identity

GET /v1/branding

The brand this customer's panel renders under.

Tous les points de terminaison identity

Toute la documentation pour développeurs

Authentification

Envoyez une clé d'API en tant que jeton du porteur (bearer token). Cet endpoint n'indique pas de permission spécifique dans la spécification, attribuez donc à votre clé le minimum requis et vérifiez la réponse plutôt que de faire des suppositions.

Où insérer l'ID de votre organisation

Cet point de terminaison prend org_id comme paramètre de requête. Omettez-le et l'appel couvrira l'ensemble de votre sous-arbre de location ; envoyez-le pour restreindre l'appel à une seule organisation.

L'identifiant de votre organisation se trouve sur l'écran des clés API de votre tableau de bord, à côté de la clé elle-même. Il s'agit du même identifiant pour chaque appel que vous effectuez.

Essayer

Remplacez tout ce qui se trouve entre crochets par vos propres valeurs, et le espace réservé à la clé par une clé de votre tableau de bord.

curl -X GET https://api.zinndigital.com/v1/branding \
  -H "Authorization: Bearer zdk_live_…"

Connecté ? La console d'API de votre tableau de bord saisit votre véritable ID d'organisation ainsi que votre propre clé, et exécute la requête sur l'API de production afin que vous puissiez voir la réponse réelle. Ouvrir ce point de terminaison dans la console API

Détails

The name, logo, colour and links the signed-in customer's dashboard paints itself with — their agency's or reseller's if they are white-labelled, otherwise Zinn®'s. Always answers, for every authenticated caller. An organisation with no brand of its own is not a 404: it receives the platform identity with is_white_label: false. A nullable answer would make every client invent its own fallback, and the second such client is the leak this feature exists to close. Resolved by walking up the organisation tree to the org that owns the brand, and gated on the white_label entitlement held by that owner — never by the client reading it, who holds no such entitlement and never will. ⛔ Not gated on a permission key. This answers "what does your screen look like?", not "may you see this data?" — the payload is the brand the caller is already looking at. It is still authenticated and org-scoped, so one tenant cannot ask what another tenant's panel looks like. Cache-Control: private, no-store — this response is never stored, by any cache, and that is a tenancy requirement rather than a tuning choice. The URL is /v1/branding for every tenant and the organisation travels in X-Zinn-Org, so a stored copy is keyed on nothing that separates one tenant from the next. It was private, max-age=60 until 2026-08-26; private bounds a stored copy to one browser profile and does not bound it to one tenant, and one browser profile is exactly where an organisation switch happens. Measured before the change: four organisations, one token, one second apart, all four answering with the first one's brand. Vary: X-Zinn-Org, Authorization is sent as well, so an intermediary that stores despite no-store still cannot serve one tenant's brand to another.

Paramètres

NomTypeObligatoireQu'est-ce que c'est
org_id (query)stringNonWhich of the caller's organisations to resolve for. Optional, and only needed by a person who belongs to several. X-Zinn-Org stands in for it when it is absent. Accepts…

Réponse

NomTypeObligatoireQu'est-ce que c'est
namestringOuiThe name shown in the page title, the sidebar header and the browser tab.
dashboard_urlstringOuiWhere this brand's panel lives. The brand's own attached hostname when it has one, otherwise the platform panel — never a hostname that does not resolve yet, because a link the…
support_urlstringOui
status_urlstringOui
logo_urlstringOuiEmpty when the brand has set no logo; the client then renders the name.
primary_colourstringOuiEmpty when the brand has set no colour; the client then uses its default.
is_white_labelbooleanOuifalse for Zinn®'s own identity. Lets a surface say "this is white-labelled" without comparing the name to a literal.
is_client_of_resellerbooleanOuitrue only when this brand belongs to an organisation above yours — that is, you are a reseller's client rather than the reseller. ⛔ Not the same question as…
localesstring[]OuiThe languages this panel may be shown in, in registry order. Every language we ship, unless the caller is a reseller's client and that reseller narrowed the list. Never empty.…
default_localestringOuiThe language a new account under this brand starts in. Always a member of locales.
locales_restrictedbooleanOuitrue when a reseller narrowed the list, so a surface can explain why a language is missing instead of looking broken.
language_switcherbooleanOuifalse when the reseller has removed the language control from their clients' panel. Render no picker — not a disabled one. locales stays populated regardless: hiding a control…
currenciesstring[]OuiThe currencies this panel may quote in, in registry order. Every currency we can charge, unless the caller is a reseller's client and that reseller narrowed the list. Never empty.
default_currencystringOuiWhat a viewer under this brand is quoted in before they choose. Always a member of currencies.
currencies_restrictedbooleanOuitrue when a reseller narrowed the list, so a surface can explain why a currency is missing instead of looking broken.
currency_switcherbooleanOuifalse when the reseller has removed the currency control. Every client of that reseller is then quoted in default_currency.
paletteobjectOuiDesign-system colour tokens the brand chose, {token: "#rrggbb"}. Empty for the platform, which means "use the design system's own" — expressed as absence rather than as…
font_stackstringOuiA complete CSS font-family value, fallbacks included. Never a bare family name: a brand whose webfont fails to load must land somewhere chosen, not on the browser's default…
font_css_urlstringOuiA stylesheet installing a self-hosted Google family, or "" for a catalogue font that needs no bytes. ⛔ Served from our origin, never fonts.googleapis.com. A <link> to…
nav_positionstringOui
densitystringOui
corner_radiusstringOui
colour_schemestringOuiThe scheme a first visit lands on.
favicon_urlstringOuiThe brand's icon, already falling back to its logo. Empty means "leave whatever the surface has" — never our mark, because on a reseller's hostname that is the leak.
email_logo_urlstringOuiThe mark for transactional mail; falls back to the panel logo.
menu_itemsBrandNavLink[]OuiCustom navigation links the provider added, already filtered to what this reader may see.

Erreurs que cet point de terminaison peut renvoyer

401 · 429