hosting
POST /v1/sites/{siteId}/ssh-keys
Authorise a public key for SSH on a site.
Authentication
Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/ssh-keys \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "handle": <string>, "key": <string> }'Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
Files one public key under a handle and returns the key as it was stored. `201` and the created key rather than the whole list, because the list is re-read anyway: `can_create` is a property of the collection and the vendor's own key count moves with it. ⛔ **What makes a key valid is checked in the service, not in this schema**, and the sentence the customer reads is the same whichever door they came through — including the one that says *"that is your private key"*. A line that is not a public key we accept, a handle outside `[A-Za-z0-9][A-Za-z0-9._-]{0,63}`, a duplicate handle, or a package type that does not include SSH are all `422` with our wording, before the vendor is called. `404` for a site with no vendor hosting package, or one that is not the caller's. Requires `sites.view` **and** `sites.panel_access` — this write grants a shell.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
siteId (path) | Uuid | Yes | Site ID (UUIDv7). |
Request body
| Name | Type | Required | What it is |
|---|---|---|---|
handle | string | Yes | What to file the key under. Constrained to `[A-Za-z0-9][A-Za-z0-9._-]{0,63}`; anything else is refused with our wording rather than the vendor's. |
key | string | Yes | The public key line, as OpenSSH writes it. |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
handle | string | Yes | The name the key is filed under, ours and the vendor's, and what `deleteSiteSshKey` addresses. Constrained to `[A-Za-z0-9][A-Za-z0-9._-]{0,63}`. |
key | string | Yes | The public key line, in full and never truncated. It is a **public** key — publishing it is what it is for — and a shortened one would stop a customer confirming that the key on… |
algorithm | string | Yes | The key type parsed out of the line. `""` when the stored line does not parse as one of the algorithms we accept, which is possible for a key added at the vendor before this sur… |
comment | string | Yes | The trailing comment on the key line. Often an email address, often empty. |
Errors this endpoint can return
401 · 403 · 404 · 422 · 429 · 503