Update Organization branding

Partial update of the Organization-level white-label branding resolved for the caller's effective Account via JSON Merge Patch. Changes affect every Account in that Organization. To update the branding for another accessible Account's Organization, send X-Wingspan-Account.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params

PATCH semantics: omitted fields are left unchanged; explicit null clears nullable fields.

string | null

An HTML paragraph the payer adds inside Wingspan's contractor-invite email. Unsafe markup is removed. It is stored on this account; an account set to inherit settings from a parent account sees the parent's paragraph until it saves its own.

uri | null
uri | null
string
string
string
string | null
string | null
string | null
string
enum
Allowed:
fonts
object

Organization-wide font choices for Wingspan-hosted and embedded surfaces. Email font support depends on each email client's rendering rules; email templates fall back to safe system stacks when a custom font is unavailable.

css
object

Organization-wide CSS customization for Wingspan-hosted and embedded surfaces. CSS is applied after the standard Wingspan theme tokens and is not used for transactional email rendering.

emailTemplates
object
emails
object

Per-direction email delivery configuration. Defaults to WingspanManaged everywhere. Three directions: - ar — invoices, charge receipts, dispute notifications, retry notices. - ap — payable notifications, payout receipts, tax-form delivery. - transactional (a.k.a. operational) — security alerts, MFA
challenges, login notifications. Security-relevant emails default
to WingspanManaged regardless of brand mode and are not delegable.

currencyPolicy
object

Per-jurisdiction currency allow-lists at onboarding. Drives the choices presented in embedded onboarding and is enforced server-side at POST /v3/finance/external-bank-accounts. Default (when currencyPolicy is unset): all currencies allowed everywhere — backwards-compatible behaviour. When set, the policy is exhaustive: countries not listed retain default behaviour; countries listed permit only the named currencies. Inheritance: child accounts inherit the parent's policy until they set their own.

retry
object

Retry-policy customization per direction. ar controls retries for failed AR charges; ap controls retries for failed disbursements.

security
object

Security-related customization. Default values are secure-by-default; the entries listed here are caller overrides for organizations with documented security exceptions.

Headers
string
length between 1 and 255
^[\x21-\x7e]{1,255}$

Optional idempotency token for authenticated POST and PATCH requests. Reusing the same key and body returns the cached response for 24 hours, except credential operations that explicitly document a 409 because one-time secret material is never cached; reusing it with a different body returns 409 IdempotencyKeyConflict. Use 1-255 printable ASCII characters.

string
^(?:[A-Za-z0-9_.]{22}|[a-f0-9]{24})$

Select the Account for an Account-scoped operation. A direct ServiceAccount API key MUST supply this header, and the target must be within the ServiceAccount owner's or Authorization grant's Account boundary. A Person bearer may select an Account on which it has an active Stakeholder, and an Account session may select its bound Account (or a descendant only when the session explicitly includes descendants).

string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json