> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Connecting Cisco Meraki to Neo

> Save a Meraki Dashboard API key and your Meraki region in Neo

You connect Meraki once at the MSP level, with one Dashboard API key.

## 1. Generate the API key

<Steps>
  <Step title="Pick the admin">
    The key acts as the dashboard admin who generates it, in every organization that admin can see. Use an admin with access to your clients' organizations. A key from a read-only admin lets Neo read only. An admin who signs in only through SAML cannot generate a key.
  </Step>

  <Step title="Generate the key">
    In **Organization** → **API & Webhooks**, open **API keys and access** and click **Generate API key**. Copy the key: Meraki shows it once. An admin can hold two keys.
  </Step>
</Steps>

<Warning>
  Do not revoke the key in Meraki after you connect it. Neo loses access until you save a new key here.
</Warning>

## 2. Add the key in Neo

<Steps>
  <Step title="Open Integrations">
    In the Neo Dashboard, open [**Integrations** → **Cisco Meraki**](https://dashboard.neoagent.io/integrations?open=meraki), under Networking.
  </Step>

  <Step title="Save the key">
    Enter the API key. Leave **Region** on Global unless you sign in to Meraki at a Canada, China, India or US FedRAMP address. Click **Save settings**. Neo checks the key against Meraki before saving, so a wrong key or region is rejected straight away.
  </Step>
</Steps>

## 3. Turn Meraki on per agent

Open the agent, go to the Integrations section, and configure the Cisco Meraki block. Agents reach only the organizations the key's admin can see.

### Pick an access profile

<CardGroup cols={2}>
  <Card title="Read Only" icon="magnifying-glass">
    Read every area. Nothing is changed.
  </Card>

  <Card title="Helpdesk" icon="headset">
    Read every area. Device, client and switch port actions (reboot, port cycle, cable test, block a client) wait on a technician.
  </Card>

  <Card title="IT Admin" icon="user-gear">
    Read and change every area. Security Appliance & VPN, Wireless, Firmware, Licensing and Administration changes wait on a technician.
  </Card>

  <Card title="Full Automation" icon="bolt">
    Read and change every area without approval, apart from the changes below that always ask.
  </Card>
</CardGroup>

### Or set each area by hand

Each area takes Disabled, Read Only or Read/Write, and has its own technician approval setting.

| Area | Covers |
| - | - |
| **Organizations & Networks** | Organizations, networks, network settings, floor plans and the configuration change log. |
| **Devices & Inventory** | Devices, availability, inventory, live diagnostics (ping, ARP and MAC tables, port status); reboot, blink LEDs, wake-on-LAN, claim. |
| **Monitoring & Clients** | Events, alerts, uplinks, loss and latency, clients, topology and LLDP/CDP; block or allow a client. |
| **Wireless** | SSIDs, RF profiles, Air Marshal, SSID firewall rules and Wi-Fi stats. |
| **Switching** | Switch ports, stacks, ACLs, routing and QoS; port cycle and cable test. |
| **Security Appliance & VPN** | MX firewall, VLANs, NAT, content filtering, threat protection, traffic shaping and VPN. |
| **Firmware** | Firmware upgrades, staged upgrades and rollbacks. |
| **Licensing** | Licences, co-term and subscriptions, seat moves. |
| **Administration** | Dashboard admins, SAML, login security, alert and webhook settings, SNMP and syslog, policy objects, group policies and templates. |
| **Systems Manager** | Managed devices, profiles, apps and device commands. |
| **Cameras, Sensors & Other** | Cameras, sensors, cellular and campus gateways, wireless controllers, Insight and Spaces. |

### Changes that always ask a technician

Whatever the profile, a technician approves: deleting, combining, splitting or unbinding a network; removing a device from a network or releasing it from the inventory; wiping or unenrolling a Systems Manager device; every change to dashboard admins, SAML, SAML roles, login security and Systems Manager admin roles; and every change to Meraki Authentication users (802.1X, splash and client VPN accounts).

### What Neo never sends

Neo refuses: deleting an organization, turning off an organization's API access, action batches, creating or revoking API keys, vMX authentication tokens, packet captures and camera snapshots.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.