# Brandfolder > Brandfolder is a digital asset management (DAM) platform, a Smartsheet company since August 2020. Its v4 REST API gives programmatic access to the same resources a user sees in the web app: organizations, Brandfolders, sections, collections, assets, attachments, tags, custom fields, labels, invitations, user permissions and webhooks. Authentication is a per-user bearer API key; there are no OAuth scopes. Base URL https://brandfolder.com/api/v4 — except the three webhook operations, which are still served from https://brandfolder.com/api/v1. Generated by API Evangelist from the provider's published OpenAPI and developer documentation on 2026-08-13. The docs host publishes its own portal-wide llms.txt at https://developers.smartsheet.com/llms.txt, which covers three products (Brandfolder, Smartsheet, Resource Management); the verbatim copy is kept alongside this file as brandfolder-smartsheet-developer-portal-llms.txt. This file is the Brandfolder-scoped view. ## API - [Brandfolder API v4](https://developers.smartsheet.com/api/brandfolder): 73 operations across 45 paths, 13 resource tags. RESTful JSON, GET/POST/PUT/DELETE only (no PATCH). - [OpenAPI 3.0.3 description](https://developers.smartsheet.com/_bundle/api/brandfolder/openapi.yaml): the machine-readable contract. - Base URL: `https://brandfolder.com/api/v4` - Auth: `Authorization: Bearer {BF_API_KEY}` — key from https://brandfolder.com/profile#integrations ## Docs - [API introduction](https://developers.smartsheet.com/api/brandfolder/introduction): the resource hierarchy — Organizations > Brandfolders > Sections > Assets > Attachments; Assets also belong to Collections and carry Tags and Custom Fields. - [Authentication](https://developers.smartsheet.com/api/brandfolder/guides/basics/authentication): bearer key, permissions inherited from the issuing user. - [Query parameters](https://developers.smartsheet.com/api/brandfolder/guides/basics/query-parameters): `fields`, `include`, `page`, `per` (default 100, max 3000), `search`, `sort_by`, `order`. - [Recipes](https://developers.smartsheet.com/api/brandfolder/guides/recipes): finding Brandfolder and section keys, searching, uploading media, syncing media. - [Error codes](https://developers.smartsheet.com/api/brandfolder/error-codes): 400, 403, 404, 405, 429, 500. - [Changelog](https://developers.smartsheet.com/api/brandfolder/changelog): two entries, most recent 2025-11-24. - [Insights Data Connector](https://developers.smartsheet.com/api/brandfolder/insights-data-connector): Enterprise-tier nightly BigQuery export. - [Additional resources](https://developers.smartsheet.com/api/brandfolder/guides/additional-resources): SDKs. ## SDKs - [Python SDK](https://github.com/brandfolder/brandfolder-sdk-python) — PyPI `brandfolder` 2.0.0 (2024-12-20) - [PHP SDK](https://github.com/brandfolder/brandfolder-sdk-php) — Packagist `brandfolder/brandfolder-sdk-php` 4.0.0-alpha (2024-08-13) - [Panel UI SDK](https://www.npmjs.com/package/@brandfolder-panel/sdk) — npm `@brandfolder-panel/sdk` 0.9.33 (2024-12-17), embeds the Brandfolder panel by iframe ## Agent surfaces - MCP: `https://developers.smartsheet.com/mcp` — a live remote MCP server (protocol 2025-06-18, 6 tools, no auth) that serves the Brandfolder OpenAPI and docs. Documentation plane only: it reads the contract, it does not call the API. There is no Brandfolder operations MCP server. - A2A agent card: none. `/.well-known/agent-card.json` and `/.well-known/agent.json` return 404 on brandfolder.com, developers.smartsheet.com and www.smartsheet.com. - Webhooks: `asset.create`, `asset.update`, `asset.delete`, subscribed per Brandfolder. No payload signing published. ## Things an agent should know before calling - No idempotency contract. A retried write creates duplicates. - No published rate limits and no rate-limit response headers; 429 exists but carries no Retry-After. - Errors are not RFC 9457. The `default` response schema is a bare string on 72 of 73 operations — branch on HTTP status, not on the body. - 403, not 404, is returned for deleted resources and for an inappropriate API key. - Pagination is `page`/`per` with `meta.total_count`; there is no cursor and no next-page link. - `sort_by` and `order` must be sent together. - Files must live at a publicly reachable URL before becoming an Attachment; use `GET /upload_requests` to obtain a temporary storage URL for direct byte upload. ## Artifacts - OpenAPI: https://raw.githubusercontent.com/api-evangelist/brandfolder/refs/heads/main/openapi/brandfolder-openapi-original.yml - APIs.json: https://raw.githubusercontent.com/api-evangelist/brandfolder/refs/heads/main/apis.yml - Conventions: https://raw.githubusercontent.com/api-evangelist/brandfolder/refs/heads/main/conventions/brandfolder-conventions.yml - Errors: https://raw.githubusercontent.com/api-evangelist/brandfolder/refs/heads/main/errors/brandfolder-problem-types.yml - Data model: https://raw.githubusercontent.com/api-evangelist/brandfolder/refs/heads/main/data-model/brandfolder-data-model.yml - Webhooks: https://raw.githubusercontent.com/api-evangelist/brandfolder/refs/heads/main/asyncapi/brandfolder-webhooks.yml - Agent skills: https://raw.githubusercontent.com/api-evangelist/brandfolder/refs/heads/main/skills/_index.yml ## Pricing - [Pricing](https://brandfolder.com/pricing): two quote-only plans, Premium and Enterprise. No published prices, no free tier, no trial, no self-serve signup.