Wi-Fi shows connected but nothing loads, and wpa_cli is the tool that tells you why without editing config files blindly. You will use it to inspect a running wpa_supplicant, identify the interface it controls, list configured networks and recover a connection. Allow about ten minutes if the supplicant is already running and you know the wireless interface name.
This guide follows the installed Ubuntu package wpasupplicant 2:2.10-21ubuntu0.4, whose client reports itself as wpa_cli v2.10. The local wpa_cli(8) page is dated 7 August 2019 and documents a smaller command set than this binary. Where they differ, trust the installed command's own help and behaviour.
Start with read-only checks. Ordinary users can run these when the control socket permits their account or group. Do not begin with sudo: it can mask a socket-permission problem and changes which user's environment you are testing.
$ command -v wpa_cli
/usr/sbin/wpa_cli
$ wpa_cli -v
wpa_cli v2.10
$ wpa_cli -h | sed -n '1,18p'
The installed client uses /var/run/wpa_supplicant by default and otherwise picks the first interface socket it finds. That default is convenient on a single-interface machine and risky the moment a second one shows up. Use an explicit interface for repeatable commands.
$ ip -br link
$ ls -l /var/run/wpa_supplicant
Pick the wireless interface from the first command and confirm a matching socket exists in the second. Replace wlp2s0 below with the value on your machine.
Run status before changing anything:
$ IFACE=wlp2s0
$ wpa_cli -i "$IFACE" status
A working connection returns status fields as name=value lines, including the WPA state and network details. What matters is whether the supplicant is disconnected, associating, completed, or reporting an authentication failure. Save the output if you need to compare a later attempt, but treat it as network-sensitive information.
Checkpoint: Record the command's exit status immediately if a script will use it:
$ wpa_cli -i "$IFACE" status > /tmp/wpa-status.txt
$ status=$?
$ printf 'wpa_cli status exit: %s\n' "$status"
$ test "$status" -eq 0
If the client says it cannot connect to the control interface, check the interface name and socket path first. If the socket exists but access is denied, ask the system administrator to grant the intended group access through ctrl_interface GROUP=... in the supplicant configuration. Use elevated privileges only for that administrative repair, then follow the host's normal service-management procedure.
list_networks is read-only and shows the network IDs that later commands use. The ID is not an SSID and can change when networks are added or removed.
$ wpa_cli -i "$IFACE" list_networks
Match the intended SSID to its row to find the numeric network ID. Do not guess it from an old shell history entry. An empty list means this client has no configured networks to select; adding credentials is a separate, security-sensitive change.
When the access point is nearby but the connection has gone stale, request a scan and inspect the result:
$ wpa_cli -i "$IFACE" scan
$ wpa_cli -i "$IFACE" scan_results
Scanning does not select a network by itself. If the intended network is already configured, ask the supplicant to reassociate:
$ wpa_cli -i "$IFACE" reassociate
$ wpa_cli -i "$IFACE" status
Warning: Reassociation briefly interrupts wireless traffic and can drop an SSH session carried by that interface. Run it from a local console or a second management path when the machine is remote. Confirm the follow-up status shows completed before testing whatever needed the network.
For a more targeted choice, the installed v2.10 client also offers select_network <network id>, which enables the chosen network and disables the rest. This changes supplicant state, so confirm the ID with list_networks first and verify with status after.
If an administrator has deliberately edited the supplicant configuration file, tell the running daemon to reread it:
$ sudo wpa_cli -i "$IFACE" reconfigure
$ wpa_cli -i "$IFACE" status
sudo is shown because a protected control socket may require it, not because every installation does; on a host set up for non-root control access, omit it. reconfigure is not a syntax checker and it will not undo an edit. If the result is worse, restore the previous configuration from the administrator's backup, reconfigure again, and check the service log with the host's normal logging tool.
Interactive mode earns its keep when an enterprise network asks for credentials that are not already in the configuration. Start it without a command:
$ wpa_cli -i "$IFACE"
> status
> quit
While attached, the client can display requests such as CTRL-REQ-PASSWORD-1:.... Reply with the matching network ID, for example password 1 your-password; for a one-time token use otp 1 your-token. The manpage is specific that a password is remembered while wpa_supplicant runs, whereas an OTP is used once and forgotten.
Warning: Never put a real password in a guide, shell history, shared terminal recording or ticket. These commands carry the value as an argument, so prefer a controlled interactive session and clear any captured output afterwards. Do not run terminate while troubleshooting a live host: it stops wpa_supplicant entirely rather than just disconnecting Wi-Fi.
wpa_cli -v confirmed the version and you accounted for its v2.10 command set.status and list_networks told you what was actually happening before any fix.