identity

GET /v1/branding/by-panel-hostname

The brand served on one panel hostname.

All identity endpoints

Authentication

Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X GET https://api.zinndigital.com/v1/branding/by-panel-hostname?hostname=<hostname> \
  -H "Authorization: Bearer zdk_live_…"

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

The brand behind a reseller's own panel address. ⛔ **Unauthenticated, deliberately, and this is the only endpoint on the API where that is the right answer.** Its caller is the edge Worker rendering a *maintenance page* — which by definition runs when the panel behind it is unreachable, quite possibly because the engine is having a bad time. A credential to fetch would be one more thing to go wrong on the error path, and the Worker has nobody to authenticate as. ⭐ It discloses nothing new: it answers **only for a hostname that is already actively serving that brand's panel**, so everything in the payload is on the screen of anyone who types that address. An unknown or inactive hostname is a `404` with no detail, so it is not an oracle for "which of these domains is a Zinn® customer".

Parameters

NameTypeRequiredWhat it is
hostname (query)stringYes

Response

NameTypeRequiredWhat it is
namestringYes
logo_urlstringYes
primary_colourstringYes
support_urlstringYes
localesstring[]YesThe languages this panel offers, so the **sign-in page** can be in one of them. A reseller selling into one market should not have their customers meet an English login form and…
default_localestringYesThe language the sign-in page opens in.
locales_restrictedbooleanYesTrue when the reseller narrowed the list.
language_switcherbooleanYesWhether the sign-in page should render a language picker at all.
currency_switcherbooleanYesWhether a currency picker should render. No `currencies` list rides on this response: a maintenance or sign-in page prices nothing, so the list would be dead weight on a respons…
paletteobjectNoThe brand's colour tokens, so the **logged-out** sign-in card can paint itself. ⚖️ The owner asked directly on 2026-09-03 whether a visitor sent to a login from a members-only p…
font_stackstringNoA complete CSS `font-family` value, fallbacks included.
font_css_urlstringNoThe self-hosted webfont stylesheet, from our own origin. Empty for a catalogue font.
nav_positionstringNo
densitystringNo
corner_radiusstringNo
colour_schemestringNo
favicon_urlstringNoThe brand's icon, already falling back to its logo.
oidc_client_idstringYesThe Keycloak client this panel signs in through. ⛔ The panel cannot sign anybody in without it. One build of the dashboard is served on `app.zinndigital.com` and on every resell…
oidc_authoritystringYesWhere this panel's browser fetches OIDC metadata from — the reseller's **own** hostname, not ours. ⛔ **This is what keeps our name out of the address bar during sign-in** (#2990…

Errors this endpoint can return

404 · 429