> ## Documentation Index
> Fetch the complete documentation index at: https://docs.bridgelinepf.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get a new hosted link for a quote

> Revokes the quote's current hosted page link immediately and returns a new one. Use it when a link was sent to the wrong person, or to get a link again after creating the quote (GET returns hosted_url null). The quote's expires_at never changes; an expired quote is a 409 QUOTE_EXPIRED. Retrying with the same Idempotency-Key returns the same link.

* The old link stops working immediately, for everyone.
* `expires_at` never changes. An expired quote returns [`409 QUOTE_EXPIRED`](/errors/QUOTE_EXPIRED); create a new quote instead.
* An interested quote can get a new link. It shows your client's choice, not the options again.
* The same `Idempotency-Key` returns the same link without revoking it again. A new key, or no key, revokes the last link and mints another.

See [replace a link](/guides/hosted-quote-page#replace-a-link).

<RequestExample>
  ```bash cURL theme={null}
  curl -X POST https://portal.bridgelinepf.com/api/v1/quotes/qte_2lo4LFk5rf8toDFJHSUZ2O/hosted-link \
    -H "Authorization: Bearer $BRIDGELINE_API_KEY" \
    -H "Idempotency-Key: $(uuidgen)"
  ```

  ```javascript Node theme={null}
  const res = await fetch(`https://portal.bridgelinepf.com/api/v1/quotes/${quoteId}/hosted-link`, {
    method: 'POST',
    headers: {
      Authorization: `Bearer ${process.env.BRIDGELINE_API_KEY}`,
      'Idempotency-Key': crypto.randomUUID(),
    },
  })
  const { hosted_url } = await res.json()
  ```

  ```python Python theme={null}
  import os
  import uuid
  import requests

  res = requests.post(
      f"https://portal.bridgelinepf.com/api/v1/quotes/{quote_id}/hosted-link",
      headers={
          "Authorization": f"Bearer {os.environ['BRIDGELINE_API_KEY']}",
          "Idempotency-Key": str(uuid.uuid4()),
      },
      timeout=30,
  )
  hosted_url = res.json()["hosted_url"]
  ```
</RequestExample>

<ResponseExample>
  ```jsonc 200 theme={null}
  {
    "id": "qte_2lo4LFk5rf8toDFJHSUZ2O",
    "hosted_url": "https://portal.bridgelinepf.com/q/4nHnCzyp1YZ78mOscafTROmG9hSYlXaplWVeA8CeU90",
    "expires_at": "2026-11-03T15:04:05Z"
  }
  ```

  ```json 409 theme={null}
  {
    "error": {
      "type": "conflict",
      "code": "QUOTE_EXPIRED",
      "message": "Create a new quote; an expired quote can't get a new link.",
      "doc_url": "https://docs.bridgelinepf.com/errors#QUOTE_EXPIRED",
      "request_id": "req_8fJ2kQ9xLm4TzW7nB3cY5pDv"
    }
  }
  ```
</ResponseExample>


## OpenAPI

````yaml POST /v1/quotes/{id}/hosted-link
openapi: 3.1.0
info:
  title: Bridgeline Public API
  version: '2026-09-23'
  description: >-
    Premium finance quotes and applications for agencies. Authenticate with an
    API key from Agency Portal → API Keys. Scopes: `quotes:read` (Read quotes),
    `quotes:write` (Create quotes), `applications:read` (Read applications),
    `applications:write` (Create and edit applications and policies),
    `agreements:write` (Send and void agreements, attest down payments),
    `loans:read` (Read agreements, loans and payouts), `webhooks:manage` (Manage
    webhook endpoints).
servers:
  - url: https://portal.bridgelinepf.com/api
    description: Production (base URL not final, see D2)
security:
  - bearerAuth: []
paths:
  /v1/quotes/{id}/hosted-link:
    post:
      tags:
        - Quotes
      summary: Get a new hosted link for a quote
      description: >-
        Revokes the quote's current hosted page link immediately and returns a
        new one. Use it when a link was sent to the wrong person, or to get a
        link again after creating the quote (GET returns hosted_url null). The
        quote's expires_at never changes; an expired quote is a 409
        QUOTE_EXPIRED. Retrying with the same Idempotency-Key returns the same
        link.
      operationId: rotateQuoteHostedLink
      parameters:
        - name: id
          in: path
          required: true
          schema:
            type: string
            description: The quote id (qte_…).
          description: The quote id (qte_…).
        - name: Bridgeline-Version
          in: header
          required: false
          description: >-
            API version (a date). Defaults to 2026-09-23; echoed on every
            response.
          schema:
            type: string
            pattern: ^\d{4}-\d{2}-\d{2}$
        - name: Idempotency-Key
          in: header
          required: false
          description: >-
            Retrying with the same key and body within 24h replays the original
            response.
          schema:
            type: string
            minLength: 1
            maxLength: 255
      responses:
        '200':
          description: The new link.
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: string
                    description: The quote id (qte_…).
                  hosted_url:
                    type: string
                    description: >-
                      The new hosted page link. Every earlier link for this
                      quote no longer works.
                  expires_at:
                    type: string
                    description: >-
                      The quote's expiry, unchanged: a new link never extends
                      it.
                required:
                  - id
                  - hosted_url
                  - expires_at
                description: A freshly minted hosted link for a quote.
        '400':
          description: Malformed request (bad JSON, version or header).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Missing, invalid, revoked or expired API key.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: >-
            API access not enabled for this agency (API_ACCESS_NOT_ENABLED for a
            live key, TEST_MODE_NOT_ENABLED for a test key), missing scope, or
            the acting broker is not active.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Not found (also returned for other agencies' ids).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '409':
          description: >-
            Idempotency-Key reused with a different request, or still in flight.
            QUOTE_EXPIRED: the quote has expired.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: Rate limited. See Retry-After.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Internal error. Safe to retry with the same Idempotency-Key.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - bearerAuth: []
components:
  schemas:
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - type
            - code
            - message
            - doc_url
            - request_id
          properties:
            type:
              type: string
              enum:
                - invalid_request
                - authentication
                - permission
                - not_found
                - conflict
                - rate_limit
                - api_error
            code:
              type: string
              description: >-
                Stable, machine-readable error code. Branch on this, never on
                `message`.
              examples:
                - INVALID_REQUEST
                - INVALID_JSON
                - INVALID_API_VERSION
                - INVALID_PAGINATION
                - IDEMPOTENCY_KEY_REQUIRED
                - IDEMPOTENCY_KEY_INVALID
                - VALIDATION_FAILED
                - INVALID_API_KEY
                - KEY_REVOKED
                - KEY_EXPIRED
                - MISSING_SCOPE
                - BROKER_NOT_ACTIVE
                - DEFAULT_BROKER_INACTIVE
                - ACTING_BROKER_NOT_ALLOWED
                - API_ACCESS_NOT_ENABLED
                - TEST_MODE_NOT_ENABLED
                - TEST_MODE_ONLY
                - NOT_FOUND
                - METHOD_NOT_ALLOWED
                - IDEMPOTENCY_KEY_REUSED
                - IDEMPOTENCY_REQUEST_IN_PROGRESS
                - QUOTE_EXPIRED
                - QUOTE_ALREADY_INTERESTED
                - RATE_LIMITED
                - INTERNAL
                - IDEMPOTENCY_RECORD_LOST
                - SERVICE_UNAVAILABLE
            message:
              type: string
            param:
              type: string
            details:
              type: array
              items:
                type: object
                required:
                  - code
                  - message
                properties:
                  code:
                    type: string
                  message:
                    type: string
                  param:
                    type: string
            doc_url:
              type: string
              format: uri
            request_id:
              type: string
              pattern: ^req_
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: bl_live_… or bl_test_… API key.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.