DEP token renewal fails with "consumer key mismatch" error: re-download token from the original ABM MDM Server entry
iOS
Title: DEP token renewal fails with "consumer key mismatch" — download token from original ABM MDM Server entryWhen renewing a DEP token in the Esper Console, the upload fails with an error similar to DEP token consumer key mismatch: existing 'CK_fd4bc91041e76dc95ca001c7844dddda...' does not match new 'CK_137816f4d200e16ff1a3b929cfd6b74f...'. To use a different DEP account, delete the existing token first.
Why this happens
Every MDM Server entry in Apple Business Manager has a unique Consumer Key embedded in its token file. Esper records that Consumer Key when you first link your tenant to Apple Business Manager. If you download a renewal token from a different MDM Server entry — even one that looks identical — the Consumer Key will not match what Esper has on record, and the upload is rejected.
Steps
-
Identify the original MDM Server entry using the error message. The Consumer Key prefix shown in the error (for example,
CK_fd4bc9...) is unique to a single MDM Server entry. Note it before proceeding. - Log in to Apple Business Manager at business.apple.com using an account that has MDM Server management rights.
- Navigate to Settings → MDM Servers and locate the entry whose Consumer Key prefix matches the one in the error message. If you are unsure which entry is correct, compare the prefix against each entry by downloading and inspecting their tokens — do not upload a mismatched token to Esper.
-
Download a fresh token from that original MDM Server entry. This generates a new
.p7mfile containing the matching Consumer Key. - Open the Esper Console and navigate to Apple MDM Management for your tenant or group.
- Remove any expired or rejected token currently listed, then upload the token file downloaded in step 4. Removing the stale token first prevents a conflict during upload.
Verify: After upload, the token entry in Apple MDM Management should display a valid future expiry date and no error banner. DEP device assignments should sync within a few minutes.
If the original MDM Server entry has been deleted
If the MDM Server entry no longer exists in Apple Business Manager and cannot be recovered, you must delete the existing DEP token in Esper before uploading a token from a new entry.
Warning: Deleting the token permanently disassociates all devices currently enrolled under that DEP configuration. Coordinate with your team and confirm the impact before proceeding.
- Go to Apple MDM Management in the Esper Console and delete the existing DEP token.
- In Apple Business Manager, go to Settings → MDM Servers and create or select the replacement MDM Server entry, then download its token.
- Upload the new token to Apple MDM Management in the Esper Console.
- Re-assign your devices to the new MDM Server entry in Apple Business Manager so they appear under the updated DEP configuration.
Verify: The new token should display a valid expiry date in Apple MDM Management, and previously assigned devices should re-appear in your DEP device list after the next sync.
If this doesn't resolve it
If the consumer key mismatch error persists after following the steps above, contact Esper Support and provide:
- A screenshot of the MDM Servers page in Apple Business Manager showing the entry you downloaded the token from
- A screenshot of the Apple MDM Management screen in the Esper Console
- The full error message text copied from the Esper Console
Still need help?
If you continue to experience DEP token renewal issues after re-downloading the token, please submit a support ticket and include your ABM MDM Server entry details and the specific "consumer key mismatch" error message you're receiving.
Please sign in to leave a comment.
Comments
0 comments