> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# TP-Link Omada API

> Check a client's Omada access points, switches, gateways and clients, reboot devices, block clients, issue hotspot vouchers and change WiFi, network and firewall settings, across the Omada cloud controller

The common use is a connectivity ticket: "WiFi is slow" or "the internet is down" at a client's site. The agent finds the client's site in Omada, checks the gateway's WAN state, the access point the user's device is on and its signal, and writes what it found.

<Info>
  Automatically enabled when you configure TP-Link Omada permissions in your agent workflow.
</Info>

## What It Does

* Find the Omada customer (in the MSP view) or the site that belongs to the ticket's company
* Read access points, switches, gateways, OLTs and stacks: status, uplink, ports, PoE, CPU and memory, firmware, online history
* Read a gateway's WAN ports: internet state, latency, packet loss and ISP
* Reboot a device, power-cycle a PoE port, adopt or forget a device, change port and device settings, plan firmware upgrades
* Find a client by name, MAC or IP, with its access point, SSID, signal, VLAN and connection history; reconnect, block, unblock or rename it, set a fixed IP or a rate limit
* Read and change WiFi (WLAN groups and SSIDs), LAN and WAN networks, DHCP reservations, routing, QoS and VoIP settings
* Read and change ACLs, firewall, NAT and port forwarding, IPS, URL and application filters, VPN, 802.1X and MAC authentication
* Create and read hotspot vouchers, and change portal settings
* Read and resolve alerts, events, audit logs, insights, incidents and health
* Read and change site templates, controller admins, roles, licenses and controller settings

Neo reaches the Omada cloud controller (Omada Central). Passwords, WiFi keys, shared secrets and private keys in a response are replaced before the agent sees them.

## Permission Groups

| Group | Access levels | Covers |
| - | - | - |
| Customers & Sites | Disabled, Read Only, Read / Write | MSP customers, sites, site tags and scenarios |
| Devices | Disabled, Read Only, Read / Write | Access points, switches, gateways, OLTs and stacks: status, ports, PoE, reboots, adoption, firmware |
| Clients | Disabled, Read Only, Read / Write | Wired and wireless clients: history, reconnect, block, names, fixed IPs, rate limits |
| Networks & WiFi | Disabled, Read Only, Read / Write | WiFi, LAN and WAN networks, DHCP, DNS, routing, QoS, VoIP, RF planning |
| Firewall, VPN & Security | Disabled, Read Only, Read / Write | ACLs, firewall, NAT and port forwarding, IPS, URL and application filters, VPN, 802.1X, MAC authentication |
| Hotspot & Portal | Disabled, Read Only, Read / Write | Guest portals, vouchers and voucher groups, authorized guests |
| Monitoring, Logs & Reports | Disabled, Read Only, Read / Write | Dashboards, alerts, events, audit logs, insights, incidents, health, reports |
| Site Templates | Disabled, Read Only, Read / Write | Site templates and the settings they push to every bound site |
| Admins & Controller Settings | Disabled, Read Only, Read / Write | Admins, roles, SSO, two-factor authentication, licenses, webhooks, mail, backups, controller settings |

## Access Profiles

| Profile | What runs on its own | What asks a technician |
| - | - | - |
| **Read Only** | Every supported read | No write is allowed |
| **Helpdesk** | Device, client, hotspot and monitoring changes: reboots, client blocks, vouchers, resolving alerts | Network, security, site, template and controller changes, and the Safety Controls below |
| **IT Admin** | Every supported change except those on the right | Every change in the Firewall, VPN & Security and the Admins & Controller Settings groups, and the Safety Controls below |
| **Full Automation** | Every supported change except the Safety Controls below | Only the Safety Controls below |

## Safety Controls

| Control | Behavior |
| - | - |
| **Deletes and restores** | Deleting a customer or a site, and restoring the controller or sites from a backup, always ask a technician |
| **Forgetting devices** | Forgetting a device or a switch stack, which removes it from the controller and resets it, always asks a technician |
| **Admins and sign-in** | Adding, changing or removing a controller or MSP admin (a re-invite included), a role or a customer role, a SAML identity provider or an SSO user group, and turning two-factor authentication on or off, always ask a technician |
| **Secrets** | A change that sets a secret (a password, key, PIN, token or SNMP community), a WiFi key or a shared secret included, always asks a technician. Secrets in a response are replaced with `[redacted by Neo]`, and a change that sends that text back is refused |
| **Bulk changes** | A bulk change (resolving or deleting logs, bulk ACL, OSPF or IP-MAC changes) must name its records: a change that selects "all" or "exclude", or leaves out the selection, is refused |
| **Not supported** | Transferring the controller's owner and binding or unbinding its cloud account, batch calls, file uploads and downloads, generating WireGuard keys, and any change that is not an operation in the Omada Open API reference Neo was built from (version 6.3.0) |


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.