Getting started with the API
Start with the ABMDM API: create a key, list devices, send lock and unlock, receive webhooks. The screens may change; call for a walkthrough.

The API connects software you already run
ABMDM has an API and event webhooks in the automation group on features. Use them when the shop already has accounting, inventory or instalment software and wants to send lock/unlock commands and receive device events without opening the dashboard every time.
Do not use the API for all-day location tracking, reading on-device content, or stripping MDM. Only devices the business owns or has written consent for.
The screens may change; call 0913 081 986 for a live walkthrough.
Create a key and make a test call
Do this in order, without a specific button name or invented endpoint path:

- Create an API key in organisation settings and store it where only the technical lead can read it.
- Make a test call to list devices — only serials in your organisation.
- Send lock, then unlock, to a test device and match the dashboard log.
- Register a webhook URL to receive device events.
- Trigger one event (lock, unlock, overdue) and confirm your software received it.
- Do not share the API key with counter staff accounts.
Parameter details live in the API docs inside the account. This page does not invent endpoint names.
Device-management background: what MDM is. Seat pricing: pricing.
Webhooks and safety
A webhook is your server address for notices when a device locks, unlocks, goes overdue or leaves management. Keep that address on HTTPS and check the event source as the current docs describe.
Revoke keys when a technical staff member leaves. Do not put keys in public source code.
What the API will not do
It will not read messages, photos or passwords. It will not strip MDM. It will not watch location all day — location is sensitive, Lost Mode or overdue only, with a log, including when the call comes through the API.
Do not invent command paths in your code and then blame the docs. Read the in-account documentation, test on a trial device, then connect live software.
Treat an API key like an admin password: revoke it when the technical lead leaves, do not commit it to public git, do not paste it in a group chat.
Prices: pricing. Automation group: features.
Use a test device before live software
Pick a trial iPhone, not a customer instalment unit. Send lock, unlock, match the log. Point the webhook at a test environment, not the accounting server that is already live.
When that is stable: change the webhook URL, narrow who knows the API key, record the names. A wrong command on a customer phone costs more than waiting one day to connect the API.
The screens may change; call 0913 081 986 for a live walkthrough (8am–9pm).
All guides · How to register for Apple Business · Connect Apple Business to ABMDM · Add a retail iPhone with Configurator
Frequently asked questions
What can the ABMDM API do?
Send commands and receive device events from your own software — list devices, lock, unlock, webhooks. Command details live in the in-account docs. Screens may change.
Do we need the Professional plan to use the API?
API and webhooks sit in the automation group on the features page. Choose a plan by device count and support needs; see pricing or call 0913 081 986.
Can the API read messages on a device?
No. Apple’s protocol does not allow reading messages, photos or passwords. The API does not open that data.
What if we lose an API key?
Revoke the old key, create a new one, and update your software. Do not send keys in a group chat.
Are the API-key screens in ABMDM fixed?
The screens may change; call 0913 081 986 for a live walkthrough.
Want advice tailored to how you operate?
Call 0913 081 986 (8am–9pm, every day) or leave your details and we will call you back.