# Create a new add-on management profile Creates a new add-on management profile (Chrome, Firefox, Edge, IE, Ulaa, or other Chromium) with optional browser-specific payload configurations. ## Endpoint `POST /bsp/api/v1/bmp/manage_addons` ## Request URL `https://[{serverurl}](https://www.manageengine.com/products/desktop-central/help/api/cloud/oauth-authentication-endpoint-domain.html)/bsp/api/v1/bmp/manage_addons` ## Scope `DesktopCentralCloud.BrowserManager.CREATE` ## Header `Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52` ## Request Parameters ### Request Headers - **Content-Type** (`string`, Mandatory): `application/json` - **Accept** (`string`, Mandatory): `application/json` ### Request Body JSON body with profile metadata including name, description, payload configurations, and platform type. `application/json` - **JSON Object** - **manage_addOn_name** (`string`, Optional): Profile name (max 500 characters) - **manage_addon_description** (`string`, Optional): Profile description (optional, max 500 characters) - **addon_payloads** (`JSON Object`, Optional): Browser-specific add-on policy configuration. Schema branches by browser_type see addonPayloadChromeBody / addonPayloadFirefoxBody / addonPayloadEdgeBody / addonPayloadUlaaBody / addonPayloadChromiumBody / addonPayloadIEBody - **platform_type** (`string`, Optional): Platform type. 1=Windows, 2=Mac, -1=All platforms ## Sample Request ```curl curl --request POST \ --url https://appdomains/bsp/api/v1/bmp/manage_addons \ --header 'Accept: application/json' \ --header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52' \ --header 'Content-Type: application/json' \ --data '{}' ``` ## Sample Request Body ### Create profile with a Chrome payload ```json { "platform_type": "-1", "manage_addon_description": "", "manage_addOn_name": "AddonPolicy 8", "addon_payloads": { "manage_chrome_addons": { "restrict_permissions": 1, "restrict_domains": -1, "pinned_addons": [ "30" ], "permissions": [ "10" ], "browser_type": 1, "policies": { "disable_user_extensions": "-1" }, "add_ons": [ { "binary_id": "30" } ], "restrict_addons": "1", "native_hosts": { "native_permission": "-1", "native_ids": [] } } } } ``` ### Create empty profile (add payloads later) ```json { "platform_type": "1", "manage_addon_description": "Standard add-on management policy", "manage_addOn_name": "Corporate Add-On Policy", "addon_payloads": {} } ``` ## Response Parameters ### HTTP Code 200 Response Body — `application/json` - **JSON Object** - **collection_id** (`string`): Collection reference ID for the profile - **profile_type** (`string`): Profile type identifier - **platform_type** (`string`): Platform type. 1=Windows, 2=Mac, -1=All platforms - **latest_version** (`string`): Latest version number of the profile - **is_moved_to_trash** (`boolean`): Whether the profile is in the trash - **manage_addon_name** (`string`): Profile display name - **scope** (`string`): Profile scope. 0=device, 1=user - **latest_published_version** (`string`): Latest published version, or `'--'` if not yet published - **manage_addon_description** (`string`): Profile description - **manage_addon_id** (`string`): Unique profile identifier - **addon_payloads** (`JSON Array`): Payload configurations associated with this profile ### HTTP Code 400 Response Body — `application/json` - **JSON Object** - **errormsg** (`string`): Message describing why the request is invalid ### HTTP Code 401 Response Body — `application/json` - **JSON Object** - **errorCode** (`long`): Unauthorized error code: credentials missing, expired, or invalid - **errorMsg** (`string`): Authentication failure reason ### HTTP Code 403 Response Body — `application/json` - **JSON Object** - **errorCode** (`long`): Error code indicating insufficient permissions - **errorMsg** (`string`): Message indicating insufficient privileges to access this resource ### HTTP Code 429 Response Body — `application/json` - **JSON Object** - **errorCode** (`long`): Rate limit error code returned when the API call reached threshold - **errorMsg** (`string`): Rate limit exceeded message with retry guidance ### HTTP Code 500 Response Body — `application/json` - **JSON Object** - **errormsg** (`string`): Message describing the internal server error ## Possible Response Codes - `200` HTTP code - `400` HTTP code - `401` HTTP code - `403` HTTP code - `429` HTTP code - `500` HTTP code ## Sample Response: HTTP 200 Created profile in Draft status ```json { "collection_id": "222", "profile_type": "64025", "platform_type": "1", "latest_version": "1", "is_moved_to_trash": false, "manage_addon_name": "TestAddon_CreateEmpty", "scope": "0", "latest_published_version": "--", "manage_addon_description": "Test empty profile", "manage_addon_id": "993", "addon_payloads": [] } ``` ## Sample Response: HTTP 400 Invalid request ```json { "errormsg": "Invalid request" } ``` ## Sample Response: HTTP 401 Unauthorized ```json { "errorCode": "UNAUTHORIZED", "errorMsg": "You are not authorized to perform this action" } ``` ## Sample Response: HTTP 403 Insufficient permissions ```json { "errorCode": "FORBIDDEN", "errorMsg": "User does not have permission to perform this operation" } ``` ## Sample Response: HTTP 429 Rate limit exceeded ```json { "errorCode": "RATE_LIMIT_EXCEEDED", "errorMsg": "Too many requests. Please try again after 5 minutes" } ``` ## Sample Response: HTTP 500 Server error ```json { "errormsg": "Internal Server error, Please try again in a moment." } ``` ![](https://www.zohowebstatic.com/sites/zweb/images/people/ico-help.png) **Duration:** 1 minute | **Threshold:** 60 | **Lock period:** 5 minutes Duration - Time window for the threshold. Threshold - Number of API calls allowed within the specified duration. Lock Period - Wait time before consecutive API requests.