> ## Documentation Index
> Fetch the complete documentation index at: https://docs.1club.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Set the website's design tokens

> Merges a flat token patch into the site's theme, optionally on top of a named preset. Read `GET /theme-tokens` first for the tokens, their allowed values and the presets.
**This writes the draft**, like every other edit here - nothing a visitor sees changes until `POST /releases` publishes it. That is the point of tokens living on the website rather than on the organization's branding: a palette change is previewable, versioned in the release, and revertible.
Merges field by field, so setting the heading font leaves the palette alone. Send `null` for a token to return it to what it inherits - from the organization's branding, from another token, or from the platform default. That is the only way back once a value has been written; there is no "unset" string.
A `preset` is the exception to that merge: it REPLACES the look rather than adding to it. Every token any preset owns is cleared first, then the chosen preset's values are written. Otherwise switching from `night` to `editorial` would keep night's whole dark palette underneath and leave the site describing a hybrid nobody chose. Tokens no preset owns - a hand-picked brand colour - are untouched.
When `preset` and `tokens` are both sent the preset is applied first and the tokens land on top, so "use the editorial look but keep our heading font" is one call.
Every problem with a patch is reported at once rather than one at a time. Tokens are validated against the catalog: an unknown key, a value outside a token's options, a font the site cannot load, or a colour that is not a hex are all refused rather than stored - a colour CSS cannot parse does not fall back, it paints the surface transparent.




## OpenAPI

````yaml /openapi-platform.json put /v1/platform/website/theme
openapi: 3.0.0
info:
  title: 1club Platform API
  version: 1.0.0
  description: >-
    The 1club Platform API lets you programmatically access and manage your
    organization's data.


    ## Official API Contract


    This documentation is the official source of truth for the 1club Platform
    API.

    If an integration relies on undocumented endpoints, fields, response shapes,
    or internal behavior outside this spec, we can't guarantee backward
    compatibility.

    Build against what's documented here to stay stable as the platform evolves.


    ## Authentication


    All requests require a customer API key passed as a Bearer token:


    ```

    Authorization: Bearer 1club_sk_live_...

    ```


    Generate API keys from the admin portal under **Settings > API Tokens**.

    The key is tied to your organization - all responses are scoped to your
    org's data.


    ## Rate Limiting


    - **100 requests per minute** per API key

    - When exceeded, the API returns `429 Too Many Requests` with a
    `Retry-After` header

    - Rate limit headers are included in every response:
      - `X-RateLimit-Limit` - max requests per window
      - `X-RateLimit-Remaining` - requests remaining
      - `X-RateLimit-Reset` - seconds until the window resets

    ## Errors


    | Status | Meaning |

    |--------|---------|

    | `400` | Invalid request parameters |

    | `401` | Missing or invalid API key |

    | `404` | Resource not found (or doesn't belong to your organization) |

    | `429` | Rate limit exceeded |

    | `500` | Internal server error |
  contact:
    name: 1club API Support
    email: support@1club.ai
servers:
  - url: https://api.1club.ai
    description: Production API
security:
  - customerApiAuth: []
tags: []
paths:
  /v1/platform/website/theme:
    put:
      tags:
        - Website
      summary: Set the website's design tokens
      description: >
        Merges a flat token patch into the site's theme, optionally on top of a
        named preset. Read `GET /theme-tokens` first for the tokens, their
        allowed values and the presets.

        **This writes the draft**, like every other edit here - nothing a
        visitor sees changes until `POST /releases` publishes it. That is the
        point of tokens living on the website rather than on the organization's
        branding: a palette change is previewable, versioned in the release, and
        revertible.

        Merges field by field, so setting the heading font leaves the palette
        alone. Send `null` for a token to return it to what it inherits - from
        the organization's branding, from another token, or from the platform
        default. That is the only way back once a value has been written; there
        is no "unset" string.

        A `preset` is the exception to that merge: it REPLACES the look rather
        than adding to it. Every token any preset owns is cleared first, then
        the chosen preset's values are written. Otherwise switching from `night`
        to `editorial` would keep night's whole dark palette underneath and
        leave the site describing a hybrid nobody chose. Tokens no preset owns -
        a hand-picked brand colour - are untouched.

        When `preset` and `tokens` are both sent the preset is applied first and
        the tokens land on top, so "use the editorial look but keep our heading
        font" is one call.

        Every problem with a patch is reported at once rather than one at a
        time. Tokens are validated against the catalog: an unknown key, a value
        outside a token's options, a font the site cannot load, or a colour that
        is not a hex are all refused rather than stored - a colour CSS cannot
        parse does not fall back, it paints the surface transparent.
      parameters:
        - in: query
          name: siteId
          schema:
            type: integer
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                preset:
                  type: string
                  description: A named look from the catalog, applied before `tokens`.
                tokens:
                  type: object
                  description: >
                    Token key to value. `null` returns a token to what it
                    inherits. See `GET /theme-tokens` for the keys.
                  additionalProperties:
                    oneOf:
                      - type: string
                      - type: boolean
                    nullable: true
            examples:
              preset:
                summary: Apply a named look, keeping the brand font
                value:
                  preset: editorial
                  tokens:
                    headingFontFamily: Montserrat
              adjust:
                summary: Flatten the surfaces and slow the motion down
                value:
                  tokens:
                    shadow: none
                    borderWidth: bold
                    motion: subtle
              clear:
                summary: Go back to the organization's brand colour
                value:
                  tokens:
                    primaryColor: null
      responses:
        '200':
          description: The theme after the patch, resolved
        '400':
          description: >-
            An unknown token, a value outside its options, or an unparseable
            colour
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PlatformError'
        '401':
          $ref: '#/components/responses/PlatformUnauthorized'
        '403':
          description: API key is missing the required `website:write` scope
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PlatformError'
        '404':
          description: The organization has no website
        '429':
          $ref: '#/components/responses/PlatformRateLimited'
      security:
        - customerApiAuth: []
components:
  schemas:
    PlatformError:
      type: object
      properties:
        error:
          type: string
  responses:
    PlatformUnauthorized:
      description: Invalid or missing API key
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/PlatformError'
    PlatformRateLimited:
      description: Rate limit exceeded
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/PlatformError'
  securitySchemes:
    customerApiAuth:
      type: http
      scheme: bearer
      description: >-
        Organization-scoped bearer credential: a customer API key
        (1club_sk_live_...) or an MCP OAuth access token.

````