identity
GET /v1/branding/font/{family}.css
The `@font-face` rules for a self-hosted family.
身份验证
请将 API 密钥作为 bearer 令牌发送。此端点在规范中未指明具体的权限,因此请为您的密钥赋予所需的最小权限,并通过检查响应来确认,而不是盲目假设。
此端点不需要组织 ID。您的密钥已用于识别其所属的组织,且响应范围也仅限于该组织。
免费试用
将尖括号中的内容替换为您自己的值,并将键占位符替换为您仪表板中的一个键。
curl -X GET https://api.zinndigital.com/v1/branding/font/{family}.css \
-H "Authorization: Bearer zdk_live_…"已登录?您仪表板中的 API 控制台会自动填入您真实的组织 ID 和您自己的密钥,并针对实时 API 运行请求,以便您查看实际的响应。 在 API 控制台中打开此端点
详细信息
The stylesheet that installs a brand's chosen Google family — from **our** origin, not Google's. ⛔ **Unauthenticated, deliberately**, and for the same reason as the logo above: a stylesheet is fetched by a `<link>` in a page nobody has signed in to yet, and the branded sign-in screen is the first place it is needed. It discloses nothing — the bytes are a public, OFL-licensed font and the family name is on screen for any visitor. ⭐ Why we serve it at all rather than linking to `fonts.googleapis.com`: that link would send every one of a reseller's clients to a third party on every page load, with their IP address and a `Referer` naming the reseller's hostname, and would need a permanent CSP widening for every panel including those that picked a catalogue font. The family is fetched once, server-side, at install time. ⛔ A family that is not installed is a **404, never an empty 200**. An empty stylesheet renders in the fallback font with nothing red anywhere, and the reseller is told their typeface "did not work" with no way to find out why.
参数
| 名称 | 类型 | 必填 | 内容简介 |
|---|---|---|---|
family (path) | string | 是 | The family name, spaces written as `+`. |
此端点可能返回的错误
404