> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hq.zone/llms.txt
> Use this file to discover all available pages before exploring further.

# Upload business logo

> Uploads a business logo supplied inline as base64 and returns the refreshed business
profile. Admin only. Accepts PNG, JPEG, SVG, WebP and GIF up to 4 MiB; the stored
logo becomes a manual override of the auto-discovered logo and is served from a
stable HQ-hosted URL.



## OpenAPI

````yaml POST /v1/api/business-profile/logo
openapi: 3.1.0
info:
  title: HQ API
  description: >-
    Public HTTP API for HQ. Authenticate with a Personal Access Token
    (`Authorization: Bearer hq_pat_...`) for server-side integrations, or an
    OAuth 2.1 authorization-code + PKCE flow for browser apps acting on a user's
    behalf. Both grant from the same resource:action scope vocabulary; an
    endpoint's required scope is listed under its `security`.
  license:
    name: Apache-2.0
    identifier: Apache-2.0
  version: 1.0.0
servers:
  - url: https://api.hq.zone
    description: HQ API (production)
security: []
tags:
  - name: me
    description: The signed-in user's own account
  - name: conversations
    description: Conversations and their messages
  - name: documents
    description: The content-addressed documents library
  - name: schedules
    description: Scheduled prompts and recurring tasks
  - name: agents
    description: Agents, their skills and integrations
  - name: memory
    description: What the assistant remembers (L5 governance)
  - name: tokens
    description: Personal Access Token management
  - name: billing
    description: Usage and billing
  - name: notifications
    description: In-app notification center
  - name: admin
    description: Workspace administration
  - name: integrations
    description: Workspace integrations (Slack, MCP, skills)
  - name: onboarding
    description: New-workspace onboarding wizard
  - name: auth
    description: Sign-in, sessions, and OAuth
paths:
  /v1/api/business-profile/logo:
    post:
      tags:
        - admin
      summary: Upload business logo
      description: >-
        Uploads a business logo supplied inline as base64 and returns the
        refreshed business

        profile. Admin only. Accepts PNG, JPEG, SVG, WebP and GIF up to 4 MiB;
        the stored

        logo becomes a manual override of the auto-discovered logo and is served
        from a

        stable HQ-hosted URL.
      operationId: upload_logo
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/LogoUploadReq'
        required: true
      responses:
        '200':
          description: Logo stored; returns the fresh profile
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ProfileResp'
        '400':
          description: Invalid upload
        '403':
          description: Admin role required
      security:
        - bearer_pat:
            - admin
        - oauth2:
            - admin
components:
  schemas:
    LogoUploadReq:
      type: object
      required:
        - filename
        - content_type
        - body_b64
      properties:
        body_b64:
          type: string
        content_type:
          type: string
        filename:
          type: string
    ProfileResp:
      type: object
      required:
        - overridden
        - detected
      properties:
        brand_palette: {}
        business_domain:
          type:
            - string
            - 'null'
          description: |-
            Currently-set domain on the tenants row. May differ from
            `crawl.domain` if the admin changed it after the last crawl.
        crawl_domain:
          type:
            - string
            - 'null'
        crawl_status:
          type:
            - string
            - 'null'
        detected:
          type: array
          items:
            $ref: '#/components/schemas/DetectedSignal'
          description: |-
            Technology signals detected for the tenant, highest-confidence
            first. Powers the read-only "Detected technology" section.
        dm_sent_at:
          type:
            - string
            - 'null'
          format: date-time
        enrichment:
          oneOf:
            - type: 'null'
            - $ref: '#/components/schemas/Enrichment'
              description: |-
                Company enrichment learned by profiling (migration 0155).
                `None` when none of industry/segment/size_hint are set.
        fetched_at:
          type:
            - string
            - 'null'
          format: date-time
        fonts: {}
        last_error:
          type:
            - string
            - 'null'
        logo_artifact_id:
          type:
            - string
            - 'null'
          format: uuid
        logo_url:
          type:
            - string
            - 'null'
        overridden:
          type: array
          items:
            type: string
          description: |-
            Which fields are currently admin-overridden. Powers the
            "Use auto" affordance in the UI - only the overridden fields
            get a reset-button.
        pages_crawled:
          type:
            - integer
            - 'null'
          format: int32
        summary:
          type:
            - string
            - 'null'
        summary_confidence:
          type:
            - number
            - 'null'
          format: float
    DetectedSignal:
      type: object
      required:
        - signal_type
        - value
      properties:
        signal_type:
          type: string
        value:
          type: string
    Enrichment:
      type: object
      properties:
        enriched_at:
          type:
            - string
            - 'null'
          format: date-time
        industry:
          type:
            - string
            - 'null'
        segment:
          type:
            - string
            - 'null'
        size_hint:
          type:
            - string
            - 'null'
  securitySchemes:
    bearer_pat:
      type: http
      scheme: bearer
      bearerFormat: hq_pat
      description: 'Personal Access Token. Send as `Authorization: Bearer hq_pat_...`.'
    oauth2:
      type: oauth2
      flows:
        authorizationCode:
          authorizationUrl: https://app.hq.zone/v1/oauth/authorize
          tokenUrl: https://api.hq.zone/v1/oauth/token
          refreshUrl: https://api.hq.zone/v1/oauth/token
          scopes:
            admin: Administer the workspace (users, settings, integrations)
            agents:read: View the agents in your workspace
            agents:write: Create and configure agents
            billing:read: View usage and billing information
            conversations:read: Read your conversations and their messages
            conversations:write: Start conversations and send messages on your behalf
            documents:read: Read your documents library
            documents:write: Upload and manage documents in your library
            memory:read: Read what the assistant remembers about you
            memory:write: Correct or delete what the assistant remembers
            schedules:read: View your scheduled tasks
            schedules:write: Create and manage scheduled tasks
            tables:read: Read your tables and their rows
            tables:write: Create tables and add, edit, or delete rows

````