> ## Documentation Index
> Fetch the complete documentation index at: https://docs.artbucket.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Brand portals

> The workspace's portals.

Scope: `write`.



## OpenAPI

````yaml /openapi.json get /api/v1/portals
openapi: 3.1.0
info:
  title: artbucket
  version: '1'
  description: >-
    Agent-first asset management. The web UI is built on this API and nothing
    else, beside signing in at /api/auth. Send `Authorization: Bearer <key>`: a
    key works in one workspace with one scope, and scopes are a ladder: read <
    propose < write < admin. People signed in to the app carry a session cookie
    instead, and their scope is what their grants add up to: on the
    organization, the workspace, or single collections and assets. A scope shown
    as needed on the workspace is also enough on the one collection or asset a
    route acts on. Agents (MCP at POST /api/v1/mcp) usually get `propose`: what
    they add waits for a human.
servers:
  - url: http://localhost:3000
security:
  - bearer: []
  - session: []
  - {}
paths:
  /api/v1/portals:
    get:
      summary: Brand portals
      description: |-
        The workspace's portals.

        Scope: `write`.
      responses:
        '200':
          description: Portals
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      type: object
                      properties:
                        id:
                          type: string
                          format: uuid
                          pattern: >-
                            ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                        slug:
                          type: string
                        name:
                          type: string
                        intro:
                          type:
                            - string
                            - 'null'
                        access:
                          type: string
                          enum:
                            - public
                            - password
                            - members
                        password:
                          type: boolean
                        expiresAt:
                          anyOf:
                            - type: string
                              format: date-time
                              pattern: >-
                                ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d+)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
                            - type: 'null'
                        expired:
                          type: boolean
                        presets:
                          type: array
                          items:
                            type: string
                            enum:
                              - web
                              - social
                              - story
                              - print
                              - png
                              - original
                        theme:
                          type: object
                          properties:
                            logo:
                              default: null
                              description: An approved image asset, shown in the header
                              anyOf:
                                - type: string
                                  format: uuid
                                  pattern: >-
                                    ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                                - type: 'null'
                            accent:
                              default: null
                              description: Buttons and links
                              anyOf:
                                - type: string
                                  pattern: ^#[0-9a-fA-F]{6}$
                                - type: 'null'
                            background:
                              default: null
                              description: The page behind everything
                              anyOf:
                                - type: string
                                  pattern: ^#[0-9a-fA-F]{6}$
                                - type: 'null'
                          required:
                            - logo
                            - accent
                            - background
                          additionalProperties: false
                        collections:
                          type: array
                          items:
                            type: object
                            properties:
                              id:
                                type: string
                                format: uuid
                                pattern: >-
                                  ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                              name:
                                type: string
                            required:
                              - id
                              - name
                            additionalProperties: false
                        brands:
                          type: array
                          items:
                            type: object
                            properties:
                              slug:
                                type: string
                              name:
                                type: string
                            required:
                              - slug
                              - name
                            additionalProperties: false
                          description: Brands whose guidelines it publishes, in tab order
                        domain:
                          anyOf:
                            - type: object
                              properties:
                                host:
                                  type: string
                                verified:
                                  type: boolean
                                record:
                                  type: object
                                  properties:
                                    type:
                                      type: string
                                      const: TXT
                                    name:
                                      type: string
                                    value:
                                      type: string
                                  required:
                                    - type
                                    - name
                                    - value
                                  additionalProperties: false
                                  description: >-
                                    What proves it: add this record at your DNS
                                    host
                                cname:
                                  anyOf:
                                    - type: object
                                      properties:
                                        type:
                                          type: string
                                          const: CNAME
                                        name:
                                          type: string
                                        value:
                                          type: string
                                      required:
                                        - type
                                        - name
                                        - value
                                      additionalProperties: false
                                    - type: 'null'
                                  description: >-
                                    Where to point it, when the server says
                                    (DOMAIN_TARGET); null: at this server
                              required:
                                - host
                                - verified
                                - record
                                - cname
                              additionalProperties: false
                            - type: 'null'
                        url:
                          type: string
                          format: uri
                          description: >-
                            Where visitors go: its domain once verified, else
                            /p/{slug}
                        pending:
                          type: integer
                          minimum: -9007199254740991
                          maximum: 9007199254740991
                          description: Access requests waiting
                        createdBy:
                          type: string
                        createdAt:
                          type: string
                          format: date-time
                          pattern: >-
                            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d+)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
                        updatedAt:
                          type: string
                          format: date-time
                          pattern: >-
                            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d+)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
                      required:
                        - id
                        - slug
                        - name
                        - intro
                        - access
                        - password
                        - expiresAt
                        - expired
                        - presets
                        - theme
                        - collections
                        - brands
                        - domain
                        - url
                        - pending
                        - createdBy
                        - createdAt
                        - updatedAt
                      additionalProperties: false
                required:
                  - data
                additionalProperties: false
        default:
          description: An error
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                      message:
                        type: string
                      detail: {}
                    required:
                      - code
                      - message
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
components:
  securitySchemes:
    bearer:
      type: http
      scheme: bearer
      description: 'An API key: ab_...'
    session:
      type: apiKey
      in: cookie
      name: better-auth.session_token
      description: Signed in, at /api/auth

````