identity

GET /v1/branding/logo/{sha256}

One brand logo, as an image.

All identity endpoints

Authentication

Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X GET https://api.zinndigital.com/v1/branding/logo/{sha256} \
  -H "Authorization: Bearer zdk_live_…"

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

The image bytes for a logo digest. ⛔ **Unauthenticated, deliberately.** Its readers are a browser painting a panel, a browser painting a reseller's *sign-in* page — which by definition has nobody signed in — and a client's own panel. Requiring a token would break the login page, which is the surface where a reseller's mark matters most. ⭐ What stands in for authentication is the digest: this is a content-addressed store, so asking for an object means already knowing the sha256 of its exact bytes. There is nothing to enumerate, and the image is one the brand publishes on its own public login page anyway. ⭐ Immutable: the bytes behind a digest can never change, so the response is cacheable for a year and a new logo is simply a new URL.

Parameters

NameTypeRequiredWhat it is
sha256 (path)stringYes

Errors this endpoint can return

404