> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hyperprop.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Update your organization profile

> Update your organization's public profile information.

**What you can update:**
- `description` - A brief description shown to traders
- `contactEmail` - Support email for trader inquiries
- `websiteUrl` - Link to your organization website
- `logoUrl` - Direct URL to your logo image
- `sessionOpenDelayMinutes` - Delay after CME open before trading starts (default: 0)
- `sessionCloseBufferMinutes` - Buffer before CME close when trading stops (default: 0)
- `commissionPerSide` - Commission per side in USD (default: 0)
- `cryptoDayEndTime` - When a 24/7 (crypto) trading day rolls over (default: `00:00`)
- `cryptoDayEndTimezone` - IANA zone that time is read in (default: `America/New_York`)

**Trading session configuration:**
By default, traders can trade during the full CME session (5:00 PM CT open → 4:00 PM CT close). Use the session fields to restrict this:

| Setting | Value | Effect |
|---------|-------|--------|
| `sessionOpenDelayMinutes: 0` | Default | Trading allowed at CME open (5:00 PM CT) |
| `sessionOpenDelayMinutes: 15` | 15 min delay | Trading allowed at 5:15 PM CT |
| `sessionCloseBufferMinutes: 0` | Default | Trading allowed until CME close (4:00 PM CT) |
| `sessionCloseBufferMinutes: 15` | 15 min buffer | Trading stops at 3:45 PM CT |

These two fields apply to CME Group futures accounts only. They have no effect on an account whose markets are crypto (`BINANCE`) — there is no session to trim.

**Crypto trading day (`BINANCE` accounts):**
Crypto perpetuals never close, so there is no session boundary to end the day. `cryptoDayEndTime` + `cryptoDayEndTimezone` let you choose one. At that moment, for crypto accounts only:

- the daily loss limit and daily drawdown baselines reset
- the end-of-day snapshot is written
- traders' personal per-day trade counters reset, and a "lock my risk settings for the day" lock expires

It is **not** a market close. Trading is never interrupted, open positions are **not** flattened, and no auto-liquidation happens at the boundary — unlike the CME 4:00 PM CT close. CME accounts ignore these fields entirely.

`cryptoDayEndTime` must be `HH:MM` or `HH:MM:SS` in 24-hour form; `cryptoDayEndTimezone` must be a real IANA zone (an unrecognised zone is rejected with 400 rather than silently falling back to UTC). The zone is stored rather than a fixed UTC offset so the boundary follows daylight saving.

**Example - Roll the crypto day at 5:00 PM New York time:**
```json
{
  "cryptoDayEndTime": "17:00",
  "cryptoDayEndTimezone": "America/New_York"
}
```

**Partial updates supported:**
Only include the fields you want to change. Omitted fields remain unchanged.

**Example - Update just your contact email:**
```json
{
  "contactEmail": "newsupport@apextrading.com"
}
```

**Example - Update multiple fields:**
```json
{
  "description": "Elite prop trading firm with 95% payout",
  "websiteUrl": "https://apextrading.com",
  "contactEmail": "traders@apextrading.com"
}
```

**Logo upload:**
For uploading a logo file, use the dedicated `POST /organization/profile/logo` endpoint instead of setting `logoUrl` directly.

**Permissions:**
Only organization **admins** can update the profile. Team members with view-only access will receive a 403 error.



## OpenAPI

````yaml /api-reference/openapi.json put /v1/organization/profile
openapi: 3.0.0
info:
  title: Hyperprop Platform API
  version: 1.0.0
  description: >-
    REST API for the Hyperprop Trading Platform — provision evaluation and
    funded trading accounts, manage traders and plans, react to account
    lifecycle events via signed webhooks, and reconcile billing. Built for prop
    firms integrating from their own backend.


    ## Authentication


    Two methods, depending on who is calling:


    ### Bearer Token (JWT) — users & dashboard

    Most endpoints accept a JWT via `Authorization: Bearer <token>`. Used by the
    dashboard and client applications.


    ### API Key — organizations (prop firms)

    Organization endpoints also accept `X-API-Key: hp_live_...` for programmatic
    access from your backend — no browser session needed. Keys are managed by
    organization admins in the dashboard; each key carries permissions (`read`,
    `write`, `admin`) and can be rotated or revoked at any time. Keys are stored
    hashed (SHA-256) — the raw key is shown once at creation. Endpoints that
    create or modify data require `write` or `admin`.


    ## Quick Start


    ```bash

    # 1. List your trading plans (grab a tradingPlanId)

    curl "https://api.hyperprop.com/platform/v1/organization/trading-plans" \
      -H "X-API-Key: hp_live_your_key_here"

    # 2. Create a trading account for a trader (by Hyperprop user ID or email)

    curl -X POST
    "https://api.hyperprop.com/platform/v1/organization/trading-accounts" \
      -H "X-API-Key: hp_live_your_key_here" \
      -H "Content-Type: application/json" \
      -d '{"type": "evaluation", "tradingPlanId": "<uuid>", "email": "trader@example.com"}'
    ```


    ## Response Envelope & Error Handling


    **Success** responses always wrap the payload:


    ```json

    { "success": true, "data": { ... }, "message": "optional human-readable
    note" }

    ```


    **Errors** — including request-validation failures, auth failures, and
    errors

    proxied from the trade engine — always return this single uniform shape with
    a

    machine-readable `code` you can switch on:


    ```json

    {
      "success": false,
      "statusCode": 404,
      "error": "Not Found",
      "message": "No Hyperprop user found with that email. The trader must have a Hyperprop account before an account can be created for them.",
      "code": "TRADER_NOT_FOUND"
    }

    ```


    Parse rule of thumb: check `success`; on `false`, switch on `code` (never on
    `message` text — messages can be reworded). Some errors carry additional
    structured context alongside these fields (e.g. payout rejections include a
    `consistency` block).


    Common codes: `VALIDATION_ERROR` (malformed payload/params), `UNAUTHORIZED`,
    `INSUFFICIENT_PERMISSIONS` / `NOT_ADMIN` (key lacks write/admin),
    `*_NOT_FOUND` (missing resource), `*_NOT_IN_ORG` (resource belongs to
    another organization), `IDEMPOTENCY_KEY_IN_PROGRESS` (duplicate in flight),
    `ENGINE_UNREACHABLE` (trade engine down — retry with the same idempotency
    key). Endpoint-specific codes (e.g. payout `OPEN_EXPOSURE`,
    `CONSISTENCY_BLOCKED`) are documented on each endpoint.


    ## Idempotency


    **Every mutating endpoint (POST, PUT, PATCH, DELETE) honors idempotency keys
    uniformly.** Send an `Idempotency-Key` header (the `X-Idempotency-Key`
    spelling is accepted as an alias) to retry any write safely without creating
    duplicates.


    How it works:


    - The key is scoped to your organization + the request path. The first
    request with a given key executes normally and its response is cached for
    **24 hours**.

    - A replay (same key, same path) within 24 hours returns the cached response
    with an `Idempotency-Replayed: true` response header — the operation is
    **not** executed again.

    - If a request with the same key is still in flight, the duplicate gets `409
    IDEMPOTENCY_KEY_IN_PROGRESS` — back off and retry; you'll then receive the
    cached response.

    - 5xx responses are **not** cached, so retrying after a server error
    re-executes the request (that's what you want). 2xx-4xx responses are cached
    — if a request failed validation and you fix the payload, use a **fresh
    key**.

    - Keys are free-form strings up to 255 characters. Use something that
    identifies the operation on your side, e.g. `order-8814-attempt-1`.


    ```bash

    curl -X POST
    "https://api.hyperprop.com/platform/v1/organization/trading-accounts" \
      -H "X-API-Key: hp_live_your_key_here" \
      -H "Idempotency-Key: order-8814-attempt-1" \
      -H "Content-Type: application/json" \
      -d '{"type": "evaluation", "tradingPlanId": "...", "traderId": "..."}'
    ```


    This applies to account creation, account PATCH (status, currentBalance,
    metadata), rules, plans, lockouts, payouts, team, webhooks — every write on
    the platform API. Payouts additionally forward the key to the trade engine
    for engine-level double-withdrawal protection.


    ## Pagination & Sorting


    List endpoints support both styles:


    - **Cursor (recommended):** pass `?cursor=` from the previous response's
    `pagination.nextCursor`. Stable under concurrent writes.

    - **Offset:** `?limit=&offset=` with `pagination.total` / `hasMore` in the
    response.


    Sorting uses `?sort=field:direction` (e.g. `?sort=created_at:asc`); allowed
    fields are listed per endpoint. Default: `created_at:desc`.


    ## Custom Metadata


    Trading accounts, purchases, traders, plans, and rules all carry a free-form
    `metadata` JSON object. Use it to store your own references — payment IDs,
    campaign tags, payout records, internal notes. Hyperprop stores and returns
    it verbatim (and lets you filter list endpoints by it, e.g.
    `?metadata=stripePaymentId:pi_123`) but never interprets it. Update
    endpoints support `mergeMetadata: true` for shallow (top-level) merges
    instead of wholesale replacement.


    ## Webhooks


    Subscribe to account lifecycle events (`account.created`,
    `account.status_changed`, `account.updated`, `account.passed`,
    `account.failed`, and more) via the Webhooks endpoints. Deliveries are
    HMAC-SHA256 signed — verify `X-Hyperprop-Signature` with your endpoint
    secret, using `X-Hyperprop-Timestamp` for replay protection;
    `X-Hyperprop-Delivery` gives you a unique delivery ID for deduplication.
    Failed deliveries are retried with backoff, and you can redeliver any event
    from the dashboard or API.


    ## MCP Connector (AI Agents)


    The platform ships a built-in [MCP](https://modelcontextprotocol.io) server,
    so AI agents and assistants (Claude, Cursor, custom agents) can operate your
    organization directly — no integration code required.


    ```http

    Endpoint:  POST https://api.hyperprop.com/platform/v1/mcp

    Transport: Streamable HTTP (stateless, JSON responses)

    Auth:      X-API-Key header, Authorization: Bearer hp_live_..., or OAuth

    ```


    **Claude web / desktop (Add custom connector):** paste the endpoint URL and
    leave the OAuth Client ID/Secret fields empty — the connector registers
    itself automatically. Claude opens a Hyperprop consent page where an org
    admin pastes the organization API key once; access then follows that key's
    permissions and ends if the key is revoked. (Under the hood: OAuth 2.1 with
    PKCE and dynamic client registration.)


    **Cursor / Claude Code — `mcp.json`:**


    ```json

    {
      "mcpServers": {
        "hyperprop": {
          "url": "https://api.hyperprop.com/platform/v1/mcp",
          "headers": { "X-API-Key": "hp_live_your_key_here" }
        }
      }
    }

    ```


    **Available tools (12):** `list_trading_plans`, `list_trading_accounts`,
    `get_trading_account`, `get_account_audit_log`, `list_traders`,
    `get_trader`, `list_purchases`, `get_purchase`, `get_billing_summary` (read)
    · `create_trading_account`, `update_trading_account`, `record_payout`
    (write).


    Every tool call executes the corresponding REST endpoint with your key, so
    organization scoping, permissions, validation, audit logging, and webhooks
    apply exactly as documented on each endpoint. Read tools work with any key;
    write tools need `write`/`admin` permission — connect a **read-only key** if
    you want a strictly read-only agent. `create_trading_account` accepts an
    optional `idempotencyKey` so agent retries can't create duplicates, and
    `record_payout` implements the documented payout recipe (append to
    `metadata.payouts`, adjust `currentBalance`, audit-logged `reason`).


    ## Endpoint Groups


    - **Authentication** — Sign up, sign in, OAuth, MFA, password reset. No auth
    required for most.

    - **User** — Profile, notifications, demo accounts, audit logs. Requires
    **Bearer token** (JWT).

    - **Organization** — Trading accounts, plans, rules, traders, purchases,
    lockouts, billing, bulk operations, webhooks, analytics. Accepts **Bearer
    token** OR **API Key**.

    - **System** — Health checks. No auth required.
  x-logo:
    url: https://app.hyperprop.com/logo-icon.svg
    altText: Hyperprop
    href: https://hyperprop.com
servers:
  - url: https://api.hyperprop.com/platform
    description: Production
security: []
tags:
  - name: Authentication
    description: >-
      User authentication - signup, signin, signout, password reset, email
      verification, OAuth, and MFA
  - name: User
    description: >-
      User account management - profile, notifications, agreements, dismissals,
      and audit logs. Requires Bearer token.
  - name: Organization
    description: >-
      Organization management - profile, team, trading accounts, plans, and
      rules. Supports **dual authentication**: Bearer JWT token (dashboard
      users) OR X-API-Key (programmatic access).
  - name: Demo
    description: >-
      Demo account management - import, list, and delete demo trading accounts.
      Requires Bearer token.
  - name: Market Data
    description: CME futures contracts and market data. Requires Bearer token.
  - name: System
    description: System endpoints - health checks and connectivity
paths:
  /v1/organization/profile:
    put:
      tags:
        - Organization
      summary: Update your organization profile
      description: >-
        Update your organization's public profile information.


        **What you can update:**

        - `description` - A brief description shown to traders

        - `contactEmail` - Support email for trader inquiries

        - `websiteUrl` - Link to your organization website

        - `logoUrl` - Direct URL to your logo image

        - `sessionOpenDelayMinutes` - Delay after CME open before trading starts
        (default: 0)

        - `sessionCloseBufferMinutes` - Buffer before CME close when trading
        stops (default: 0)

        - `commissionPerSide` - Commission per side in USD (default: 0)

        - `cryptoDayEndTime` - When a 24/7 (crypto) trading day rolls over
        (default: `00:00`)

        - `cryptoDayEndTimezone` - IANA zone that time is read in (default:
        `America/New_York`)


        **Trading session configuration:**

        By default, traders can trade during the full CME session (5:00 PM CT
        open → 4:00 PM CT close). Use the session fields to restrict this:


        | Setting | Value | Effect |

        |---------|-------|--------|

        | `sessionOpenDelayMinutes: 0` | Default | Trading allowed at CME open
        (5:00 PM CT) |

        | `sessionOpenDelayMinutes: 15` | 15 min delay | Trading allowed at 5:15
        PM CT |

        | `sessionCloseBufferMinutes: 0` | Default | Trading allowed until CME
        close (4:00 PM CT) |

        | `sessionCloseBufferMinutes: 15` | 15 min buffer | Trading stops at
        3:45 PM CT |


        These two fields apply to CME Group futures accounts only. They have no
        effect on an account whose markets are crypto (`BINANCE`) — there is no
        session to trim.


        **Crypto trading day (`BINANCE` accounts):**

        Crypto perpetuals never close, so there is no session boundary to end
        the day. `cryptoDayEndTime` + `cryptoDayEndTimezone` let you choose one.
        At that moment, for crypto accounts only:


        - the daily loss limit and daily drawdown baselines reset

        - the end-of-day snapshot is written

        - traders' personal per-day trade counters reset, and a "lock my risk
        settings for the day" lock expires


        It is **not** a market close. Trading is never interrupted, open
        positions are **not** flattened, and no auto-liquidation happens at the
        boundary — unlike the CME 4:00 PM CT close. CME accounts ignore these
        fields entirely.


        `cryptoDayEndTime` must be `HH:MM` or `HH:MM:SS` in 24-hour form;
        `cryptoDayEndTimezone` must be a real IANA zone (an unrecognised zone is
        rejected with 400 rather than silently falling back to UTC). The zone is
        stored rather than a fixed UTC offset so the boundary follows daylight
        saving.


        **Example - Roll the crypto day at 5:00 PM New York time:**

        ```json

        {
          "cryptoDayEndTime": "17:00",
          "cryptoDayEndTimezone": "America/New_York"
        }

        ```


        **Partial updates supported:**

        Only include the fields you want to change. Omitted fields remain
        unchanged.


        **Example - Update just your contact email:**

        ```json

        {
          "contactEmail": "newsupport@apextrading.com"
        }

        ```


        **Example - Update multiple fields:**

        ```json

        {
          "description": "Elite prop trading firm with 95% payout",
          "websiteUrl": "https://apextrading.com",
          "contactEmail": "traders@apextrading.com"
        }

        ```


        **Logo upload:**

        For uploading a logo file, use the dedicated `POST
        /organization/profile/logo` endpoint instead of setting `logoUrl`
        directly.


        **Permissions:**

        Only organization **admins** can update the profile. Team members with
        view-only access will receive a 403 error.
      operationId: putV1OrganizationProfile
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Model746'
      responses:
        '200':
          description: Success - Profile updated. Returns the complete updated profile.
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/Model748'
        '400':
          description: >-
            Bad Request - Empty payload or no valid fields provided
            (`NO_FIELDS_TO_UPDATE`), or a field failed validation
            (`VALIDATION_ERROR`, e.g. `cryptoDayEndTimezone` is not a real IANA
            zone: `"America/Nowhere" is not a valid IANA timezone (e.g.
            America/New_York)`, or `cryptoDayEndTime` is not `HH:MM`)
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/Model749'
        '401':
          description: Unauthorized - Invalid or missing session token
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/Model750'
        '403':
          description: Forbidden - You need admin privileges to update the profile
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/Model751'
        '500':
          description: An unexpected error occurred
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/Model3'
      security:
        - Bearer: []
        - X-API-Key: []
components:
  schemas:
    Model746:
      type: object
      properties:
        description:
          type: string
          description: Brief description of your organization (shown to traders)
          example: Professional prop trading firm specializing in futures and forex
        contactEmail:
          type: string
          description: Support email where traders can reach you
          example: support@apextrading.com
          x-format:
            email: true
        websiteUrl:
          type: string
          description: Your organization website URL
          example: https://apextrading.com
          x-format:
            uri:
              scheme:
                - https
                - http
        logoUrl:
          type: string
          description: >-
            Direct URL to your logo (use the upload endpoint instead for best
            results)
          example: https://storage.hyperprop.com/logos/apex-trading.png
          x-format:
            uri:
              scheme:
                - https
        sessionOpenDelayMinutes:
          type: integer
          description: >-
            Minutes after CME session opens before trading is allowed (0 = trade
            immediately at open)
          example: 15
          minimum: 0
          maximum: 120
        sessionCloseBufferMinutes:
          type: integer
          description: >-
            Minutes before CME session closes that trading stops (0 = trade
            until close)
          example: 15
          minimum: 0
          maximum: 120
        commissionPerSide:
          type: number
          description: >-
            Commission per side in USD, max $100, 2 decimal places (e.g., 2.50 =
            $2.50 per side, $5.00 round trip)
          example: 2
          minimum: 0
          maximum: 100
          x-constraint:
            precision: 2
        cryptoDayEndTime:
          type: string
          description: >-
            Local time at which a 24/7 (crypto) trading day rolls over, `HH:MM`.
            This moves the daily loss limit and daily drawdown baseline and
            writes the day snapshot — it does NOT close the market and does NOT
            flatten positions, unlike the CME session close. Default `00:00`.
          example: '00:00'
          pattern: ^([01]\d|2[0-3]):[0-5]\d(:[0-5]\d)?$
        cryptoDayEndTimezone:
          type: string
          description: >-
            IANA timezone for `cryptoDayEndTime`, so the boundary follows
            daylight saving (e.g. `America/New_York`, `UTC`, `Europe/London`).
            Rejected with 400 if it is not a zone the runtime recognises.
            Default `America/New_York`.
          example: America/New_York
    Model748:
      type: object
      properties:
        success:
          type: boolean
          example: true
        message:
          type: string
          example: Organization profile updated successfully
        data:
          $ref: '#/components/schemas/Model747'
    Model749:
      type: object
      properties:
        statusCode:
          type: number
          example: 400
        error:
          type: string
          example: Bad Request
        message:
          type: string
          example: No fields to update
        code:
          type: string
          example: NO_FIELDS_TO_UPDATE
    Model750:
      type: object
      properties:
        statusCode:
          type: number
          example: 401
        error:
          type: string
          example: Unauthorized
        message:
          type: string
          example: Invalid or expired session
    Model751:
      type: object
      properties:
        statusCode:
          type: number
          example: 403
        error:
          type: string
          example: Forbidden
        message:
          type: string
          example: Only organization admins can perform this action
        code:
          type: string
          example: NOT_ADMIN
    Model3:
      type: object
      properties:
        success:
          type: boolean
          description: Always false on errors
          example: false
        statusCode:
          type: number
          example: 500
        error:
          type: string
          example: Internal Server Error
        message:
          type: string
          example: An unexpected error occurred
        code:
          type: string
          description: Machine-readable error code — switch on this, not on message text
          example: INTERNAL_ERROR
    Model747:
      type: object
      example:
        id: 6075600e-ceeb-4be1-ade6-1fc2ab8d044a
        organizationId: a6fcc0ce-eb28-4f43-b256-96a3144b0d34
        name: FakePropFirm
        description: Professional prop trading firm specializing in futures
        contactEmail: support@propfirm.com
        websiteUrl: https://propfirm.com
        logoUrl: https://api.dicebear.com/9.x/glass/svg?seed=FakePropFirm
        sessionOpenDelayMinutes: 15
        sessionCloseBufferMinutes: 15
        commissionPerSide: 2
        cryptoDayEndTime: '17:00:00'
        cryptoDayEndTimezone: America/New_York
        createdAt: '2025-12-19T15:23:52.403Z'
        updatedAt: '2026-03-12T14:30:00.000Z'
      properties:
        id:
          type: string
          description: Profile record ID
        organizationId:
          type: string
          description: Your organization ID
        name:
          type: string
          description: Organization name
        description:
          type: string
          description: Your description
        contactEmail:
          type: string
          description: Support email
        websiteUrl:
          type: string
          description: Website URL
        logoUrl:
          type: string
          description: Logo URL
        sessionOpenDelayMinutes:
          type: number
          description: Minutes after CME open before trading allowed
        sessionCloseBufferMinutes:
          type: number
          description: Minutes before CME close that trading stops
        commissionPerSide:
          type: number
          description: Commission per side in USD
        cryptoDayEndTime:
          type: string
          description: When a 24/7 (crypto) trading day rolls over, as stored (`HH:MM:SS`)
        cryptoDayEndTimezone:
          type: string
          description: IANA zone the crypto day-end time is read in
        createdAt:
          type: string
        updatedAt:
          type: string
  securitySchemes:
    Bearer:
      type: apiKey
      name: Authorization
      in: header
      description: >-
        JWT Bearer token for user session auth. Format: "Bearer {token}". Used
        by User and Organization endpoints.
    X-API-Key:
      type: apiKey
      name: X-API-Key
      in: header
      description: >-
        Organization API key for programmatic access. Format: "hp_live_{key}".
        Used by Organization endpoints as an alternative to Bearer token. Keys
        are managed in the dashboard.

````

## Related topics

- [Get your organization profile](/platform-api/organization/get-your-organization-profile.md)
- [Update user profile](/platform-api/user/update-user-profile.md)
- [Update a trader](/platform-api/organization/update-a-trader.md)
- [Update a trading account](/platform-api/organization/update-a-trading-account.md)
- [Delete organization logo](/platform-api/organization/delete-organization-logo.md)
