hosting

POST /v1/transfers/{transferId}/accept

Accept an incoming site transfer.

All hosting endpoints

Authentication

Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/transfers/{transferId}/accept \
  -H "Authorization: Bearer zdk_live_…"

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Takes ownership of the site. **This is the moment everything moves**, in one database transaction: the site, its subscription and paid term, its backups, links, CDN and edge bindings, security posture, placement and — when the offer included the domain — the registration, its DNS and its mail. Traffic, resource and vitals samples, support tickets, abuse reports and paid add-ons stay with the previous owner, because they are that party's record rather than a property of the site. Two references into the previous owner's own accounts are **detached** on the way: the site's CDN/edge `connection` and the domain's registrar credential. Carried across, the new owner would be operating a stranger's provider account. Mailbox passwords do **not** travel — they are vendor-side and are not ours to hand over. The new owner resets each one from the mail panel. The guard runs again here, on both organizations, and `422` refuses with the reasons. Addressable only by the **receiving** organization: a sender cannot accept their own offer. `409` when the offer was already decided. Requires `sites.view` **and** `sites.transfer`.

Parameters

NameTypeRequiredWhat it is
transferId (path)UuidYesSite transfer offer ID (UUIDv7).

Response

NameTypeRequiredWhat it is
idUuidYesUUIDv7 identifier — sortable by creation time (docs/02 §8).
site_idUuidYesUUIDv7 identifier — sortable by creation time (docs/02 §8).
site_namestringNoThe site's name as it was when the offer was made. Snapshotted onto the offer, not read live: while a transfer is pending the site still belongs to the sender, and reading it li…
primary_domainstringNoThe site's domain as it was when the offer was made. Snapshotted, as above.
directionstring<incoming, outgoing>YesFrom **this caller's** point of view. Computed per request, never stored — the same row is outgoing to one party and incoming to the other.
statusstring<pending, accepted, declined, cancelled, expired, failed>YesFive terminal states rather than one, because *why* an offer ended is what support is actually asked. `failed` means it was accepted and could not complete; nothing moved.
include_domainbooleanYesWhether the domain, its DNS and its mail travel with the site.
recipient_emailstringNoOnly populated for the **sender**. To the receiver it is their own address and carries no information; to anyone else it would be a third party's email address in a row two orga…
messagestringNo
expires_atstringYesAn unaccepted offer expires fourteen days after it is made.
term_ends_atstringNo
renewal_amount_minorintegerNo
renewal_currencystringNo
created_atstringYes
decided_atstringNo
failure_reasonstringNoWhy a `failed` transfer could not complete. Empty otherwise.

Errors this endpoint can return

401 · 403 · 404 · 409 · 422 · 429