hosting
POST /v1/migrations/discover
Identify a host from its hostname, with no site yet.
Authentication
Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X POST https://api.zinndigital.com/v1/migrations/discover \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "host": <string> }'Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
The org-scoped twin of POST /v1/sites/{siteId}/migrations/discover. Same workflow, same 202-plus-poll shape, and the same owner ruling behind it: signed-in customers only, never a prospect — the hostname is attacker-supplied by construction and "probe this for me" is the classic shape of a request to reach something the caller cannot. It exists because the customer it serves has no sites at all, which is exactly the customer being asked "which control panel do you log in to?" by a form they cannot answer. hosting.import.manage is an org permission, so every run still has a named actor and an org to rate-limit; only the site-level anchor is dropped, and nothing about the ruling rested on it. POST rather than GET, and not because of a secret — there is none in the body. It knocks on a third party's administrative ports, which is an act rather than a lookup, and must not be repeated by a browser prefetch, a CDN revalidation or a back button. Name the organisation with X-Zinn-Org when you belong to more than one; a caller in exactly one org may omit it.
Request body
| Name | Type | Required | What it is |
|---|---|---|---|
host | string | Yes | The server address the current host gave them, e.g. server123.theirhost.com. A hostname, not a web address — no scheme and no path. The customer's own domain works too when it… |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
outcome | string<pending, identified, unidentified, unreachable> | Yes | pending while the discovery workflow is still probing — poll getMigrationDiscovery until it is one of the other three (D19865). ⛔ Three answers and never a boolean.… |
host | string | Yes | The hostname as it was normalised, which may differ from what was typed. |
source | string | Yes | The best candidate's MigrationSource, or "" when there is none. |
port | integer | Yes | The login port for that source, which is not necessarily the port the evidence came from: a banner read from cPanel's plaintext 2082 reports 2083, because that is where the… |
confidence | integer | Yes | — |
confident | boolean | Yes | May the credential form be pre-filled from this? |
candidates | MigrationDiscoveryCandidate[] | Yes | — |
expectations | string[] | Yes | Machine codes for what to expect from the winning source — e.g. ftp_files_only. ⛔ Expectations, not a capability claim: the authoritative answer comes from the credentialed… |
routes | MigrationDiscoveryRoute[] | Yes | Every way in that was tried. Read it when a panel is firewalled — a host with 2083 closed and 22 open can still have everything moved. |
proxy_fronted | boolean | Yes | This address is a CDN in front of a website, not a hosting account — several different panels' login ports accepted a connection at once and none of them answered with its own… |
refused | string | Yes | A customer-readable reason the hostname was rejected before any packet went out — a private address, an unresolvable name. "" otherwise. |
agent_used | boolean | Yes | Whether a language model was asked to read the sign-in page. It is asked only when the deterministic table produced no confident panel. |
agent_unavailable | string | Yes | Machine code when the model was asked and could not answer (ai_unavailable, ai_timeout, …). "" when it was not asked or it answered. ⛔ The deterministic answer stands either… |
discovery_id | string | Yes | The recorded run, for support. "" when the row could not be written — which never costs the customer their answer. |
Errors this endpoint can return
401 · 403 · 422 · 429 · 503