Skip to content

Branding

Logo status

settings:read
Request exampleNo request body
curl https://api.rieckflow.com/v1/branding \
-H "Authorization: Bearer $RIECK_API_KEY"
200 Success envelopeapplication/json
Possible errors 4
HTTPCodeMeaning
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
429rate_limitedThe organisation’s rate budget is exhausted.

Upload logo

settings:write
Request body fields 3
FieldTypeRequiredDescription
datastringYesField in the request payload.
mimestringYesField in the request payload.
variantstringNoField in the request payload.
Request exampleapplication/json
curl -X PUT https://api.rieckflow.com/v1/branding/logo \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041" \
-H "Content-Type: application/json" \
-d '{
"data": "…",
"mime": "image/png",
"variant": "light"
}'
200 Success envelopeapplication/json
Possible errors 9
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
400invalid_requestThe request body or parameter failed validation.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
413payload_too_largeThe JSON or uploaded file exceeds this endpoint’s size limit.
429rate_limitedThe organisation’s rate budget is exhausted.
Request body — fuldt JSON Schema
{
"type": "object",
"properties": {
"data": {
"type": "string",
"minLength": 1
},
"mime": {
"type": "string",
"enum": [
"image/png",
"image/jpeg",
"image/svg+xml",
"image/webp"
]
},
"variant": {
"default": "light",
"type": "string",
"enum": [
"light",
"dark"
]
}
},
"required": [
"data",
"mime"
],
"additionalProperties": false
}

Delete logo variant

settings:write
ParameterInTypeRequiredDescription
variantquerystringNolight (default) or dark
Request exampleNo request body
curl -X DELETE https://api.rieckflow.com/v1/branding/logo \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041"
204 No contentNo response body
Possible errors 7
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
429rate_limitedThe organisation’s rate budget is exhausted.

Get payment domain

settings:read
Request exampleNo request body
curl https://api.rieckflow.com/v1/payment-domain \
-H "Authorization: Bearer $RIECK_API_KEY"
200 Success envelopeapplication/json
Response fields 2
FieldTypeDescription
data.domainstring | nullCustom hosted-payment domain.
data.verifiedbooleanWhether DNS verification has passed.
Possible errors 4
HTTPCodeMeaning
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
429rate_limitedThe organisation’s rate budget is exhausted.

Set payment domain

settings:write

Changing the domain resets verification.

Request body fields 1
FieldTypeRequiredDescription
domainstringYesField in the request payload.
Request exampleapplication/json
curl -X PUT https://api.rieckflow.com/v1/payment-domain \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041" \
-H "Content-Type: application/json" \
-d '{
"domain": "…"
}'
200 Success envelopeapplication/json
Response fields 2
FieldTypeDescription
data.domainstring | nullCustom hosted-payment domain.
data.verifiedbooleanWhether DNS verification has passed.
Possible errors 9
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
400invalid_requestThe request body or parameter failed validation.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
413payload_too_largeThe JSON or uploaded file exceeds this endpoint’s size limit.
429rate_limitedThe organisation’s rate budget is exhausted.
Request body — fuldt JSON Schema
{
"type": "object",
"properties": {
"domain": {
"anyOf": [
{
"type": "string",
"minLength": 1,
"maxLength": 255
},
{
"type": "null"
}
]
}
},
"required": [
"domain"
],
"additionalProperties": false
}

Run live domain check

settings:write
Request exampleNo request body
curl -X POST https://api.rieckflow.com/v1/payment-domain/verify \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041"
200 Success envelopeapplication/json
Possible errors 8
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
422no_domain_configuredConfigure a domain before requesting verification.
429rate_limitedThe organisation’s rate budget is exhausted.

List embed origins

settings:read
Request exampleNo request body
curl https://api.rieckflow.com/v1/embed-origins \
-H "Authorization: Bearer $RIECK_API_KEY"
200 The origins allowed to frame the embedded payment window, with each origin’s verification token.application/json
Response fields 3
FieldTypeDescription
data.originurlOrigin allowed to frame the embedded payment window.
data.verifiedbooleanWhether the verification file was accepted.
data.verificationTokenstringExact token to publish at verificationPath.
Possible errors 4
HTTPCodeMeaning
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
429rate_limitedThe organisation’s rate budget is exhausted.

Register an embed origin

settings:write

Idempotent per origin. Registration alone grants nothing: publish the returned verificationToken at verificationPath on the origin, then POST /verify. Until verified, the origin cannot frame the payment window.

Request body fields 1
FieldTypeRequiredDescription
originstringYesField in the request payload.
Request exampleapplication/json
curl -X POST https://api.rieckflow.com/v1/embed-origins \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041" \
-H "Content-Type: application/json" \
-d '{
"origin": "…"
}'
201 Success envelopeapplication/json
Response fields 3
FieldTypeDescription
data.originurlOrigin allowed to frame the embedded payment window.
data.verifiedbooleanWhether the verification file was accepted.
data.verificationTokenstringExact token to publish at verificationPath.
Possible errors 9
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
400invalid_requestThe request body or parameter failed validation.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
413payload_too_largeThe JSON or uploaded file exceeds this endpoint’s size limit.
429rate_limitedThe organisation’s rate budget is exhausted.
Request body — fuldt JSON Schema
{
"type": "object",
"properties": {
"origin": {
"type": "string",
"minLength": 1,
"maxLength": 255
}
},
"required": [
"origin"
],
"additionalProperties": false
}

Get an embed origin

settings:read
ParameterInTypeRequiredDescription
originIdpathstringYes
Request exampleNo request body
curl https://api.rieckflow.com/v1/embed-origins/9b2f1c1e-… \
-H "Authorization: Bearer $RIECK_API_KEY"
200 Success envelopeapplication/json
Response fields 3
FieldTypeDescription
data.originurlOrigin allowed to frame the embedded payment window.
data.verifiedbooleanWhether the verification file was accepted.
data.verificationTokenstringExact token to publish at verificationPath.
Possible errors 5
HTTPCodeMeaning
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
404embed_origin_not_foundThe embed origin does not exist or belongs to another organisation.
429rate_limitedThe organisation’s rate budget is exhausted.

Remove an embed origin

settings:write
ParameterInTypeRequiredDescription
originIdpathstringYes
Request exampleNo request body
curl -X DELETE https://api.rieckflow.com/v1/embed-origins/9b2f1c1e-… \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041"
204 Takes effect immediately — the embed shell resolves the allowlist per request.No response body
Possible errors 8
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
404embed_origin_not_foundThe embed origin does not exist or belongs to another organisation.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
429rate_limitedThe organisation’s rate budget is exhausted.

Verify an embed origin

settings:write

Fetches the token file from your own origin over HTTPS. Status: verified, file_missing, token_mismatch, not_reachable, invalid.

ParameterInTypeRequiredDescription
originIdpathstringYes
Request exampleNo request body
curl -X POST https://api.rieckflow.com/v1/embed-origins/9b2f1c1e-…/verify \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041"
200 Success envelopeapplication/json
Possible errors 8
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
404embed_origin_not_foundThe embed origin does not exist or belongs to another organisation.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
429rate_limitedThe organisation’s rate budget is exhausted.

Get customer-portal settings

settings:read
Request exampleNo request body
curl https://api.rieckflow.com/v1/customer-portal \
-H "Authorization: Bearer $RIECK_API_KEY"
200 Success envelopeapplication/json
Response fields 3
FieldTypeDescription
data.subdomainstring | nullRieck-hosted customer portal subdomain.
data.customDomainVerifiedbooleanWhether the custom hostname is live.
data.urlurl | nullPublic portal URL currently safe to open.
Possible errors 4
HTTPCodeMeaning
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
429rate_limitedThe organisation’s rate budget is exhausted.

Update customer-portal settings

settings:write
Request body fields 6
FieldTypeRequiredDescription
subdomainstringNoField in the request payload.
activebooleanNoWhether the resource is active.
subscriptionSelfServicebooleanNoField in the request payload.
primaryColorstringNoField in the request payload.
palettestringNoField in the request payload.
customDomainstringNoField in the request payload.
Request exampleapplication/json
curl -X PATCH https://api.rieckflow.com/v1/customer-portal \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041" \
-H "Content-Type: application/json" \
-d '{
"active": true,
"subscriptionSelfService": true
}'
200 Success envelopeapplication/json
Response fields 3
FieldTypeDescription
data.subdomainstring | nullRieck-hosted customer portal subdomain.
data.customDomainVerifiedbooleanWhether the custom hostname is live.
data.urlurl | nullPublic portal URL currently safe to open.
Possible errors 9
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
400invalid_requestThe request body or parameter failed validation.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
413payload_too_largeThe JSON or uploaded file exceeds this endpoint’s size limit.
429rate_limitedThe organisation’s rate budget is exhausted.
Request body — fuldt JSON Schema
{
"type": "object",
"properties": {
"subdomain": {
"type": "string",
"pattern": "^[a-z0-9][a-z0-9-]{1,38}[a-z0-9]$"
},
"active": {
"type": "boolean"
},
"subscriptionSelfService": {
"type": "boolean"
},
"primaryColor": {
"anyOf": [
{
"type": "string",
"pattern": "^#[0-9a-fA-F]{6}$"
},
{
"type": "null"
}
]
},
"palette": {
"type": "string",
"enum": [
"laerred",
"smoer",
"lys",
"beton",
"sand",
"graa",
"mint",
"blaa",
"is",
"groen",
"varm",
"lavendel",
"rosa",
"moerk",
"midnat",
"grafit",
"skov",
"espresso",
"vin"
]
},
"customDomain": {
"anyOf": [
{
"type": "string",
"minLength": 1,
"maxLength": 255
},
{
"type": "null"
}
]
}
},
"additionalProperties": false
}

Verify portal custom domain

settings:write
Request exampleNo request body
curl -X POST https://api.rieckflow.com/v1/customer-portal/verify-domain \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041"
200 Success envelopeapplication/json
Possible errors 8
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
422no_domain_configuredConfigure a domain before requesting verification.
429rate_limitedThe organisation’s rate budget is exhausted.