> ## Documentation Index
> Fetch the complete documentation index at: https://docs.1club.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Get the website's theme

> What the site has chosen, what that resolves to once the organization's branding and the declared defaults are applied, and which of the three supplied each value.
`sources` is the field to read before changing anything: it tells you whether a colour is one the customer picked for this website (`site`), the organization's brand colour (`branding`), or a platform default. Overwriting a `branding` value is how a site quietly stops matching the rest of the customer's brand, so prefer leaving those alone unless asked.
A token missing from `resolved` is one whose fallback is computed by the stylesheet from the palette - the surface, muted-text and border colours - rather than one that has no value.




## OpenAPI

````yaml /openapi-platform.json get /v1/platform/website/theme
openapi: 3.0.0
info:
  title: 1club Platform API
  version: 1.0.0
  description: >-
    The 1club Platform API lets you programmatically access and manage your
    organization's data.


    ## Official API Contract


    This documentation is the official source of truth for the 1club Platform
    API.

    If an integration relies on undocumented endpoints, fields, response shapes,
    or internal behavior outside this spec, we can't guarantee backward
    compatibility.

    Build against what's documented here to stay stable as the platform evolves.


    ## Authentication


    All requests require a customer API key passed as a Bearer token:


    ```

    Authorization: Bearer 1club_sk_live_...

    ```


    Generate API keys from the admin portal under **Settings > API Tokens**.

    The key is tied to your organization - all responses are scoped to your
    org's data.


    ## Rate Limiting


    - **100 requests per minute** per API key

    - When exceeded, the API returns `429 Too Many Requests` with a
    `Retry-After` header

    - Rate limit headers are included in every response:
      - `X-RateLimit-Limit` - max requests per window
      - `X-RateLimit-Remaining` - requests remaining
      - `X-RateLimit-Reset` - seconds until the window resets

    ## Errors


    | Status | Meaning |

    |--------|---------|

    | `400` | Invalid request parameters |

    | `401` | Missing or invalid API key |

    | `404` | Resource not found (or doesn't belong to your organization) |

    | `429` | Rate limit exceeded |

    | `500` | Internal server error |
  contact:
    name: 1club API Support
    email: support@1club.ai
servers:
  - url: https://api.1club.ai
    description: Production API
security:
  - customerApiAuth: []
tags: []
paths:
  /v1/platform/website/theme:
    get:
      tags:
        - Website
      summary: Get the website's theme
      description: >
        What the site has chosen, what that resolves to once the organization's
        branding and the declared defaults are applied, and which of the three
        supplied each value.

        `sources` is the field to read before changing anything: it tells you
        whether a colour is one the customer picked for this website (`site`),
        the organization's brand colour (`branding`), or a platform default.
        Overwriting a `branding` value is how a site quietly stops matching the
        rest of the customer's brand, so prefer leaving those alone unless
        asked.

        A token missing from `resolved` is one whose fallback is computed by the
        stylesheet from the palette - the surface, muted-text and border colours
        - rather than one that has no value.
      parameters:
        - in: query
          name: siteId
          schema:
            type: integer
      responses:
        '200':
          description: The site theme
          content:
            application/json:
              schema:
                type: object
                properties:
                  stored:
                    type: object
                    description: >-
                      Exactly what this website has set. Absent keys are
                      inherited.
                    additionalProperties: true
                  resolved:
                    type: object
                    description: What each token renders as, inheritance applied.
                    additionalProperties: true
                  sources:
                    type: object
                    description: 'Per token: `site`, `branding` or `default`.'
                    additionalProperties:
                      type: string
        '401':
          $ref: '#/components/responses/PlatformUnauthorized'
        '403':
          description: API key is missing the required `website:read` scope
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PlatformError'
        '404':
          description: The organization has no website
        '429':
          $ref: '#/components/responses/PlatformRateLimited'
      security:
        - customerApiAuth: []
components:
  responses:
    PlatformUnauthorized:
      description: Invalid or missing API key
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/PlatformError'
    PlatformRateLimited:
      description: Rate limit exceeded
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/PlatformError'
  schemas:
    PlatformError:
      type: object
      properties:
        error:
          type: string
  securitySchemes:
    customerApiAuth:
      type: http
      scheme: bearer
      description: >-
        Organization-scoped bearer credential: a customer API key
        (1club_sk_live_...) or an MCP OAuth access token.

````