hosting
POST /v1/sites/{siteId}/wordpress/plugins
Install a plugin on a site's WordPress.
Authentifizierung
Senden Sie einen API-Schlüssel als Bearer-Token. Der Schlüssel muss über die Berechtigung sites.view verfügen; ein Schlüssel ohne diese wird mit 403 statt 404 abgelehnt.
Dieser Endpunkt erfordert keine Organisations-ID. Ihr Schlüssel identifiziert bereits die zugehörige Organisation, und die Antwort ist entsprechend eingeschränkt.
Ausprobieren
Ersetzen Sie alles in spitzen Klammern durch Ihre eigenen Werte und den Platzhalter für den Schlüssel durch einen Schlüssel aus Ihrem Dashboard.
curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/wordpress/plugins \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ }'Angemeldet? Die API-Konsole in Ihrem Dashboard trägt automatisch Ihre echte Organisations-ID sowie Ihren eigenen Schlüssel ein und führt die Anfrage gegen die Live-API aus, sodass Sie die tatsächliche Antwort sehen können. Öffnen Sie diesen Endpunkt in der API-Konsole
Details
Installs a plugin and, by default, activates it. Either from the **wordpress.org directory** by `slug` (what `searchWordPressPluginDirectory` returns), or from a **zip the customer uploads**. ⛔ Exactly one of `slug` and `zip` — never both. A request carrying both is refused `422` rather than resolved by precedence, because a caller that sent the wrong one would otherwise install something it did not ask for and be told it succeeded. Idempotent: a plugin already present is activated rather than reinstalled, and an upload of a plugin that is already there replaces it in place. Nothing is ever removed — use `deleteSiteWordPressPlugin` for that. ⚠️ An uploaded zip is **the customer's own code running on their own site**, and we do not review it. It is size-capped and rejected unless it is a valid archive containing a single top-level directory with a PHP plugin header, which is what WordPress itself requires — not a security review, and not presented as one. Refused `422` when the package type does not carry `wp_plugins`, or when WordPress is not installed. `404` for a site with no vendor hosting package. Requires `sites.view` and `sites.panel_access`.
Parameter
| Name | Typ | Erforderlich | Was es ist |
|---|---|---|---|
siteId (path) | Uuid | Ja | Site ID (UUIDv7). |
Anfragekörper
| Name | Typ | Erforderlich | Was es ist |
|---|---|---|---|
slug | string | Nein | A wordpress.org directory slug. Lower-case, digits and hyphens — the directory's own alphabet, enforced here so a path separator or a URL can never reach the box as a "slug". |
zip | string | Nein | A base64-encoded plugin zip. Present instead of a multipart upload because every other write on this API is JSON and one exception would need its own auth, size and error handling. |
activate | boolean | Nein | Activate after installing. `false` puts the files in place and leaves the plugin switched off — what a staged rollout of something risky wants. Deliberately not the default: "in… |
Antwort
| Name | Typ | Erforderlich | Was es ist |
|---|---|---|---|
data | SiteWordPressPlugin[] | Ja | The installed plugins. |
stack_cache_installed | boolean | Ja | ⛔ **Cannot be derived from `data`.** this platform excludes its own server-side cache plugin from the listing, so a client deriving this flag from the rows would answer "not ins… |
Fehler, die dieser Endpunkt zurückgeben kann
401 · 403 · 404 · 409 · 413 · 422 · 429 · 503