> ## Documentation Index
> Fetch the complete documentation index at: https://docs.stackone.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect Apple Business Manager with OAuth 2.0 (Client Assertion) – StackOne Hub

> Link a Apple Business Manager account in the StackOne Hub using OAuth 2.0 (Client Assertion). End-user guide to authorize the integration and start using Apple Business Manager actions.

<Warning>Only an Apple Business user with the Organization Administrator role can create an API account, and the client assertion must be re-signed and re-entered before its expiry date or every call starts failing.</Warning>

<section data-guide-section data-guide-scopes="">
  <h2>Create an API account</h2>

  <p>Create an API account in Apple Business. Apple generates the key pair and gives you the private key to download.</p>

  <Steps>
    <Step title="Open API accounts">
      <div data-guide-step data-guide-scopes="" data-guide-display-scopes-list="">
        <p>Sign in to <a href="https://business.apple.com" target="_blank" rel="noopener noreferrer">Apple Business</a> with a user who has the Organization Administrator role, choose <strong>Settings</strong>, then <strong>API</strong>.</p>
      </div>
    </Step>

    <Step title="Add the account">
      <div data-guide-step data-guide-scopes="" data-guide-display-scopes-list="">
        <p>Select <strong>Add API Account</strong>, enter a name such as `StackOne`, select its role, then select <strong>Next</strong>.</p>
      </div>
    </Step>

    <Step title="Download the private key">
      <div data-guide-step data-guide-scopes="" data-guide-display-scopes-list="">
        <p>Select <strong>Generate & Download</strong> to generate and download the key. The key's filename ends in `.pem`, and you generate it only once.</p>
      </div>
    </Step>

    <Step title="Copy the client id">
      <div data-guide-step data-guide-scopes="" data-guide-display-scopes-list="">
        <p>Select <strong>Edit</strong> on the API account to view its <strong>Client ID</strong> and <strong>Key ID</strong>.</p>
      </div>
    </Step>
  </Steps>
</section>

<section data-guide-section data-guide-scopes="">
  <h2>Sign a client assertion</h2>

  <p>Apple's OAuth implementation guide includes a Python script that signs a client assertion JWT (ES256) from the downloaded private key.</p>

  <Steps>
    <Step title="Run the sample script">
      <div data-guide-step data-guide-scopes="" data-guide-display-scopes-list="">
        <p>Follow the sample script on <a href="https://developer.apple.com/documentation/apple-school-and-business-manager-api/implementing-oauth-for-the-apple-school-manager-and-apple-business-api" target="_blank" rel="noopener noreferrer">Apple's OAuth implementation guide</a>, passing your client id, key id and downloaded private key. Choose an expiry up to 180 days out.</p>

        <ul>
          <li>The script prints a signed JWT string. Copy it in full.</li>
        </ul>
      </div>
    </Step>
  </Steps>
</section>

<div data-whitelabel-hide>
  <h2>Linking the Account from the Hub</h2>

  <Steps>
    <Step title="Navigate to the Hub">
      Use one of the three <a href="/connect/managing-connectors/linking-accounts">Linking Account Methods</a> to access the Hub.
    </Step>

    <Step title="Fill out the fields">
      Fill out the following fields using details from your provider:

      <ul>
        <li><strong>Client ID</strong></li>
        <li><strong>Client Assertion</strong></li>
      </ul>
    </Step>

    <Step title="Connect">
      <ul>
        <li>Click <strong>Connect</strong></li>
        <li>If applicable, the provider will redirect you to a sign-in or authorization page. Complete the provider's authorization flow.</li>
        <li>Once authorization is successful, you will see a confirmation popup</li>
      </ul>
    </Step>
  </Steps>

  <p>If the account linking is successful, you will see the newly linked account in your <a href="/gateway/concepts/linked-accounts">Accounts</a> page.</p>
</div>
