Branding
GET /v1/branding
Section titled “GET /v1/branding”Request exampleNo request body
curl https://api.rieckflow.com/v1/branding \ -H "Authorization: Bearer $RIECK_API_KEY"const svar = await rieck.request("GET", "/v1/branding");{ "data": { "logo": { "present": true, "mime": "image/svg+xml" }, "darkLogo": { "present": true } }}200 Success envelopeapplication/json
Possible errors 4
| HTTP | Code | Meaning |
|---|---|---|
| 401 | invalid_api_key | The API key is missing, invalid, expired or revoked. |
| 403 | api_not_included | The organisation’s plan does not include API access. |
| 403 | insufficient_scope | The key does not have the required scope. |
| 429 | rate_limited | The organisation’s rate budget is exhausted. |
PUT /v1/branding/logo
Section titled “PUT /v1/branding/logo”Request body fields 3
| Field | Type | Required | Description |
|---|---|---|---|
data | string | Yes | Field in the request payload. |
mime | string | Yes | Field in the request payload. |
variant | string | No | Field in the request payload. |
Request exampleapplication/json
curl -X PUT https://api.rieckflow.com/v1/branding/logo \ -H "Authorization: Bearer $RIECK_API_KEY" \ -H "Idempotency-Key: order-2041" \ -H "Content-Type: application/json" \ -d '{ "data": "…", "mime": "image/png", "variant": "light" }'const svar = await rieck.request("PUT", "/v1/branding/logo", { body: { "data": "…", "mime": "image/png", "variant": "light" },});{ "data": { "logo": { "present": true, "mime": "image/svg+xml" }, "darkLogo": { "present": true } }}200 Success envelopeapplication/json
Possible errors 9
| HTTP | Code | Meaning |
|---|---|---|
| 400 | invalid_idempotency_key | Idempotency-Key is missing or malformed. |
| 400 | invalid_request | The request body or parameter failed validation. |
| 401 | invalid_api_key | The API key is missing, invalid, expired or revoked. |
| 403 | api_not_included | The organisation’s plan does not include API access. |
| 403 | insufficient_scope | The key does not have the required scope. |
| 409 | idempotency_conflict | The same key was used with a different request. |
| 409 | idempotency_in_progress | The same operation is currently being processed. Retry later. |
| 413 | payload_too_large | The JSON or uploaded file exceeds this endpoint’s size limit. |
| 429 | rate_limited | The organisation’s rate budget is exhausted. |
Request body — fuldt JSON Schema
{ "type": "object", "properties": { "data": { "type": "string", "minLength": 1 }, "mime": { "type": "string", "enum": [ "image/png", "image/jpeg", "image/svg+xml", "image/webp" ] }, "variant": { "default": "light", "type": "string", "enum": [ "light", "dark" ] } }, "required": [ "data", "mime" ], "additionalProperties": false}DELETE /v1/branding/logo
Section titled “DELETE /v1/branding/logo”| Parameter | In | Type | Required | Description |
|---|---|---|---|---|
variant | query | string | No | light (default) or dark |
Request exampleNo request body
curl -X DELETE https://api.rieckflow.com/v1/branding/logo \ -H "Authorization: Bearer $RIECK_API_KEY" \ -H "Idempotency-Key: order-2041"const svar = await rieck.request("DELETE", "/v1/branding/logo");204 No contentNo response body
Possible errors 7
| HTTP | Code | Meaning |
|---|---|---|
| 400 | invalid_idempotency_key | Idempotency-Key is missing or malformed. |
| 401 | invalid_api_key | The API key is missing, invalid, expired or revoked. |
| 403 | api_not_included | The organisation’s plan does not include API access. |
| 403 | insufficient_scope | The key does not have the required scope. |
| 409 | idempotency_conflict | The same key was used with a different request. |
| 409 | idempotency_in_progress | The same operation is currently being processed. Retry later. |
| 429 | rate_limited | The organisation’s rate budget is exhausted. |
GET /v1/payment-domain
Section titled “GET /v1/payment-domain”Request exampleNo request body
curl https://api.rieckflow.com/v1/payment-domain \ -H "Authorization: Bearer $RIECK_API_KEY"const svar = await rieck.request("GET", "/v1/payment-domain");{ "data": { "domain": "pay.acme.example", "verified": true, "verifiedAt": "2026-08-04T09:32:11Z" }}200 Success envelopeapplication/json
Response fields 2
| Field | Type | Description |
|---|---|---|
data.domain | string | null | Custom hosted-payment domain. |
data.verified | boolean | Whether DNS verification has passed. |
Possible errors 4
| HTTP | Code | Meaning |
|---|---|---|
| 401 | invalid_api_key | The API key is missing, invalid, expired or revoked. |
| 403 | api_not_included | The organisation’s plan does not include API access. |
| 403 | insufficient_scope | The key does not have the required scope. |
| 429 | rate_limited | The organisation’s rate budget is exhausted. |
PUT /v1/payment-domain
Section titled “PUT /v1/payment-domain”Changing the domain resets verification.
Request body fields 1
| Field | Type | Required | Description |
|---|---|---|---|
domain | string | Yes | Field in the request payload. |
Request exampleapplication/json
curl -X PUT https://api.rieckflow.com/v1/payment-domain \ -H "Authorization: Bearer $RIECK_API_KEY" \ -H "Idempotency-Key: order-2041" \ -H "Content-Type: application/json" \ -d '{ "domain": "…" }'const svar = await rieck.request("PUT", "/v1/payment-domain", { body: { "domain": "…" },});{ "data": { "domain": "pay.acme.example", "verified": true, "verifiedAt": "2026-08-04T09:32:11Z" }}200 Success envelopeapplication/json
Response fields 2
| Field | Type | Description |
|---|---|---|
data.domain | string | null | Custom hosted-payment domain. |
data.verified | boolean | Whether DNS verification has passed. |
Possible errors 9
| HTTP | Code | Meaning |
|---|---|---|
| 400 | invalid_idempotency_key | Idempotency-Key is missing or malformed. |
| 400 | invalid_request | The request body or parameter failed validation. |
| 401 | invalid_api_key | The API key is missing, invalid, expired or revoked. |
| 403 | api_not_included | The organisation’s plan does not include API access. |
| 403 | insufficient_scope | The key does not have the required scope. |
| 409 | idempotency_conflict | The same key was used with a different request. |
| 409 | idempotency_in_progress | The same operation is currently being processed. Retry later. |
| 413 | payload_too_large | The JSON or uploaded file exceeds this endpoint’s size limit. |
| 429 | rate_limited | The organisation’s rate budget is exhausted. |
Request body — fuldt JSON Schema
{ "type": "object", "properties": { "domain": { "anyOf": [ { "type": "string", "minLength": 1, "maxLength": 255 }, { "type": "null" } ] } }, "required": [ "domain" ], "additionalProperties": false}POST /v1/payment-domain/verify
Section titled “POST /v1/payment-domain/verify”Request exampleNo request body
curl -X POST https://api.rieckflow.com/v1/payment-domain/verify \ -H "Authorization: Bearer $RIECK_API_KEY" \ -H "Idempotency-Key: order-2041"const svar = await rieck.request("POST", "/v1/payment-domain/verify");{ "data": { "domain": "pay.acme.example", "status": "verified", "verified": true }}200 Success envelopeapplication/json
Possible errors 8
| HTTP | Code | Meaning |
|---|---|---|
| 400 | invalid_idempotency_key | Idempotency-Key is missing or malformed. |
| 401 | invalid_api_key | The API key is missing, invalid, expired or revoked. |
| 403 | api_not_included | The organisation’s plan does not include API access. |
| 403 | insufficient_scope | The key does not have the required scope. |
| 409 | idempotency_conflict | The same key was used with a different request. |
| 409 | idempotency_in_progress | The same operation is currently being processed. Retry later. |
| 422 | no_domain_configured | Configure a domain before requesting verification. |
| 429 | rate_limited | The organisation’s rate budget is exhausted. |
GET /v1/embed-origins
Section titled “GET /v1/embed-origins”Request exampleNo request body
curl https://api.rieckflow.com/v1/embed-origins \ -H "Authorization: Bearer $RIECK_API_KEY"const svar = await rieck.request("GET", "/v1/embed-origins");{ "data": { "id": "9b2f1c1e-6b87-4d9b-91a0-47c8d72b8440", "origin": "https://app.acme.example", "verified": true, "verifiedAt": "2026-08-04T09:32:11Z", "verificationToken": "rieck-verify=7d3264f1a93b", "verificationPath": "/.well-known/rieck-embed-verification.txt" }}200 The origins allowed to frame the embedded payment window, with each origin’s verification token.application/json
Response fields 3
| Field | Type | Description |
|---|---|---|
data.origin | url | Origin allowed to frame the embedded payment window. |
data.verified | boolean | Whether the verification file was accepted. |
data.verificationToken | string | Exact token to publish at verificationPath. |
Possible errors 4
| HTTP | Code | Meaning |
|---|---|---|
| 401 | invalid_api_key | The API key is missing, invalid, expired or revoked. |
| 403 | api_not_included | The organisation’s plan does not include API access. |
| 403 | insufficient_scope | The key does not have the required scope. |
| 429 | rate_limited | The organisation’s rate budget is exhausted. |
POST /v1/embed-origins
Section titled “POST /v1/embed-origins”Idempotent per origin. Registration alone grants nothing: publish the returned verificationToken at verificationPath on the origin, then POST /verify. Until verified, the origin cannot frame the payment window.
Request body fields 1
| Field | Type | Required | Description |
|---|---|---|---|
origin | string | Yes | Field in the request payload. |
Request exampleapplication/json
curl -X POST https://api.rieckflow.com/v1/embed-origins \ -H "Authorization: Bearer $RIECK_API_KEY" \ -H "Idempotency-Key: order-2041" \ -H "Content-Type: application/json" \ -d '{ "origin": "…" }'const svar = await rieck.request("POST", "/v1/embed-origins", { body: { "origin": "…" },});{ "data": { "id": "9b2f1c1e-6b87-4d9b-91a0-47c8d72b8440", "origin": "https://app.acme.example", "verified": true, "verifiedAt": "2026-08-04T09:32:11Z", "verificationToken": "rieck-verify=7d3264f1a93b", "verificationPath": "/.well-known/rieck-embed-verification.txt" }}201 Success envelopeapplication/json
Response fields 3
| Field | Type | Description |
|---|---|---|
data.origin | url | Origin allowed to frame the embedded payment window. |
data.verified | boolean | Whether the verification file was accepted. |
data.verificationToken | string | Exact token to publish at verificationPath. |
Possible errors 9
| HTTP | Code | Meaning |
|---|---|---|
| 400 | invalid_idempotency_key | Idempotency-Key is missing or malformed. |
| 400 | invalid_request | The request body or parameter failed validation. |
| 401 | invalid_api_key | The API key is missing, invalid, expired or revoked. |
| 403 | api_not_included | The organisation’s plan does not include API access. |
| 403 | insufficient_scope | The key does not have the required scope. |
| 409 | idempotency_conflict | The same key was used with a different request. |
| 409 | idempotency_in_progress | The same operation is currently being processed. Retry later. |
| 413 | payload_too_large | The JSON or uploaded file exceeds this endpoint’s size limit. |
| 429 | rate_limited | The organisation’s rate budget is exhausted. |
Request body — fuldt JSON Schema
{ "type": "object", "properties": { "origin": { "type": "string", "minLength": 1, "maxLength": 255 } }, "required": [ "origin" ], "additionalProperties": false}GET /v1/embed-origins/{originId}
Section titled “GET /v1/embed-origins/{originId}”| Parameter | In | Type | Required | Description |
|---|---|---|---|---|
originId | path | string | Yes |
Request exampleNo request body
curl https://api.rieckflow.com/v1/embed-origins/9b2f1c1e-… \ -H "Authorization: Bearer $RIECK_API_KEY"const svar = await rieck.request("GET", "/v1/embed-origins/9b2f1c1e-…");{ "data": { "id": "9b2f1c1e-6b87-4d9b-91a0-47c8d72b8440", "origin": "https://app.acme.example", "verified": true, "verifiedAt": "2026-08-04T09:32:11Z", "verificationToken": "rieck-verify=7d3264f1a93b", "verificationPath": "/.well-known/rieck-embed-verification.txt" }}200 Success envelopeapplication/json
Response fields 3
| Field | Type | Description |
|---|---|---|
data.origin | url | Origin allowed to frame the embedded payment window. |
data.verified | boolean | Whether the verification file was accepted. |
data.verificationToken | string | Exact token to publish at verificationPath. |
Possible errors 5
| HTTP | Code | Meaning |
|---|---|---|
| 401 | invalid_api_key | The API key is missing, invalid, expired or revoked. |
| 403 | api_not_included | The organisation’s plan does not include API access. |
| 403 | insufficient_scope | The key does not have the required scope. |
| 404 | embed_origin_not_found | The embed origin does not exist or belongs to another organisation. |
| 429 | rate_limited | The organisation’s rate budget is exhausted. |
DELETE /v1/embed-origins/{originId}
Section titled “DELETE /v1/embed-origins/{originId}”| Parameter | In | Type | Required | Description |
|---|---|---|---|---|
originId | path | string | Yes |
Request exampleNo request body
curl -X DELETE https://api.rieckflow.com/v1/embed-origins/9b2f1c1e-… \ -H "Authorization: Bearer $RIECK_API_KEY" \ -H "Idempotency-Key: order-2041"const svar = await rieck.request("DELETE", "/v1/embed-origins/9b2f1c1e-…");204 Takes effect immediately — the embed shell resolves the allowlist per request.No response body
Possible errors 8
| HTTP | Code | Meaning |
|---|---|---|
| 400 | invalid_idempotency_key | Idempotency-Key is missing or malformed. |
| 401 | invalid_api_key | The API key is missing, invalid, expired or revoked. |
| 403 | api_not_included | The organisation’s plan does not include API access. |
| 403 | insufficient_scope | The key does not have the required scope. |
| 404 | embed_origin_not_found | The embed origin does not exist or belongs to another organisation. |
| 409 | idempotency_conflict | The same key was used with a different request. |
| 409 | idempotency_in_progress | The same operation is currently being processed. Retry later. |
| 429 | rate_limited | The organisation’s rate budget is exhausted. |
POST /v1/embed-origins/{originId}/verify
Section titled “POST /v1/embed-origins/{originId}/verify”Fetches the token file from your own origin over HTTPS. Status: verified, file_missing, token_mismatch, not_reachable, invalid.
| Parameter | In | Type | Required | Description |
|---|---|---|---|---|
originId | path | string | Yes |
Request exampleNo request body
curl -X POST https://api.rieckflow.com/v1/embed-origins/9b2f1c1e-…/verify \ -H "Authorization: Bearer $RIECK_API_KEY" \ -H "Idempotency-Key: order-2041"const svar = await rieck.request("POST", "/v1/embed-origins/9b2f1c1e-…/verify");{ "data": { "id": "9b2f1c1e-6b87-4d9b-91a0-47c8d72b8440", "origin": "https://app.acme.example", "status": "verified", "verified": true }}200 Success envelopeapplication/json
Possible errors 8
| HTTP | Code | Meaning |
|---|---|---|
| 400 | invalid_idempotency_key | Idempotency-Key is missing or malformed. |
| 401 | invalid_api_key | The API key is missing, invalid, expired or revoked. |
| 403 | api_not_included | The organisation’s plan does not include API access. |
| 403 | insufficient_scope | The key does not have the required scope. |
| 404 | embed_origin_not_found | The embed origin does not exist or belongs to another organisation. |
| 409 | idempotency_conflict | The same key was used with a different request. |
| 409 | idempotency_in_progress | The same operation is currently being processed. Retry later. |
| 429 | rate_limited | The organisation’s rate budget is exhausted. |
GET /v1/customer-portal
Section titled “GET /v1/customer-portal”Request exampleNo request body
curl https://api.rieckflow.com/v1/customer-portal \ -H "Authorization: Bearer $RIECK_API_KEY"const svar = await rieck.request("GET", "/v1/customer-portal");{ "data": { "subdomain": "acme", "active": true, "subscriptionSelfService": true, "primaryColor": "#005a4f", "palette": "groen", "customDomain": "customers.acme.example", "customDomainVerified": true, "url": "https://customers.acme.example" }}200 Success envelopeapplication/json
Response fields 3
| Field | Type | Description |
|---|---|---|
data.subdomain | string | null | Rieck-hosted customer portal subdomain. |
data.customDomainVerified | boolean | Whether the custom hostname is live. |
data.url | url | null | Public portal URL currently safe to open. |
Possible errors 4
| HTTP | Code | Meaning |
|---|---|---|
| 401 | invalid_api_key | The API key is missing, invalid, expired or revoked. |
| 403 | api_not_included | The organisation’s plan does not include API access. |
| 403 | insufficient_scope | The key does not have the required scope. |
| 429 | rate_limited | The organisation’s rate budget is exhausted. |
PATCH /v1/customer-portal
Section titled “PATCH /v1/customer-portal”Request body fields 6
| Field | Type | Required | Description |
|---|---|---|---|
subdomain | string | No | Field in the request payload. |
active | boolean | No | Whether the resource is active. |
subscriptionSelfService | boolean | No | Field in the request payload. |
primaryColor | string | No | Field in the request payload. |
palette | string | No | Field in the request payload. |
customDomain | string | No | Field in the request payload. |
Request exampleapplication/json
curl -X PATCH https://api.rieckflow.com/v1/customer-portal \ -H "Authorization: Bearer $RIECK_API_KEY" \ -H "Idempotency-Key: order-2041" \ -H "Content-Type: application/json" \ -d '{ "active": true, "subscriptionSelfService": true }'const svar = await rieck.request("PATCH", "/v1/customer-portal", { body: { "active": true, "subscriptionSelfService": true },});{ "data": { "subdomain": "acme", "active": true, "subscriptionSelfService": true, "primaryColor": "#005a4f", "palette": "groen", "customDomain": "customers.acme.example", "customDomainVerified": true, "url": "https://customers.acme.example" }}200 Success envelopeapplication/json
Response fields 3
| Field | Type | Description |
|---|---|---|
data.subdomain | string | null | Rieck-hosted customer portal subdomain. |
data.customDomainVerified | boolean | Whether the custom hostname is live. |
data.url | url | null | Public portal URL currently safe to open. |
Possible errors 9
| HTTP | Code | Meaning |
|---|---|---|
| 400 | invalid_idempotency_key | Idempotency-Key is missing or malformed. |
| 400 | invalid_request | The request body or parameter failed validation. |
| 401 | invalid_api_key | The API key is missing, invalid, expired or revoked. |
| 403 | api_not_included | The organisation’s plan does not include API access. |
| 403 | insufficient_scope | The key does not have the required scope. |
| 409 | idempotency_conflict | The same key was used with a different request. |
| 409 | idempotency_in_progress | The same operation is currently being processed. Retry later. |
| 413 | payload_too_large | The JSON or uploaded file exceeds this endpoint’s size limit. |
| 429 | rate_limited | The organisation’s rate budget is exhausted. |
Request body — fuldt JSON Schema
{ "type": "object", "properties": { "subdomain": { "type": "string", "pattern": "^[a-z0-9][a-z0-9-]{1,38}[a-z0-9]$" }, "active": { "type": "boolean" }, "subscriptionSelfService": { "type": "boolean" }, "primaryColor": { "anyOf": [ { "type": "string", "pattern": "^#[0-9a-fA-F]{6}$" }, { "type": "null" } ] }, "palette": { "type": "string", "enum": [ "laerred", "smoer", "lys", "beton", "sand", "graa", "mint", "blaa", "is", "groen", "varm", "lavendel", "rosa", "moerk", "midnat", "grafit", "skov", "espresso", "vin" ] }, "customDomain": { "anyOf": [ { "type": "string", "minLength": 1, "maxLength": 255 }, { "type": "null" } ] } }, "additionalProperties": false}POST /v1/customer-portal/verify-domain
Section titled “POST /v1/customer-portal/verify-domain”Request exampleNo request body
curl -X POST https://api.rieckflow.com/v1/customer-portal/verify-domain \ -H "Authorization: Bearer $RIECK_API_KEY" \ -H "Idempotency-Key: order-2041"const svar = await rieck.request("POST", "/v1/customer-portal/verify-domain");{ "data": { "domain": "pay.acme.example", "status": "verified", "verified": true }}200 Success envelopeapplication/json
Possible errors 8
| HTTP | Code | Meaning |
|---|---|---|
| 400 | invalid_idempotency_key | Idempotency-Key is missing or malformed. |
| 401 | invalid_api_key | The API key is missing, invalid, expired or revoked. |
| 403 | api_not_included | The organisation’s plan does not include API access. |
| 403 | insufficient_scope | The key does not have the required scope. |
| 409 | idempotency_conflict | The same key was used with a different request. |
| 409 | idempotency_in_progress | The same operation is currently being processed. Retry later. |
| 422 | no_domain_configured | Configure a domain before requesting verification. |
| 429 | rate_limited | The organisation’s rate budget is exhausted. |