Associates one or more published configuration profiles to specific devices for deployment. Both profile_ids and device_ids arrays are required with a maximum of 1000 items each. Only published profiles (status 110) can be associated.
post /bsp/api/v1/bmp/profiles/devices
https://{server-hostname}:8383/bsp/api/v1/bmp/profiles/devices
BrowserManager.CREATECopied!
Authorization: d92d4xxxxxxxxxxxxx15f52
JSON body containing profile_ids and device_ids arrays for profile-to-device association
Request body for associating profiles to devices
Required. Device resource IDs from List Devices response (device_id field). Max 1000
Profile IDs from List Profiles response (profile_id field). Max 1000, only published profiles allowed
curl --request POST \
--url https://appdomain/bsp/api/v1/bmp/profiles/devices \
--header 'Accept: application/json' \
--header 'Authorization: d92d4xxxxxxxxxxxxx15f52' \
--header 'Content-Type: application/json' \
--data '{"device_ids":[999,888],"profile_ids":[111]}'Associate two profiles to two devices
{
"device_ids": [
999,
888
],
"profile_ids": [
111
]
}
Bad request error for invalid input or constraint violations
Error code identifying the specific validation failure
Message describing the validation failure
Unauthorized error code returned when authentication credentials are missing, expired, or invalid (authentication=required)
Authentication failure reason
Forbidden error code returned when the authenticated user does not have the required uem-roles (e.g., DataEncryption_Admin or DataEncryptionRecoveryKey_Admin)
Message indicating insufficient privileges to access this resource
Conflict error due to the current state of the profile
Conflict error message
Rate limit error code returned when the API call threshold (configured via threshold/duration in security XML) is exceeded; client is locked out for lock-period minutes
Rate limit exceeded message with retry guidance
Internal server error response for profile operations
Error message describing the server failure
Error code for internal server errors
Returns 204 No Content on success.
204 Returns 204 No Content on success.Invalid request parameters
{
"errorcode": "IAM0003",
"errormsg": "Invalid request."
}
API key is missing or invalid
{
"errorCode": "IAM0001",
"errorMsg": "Authentication key is invalid. Please regenerate the key and try again."
}
Forbidden
{
"errorCode": "FORBIDDEN",
"errorMsg": "User does not have permission to perform this operation"
}
The specified profile does not exist or is in trash
{
"errormsg": "Profile not found"
}
Profile must be published before it can be associated to devices
{
"errormsg": "Profile is not published."
}
Rate limit exceeded
{
"errorCode": "RATE_LIMIT_EXCEEDED",
"errorMsg": "Too many requests. Please try again after 5 minutes"
}
Server error
{
"error_description": "Internal Server error, Please try again in a moment.",
"error_code": "COM0004"
}
![]()
Duration: 1 minute | Threshold: 60 | Lock period: 5 minutes
Duration - Time window for the threshold.
Threshold - Number of API calls allowed within the specified duration.
Lock Period - Wait time before consecutive API requests.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.