Branding

Create or replace the acting organization's branding

Changed on

PUT /branding/ — create or replace the acting org's branding.

Audited: a refused write (gate failure or serializer validation error) raises before this method reaches the upsert, so nothing is ever recorded for a refused write. A first-time upsert records a CREATE with no diff; an upsert that replaces an existing row records an UPDATE with a diff naming only the fields that actually changed, using the before-state captured BEFORE the write.

put/branding/

Request

  • The document declares no server URL.
  • Auth: one of:
    • HTTP bearer
    • API key in cookie sessionid

Headers

X-Organization-Idstring

Selects the active organization for this request. Optional for callers that belong to exactly one active organization — the single membership is resolved implicitly. Required when the caller has two or more active memberships; omitting it in that case returns 400. If the header names an organization the caller is not an active member of, the server returns 403.

Request body

app_namestring required

The display name of the white-labeled app (e.g., 'MyScheduler').

logo_urlstring nullable
primary_colorstring

Primary color as hex code: #RRGGBB or #RRGGBBAA.

secondary_colorstring

Secondary color as hex code: #RRGGBB or #RRGGBBAA.

support_emailstring email

Email address for the From/reply-to on branded transactional emails.

redirect_urlstring uri

Single post-authentication redirect destination for this organization. Replaces the old return_url_allowlist: no caller-supplied redirect target is ever honored, so there is nothing to validate at request time and no open-redirect surface. Must be HTTPS with no wildcard character and no path-prefix pattern (organizations.redirect_url_validation).

Response

app_namestring required

The display name of the white-labeled app (e.g., 'MyScheduler').

logo_urlstring nullable
primary_colorstring

Primary color as hex code: #RRGGBB or #RRGGBBAA.

secondary_colorstring

Secondary color as hex code: #RRGGBB or #RRGGBBAA.

support_emailstring email

Email address for the From/reply-to on branded transactional emails.

redirect_urlstring uri

Single post-authentication redirect destination for this organization. Replaces the old return_url_allowlist: no caller-supplied redirect target is ever honored, so there is nothing to validate at request time and no open-redirect surface. Must be HTTPS with no wildcard character and no path-prefix pattern (organizations.redirect_url_validation).

Changes

    • ▲

      the response property became nullable for the status

    • ▲

      the response property became nullable for the status

    • ○

      the request property became nullable (media type: application/json)

    • ○

      the request property became nullable (media type: application/x-www-form-urlencoded)

    • ○

      the request property became nullable (media type: multipart/form-data)

    • ▲

      the request property became not nullable (media type: application/json)

    • ▲

      the request property became not nullable (media type: application/x-www-form-urlencoded)

    • ▲

      the request property became not nullable (media type: multipart/form-data)