# Repository · Settings

Part of AppEngine API Documentation. Full index: https://appengine.appmint.io/documentation.md
## GET /repository/setting/{settingType}/{settingName}/{subName}

**Get an org setting**

`operationId: RepositoryController_getSettingHandler`

Reads an organization setting. `settingType` names the group; `settingName` and `subName` drill into named or nested values.

Settings can hold credentials and security configuration, which is why these routes are admin-only.

#### Signature

```http
GET /repository/setting/{settingType}/{settingName}/{subName} (settingType: string, settingName: string, subName: string) -> The setting value
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`). Required role(s): `ConfigAdmin`, `ContentAdmin`.

#### Errors

Plus the standard platform errors: `401`, `403`, `429`, `500`.

#### See also

- `POST /repository/setting/{settingType}/{settingName}/{subName}`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |
| `settingType` | path | string | yes | Setting group. |
| `settingName` | path | string | yes | Named setting within the group. |
| `subName` | path | string | yes | Nested value within the setting. |

### Responses

| Status | Meaning |
| --- | --- |
| `200` | The setting value |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## POST /repository/setting/{settingType}/{settingName}/{subName}

**Set an org setting**

`operationId: RepositoryController_setSettingHandler`

Writes an organization setting.

The body is unwrapped intelligently: send `{ "value": … }` and the inner value is stored; send anything else and the whole body is stored as the value. That means a payload that happens to contain a `value` key will be unwrapped whether you meant it or not.

#### Signature

```http
POST /repository/setting/{settingType}/{settingName}/{subName} (settingType: string, settingName: string, subName: string, body) -> The stored setting
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`). Required role(s): `ConfigAdmin`, `ContentAdmin`.

#### Notes

- A body containing a `value` key is always unwrapped — wrap it twice if `value` is a genuine field of your setting.

#### Errors

Plus the standard platform errors: `401`, `403`, `429`, `500`.

#### See also

- `DELETE /repository/setting/{settingType}/{settingName}/{subName}`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |
| `settingType` | path | string | yes | Setting group. |
| `settingName` | path | string | yes | Named setting within the group. |
| `subName` | path | string | yes | Nested value within the setting. |

### Request body

The value to store. Wrapped in `value`, or sent bare.

```json
{
  "value": {
    "minLength": 12
  }
}
```

### Responses

| Status | Meaning |
| --- | --- |
| `201` | The stored setting |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## DELETE /repository/setting/{settingType}/{settingName}/{subName}

**Delete an org setting**

`operationId: RepositoryController_deleteSettingHandler`

Removes an organization setting. Deleting a group rather than a named setting removes everything under it, so name the setting precisely.

#### Signature

```http
DELETE /repository/setting/{settingType}/{settingName}/{subName} (settingType: string, settingName: string, subName: string) -> Deletion result
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`). Required role(s): `ConfigAdmin`, `ContentAdmin`.

#### Notes

- Omitting `settingName` deletes the entire group.

#### Errors

Plus the standard platform errors: `401`, `403`, `429`, `500`.

#### See also

- `GET /repository/setting/{settingType}/{settingName}/{subName}`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |
| `settingType` | path | string | yes | Setting group. |
| `settingName` | path | string | yes | Named setting. Omit to delete the whole group. |
| `subName` | path | string | yes | Nested value. |

### Responses

| Status | Meaning |
| --- | --- |
| `200` | Deletion result |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

