Skip to content

Create App Password setup links

POST
/api/v1/auth/app-passwords/{id}/profiles
curl --request POST \
--url https://example.com/api/v1/auth/app-passwords/2489E9AD-2EE2-8E00-8EC9-32D5F69181C0/profiles \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "password": "example" }'

Route: /api/v1/auth/app-passwords/{id}/profiles. Inputs: id. A recent account assertion is required. Do not automatically replay this operation after an uncertain result.

id
required
string format: uuid

App password id

Media typeapplication/json
object
password
required

The secret is sent only over the authenticated session and is never written to Security state or logs.

string
Examplegenerated
{
"password": "example"
}
Media typeapplication/json
object
expires_at
required

Unix time when both links expire.

integer format: int64
imap_port
integer | null format: int32
mac_url
required

A separate one-use link for the Mac download action.

string
mail_host

Non-secret Mail host and TLS ports for manual device setup (#486). Present only when this credential grants Mail read access.

string | null
mobile_url
required

One-use link encoded in the iPhone and iPad QR code.

string
profile_signing
required

Signing status for the exact profile bytes behind both links.

object
display_name

The company name from the Developer ID common name, with its team ID removed.

string | null
enabled
required

True when the certificate and chain are currently valid.

boolean
expires_at

The earliest expiry time in the signer certificate chain, in Unix seconds.

integer | null format: int64
expires_soon
required

True when the earliest expiry is within 30 days.

boolean
submission_port
integer | null format: int32
Examplegenerated
{
"expires_at": 1,
"imap_port": 1,
"mac_url": "example",
"mail_host": "example",
"mobile_url": "example",
"profile_signing": {
"display_name": "example",
"enabled": true,
"expires_at": 1,
"expires_soon": true
},
"submission_port": 1
}
Media typeapplication/json
object
code
required
string
message
required
string
Examplegenerated
{
"code": "example",
"message": "example"
}
Media typeapplication/json
object
code
required
string
message
required
string
Examplegenerated
{
"code": "example",
"message": "example"
}