identity

GET /v1/branding

The brand this customer's panel renders under.

Gbogbo àwọn identity endpoints

Ìfàṣẹ́pọ̀

Fi bọ́kì kọ́kọ́ (bearer token) ránṣẹ́ gẹ́gẹ́ bí àmì ìdánimọ̀ API. Ibùdó yìí kò sọ àṣẹ pàtó kan nínú àlàyé rẹ̀, nítorí náà fún kọ́kọ́ rẹ̀ ní ohun tó kéré jù lọ tí ó nílò kí o sì ṣàyẹ̀wò ìdáhùn náà dípò kí o kàn rò ó.

Ibùdó àmì ìdánimọ̀ ilé-iṣẹ́ rẹ sí

Oju-iwọle yii nlo org_id gẹgẹbi ayẹwo ibeere. Fi silẹ ni ita yoo si bo igi iyalo rẹ lapapọ; ranṣẹ si lati dín ibeere naa kù si ajọ kan.

Id àjọ rẹ wa lórí ojú-ìwákòòkò àwọn bọ́tìnnì API nínú daṣibọọdú rẹ, lẹ́gbẹ̀ẹ́ bọ́tìnnì náà gan-an. Ó jẹ́ ìd kan náà nínú gbogbo ìpè tí o bá ṣe.

Gbiyanju rẹ

Rọ́pọ̀ èyíkéyìí nínú àwọn àmì ìtọ́ka < > pẹ̀lú iye tirẹ̀, àti àmì ìdánimọ̀ bọ́tìnnì náà pẹ̀lú bọ́tìnnì kan láti inú dásibọ̀ọ̀dù rẹ.

curl -X GET https://api.zinndigital.com/v1/branding \
  -H "Authorization: Bearer zdk_live_…"

Ṣé o ti wọlé? Iwọ̀n api ní nú ìgbékalẹ̀ rẹ kún id àjọ gidi rẹ ati bọtini tirẹ, o si nṣiṣẹ ibeere na lòdì si api gidi ki o le rii esi gidi na. Ṣí ojú abáná yìí sílẹ̀ nínú kọnsólù API

Àwọn kúlẹ̀kúlẹ̀

The name, logo, colour and links the signed-in customer's dashboard paints itself with — their agency's or reseller's if they are white-labelled, otherwise Zinn®'s. **Always answers, for every authenticated caller.** An organisation with no brand of its own is not a `404`: it receives the platform identity with `is_white_label: false`. A nullable answer would make every client invent its own fallback, and the second such client is the leak this feature exists to close. Resolved by walking **up** the organisation tree to the org that owns the brand, and gated on the `white_label` entitlement held by that owner — never by the client reading it, who holds no such entitlement and never will. ⛔ Not gated on a permission key. This answers *"what does your screen look like?"*, not *"may you see this data?"* — the payload is the brand the caller is already looking at. It is still authenticated and org-scoped, so one tenant cannot ask what another tenant's panel looks like. **`Cache-Control: private, no-store`** — this response is never stored, by any cache, and that is a tenancy requirement rather than a tuning choice. The URL is `/v1/branding` for every tenant and the organisation travels in `X-Zinn-Org`, so a stored copy is keyed on nothing that separates one tenant from the next. It was `private, max-age=60` until 2026-08-26; `private` bounds a stored copy to one browser profile and **does not** bound it to one tenant, and one browser profile is exactly where an organisation switch happens. Measured before the change: four organisations, one token, one second apart, all four answering with the first one's brand. `Vary: X-Zinn-Org, Authorization` is sent as well, so an intermediary that stores despite `no-store` still cannot serve one tenant's brand to another.

Àwọn ìpìlẹ̀

OrúkọIruTí a nílòKini o jẹ
org_id (query)stringBẹẹkọWhich of the caller's organisations to resolve for. Optional, and only needed by a person who belongs to several. `X-Zinn-Org` stands in for it when it is absent. Accepts **any…

Idahun

OrúkọIruTí a nílòKini o jẹ
namestringBẹẹniThe name shown in the page title, the sidebar header and the browser tab.
dashboard_urlstringBẹẹniWhere this brand's panel lives. The brand's own attached hostname when it has one, otherwise the platform panel — never a hostname that does not resolve yet, because a link the…
support_urlstringBẹẹni
status_urlstringBẹẹni
logo_urlstringBẹẹniEmpty when the brand has set no logo; the client then renders the name.
primary_colourstringBẹẹniEmpty when the brand has set no colour; the client then uses its default.
is_white_labelbooleanBẹẹni`false` for Zinn®'s own identity. Lets a surface say "this is white-labelled" without comparing the name to a literal.
is_client_of_resellerbooleanBẹẹni`true` only when this brand belongs to an organisation **above** yours — that is, you are a reseller's client rather than the reseller. ⛔ Not the same question as `is_white_labe…
localesstring[]BẹẹniThe languages this panel may be shown in, in registry order. Every language we ship, unless the caller is a reseller's client and that reseller narrowed the list. Never empty. S…
default_localestringBẹẹniThe language a new account under this brand starts in. Always a member of `locales`.
locales_restrictedbooleanBẹẹni`true` when a reseller narrowed the list, so a surface can explain why a language is missing instead of looking broken.
language_switcherbooleanBẹẹni`false` when the reseller has removed the language control from their clients' panel. Render no picker — not a disabled one. `locales` stays populated regardless: hiding a contr…
currenciesstring[]BẹẹniThe currencies this panel may quote in, in registry order. Every currency we can charge, unless the caller is a reseller's client and that reseller narrowed the list. Never empty.
default_currencystringBẹẹniWhat a viewer under this brand is quoted in before they choose. Always a member of `currencies`.
currencies_restrictedbooleanBẹẹni`true` when a reseller narrowed the list, so a surface can explain why a currency is missing instead of looking broken.
currency_switcherbooleanBẹẹni`false` when the reseller has removed the currency control. Every client of that reseller is then quoted in `default_currency`.
paletteobjectBẹẹniDesign-system colour tokens the brand chose, `{token: "#rrggbb"}`. **Empty for the platform**, which means *"use the design system's own"* — expressed as absence rather than as…
font_stackstringBẹẹniA complete CSS `font-family` value, fallbacks included. Never a bare family name: a brand whose webfont fails to load must land somewhere chosen, not on the browser's default se…
font_css_urlstringBẹẹniA stylesheet installing a self-hosted Google family, or `""` for a catalogue font that needs no bytes. ⛔ Served from **our** origin, never `fonts.googleapis.com`. A `<link>` to…
nav_positionstringBẹẹni
densitystringBẹẹni
corner_radiusstringBẹẹni
colour_schemestringBẹẹniThe scheme a first visit lands on.
favicon_urlstringBẹẹniThe brand's icon, already falling back to its logo. Empty means *"leave whatever the surface has"* — never our mark, because on a reseller's hostname that is the leak.
email_logo_urlstringBẹẹniThe mark for transactional mail; falls back to the panel logo.
menu_itemsBrandNavLink[]BẹẹniCustom navigation links the provider added, **already filtered** to what this reader may see.

Awọn aṣiṣe ti ibudo ipari yii le da pada

401 · 429