> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Renew, update, or delete ADE tokens via the Iru API

> Renew, update, or delete Automated Device Enrollment tokens with the Iru Endpoint API to prevent expiration and maintain Apple Business connections.

<Note title="Apple Business name change">
  **Apple Business Manager** is now **Apple Business**. **Apple School Manager** is unchanged. For more information, see [Introducing Apple Business](https://www.apple.com/newsroom/2026/03/introducing-apple-business-a-new-all-in-one-platform-for-businesses-of-all-sizes/) and [Apple Business Manager is now Apple Business](https://support.apple.com/guide/apple-business-manager/apple-business-manager-is-now-apple-business-axmd79d79dea/web).
</Note>

### About ADE Token Management

Automated Device Enrollment (ADE) tokens require periodic renewal and management to maintain device enrollment capabilities. This process allows you to efficiently manage multiple ADE tokens using API automation, reducing manual effort and ensuring consistent token lifecycle management.

### How It Works

ADE token management involves using the Iru Endpoint API through Postman to perform bulk operations on multiple tokens. The process includes configuring API access, setting up environment variables, downloading tokens from Apple Business or Apple School Manager, and using automated workflows to renew, update, or delete tokens efficiently.

<Warning>
  If you do not feel confident in completing this process yourself, please reach out to [Iru Endpoint Support](/en/iru/iru-support/access-to-iru-support) for additional guidance.
</Warning>

### Prerequisites

* Access to Iru Endpoint with API token creation permissions
* Postman application installed and configured
* Access to Apple Business or Apple School Manager
* Multiple ADE tokens that need renewal or management
* Basic understanding of API operations and Postman workflows

### Configuring an Iru Endpoint API token

Prepare an API token and store it in a secure location. You can read more about this in our [Iru Endpoint API](/en/endpoint/api/iru-api-overview) article. You can skip this section if you already have an API token prepared.

<Steps>
  <Step title="Create or modify an API token">
    Create a new API token or modify an existing one with the required permissions.
  </Step>

  <Step title="Open API tokens">
    In your Iru Endpoint tenant, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Access** → **API tokens**.

    <Frame>
      <img src="https://mintcdn.com/iru/8BYPjuKZa-zyEEf_/assets/media/images/iru-nav-access.png?fit=max&auto=format&n=8BYPjuKZa-zyEEf_&q=85&s=466fdf5fb47efd6bab8b450a5a1e8302" alt="Screenshot of the account menu with Access option highlighted" width="562" height="1040" data-path="assets/media/images/iru-nav-access.png" />
    </Frame>
  </Step>

  <Step title="Configure Permissions">
    Create or modify the existing API token to include all Automated Device Enrollment-related permissions.

    <Frame>
      <img src="https://mintcdn.com/iru/NKSnzq9fKEdl088H/assets/media/images/Pv42CEgaUUCs11xRUAzMXocu02W0mHPlvA.png?fit=max&auto=format&n=NKSnzq9fKEdl088H&q=85&s=c089b38a14fb7fbf12a2718caf6eed7a" alt="Access page showing API tokens for configuring ADE token permissions" width="2968" height="2398" data-path="assets/media/images/Pv42CEgaUUCs11xRUAzMXocu02W0mHPlvA.png" />
    </Frame>
  </Step>
</Steps>

### Preparing Postman

Most of the steps moving forward will be performed inside the Postman application on your device. You can skip this section if you already have Postman configured.

<Steps>
  <Step title="Verify Collection Structure">
    Check your Collection for the Automated Device Enrollment integrations folder.
  </Step>

  <Step title="Define API URL">
    Define your API URL if undefined in the Iru Endpoint API folder at the top of the collection.
  </Step>

  <Step title="Configure Environment Variables">
    Define the API Token in your Environment variables following our How to Set Up the Iru Endpoint API in Postman article.
  </Step>
</Steps>

### Configuring Postman Environment Variables

Now that the basics of Postman have been configured, you will need to define some Environment Variables in Postman to keep track of the Automated Device Enrollment servers.

<Steps>
  <Step title="Create Environment Variables">
    In Postman, click the **Environments** tab in the left sidebar, then click **Create Environment** to create a new environment. Name your environment (e.g., "Iru Endpoint API") and add the following variables:

    * **Variable**: `base_url`
      * **Initial Value**: `https://<subdomain>.api.iru.com/api/v1`
      * **Current Value**: `https://<subdomain>.api.iru.com/api/v1`

    <Note>Replace `<subdomain>` with your tenant's actual subdomain, or copy the base URL directly from your tenant. The URL shown in your tenant may use the `api.kandji.io` domain. Both `<subdomain>.api.iru.com` and `<subdomain>.api.kandji.io` will work without modification.</Note>

    * **Variable**: `token`
      * **Initial Value**: `your_api_token_here`
      * **Current Value**: `your_api_token_here`

    Click **Save** to save your environment, then select your newly created environment from the environment dropdown in the top-right corner.
  </Step>

  <Step title="Add to Existing Variables">
    If you already have environment variables configured, you can add the new items to the existing variables.
  </Step>

  <Step title="List ADE Integrations">
    Navigate to **Iru Endpoint API** > **Automated Device Enrollment Integrations** > **GET List ADE Integrations** in the Collection.
  </Step>

  <Step title="Execute Request">
    Click the **Send** button to execute the request.

    <Frame>
      <img src="https://mintcdn.com/iru/eqrMRa098FywfIL4/assets/media/images/s_gndtjtsb7clcnwtlrh7xa66k_f8-n0pg.png?fit=max&auto=format&n=eqrMRa098FywfIL4&q=85&s=b5b25f88d1ff8de846e36768393d5cd6" alt="Postman Collection showing Automated Device Enrollment Integrations folder and GET List ADE Integrations request" width="1657" height="462" data-path="assets/media/images/s_gndtjtsb7clcnwtlrh7xa66k_f8-n0pg.png" />
    </Frame>
  </Step>

  <Step title="Copy Token IDs">
    In the **Body** section of the Results, copy the top-level IDs of each Automated Device Enrollment token.
  </Step>

  <Step title="Create Token Variables">
    For each token ID, create an environment variable with a naming scheme such as `ade_token_1`, `ade_token_2`, etc., incrementing the number for each token.
  </Step>

  <Step title="Note Server Names">
    Make a note of the associated `server_name` for each token. You will need this information when downloading the tokens from Apple Business or Apple School Manager.

    <Frame>
      <img src="https://mintcdn.com/iru/mol1UbnodotF3fFx/assets/media/images/hhp7d5qxdqvqlghctn3e_vabqzoy2osqsw.png?fit=max&auto=format&n=mol1UbnodotF3fFx&q=85&s=7d4cbc5b8bd4f9e8b5ce4654b4fca8fa" alt="Postman request Body section showing ADE token IDs to copy for environment variables" width="1174" height="501" data-path="assets/media/images/hhp7d5qxdqvqlghctn3e_vabqzoy2osqsw.png" />
    </Frame>
  </Step>

  <Step title="Set Variable Values">
    Paste the ID value for each token into the corresponding `ade_token_#` variable (e.g., `ade_token_1`, `ade_token_2`).
  </Step>

  <Step title="Secure Variables">
    You can set the variable type to secret so that the value of the variable is not visible.

    <Frame>
      <img src="https://mintcdn.com/iru/OVGwzrvB1dITOQ_N/assets/media/images/fegwvcjvpkgx1pfo-l_6lqxlxmjuss9v4w.png?fit=max&auto=format&n=OVGwzrvB1dITOQ_N&q=85&s=b0f69f789107b6569f5f4f4211e6d6a1" alt="Postman Environments tab showing Create Environment and variables for base_url and token" width="807" height="386" data-path="assets/media/images/fegwvcjvpkgx1pfo-l_6lqxlxmjuss9v4w.png" />
    </Frame>
  </Step>
</Steps>

### Downloading ADE Tokens

<Steps>
  <Step title="Access Apple Business or Apple School Manager">
    Sign in to your [Apple Business](https://business.apple.com) or [Apple School Manager](https://school.apple.com) account.
  </Step>

  <Step title="Open the Devices tab">
    Click the **Devices** tab at the top of the page.
  </Step>

  <Step title="Open Management">
    In the left sidebar, click **Management**.
  </Step>

  <Step title="Select the matching device management service">
    In the **Management Services** list, select the service whose name matches the first ADE integration's `server_name` from the list you made earlier in Postman.

    <Frame>
      <img src="https://mintcdn.com/iru/QlM0bw2VPN4WhxbZ/assets/media/images/iru-apple-business-existing-management-service.png?fit=max&auto=format&n=QlM0bw2VPN4WhxbZ&q=85&s=96b271af974cf199cabc45e38be537c8" alt="Apple Business or Apple School Manager Management Services list with an existing device management service" width="2722" height="1496" data-path="assets/media/images/iru-apple-business-existing-management-service.png" />
    </Frame>
  </Step>

  <Step title="Open the service actions menu">
    Click the ellipsis (**…**) for that service.
  </Step>

  <Step title="Download the token">
    Click **Download Token**.

    <Frame>
      <img src="https://mintcdn.com/iru/QlM0bw2VPN4WhxbZ/assets/media/images/iru-apple-business-download-management-service-token.png?fit=max&auto=format&n=QlM0bw2VPN4WhxbZ&q=85&s=2e0c00b13080be10f6890fd4179aaa09" alt="Apple Business or Apple School Manager Download Service Token action" width="1012" height="1264" data-path="assets/media/images/iru-apple-business-download-management-service-token.png" />
    </Frame>
  </Step>

  <Step title="Repeat for All Tokens">
    Repeat this process for each token that you will be renewing.
  </Step>
</Steps>

### Creating Postman Folder Template

Creating folders in Postman will make it easier to keep track of your Automated Device Enrollment tokens.

<Steps>
  <Step title="Access Folder Options">
    Click on the ellipsis next to the Automated Device Enrollment Integrations folder.
  </Step>

  <Step title="Add New Folder">
    Click Add folder.

    <Frame>
      <img src="https://mintcdn.com/iru/TrNeDzYbuegnhNyr/assets/media/images/lro_3myqy6ypjcw4dpurredes9vrc8tldw.png?fit=max&auto=format&n=TrNeDzYbuegnhNyr&q=85&s=f5780b8d9dd41876ac419c6c2b8721af" alt="Postman Collection showing Add folder and ADE_Token1 folder with Renew and Update ADE Integration items" width="584" height="606" data-path="assets/media/images/lro_3myqy6ypjcw4dpurredes9vrc8tldw.png" />
    </Frame>
  </Step>

  <Step title="Name the Folder">
    Name the folder ADE\_Token1.
  </Step>

  <Step title="Select Integration Items">
    Navigate to the **Automated Device Enrollment Integrations** folder and select the **Renew ADE Integration** and **Update ADE Integration** items.
  </Step>

  <Step title="Copy Items">
    Right-click the selected items and choose **Copy**.
  </Step>

  <Step title="Access New Folder">
    Click on the ellipsis next to the ADE\_Token1 folder.
  </Step>

  <Step title="Paste Items">
    Click **Paste** to add the copied items to the new folder.
  </Step>
</Steps>

### Modifying Renew Item

<Steps>
  <Step title="Select Renew Item">
    Select the **Renew ADE Integration** item from your token folder.
  </Step>

  <Step title="Rename Item">
    Rename it to **Renew ADE1 Integration** (or **Renew ADE2 Integration**, etc., based on your token number).
  </Step>

  <Step title="Update Address Bar">
    In the section to the right, click on the address bar to the left of the **Send** button.
  </Step>

  <Step title="Update Token Variable">
    Select the text inside `{{ade_token_ade}}` and update it to `{{ade_token_1}}` (or `{{ade_token_2}}`, etc., based on your token number).
  </Step>

  <Step title="Configure Body">
    Click on the Body tab below.
  </Step>

  <Step title="Enter Token Details">
    Enter the `blueprint_id`, phone, and email that should be associated with the token.

    <Frame>
      <img src="https://mintcdn.com/iru/TrNeDzYbuegnhNyr/assets/media/images/lxnkojp8pd_t7beakdetpgm4pnbwkan7wg.png?fit=max&auto=format&n=TrNeDzYbuegnhNyr&q=85&s=41a45cc30548ef654602ec7039c86e09" alt="Postman Renew ADE Integration request showing address bar with token variable and Body tab with blueprint_id, phone, email, and file upload" width="1657" height="527" data-path="assets/media/images/lxnkojp8pd_t7beakdetpgm4pnbwkan7wg.png" />
    </Frame>
  </Step>

  <Step title="Select Token File">
    For the file, click x by any current files, and then click Select Files.
  </Step>

  <Step title="Choose P7M File">
    Choose the .p7m file that matches this ADE token.
  </Step>

  <Step title="Save Changes">
    Save the changes.
  </Step>
</Steps>

### Modifying Update Item

<Steps>
  <Step title="Select Update Item">
    Select the **Update ADE Integration** item from your token folder.
  </Step>

  <Step title="Rename Item">
    Rename it to **Update ADE1 Integration** (or **Update ADE2 Integration**, etc., based on your token number).
  </Step>

  <Step title="Update Address Bar">
    In the section to the right, click on the address bar to the left of the **Send** button.
  </Step>

  <Step title="Update Token Variable">
    Select the text inside `{{ade_token_ade}}` and update it to `{{ade_token_1}}` (or `{{ade_token_2}}`, etc., based on your token number).
  </Step>

  <Step title="Configure Body">
    Click on the Body tab below.
  </Step>

  <Step title="Enter Update Information">
    This is where you can enter new `blueprint_id`, phone, and email information.
  </Step>

  <Step title="Save Changes">
    Save the changes.

    <Frame>
      <img src="https://mintcdn.com/iru/eqrMRa098FywfIL4/assets/media/images/tebxp4bw1fpdputejvgpfkodutxllfqwvg.png?fit=max&auto=format&n=eqrMRa098FywfIL4&q=85&s=9edf5ebe1c8b37c652525373baf4fe5d" alt="Postman Update ADE Integration request showing Body section for blueprint_id, phone, and email updates" width="1656" height="435" data-path="assets/media/images/tebxp4bw1fpdputejvgpfkodutxllfqwvg.png" />
    </Frame>
  </Step>
</Steps>

### Duplicating ADE\_Token Folder

<Steps>
  <Step title="Access Folder Options">
    Click on the ellipsis next to the ADE\_Token1 folder.
  </Step>

  <Step title="Duplicate Folder">
    Choose Duplicate.

    <Frame>
      <img src="https://mintcdn.com/iru/Pp4ndpzRp4nipP1L/assets/media/images/0mynl_k9tyrkubc0yi3m-zlih5iptakt2a.png?fit=max&auto=format&n=Pp4ndpzRp4nipP1L&q=85&s=2a86f40c7ae88d30e025cf7195940849" alt="Postman folder ellipsis menu showing Duplicate option for ADE token folder" width="582" height="611" data-path="assets/media/images/0mynl_k9tyrkubc0yi3m-zlih5iptakt2a.png" />
    </Frame>
  </Step>

  <Step title="Update Folder Contents">
    Update the contents of the folder using the process above.
  </Step>

  <Step title="Create Additional Folders">
    Make duplicates of the folder for each of your ADE tokens.
  </Step>
</Steps>

### Renewing ADE Integration

Now that everything is configured, you can send the Renew command.

<Steps>
  <Step title="Select Renew Command">
    Navigate to the specific token folder you created (e.g., **ADE\_Token1**, **ADE\_Token2**, etc.) and select the **Renew ADE1 Integration** (or **Renew ADE2 Integration**, etc.) item that corresponds to your token number.
  </Step>

  <Step title="Execute Command">
    Click the Send button.

    <Frame>
      <img src="https://mintcdn.com/iru/eqrMRa098FywfIL4/assets/media/images/saqudhpbt1dw4wlkmkmvfr7furqxnqktfa.png?fit=max&auto=format&n=eqrMRa098FywfIL4&q=85&s=01fe5204ae332a05c90d7c8ec868121e" alt="Postman Renew ADE Integration request with Send button to execute renewal" width="1656" height="528" data-path="assets/media/images/saqudhpbt1dw4wlkmkmvfr7furqxnqktfa.png" />
    </Frame>
  </Step>
</Steps>

### Updating ADE Integration

Updating the ADE Integration will allow you to change the associated Blueprint ID, phone number, and email address.

<Steps>
  <Step title="Select Update Command">
    Navigate to the specific token folder you created (e.g., **ADE\_Token1**, **ADE\_Token2**, etc.) and select the **Update ADE1 Integration** (or **Update ADE2 Integration**, etc.) item that corresponds to your token number.
  </Step>

  <Step title="Update Details">
    Update the details in the Body section that need updating.
  </Step>

  <Step title="Execute Command">
    Click the Send button.

    <Frame>
      <img src="https://mintcdn.com/iru/2JN9EXN6FEm5sMxP/assets/media/images/4w-xzfsnw1zklftmhp22xg91hln3ylkcow.png?fit=max&auto=format&n=2JN9EXN6FEm5sMxP&q=85&s=f1e6f8a8e0b731898214fd0bd042b46a" alt="Postman Update ADE Integration request with Send button to execute update" width="1658" height="433" data-path="assets/media/images/4w-xzfsnw1zklftmhp22xg91hln3ylkcow.png" />
    </Frame>
  </Step>
</Steps>

### Checking Current Integrations

Iru Endpoint API > Automated Device Enrollment Integrations > GET List ADE Integrations command will give us all current ADE integrations so that we can verify that the integration was Renewed or Updated successfully.

<Steps>
  <Step title="Select List Command">
    Select Iru Endpoint API > Automated Device Enrollment Integrations > GET List ADE Integrations in the Collection.
  </Step>

  <Step title="Execute Command">
    Click the Send button.
  </Step>

  <Step title="Verify Renewal">
    The `days_left` variable should be 364 if the Renew command was successful.
  </Step>

  <Step title="Verify Updates">
    To verify an update, check the information associated with the ADE token to verify that it was updated.

    <Frame>
      <img src="https://mintcdn.com/iru/31OfB-o1LvAjxToj/assets/media/images/9x1u4vgwuq3spir7odaqcloxfdquzyhpya.png?fit=max&auto=format&n=31OfB-o1LvAjxToj&q=85&s=35f5e9e8ff9ff9865063eb073809e5c6" alt="Postman GET List ADE Integrations response showing days_left and integration details for verification" width="1596" height="1143" data-path="assets/media/images/9x1u4vgwuq3spir7odaqcloxfdquzyhpya.png" />
    </Frame>
  </Step>
</Steps>

### Deleting Integration

Iru Endpoint API > Automated Device Enrollment Integrations > DEL Delete ADE Integration command will delete the ADE integration associated with the supplied ADE Token ID.

<Steps>
  <Step title="Select Delete Command">
    Select Iru Endpoint API > Automated Device Enrollment Integrations > DEL Delete ADE Integration in the Collection.
  </Step>

  <Step title="Set Token ID">
    Populate the `ade_token_id` variable with the ID of the ADE Token.
  </Step>

  <Step title="Execute Command">
    Click the Send button.

    <Frame>
      <img src="https://mintcdn.com/iru/OVGwzrvB1dITOQ_N/assets/media/images/e7sIgqB8Mz2xLBL5WBvgaZKGrand9CrlLg.png?fit=max&auto=format&n=OVGwzrvB1dITOQ_N&q=85&s=0a589f1059e06d7f41def973eca2d4f0" alt="Postman DEL Delete ADE Integration request with ade_token_id variable and Send button" width="1743" height="601" data-path="assets/media/images/e7sIgqB8Mz2xLBL5WBvgaZKGrand9CrlLg.png" />
    </Frame>
  </Step>
</Steps>

### Considerations

<AccordionGroup>
  <Accordion title="API security, Postman, and environment setup">
    * **API Token Security**: Ensure API tokens are stored securely and have appropriate permissions for ADE operations
    * **Postman Configuration**: Proper Postman setup is essential for successful API operations
    * **Environment Variables**: Use environment variables to manage multiple token IDs efficiently
    * **Error Handling**: Be prepared to troubleshoot API errors and token validation issues
  </Accordion>

  <Accordion title="Tokens, files, and Apple portal access">
    * **Token Lifecycle**: ADE tokens have expiration dates and require periodic renewal to maintain enrollment capabilities
    * **Token File Management**: Keep track of downloaded .p7m files and associate them with correct token IDs
    * **Apple Business or Apple School Manager access**: Ensure you can sign in to the portal and download tokens
    * **Verification Process**: Always verify successful operations by checking integration status and token expiration
  </Accordion>

  <Accordion title="Bulk operations and access control">
    * **Bulk Operations**: Use folder templates to efficiently manage multiple tokens
    * **Access Control**: Ensure only authorized personnel have access to token management operations
  </Accordion>

  <Accordion title="Testing, monitoring, and continuity">
    * **Testing**: Test operations on a small scale before performing bulk operations
    * **Monitoring**: Regularly monitor token expiration dates and renewal schedules
    * **Documentation**: Keep records of token configurations and associated server names
    * **Backup Strategy**: Maintain backups of token configurations and API settings
  </Accordion>
</AccordionGroup>
