---
title: "Create a provisioning profile"
method: POST
path: "/appsec/7.0/apple/profiles"
tags: ["Profiles"]
---

# Create a provisioning profile

`POST /appsec/7.0/apple/profiles`

## Request body

- CreateProfileRequest
  - `name` string, required
  - `profileType` 'IOS_APP_DEVELOPMENT' | 'IOS_APP_STORE' | 'IOS_APP_ADHOC' | 'MAC_APP_DEVELOPMENT' | 'MAC_APP_STORE' | 'MAC_APP_DIRECT' | 'MAC_CATALYST_APP_DEVELOPMENT' | 'MAC_CATALYST_APP_STORE' | 'MAC_CATALYST_APP_DIRECT', required
  - `bundleIdAppleId` string, required — Apple's bundle-id resource id (not the reverse-DNS string).
  - `certificateIds` string[], required — Apple certificate resource ids to embed.
  - `deviceIds` string[], nullable — Apple device resource ids (development / ad-hoc profiles only).

## Response `201`

Profile created

- ProfileDTO
  - `id` integer
  - `appleProfileId` string, nullable
  - `name` string
  - `profileType` string
  - `bundleId` string — Reverse-DNS bundle identifier (best-effort; falls back to Apple's resource id).
  - `uuid` string, nullable
  - `expiresAt` integer, nullable
  - `status` string

## Other responses

- `400` — Missing or invalid parameters (plain-text reason in the body).
- `403` — Caller is anonymous / not authenticated.
- `409` — The account's App Store Connect API key is missing, was rejected by Apple (revoked, or the Key ID / Issuer ID do not match the .p8), or lacks the access this call needs. The developer has to fix the stored key -- retrying will not clear it. The body is a plain-text explanation written for them.
- `422` — The stored key is fine but Apple refused this particular request (for example "You already have a current Distribution certificate"). The body is a plain-text explanation, carrying Apple's own wording where Apple supplied it.
- `429` — Apple is rate-limiting App Store Connect requests for this team. Retrying after a pause is correct.
- `502` — App Store Connect is down or unreachable, so the call could not be completed. This is the only genuinely upstream failure and the only one worth retrying automatically; anything the developer must act on comes back as 409 or 422 instead.

## Changes

- **2026-08-19** `f0b48d0af96f` — 2 info
  - added the non-success response with the status `422`
  - added the non-success response with the status `429`

[Change history](https://skmtc.dev/codenameone/apis/codename-one-apple-signing-service/changes/appsec/7.0/apple/profiles/post.md)

---

[API](https://skmtc.dev/codenameone/apis/codename-one-apple-signing-service.md) · [All operations](https://skmtc.dev/codenameone/apis/codename-one-apple-signing-service/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/codenameone/codename-one-apple-signing-service/revisions/f0b48d0af96f/schema)
