hosting

POST /v1/migrations

Create the site and start migrating onto it, in one call.

All hosting endpoints

All developer docs

Authentication

Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/migrations \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "source": <MigrationSource>, "host": <string>, "username": <string>, "ownership_attested": <boolean>, "site": <object> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

The "deploy it and start the migration straight away" path, and the only one that works from an account with no sites yet. ⛔⛔ One endpoint rather than "call POST /v1/sites then POST /v1/sites/{id}/migrations", because the two-call version fails badly: a browser closed between them, or a migration refused for a bad password, leaves an orphan site the customer never asked for, holding one of their plan's site slots, with a hostname they must now delete. Each endpoint did exactly what it was asked and the customer is left holding it. So the ordering here is load-bearing: the source is probed first, and the site is created only once the credentials have been proven against the customer's old host and the estate enumerated. The two failures a customer will actually hit both happen while nothing has been created — and so do the attestation and mail refusals (ownership_not_attested, mailbox_passwords_required, source_cannot_migrate_mail), which until 2026-09-13 were asked only after the site existed. Send mailbox_passwords for the addresses POST /v1/migrations/probe lists. ⛔ Not idempotent, and it does not pretend to be — a retry is refused by the hostname uniqueness constraint, which is a clean conflict rather than a second site. Requires both sites.create and hosting.import.manage: it spends a site slot and connects to a third party's production server, and a principal holding one of those powers must not acquire the other by coming through this door.

Request body

NameTypeRequiredWhat it is
sourceMigrationSourceYesThe kind of hosting the site is being pulled from. ⛔ plesk is offered so the refusal can be specific and actionable, not because it is supported: pleskbackup is reachable…
hoststringYesThe server's public hostname, e.g. server123.yourhost.com. Must resolve to a public address — a private or link-local target is refused with source_host_not_public at the door…
usernamestringYesThe login for the source panel or account.
portintegerNo0 means the source driver's default for that panel.
passwordstringNo
private_keystringNoAn SSH private key in PEM form, for an ssh source.
api_tokenstringNo
include_mailbooleanNo⚖️ Defaults to true, and a source that cannot deliver mailboxes is refused rather than silently migrated without them — a migration that moves a website and loses the mail is…
mailbox_passwordsobjectNoaddress -> password, for every mailbox being moved. Required up front rather than discovered mid-sync: most panels will not hand over a mailbox without its own password, and…
ownership_attestedbooleanYes⚠️ As on SiteMigrationCreate: recorded because it cannot be reconstructed afterwards, required, and not a legal control.
siteobjectYesThe site to create. ⛔ Nested rather than flattened, and the nesting is load-bearing: MigrationCredentials already has a host (the server we are migrating from) and this…

Response

NameTypeRequiredWhat it is
idUuidYesUUIDv7 identifier — sortable by creation time (docs/02 §8).
site_idUuidYesUUIDv7 identifier — sortable by creation time (docs/02 §8).
sourceMigrationSourceYesThe kind of hosting the site is being pulled from. ⛔ plesk is offered so the refusal can be specific and actionable, not because it is supported: pleskbackup is reachable…
statusSiteMigrationStatusYesauthenticating, inventorying and transferring are separate states rather than one running because they fail for opposite reasons and the customer's next action differs: a…
status_reasonstringNoA machine code the dashboard renders through its own catalogue — never an English sentence composed by the engine, which could be shown to none of the other 57 locales.
include_mailbooleanYes
source_hoststringNoThe hostname the estate is being pulled from. Host only: no port, no username, and never a secret.
files_totalintegerYes
files_doneintegerYes
databases_totalintegerYes
databases_doneintegerYes
mailboxes_totalintegerYes
mailboxes_doneintegerYes
items_failedintegerYes⛔ Counted separately from the *_done fields, never folded into them. "We could not get it" reported as "done" makes the completion report a lie.
bytes_transferredintegerYes
warningsstring[]YesMachine warning codes the dashboard localises.
mail_synced_atstringNoWhen the mail delta last ran. null and a timestamp are different states, and the cutover control reads this to tell them apart.
dns_records_capturedintegerNoHow many records were read off the source's zone and will be published on cutover. ⛔ Counted separately from dns_records_unsupported, never as one total: "we captured 14…
dns_records_unsupportedintegerNoReal records the source holds that our DNS editor cannot express (an SSHFP, a TLSA, an MX with no preference). Stored and listed on the detail endpoint rather than dropped —…
dns_captured_atstringNoWhen the source's zone was read. null means never attempted, which is NOT the same as attempted-and-the-panel-holds-no-zone; only the first is worth retrying.
verified_atstringNoWhen the migrated site was last fetched over HTTP and compared with the source. null means the destination has never been looked at.
verification_codestringNoA machine code the dashboard localises. Empty means the destination is serving the site as well as the source was. ⛔ The migration's own counters cannot answer this: they travel…
destination_statusintegerNoThe HTTP status the migrated site returned, fetched at its origin address with a Host: header — before cutover the customer's domain still resolves to the OLD host, so asking…
source_statusintegerNoThe HTTP status the source returned. ⭐ Reported beside destination_status because the interesting failure is the PAIR: a destination 200 against a source 500 means we faithfully…
replaces_existingbooleanNoWhether this migration landed on a site that already held a website. Stamped when the job is created and never recomputed: after the apply step the site is occupied…
safety_backup_statestring<not_needed, pending, taken, unsupported, failed>NoWhat became of the backup taken immediately before the apply step replaced the site. ⛔ Five values rather than a boolean: "there is no safety backup" is one rendered sentence…
safety_backup_idstringNoThe SiteBackup id, or "". ⛔ Still reported after the archive has been pruned by retention, so a rollback can say "that archive has expired" rather than looking like a…
rolled_back_atstringNoWhen the customer put the site back. Set once — restoring the pre-migration archive over a site that is already the pre-migration archive can only lose work done since.
rollbackMigrationRollbackNoWhether this migration can be put back, and — when it cannot — why not. ⛔⛔ reason travels with available, always. Six different facts render as the same absent button…
started_atstringNo
finished_atstringNo
created_atstringYes
site_namestringYesMay be empty — a site's display name is optional, which is exactly the case for sites created by POST /v1/migrations, so a row rendered from this alone would be blank for them.
site_domainstringYes
site_statusstringYes

Errors this endpoint can return

401 · 403 · 409 · 422 · 429 · 503