Product1 distinct publisher3 min readUpdated
The expanded API can pull inventory and audit events and assign devices. The 403 error most admins hit first is a permissions problem, and Apple's own docs do not close the gap.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
The expanded API can pull inventory and audit events and assign devices. The 403 error most admins hit first is a permissions problem, and Apple's own docs do not close the gap.
Apple used this year's WWDC to announce an expanded Apple Business API that lets IT admins retrieve device information, review audit events, and assign or unassign devices directly through the API [1]. The endpoints are what large fleets have asked for; the part generating friction is the permission model behind them, which developers have reported is frustrating to configure properly [2].
The failure mode is specific and repeatable. According to 9to5Mac's Apple @ Work column, written by Bradley Chambers, an Apple IT admin since 2009 [14], testers calling the Audit Events API are likely to get a 403 Forbidden, with a message stating that the API key in use does not allow the request [3]. The call is not malformed. The API account simply lacks the permission. Apple's documentation does say, in its data access section, that you need permission to access audit events via the Admin API, but per the same report it is not clear how to apply that permission to your account [4]. That is the whole gap: a documented requirement with an undocumented path.
The fix lives in Settings > Roles and Permissions, where you adjust the permissions on the API account, and where a custom role can be based on an existing role with permissions added rather than built from nothing [5]. The default roles are IT Administrator, Marketing Administrator, People Manager, Device Enrollment Manager, and Content Manager [6], five in total [7], and checking every individual organization permission attached to each one is tedious [8].
Two ceilings deserve attention before anyone writes automation against this. An organization can have up to 50 API accounts and create up to 15 custom roles [9]. That works out to roughly 3.3 API accounts per custom role if all fifteen are used [10], so one bespoke least-privilege role per integration is not on the table; roles will be shared across accounts, and that mapping is a design decision rather than something to discover later. The second is a governance detail with wider blast radius: any user who can view, edit, and delete roles can change specific permissions for all default roles [11]. The meaning of IT Administrator in a given tenant is therefore mutable, and one edit reaches everyone holding it.
The documentation gap is currently being filled from outside Apple. AppleShare IT built a web tool, the Apple Business Roles Checker, using Claude to turn Apple's large default roles and permissions document into a wizard-style checklist [12]. An admin selects the organization permissions the API account needs, and the tool identifies which default role already covers them, or shows how to customize an existing role if none does [13].
Worth watching: whether Apple documents the path from the stated audit-events requirement to an actual API account configuration [4], since every day it does not is a day the community tool is load-bearing infrastructure for other people's deployments [12]. Also worth watching is whether the 50-account and 15-custom-role limits hold as more automation moves onto this API [9], and whether editing default roles globally [11] starts showing up in audit findings rather than support threads.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Properly configuring the API can be frustrating, according to reports from developers cited by 9to5Mac.
When testing the new APIs, it has been reported that you are likely to encounter a 403 Forbidden error when using the Audit Events API, with the API returning a message stating that the currently used API key does not allow the request.
At this year's WWDC, Apple announced an expanded Apple Business API that allows IT admins to retrieve device information, review audit events, and assign or unassign devices directly via the API.
Apple's documentation for creating an API account in Apple Business says in its data access section that you need permission to access audit events via the Admin API, but it is not clear how to apply that same permission to your account.
To fix the 403 error you adjust the permissions on the API account; custom roles are created or edited under Settings > Roles and Permissions, and a custom role can be based on an existing role with permissions added.
The default Apple Business Manager roles include IT Administrator, Marketing Administrator, People Manager, Device Enrollment Manager, and Content Manager.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single-source practitioner report
Every assertion comes from one publisher's column. The API capabilities, the documented ceilings, and the roles list are attributed to Apple's own documentation and are specific and checkable, which raises credibility. But the central failure mode is relayed second-hand ('it's been reported'), there is no reproduction transcript, version, or date for the 403 behavior, no Apple comment, and no corroborating outlet in the cluster.
Shipped, usage anecdotal
Two real releases are observable: Apple's expanded Business API and AppleShare IT's Roles Checker web tool. Beyond that, adoption evidence is anecdotal, limited to unnamed developers reporting 403 errors while testing. No organization counts, download or traffic figures, MDM vendor integrations, or deployment disclosures for the API are supplied, and the sponsor's customer count is marketing copy about a separate product rather than API adoption.
Mildly overstated enthusiasm
The practical content is measured and largely verifiable, so the gap is small. It tilts slightly positive because the column calls the API 'fantastic' and 'incredibly powerful' for large-fleet automation and endorses a third-party tool as '100% worth bookmarking' without any accuracy, maintenance, or trust review, while the underlying evidence for both the failure mode and any usage remains anecdotal and single-sourced.
Sponsored vendor-adjacent column
The column is bracketed top and bottom by identical Mosyle sponsor copy ('exclusively brought to you by Mosyle', 'Over 45,000 organizations', extended-trial call to action) for an Apple device-management platform that directly benefits from enthusiasm about Apple enterprise management APIs. The author is a practicing Apple IT admin, which grounds the guidance but also aligns him with the MacAdmins community whose tool he promotes. Sponsorship is disclosed openly, which moderates the score; no compensation link to AppleShare IT is asserted or evidenced.
Moderate
Confidence is moderate: the story's mechanics are internally consistent, specific, and typical of documented Apple Business Manager behavior, and the operational advice is actionable. It is held down by the single-publisher cluster, the second-hand sourcing of the 403 failure, the absence of Apple or independent confirmation, and the sponsored context around the reporting.
product
Siri gets its own Mac app, and with it a surface your software has to answer to1 distinct publisher
product
Apple cuts at least 60 Vision roles, and the visionOS roadmap gets harder to underwrite1 distinct publisher
product
Memory-cost inflation is now shrinking smartphone demand, and moving share while it does1 distinct publisher
product
Apple tells regulators it may collect nothing on third-party store sales1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 15, 2026