Skip to main content

How to Use Extension Attribute Placeholders in Command Scripts

Swif allows you to run flexible MDM command scripts across multiple devices by using Extension Attribute Placeholders. Instead of hardcoding values or creating separate scripts for every device, you can use placeholders that Swif automatically resolves at execution time using each device's unique metadata.

Overview

When you execute a script, Swif identifies placeholders using the {{Device.extensionAttributes.KEY}} syntax and replaces them with the actual values stored in that device's extension attributes. This functionality is powered by the new command endpoint, which processes the deviceContexts for each target.

This is particularly useful for:

  • Deploying unique configuration files: Such as WireGuard or VPN configs where each device needs a unique key.

  • Passing device-specific credentials: Injecting unique passwords or tokens securely.

  • Customizing scripts: Tailoring execution based on hardware specs, asset tags, or ownership.

Prerequisites

  • Extension Attributes: You must have extension attributes defined and populated for your target devices.

  • MDM Access: Permissions to create and run MDM command templates.


How to Set Up Placeholders

Step 1: Define Your Placeholders

In your shell script, use the double-curly brace syntax {{Device.extensionAttributes.ATTRIBUTE_NAME}} to represent the value you want to inject.

Example Script:

# A script to set a unique asset tag on the device

echo "Setting asset tag to {{Device.extensionAttributes.ASSET_TAG}}"
/usr/local/bin/my-tool --set-tag {{Device.extensionAttributes.ASSET_TAG}}

Step 2: Populate Device Attributes

Ensure the devices you are targeting have the corresponding attribute set. For example, if your script uses {{Device.extensionAttributes.ASSET_TAG}}:

  • Device A might have ASSET_TAG: "SWIF-001"

  • Device B might have ASSET_TAG: "SWIF-002"

Step 3: Execute the Command

When you run the command via the Swif dashboard or API, the backend automatically fetches the deviceContexts for each target device.

  • Device A will execute: echo "Setting asset tag to SWIF-001"

  • Device B will execute: echo "Setting asset tag to SWIF-002"

  • Devices without the attribute will retain the literal placeholder string (e.g., {{Device.extensionAttributes.ASSET_TAG}}) to prevent accidental execution with empty values.

Advanced Usage: WireGuard Example

A common use case is deploying WireGuard configurations where each device requires a unique PrivateKey.

Command Template Script:

cat <<EOF > /etc/wireguard/wg0.conf
[Interface]
PrivateKey = {{Device.extensionAttributes.WG_PRIVATE_KEY}}
Address = 10.0.0.2/32
DNS = 1.1.1.1
EOF

By setting the WG_PRIVATE_KEY extension attribute for each device, you can deploy this single template to your entire fleet securely.

Verification & Platform Support

This command flow and placeholder resolution work consistently across macOS, Windows, and Linux.

To verify resolution:

  1. Run a simple test script: echo "{{Device.extensionAttributes.YOUR_ATTRIBUTE}}"

  2. Check the Command Logs in the Swif dashboard.

  3. The output should show the resolved value rather than the placeholder brackets.

Tips

  • UI Integrity: Placeholders remain literal in the Swif UI to ensure no premature resolution occurs before the script reaches the device.

  • Case Sensitivity: Ensure the placeholder name in your script matches the extension attribute key exactly.

  • Default Behavior: If a device does not have the specified attribute, the placeholder will not be replaced. Always verify your device metadata before running critical scripts.

Did this answer your question?