Gideon resource library

Apple Business content token (VPP) troubleshooting guide

Diagnose expired or invalid Apple Business content tokens, license-sync failures, account changes, and management-service conflicts without disrupting managed app assignments.

Overview

Apple Business Manager became Apple Business in April 2026. The Volume Purchase Program was integrated years earlier, but many management platforms and support articles still use the terms VPP token, location token, server token, or sToken. In Apple's current terminology, the file used by an external device management service to communicate about app and book licenses is a content token.

A content-token problem affects communication about Apps and Books licenses and managed app assignments. It is separate from an Automated Device Enrollment token and the Apple Push Notification service certificate, even though all three may appear near one another in a device management console.

Where to download the current content token

  • Open Apple Business. Sign in at business.apple.com with a Managed Apple Account whose role can obtain and assign Apps and Books licenses.
  • Open the token area. In the browser interface, go to Settings > Payments & Billing, select Apps and Books, then download the content token for the intended external device management service or organizational unit.
  • Match the license pool. Confirm the organizational unit—or legacy location name shown by an existing MDM integration—matches the app licenses and existing token record you intend to renew.
  • Update the existing MDM record. Use the vendor's renewal or edit workflow to upload the downloaded token to the existing connector. Do not create a second connector merely because the file is new.

Before replacing or deleting anything

  • Record the current state. Capture the token name, external management service, organizational unit or legacy location, expiration date, Managed Apple Account, last successful sync, current error, and affected applications.
  • Preserve assignment evidence. Export or record app assignments and license counts where the management platform supports it. This is especially important before a management-service migration.
  • Identify the failing integration. Confirm whether the alert concerns the Apps and Books content token, the Automated Device Enrollment token, or the Apple Push Notification service certificate. Renewing one does not repair the others.
  • Avoid deleting the connector. Some MDM platforms associate applications, assignments, license state, and revocation capability with the existing token object. Renewal should update that object unless the vendor's documented migration procedure requires replacement.

Expired or invalid token

Apple states that content tokens become invalid one year after creation and when the password changes for the Managed Apple Account used to download the existing token. A management platform may also report the token as invalid after related account changes, such as a domain change, password expiration, or account disablement.

  • Download a fresh token. Use an authorized Managed Apple Account to download the current content token for the same external management service and organizational unit or legacy location.
  • Renew the existing connection. Upload the file through the existing token's edit or renewal workflow in the MDM console. For Microsoft Intune, update the existing Apple VPP token under Tenant administration > Connectors and tokens.
  • Verify the result. Confirm the MDM console shows the new expiration date, run or wait for a content sync, and verify that expected applications and license counts return without recreating assignments.
  • Use a dedicated account going forward. Apple recommends a dedicated Managed Apple Account with a custom role limited to the Apps and Books license permission for downloading and managing content tokens.

How to interpret authentication and vendor error messages

Error text varies by management platform. A generic HTTP 401 indicates an authentication failure, but it does not by itself distinguish an expired token, password-driven invalidation, a disabled account, a malformed upload, or a vendor-side connector problem. Numeric messages such as 9625 should be interpreted using the documentation for the MDM product that emitted them, not presented as universal Apple error codes.

  • Check token and account state together. Compare the token expiration date with recent password, domain, role, and account-status changes for the Managed Apple Account associated with token management.
  • Preserve the vendor message. Record the full error, timestamp, connector name, request or correlation identifier, and last successful synchronization before renewing.
  • Escalate persistent authentication failures. If a fresh token uploaded to the existing connector remains invalid, use the MDM vendor's token troubleshooting path before deleting the connector or transferring licenses.

Token already used by another management service

A content token should not be used concurrently by multiple external management services or separate MDM tenants. Reusing it can create inconsistent license inventory, assignment failures, or loss of user and license records.

  • Identify the active owner. Determine which production, test, regional, or legacy management service currently uses the token and which organizational unit or legacy location supplies its licenses.
  • Plan a controlled migration. Follow both Apple's and the destination vendor's migration sequence. Record assignments, remove the token from the source at the planned cutover, upload the appropriate token to the destination, and verify license inventory before changing application assignments.
  • Create separation at the license-pool level. If two management services must operate at the same time, use separate organizational units or legacy locations and intentionally transfer or acquire the required licenses for each pool. Do not reuse one token in both services.

Token uploads but applications do not sync

  • Confirm licenses exist in the selected pool. Verify that the applications were acquired in Apps and Books and assigned to the organizational unit or legacy location represented by the content token. A valid but empty pool can synchronize successfully without displaying applications.
  • Check synchronization behavior. Some MDM platforms synchronize automatically on a schedule and also provide a manual sync action. For example, Intune synchronizes location tokens daily by default and allows an administrator to start a manual sync.
  • Verify the existing connector was renewed. If a second connector was accidentally created, the expected assignments may still belong to the original token record. Compare token identity, location or organizational unit, and assigned applications before moving anything.
  • Review app availability and assignment. Confirm the application remains available in the relevant country or region, sufficient licenses exist, and the device or user assignment is still active in the MDM platform.
  • Use vendor logs for the next step. If license inventory is correct but synchronization still fails, inspect the management platform's connector status and synchronization logs rather than repeatedly downloading new token files.

Symptom-based decision path

SymptomCheck firstSafest next action
Token is expired or invalidExpiration and Managed Apple Account changesDownload the matching token and update the existing connector
Authentication or 401 errorFull vendor error, account state, and token expirationRenew in place; use vendor troubleshooting if it remains invalid
Token is already in useCurrent MDM tenant or service using the tokenPlan a controlled migration or separate the license pools
Upload succeeds but no apps appearOrganizational unit or legacy location and acquired licensesRun a sync and verify the token represents the expected pool
Apps appear but assignments failAvailable license count and assignment stateCorrect license or assignment state without replacing the token
Device enrollment failsADE token, APNs certificate, profile, and network pathTroubleshoot enrollment separately from the content token

Before the next renewal cycle

  • Assign durable ownership. Use a dedicated Managed Apple Account rather than a personal administrator account, document the account owner and recovery process, and grant only the permissions required to manage Apps and Books licenses.
  • Track expiration independently. Record the token expiration in the team's operational calendar or monitoring system and create reminders early enough to renew and verify before the one-year deadline.
  • Add account changes to the runbook. Require a content-token check after password, domain, role, or account-status changes affecting the Managed Apple Account used for token management.
  • Test the full outcome. A successful upload is not enough. Verify the updated expiration, a completed catalog sync, expected license counts, and at least one representative managed-app assignment.

Related resources

Primary references

How to use this resource

Use this runbook when app licenses stop synchronizing, a token approaches expiration, or an MDM migration exposes a token conflict. Preserve the existing connector and assignment state, identify the exact token and license pool, renew in place when possible, and define success as a verified catalog sync with expected license counts and working assignments.

Back to topic hub