hosting
DELETE /v1/sites/{siteId}/ssh-keys/{handle}
Withdraw an authorised SSH key from a site.
Authentication
Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X DELETE https://api.zinndigital.com/v1/sites/{siteId}/ssh-keys/{handle} \
-H "Authorization: Bearer zdk_live_…"Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
Removes the key from the package's authorised list. Whatever was signing in with it stops immediately, which is the point — a laptop that was lost is a key that has to stop working now rather than at the next deploy. `204` and no body: the client re-reads the list, because `can_create` and the vendor's key count both move with the removal and neither can be derived from the response to a delete. `404` for a site with no vendor hosting package, one that is not the caller's, or a handle that is not on it — the delete URL must not become a way to enumerate what exists elsewhere. Requires `sites.view` **and** `sites.panel_access`.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
siteId (path) | Uuid | Yes | Site ID (UUIDv7). |
handle (path) | string | Yes | The handle the key is filed under, exactly as `getSiteSshAccess` reports it. Constrained to `[A-Za-z0-9][A-Za-z0-9._-]{0,63}`, so it never contains a slash — but it is the custo… |
Errors this endpoint can return
401 · 403 · 404 · 422 · 429 · 503