# Whitelabel Branding

<a id="get-api-v1-system-whitelabel"></a>
#### `GET /api/v1/system/whitelabel`

*Public branding*

Return whitelabel branding data. Public — no authentication required (login page uses this).

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_dict_str__Any__` | Successful Response |

**Response example (200):**

```json
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X GET \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/system/whitelabel
```

---

<a id="get-api-v1-system-whitelabel-addon-status"></a>
#### `GET /api/v1/system/whitelabel/addon-status`

*Whitelabel addon status*

Return whitelabel addon licensing status from the licence cache (no vendor call). `addon_status` is the publisher's status for the addon, or `expired` when a row the publisher still reports active has passed its expiry date; `licensed` is true only for `active`.

**Auth:** admin browser session only (the `whost_session` cookie the panel holds); an HMAC-signed request is answered `401 AUTH_FAILED`.

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_dict_str__Any__` | Successful Response |

**Response example (200):**

```json
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X GET \
  -b "whost_session=$WHOST_SESSION" \
  https://your-server:2000/api/v1/system/whitelabel/addon-status
```

---

<a id="delete-api-v1-system-whitelabel-login-video-page"></a>
#### `DELETE /api/v1/system/whitelabel/login-video/{page}`

*Remove sign-in page video*

Remove the uploaded background video and cover of the admin or the client sign-in page (page: admin, client); the page shows the default video again. Answers 403 LICENSE_ADDON_REQUIRED while the whitelabel addon is not licensed and 404 LOGIN_VIDEO_NOT_FOUND when the page has no uploaded video or cover.

**Auth:** admin browser session only (the `whost_session` cookie the panel holds); an HMAC-signed request is answered `401 AUTH_FAILED`.

**Path parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `page` | string | yes | enum: `admin`, `client` |

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_dict_str__Any__` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X DELETE \
  -b "whost_session=$WHOST_SESSION" \
  https://your-server:2000/api/v1/system/whitelabel/login-video/{page}
```

---

<a id="post-api-v1-system-whitelabel-login-video-page"></a>
#### `POST /api/v1/system/whitelabel/login-video/{page}`

*Upload sign-in page video*

Replace the background video of the admin or the client sign-in page (page: admin, client) with an MP4 whose video track is H.264, at most 5 MB (`video`), and/or its cover image, a JPEG, PNG or WebP of at most 2 MB shown until the video plays (`poster`). The video is stored as uploaded with its descriptive tags, XMP packet and creation times blanked (the agent does not transcode; the panel compresses a larger video in the browser and takes the cover from its first frame); the cover is scaled to fit 1920 x 1080 px (1080 x 1920 for a portrait picture). A new video without a cover removes the previous cover. Each field answers its public address (/branding/<file>); `optimized` reports the source and stored size per field. Answers 403 LICENSE_ADDON_REQUIRED while the whitelabel addon is not licensed, 400 LOGIN_VIDEO_REQUIRED for a cover sent while the page has no uploaded video, 415 UNSUPPORTED_MEDIA_TYPE for a file that is not an MP4 or a video that is not H.264 and 400 INVALID_VIDEO for an MP4 that cannot be read.

**Auth:** admin browser session only (the `whost_session` cookie the panel holds); an HMAC-signed request is answered `401 AUTH_FAILED`.

**Path parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `page` | string | yes | enum: `admin`, `client` |

**Body fields:**

| Field | Type | Required | Notes |
|-------|------|----------|-------|
| `poster` | string | no | — |
| `video` | string | no | — |

**Request body example:**

```json
{
  "poster": "string",
  "video": "string"
}
```

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_dict_str__Any__` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X POST \
  -b "whost_session=$WHOST_SESSION" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/system/whitelabel/login-video/{page}
```

---

<a id="post-api-v1-system-whitelabel-logo"></a>
#### `POST /api/v1/system/whitelabel/logo`

*Upload logo*

Upload one or more whitelabel logos (logo_light, logo_dark, favicon, favicon_dark; JPEG, PNG, WebP or SVG, at most 2 MB each). Raster logos are scaled to fit 512 x 160 px (width x height) and favicons to a square PNG of at most 256 px with transparent padding; SVG is sanitised and kept as a vector. Each uploaded field answers its public address (/branding/<file>, served by the panel's web server and cached as immutable); `optimized` reports the source and stored size per field. Answers 403 LICENSE_ADDON_REQUIRED while the whitelabel addon is not licensed, 400 IMAGE_DIMENSIONS_TOO_LARGE above 25 megapixels and 400 INVALID_IMAGE for a file that does not decode as its type.

**Auth:** admin browser session only (the `whost_session` cookie the panel holds); an HMAC-signed request is answered `401 AUTH_FAILED`.

**Body fields:**

| Field | Type | Required | Notes |
|-------|------|----------|-------|
| `favicon` | string | no | — |
| `favicon_dark` | string | no | — |
| `logo_dark` | string | no | — |
| `logo_light` | string | no | — |

**Request body example:**

```json
{
  "favicon": "string",
  "favicon_dark": "string",
  "logo_dark": "string",
  "logo_light": "string"
}
```

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_dict_str__Any__` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X POST \
  -b "whost_session=$WHOST_SESSION" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/system/whitelabel/logo
```

---

<a id="delete-api-v1-system-whitelabel-logo-logo-type"></a>
#### `DELETE /api/v1/system/whitelabel/logo/{logo_type}`

*Delete logo*

Delete a whitelabel logo (logo_type: light, dark, favicon, favicon_dark). Answers 403 LICENSE_ADDON_REQUIRED while the whitelabel addon is not licensed.

**Auth:** admin browser session only (the `whost_session` cookie the panel holds); an HMAC-signed request is answered `401 AUTH_FAILED`.

**Path parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `logo_type` | string | yes | — |

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_dict_str__Any__` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X DELETE \
  -b "whost_session=$WHOST_SESSION" \
  https://your-server:2000/api/v1/system/whitelabel/logo/{logo_type}
```

---

<a id="post-api-v1-system-whitelabel-reset"></a>
#### `POST /api/v1/system/whitelabel/reset`

*Reset whitelabel*

Reset all whitelabel settings to defaults. Answers 403 LICENSE_ADDON_REQUIRED while the whitelabel addon is not licensed.

**Auth:** admin browser session only (the `whost_session` cookie the panel holds); an HMAC-signed request is answered `401 AUTH_FAILED`.

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_dict_str__Any__` | Successful Response |

**Response example (200):**

```json
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X POST \
  -b "whost_session=$WHOST_SESSION" \
  https://your-server:2000/api/v1/system/whitelabel/reset
```

---

<a id="get-api-v1-system-whitelabel-settings"></a>
#### `GET /api/v1/system/whitelabel/settings`

*Whitelabel settings*

Return full whitelabel settings for the admin configuration page.

**Auth:** admin browser session only (the `whost_session` cookie the panel holds); an HMAC-signed request is answered `401 AUTH_FAILED`.

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_dict_str__Any__` | Successful Response |

**Response example (200):**

```json
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X GET \
  -b "whost_session=$WHOST_SESSION" \
  https://your-server:2000/api/v1/system/whitelabel/settings
```

---

<a id="put-api-v1-system-whitelabel-settings"></a>
#### `PUT /api/v1/system/whitelabel/settings`

*Update whitelabel settings*

Update whitelabel settings (colors, company name, toggles). Answers 403 LICENSE_ADDON_REQUIRED while the whitelabel addon is not licensed.

**Auth:** admin browser session only (the `whost_session` cookie the panel holds); an HMAC-signed request is answered `401 AUTH_FAILED`.

**Body fields:**

| Field | Type | Required | Notes |
|-------|------|----------|-------|
| `company_name` | string | no | — |
| `enabled` | boolean | no | — |
| `hide_login_branding` | boolean | no | — |
| `nav_color` | string | no | — |
| `nav_color_dark` | string | no | — |
| `primary_color` | string | no | — |
| `primary_color_dark` | string | no | — |
| `secondary_color` | string | no | — |
| `secondary_color_dark` | string | no | — |

**Request body example:**

```json
{
  "company_name": "string",
  "enabled": false,
  "hide_login_branding": false,
  "nav_color": "string",
  "nav_color_dark": "string",
  "primary_color": "string",
  "primary_color_dark": "string",
  "secondary_color": "string",
  "secondary_color_dark": "string"
}
```

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_dict_str__Any__` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X PUT \
  -b "whost_session=$WHOST_SESSION" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/system/whitelabel/settings
```

---
