# Add a new Extensible SSO payload configuration to an existing profile
To create Mac Extensible SSO policy
## Endpoints
**POST** `/api/v1/mdm/profiles/{profile_id}/payloads/macextensiblessopolicy`
## Request URL
`https://{server-hostname}:8383/api/v1/mdm/profiles/{profile_id}/payloads/macextensiblessopolicy`
## Scope
`MDMDeviceMgmt.CREATE`
## Header
`Authorization: d92d4xxxxxxxxxxxxx15f52`
## Request Parameters
### Request Headers
- **Content-Type** (string, Mandatory): `application/json`
- **Accept** (string, Mandatory): `application/json`
### Path Parameters
- **profile_id** (string, Mandatory): Unique identifier of the profile. Obtain from the [Create Profile](https://www.manageengine.com/products/desktop-central/help/api/onpremise/mdm-profiles-create-profile.html) or [Get Profiles](https://www.manageengine.com/products/desktop-central/help/api/onpremise/mdm-profiles-get-profile.html) response.
### Request Body
`application/json`
- **extension_identifier** (string, Mandatory): Bundle identifier of the app extension that provides Single Sign-On (e.g., `com.apple.AppSSOKerberos.KerberosExtension`)
- **team_identifier** (string, Mandatory): Apple Developer Team identifier of the app extension
- **type** (integer, Mandatory): SSO extension type. Allowed values: `0=Credential (Kerberos)`, `1=Redirect`
- **realm** (string, Mandatory): Kerberos realm name (e.g., `ZYLKER.COM`). Required when type is `0` (Credential), must be empty when type is `1` (Redirect)
- **authentication_method** (integer, Mandatory): Authentication method for Platform SSO. Allowed values: `-1=Not Configured`, `0=Password`, `1=User Secure Enclave Key`
- **screen_locked_behavior** (integer, Mandatory): Behavior when SSO is requested while the screen is locked. Allowed values: `-1=Not Configured`, `0=Cancel`, `1=Do Not Handle`
- **extension_data** (string, Mandatory): Custom configuration data for the SSO extension in Apple property list XML format
- **registration_token** (string, Mandatory): Token used for Platform SSO registration. When provided, authentication_method must also be configured
- **hosts_and_urls** (array, Mandatory): List of identity provider URL prefixes that the SSO extension handles (at least one required)
- **denied_apps_details** (JSON Array, Mandatory): List of apps excluded from using this SSO extension. Each item requires an app_group_id.
## Sample Request
```curl
curl --request POST \
--url https://appdomain/api/v1/mdm/profiles/{profile_id}/payloads/macextensiblessopolicy \
--header 'Accept: application/json' \
--header 'Authorization: d92d4xxxxxxxxxxxxx15f52' \
--header 'Content-Type: application/json' \
--data '{"authentication_method":-1,"hosts_and_urls":["https://login.zylker.com"],"extension_identifier":"com.apple.AppSSOKerberos.KerberosExtension","screen_locked_behavior":-1,"extension_data":"helpURLhttps://zylker.com/help","team_identifier":"apple","realm":"ZYLKER.COM","registration_token":"","type":0,"denied_apps_details":[{"app_group_id":9007199254741072}]}'
```
### Sample Request Body
Add Extensible SSO payload to the profile
```json
{
"authentication_method": -1,
"hosts_and_urls": [
"https://login.zylker.com"
],
"extension_identifier": "com.apple.AppSSOKerberos.KerberosExtension",
"screen_locked_behavior": -1,
"extension_data": "helpURLhttps://zylker.com/help",
"team_identifier": "apple",
"realm": "ZYLKER.COM",
"registration_token": "",
"type": 0,
"denied_apps_details": [
{
"app_group_id": 9007199254741072
}
]
}
```
## Response Parameters
### HTTP Code 200
Response Body: `application/json`
- **payload_id** (long): Unique identifier for the created payload item
- **extension_identifier** (string): Bundle identifier of the app extension that provides Single Sign-On
- **team_identifier** (string): Apple Developer Team identifier of the app extension
- **type** (integer): SSO extension type. Allowed values: `0=Credential (Kerberos)`, `1=Redirect`
- **realm** (string): Kerberos realm name. Empty when type is `1` (Redirect)
- **authentication_method** (integer): Authentication method for Platform SSO. Allowed values: `-1=Not Configured`, `0=Password`, `1=User Secure Enclave Key`
- **screen_locked_behavior** (integer): Behavior when SSO is requested while the screen is locked. Allowed values: `-1=Not Configured`, `0=Cancel`, `1=Do Not Handle`
- **extension_data** (string): Custom configuration data for the SSO extension in Apple property list XML format
- **registration_token** (string): Token used for Platform SSO registration
- **hosts_and_urls** (array): List of identity provider URL prefixes that the SSO extension handles
- **denied_apps_details** (JSON Array): List of apps excluded from using this SSO extension, with resolved app details
## Possible Response Codes
- **200** (HTTP code)
## Sample Response: HTTP 200
Extensible SSO payload successfully added
```json
{
"authentication_method": -1,
"hosts_and_urls": [
"https://login.zylker.com"
],
"extension_identifier": "com.apple.AppSSOKerberos.KerberosExtension",
"payload_id": 9007199254741000,
"screen_locked_behavior": -1,
"extension_data": "helpURLhttps://zylker.com/help",
"team_identifier": "apple",
"realm": "ZYLKER.COM",
"registration_token": "",
"type": 0,
"denied_apps_details": [
{
"identifier": "com.zylker.deniedapp",
"group_display_name": "Denied App",
"app_group_id": 9007199254741072
}
]
}
```
## Rate Limits
**Duration:** 1 minute | **Threshold:** 30 | **Lock period:** 5 minutes
Duration - Time window for the threshold.
Threshold - Number of API calls allowed within the specified duration.
Lock Period - Wait time before consecutive API requests.