hosting

GET /v1/sites/{siteId}/backups

List a site's backups and what its plan grants.

All hosting endpoints

Authentication

Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/backups \
  -H "Authorization: Bearer zdk_live_…"

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

A cheap database read, polled while a backup is in flight, so it never calls the hosting adapter or object storage. `offsite_enabled` is reported deliberately: when it is false every backup lives on the same host as the site, so a host loss takes both — the customer is entitled to know that before they need a restore. Requires `sites.view`.

Parameters

NameTypeRequiredWhat it is
siteId (path)UuidYesSite ID (UUIDv7).

Response

NameTypeRequiredWhat it is
site_idUuidYesUUIDv7 identifier — sortable by creation time (docs/02 §8).
backupsSiteBackup[]Yes
can_backupbooleanYesFalse while a backup is in flight, when this site's hosting platform cannot take one at all, or when the site's on-demand allowance for the last 24 hours is spent.
in_progressbooleanYes
on_demand_backupsbooleanYesAlways true. On-demand backups are included on every plan (owner ruling 2026-08-10); what bounds them is `on_demand_limit` per rolling 24 hours, not the plan. Retained for compa…
unsupported_reasonstringNoA stable machine identifier saying why this site's hosting platform cannot be backed up at all, or empty when it can. The client renders it as a localised sentence. Distinct fro…
on_demand_limitintegerYesOn-demand backups allowed per rolling 24 hours, per site.
on_demand_usedintegerYesOn-demand backups taken in the last 24 hours. Failed attempts are not counted — the customer got nothing from them.
on_demand_remainingintegerYesHow many the customer may still take right now.
on_demand_next_atstringYesWhen the next on-demand slot opens, as the oldest counted backup ages out of the rolling window. Null whenever `on_demand_remaining` is above zero.
daily_backupsbooleanYesThe plan's `daily_backups` entitlement — whether the nightly sweep selects this site.
retention_daysintegerYesThe plan's `backup_retention_days` entitlement, clamped to the platform maximum.
offsite_enabledbooleanYesWhether object storage is configured. False means every backup stays on the worker host it was taken on.
immutablebooleanYesWhether backup immutability is enforced **and proven recently**. True only when the platform's last reconciliation actually attempted to delete a canary object under the backup…
immutable_daysintegerYesHow many days a written backup cannot be altered or deleted by anyone — us, a compromised site, or a stolen token. 30 by owner ruling (2026-08-12), matching sold retention; `0`…
immutability_verified_atstringYesWhen a delete was last actually attempted against the protected prefix and refused. ⛔ Not when the configuration was last read, and not when the reconciler last ran: a run that…
immutability_reasonstringYesA stable machine identifier saying why immutability is not currently provable — `never_checked`, `no_rule`, `delete_succeeded`, `credential_missing`, `canary_write_failed`, `ven…
restore_drill_passedbooleanYesWhether the platform's weekly restore drill last **passed**, and recently enough to still mean something. The drill restores a real stored backup onto a platform-owned site and…
restore_drill_atstringYesWhen the last drill finished, whatever its outcome. Null when no drill has ever completed.
restore_drill_reasonstringYesA stable machine identifier saying why restores are not currently proven — `never_drilled`, `no_drill_site`, `no_recent_backup`, `canary_unavailable`, `restore_failed`, `fence_r…

Errors this endpoint can return

401 · 403 · 404 · 429