# Create a configuration profile Creates a new configuration profile in Draft state. Payloads can be added before publishing. ## Endpoint `POST /bsp/api/v1/bmp/profiles` ## Request URL `https://{serverurl}/bsp/api/v1/bmp/profiles` ## Scope `DesktopCentralCloud.BrowserManager.CREATE` ## Header `Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52` ## Request Parameters ### Request Headers | Header | Type | Required | Value | |---|---|---|---| | Content-Type | string | Mandatory | application/json | | Accept | string | Mandatory | application/json | ### Request Body JSON body with profile metadata. Use the dropdown to switch between the 8 supported profile-type examples. `application/json` ## Examples ### Browser Customization (64100) Container for browser customization payloads (Chrome, Edge, IE, Firefox, Ulaa, Other Chromium). Windows, Mac. #### Sample Request ```bash curl --request POST \ --url https://appdomains/bsp/api/v1/bmp/profiles \ --header 'Accept: application/json' \ --header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52' \ --header 'Content-Type: application/json' \ --data '{}' ``` #### Sample Request Body - Browser Customization (64100) Browser Customization (64100) - container for browser customization payloads. Add browser-specific payloads (Chrome / Edge / Firefox / IE / Ulaa / Other Chromium) via POST /profiles/{profile_id}/payloads after creation. Windows + Mac supported via platform_type='-1'. ```json { "profile_name": "Browser Configuration Baseline", "SECURITY_TYPE": 1, "profile_type": 64100, "platform_type": "1", "SCOPE": 0, "profile_id": -1, "CLONE_FROM": -1, "profile_description": "Container for Chrome/Edge/Firefox customization payloads" } ``` ## Response Parameters ### HTTP code 200 Response Body - `application/json` Full configuration profile details including metadata, version info, and associated payloads. | Attribute | Type | Description | |---|---|---| | profile_id | string | Profile ID | | profile_name | string | Display name | | profile_description | string | Description | | profile_type | string | Profile type code. 64100=Browser Customization, 64005=File Activity, 64011=Browser Router, 64050=Web Isolation, 64200=Threat Prevention, 64201=Data Leakage Prevention, 64210=Browser Lockdown, 64500=Compliance, 64510=Default Extension, 64950=URL Filter, 64960=Managed Browser | | scope | string | '0'=Device, '1'=User | | is_moved_to_trash | boolean | In trash | | collection_id | string | Collection reference ID | | platform_type | string | '1'=Windows, '2'=Mac, '-1'=All platforms (Windows + Mac) | | latest_version | string | Latest version (increments on modify) | | latest_published_version | string | Latest published version, or '--' if never published | | payloads | JSON Array | Associated payload configurations | ### HTTP code 400 Response Body - `application/json` Bad request error for invalid input or constraint violations. | Attribute | Type | Description | |---|---|---| | errorcode | string | Error code identifying the specific validation failure | | errormsg | string | Message describing the validation failure | ### HTTP code 401 Response Body - `application/json` | Attribute | Type | Description | |---|---|---| | errorCode | long | Unauthorized error code: credentials missing, expired, or invalid | | errorMsg | string | Authentication failure reason | ### HTTP code 403 Response Body - `application/json` | Attribute | Type | Description | |---|---|---| | errorCode | long | Error code indicating insufficient permissions | | errorMsg | string | Message indicating insufficient privileges to access this resource | ### HTTP code 429 Response Body - `application/json` | Attribute | Type | Description | |---|---|---| | errorCode | long | Rate limit error code returned when the API call reached threshold | | errorMsg | string | Rate limit exceeded message with retry guidance | ### HTTP code 500 Response Body - `application/json` Internal server error response for profile operations. | Attribute | Type | Description | |---|---|---| | error_description | string | Error message describing the server failure | | error_code | string | Error code for internal server errors | ## Possible Response Codes - `200` - `400` - `401` - `403` - `429` - `500` ## Response Examples ### Sample Response: HTTP 200 - Browser Customization (64100) Newly created Browser Customization profile (64100). ```json { "collection_id": "222", "profile_name": "Browser Configuration Baseline", "profile_type": "64100", "platform_type": "1", "latest_version": "1", "is_moved_to_trash": false, "payloads": [], "profile_id": "111", "scope": "0", "latest_published_version": "--", "profile_description": "Container for Chrome/Edge/Firefox customization payloads" } ``` ### Sample Response: HTTP 400 Invalid profile creation parameters. ```json { "errorcode": "IAM0003", "errormsg": "Invalid request." } ``` ### Sample Response: HTTP 401 API key is missing or invalid. ```json { "errorCode": "IAM0001", "errorMsg": "Authentication key is invalid. Please regenerate the key and try again." } ``` ### Sample Response: HTTP 403 Forbidden. ```json { "errorCode": "FORBIDDEN", "errorMsg": "User does not have permission to perform this operation" } ``` ### Sample Response: HTTP 429 Rate limit exceeded. ```json { "errorCode": "RATE_LIMIT_EXCEEDED", "errorMsg": "Too many requests. Please try again after 5 minutes" } ``` ### Sample Response: HTTP 500 Server error. ```json { "error_description": "Internal Server error, Please try again in a moment.", "error_code": "COM0004" } ``` ## Rate Limits ![](https://www.zohowebstatic.com/sites/zweb/images/people/ico-help.png) **Duration:** 1 minute | **Threshold:** 60 | **Lock period:** 5 minutes Duration - Time window for the threshold. Threshold - Number of API calls allowed within the specified duration. Lock Period - Wait time before consecutive API requests.