---
title: "Find or create an App Group"
method: POST
path: "/appsec/7.0/apple/app-groups"
tags: ["App Groups"]
---

# Find or create an App Group

`POST /appsec/7.0/apple/app-groups`

Find-or-create: if the identifier already exists at Apple, the existing group is returned rather than a 409.

## Request body

- CreateAppGroupRequest
  - `identifier` string, required — The App Group identifier
  - `name` string, required

## Response `201`

App Group created or found

- AppGroupDTO
  - `id` string — Apple's app-group resource id.
  - `identifier` string — The App Group identifier
  - `name` string

## Other responses

- `400` — Missing or invalid parameters (plain-text reason in the body).
- `403` — Caller is anonymous / not authenticated.
- `409` — The account's App Store Connect API key is missing, was rejected by Apple (revoked, or the Key ID / Issuer ID do not match the .p8), or lacks the access this call needs. The developer has to fix the stored key -- retrying will not clear it. The body is a plain-text explanation written for them.
- `422` — The stored key is fine but Apple refused this particular request (for example "You already have a current Distribution certificate"). The body is a plain-text explanation, carrying Apple's own wording where Apple supplied it.
- `429` — Apple is rate-limiting App Store Connect requests for this team. Retrying after a pause is correct.
- `502` — App Store Connect is down or unreachable, so the call could not be completed. This is the only genuinely upstream failure and the only one worth retrying automatically; anything the developer must act on comes back as 409 or 422 instead.

## Changes

- **2026-08-19** `f0b48d0af96f` — 2 info
  - added the non-success response with the status `422`
  - added the non-success response with the status `429`
- **2026-07-13** `e1a39e5da408` — 1 info
  - endpoint added
- **2026-07-06** `745ddb8c0d15` — 1 breaking
  - api path removed without deprecation

[Change history](https://skmtc.dev/codenameone/apis/codename-one-apple-signing-service/changes/appsec/7.0/apple/app-groups/post.md)

---

[API](https://skmtc.dev/codenameone/apis/codename-one-apple-signing-service.md) · [All operations](https://skmtc.dev/codenameone/apis/codename-one-apple-signing-service/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/codenameone/codename-one-apple-signing-service/revisions/f0b48d0af96f/schema)
