# Sinch Compliance API - Brands

This API describes the set of endpoints available to create customer brands.

The list of endpoints allows to create, update and delete a customer brand and also get the current state.

Version: 1.0.0
License: MIT

## Servers

Production server. Data processed and stored within Europe.
```
https://compliance.api.sinch.com
```

## Security

### OAuth2

The username and password are your Key ID and Key Secret from the Access keys section in the Sinch Customer Dashboard. Exchange these for a bearer token (access token).

Type: oauth2
Token URL: https://auth.sinch.com/oauth2/token
Scopes:
- `read`: read
- `write`: write

### hmacAuth

HMAC-SHA256 signature used to authenticate webhook deliveries. The signature is computed over the request body using the project's HMAC secret and sent in the X-Sinch-Signature header. Please refer to the Brand Callback endpoints for more information.

Type: apiKey
In: header
Name: X-Sinch-Signature

## Download OpenAPI description

 - [Sinch Compliance API - Brands](https://developers.sinch.com/_bundle/docs/compliance-center/api-reference/compliance-brands.yaml)

## Brands

 - [POST /v1/projects/{projectId}/us/brands](https://developers.sinch.com/docs/compliance-center/api-reference/compliance-brands/brands/createbrand.md): Creates a new Draft Brand in US with the request data. Note: The `Idempotency-Key` header is not supported in this version. Submitting the same request twice may create duplicate resources. Callers ar
 - [GET /v1/projects/{projectId}/us/brands](https://developers.sinch.com/docs/compliance-center/api-reference/compliance-brands/brands/listbrands.md): List existing brands according to the specified filters.
 - [POST /v1/projects/{projectId}/us/brands/import](https://developers.sinch.com/docs/compliance-center/api-reference/compliance-brands/brands/importbrand.md): This endpoint allows you to import a brand that has already been registered through another reseller or directly by the end-customer, enabling you to manage it through your account. To initiate the tr
 - [GET /v1/projects/{projectId}/us/brands/{brandId}](https://developers.sinch.com/docs/compliance-center/api-reference/compliance-brands/brands/getbrand.md): The endpoint receives as path param project id and brand id. If the project and brand exist, the details of the brand are returned.
 - [DELETE /v1/projects/{projectId}/us/brands/{brandId}](https://developers.sinch.com/docs/compliance-center/api-reference/compliance-brands/brands/deletebrand.md): The endpoint receives as path param project id and brand id. If the project and brand exist, the brand is deleted.
 - [PATCH /v1/projects/{projectId}/us/brands/{brandId}](https://developers.sinch.com/docs/compliance-center/api-reference/compliance-brands/brands/patchbrand.md): Patches an existing brand. Fields omitted from the request body are unchanged. Fields set to `null` are treated as an explicit request to clear the field; if a field does not support clearing, the req
 - [POST /v1/projects/{projectId}/us/brands/{brandId}/attachments](https://developers.sinch.com/docs/compliance-center/api-reference/compliance-brands/brands/uploadbrandattachment.md): Upload an attachment to be linked to a brand.
 - [GET /v1/projects/{projectId}/us/brands/{brandId}/attachments/{attachmentId}](https://developers.sinch.com/docs/compliance-center/api-reference/compliance-brands/brands/downloadbrandattachment.md): Download Brand Attachment.
 - [DELETE /v1/projects/{projectId}/us/brands/{brandId}/attachments/{attachmentId}](https://developers.sinch.com/docs/compliance-center/api-reference/compliance-brands/brands/deletebrandattachment.md): Delete a Brand attachment.
## Orders

 - [GET /v1/projects/{projectId}/us/orders](https://developers.sinch.com/docs/compliance-center/api-reference/compliance-brands/orders/listbrandorders.md): List Brand Orders, according to the filters applied. This endpoint allows filtering over all brands.
 - [POST /v1/projects/{projectId}/us/brands/{brandId}/orders](https://developers.sinch.com/docs/compliance-center/api-reference/compliance-brands/orders/createbrandorder.md): Creates a new Brand Order for the specified brand ID and process selected. Note: The `Idempotency-Key` header is not supported in this version. Submitting the same request twice may create duplicate o
 - [GET /v1/projects/{projectId}/us/brands/{brandId}/orders](https://developers.sinch.com/docs/compliance-center/api-reference/compliance-brands/orders/listbrandorderbybrandid.md): List Brand Orders per brand id, according to the filters applied.
 - [GET /v1/projects/{projectId}/us/brands/{brandId}/orders/{orderId}](https://developers.sinch.com/docs/compliance-center/api-reference/compliance-brands/orders/getbrandorder.md): The endpoint receives as path param project id, brand id and order id. If the project and order exist, the details of the brand are returned.
 - [DELETE /v1/projects/{projectId}/us/brands/{brandId}/orders/{orderId}](https://developers.sinch.com/docs/compliance-center/api-reference/compliance-brands/orders/deletebrandorder.md): Delete a Brand Order.
 - [POST /v1/projects/{projectId}/us/brands/{brandId}/orders/{orderId}/retry](https://developers.sinch.com/docs/compliance-center/api-reference/compliance-brands/orders/retrybrandorder.md): Updates a brand Order. Only INCOMPLETE or NEW orders can be retried. Retry flow will get new properties and attachments from the brand and apply the same validations as create Order. No body is needed
 - [POST /v1/projects/{projectId}/us/brands/{brandId}/orders/{orderId}/resendConfirmationEmail](https://developers.sinch.com/docs/compliance-center/api-reference/compliance-brands/orders/brandorderresendconfirmationemail.md): Resends the brand registration confirmation email to the end-customer. Certain product verification processes require the end-customer's approval via email to complete a brand's registration for a spe
 - [POST /v1/projects/{projectId}/us/brands/{brandId}/orders/{orderId}/verifyOtp](https://developers.sinch.com/docs/compliance-center/api-reference/compliance-brands/orders/brandorderverifyotp.md): Verifies the One-Time Password (OTP) received by the brand's registered mobile phone number to complete the US_10DLC_TCR_SOLE_PROPRIETOR order. After creating the order, an OTP is automatically sent v
 - [POST /v1/projects/{projectId}/us/brands/{brandId}/orders/{orderId}/resendOtp](https://developers.sinch.com/docs/compliance-center/api-reference/compliance-brands/orders/brandorderresendotp.md): This endpoint triggers a resend of the One-Time Password (OTP) required for verifying US_10DLC_TCR_SOLE_PROPRIETOR orders. Use this if the initial OTP expired or was not received by the brand. The new
## Brand Webhooks

 - [POST BrandOrderStatusUpdated](https://developers.sinch.com/docs/compliance-center/api-reference/compliance-brands/brand-webhooks-delivery/brandorderstatuscallback.md): The endpoint receives a callback when the brand order status is updated. To receive callback notifications, the customer must provide a callback URL in the create Order (/us/brands/{brandId}/orders) r
## Brand Callbacks

 - [GET /v1/projects/{projectId}/callbackConfig](https://developers.sinch.com/docs/compliance-center/api-reference/compliance-brands/brand-callbacks/getcallbackconfig.md): Returns the callback configuration for the specified project. The HMAC secret is masked — only the last 6 characters are visible. To retrieve the full secret, rotate it using `POST /v1/projects/{proje
 - [PATCH /v1/projects/{projectId}/callbackConfig](https://developers.sinch.com/docs/compliance-center/api-reference/compliance-brands/brand-callbacks/updatecallbackconfig.md): Sets a customer-provided HMAC secret for the specified project. The full secret is returned once in the response body — this is the only time it is visible in plain text. Store it securely immediately
 - [POST /v1/projects/{projectId}/callbackConfig/rotate](https://developers.sinch.com/docs/compliance-center/api-reference/compliance-brands/brand-callbacks/rotatecallbacksecret.md): Generates a new server-side HMAC secret for the specified project and replaces the existing one. The full secret is returned once in the response body — this is the only time it is visible in plain te
