Mental model
Cisco objective 5.14 says “Interpret a sequence diagram that includes API calls”. A sequence diagram is a picture of a conversation: who talked, in what order, what they said.
┌────────┐ ┌───────────┐ ┌──────────────┐
│ Client │ │ Auth API │ │ Resource API │
└────────┘ └───────────┘ └──────────────┘
│ │ │
│─POST /login──▶ │
│ │ │
│◀──200 {token}┤ │
│ │ │
│─GET /devices (Authorization: Bearer <token>)▶│
│ │ │
│◀────────────────────200 [...]──┤
│ │ │
Three actors (boxes at top). Each has a lifeline (the vertical line below). Arrows between lifelines are messages, read top to bottom in time order.
The vocabulary
| Element | Meaning |
|---|---|
| Box at top | A participant (Client, API server, Database, Device, User) |
| Dashed vertical line below | That participant’s lifeline (where they exist in time) |
| Solid narrow box over the lifeline | Activation / “the actor is working” |
Solid arrow ──▶ | Message / request |
Dashed arrow ◀── or --▶ | Return / response |
| Self-arrow (loops back to same lifeline) | The actor calls itself (internal method call) |
alt box | If-else branch; two sub-frames with a condition label |
loop box | Repeat the enclosed messages while some condition holds |
opt box | Optional sub-flow; happens only if a condition is true |
par box | Parallel execution of two sub-frames |
Reading the example
Client → Auth API POST /login (request credentials)
Client ← Auth API 200 {token} (receive bearer token)
Client → Resource API GET /devices + Bearer (use token to fetch data)
Client ← Resource API 200 [...] (receive devices list)
Two-step OAuth2-style flow: log in to get a token, use the token for subsequent calls.
A busier example
┌────────┐ ┌─────────┐ ┌─────────────────┐ ┌──────────┐
│Browser │ │ Web app │ │ Catalyst Center │ │ Switch │
└────────┘ └─────────┘ └─────────────────┘ └──────────┘
│ │ │ │
│─GET /ui──▶│ │ │
│ │─POST /auth────▶│ │
│ │◀────token──────┤ │
│ │─GET /devices──▶│ │
│ │ │─SSH/show──────▶│
│ │ │◀───output──────┤
│ │◀───devices JSON┤ │
│◀─HTML─────┤ │ │
Interpretation:
- Browser hits the web app.
- Web app authenticates to Catalyst Center.
- Web app asks Catalyst Center for devices.
- Catalyst Center queries each switch over SSH to get live state.
- Catalyst Center returns the merged list to the web app.
- Web app renders HTML back to the browser.
loop and alt frames
loop for each device
│
│─GET /device/{id}/clients────▶│
│◀───200 [clients]─────────────┤
│
end loop
alt switch is reachable
│─GET /switch/stats─▶│
│◀────200 stats──────┤
else
│─record "down" ───▶ (log)
end alt
Any grouping with a label on top (loop, alt, opt, par) applies to the enclosed arrows.
Reading tips for the exam
- Identify the actors at the top of the diagram.
- Follow the time order top to bottom.
- Note the arrow direction — who initiated vs who replied.
- Pay attention to labels on arrows — HTTP method + URL + headers tell you what the call is.
- Watch for alt/loop/opt frames — they change the flow.
- Describe the end result in one sentence.
Where you see sequence diagrams
- API documentation (how an OAuth2 flow unfolds).
- Vendor whitepapers.
- RFCs (TLS handshake, QUIC handshake).
- Incident post-mortems (“what messages happened in what order when the system failed”).
Tools that draw them: PlantUML, Mermaid (used in GitHub markdown), draw.io, Lucidchart.
FAQ
What is a Mermaid sequence diagram? A text format for drawing sequence diagrams. Looks like:
sequenceDiagram
Client->>Auth: POST /login
Auth-->>Client: 200 {token}
Client->>Resource: GET /devices
Resource-->>Client: 200 [...]
GitHub and GitLab render these inline from markdown.
Is a flowchart the same as a sequence diagram? No. Flowchart shows decision logic (branches, loops) regardless of actors. Sequence diagram emphasises the chronology between two or more actors.
Are swimlane diagrams on the exam? Not called out specifically. Swimlanes are a flowchart variant that assigns each step to an actor; useful but not required for 5.14.
Do I need to draw sequence diagrams for the exam? No. 5.14 is interpret-level. Reading, not drawing.
