# Add a new App Lock payload configuration to an existing profile To create App Lock policy ## Endpoints **POST** `/api/v1/mdm/profiles/{profile_id}/payloads/applockpolicy` ## Request URL `https://{serverurl}/api/v1/mdm/profiles/{profile_id}/payloads/applockpolicy` ## Scope `MDMOnDemand.MDMDeviceMgmt.CREATE` ## Header ``` Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52 ``` ## Request Parameters ### Path Parameters - **profile_id** (string, Mandatory) Unique identifier of the profile. Obtain from the [Create Profile](https://www.manageengine.com/mobile-device-management/help/api/cloud/profiles-create-profile.html) or [Get Profiles](https://www.manageengine.com/mobile-device-management/help/api/cloud/profiles-get-profile.html) response ### Query Parameters - **t** (long, Optional) - **ignoreHeader** (boolean, Optional) - **qlt** (long, Optional) - **previousTab** (string, Optional) - **service** (string, Optional) - **search** (string, Optional) Free-text search string applied to the default searchable fields of the resource - **all** (boolean, Optional) - **dc_customerid** (long, Optional) - **mdm_instance** (string, Optional) - **signupsrc** (string, Optional) - **zaaid** (string, Optional) - **command** (string, Optional) - **orderby** (string, Optional) - **sortorder** (string, Optional) - **select_all** (boolean, Optional) When true, applies the operation to every record matching the current filter rather than to specific IDs. Default: false - **zoho-internal** (boolean, Optional) - **dc_instance** (string, Optional) - **SUBREQUEST** (string, Optional) - **source** (string, Optional) - **nocache** (long, Optional) Param to avoid being served from cache - **wms_csrparam** (string, Optional) CSRF Token ### Request Body `application/json` - **idle_refresh_timeout** (integer, Optional) Idle refresh timeout for web app kiosk in seconds. -1 means disabled. Default: -1 - **clear_session_and_cookies** (boolean, Optional) Clear Session And Cookies. Default: true - **webclippolicies** (JSON array, Optional) List of web clips configured for kiosk mode - **webclip_policy_id** (long, Optional) Web clip policy ID - **webclip_name** (string, Optional) Display name of the web clip - **auto_distribute_webapp** (boolean, Optional) Auto Distribute Webapp. Default: true - **app_name** (string, Optional) App Name - **identifier** (string, Optional) Identifier - **disable_touch** (boolean, Optional) Disable Touch. Default: false - **disable_device_rotation** (boolean, Optional) Disable Device Rotation. Default: false - **disable_volume_buttons** (boolean, Optional) Disable Volume Buttons. Default: false - **disable_ringer_switch** (boolean, Optional) Disable Ringer Switch. Default: false - **disable_sleep_button** (boolean, Optional) Disable Sleep Button. Default: false - **disable_auto_lock** (boolean, Optional) Disable Auto Lock. Default: true - **voice_over** (boolean, Optional) Voice Over. Default: false - **zoom** (boolean, Optional) Zoom. Default: false - **invert_colors** (boolean, Optional) Invert Colors. Default: false - **asst_touch** (boolean, Optional) Asst Touch. Default: false - **enable_speak_selection** (boolean, Optional) Enable Speak Selection. Default: false - **enable_mono_audio** (boolean, Optional) Enable Mono Audio. Default: false - **enable_voice_control** (boolean, Optional) Enable Voice Control. Default: false - **show_me_mdm_app** (boolean, Optional) Show Me Mdm App. Default: true - **kiosk_mode** (integer, Mandatory) Kiosk mode type. Allowed values: 1 = Single App Kiosk 2 = Multi App Kiosk 3 = Single Web App Kiosk - **allowed_apps** (JSON array, Optional) List of allowed kiosk apps - **app_id** (long, Optional) App ID of the kiosk app. Use the app_group_id from the [Apps API](https://www.manageengine.com/mobile-device-management/help/api/cloud/app-management-get-an-app.html) response - **group_display_name** (string, Optional) Display name of the app group - **autonomous_kiosk_apps** (JSON array, Optional) List of autonomous single app mode apps - **app_id** (long, Optional) App ID of the kiosk app. Use the app_group_id from the [Apps API](https://www.manageengine.com/mobile-device-management/help/api/cloud/app-management-get-an-app.html) response - **group_display_name** (string, Optional) Display name of the app group - **auto_distribute_apps** (boolean, Optional) Auto Distribute Apps. Default: false ## Sample Request ### Curl ```bash curl --request POST \ --url https://appdomain/api/v1/mdm/profiles/{profile_id}/payloads/applockpolicy \ --header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52' \ --header 'content-type: application/json' \ --data '{"kiosk_mode":1}' ``` ### Java ```java import java.net.URI; import java.net.http.HttpClient; import java.net.http.HttpRequest; import java.net.http.HttpResponse; import java.io.IOException; import java.net.http.HttpTimeoutException; public class Main { public static void main(String[] args) { HttpRequest request = HttpRequest.newBuilder() .uri(URI.create("https://appdomain/api/v1/mdm/profiles/{profile_id}/payloads/applockpolicy")) .header("content-type", "application/json") .header("Authorization", "Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52") .method("POST", HttpRequest.BodyPublishers.ofString("{\"kiosk_mode\":1}")) .build(); HttpResponse response = HttpClient.newHttpClient().send(request, HttpResponse.BodyHandlers.ofString()); System.out.println(response.body()); } } ``` ### Python ```python import http.client conn = http.client.HTTPSConnection("appdomain") payload = "{\"kiosk_mode\":1}" headers = { 'content-type': "application/json", 'Authorization': "Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52" } conn.request("POST", "/api/v1/mdm/profiles/{profile_id}/payloads/applockpolicy", payload, headers) res = conn.getresponse() data = res.read() print(data.decode("utf-8")) ``` ### Deluge ```javascript headersMap = Map(); headersMap.put("Content-Type", "application/json"); headersMap.put("Accept", "application/json"); data=Map(); data.put("kiosk_mode","1"); response = invokeUrl [ url: "https://appDomain/api/v1/mdm/profiles/{profile_id}/payloads/applockpolicy" type: POST headers: headersMap body: data connection: connection_name ] info response; ``` ### PowerShell ```powershell $headers=@{} $headers.Add("content-type", "application/json") $headers.Add("Authorization", "Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52") $response = Invoke-WebRequest -Uri 'https://appdomain/api/v1/mdm/profiles/{profile_id}/payloads/applockpolicy' -Method POST -Headers $headers -ContentType 'application/json' -Body '{"kiosk_mode":1}' ``` ## Sample Request Body Add App Lock payload to the profile ```json { "app_name": "Zylker User", "identifier": "value", "disable_volume_buttons": false, "disable_ringer_switch": false, "idle_refresh_timeout": -1, "webclippolicies": [ { "webclip_policy_id": 9007199254741076, "webclip_name": "Zylker Web Clip" } ], "clear_session_and_cookies": true, "disable_touch": false, "disable_device_rotation": false, "kiosk_mode": 1, "auto_distribute_webapp": true } ``` ## Response Parameters ### HTTP 200 Response Body: `application/json` - **payload_id** (long) Unique identifier for the created payload item - **idle_refresh_timeout** (integer) Idle refresh timeout for web app kiosk in seconds. -1 means disabled. Default: -1 - **clear_session_and_cookies** (boolean) Clear Session And Cookies. Default: true - **webclippolicies** (JSON array) List of web clips configured for kiosk mode - **webclip_policy_id** (long) Web clip policy ID - **webclip_name** (string) Display name of the web clip - **auto_distribute_webapp** (boolean) Auto Distribute Webapp. Default: true - **app_name** (string) App Name - **identifier** (string) Identifier - **disable_touch** (boolean) Disable Touch. Default: false - **disable_device_rotation** (boolean) Disable Device Rotation. Default: false - **disable_volume_buttons** (boolean) Disable Volume Buttons. Default: false - **disable_ringer_switch** (boolean) Disable Ringer Switch. Default: false - **disable_sleep_button** (boolean) Disable Sleep Button. Default: false - **disable_auto_lock** (boolean) Disable Auto Lock. Default: true - **voice_over** (boolean) Voice Over. Default: false - **zoom** (boolean) Zoom. Default: false - **invert_colors** (boolean) Invert Colors. Default: false - **asst_touch** (boolean) Asst Touch. Default: false - **enable_speak_selection** (boolean) Enable Speak Selection. Default: false - **enable_mono_audio** (boolean) Enable Mono Audio. Default: false - **enable_voice_control** (boolean) Enable Voice Control. Default: false - **show_me_mdm_app** (boolean) Show Me Mdm App. Default: true - **kiosk_mode** (integer) Kiosk mode type. Allowed values: 1 = Single App Kiosk 2 = Multi App Kiosk 3 = Single Web App Kiosk - **allowed_apps** (JSON array) List of allowed kiosk apps - **app_id** (long) App ID of the kiosk app. Use the app_group_id from the [Apps API](https://www.manageengine.com/mobile-device-management/help/api/cloud/app-management-get-an-app.html) response - **group_display_name** (string) Display name of the app group - **autonomous_kiosk_apps** (JSON array) List of autonomous single app mode apps - **app_id** (long) App ID of the kiosk app. Use the app_group_id from the [Apps API](https://www.manageengine.com/mobile-device-management/help/api/cloud/app-management-get-an-app.html) response - **group_display_name** (string) Display name of the app group - **auto_distribute_apps** (boolean) Auto Distribute Apps. Default: false ## Possible Response Codes - **200** – HTTP code ## Sample Response: HTTP 200 App Lock payload successfully added ```json { "app_name": "Zylker User", "identifier": "value", "payload_id": 9007199254741000, "disable_volume_buttons": false, "disable_ringer_switch": false, "idle_refresh_timeout": -1, "webclippolicies": [ { "webclip_policy_id": 9007199254741076, "webclip_name": "Zylker Web Clip" } ], "clear_session_and_cookies": true, "disable_touch": false, "disable_device_rotation": false, "kiosk_mode": 1, "auto_distribute_webapp": true } ``` **Duration:** 1 minute **Threshold:** 30 **Lock period:** 5 minutes Duration - Time window for the threshold. Threshold - Number of API calls allowed within the specified duration. Lock Period - Wait time before consecutive API requests.