hosting

PUT /v1/sites/{siteId}/external-backup

Connect an externally hosted site so we can back it up.

All hosting endpoints

Authentication

Send an API key as a bearer token. The key must carry the hosting.backup.manage permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X PUT https://api.zinndigital.com/v1/sites/{siteId}/external-backup \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "channel": <ExternalBackupChannel> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Configures one of two channels. `connector` — the customer installs the Zinn® Connector plugin and pairs it. Nothing else is needed and we never hold a server credential. The plugin makes outbound calls only; it opens no route on their site. Backup only: it cannot restore. `ssh` — the customer gives us a host, a username, the document root and a private key. This channel can also **push a site back**, including when the site itself will not load, which is the only way a one-click restore can be honest. `ssh_secret` is write-only. It goes straight to our secret store and only a pointer to it is kept; it is never returned by this or any other endpoint. Re-connecting a `connector` site mints a fresh pairing token and invalidates whatever the previous install held. Requires `hosting.backup.manage`.

Parameters

NameTypeRequiredWhat it is
siteId (path)UuidYesSite ID (UUIDv7).

Request body

NameTypeRequiredWhat it is
channelExternalBackupChannelYesHow we reach a site we do not host. `connector` is the Zinn® Connector plugin (outbound-only, backup but no restore); `ssh` is SSH/SFTP, the only channel that can push a site ba…
ssh_hoststringNoRequired when `channel` is `ssh`.
ssh_portintegerNo
ssh_usernamestringNoRequired when `channel` is `ssh`.
remote_pathstringNoThe document root, required when `channel` is `ssh`. Refused at configuration time rather than at 03:00 when the sweep runs.
ssh_secretstringNoThe private key (PEM) or password. Written to our secret store and never returned. Omit it to keep the credential already stored.

Response

NameTypeRequiredWhat it is
configuredbooleanYesFalse when nobody has connected this site yet. The rest of the object is still present and empty — a screen must not have to tell "not set up" from "failed to load" by the absen…
channelExternalBackupChannel | string<>YesEmpty string when `configured` is false.
enabledbooleanYesA disabled connection is paused, not deleted — the set-up survives.
can_restorebooleanYesWhether we can push a backup back down this channel. **False for `connector`**, and that is not a limitation to route around: a WordPress plugin cannot run inside a WordPress to…
summarystringYesOne sentence stating what this connection can and cannot do, composed server-side so every surface says the same thing about the backup/restore asymmetry.
ssh_hoststringYesEmpty on a `connector` connection.
ssh_portintegerYes
ssh_usernamestringYes
remote_pathstringYesThe site's document root — what we archive, and what we restore into.
credential_presentbooleanYesWhether a credential is stored in our secret store. The credential itself is never returned by any endpoint.
last_verified_atstringYesNull when the connection has never been checked.
last_verified_okbooleanYesNull means never checked, which is not the same as failing — the absence of a measurement is not a measurement.
last_verify_detailstringYes

Errors this endpoint can return

401 · 403 · 404 · 422