How to renew a VPP sToken

Purpose

The Apps and Books / VPP sToken allows Workspace ONE UEM to sync Apple-purchased app and book licenses and assign them to users or devices.

Apple now refers to these as content tokens in Apple Business. Apple states that content tokens become invalid one year after creation or when the password changes for the Managed Apple Account used to download the token. When a content token becomes invalid, app and book license communication between Apple Business and the external device management service stops.

Apple Business Steps

  1. Open Apple Business.
  2. Sign in with an account that has permissions to get licenses for Apps and Books.
  3. Go to:
Settings > Payments & Billing
  1. Select:
Apps & Books
  1. Download the content token for the correct location / organizational unit / device management service.

Apple’s current guidance lists the content token download path as Settings > Payments & Billing > Apps & Books > Download.

Workspace ONE UEM Steps

  1. Log in to the Workspace ONE UEM Console.
  2. Confirm you are in the correct Organization Group.
  3. Go to:
Groups & Settings > All Settings > Devices & Users > Apple > VPP Managed Distribution

Omnissa’s current Workspace ONE UEM documentation states that VPP Managed Distribution uses service tokens, also called sTokens, and that this page is located under Groups & Settings > All Settings > Devices & Users > Apple > VPP Managed Distribution.

  1. Upload the newly downloaded sToken/content token.
  2. Confirm the correct:
Description / VPP account ID
Country / region
Token file
  1. Save the change.
  2. Sync purchased apps and licenses as appropriate.

Validation

Confirm:

- VPP / Apps and Books token expiration date is updated.
- Purchased apps are visible in Workspace ONE UEM.
- License counts sync successfully.
- Assigned apps remain available to targeted users/devices.
- No Apps and Books / VPP authentication or token expiration errors are present.

Last modified: Friday, 10 July 2026, 8:06 PM