Add a new SSO payload configuration to an existing profile

Open in ChatGPT Open in ChatGPT to ask questions about this page
Open in Claude Open in Claude to ask questions about this page
Copy as MarkdownCopy this page as markdown to use with AI assistants
View as Markdown Open this page as markdown in a new tab

To create Ios SSO policy

Request URL

https://{server-hostname}:8383/api/v1/mdm/profiles/{profile_id}/payloads/iosssopolicy

Scope

MDMDeviceMgmt.CREATECopied!

Header

Authorization: d92d4xxxxxxxxxxxxx15f52

Request Parameters

- Request Headers

Content-TypestringMandatory
application/jsonapplication/jsonCopied!
AcceptstringMandatory
application/jsonapplication/jsonCopied!

- Path Parameters

profile_idstringMandatory

Unique identifier of the profile. Obtain from the Create Profile or Get Profiles response

- Request Body

application/json
JSON Object
Hide Sub-Attributes
account_display_namestringMandatory

Account Display Name

account_typeintegerOptional

SSO account type. Allowed values: 0=Kerberos

auth_typeintegerOptional

SSO authentication type. Allowed values: 0=Password/Username, 1=Certificate

kerberos_prinicpal_namestringOptional

Kerberos Prinicpal Name

kerberos_realmstringMandatory

Kerberos Realm

client_cert_idlongOptional

Client identity certificate ID obtained from the Certificates API. Must be an identity certificate (is_identity = true)

allowed_appsJSON ArrayOptional

List of apps allowed for Single Sign-On

Show Sub-Attributes
JSON Object
Show Sub-Attributes
group_display_namestringOptional

Display name of the app group

identifierstringOptional

Bundle identifier of the app

url_detailsJSON ArrayOptional

List of URL prefixes that must be matched for SSO to work

Show Sub-Attributes
JSON Object
Show Sub-Attributes
urlstringOptional

URL or domain string

Sample Request

Curl
Java
Python
Deluge
PowerShell
Copied!
curl --request POST \
  --url https://appdomain/api/v1/mdm/profiles/{profile_id}/payloads/iosssopolicy \
  --header 'Accept: application/json' \
  --header 'Authorization:  d92d4xxxxxxxxxxxxx15f52' \
  --header 'Content-Type: application/json' \
  --data '{"client_cert_id":-1,"account_type":1,"auth_type":1,"url_details":["https://zylker.com/auth"],"account_display_name":"Zylker User","allowed_apps":[{"group_display_name":"Zylker App","identifier":"com.zylker.app"}],"kerberos_realm":"value","kerberos_prinicpal_name":"Zylker User"}'

Sample Request Body

Add SSO payload to the profile

Copied!
  {
    "client_cert_id": -1,
    "account_type": 1,
    "auth_type": 1,
    "url_details": [
      "https://zylker.com/auth"
    ],
    "account_display_name": "Zylker User",
    "allowed_apps": [
      {
        "group_display_name": "Zylker App",
        "identifier": "com.zylker.app"
      }
    ],
    "kerberos_realm": "value",
    "kerberos_prinicpal_name": "Zylker User"
  }
                
Show full

Response Parameters

- HTTP code 200

Response Body - application/json
JSON Object
Hide Sub-Attributes
payload_idlong

Unique identifier for the created payload item

account_display_namestring

Account Display Name

account_typeinteger

SSO account type. Allowed values: 0=Kerberos

auth_typeinteger

SSO authentication type. Allowed values: 0=Password/Username, 1=Certificate

kerberos_prinicpal_namestring

Kerberos Prinicpal Name

kerberos_realmstring

Kerberos Realm

client_cert_idlong

Client identity certificate ID obtained from the Certificates API. Must be an identity certificate (is_identity = true)

allowed_appsJSON Array

List of apps allowed for Single Sign-On

Show Sub-Attributes
JSON Object
Show Sub-Attributes
group_display_namestring

Display name of the app group

identifierstring

Bundle identifier of the app

url_detailsJSON Array

List of URL prefixes that must be matched for SSO to work

Show Sub-Attributes
JSON Object
Show Sub-Attributes
urlstring

URL or domain string

Possible Response Codes

200HTTP code

Sample Response: HTTP 200

SSO payload successfully added

Copied!
  {
    "client_cert_id": -1,
    "payload_id": 9007199254741000,
    "account_type": 1,
    "auth_type": 1,
    "url_details": [
      "https://zylker.com/auth"
    ],
    "account_display_name": "Zylker User",
    "allowed_apps": [
      {
        "group_display_name": "Zylker App",
        "identifier": "com.zylker.app"
      }
    ],
    "kerberos_realm": "value",
    "kerberos_prinicpal_name": "Zylker User"
  }
                
Show full

Duration: 1 minute | Threshold: 30 | Lock period: 5 minutes

Duration - Time window for the threshold.
Threshold - Number of API calls allowed within the specified duration.
Lock Period - Wait time before consecutive API requests.