Skip to content

marketing.brandKit.put

Save the account's brand kit

PUT/marketing/brand-kit

Operation
marketing.brandKit.put
MCP tool
marketing_brandKit_put

Set the brand a marketing video signs with: the name on the pill, the accent colour, the default closing line, and optionally a palette, a font, a copy language and a tone. The whole kit is REPLACED, not merged — name and accent are always required, and a half left out of palette/font/copyLanguage/tone keeps what the row already had. The house copy rule is enforced here: no dashes in the name or the call to action, because the designs set them in type that has no dash. The logo is not set here: files are not part of v1.0.

curl -X PUT "https://api.gogoscreen.com/api/v1/marketing/brand-kit" \
  -H "Authorization: Bearer $GOGOSCREEN_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{ "accent": "<accent>", "name": "<name>" }'
A request to this operation.

At a glance

FactDetail
Scopesmarketing:write
Credentialsa signed in dashboard session or an API key.
Rate limit120 requests a minute per credential, in the write class.
IdempotencyRequired. Send an Idempotency-Key header; a retry with the same key and the same body returns the stored answer with Idempotent-Replayed: true. How idempotency works.
MCP toolmarketing_brandKit_put
Always setsCache-Control: private, no-store
Verified emailRequired. An account whose email address is not verified meets 403 email_unverified before the operation runs.
Marketing videosRequired. An account without marketing videos enabled meets 403 feature_disabled before the operation runs.

Request body

A JSON body is required. Unknown fields are refused rather than ignored, so a typo is a 400 validation_failed rather than a setting that silently did nothing.

NameTypeRequiredDescription
accentstringRequiredThe accent colour as #rrggbb.pattern: ^#[0-9a-fA-F]{6}$
namestringRequiredThe name on the brand pill. No dashes.1–60 characters
copyLanguagestring | nullOptionalA language tag such as en or fr-CA.max 35 characters
defaultCtastring | nullOptionalThe closing line when a video does not name one. No dashes.max 60 characters
fontstring | nullOptionalA font id from the marketing catalogue.max 64 characters
palettestring[] | nullOptionalUp to four colours. The accent leads it; two entries are the band and the panel.max 4 items
tonestring | nullOptionalmax 32 characters

Response

Answers 200. Every answer also carries RateLimit-Limit, RateLimit-Remaining and RateLimit-Reset, and every error body carries a requestId.

200 OK

Save the account's brand kit

200 OK body
NameTypeDescription
brandKitobjectany keys
200 OK headers
HeaderMeaning
Cache-ControlAlways private, no-store.
Idempotent-ReplayedPresent only when this answer was stored by an earlier call with the same Idempotency-Key. Nothing new was done.

Errors

Every refusal is { error: { code, message, details?, requestId } }. Branch on code, never on the sentence. The full catalogue is at Errors.

CodeStatusWhen it happensWhat to do
idempotency_key_required400A mutating operation arrived over HTTP with no Idempotency-Key header. It is refused before the body is parsed, so a caller missing both learns about both at once.Add an Idempotency-Key header of up to 128 characters, unique to this request. Over MCP the same value goes in the idempotencyKey tool argument.
invalid_brand_kit400The brand kit sent is not valid: a missing required field, a colour that is not a colour, or a dash in copy the designs set in type that has no dash.details.errors names each problem. Fix them all and send the whole kit again, since the kit is replaced rather than merged.
validation_failed400The merged path, query and body did not match the operation's schema. The schemas are strict, so an unknown field is a failure rather than something ignored, and a string carrying half of a character is refused before it can be stored.Read details.issues. Each entry carries a path, a message and a machine readable code. Fix every named field and send the request again; the same body always fails the same way.
unauthorized401No credential was presented, or the key is unknown, revoked or expired, or an X-API-Key header carried something that is not an API key. details.reason says which.Send Authorization: Bearer gsk_live_…. A revoked or expired key never starts working again, so issue a new one in the developer console. Put a dashboard session token in Authorization, never in X-API-Key.
forbidden_scope403The credential does not carry every scope the operation declares, or it is the wrong kind of credential for it. keys.* and assistant.* are user only and can never be called by a key.details.requiredScopes and details.missingScopes name what is missing. A key's scopes cannot be changed after it is issued, so create a new key with them. When details.allowedActors is present, no key can call this operation at all.
not_found404No resource of that id belongs to this account. A resource that belongs to somebody else answers 404 as well, never 403.Check the id. Do not treat this as a permissions problem.
conflict409The request conflicts with the state the resource is in, and no more specific code applies.Re-read the resource and decide from its current state. Retrying the same request unchanged will not help.
idempotency_conflict409That idempotency key has already been used on this operation with a different request body.Use a fresh key for a different request. A key stands for one intent, not for one attempt.
idempotency_in_progress409The first request under that key is still being worked. Two concurrent identical requests both reach the store and one of them is told this.Wait the Retry-After seconds, which is 2, and send exactly the same request again with the same key. Do not change the body and do not mint a new key.
payload_too_large413The request body is over the transport's limit: 256 kb over HTTP, 1 mb over MCP.Send less. details.limit carries the limit. Version 1 has no upload operations, so a body this size is usually a mistake.
unsupported_media_type415The request carried a body whose Content-Type is not application/json, whose charset is not utf-8, or whose Content-Encoding this API does not decode. A body nobody can read would otherwise be silently discarded.Send Content-Type: application/json and utf-8 bytes. details names the charset, encoding or content type that was objected to.
rate_limited429The credential's per minute budget, the account's per minute ceiling, or a daily cap was exceeded. details.scope is minute, day or account, or global when the product's own daily cap on voice previews is spent.Wait the Retry-After seconds and retry. details.limit and details.resetAt say what was hit and when it reopens. The RateLimit-* headers on every answer let a client pace itself before it gets here.
internal_error500An unhandled failure inside this API. The original message is logged and never answered.Retry once, then quote requestId to support. A 5xx deletes the idempotency claim rather than storing it, so retrying under the same key is safe.