hosting

POST /v1/sites/{siteId}/migrations

Migrate a site in from another host.

All hosting endpoints

Authentication

Send an API key as a bearer token. The key must carry the hosting.import.manage permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/migrations \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "source": <MigrationSource>, "host": <string>, "username": <string>, "ownership_attested": <boolean> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Probes the source, records the job and its per-item rows, then starts a durable workflow that resumes rather than restarts — a 5,000-file or 40-mailbox job survives a worker being replaced, which matters because a restart would mean a second full read of a stranger's live server. Returns `202` with the **new job state**, never a bare acknowledgement. Refused up front, while the customer still has their old account, if the source cannot give us the mail they asked for (`source_cannot_migrate_mail`) or if any mailbox has no password (`mailbox_passwords_required`, with the count in the detail rows) — a migration that moves a website and silently loses the mailboxes is worse for the customer than no migration at all. Other refusals are 422 with a machine `code`; a site that already has a migration running is 409; a site mid-move between our own fleet workers is also 409. If the workflow service or the secret store is unavailable the answer is 503 and **no job is written** — an acceptance we cannot honour would leave the customer watching a progress bar for ever. Requires `hosting.import.manage`.

Parameters

NameTypeRequiredWhat it is
siteId (path)UuidYesSite ID (UUIDv7).
Idempotency-Key (header)stringNoClient-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats.

Request body

NameTypeRequiredWhat it is
sourceMigrationSourceYesThe kind of hosting the site is being pulled from. ⛔ `plesk` is offered so the refusal can be specific and actionable, **not** because it is supported: `pleskbackup` is reachabl…
hoststringYesThe server's public hostname, e.g. `server123.yourhost.com`. Must resolve to a public address — a private or link-local target is refused with `source_host_not_public` at the do…
usernamestringYesThe login for the source panel or account.
portintegerNo`0` means the source driver's default for that panel.
passwordstringNo
private_keystringNoAn SSH private key in PEM form, for an `ssh` source.
api_tokenstringNo
include_mailbooleanNo⚖️ Defaults to true, and a source that cannot deliver mailboxes is **refused rather than silently migrated without them** — a migration that moves a website and loses the mail i…
mailbox_passwordsobjectNo`address -> password`, for every mailbox being moved. Required up front rather than discovered mid-sync: most panels will not hand over a mailbox without its own password, and f…
ownership_attestedbooleanYes⚠️ The customer's assertion that this estate is theirs to move, recorded because it cannot be reconstructed afterwards. Required — the job is refused without it — but it is **no…

Response

NameTypeRequiredWhat it is
idUuidYesUUIDv7 identifier — sortable by creation time (docs/02 §8).
site_idUuidYesUUIDv7 identifier — sortable by creation time (docs/02 §8).
sourceMigrationSourceYesThe kind of hosting the site is being pulled from. ⛔ `plesk` is offered so the refusal can be specific and actionable, **not** because it is supported: `pleskbackup` is reachabl…
statusSiteMigrationStatusYes`authenticating`, `inventorying` and `transferring` are separate states rather than one `running` because they fail for opposite reasons and the customer's next action differs:…
status_reasonstringNoA machine code the dashboard renders through its own catalogue — never an English sentence composed by the engine, which could be shown to none of the other 57 locales.
include_mailbooleanYes
source_hoststringNoThe hostname the estate is being pulled from. Host only: no port, no username, and never a secret.
files_totalintegerYes
files_doneintegerYes
databases_totalintegerYes
databases_doneintegerYes
mailboxes_totalintegerYes
mailboxes_doneintegerYes
items_failedintegerYes⛔ Counted separately from the `*_done` fields, never folded into them. "We could not get it" reported as "done" makes the completion report a lie.
bytes_transferredintegerYes
warningsstring[]YesMachine warning codes the dashboard localises.
mail_synced_atstringNoWhen the mail delta last ran. `null` and a timestamp are different states, and the cutover control reads this to tell them apart.
dns_records_capturedintegerNoHow many records were read off the source's zone and will be published on cutover. ⛔ Counted separately from `dns_records_unsupported`, never as one total: "we captured 14 recor…
dns_records_unsupportedintegerNoReal records the source holds that our DNS editor cannot express (an `SSHFP`, a `TLSA`, an `MX` with no preference). Stored and listed on the detail endpoint rather than dropped…
dns_captured_atstringNoWhen the source's zone was read. `null` means never attempted, which is NOT the same as attempted-and-the-panel-holds-no-zone; only the first is worth retrying.
verified_atstringNoWhen the migrated site was last fetched over HTTP and compared with the source. `null` means the destination has never been looked at.
verification_codestringNoA machine code the dashboard localises. Empty means the destination is serving the site as well as the source was. ⛔ The migration's own counters cannot answer this: they travel…
destination_statusintegerNoThe HTTP status the migrated site returned, fetched at its origin address with a `Host:` header — before cutover the customer's domain still resolves to the OLD host, so asking…
source_statusintegerNoThe HTTP status the source returned. ⭐ Reported beside `destination_status` because the interesting failure is the PAIR: a destination 200 against a source 500 means we faithful…
started_atstringNo
finished_atstringNo
created_atstringYes

Errors this endpoint can return

401 · 403 · 404 · 409 · 422 · 429 · 503