hosting

POST /v1/migrations/discover

Identify a host from its hostname, with no site yet.

All hosting endpoints

All developer docs

Authentication

Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/migrations/discover \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "host": <string> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

The org-scoped twin of POST /v1/sites/{siteId}/migrations/discover. Same workflow, same 202-plus-poll shape, and the same owner ruling behind it: signed-in customers only, never a prospect — the hostname is attacker-supplied by construction and "probe this for me" is the classic shape of a request to reach something the caller cannot. It exists because the customer it serves has no sites at all, which is exactly the customer being asked "which control panel do you log in to?" by a form they cannot answer. hosting.import.manage is an org permission, so every run still has a named actor and an org to rate-limit; only the site-level anchor is dropped, and nothing about the ruling rested on it. POST rather than GET, and not because of a secret — there is none in the body. It knocks on a third party's administrative ports, which is an act rather than a lookup, and must not be repeated by a browser prefetch, a CDN revalidation or a back button. Name the organisation with X-Zinn-Org when you belong to more than one; a caller in exactly one org may omit it.

Request body

NameTypeRequiredWhat it is
hoststringYesThe server address the current host gave them, e.g. server123.theirhost.com. A hostname, not a web address — no scheme and no path. The customer's own domain works too when it…

Response

NameTypeRequiredWhat it is
outcomestring<pending, identified, unidentified, unreachable>Yespending while the discovery workflow is still probing — poll getMigrationDiscovery until it is one of the other three (D19865). ⛔ Three answers and never a boolean.…
hoststringYesThe hostname as it was normalised, which may differ from what was typed.
sourcestringYesThe best candidate's MigrationSource, or "" when there is none.
portintegerYesThe login port for that source, which is not necessarily the port the evidence came from: a banner read from cPanel's plaintext 2082 reports 2083, because that is where the…
confidenceintegerYes
confidentbooleanYesMay the credential form be pre-filled from this?
candidatesMigrationDiscoveryCandidate[]Yes
expectationsstring[]YesMachine codes for what to expect from the winning source — e.g. ftp_files_only. ⛔ Expectations, not a capability claim: the authoritative answer comes from the credentialed…
routesMigrationDiscoveryRoute[]YesEvery way in that was tried. Read it when a panel is firewalled — a host with 2083 closed and 22 open can still have everything moved.
proxy_frontedbooleanYesThis address is a CDN in front of a website, not a hosting account — several different panels' login ports accepted a connection at once and none of them answered with its own…
refusedstringYesA customer-readable reason the hostname was rejected before any packet went out — a private address, an unresolvable name. "" otherwise.
agent_usedbooleanYesWhether a language model was asked to read the sign-in page. It is asked only when the deterministic table produced no confident panel.
agent_unavailablestringYesMachine code when the model was asked and could not answer (ai_unavailable, ai_timeout, …). "" when it was not asked or it answered. ⛔ The deterministic answer stands either…
discovery_idstringYesThe recorded run, for support. "" when the row could not be written — which never costs the customer their answer.

Errors this endpoint can return

401 · 403 · 422 · 429 · 503