identity

GET /v1/branding/by-panel-hostname

The brand served on one panel hostname.

Alle identity Endpunkte

Authentifizierung

Senden Sie einen API-Schlüssel als Bearer-Token. Dieser Endpunkt gibt in der Spezifikation keine spezifische Berechtigung an. Versehen Sie Ihren Schlüssel daher mit den minimal erforderlichen Rechten und prüfen Sie die Antwort, anstatt Annahmen zu treffen.

Dieser Endpunkt erfordert keine Organisations-ID. Ihr Schlüssel identifiziert bereits die zugehörige Organisation, und die Antwort ist entsprechend eingeschränkt.

Ausprobieren

Ersetzen Sie alles in spitzen Klammern durch Ihre eigenen Werte und den Platzhalter für den Schlüssel durch einen Schlüssel aus Ihrem Dashboard.

curl -X GET https://api.zinndigital.com/v1/branding/by-panel-hostname?hostname=<hostname> \
  -H "Authorization: Bearer zdk_live_…"

Angemeldet? Die API-Konsole in Ihrem Dashboard trägt automatisch Ihre echte Organisations-ID sowie Ihren eigenen Schlüssel ein und führt die Anfrage gegen die Live-API aus, sodass Sie die tatsächliche Antwort sehen können. Öffnen Sie diesen Endpunkt in der API-Konsole

Details

The brand behind a reseller's own panel address. ⛔ **Unauthenticated, deliberately, and this is the only endpoint on the API where that is the right answer.** Its caller is the edge Worker rendering a *maintenance page* — which by definition runs when the panel behind it is unreachable, quite possibly because the engine is having a bad time. A credential to fetch would be one more thing to go wrong on the error path, and the Worker has nobody to authenticate as. ⭐ It discloses nothing new: it answers **only for a hostname that is already actively serving that brand's panel**, so everything in the payload is on the screen of anyone who types that address. An unknown or inactive hostname is a `404` with no detail, so it is not an oracle for "which of these domains is a Zinn® customer".

Parameter

NameTypErforderlichWas es ist
hostname (query)stringJa

Antwort

NameTypErforderlichWas es ist
namestringJa
logo_urlstringJa
primary_colourstringJa
support_urlstringJa
localesstring[]JaThe languages this panel offers, so the **sign-in page** can be in one of them. A reseller selling into one market should not have their customers meet an English login form and…
default_localestringJaThe language the sign-in page opens in.
locales_restrictedbooleanJaTrue when the reseller narrowed the list.
language_switcherbooleanJaWhether the sign-in page should render a language picker at all.
currency_switcherbooleanJaWhether a currency picker should render. No `currencies` list rides on this response: a maintenance or sign-in page prices nothing, so the list would be dead weight on a respons…
paletteobjectNeinThe brand's colour tokens, so the **logged-out** sign-in card can paint itself. ⚖️ The owner asked directly on 2026-09-03 whether a visitor sent to a login from a members-only p…
font_stackstringNeinA complete CSS `font-family` value, fallbacks included.
font_css_urlstringNeinThe self-hosted webfont stylesheet, from our own origin. Empty for a catalogue font.
nav_positionstringNein
densitystringNein
corner_radiusstringNein
colour_schemestringNein
favicon_urlstringNeinThe brand's icon, already falling back to its logo.
oidc_client_idstringJaThe Keycloak client this panel signs in through. ⛔ The panel cannot sign anybody in without it. One build of the dashboard is served on `app.zinndigital.com` and on every resell…
oidc_authoritystringJaWhere this panel's browser fetches OIDC metadata from — the reseller's **own** hostname, not ours. ⛔ **This is what keeps our name out of the address bar during sign-in** (#2990…

Fehler, die dieser Endpunkt zurückgeben kann

404 · 429