Skip to content

Setup Tab

Karthikeyan Marappan edited this page Sep 11, 2026 · 6 revisions

Setup Tab — Credentials & Settings

The Setup tab configures everything the app needs before running a sync. All secrets are stored in the macOS Keychain and never written to disk in plain text. In v2.0 each environment has its own isolated credential store.


Apple Manager section

Account Type

Choose Apple Business Manager (ABM) or Apple School Manager (ASM).

The account type is set automatically when you save credentials — you do not need to choose it when creating a new environment. The sidebar label and section heading update immediately when you tap either button.

The account type is locked while credentials are saved in Keychain or device data is cached. To switch, clear credentials using the Clear button and delete the cache in Cache Settings first.

If the displayed account type does not match your credentials after upgrading from v2.0, it is corrected automatically on next launch. The app reads the account type from the Keychain scope key, the clientId prefix (SCHOOLAPI/BUSINESSAPI), or the scope of data already in cache — whichever is available.


Client ID

The Client ID from your ABM/ASM API key. Found at Settings → API → [key name] → Client ID.


Key ID

The Key ID for your API key — used in the JWT header. Found on the same API key detail page.


Private Key (.p8 / .pem)

The secret key file Apple generated when you created the API key.

  1. Click Choose… and select your .p8 or .pem file
  2. Content is read once and stored in Keychain — the file path is not saved
  3. The file is not needed on disk after saving to Keychain

Status indicators (v2.4): the pill next to the file picker now also shows a masked version of your Key ID (e.g. AUTHKEY_X…7L2K), so it's clear which key is currently active if you've ever loaded more than one:

  • 🔒 Loaded from Keychain · AUTHKEY_X…7L2K — ready
  • 📄 Loaded from file · AUTHKEY_X…7L2K — loaded this session
  • (no key) — choose a file before syncing

Apple only lets you download the .p8 file once. If lost, delete the key in ABM/ASM and create a new one.


Saving credentials (v2.4: automatic)

There's no "Save to Keychain" checkbox anymore — Client ID, Key ID, and private key save to the Keychain automatically, about half a second after you stop typing, and again the moment Test Auth succeeds. A status line under the fields tells you what actually happened:

  • Saved to Keychain · Verified <relative time> — credentials are saved and the last Test Auth succeeded
  • Saved to Keychain · Not verified — saved, but Test Auth hasn't been run (or last failed) this session
  • Not saved yet — nothing has been typed yet in this environment

Clear — removes all ABM/ASM credentials for this environment from Keychain and blanks the fields.


Test Auth

Sends a real authentication request to Apple's token endpoint. Green ✓ means ready to sync. Also saves your credentials immediately, so you don't need to wait for the debounce before testing.


Jamf Pro section

Jamf URL

Base URL of your Jamf Pro server, no trailing slash. Examples:

https://yourcompany.jamfcloud.com
https://jamf.internal.example.com:8443

Client ID / Client Secret

OAuth2 credentials from Jamf Pro → Settings → API Roles and Clients.

Page Size

Records per API call — a segmented control (500 / 1000 / 1500 / 2000; a slider pre-v2.4). Default 1000. Reduce to 500 if you see timeouts in the sync log during Step 2.

Jamf credentials save automatically too, the same way Apple's do — see "Saving credentials" above.

API Privileges Required

Shows the exact permissions needed:

Permission Used for
Read Computers Mac inventory (Step 2)
Read Mobile Devices iPad/iPhone/Apple TV inventory (Step 2)
Update Computers Write warranty to Macs (Step 4)
Update Mobile Devices Write warranty to mobile devices (Step 4)

Sync Options section

Sync Device Types (Added in v1.2)

Controls which device types are included in coverage fetch and Jamf write-back. The Apple org devices fetch always runs in full.

Option Coverage & Write-back
Mac + Mobile All devices (default)
Mac Only Macs only
Mobile Only iPhone, iPad, Apple TV only

Cached data for unselected types is kept but not refreshed until included again.


Device Cache (days)

How long the downloaded device list stays valid. Default 1 day. Set to 0 to always re-fetch. Overridden by Force Refresh Devices.

Coverage Cache (days)

How long coverage results stay valid. Default 7 days. Set to 0 to always re-check. Overridden by Do Not Refetch or Force Refresh Coverage.

Force Refresh Devices

Forces the next sync to re-download all device records, even if cache is fresh. Resets automatically after the sync.

Force Refresh Coverage

Forces the next sync to re-check all devices' coverage from scratch. Resets automatically after the sync.

Coverage Fetch Limit

Caps coverage API calls per run. 0 = no limit. Next run resumes from where the last stopped — useful for large fleets to spread Apple API load across multiple runs.

Do Not Refetch Cached Warranty

When on (recommended), devices that already have any coverage result are skipped. Only .notFetched devices are checked. Dramatically reduces Apple API calls on repeat syncs.


Cache Settings section

Cache Location

Shows the path to this environment's SQLite database. Click the folder icon to open in Finder.

In v2.0 each environment has its own file:

~/Library/Containers/com.karthikmac.axmjamfsync/Data/Library/
  Application Support/AxM Jamf Sync/environments/{uuid}.sqlite

Delete Cache

Wipes all device records and clears sync timestamps for this environment. Credentials are not affected. The next sync re-downloads everything from scratch.

Clone this wiki locally