Branding

Update the acting organization's branding (partial)

Changed on

PATCH /branding/ — update the acting org's branding (partial).

Audited: a refused write (gate failure, 404-not-configured, or serializer validation error) raises before this method reaches serializer.save(), so nothing is ever recorded for a refused write. Always an UPDATE (PATCH never creates — see _get_branding_or_404); the before-state is captured BEFORE serializer.save() mutates instance in place.

patch/branding/

Request

  • The document declares no server URL.
  • Auth: one of:
    • HTTP bearer
    • API key in cookie sessionid

Headers

X-Organization-Idstring

Selects the active organization for this request. Optional for callers that belong to exactly one active organization — the single membership is resolved implicitly. Required when the caller has two or more active memberships; omitting it in that case returns 400. If the header names an organization the caller is not an active member of, the server returns 403.

Request body

app_namestring

The display name of the white-labeled app (e.g., 'MyScheduler').

logo_urlstring nullable
primary_colorstring

Primary color as hex code: #RRGGBB or #RRGGBBAA.

secondary_colorstring

Secondary color as hex code: #RRGGBB or #RRGGBBAA.

support_emailstring email

Email address for the From/reply-to on branded transactional emails.

redirect_urlstring uri

Single post-authentication redirect destination for this organization. Replaces the old return_url_allowlist: no caller-supplied redirect target is ever honored, so there is nothing to validate at request time and no open-redirect surface. Must be HTTPS with no wildcard character and no path-prefix pattern (organizations.redirect_url_validation).

Response

app_namestring required

The display name of the white-labeled app (e.g., 'MyScheduler').

logo_urlstring nullable
primary_colorstring

Primary color as hex code: #RRGGBB or #RRGGBBAA.

secondary_colorstring

Secondary color as hex code: #RRGGBB or #RRGGBBAA.

support_emailstring email

Email address for the From/reply-to on branded transactional emails.

redirect_urlstring uri

Single post-authentication redirect destination for this organization. Replaces the old return_url_allowlist: no caller-supplied redirect target is ever honored, so there is nothing to validate at request time and no open-redirect surface. Must be HTTPS with no wildcard character and no path-prefix pattern (organizations.redirect_url_validation).

Changes

    • ▲

      the response property became nullable for the status

    • ○

      the request property became nullable (media type: application/json)

    • ○

      the request property became nullable (media type: application/x-www-form-urlencoded)

    • ○

      the request property became nullable (media type: multipart/form-data)

    • ▲

      the request property became not nullable (media type: application/json)

    • ▲

      the request property became not nullable (media type: application/x-www-form-urlencoded)

    • ▲

      the request property became not nullable (media type: multipart/form-data)