Publishes an extension profile, making it available for distribution to devices. Cannot publish an already-published profile.
https://{server-hostname}:8383/bsp/api/v1/bmp/extensions/{extension_id}/publish
BrowserManager.CREATECopied!
Authorization: d92d4xxxxxxxxxxxxx15f52
Extension Profile ID from List Extensions response (extension_id field)
curl --request POST \
--url https://appdomain/bsp/api/v1/bmp/extensions/{extension_id}/publish \
--header 'Accept: application/json' \
--header 'Authorization: d92d4xxxxxxxxxxxxx15f52'Unauthorized error code returned when authentication credentials are missing, expired, or invalid (authentication=required)
Authentication failure reason
Forbidden error code returned when the authenticated user does not have the required uem-roles (e.g., DataEncryption_Admin or DataEncryptionRecoveryKey_Admin)
Message indicating insufficient privileges to access this resource
Conflict error when trying to publish an already-published extension profile
Error message indicating the profile is already published
Rate limit error code returned when the API call threshold (configured via threshold/duration in security XML) is exceeded; client is locked out for lock-period minutes
Rate limit exceeded message with retry guidance
Internal server error during extension operations
Error message describing the server failure
Error code for internal server errors
Returns 204 No content on success
204 Returns 204 No content on successUnauthorized
{
"errorCode": "UNAUTHORIZED",
"errorMsg": "You are not authorized to perform this action"
}
Forbidden
{
"errorCode": "FORBIDDEN",
"errorMsg": "You do not have permission to access this resource"
}
Already published
{
"errormsg": "Profile already published."
}
Rate limit exceeded
{
"errorCode": "RATE_LIMIT_EXCEEDED",
"errorMsg": "You have exceeded the maximum number of API calls. Please try again later."
}
Server error
{
"error_description": "Internal Server error, Please try again in a moment.",
"error_code": "COM0004"
}
![]()
Duration: 1 minute | Threshold: 60 | Lock period: 5 minutes
Duration - Time window for the threshold.
Threshold - Number of API calls allowed within the specified duration.
Lock Period - Wait time before consecutive API requests.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.