> ## Documentation Index
> Fetch the complete documentation index at: https://docs.closient.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Add a GS1 Company Prefix

> Add a GS1 Company Prefix (licensed or closed-loop) to the caller's organization. Idempotent: adding a prefix already on file for this org returns the existing row. Owner/manager only (`organization.change_organization`).



## OpenAPI

````yaml /openapi/openapi-dashboard.json post /dashboard/api/v1/company-prefixes/{organization_id}
openapi: 3.1.0
info:
  title: Brand Dashboard API
  version: 1.0.0
  description: >
    Endpoints powering the brand dashboard: catalogue completeness, product
    images, nutrition and document management, brand analytics, data export, and
    GS1 Company Prefix management + self-service GIAI minting. Every endpoint is
    scoped to an organization you are a member of — pass an org-scoped API key,
    or authenticate with a session, and you reach exactly the organizations your
    account belongs to. This is the same surface the Closient dashboard UI
    itself uses, so anything you can do in the dashboard you can do here.


    ## Authentication


    All endpoints require an API key passed via the `X-API-Key` HTTP header,
    unless otherwise noted.


    ```

    X-API-Key: csb_<body>_<checksum>

    ```


    Generate API keys in **Settings > API Keys** in your dashboard, or via the
    Account API.

    Session-based (cookie) authentication is also accepted for browser-based
    access.


    ## Rate Limits


    | Tier        | Requests / minute | Requests / day |

    |-------------|-------------------|----------------|

    | Default     | 300               | 10,000         |

    | Custom      | Contact us        | Contact us     |


    Rate-limit headers are included on every response so callers can
    self-throttle without

    hitting our 429s ("informed governor"):


    - `RateLimit-Policy` — every active window, e.g. `300;w=60, 10000;w=86400`

    - `RateLimit-Limit` — quota for the **most-restrictive** currently-active
    window

    - `RateLimit-Remaining` — requests left in that window

    - `RateLimit-Reset` — seconds until that window resets (relative; clock-skew
    safe)


    Legacy `X-RateLimit-*` aliases are also emitted for back-compat.
    `X-RateLimit-Reset`

    keeps the absolute Unix-timestamp shape to avoid breaking existing
    consumers.


    When rate-limited, you receive `429 Too Many Requests` with a
    `retry_after_seconds` field

    in the error envelope and a `Retry-After` header.


    ## Pagination


    List endpoints return paginated results in this envelope:


    ```json

    {
      "data": [...],
      "pagination": {
        "page": 1,
        "page_size": 25,
        "total_count": 342,
        "total_pages": 14,
        "has_next": true,
        "has_previous": false
      }
    }

    ```


    Use `?page=2&page_size=50` query parameters. Maximum page size is 100.


    ## Error Responses


    All errors conform to [RFC 9457 Problem
    Details](https://www.rfc-editor.org/rfc/rfc9457)

    with `Content-Type: application/problem+json`:


    ```json

    {
      "type": "https://closient.com/docs/errors/not_found",
      "title": "Not Found",
      "status": 404,
      "detail": "The requested resource was not found.",
      "error_code": "not_found",
      "retryable": false,
      "timestamp": "2026-03-31T12:00:00+00:00"
    }

    ```


    Common error codes: `unauthorized` (401), `forbidden` (403), `not_found`
    (404),

    `validation_error` (422), `rate_limited` (429), `internal_error` (500).
  termsOfService: https://www.closient.com/terms/
servers:
  - url: https://www.closient.com
security: []
externalDocs:
  description: Closient Documentation
  url: https://docs.closient.com
paths:
  /dashboard/api/v1/company-prefixes/{organization_id}:
    post:
      tags:
        - GS1 Company Prefixes
      summary: Add a GS1 Company Prefix
      description: >-
        Add a GS1 Company Prefix (licensed or closed-loop) to the caller's
        organization. Idempotent: adding a prefix already on file for this org
        returns the existing row. Owner/manager only
        (`organization.change_organization`).
      operationId: apps_dashboard_api_company_prefixes_add_company_prefix
      parameters:
        - in: path
          name: organization_id
          schema:
            description: UUID of the organization.
            format: shortuuid
            maxLength: 22
            minLength: 22
            pattern: ^[23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz]{22}$
            title: Organization Id
            type: string
          required: true
          description: UUID of the organization.
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CompanyPrefixCreateIn'
        required: true
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CompanyPrefixOut'
        '400':
          description: Bad Request
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '401':
          description: Unauthorized
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '403':
          description: Forbidden
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '404':
          description: Not Found
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '405':
          description: Method Not Allowed
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '409':
          description: Conflict
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '422':
          description: Unprocessable Content
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '429':
          description: Too Many Requests
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
      security:
        - APIKeyHeaderAuth: []
        - OAuthTokenAuth: []
        - CookieGatedSessionAuth: []
components:
  schemas:
    CompanyPrefixCreateIn:
      description: Request body to add a GS1 Company Prefix to the caller's organization.
      examples:
        - is_licensed: true
          label: Primary GS1 US licence
          prefix: '0614141'
      properties:
        prefix:
          description: The 4-12 digit GS1 Company Prefix to add.
          maxLength: 12
          minLength: 4
          pattern: ^\d{4,12}$
          title: Prefix
          type: string
        is_licensed:
          default: true
          description: >-
            False for a closed-loop, internal-only prefix whose minted
            identifiers are non-conformant.
          title: Is Licensed
          type: boolean
        label:
          default: ''
          description: Optional human label to tell multiple prefixes apart.
          maxLength: 120
          title: Label
          type: string
      required:
        - prefix
      title: CompanyPrefixCreateIn
      type: object
    CompanyPrefixOut:
      description: One GS1 Company Prefix the caller's organization holds.
      examples:
        - id: a1b2c3d4e5f6g7h8i9j0k1
          is_conformant: true
          is_licensed: true
          label: Primary GS1 US licence
          prefix: '0614141'
          verification_status: verified
      properties:
        id:
          description: >-
            URL-safe 22-character shortuuid encoding of the row's UUID primary
            key. Stable across the row's lifetime; suitable for sharing in URLs,
            log lines, and external SDK clients. Accepted on input as either the
            shortuuid form or the canonical UUID form
            (``xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx``).
          format: shortuuid
          maxLength: 22
          minLength: 22
          pattern: ^[23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz]{22}$
          title: Id
          type: string
        prefix:
          description: 4–12 digit GS1 Company Prefix. Globally unique.
          title: Prefix
          type: string
        is_licensed:
          description: >-
            True for a real GS1-licensed prefix; False for a closed-loop,
            internal-only prefix whose identifiers are non-conformant.
          title: Is Licensed
          type: boolean
        verification_status:
          $ref: '#/components/schemas/PrefixVerificationStatusEnum'
          description: Ownership-verification state for a licensed prefix.
        label:
          description: Optional human label to tell multiple prefixes apart.
          title: Label
          type: string
        is_conformant:
          description: >-
            Whether identifiers minted from this prefix may be presented as
            GS1-conformant: requires both `is_licensed` and a
            `verification_status` of `verified`. Always false for a closed-loop
            prefix, regardless of verification status.
          title: Is Conformant
          type: boolean
      required:
        - id
        - prefix
        - is_licensed
        - verification_status
        - label
        - is_conformant
      title: CompanyPrefixOut
      type: object
    ErrorOut:
      description: |-
        RFC 9457 Problem Details response.

        All API errors are returned in this format with Content-Type:
        application/problem+json.
      examples:
        - detail: The requested resource was not found.
          error_code: not_found
          retryable: false
          status: 404
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Not Found
          type: https://closient.com/docs/errors/not_found
        - detail: Validation error.
          details:
            - loc:
                - body
                - name
              msg: Field required
              type: missing
          error_code: validation_error
          retryable: false
          status: 422
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Validation Error
          type: https://closient.com/docs/errors/validation_error
        - detail: Rate limit exceeded. Please try again later.
          error_code: rate_limited
          retry_after: 31
          retryable: true
          status: 429
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Rate Limited
          type: https://closient.com/docs/errors/rate_limited
      properties:
        type:
          description: URI reference identifying the error type.
          title: Type
          type: string
        title:
          description: Short human-readable summary of the error.
          title: Title
          type: string
        status:
          description: HTTP status code.
          title: Status
          type: integer
        detail:
          description: Human-readable explanation of this specific occurrence.
          title: Detail
          type: string
        error_code:
          description: Machine-readable error code (e.g. not_found, unauthorized).
          title: Error Code
          type: string
        retryable:
          default: false
          description: Whether retrying the same request can succeed.
          title: Retryable
          type: boolean
        timestamp:
          description: ISO 8601 timestamp of when the error occurred.
          title: Timestamp
          type: string
        retry_after:
          anyOf:
            - type: integer
            - type: 'null'
          description: Seconds to wait before retrying (when applicable).
          title: Retry After
        owner_action_required:
          anyOf:
            - type: boolean
            - type: 'null'
          description: Whether the error requires account owner intervention.
          title: Owner Action Required
        details:
          description: Additional context (validation errors, etc.).
          title: Details
      required:
        - type
        - title
        - status
        - detail
        - error_code
        - timestamp
      title: ErrorOut
      type: object
    PrefixVerificationStatusEnum:
      description: Mirrors ``apps.registry.models.PrefixVerificationStatus`` (C-4072).
      enum:
        - unverified
        - verified
        - disputed
      title: PrefixVerificationStatusEnum
      type: string
  securitySchemes:
    APIKeyHeaderAuth:
      type: apiKey
      in: header
      name: X-API-Key
    OAuthTokenAuth:
      type: http
      scheme: bearer
    CookieGatedSessionAuth:
      type: apiKey
      in: cookie
      name: sessionid

````