hosting

GET /v1/sites/{siteId}/cdn/canonical-host

Which hostname serves, which redirects, and whether HTTPS is forced.

All hosting endpoints

Authentication

Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/cdn/canonical-host \
  -H "Authorization: Bearer zdk_live_…"

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Returns the whole serving plan rather than the two stored flags: the host that serves, the host that `301`s to it, and **every hostname the edge certificate must cover**. A client given only `canonical_host` would have to work out the alias itself, and two implementations of "what is the other hostname" is exactly the drift the engine-owns-policy rule exists to prevent. `certificate_hosts` always contains **both** names, and that is the half that is invisible when testing in a browser. TLS is negotiated on the name being redirected *from*, so a certificate covering only the canonical host puts a full-page security interstitial in front of the alias and the visitor never reaches the redirect at all. Requires `sites.view`.

Parameters

NameTypeRequiredWhat it is
siteId (path)UuidYesSite ID (UUIDv7).

Response

NameTypeRequiredWhat it is
canonical_hoststring<apex, www>Yes
force_httpsbooleanYesRedirect http to https at the edge. Defaults to true on every new site.
serves_onstringYesThe hostname that actually serves.
redirects_fromstringYesThe hostname that permanently redirects to `serves_on`.
redirect_statusintegerYesAlways 301. A 302 tells search engines to keep indexing the alias, which leaves the duplicate-content problem unsolved while looking correct in a browser.
certificate_hostsstring[]Yes**Both** hostnames, always. TLS is negotiated on the name being redirected from, so a certificate covering only `serves_on` puts a security interstitial in front of the alias an…
apex_deliverystring<native, alias, a_records, unsupported>YesHow the zone apex is made to resolve. A bare apex cannot be a `CNAME`, so on a pull-zone CDN it resolves only through CNAME-flattening/ALIAS at the DNS provider, or through A/AA…
apex_deliverablebooleanYes`false` when neither mechanism is available for this CDN/DNS pairing. The combination is refused rather than accepted, because the alternative provisions cleanly, reports health…

Errors this endpoint can return

401 · 403 · 404 · 422 · 429