Skip to content

Create a Google Web Token
Stable

Request

Creates a Google Web Token for embedding the Console Google Play Store.

Generates a web token scoped to the tenant's Google Enterprise, used to render the Console Google Play Store UI at the specified parent_url.

About Google EMM Web Token Google requires a short-lived web token to securely embed its managed Play Store UI (what Esper calls the Console Google Play Store) inside a parent web page. This endpoint generates that token for a given Google Enterprise binding.

Key Fields / Query Parameters

  • google_enterprise_id — Required — ID of the Google enterprise the token is scoped to
  • parent_url — Required — must be a valid HTTPS URL; the page that will embed the Console Google Play Store using this token

Common Use Cases

  • Embedding the Console Google Play Store inside a custom admin portal
  • Refreshing an expired web token to keep an embedded Play Store view working
  • Building a custom app-approval workflow that surfaces the managed Play Store UI

Best Practices

  • Always use HTTPS for parent_url, since Google validates the scheme
  • Treat the returned token as short-lived — regenerate it rather than caching indefinitely
  • Confirm the google_enterprise_id corresponds to a fully enrolled Google Enterprise before requesting a token

Workflow

  1. Confirm the tenant's Google EMM enrollment is complete (GET /v2/emm/details/)
  2. POST the google_enterprise_id and parent_url to this endpoint
  3. Use the returned token to render the Console Google Play Store iframe/embed at parent_url
Headers
Authorizationstringrequired

Bearer token for authorization

Bodyapplication/jsonrequired
google_enterprise_idstring, non-emptyrequired

The ID of the Google enterprise. It is required and cannot be empty.

Example:"test"
parent_urlstring, (uri)^https://required

The parent URL. It must be a valid URL with the https scheme.

Example:"https://valid.url"
cURL
curl -i -X POST \
  https://develop-api.esper.io/_mock/openapi/v2/emm/web-token/ \
  -H 'Authorization: string' \
  -H 'Content-Type: application/json' \
  -d '{
    "google_enterprise_id": "test",
    "parent_url": "https://valid.url"
  }'

Responses

Successful Response

Bodyapplication/json
tokenstring

The generated token.

Example:"test_1245"
Response
{ "token": "test_1245" }