ai

POST /v1/ai/site-builds/{siteBuildId}/plugin-plan

Which plugins this generated site needs, and a custom one if it needs that.

All ai endpoints

Authentication

Send an API key as a bearer token. The key must carry the sites.create permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/ai/site-builds/{siteBuildId}/plugin-plan \
  -H "Authorization: Bearer zdk_live_…"

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Chooses plugins for the generated site from a curated set, and writes one small WordPress plugin when the site needs behaviour no listed plugin provides. Generated PHP is **scanned before it is packaged**, not before it is installed: dynamic execution, shell access, remote includes, direct filesystem writes, unescaped request data and hand-built SQL are refused outright, and a plugin that fails never becomes an archive at all. When that happens the reason appears in `notes` — a scan that silently dropped its subject would be indistinguishable from a scan that found nothing. Slugs the model proposes that are not in the curated set are dropped and **counted** in `rejected` rather than passed through. The generated plugin's source is deliberately not returned. It is real PHP that has passed the scan; handing it to a client invites an edited copy to be posted back on a path that believes it was scanned. Ask for it at publish time with `include_generated_plugin`, and it is regenerated and re-scanned there. Spends AI credit and is metered under the `site_builder` surface, on the one AI meter. Requires `sites.create`.

Parameters

NameTypeRequiredWhat it is
siteBuildId (path)UuidYes

Response

NameTypeRequiredWhat it is
planSiteMakerPluginPlanYes
catalogueobject[]YesThe curated set the model may choose from, and nothing else.

Errors this endpoint can return

401 · 403 · 404 · 422 · 429