hosting

GET /v1/sites/{siteId}/cache

Get a site's server-side cache policy.

All hosting endpoints

Authentication

Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/cache \
  -H "Authorization: Bearer zdk_live_…"

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

How long the hosting platform caches the site's assets, every asset class the vendor reported, and its cacheability report for the URLs it has seen. ⛔ This is the **server-side** cache on the package itself, not `getSiteCdn` — that resource is our own Cloudflare/Bunny/CDN77 tier picker and answers about a pool zone. Conflating the two is exactly how a purge button came to call a Cloudflare path for a site whose edge is the vendor's. `permitted` and `purge_permitted` are two fields rather than one because they are two facts: the purge was measured working on a package whose cache settings and report the vendor refuses. `reported` carries every class the vendor named, including the five that cannot be written — a client renders those read-only, because writing them deletes them. Each `reasons` entry is a stable identifier (`set_cookie`, `cache_control`, …) that the client localises; no vendor prose reaches a customer through this resource. `404` for a site with no vendor hosting package, or one that is not the caller's. Requires `sites.view` — how long a site caches its CSS is the same class of fact as the rest of the Hosting tab.

Parameters

NameTypeRequiredWhat it is
siteId (path)UuidYesSite ID (UUIDv7).

Response

NameTypeRequiredWhat it is
permittedbooleanYesWhether the package type exposes cache settings and the report at all.
purge_permittedbooleanYesWhether a purge is permitted. Separate from `permitted` on purpose: the purge was measured working on a package whose cache settings and report the vendor refuses.
css_secondsintegerYesHow long stylesheets are cached.
image_secondsintegerYesHow long images are cached.
javascript_secondsintegerYesHow long scripts are cached.
reportedobjectYesEvery asset class the vendor reported, keyed by its own name, including the classes that cannot be written. ⛔ Read-only on a client: writing them deletes them, because the vendo…
report_availablebooleanYesWhether the cacheability report could be read. False renders an explanation rather than an empty table, so "nothing has been seen yet" and "not part of this plan" never look ide…
reportSiteCacheReportRow[]YesWhat the platform did with the URLs it has seen.

Errors this endpoint can return

401 · 403 · 404 · 422 · 429 · 503