hosting

POST /v1/sites/{siteId}/wordpress/users

Create an account on a site's WordPress.

All hosting endpoints

Authentication

Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/wordpress/users \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "login": <string>, "email": <string>, "display_name": <string>, "password": <string> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Adds a WordPress account. **The caller chooses the password** and it travels in the request only: it is never echoed in the response, never written to our records and never logged. `login` and `email` are checked against WordPress's own rules here, so the customer gets our sentence about a field they can see rather than WordPress's about one they cannot. Refused `422` when the package type does not carry `wp_users`, or when WordPress is not installed. `404` for a site with no vendor hosting package. Requires `sites.view` and `sites.panel_access`.

Parameters

NameTypeRequiredWhat it is
siteId (path)UuidYesSite ID (UUIDv7).

Request body

NameTypeRequiredWhat it is
loginstringYesThe account's login name. WordPress caps `user_login` at 60 characters and rejects anything outside this character set, so both are enforced here rather than surfaced as a vendo…
emailstringYesThe account's email address.
display_namestringYesThe name shown on the site's posts and comments.
passwordstringYesThe account's password. Write-only: it is accepted here and appears in no response, no log line and no error body.
rolestringNoThe role to create the account in — any role `listSiteWordPressRoles` reports for this install. Omit it (or send `""`) for the platform's default, which is what a vendor with no…

Response

NameTypeRequiredWhat it is
idstringYesThe account's WordPress id, carried as a string because it is the vendor's identifier rather than ours.
loginstringYesThe name the account signs in with.
display_namestringYesThe name shown on the site's posts and comments.
emailstringYesThe account's email address. Personal data about the customer's **own** users, which is why the whole listing is gated on `sites.panel_access`.
rolesstringYesThe account's roles, in the vendor's own spelling.
registered_atstringYesWhen WordPress recorded the account, in the vendor's own format. Not typed as a date-time: the platform does not guarantee one, and coercing it would invent precision.
is_administratorbooleanYesWhether the account is an administrator. ⛔ Set from **which vendor endpoint the row came from**, not guessed from the role string — the two lists sit behind two different capabi…

Errors this endpoint can return

401 · 403 · 404 · 409 · 422 · 429 · 503