# Add a new Certificate payload configuration to an existing profile To create Mac Certificate policy ## Endpoint **POST** `/api/v1/mdm/profiles/{profile_id}/payloads/maccertificatepolicy` ## Request URL `https://{server-hostname}:8383/api/v1/mdm/profiles/{profile_id}/payloads/maccertificatepolicy` ## Scope `MDMDeviceMgmt.CREATE` ## Header `Authorization: d92d4xxxxxxxxxxxxx15f52` ## Request Parameters ### Request Headers - **Content-Type** `string` — **Mandatory** — `application/json` - **Accept** `string` — **Mandatory** — `application/json` ### Path Parameters - **profile_id** `string` — **Mandatory** Unique identifier of the profile. Obtain from the [Create Profile](https://www.manageengine.com/products/desktop-central/help/api/onpremise/mdm-profiles-create-profile.html) or [Get Profiles](https://www.manageengine.com/products/desktop-central/help/api/onpremise/mdm-profiles-get-profile.html) response. ### Request Body `application/json` **JSON Object** - **certificate_id** `long` — **Mandatory** Certificate ID obtained from the [Certificates API](https://www.manageengine.com/products/desktop-central/help/api/onpremise/certificates-get-certificates.html) - **allow_other_app_access** `boolean` — Optional Allow third-party apps to access the private key in Keychain. Default: false - **key_is_extractable** `boolean` — Optional Allow private key to be exported from Keychain. Default: true ## Sample Request ```curl curl --request POST \ --url https://appdomain/api/v1/mdm/profiles/{profile_id}/payloads/maccertificatepolicy \ --header 'Accept: application/json' \ --header 'Authorization: d92d4xxxxxxxxxxxxx15f52' \ --header 'Content-Type: application/json' \ --data '{"certificate_id":1,"allow_other_app_access":false,"key_is_extractable":true}' ``` ## Sample Request Body Add Certificate payload to the profile ```json { "certificate_id": 1, "allow_other_app_access": false, "key_is_extractable": true } ``` ## Response Parameters ### HTTP Code 200 Response Body — `application/json` **JSON Object** - **payload_id** `long` Unique identifier for the created payload item - **certificate_id** `long` Certificate ID obtained from the [Certificates API](https://www.manageengine.com/products/desktop-central/help/api/onpremise/certificates-get-certificates.html) - **allow_other_app_access** `boolean` Allow third-party apps to access the private key in Keychain. Default: false - **key_is_extractable** `boolean` Allow private key to be exported from Keychain. Default: true ## Possible Response Codes - **200** — HTTP code ## Sample Response: HTTP 200 Certificate payload successfully added ```json { "certificate_id": 1, "payload_id": 9007199254741000, "allow_other_app_access": false, "key_is_extractable": true } ``` ## API Rate Limits ![](https://www.zohowebstatic.com/sites/zweb/images/people/ico-help.png) **Duration:** 1 minute | **Threshold:** 30 | **Lock period:** 5 minutes Duration - Time window for the threshold. Threshold - Number of API calls allowed within the specified duration. Lock Period - Wait time before consecutive API requests.