Keep getting "Invalid Token" error during ADE/ABM sync?Solved

Participant
Discussion
16 hours ago May 07, 2026

I’m running into a wall here and could use some help. I’m trying to get my Apple Business Manager (ABM) synced up with Hexnode for Automated Device Enrollment (ADE). But every single time I try to upload the ABM token into the Hexnode portal, the sync fails and it just throws an “Invalid Token” error at me. 

Is Apple generating bad tokens right now, or is my file corrupted? How do I get past this so I can actually start enrolling my devices? Appreciate y’all! 

Replies (1)

Marked SolutionPending Review
Hexnode Expert
5 hours ago May 08, 2026
Marked SolutionPending Review

Hi @bram, welcome to the community! 

Don’t worry, your file isn’t corrupted and Apple isn’t generating bad tokens.  

The “Invalid Token” error happens because there is a mismatch between the MDM server you are pulling the token from in Apple Business Manager and the specific account you have set up in Hexnode. If an enterprise has multiple MDM servers configured in ABM (which is very common), it’s easy to accidentally download the token from the wrong one. Hexnode immediately rejects it because the credentials don’t match its expected server profile. 

Here is the exact step-by-step to resolve this and get your sync working: 

Step 1: Verify the Server Name in Hexnode 

First, we need to see exactly which server Hexnode is looking for. 

  1. Log in to your Hexnode UEM portal. 

  1. Navigate to Admin > Apple Business Manager > ADE Accounts. 

  1. Look at your configured account and take note of the exact Server Name listed there. 

Step 2: Match the Server in Apple Business Manager 

Now, we need to go grab the token from that specific server in Apple’s portal. 

  1. Log in to your Apple Business Manager account. 

  1. Click on your profile at the bottom left and select Preferences, then go to MDM Servers (or simply select MDM Servers from the sidebar depending on your ABM interface layout). 

  1. Look through your list of servers and locate the one that exactly matches the Server Name you found in Hexnode. 

Step 3: Download and Upload the Correct Token 

  1. Click on that specific, matching MDM server in ABM. 

  1. Click Download Token to get the correct .p7m server token file. 

  1. Head back over to your Hexnode portal and upload this newly downloaded token. 

Once the correct token is uploaded, the mismatch will be resolved, and your ADE sync will process successfully. Let us know if you still run into any friction after matching up the servers! 

Save