1Interfaces on a specific device
GET /dataservice/statistics/approuteApplication-aware route stats
GET /dataservice/template/deviceDevice templates (configuration)

Python with requests

import requests
requests.packages.urllib3.disable_warnings()

BASE = "https://vmanage.example.com"
s = requests.Session()

# login
s.post(f"{BASE}/j_security_check",
       data={"j_username": "admin", "j_password": "password"},
       verify=False)

# CSRF token
csrf = s.get(f"{BASE}/dataservice/client/token", verify=False).text
s.headers["X-XSRF-TOKEN"] = csrf

# list devices
r = s.get(f"{BASE}/dataservice/device", verify=False)
for d in r.json()["data"]:
    print(f"{d['host-name']:25} {d['system-ip']:12} {d['device-type']:10} {d['reachability']}")

Session + cookie + header-on-session covers both auth steps cleanly.

Common gotchas

  • Login returns an HTML login page on failure. HTTP 200 but with <html> in the body. Check content-type / body shape, not the status.
  • CSRF token mismatch on write operations if you re-login without re-fetching the token.
  • URL space is dataservice, not api or rest — unlike Catalyst Center and Meraki.
  • Multi-tenant deployments need extra tenantName query param on some endpoints.
  • Older vManage versions have slightly different auth endpoints — docs vary by version.

FAQ

Why is auth so complex vs Catalyst Center? vManage inherited the auth pattern from the Viptela product. Cisco acquired Viptela in 2017; the API retains its original shape. Modern Cisco controllers (Catalyst Center, Nexus Dashboard) use token-only.

Is there an SDK? cisco-sdwan (community) and various vendor sample scripts. For 200-901, requests is enough.

What is Catalyst SD-WAN Manager? Rebranded name for vManage. Same product, same API.

Where is the DevNet Sandbox? developer.cisco.com has an always-on Catalyst SD-WAN sandbox with a small demo fabric.

Master this on a real network

Want this drilled into reflex?

1:1 weekly sessions, live feedback on your labs, and US interview prep: built around the CCNA Automation® exam blueprint. Free first session. No card on file until you decide.

Claim my free session →

Get the free CCNA 12-week roadmap

You're already reading up on Catalyst SD-WAN API: Login, CSRF, GET Devices. The roadmap is the order I recommend studying every CCNA topic in: with what to lab each week and where Catalyst SD-WAN API: Login, CSRF, GET Devices fits. A written personal reply, not an autoresponder. Expect it within one business day.

Personal reply from a senior network engineer. No third-party tracking. Unsubscribe any time.