hosting
POST /v1/sites/{siteId}/site-blueprint-deploy
Replace a site's content with a blueprint's.
Authentication
Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/site-blueprint-deploy \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "blueprint_id": <Uuid> }'Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
⛔ **Destructive.** This overwrites the site's live database and files with the contents of the named blueprint, then rewrites the restored content's stored web addresses to this site's domain (a WordPress database names its own URLs, so without that step the new site would redirect its visitors to the old one). Its own path on the **site**, beside `backups/restore`, rather than a verb on the blueprint — the destruction happens here, so it is gated on `hosting.backup.manage` and cannot be reached by varying the body of anything gentler. ⛔ A blueprint captured from a different **stack** is refused with a `422` (`stack_mismatch`) — WordPress can only be deployed onto WordPress. So is one from a different **hosting platform** (`platform_mismatch`), whose archive our adapter cannot restore here. A blueprint belonging to a **different account** is refused with `org_mismatch`, even when your token can reach both: hierarchical tenancy means a reseller's key spans every client organisation, and a blueprint is that site's whole database — it never crosses between accounts. A blueprint that is still being captured is `blueprint_not_ready`. A deploy already in flight on this site is a `409`. The refusal is a **machine code**, carried in `error.details[0].code`, so a client can render it in the customer's own language; `error.message` is the English equivalent for a caller with no catalogue. ⛔ Read the code from `details`, not from `error.code` — that is the generic `UNPROCESSABLE_ENTITY` for every 422 this API produces.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
siteId (path) | Uuid | Yes | Site ID (UUIDv7). |
Idempotency-Key (header) | string | No | Client-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats. |
Request body
| Name | Type | Required | What it is |
|---|---|---|---|
blueprint_id | Uuid | Yes | The SITE blueprint to deploy. ⛔ Always named explicitly — never "the latest". This overwrites a live site. |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
id | Uuid | Yes | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
blueprint_id | Uuid | Yes | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
site_id | Uuid | Yes | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
status | SiteBlueprintDeployStatus | Yes | ⭐ `waiting` is a real state and not a synonym for `pending`. A deploy started from the create form cannot restore anything until the new site has finished provisioning, which ta… |
message | string | No | Why it failed, or — after a successful restore whose URL rewrite did not take — what still needs attention. Rendered to the customer verbatim. |
started_at | object | No | — |
finished_at | object | No | — |
created_at | string | Yes | — |
Errors this endpoint can return
401 · 403 · 404 · 409 · 422 · 429 · 503