Remove the website's own hero photo (admin, or manage_org_settings)
/api/organization/site-backgroundDeletes the object and nulls site_background_image_url. The website falls back to the widget's own hero photo, live, not to no photo at all. Takes no body.
Authorization
sessionCookie The dashboard's Supabase Auth session cookie, set at sign-in. Large sessions are split across
numbered chunks (…auth-token.0, .1), so treat this as a cookie family rather than one name.
Every request re-validates it against the Auth server (getUser()), never by decoding the cookie
locally: a JWT nothing has checked is not a credential. Tenancy is then read from the verified
app_metadata.company_id claim and enforced by row-level security; it is never read from request
input, on any route, ever.
role (admin / staff) is deliberately not in RLS. It gates specific actions in route code,
the operations marked admin below, so hiding a button in the UI is cosmetic only, and a route's
own check is the enforcement.
In: cookie
Response Body
application/json
application/json
application/json
application/json
curl -X DELETE "https://example.com/api/organization/site-background"{ "ok": true}Upload the website's own hero photo (admin, or manage_org_settings) POST
The website's OWN hero photo (migration 0194), independent of /api/organization/background's widget hero (SiteShell used to always reuse that same photo). Same shape as that route otherwise: same 5 MB ceiling and bucket (`booking-backgrounds`, a distinct fixed path per company), same admin gate. Unset falls back to the widget's own photo, live.
Upload your own profile photo POST
Personal account data, not tenant data; a plain signed-in check, no organization scoping, no role. The storage policy pins writes to `{userId}/avatar`, which is what actually enforces "only your own folder". Stored on the auth user's metadata, not on any booking table.