Renew DEP / VPP Tokens

Apple DEP and VPP tokens have a maximum validity of 1 year and must be renewed regularly to ensure uninterrupted device management and app assignment. This guide explains how to easily renew these tokens.

DEP and VPP tokens are independent of each other: each token expires one year after its own creation. Therefore, only the token whose expiration is approaching is renewed.

Additionally, as of version 5.33, Relution provides a centralized overview of all connected DEP tokens. Administrators of the Global organization can see at a glance:

  • Which DEP tokens are valid or expired
  • When the respective tokens expire

Token Overview in the Relution Portal

The two token types are managed in different places in the portal.

Accessing DEP Accounts

To access the central overview of DEP accounts, follow these steps:

  1. Log in to the Global organization.
  2. Open Settings in the left sidebar.
  3. Navigate to the Device platform specific section.
  4. Select Apple Automated Device Enrollment.
  5. Open the All DEP accounts tab (available from version 5.33.0).

Accessing VPP Accounts

To access the overview of VPP accounts, follow these steps:

  1. Log in to the Global organization.
  2. Open Settings in the left sidebar.
  3. Navigate to the Volume Purchase Program section.
  4. Select User Account.
  5. Open the All VPP accounts tab (available from version 5.33.0).

Renewing VPP Tokens (Content Tokens)

The VPP token is first downloaded from Apple and then uploaded to Relution.

Download from Apple School Manager (ASM)

  1. The login takes place in Apple School Manager →.
  2. The logged-in user name in the bottom left corner is clicked.
  3. Settings is opened.
  4. Payments & Billing is selected.
  5. Under Content Tokens, the desired token is downloaded.
    • File format: sToken_for_[Location].vpptoken

Apple School Manager VPP Download

Download from Apple Business (formerly ABM)

  1. The login takes place in Apple Business →.
  2. The organization name in the top right corner is clicked.
  3. Settings is opened.
  4. Payments & Billing is selected.
  5. Under Content Tokens, Download is clicked for the desired token.
    • File format: sToken_for_[Location].vpptoken

Apple Business Manager VPP Download

Uploading to Relution

  1. Log in to the Relution portal and switch to the corresponding organization.
  2. Open Settings.
  3. Navigate to Volume Purchase Program (VPP) → User Account.
  4. Select the token to be renewed via the three-dot menu.
  5. Click Update token.
  6. Upload the previously downloaded file (*.vpptoken).
  7. Complete the process by clicking Update token.

Relution VPP Update Step 1

Relution VPP Update Step 2


Renewing DEP Tokens (Server Tokens)

For the DEP token, the public key certificate from Relution is required before the new token can be generated at Apple.

Download from Apple School Manager (ASM)

  1. The login takes place in Apple School Manager →.

  2. The logged-in user name in the bottom left corner is clicked.

  3. Settings is opened.

  4. In the list of device management services, the device management service connected to Relution is selected.

  5. The new token is downloaded via the corresponding button of the device management service.

    • File format: *_smime.p7m

Apple School Manager DEP Download

Download from Apple Business (formerly ABM)

  1. The login takes place in Apple Business →.
  2. Devices in the top center is clicked.
  3. In the left navigation, Management Services is selected.
  4. In the list of device management services, the desired service is selected.
  5. At the top right, the three-dot menu (…) is opened and the new token is downloaded from there.
    • File format: *_smime.p7m

Apple Business Manager DEP Overview

Apple Business Manager DEP Download

Uploading to Relution

  1. Log in to the Relution portal and switch to the corresponding organization.
  2. Open Settings.
  3. Navigate to Device platform specific → Apple Automated Device Enrollment.
  4. Select the desired token via the three-dot menu.
  5. Click Update token.
  6. Upload the *_smime.p7m file via Select file.
  7. Complete the process by clicking Save.

Relution DEP Update Step 1

Relution DEP Update Step 2


Important Notes & Troubleshooting

The following points are the most common causes of failed token renewals.

Common Errors

In practice, VPP tokens (.vpptoken) and DEP tokens (.p7m) are frequently mixed up and uploaded into the wrong menus. When this happens, Relution will trigger error messages such as Invalid Token or Uploaded file invalid.

File Extensions Overview

Token TypePurposeFile Extension
DEP TokenAutomated Device Enrollment*_smime.p7m
VPP TokenApp and book licenses (Volume Purchase Program)*.vpptoken
Public KeyEncryption certificate from Relution for ABM/ASM*.pem (Only required during initial setup)

Premature Token Invalidation

A token can become invalid before its regular 1-year expiration date. Common causes include:

  • Password Changes: The password of the underlying Managed Apple ID in ABM/ASM was changed.
  • Account Status Changes: The administrator account used to generate the token was deleted, deactivated, or downgraded in permissions.
  • New Apple Terms & Conditions: Apple has published updated terms of service in the ABM/ASM portal. Token communication is temporarily blocked until a main administrator accepts the new terms within the Apple portal.
Top