# Add a routing payload to a profile Adds a routing payload to a Draft profile, mapping URLs or web domain groups to a target browser. ## Endpoint `POST /bsp/api/v1/bmp/browser_router/{profile_id}/router_payloads` ## Request URL `https://`[{serverurl}](https://www.manageengine.com/products/desktop-central/help/api/cloud/oauth-authentication-endpoint-domain.html)`/bsp/api/v1/bmp/browser_router/{profile_id}/router_payloads` ## Scope `DesktopCentralCloud.BrowserManager.CREATE` ## Header `Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52` ## Request Parameters ### Request Headers | Name | Type | Required | Value | |---|---|---|---| | Content-Type | string | Mandatory | application/json | | Accept | string | Mandatory | application/json | ### Path Parameters | Name | Type | Required | Description | |---|---|---|---| | profile_id | string | Mandatory | Browser Router Profile ID from [List Browser Router Profiles](https://www.manageengine.com/products/desktop-central/help/api/cloud/browser-router-list-browser-router-profiles.html) response (`profile_id` field) | ### Request Body JSON body with a `router_payloads` object containing the routing rule: target browser (`open_in`), optional browser mode, URL entries with webdomain IDs, and/or group entries with group IDs. **Content type:** `application/json` **Type:** JSON Object Routing payload. Pick a target browser from the dropdown. ## Examples ### Chrome #### Sample Request ```curl curl --request POST \ --url https://appdomains/bsp/api/v1/bmp/browser_router/{profile_id}/router_payloads \ --header 'Accept: application/json' \ --header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52' \ --header 'Content-Type: application/json' \ --data '{}' ``` #### Sample Request Body - Chrome Route URLs and groups to Google Chrome. `open_in`: target browser, set to `chrome`. `urls.webdomain_ids`: array of pre-created webdomain IDs to route. `urls.doc_type`: IE document compatibility mode, set to empty string as IE mode is not applicable for Chrome. `groups.ids`: array of pre-created webdomain group IDs to route. `groups.doc_type`: IE document compatibility mode for the group, set to empty string. `intranet_zone`: whether to include local intranet zone sites in this rule. ```json { "router_payloads": { "urls": [ { "webdomain_ids": [ "21" ], "doc_type": "" } ], "groups": [ { "ids": [ "313" ], "doc_type": "" } ], "intranet_zone": false, "open_in": "chrome" } } ``` ## Response Parameters ### HTTP Code 200 **Response body:** `application/json` **Type:** JSON Object | Name | Type | Description | |---|---|---| | router_payload | JSON Array | Created payload configurations with routing details | ### HTTP Code 400 **Response body:** `application/json` | Name | Type | Description | |---|---|---| | error_description | string | Name of the duplicate webdomain or group already assigned to another payload | | error_code | string | Error code for duplicate webdomain/group assignment | ### HTTP Code 401 **Response body:** `application/json` | Name | Type | Description | |---|---|---| | errorCode | long | Unauthorized error code returned when authentication credentials are missing, expired, or invalid (authentication=required) | | errorMsg | string | Authentication failure reason | ### HTTP Code 403 **Response body:** `application/json` | Name | Type | Description | |---|---|---| | errorCode | long | Forbidden error code returned when the authenticated user does not have the required uem-roles (e.g., DataEncryption_Admin or DataEncryptionRecoveryKey_Admin) | | errorMsg | string | Message indicating insufficient privileges to access this resource | ### HTTP Code 404 **Response body:** `application/json` | Name | Type | Description | |---|---|---| | error_description | string | Message indicating the specified profile or payload was not found | ### HTTP Code 409 **Response body:** `application/json` | Name | Type | Description | |---|---|---| | error_description | string | Message indicating published profiles cannot be modified | ### HTTP Code 429 **Response body:** `application/json` | Name | Type | Description | |---|---|---| | errorCode | long | Rate limit error code returned when the API call threshold (configured via threshold/duration in security XML) is exceeded; client is locked out for lock-period minutes | | errorMsg | string | Rate limit exceeded message with retry guidance | ### HTTP Code 500 **Response body:** `application/json` | Name | Type | Description | |---|---|---| | error_description | string | Message describing the server-side failure | | error_code | string | Internal server error code | ## Response Examples ### Sample Response: HTTP 400 Duplicate webdomain ```json { "error_description": "example.com", "error_code": "BSP_BR0001" } ``` ### Sample Response: HTTP 401 Unauthorized ```json { "errorCode": "UNAUTHORIZED", "errorMsg": "You are not authorized to perform this action" } ``` ### Sample Response: HTTP 403 Forbidden ```json { "errorCode": "FORBIDDEN", "errorMsg": "You do not have permission to access this resource" } ``` ### Sample Response: HTTP 404 Profile not found ```json { "error_description": "Profile not found" } ``` ### Sample Response: HTTP 409 Profile is published ```json { "error_description": "Cannot modify a published profile" } ``` ### Sample Response: HTTP 429 Rate limit exceeded ```json { "errorCode": "RATE_LIMIT_EXCEEDED", "errorMsg": "You have exceeded the maximum number of API calls. Please try again later." } ``` ### Sample Response: HTTP 500 Server error ```json { "error_description": "Internal Server error, Please try again in a moment.", "error_code": "COM0004" } ``` ## Rate Limits ![](https://www.zohowebstatic.com/sites/zweb/images/people/ico-help.png) **Duration:** 1 minute | **Threshold:** 60 | **Lock period:** 5 minutes Duration - Time window for the threshold. Threshold - Number of API calls allowed within the specified duration. Lock Period - Wait time before consecutive API requests.