compute

POST /v1/compute/servers/{serverId}/snapshots/{snapshotId}

Roll a server back to a snapshot.

All compute endpoints

Authentication

Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/compute/servers/{serverId}/snapshots/{snapshotId} \
  -H "Authorization: Bearer zdk_live_…"

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

⛔⛔ **The most destructive operation on this API, and more so than `rebuildComputeServer`.** A rebuild gives the customer the clean machine they asked for; a restore **overwrites the live disk** with an older one. Everything written since the snapshot is gone, the current state is not itself snapshotted first, and there is no undo at the provider or here. Refused on a snapshot that is not `ready` — an image still being written restores an incomplete disk, and the provider will happily start it. Requires `sites.view` and `sites.delete`, the same key as deleting a website, because the blast radius is the same: data the customer cannot get back.

Parameters

NameTypeRequiredWhat it is
serverId (path)UuidYesThe server's id, as `listComputeServers` reports it. **Ours** (UUIDv7), minted when the order row was written — never the provider's own identifier for the machine.
snapshotId (path)stringYesThe **provider's** id for the image, as the listing reported it — not one of ours. The engine re-checks that the snapshot was created from this machine before touching it, becau…

Response

NameTypeRequiredWhat it is
idUuidYes**Ours**, and also the provisioning workflow's id and the machine's name at the provider — which is what makes the whole purchase path idempotent.
namestringYesWhat the customer called it. ⛔ At the provider a machine's name is its row id; confusing the two is a cross-tenant defect, so this is the customer's string and nothing else.
deploy_targetstringYesWhich compute range the machine belongs to.
plan_codestringYesThe tier it was bought on, or `""` when it was ordered by size alone.
providerstringYesOur provider id.
specstringYesThe machine size it currently runs.
zonestringYesThe data centre it runs in.
statusstring<pending, provisioning, active, failed, suspended, terminated>YesHow far the order got — **ours**, and a different fact from `power_state`. `pending` is a row with nothing bought and nothing charged; `failed` is the state whose `message` is t…
messagestringYesWhy the order failed, in a sentence the customer reads. Blank unless `failed`.
vendor_statusstringYesThe provider's own word, verbatim and unrounded. Staff-facing detail; a customer client renders `status` and never this.
power_statestring<unknown, on, off, starting, stopping, rebooting>YesWhat the machine is doing right now. ⛔ **Six values, not two, and the four extra ones are the point: a machine mid-transition is not "on".** `unknown` is the honest answer when…
addressesstring[]YesPublic addresses **if the provider states them**. Empty means *not stated*, never "none" — a machine rendered as having no address reads as broken.
optimisationstringYesThe stack optimisation profile it was built with, or `""` for none.
term_monthsintegerYesThe term it was bought on, or null when the provider states none.
renews_atstringYes⛔ **Always null today, and honestly so**: the provider publishes no renewal date, and one computed from the order plus the term would be our arithmetic rendered as the provider'…
created_atstringYesWhen the row was created, or `""` when not stated.
operablebooleanYesWhether the customer may act on this machine — power, resize, renew, rebuild. ⛔ Read rather than re-derived from `status`: the engine refuses every one of those on anything but…
imagestringYesThe provider image the machine was built from. Blank on the resold range, which installs one managed image and offers no choice.
suspendedbooleanYes⛔⛔ **Whether WE stopped it, which is not the same fact as `power_state`.** A stopped machine is the customer's own choice and they may start it again; a suspended one is ours an…
suspension_reasonstringYesWhy, verbatim, so the customer reads the same sentence support wrote. Blank when the machine is in good standing.
capabilitiesstring[]Yes⭐⭐ **What this machine's provider can actually do** — capability tokens such as `compute:snapshots`, `compute:console`, `compute:firewall`, `compute:backups_manage` and `compute…

Errors this endpoint can return

401 · 403 · 404 · 422 · 429 · 503