compute

POST /v1/compute/servers/{serverId}/rebuild

Reinstall a server's operating system.

All compute endpoints

Authentication

Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/compute/servers/{serverId}/rebuild \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "operating_system": <string>, "confirm": <string> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

⛔⛔ **Destructive: everything on the disk is erased and cannot be recovered.** The machine comes back on a fresh image, so the answer carries `power_state: rebooting` and a client polls from there. Three guards, and none of them is optional. The caller needs `sites.delete` rather than the key that merely spends money — `dev` may commit the organisation to a billable resource without being trusted to destroy data, so this is deliberately **not** the key `resizeComputeServer` uses. The typed confirmation is re-checked **server-side**, because a dialog a client owns is a dialog an API caller skips: `confirm` must equal the server's `name` exactly, compared case-sensitively after surrounding whitespace, and anything else is `422`. And the action is audit-logged **before** the provider is called and left in place whatever happens, because an audit row written only on success leaves no trace of an attempted wipe that errored halfway — precisely the event an investigation is looking for. ⛔ **`503` is the expected answer today, and it is honest.** No adapter currently advertises rebuild: a usable one needs the provider's own operating-system list, and an OS token we guessed would wipe a customer's machine and reinstall the wrong thing. It is a `503` rather than a `422` because it is **our** gap, and a customer told "invalid input" for a control nobody wired would retype the same thing for ever. `404` for a server that is not the caller's; `422` for an empty `operating_system` or a machine that is not `active`. Requires `sites.view` **and** `sites.delete`.

Parameters

NameTypeRequiredWhat it is
serverId (path)UuidYesThe server's id, as `listComputeServers` reports it. **Ours** (UUIDv7), minted when the order row was written — never the provider's own identifier for the machine.

Request body

NameTypeRequiredWhat it is
operating_systemstringYesWhich image to install, as the provider names it. ⛔ Never a string a screen or a customer composed — an OS token we guessed would wipe the machine and reinstall the wrong thing,…
confirmstringYesThe server's `name`, typed by the customer. Compared **case-sensitively** after surrounding whitespace and nothing else, so a client that forgave more would enable the button on…

Response

NameTypeRequiredWhat it is
idUuidYes**Ours**, and also the provisioning workflow's id and the machine's name at the provider — which is what makes the whole purchase path idempotent.
namestringYesWhat the customer called it. ⛔ At the provider a machine's name is its row id; confusing the two is a cross-tenant defect, so this is the customer's string and nothing else.
deploy_targetstringYesWhich compute range the machine belongs to.
plan_codestringYesThe tier it was bought on, or `""` when it was ordered by size alone.
providerstringYesOur provider id.
specstringYesThe machine size it currently runs.
zonestringYesThe data centre it runs in.
statusstring<pending, provisioning, active, failed, suspended, terminated>YesHow far the order got — **ours**, and a different fact from `power_state`. `pending` is a row with nothing bought and nothing charged; `failed` is the state whose `message` is t…
messagestringYesWhy the order failed, in a sentence the customer reads. Blank unless `failed`.
vendor_statusstringYesThe provider's own word, verbatim and unrounded. Staff-facing detail; a customer client renders `status` and never this.
power_statestring<unknown, on, off, starting, stopping, rebooting>YesWhat the machine is doing right now. ⛔ **Six values, not two, and the four extra ones are the point: a machine mid-transition is not "on".** `unknown` is the honest answer when…
addressesstring[]YesPublic addresses **if the provider states them**. Empty means *not stated*, never "none" — a machine rendered as having no address reads as broken.
optimisationstringYesThe stack optimisation profile it was built with, or `""` for none.
term_monthsintegerYesThe term it was bought on, or null when the provider states none.
renews_atstringYes⛔ **Always null today, and honestly so**: the provider publishes no renewal date, and one computed from the order plus the term would be our arithmetic rendered as the provider'…
created_atstringYesWhen the row was created, or `""` when not stated.
operablebooleanYesWhether the customer may act on this machine — power, resize, renew, rebuild. ⛔ Read rather than re-derived from `status`: the engine refuses every one of those on anything but…
imagestringYesThe provider image the machine was built from. Blank on the resold range, which installs one managed image and offers no choice.
suspendedbooleanYes⛔⛔ **Whether WE stopped it, which is not the same fact as `power_state`.** A stopped machine is the customer's own choice and they may start it again; a suspended one is ours an…
suspension_reasonstringYesWhy, verbatim, so the customer reads the same sentence support wrote. Blank when the machine is in good standing.
capabilitiesstring[]Yes⭐⭐ **What this machine's provider can actually do** — capability tokens such as `compute:snapshots`, `compute:console`, `compute:firewall`, `compute:backups_manage` and `compute…

Errors this endpoint can return

401 · 403 · 404 · 422 · 429 · 503