Update security settings
/settings/securityUpdates the content protection settings. Only the fields included in the request are changed: setting a field to null clears its configured value and restores the default, and omitted fields are left unchanged.
Provider credentials are write-only. Enabling a video provider requires its credentials, either already stored or sent in the same request. This check applies only to the providers included in the request, so updating other settings never fails because of a provider that is not part of the request.
To avoid overwriting a newer version, send the ETag returned by the retrieve operation in the If-Match header. The header is optional; when it is omitted, the update is applied to the current revision.
Autonomous mode: the API credential secret, sent as a bearer token. Credential secrets are identified by a fixed prefix.
In: header
Header Parameters
Client-generated key that makes the request safe to retry. Must be 1 to 128 characters from [A-Za-z0-9._:-]. Optional on this operation; when sent, a malformed key returns idempotency_key_invalid, and repeating the request with the same key and the same body returns the stored result with Idempotent-Replayed: true.
Expected revision of the resource, in the same format as the ETag header (W/"<type>:<id>:<revision>"). If the resource has changed since that revision, the request fails with 412 and the revision_mismatch error code. * matches the current revision. Any other value fails with 400 and the if_match_invalid error code. When omitted, the update is applied to the current revision.
Optional client-generated identifier of the request, up to 64 characters from [A-Za-z0-9._-]. Echoed back in the response and recorded in the request log; it never replaces the server-generated X-Request-Id.
length <= 64Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X PATCH "https://example.com/settings/security" \ -H "Content-Type: application/json" \ -d '{}'{ "data": { "defaults": {}, "drm": { "enabled": true, "social": { "background_color": "string", "opacity": "string", "position": "top", "text_color": "string" }, "youtube": { "enabled": true, "position": "top-left" } }, "object": "settings", "propagation": {}, "providers": { "panda": { "available": true, "configured": true, "enabled": true, "group_id": "string" }, "vdocipher": { "configured": true, "enabled": true, "watermark": true, "whitelist": true }, "videofront": { "configured": true, "enabled": true } }, "replica": {}, "revision": "string" }}Retrieve security settings GET
Returns the content protection settings of the account: social DRM watermark, YouTube player protection, and video provider integrations. Provider credentials are never returned; the `configured` fields indicate whether they have been set. The response includes an `ETag` representing the current revision of these settings; changes to other settings groups do not affect it. Send this value in the `If-Match` header when updating these settings to avoid overwriting a newer version.
Retrieve user profile settings GET
Returns the user profile settings of the account: which profile fields users can view or edit, and whether their full name is displayed in support conversations. The response includes an `ETag` representing the current revision of these settings; changes to other settings groups do not affect it. Send this value in the `If-Match` header when updating these settings to avoid overwriting a newer version.