hosting

POST /v1/sites/{siteId}/security/scan

Scan a site for malware now.

Alle hosting Endpunkte

Authentifizierung

Senden Sie einen API-Schlüssel als Bearer-Token. Dieser Endpunkt gibt in der Spezifikation keine spezifische Berechtigung an. Versehen Sie Ihren Schlüssel daher mit den minimal erforderlichen Rechten und prüfen Sie die Antwort, anstatt Annahmen zu treffen.

Dieser Endpunkt erfordert keine Organisations-ID. Ihr Schlüssel identifiziert bereits die zugehörige Organisation, und die Antwort ist entsprechend eingeschränkt.

Ausprobieren

Ersetzen Sie alles in spitzen Klammern durch Ihre eigenen Werte und den Platzhalter für den Schlüssel durch einen Schlüssel aus Ihrem Dashboard.

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/security/scan \
  -H "Authorization: Bearer zdk_live_…"

Angemeldet? Die API-Konsole in Ihrem Dashboard trägt automatisch Ihre echte Organisations-ID sowie Ihren eigenen Schlüssel ein und führt die Anfrage gegen die Live-API aus, sodass Sie die tatsächliche Antwort sehen können. Öffnen Sie diesen Endpunkt in der API-Konsole

Details

Queues an on-demand scan and answers `202` with the site's state, which will read `scanning` once the workflow starts. Gated on `sites.view`, not on a write key: asking for a fresh scan of your own site changes nothing about it, and it is the first thing a worried customer does. **Concurrency is bounded by the workflow id, which is per site.** A second request while a scan is running is still a `202` — a scan of this site *is* in progress, which is what was asked for — and no second scan of the same document root starts. `422` when the site is not running (a suspended or still-provisioning site has no document root to scan). `503` when the durable-execution service is unreachable: answering `202` there would flip the card to *scanning…* for a scan that was never started, and the customer would watch a spinner for hours.

Parameter

NameTypErforderlichWas es ist
siteId (path)UuidJaSite ID (UUIDv7).

Antwort

NameTypErforderlichWas es ist
statusMalwareStatusJaA site's scan verdict. There is deliberately **no** `unscanned` member: a site nothing has looked at yet is `clean` with `last_scan_at: null`, which is one nullable timestamp ra…
last_scan_atobjectJaWhen a scan last **completed**. `null` = never scanned. A scan that failed does not stamp this, so a stale success can never be mistaken for a fresh one.
detectionsMalwareDetection[]Ja
recent_resolutionsResolvedMalwareDetection[]JaFindings that were present and are not any more, most recently cleared first — the record of the protection having worked, which an all-clear alone cannot show. `resolved_at` al…
can_rescanbooleanJaWhether `rescanSite` will accept a request for this site: false while a scan is already running, false for a site that is not running at all (there is no document root to scan),…
last_scan_error_codestring<, scan_conflict, scanner_unreachable, scanner_missing, scan_failed>JaWhy a scan that **ran** could not finish; empty when none has failed. Non-empty means an attempt was made against this site and broke — an unreachable host, a vendor error, a sc…
unavailable_reasonstringJaWhy **no scan was attempted**; empty when one was. A stable machine identifier for the client to localise, never a sentence and never a vendor name. `vendor_unsupported` — the h…
runtimeSiteRuntimeSecurityJaWhat our runtime sensor saw **happen** on this site, and whether anything was watching it at all. The malware fields above are a verdict on files at rest; this is the other half…

Fehler, die dieser Endpunkt zurückgeben kann

401 · 403 · 404 · 422 · 429 · 503