Skip to main content
Only an Apple Business user with the Organization Administrator role can create an API account, and the client assertion must be re-signed and re-entered before its expiry date or every call starts failing.

Create an API account

Create an API account in Apple Business. Apple generates the key pair and gives you the private key to download.

1

Open API accounts

Sign in to Apple Business with a user who has the Organization Administrator role, choose Settings, then API.

2

Add the account

Select Add API Account, enter a name such as StackOne, select its role, then select Next.

3

Download the private key

Select Generate & Download to generate and download the key. The key’s filename ends in .pem, and you generate it only once.

4

Copy the client id

Select Edit on the API account to view its Client ID and Key ID.

Sign a client assertion

Apple’s OAuth implementation guide includes a Python script that signs a client assertion JWT (ES256) from the downloaded private key.

1

Run the sample script

Follow the sample script on Apple’s OAuth implementation guide, passing your client id, key id and downloaded private key. Choose an expiry up to 180 days out.

  • The script prints a signed JWT string. Copy it in full.

Linking the Account from the Hub

1

Navigate to the Hub

Use one of the three Linking Account Methods to access the Hub.
2

Fill out the fields

Fill out the following fields using details from your provider:
  • Client ID
  • Client Assertion
3

Connect

  • Click Connect
  • If applicable, the provider will redirect you to a sign-in or authorization page. Complete the provider’s authorization flow.
  • Once authorization is successful, you will see a confirmation popup

If the account linking is successful, you will see the newly linked account in your Accounts page.