Retrieve the full configuration details of a Per-App VPN payload item

Open in ChatGPT Open in ChatGPT to ask questions about this page
Open in Claude Open in Claude to ask questions about this page
Copy as MarkdownCopy this page as markdown to use with AI assistants
View as Markdown Open this page as markdown in a new tab

To get Mac Per App Vpn Policy payload item

Request URL

https://{server-hostname}:8383/api/v1/mdm/profiles/{profile_id}/payloads/macperappvpn/payloaditems/{payload_id}

Scope

MDMDeviceMgmt.READCopied!

Header

Authorization: d92d4xxxxxxxxxxxxx15f52

Request Parameters

- Request Headers

AcceptstringMandatory
application/jsonapplication/jsonCopied!

- Path Parameters

profile_idstringMandatory

Unique identifier of the profile. Obtain from the Create Profile or Get Profiles response

payload_idstringMandatory

Unique identifier of the payload item. Obtain from the Get Payload Item IDs response

- Query Parameters

includestringOptional

Comma-separated list of related fields to include in the response (e.g., assigned_to, payload_details). When omitted, only top-level fields are returned

Sample Request

Curl
Java
Python
Deluge
PowerShell
Copied!
curl --request GET \
  --url 'https://appdomain/api/v1/mdm/profiles/{profile_id}/payloads/macperappvpn/payloaditems/{payload_id}?include=payloaditems' \
  --header 'Accept: application/json' \
  --header 'Authorization:  d92d4xxxxxxxxxxxxx15f52'

Response Parameters

- HTTP code 200

Response Body - application/json
JSON Object
Hide Sub-Attributes
payload_idlong

Unique identifier of the payload item

sub_configstring

VPN sub-configuration type indicating the active VPN protocol. Corresponds to the connection_type value (e.g., L2TP, PPTP, IPSEC, IKEV2, CUSTOMSSL). Default: L2TP

connection_namestring

Display name for the VPN connection shown to the user in System Preferences. Default: VPN Configuration

connection_typestring

VPN connection type. Allowed values: 0=L2TP, 1=PPTP, 2=IPSec, 3=Cisco Legacy AnyConnect, 4=Juniper SSL, 5=F5 SSL, 6=Custom SSL, 7=Pulse Secure, 8=IKEv2, 9=Cisco AnyConnect, 10=SonicWall, 11=Aruba VIA, 12=CheckPoint Mobile

send_all_nw_trafficboolean

Whether all network traffic is routed through the VPN tunnel (full tunnel mode). When false, split tunneling is used. Default: false

certificate_uuidstring

UUID of the identity certificate payload used for VPN authentication. Obtain from the Upload Certificate API

enable_vpn_on_demandboolean

Whether VPN On Demand is enabled, allowing the system to automatically establish the VPN connection based on configured rules. Default: false

disconnect_on_idle_timeoutstring

Disconnect on idle timeout in seconds. 0 means disabled. Default: 0

f5sslJSON Object

F5Ssl

Show Sub-Attributes
customsslJSON Object

Customssl

Show Sub-Attributes
sonicwallJSON Object

Sonicwall

Show Sub-Attributes
proxy_typestring

Proxy configuration type. Allowed values: 0=None, 1=Manual, 2=Automatic (PAC URL)

proxy_serverstring

Hostname or IP address of the HTTP proxy server. Required when proxy_type is 1 (Manual)

proxy_server_portstring

Port number of the HTTP proxy server. Valid range: 0-65535. Default: 0

proxy_user_namestring

Username for proxy server authentication

proxy_passwordstring

Password for proxy server authentication (sensitive - write-only, not returned in responses)

proxy_password_idlong

Internal identifier for the stored proxy password credential

proxy_pac_urlstring

URL of the Proxy Auto-Configuration (PAC) file. Required when proxy_type is 2 (Automatic)

ondemand_user_override_disabledboolean

Whether the user is prevented from overriding VPN On Demand settings. When true, the user cannot manually disconnect an on-demand VPN. Default: false

ondemandrulesJSON Array

List of VPN On Demand rules controlling when the VPN connects/disconnects

Show Sub-Attributes
JSON Object
Show Sub-Attributes
rule_orderinteger

Order in which the rule is evaluated

actioninteger

Action to take. Allowed values: 0=Disconnect, 1=Connect, 2=Ignore, 3=Evaluate Connection

typeinteger

Match type. Allowed values: 0=Always, 1=DNS Domain Match, 2=DNS Server Address Match, 3=Interface Type Match, 4=SSID Match, 5=URL String Probe

valuearray

List of match values (domains, addresses, SSIDs, etc.) based on the match type

safari_domainsarray

List of domain strings that trigger the Per-App VPN when accessed in Safari (e.g., internal.zylker.com, *.corp.zylker.com)

excluded_domainsarray

List of domain strings whose traffic bypasses the Per-App VPN tunnel even when the VPN is active

vpn_typestring

VPN scope type. Allowed values: 1=Device-level VPN, 2=Per-App VPN

provider_typestring

VPN provider type. Allowed values: 0=Packet Tunnel (default), 1=App Proxy

vpnuuidstring

Unique identifier (UUID) for this VPN configuration, used to reference this VPN from Per-App VPN app assignments

allowed_appsJSON Array

List of apps allowed to use this Per-App VPN. Each app is identified by app_group_id from the Apps API

Show Sub-Attributes
JSON Object
Show Sub-Attributes
app_idlong

App ID of the VPN app. Use the app_group_id from the Apps API response

is_system_appboolean

Whether this is a system app. Default: false

group_display_namestring

Display name of the app group

autonomous_kiosk_appsJSON Array

List of autonomous single app mode apps

Show Sub-Attributes
JSON Object
Show Sub-Attributes
app_idlong

App ID of the kiosk app. Use the app_group_id from the Apps API response

group_display_namestring

Display name of the app group

ondemand_match_app_enabledboolean

Whether Per-App VPN automatically connects when associated apps launch. When enabled, the VPN triggers on app launch matching. Default: true

custom_dataJSON Array

List of custom key-value pairs for vendor-specific VPN configuration

Show Sub-Attributes
JSON Object
Show Sub-Attributes
custom_keystring

Custom configuration key name

custom_valuestring

Custom configuration key value

ikev2JSON Object

Ikev2

Show Sub-Attributes

Possible Response Codes

200HTTP code

Sample Response: HTTP 200

Full configuration details of Per-App VPN payload item

Copied!
  {
    "connection_name": "VPN Configuration",
    "send_all_nw_traffic": false,
    "payload_id": 9007199254741000,
    "sonicwall": {},
    "connection_type": 0,
    "customssl": {},
    "sub_config": "L2TP",
    "enable_vpn_on_demand": false,
    "f5ssl": {},
    "certificate_uuid": "value",
    "disconnect_on_idle_timeout": 0,
    "vpn_type": 1
  }
                
Show full

Duration: 1 minute | Threshold: 120 | Lock period: 5 minutes

Duration - Time window for the threshold.
Threshold - Number of API calls allowed within the specified duration.
Lock Period - Wait time before consecutive API requests.