hosting

POST /v1/sites/{siteId}/site-blueprint-deploy

Replace a site's content with a blueprint's.

All hosting endpoints

Authentication

Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/site-blueprint-deploy \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "blueprint_id": <Uuid> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

⛔ **Destructive.** This overwrites the site's live database and files with the contents of the named blueprint, then rewrites the restored content's stored web addresses to this site's domain (a WordPress database names its own URLs, so without that step the new site would redirect its visitors to the old one). Its own path on the **site**, beside `backups/restore`, rather than a verb on the blueprint — the destruction happens here, so it is gated on `hosting.backup.manage` and cannot be reached by varying the body of anything gentler. ⛔ A blueprint captured from a different **stack** is refused with a `422` (`stack_mismatch`) — WordPress can only be deployed onto WordPress. So is one from a different **hosting platform** (`platform_mismatch`), whose archive our adapter cannot restore here. A blueprint belonging to a **different account** is refused with `org_mismatch`, even when your token can reach both: hierarchical tenancy means a reseller's key spans every client organisation, and a blueprint is that site's whole database — it never crosses between accounts. A blueprint that is still being captured is `blueprint_not_ready`. A deploy already in flight on this site is a `409`. The refusal is a **machine code**, carried in `error.details[0].code`, so a client can render it in the customer's own language; `error.message` is the English equivalent for a caller with no catalogue. ⛔ Read the code from `details`, not from `error.code` — that is the generic `UNPROCESSABLE_ENTITY` for every 422 this API produces.

Parameters

NameTypeRequiredWhat it is
siteId (path)UuidYesSite ID (UUIDv7).
Idempotency-Key (header)stringNoClient-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats.

Request body

NameTypeRequiredWhat it is
blueprint_idUuidYesThe SITE blueprint to deploy. ⛔ Always named explicitly — never "the latest". This overwrites a live site.

Response

NameTypeRequiredWhat it is
idUuidYesUUIDv7 identifier — sortable by creation time (docs/02 §8).
blueprint_idUuidYesUUIDv7 identifier — sortable by creation time (docs/02 §8).
site_idUuidYesUUIDv7 identifier — sortable by creation time (docs/02 §8).
statusSiteBlueprintDeployStatusYes⭐ `waiting` is a real state and not a synonym for `pending`. A deploy started from the create form cannot restore anything until the new site has finished provisioning, which ta…
messagestringNoWhy it failed, or — after a successful restore whose URL rewrite did not take — what still needs attention. Rendered to the customer verbatim.
started_atobjectNo
finished_atobjectNo
created_atstringYes

Errors this endpoint can return

401 · 403 · 404 · 409 · 422 · 429 · 503