# Add a new Extensible SSO payload configuration to an existing profile To create Ios Extensible SSO policy ## Endpoint `POST /api/v1/mdm/profiles/{profile_id}/payloads/iosextensiblessopolicy` ## Request URL `https://{server-hostname}:8383/api/v1/mdm/profiles/{profile_id}/payloads/iosextensiblessopolicy` ## Scope `MDMDeviceMgmt.CREATE` ## Header `Authorization: d92d4xxxxxxxxxxxxx15f52` ## Request Parameters ### Request Headers - **Content-Type** (`string`, Mandatory): `application/json` - **Accept** (`string`, Mandatory): `application/json` ### Path Parameters - **profile_id** (`string`, Mandatory): Unique identifier of the profile. Obtain from the [Create Profile](https://www.manageengine.com/products/desktop-central/help/api/onpremise/mdm-profiles-create-profile.html) or [Get Profiles](https://www.manageengine.com/products/desktop-central/help/api/onpremise/mdm-profiles-get-profile.html) response. ### Request Body `application/json` **JSON Object** - **extension_identifier** (`string`, Mandatory): Extension Identifier - **team_identifier** (`string`, Mandatory): Team Identifier - **screen_locked_behavior** (`integer`, Mandatory): Screen Locked Behavior - **type** (`integer`, Mandatory): Type - **extension_data** (`string`, Mandatory): Extension Data - **realm** (`string`, Mandatory): Realm - **hosts_and_urls** (`array`, Mandatory): List of URL strings for the identity provider hosts - **denied_apps_details** (`JSON Array`, Mandatory): List of denied apps excluded from Extensible SSO ## Sample Request ```curl curl --request POST \ --url https://appdomain/api/v1/mdm/profiles/{profile_id}/payloads/iosextensiblessopolicy \ --header 'Accept: application/json' \ --header 'Authorization: d92d4xxxxxxxxxxxxx15f52' \ --header 'Content-Type: application/json' \ --data '{"hosts_and_urls":["https://zylker.com"],"extension_identifier":"value","screen_locked_behavior":1,"extension_data":"value","team_identifier":"value","realm":"value","type":1,"denied_apps_details":[{"app_group_id":9007199254741072}]}' ``` ## Sample Request Body Add Extensible SSO payload to the profile ```json { "hosts_and_urls": [ "https://zylker.com" ], "extension_identifier": "value", "screen_locked_behavior": 1, "extension_data": "value", "team_identifier": "value", "realm": "value", "type": 1, "denied_apps_details": [ { "app_group_id": 9007199254741072 } ] } ``` ## Response Parameters ### HTTP Code 200 Response Body — `application/json` **JSON Object** - **payload_id** (`long`): Unique identifier for the created payload item - **extension_identifier** (`string`): Extension Identifier - **team_identifier** (`string`): Team Identifier - **screen_locked_behavior** (`integer`): Screen Locked Behavior - **type** (`integer`): Type - **extension_data** (`string`): Extension Data - **realm** (`string`): Realm - **hosts_and_urls** (`array`): List of URL strings for the identity provider hosts - **denied_apps_details** (`JSON Array`): List of denied apps excluded from Extensible SSO ## Possible Response Codes - **200**: HTTP code ## Sample Response: HTTP 200 Extensible SSO payload successfully added ```json { "hosts_and_urls": [ "https://zylker.com" ], "extension_identifier": "value", "payload_id": 9007199254741000, "screen_locked_behavior": 1, "extension_data": "value", "team_identifier": "value", "realm": "value", "type": 1, "denied_apps_details": [ { "app_group_id": 9007199254741072 } ] } ``` ## API Rate Limit ![](https://www.zohowebstatic.com/sites/zweb/images/people/ico-help.png) **Duration:** 1 minute | **Threshold:** 30 | **Lock period:** 5 minutes Duration - Time window for the threshold. Threshold - Number of API calls allowed within the specified duration. Lock Period - Wait time before consecutive API requests.