# Add a new Per-App VPN payload configuration to an existing profile To create Ios Per App Vpn policy ## Endpoints **POST** `/api/v1/mdm/profiles/{profile_id}/payloads/iosperappvpn` ## Request URL ``` https://{serverurl}/api/v1/mdm/profiles/{profile_id}/payloads/iosperappvpn ``` ## Scope ``` MDMOnDemand.MDMDeviceMgmt.CREATE ``` ## Header ``` Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52 ``` ## Request Parameters ### Path Parameters - **profile_id** (string) — **Mandatory** Unique identifier of the profile. Obtain from the [Create Profile](https://www.manageengine.com/mobile-device-management/help/api/cloud/profiles-create-profile.html) or [Get Profiles](https://www.manageengine.com/mobile-device-management/help/api/cloud/profiles-get-profile.html) response ### Query Parameters - **t** (long) — Optional - **ignoreHeader** (boolean) — Optional - **qlt** (long) — Optional - **previousTab** (string) — Optional - **service** (string) — Optional - **search** (string) — Optional Free-text search string applied to the default searchable fields of the resource - **all** (boolean) — Optional - **dc_customerid** (long) — Optional - **mdm_instance** (string) — Optional - **signupsrc** (string) — Optional - **zaaid** (string) — Optional - **command** (string) — Optional - **orderby** (string) — Optional - **sortorder** (string) — Optional - **select_all** (boolean) — Optional When true, applies the operation to every record matching the current filter rather than to specific IDs. Default: false - **zoho-internal** (boolean) — Optional - **dc_instance** (string) — Optional - **SUBREQUEST** (string) — Optional - **source** (string) — Optional - **nocache** (long) — Optional Param to avoid being served from cache - **wms_csrparam** (string) — Optional CSRF Token ### Request Body **Content-Type:** `application/json` **Type:** JSON object #### Attributes - **sub_config** (string) — Optional Sub Config. Default: L2TP - **connection_name** (string) — **Mandatory** Connection Name. Default: VPN Configuration - **connection_type** (integer) — **Mandatory** VPN connection type. Allowed values: 0=L2TP, 1=PPTP, 2=IPSec, 3=Cisco Legacy AnyConnect, 4=Juniper SSL, 5=F5 SSL, 6=Custom SSL, 7=Pulse Secure, 8=IKEv2, 9=Cisco AnyConnect, 10=SonicWall, 11=Aruba VIA, 12=CheckPoint Mobile - **send_all_nw_traffic** (boolean) — Optional Send All Nw Traffic. Default: false - **certificate_uuid** (string) — Optional Certificate Uuid - **enable_vpn_on_demand** (boolean) — Optional Enable Vpn On Demand. Default: false - **disconnect_on_idle_timeout** (integer) — Optional Disconnect on idle timeout in seconds. 0 means disabled. Default: 0 - **cisco** (JSON object) — Optional - **juniperssl** (JSON object) — Optional - **pulsesecure** (JSON object) — Optional - **f5ssl** (JSON object) — Optional - **customssl** (JSON object) — Optional - **ciscoanyconnect** (JSON object) — Optional - **sonicwall** (JSON object) — Optional - **arubavia** (JSON object) — Optional - **checkpoint** (JSON object) — Optional - **proxy_type** (integer) — Optional Proxy configuration type. Allowed values: 0=None, 1=Manual, 2=Automatic (PAC URL) - **proxy_server** (string) — Optional - **proxy_server_port** (integer) — Optional Proxy Server Port. Default: 0 - **proxy_user_name** (string) — Optional - **proxy_password** (string) — Optional Proxy Password (sensitive - write-only) - **proxy_password_id** (long) — Optional - **proxy_pac_url** (string) — Optional - **ondemand_user_override_disabled** (boolean) — Optional Ondemand User Override Disabled. Default: false - **ondemandrules** (JSON array) — Optional List of VPN On Demand rules controlling when the VPN connects/disconnects - **rule_order** (integer) — Optional Order in which the rule is evaluated - **action** (integer) — Optional Action to take. Allowed values: 0=Disconnect, 1=Connect, 2=Ignore, 3=Evaluate Connection - **type** (integer) — Optional Match type. Allowed values: 0=Always, 1=DNS Domain Match, 2=DNS Server Address Match, 3=Interface Type Match, 4=SSID Match, 5=URL String Probe - **value** (array) — Optional List of match values (domains, addresses, SSIDs, etc.) based on the match type - **vpn_type** (integer) — **Mandatory** VPN scope type. Allowed values: 1=Device-level VPN, 2=Per-App VPN - **provider_type** (integer) — Optional VPN provider type. Allowed values: 0=Packet Tunnel (default), 1=App Proxy - **vpnuuid** (string) — Optional - **safari_domains** (array) — Optional List of Safari domain strings that trigger Per-App VPN - **excluded_domains** (array) — Optional List of domain strings excluded from Per-App VPN - **smb_domains** (array) — Optional List of SMB domain strings that trigger Per-App VPN - **allowed_apps** (JSON array) — Optional List of apps allowed to use this Per-App VPN - **app_id** (long) — Optional App ID of the VPN app. Use the app_group_id from the [Apps API](https://www.manageengine.com/mobile-device-management/help/api/cloud/app-management-get-an-app.html) response - **is_system_app** (boolean) — Optional Whether this is a system app. Default: false - **group_display_name** (string) — Optional Display name of the app group - **autonomous_kiosk_apps** (JSON array) — Optional List of autonomous single app mode apps - **app_id** (long) — Optional App ID of the kiosk app. Use the app_group_id from the [Apps API](https://www.manageengine.com/mobile-device-management/help/api/cloud/app-management-get-an-app.html) response - **group_display_name** (string) — Optional Display name of the app group - **ondemand_match_app_enabled** (boolean) — Optional Ondemand Match App Enabled. Default: true - **custom_data** (JSON array) — Optional List of custom key-value pairs for vendor-specific VPN configuration - **custom_key** (string) — Optional Custom configuration key name - **custom_value** (string) — Optional Custom configuration key value - **ipsec** (JSON object) — Optional - **ikev2** (JSON object) — Optional ## Sample Request ### Curl ```bash curl --request POST \ --url https://appdomain/api/v1/mdm/profiles/{profile_id}/payloads/iosperappvpn \ --header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52' \ --header 'content-type: application/json' \ --data '{"connection_name":"VPN Configuration","connection_type":0,"vpn_type":1}' ``` ### Java ```java import java.net.URI; import java.net.http.HttpClient; import java.net.http.HttpRequest; import java.net.http.HttpResponse; public class Main { public static void main(String[] args) throws Exception { HttpRequest request = HttpRequest.newBuilder() .uri(URI.create("https://appdomain/api/v1/mdm/profiles/{profile_id}/payloads/iosperappvpn")) .header("content-type", "application/json") .header("Authorization", "Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52") .method("POST", HttpRequest.BodyPublishers.ofString("{\"connection_name\":\"VPN Configuration\",\"connection_type\":0,\"vpn_type\":1}")) .build(); HttpResponse response = HttpClient.newHttpClient() .send(request, HttpResponse.BodyHandlers.ofString()); System.out.println(response.body()); } } ``` ### Python ```python import http.client conn = http.client.HTTPSConnection("appdomain") payload = "{\"connection_name\":\"VPN Configuration\",\"connection_type\":0,\"vpn_type\":1}" headers = { 'content-type': "application/json", 'Authorization': "Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52" } conn.request("POST", "/api/v1/mdm/profiles/{profile_id}/payloads/iosperappvpn", payload, headers) res = conn.getresponse() data = res.read() print(data.decode("utf-8")) ``` ### Deluge ```javascript headersMap = Map(); headersMap.put("Content-Type", "application/json"); headersMap.put("Accept", "application/json"); data = Map(); data.put("connection_name","value"); data.put("connection_type","1"); data.put("vpn_type","1"); response = invokeUrl [ url: "https://appDomain/api/v1/mdm/profiles/{profile_id}/payloads/iosperappvpn" type: POST headers: headersMap body: data connection: connection_name ] info response; ``` ### PowerShell ```powershell $headers=@{} $headers.Add("content-type", "application/json") $headers.Add("Authorization", "Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52") $response = Invoke-WebRequest -Uri 'https://appdomain/api/v1/mdm/profiles/{profile_id}/payloads/iosperappvpn' -Method POST -Headers $headers -ContentType 'application/json' -Body '{"connection_name":"VPN Configuration","connection_type":0,"vpn_type":1}' ``` ## Sample Request Body ```json { "connection_name": "VPN Configuration", "send_all_nw_traffic": false, "connection_type": 0, "pulsesecure": {}, "sub_config": "L2TP", "juniperssl": {}, "enable_vpn_on_demand": false, "certificate_uuid": "value", "disconnect_on_idle_timeout": 0, "cisco": {}, "vpn_type": 1 } ``` ## Response Parameters ### HTTP 200 **Content-Type:** `application/json` **Type:** JSON object #### Attributes - **payload_id** (long) Unique identifier for the created payload item - **sub_config** (string) - **connection_name** (string) - **connection_type** (integer) - **send_all_nw_traffic** (boolean) - **certificate_uuid** (string) - **enable_vpn_on_demand** (boolean) - **disconnect_on_idle_timeout** (integer) - **cisco** (JSON object) - **juniperssl** (JSON object) - **pulsesecure** (JSON object) - **f5ssl** (JSON object) - **customssl** (JSON object) - **ciscoanyconnect** (JSON object) - **sonicwall** (JSON object) - **arubavia** (JSON object) - **checkpoint** (JSON object) - **proxy_type** (integer) - **proxy_server** (string) - **proxy_server_port** (integer) - **proxy_user_name** (string) - **proxy_password** (string) - **proxy_password_id** (long) - **proxy_pac_url** (string) - **ondemand_user_override_disabled** (boolean) - **ondemandrules** (JSON array) - **rule_order** (integer) - **action** (integer) - **type** (integer) - **value** (array) - **vpn_type** (integer) - **provider_type** (integer) - **vpnuuid** (string) - **safari_domains** (array) - **excluded_domains** (array) - **smb_domains** (array) - **allowed_apps** (JSON array) - **app_id** (long) - **is_system_app** (boolean) - **group_display_name** (string) - **autonomous_kiosk_apps** (JSON array) - **app_id** (long) - **group_display_name** (string) - **ondemand_match_app_enabled** (boolean) - **custom_data** (JSON array) - **custom_key** (string) - **custom_value** (string) - **ipsec** (JSON object) - **ikev2** (JSON object) ## Sample Response (HTTP 200) ```json { "connection_name": "VPN Configuration", "send_all_nw_traffic": false, "payload_id": 9007199254741000, "connection_type": 0, "pulsesecure": {}, "sub_config": "L2TP", "juniperssl": {}, "enable_vpn_on_demand": false, "certificate_uuid": "value", "disconnect_on_idle_timeout": 0, "cisco": {}, "vpn_type": 1 } ``` ## Possible Response Codes - **200** — HTTP code ## API Rate Limits **Duration:** 1 minute **Threshold:** 30 **Lock period:** 5 minutes - **Duration** — Time window for the threshold. - **Threshold** — Number of API calls allowed within the specified duration. - **Lock period** — Wait time before consecutive API requests.