identity
GET /v1/branding/font/{family}.css
The `@font-face` rules for a self-hosted family.
Authentication
Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X GET https://api.zinndigital.com/v1/branding/font/{family}.css \
-H "Authorization: Bearer zdk_live_…"Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
The stylesheet that installs a brand's chosen Google family — from **our** origin, not Google's. ⛔ **Unauthenticated, deliberately**, and for the same reason as the logo above: a stylesheet is fetched by a `<link>` in a page nobody has signed in to yet, and the branded sign-in screen is the first place it is needed. It discloses nothing — the bytes are a public, OFL-licensed font and the family name is on screen for any visitor. ⭐ Why we serve it at all rather than linking to `fonts.googleapis.com`: that link would send every one of a reseller's clients to a third party on every page load, with their IP address and a `Referer` naming the reseller's hostname, and would need a permanent CSP widening for every panel including those that picked a catalogue font. The family is fetched once, server-side, at install time. ⛔ A family that is not installed is a **404, never an empty 200**. An empty stylesheet renders in the fallback font with nothing red anywhere, and the reseller is told their typeface "did not work" with no way to find out why.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
family (path) | string | Yes | The family name, spaces written as `+`. |
Errors this endpoint can return
404