To create Mac SCEP policy
https://{server-hostname}:8383/api/v1/mdm/profiles/{profile_id}/payloads/macsceppolicy
MDMDeviceMgmt.CREATECopied!
Authorization: d92d4xxxxxxxxxxxxx15f52
Unique identifier of the profile. Obtain from the Create Profile or Get Profiles response
SCEP template configuration ID. First create a SCEP server using Add SCEP Server, then create a template using Add SCEP Template to obtain this ID
Whether the private key can be extracted from the keychain. When false, the key is non-exportable for enhanced security. Default: true
Whether all apps on the device can access the SCEP certificate and private key in the keychain. Default: false
curl --request POST \
--url https://appdomain/api/v1/mdm/profiles/{profile_id}/payloads/macsceppolicy \
--header 'Accept: application/json' \
--header 'Authorization: d92d4xxxxxxxxxxxxx15f52' \
--header 'Content-Type: application/json' \
--data '{"allow_all_apps_access":false,"scep_config_id":1,"key_is_extractable":true}'Add SCEP payload to the profile
{
"allow_all_apps_access": false,
"scep_config_id": 1,
"key_is_extractable": true
}
Unique identifier for the created payload item
SCEP template configuration ID. First create a SCEP server using Add SCEP Server, then create a template using Add SCEP Template to obtain this ID
Whether the private key can be extracted from the keychain. When false, the key is non-exportable for enhanced security. Default: true
Whether all apps on the device can access the SCEP certificate and private key in the keychain. Default: false
SCEP payload successfully added
{
"payload_id": 9007199254741000,
"allow_all_apps_access": false,
"scep_config_id": 1,
"key_is_extractable": true
}
![]()
Duration: 1 minute | Threshold: 30 | Lock period: 5 minutes
Duration - Time window for the threshold.
Threshold - Number of API calls allowed within the specified duration.
Lock Period - Wait time before consecutive API requests.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.