Authenticatie
Stuur een API-sleutel mee als bearer token. De sleutel moet over de permissie reseller.manage beschikken; een sleutel zonder deze permissie wordt geweigerd met een 403 in plaats van een 404.
Waar je organisatie-id komt te staan
Dit eindpunt accepteert org_id als queryparameter. Laat deze achterwege en de aanroep destilleert je gehele tenant-substructie; stuur deze mee om de aanroep te beperken tot één organisatie.
Uw organisatie-id staat op het scherm met API-sleutels in uw dashboard, naast de sleutel zelf. Dit is in elke aanroep die u doet dezelfde id.
Probeer het
Vervang alles tussen punthaakjes door uw eigen waarden en de sleutelplaatsvervanger door een sleutel uit uw dashboard.
curl -X PUT https://api.zinndigital.com/v1/reseller/brand \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "name": <string> }'Ingelogd? De API-console in je dashboard vult je echte organisatie-id en je eigen sleutel in, en voert het verzoek uit tegen de live API zodat je de daadwerkelijke respons kunt zien. Open dit eindpunt in de API-console
Details
Creates or updates your brand. Requires `reseller.manage` — reading your brand is a view permission; changing what every one of your clients sees is not. ⛔ **This endpoint is why white-label was unreachable until 2026-08-16.** The resolver, the entitlement gate, the org-tree walk, the e-mail path and the panel painting were all built and correct, and nothing anywhere could create the row they all read — `Brand` held zero rows across the estate. ⛔ `panel_hostname`, `sending_domain` and `sending_domain_verified` are **refused here, with a sentence saying why**, rather than ignored. All three are facts about the outside world this endpoint cannot establish: a hostname nobody serves is a link to nowhere, an unverified sending domain does not deliver, and a verified flag a customer can set is a wish rather than a verification. Refused with 422 when white-label is not on your plan — storing a brand the resolver would decline to serve is configuration that silently does nothing.
Parameters
| Naam | Type | Verplicht | Wat dit is |
|---|---|---|---|
org_id (query) | Uuid | Nee | The organization this call acts on. Optional for a caller with exactly one direct membership; **required** for anyone with more than one — which is every reseller and every agen… |
Aanvraaglichaam
| Naam | Type | Verplicht | Wat dit is |
|---|---|---|---|
name | string | Ja | What your clients are told they are using. Never blank. |
primary_colour | string | Nee | — |
support_url | string | Nee | — |
status_url | string | Nee | — |
palette | object | Nee | Named colour tokens, hex values only. An unrecognised token is a **422 naming it**, not a silent drop — a field that is ignored is how somebody comes to believe the platform is… |
font_source | string<catalogue, google, > | Nee | — |
font_key | string | Nee | — |
font_google_family | string | Nee | Install it with `POST /v1/reseller/brand/font` first — this field selects a family we already hold, and setting it alone would name a stylesheet with nothing behind it. |
nav_position | string<side, top, > | Nee | — |
density | string<comfortable, compact, > | Nee | — |
corner_radius | string<soft, square, > | Nee | — |
colour_scheme | string<system, light, dark, > | Nee | — |
favicon_sha256 | string | Nee | — |
email_logo_sha256 | string | Nee | — |
dns_nameservers | string[] | Nee | Your own nameservers. **At least two, or none** — a registrar refuses a single one, and refusing it here with a sentence is better than at the registrar with a code. |
Reactie
| Naam | Type | Verplicht | Wat dit is |
|---|---|---|---|
configured | boolean | Ja | Whether a brand row exists yet. False renders an empty form, not a 404. |
entitled | boolean | Ja | Whether white-label is on this org's plan at all. |
name | string | Ja | — |
logo_url | string | Ja | — |
primary_colour | string | Ja | — |
support_url | string | Ja | — |
status_url | string | Ja | — |
panel_hostname | string | Ja | Read-only here — provisioned on `/v1/reseller/brand/panel-hostname`, because a hostname you merely typed is a link to nowhere on every client's screen. |
panel_hostname_active | boolean | Ja | Whether the edge is actually **serving** it. ⛔ Measured, not the edge's status word: a custom hostname can be `active` with a valid certificate and still answer 522, so the engi… |
panel_hostname_status | string | Ja | The edge's own status word, for display. Never branch on it. |
panel_hostname_records | BrandDnsRecord[] | Ja | — |
sending_domain | string | Ja | Read-only here — provisioned on `/v1/reseller/brand/sending-domain`, because an unverified domain does not deliver. |
sending_domain_verified | boolean | Ja | Read-only. The mail provider's answer, not a setting. |
sending_domain_status | string | Ja | The provider's own status word, for display. Never branch on it. |
sending_domain_records | BrandDnsRecord[] | Ja | — |
palette | object | Nee | Named design-system colour tokens, `{token: "#rrggbb"}`, over the closed set in `palette_tokens`. ⛔ Hex only, and that is a security boundary rather than a formatting rule: a CS… |
font_source | string<catalogue, google, > | Nee | `catalogue` for one of `font_catalogue`, `google` for a family we self-host. |
font_key | string | Nee | The catalogue key when `font_source` is `catalogue`. |
font_google_family | string | Nee | A Google family NAME, never a URL. ⛔ We fetch the family once, server-side, and serve the woff2 files from our own origin — so your clients never make a request to Google and th… |
nav_position | string<side, top, > | Nee | — |
density | string<comfortable, compact, > | Nee | — |
corner_radius | string<soft, square, > | Nee | — |
colour_scheme | string<system, light, dark, > | Nee | The scheme a client's **first** visit lands on. ⛔ A default, never a lock — the panel's own theme toggle still works, because removing a visitor's dark mode is an accessibility… |
favicon_sha256 | string | Nee | A favicon distinct from the panel logo. Upload it with `POST /v1/branding/logo` and `purpose=favicon`. Empty falls back to the logo — a 32px render of a wordmark beats somebody… |
favicon_url | string | Nee | — |
email_logo_sha256 | string | Nee | The mark used in transactional mail (`purpose=email`). Separate because the constraints differ: mail clients render on a light background whatever the reader's theme, block SVG,… |
email_logo_url | string | Nee | — |
dns_nameservers | string[] | Nee | Your **own** authoritative nameservers, so a client typing them into a registrar never reads ours. Empty means ours. ⛔ At least two, or none — registrars refuse a single nameser… |
font_catalogue | object[] | Nee | The typefaces you may pick, served **with** the value so a new one appears in your picker on deploy rather than when somebody remembers to update the app too. |
layout_options | object | Nee | The allowed values for each layout choice, keyed by field name. |
palette_tokens | string[] | Nee | The colour tokens `palette` may name. |
accent_contrast | BrandAccentContrast | Nee | How readable your accent colour is, and the ink we will paint on it. ⚠️ **Reported, never enforced.** A legitimate corporate colour can be mid-grey, and refusing to save it woul… |
Fouten die dit eindpunt kan retourneren
401 · 403 · 404 · 422 · 429