-
Notifications
You must be signed in to change notification settings - Fork 6
Setup Tab
The Setup tab configures everything the app needs before running a sync. All secrets are stored in the macOS Keychain and never written to disk in plain text. In v2.0 each environment has its own isolated credential store.
Choose Apple Business Manager (ABM) or Apple School Manager (ASM).
The account type is set automatically when you save credentials — you do not need to choose it when creating a new environment. The sidebar label and section heading update immediately when you tap either button.
The account type is locked while credentials are saved in Keychain or device data is cached. To switch, clear credentials using the Clear button and delete the cache in Cache Settings first.
If the displayed account type does not match your credentials after upgrading from v2.0, it is corrected automatically on next launch. The app reads the account type from the Keychain scope key, the clientId prefix (
SCHOOLAPI/BUSINESSAPI), or the scope of data already in cache — whichever is available.
The Client ID from your ABM/ASM API key. Found at Settings → API → [key name] → Client ID.
The Key ID for your API key — used in the JWT header. Found on the same API key detail page.
The secret key file Apple generated when you created the API key.
- Click Choose… and select your
.p8or.pemfile - Content is read once and stored in Keychain — the file path is not saved
- The file is not needed on disk after saving to Keychain
Status indicators (v2.4): the pill next to the file picker now also shows a masked version of your Key ID (e.g. AUTHKEY_X…7L2K), so it's clear which key is currently active if you've ever loaded more than one:
- 🔒 Loaded from Keychain · AUTHKEY_X…7L2K — ready
- 📄 Loaded from file · AUTHKEY_X…7L2K — loaded this session
- (no key) — choose a file before syncing
Apple only lets you download the
.p8file once. If lost, delete the key in ABM/ASM and create a new one.
There's no "Save to Keychain" checkbox anymore — Client ID, Key ID, and private key save to the Keychain automatically, about half a second after you stop typing, and again the moment Test Auth succeeds. A status line under the fields tells you what actually happened:
-
Saved to Keychain · Verified
<relative time>— credentials are saved and the last Test Auth succeeded - Saved to Keychain · Not verified — saved, but Test Auth hasn't been run (or last failed) this session
- Not saved yet — nothing has been typed yet in this environment
Clear — removes all ABM/ASM credentials for this environment from Keychain and blanks the fields.
Sends a real authentication request to Apple's token endpoint. Green ✓ means ready to sync. Also saves your credentials immediately, so you don't need to wait for the debounce before testing.
Base URL of your Jamf Pro server, no trailing slash. Examples:
https://yourcompany.jamfcloud.com
https://jamf.internal.example.com:8443
OAuth2 credentials from Jamf Pro → Settings → API Roles and Clients.
Records per API call — a segmented control (500 / 1000 / 1500 / 2000; a slider pre-v2.4). Default 1000. Reduce to 500 if you see timeouts in the sync log during Step 2.
Jamf credentials save automatically too, the same way Apple's do — see "Saving credentials" above.
Shows the exact permissions needed:
| Permission | Used for |
|---|---|
| Read Computers | Mac inventory (Step 2) |
| Read Mobile Devices | iPad/iPhone/Apple TV inventory (Step 2) |
| Update Computers | Write warranty to Macs (Step 4) |
| Update Mobile Devices | Write warranty to mobile devices (Step 4) |
Controls which device types are included in coverage fetch and Jamf write-back. The Apple org devices fetch always runs in full.
| Option | Coverage & Write-back |
|---|---|
| Mac + Mobile | All devices (default) |
| Mac Only | Macs only |
| Mobile Only | iPhone, iPad, Apple TV only |
Cached data for unselected types is kept but not refreshed until included again.
How long the downloaded device list stays valid. Default 1 day. Set to 0 to always re-fetch. Overridden by Force Refresh Devices.
How long coverage results stay valid. Default 7 days. Set to 0 to always re-check. Overridden by Do Not Refetch or Force Refresh Coverage.
Forces the next sync to re-download all device records, even if cache is fresh. Resets automatically after the sync.
Forces the next sync to re-check all devices' coverage from scratch. Resets automatically after the sync.
Caps coverage API calls per run. 0 = no limit. Next run resumes from where the last stopped — useful for large fleets to spread Apple API load across multiple runs.
When on (recommended), devices that already have any coverage result are skipped. Only .notFetched devices are checked. Dramatically reduces Apple API calls on repeat syncs.
Shows the path to this environment's SQLite database. Click the folder icon to open in Finder.
In v2.0 each environment has its own file:
~/Library/Containers/com.karthikmac.axmjamfsync/Data/Library/
Application Support/AxM Jamf Sync/environments/{uuid}.sqlite
Wipes all device records and clears sync timestamps for this environment. Credentials are not affected. The next sync re-downloads everything from scratch.