Replaces URL rules, group rules, and block message in a JRM payload. Published profiles cannot be updated.
https://{serverurl}/bsp/api/v1/bmp/jrm/{jrm_profile_id}/jrm_payloads/{jrm_payload_id}
Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52
JRM Payload ID from Get JRM Profile response (config_data_item_id field)
JRM Profile ID from List JRM Profiles response (jrm_profile_id field)
Complete replacement of all payload rules. Include ONLY 'urls' OR 'groups' (not both). Any existing rules will be fully replaced. Do not send empty arrays for urls or groups omit the key entirely if not used. The 'block_message' field is only available when action=0 (Block).
curl --request PUT \
--url https://appdomains/bsp/api/v1/bmp/jrm/{jrm_profile_id}/jrm_payloads/{jrm_payload_id} \
--header 'Accept: application/json' \
--header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52' \
--header 'Content-Type: application/json' \
--data '{}'Replace with URL allow rule
{
"jrm_payloads": {
"urls": [
{
"java_version": "1.8.0_01",
"action": 1,
"webdomain_ids": [
"3"
]
}
]
}
}
Replace with URL block rule
{
"jrm_payloads": {
"urls": [
{
"action": 0,
"webdomain_ids": [
"3"
]
}
],
"block_message": "Blocked by policy"
}
}
curl --request PUT \
--url https://appdomains/bsp/api/v1/bmp/jrm/{jrm_profile_id}/jrm_payloads/{jrm_payload_id} \
--header 'Accept: application/json' \
--header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52' \
--header 'Content-Type: application/json' \
--data '{}'Switch to group rules
{
"jrm_payloads": {
"groups": [
{
"ids": [
"28"
],
"action": 0
}
],
"block_message": "Groups only test"
}
}
Response after modifying an existing payload
The updated payload reflecting your changes
Payload details returned after create or modify
Always '64101' identifies this as a Java Rules Manager payload
Custom message shown to users when Java is blocked (only applies when action=0). Empty string if not set
The rule sets with URL/group rules. Use 'config_data_item_id' from here as {jrm_payload_id} for future Modify/Delete calls
Individual rule set with URL and group rules
Unique ID for this rule set use as {jrm_payload_id} in Modify Payload (PUT) API
URL-based rules each entry controls Java behavior for a specific website
Java rule for a specific website URL
Webdomain ID (references a site configured in Browser Security > Web Domain Management)
The website URL/domain name (read-only, set when the webdomain was created)
What to do with Java on this site: '0' = Block Java entirely, '1' = Allow Java to run, '2' = Use browser's default Java setting
When action is '1' (Allow), specifies the required Java version (e.g., '1.7.0_04'). Leave empty to allow any installed version
Group-based rules each entry controls Java behavior for a group of websites
Java rule for a webdomain group
Webdomain group ID (references a group configured in Browser Security > Web Domain Management)
Name of the webdomain group (read-only, set when the group was created)
What to do with Java for all sites in this group: '0' = Block Java, '1' = Allow Java, '2' = Use browser default
When action is '1' (Allow), specifies the required Java version. Leave empty to allow any installed version
Whether default Rich Internet Application settings are applied
Configuration label (always 'JAVA_RULES_MANAGER')
Error identifier (e.g., 'IAM0006' for invalid field value)
Describes which field or value is invalid
Unauthorized error code: credentials missing, expired, or invalid
Authentication failure reason
Error code indicating insufficient permissions
Message indicating insufficient privileges to access this resource
Rate limit error code returned when the API call reached threshold
Rate limit exceeded message with retry guidance
Description of the server-side error
Updated payload
{
"payloads": [
{
"payload_type": "64101",
"block_message": "Blocked by policy",
"jrm_details": [
{
"config_data_item_id": "971",
"urls": [
{
"java_version": "",
"action": "0",
"id": "3",
"url": "localhost"
}
],
"groups": []
}
],
"default_rias": false,
"config_label": "JAVA_RULES_MANAGER"
}
]
}
Invalid payload
{
"errorcode": "IAM0003",
"errormsg": "Invalid request."
}
Invalid Java version
{
"errorCode": "IAM0025",
"url": "/bsp/api/v1/bmp/jrm/{jrm_profile_id}/jrm_payloads/{jrm_payload_id}",
"errorMsg": "java_version is an invalid parameter format."
}
Empty array
{
"errorCode": "IAM0022",
"url": "/bsp/api/v1/bmp/jrm/{jrm_profile_id}/jrm_payloads/{jrm_payload_id}",
"errorMsg": "Array size exceeds limit."
}
Unauthorized
{
"errorCode": "IAM0001",
"errorMsg": "Authentication key is invalid. Please regenerate the key and try again."
}
Forbidden
{
"errorCode": "FORBIDDEN",
"errorMsg": "You do not have permission to access this resource"
}
Rate limit exceeded
{
"errorCode": "RATE_LIMIT_EXCEEDED",
"errorMsg": "You have exceeded the maximum number of API calls. Please try again later."
}
Server error
{
"errormsg": "Internal Server error, Please try again in a moment."
}
![]()
Duration: 1 minute | Threshold: 60 | Lock period: 5 minutes
Duration - Time window for the threshold.
Threshold - Number of API calls allowed within the specified duration.
Lock Period - Wait time before consecutive API requests.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.