hosting
GET /v1/sites/{siteId}/database
Get a site's database size and panel links.
Authentication
Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/database \
-H "Authorization: Bearer zdk_live_…"Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
The per-site Tools tab's Database card — the site's MySQL size and table count, plus single-use SSO links into the phpMyAdmin and File Manager panels. Requires **both** `sites.view` and `sites.panel_access` — the panels are full database and filesystem access, which is strictly more than listing a site — and is RLS-scoped to a site the caller holds `sites.panel_access` over, so holding the key in one org never reaches another org's site. An out-of-scope or unknown id is a `404`, exactly like `getSite`; a caller who can see the site but lacks `sites.panel_access` gets a `403`. **The data source is provisioned, not synchronous.** The size/table figures come from the site's fleet worker and the panels are stood up per host behind Cloudflare Access. Until a host is serving them, `available` is `false` and every figure and panel URL is `null` — never a fabricated `0` or a link to a panel that is not there. The shape is stable, so populating it later is not a contract change. Panel URLs, when present, are always HTTPS single-use links minted on read (a non-HTTPS panel URL is never returned).
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
siteId (path) | Uuid | Yes | Site ID (UUIDv7). |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
available | boolean | Yes | Whether a host is serving this site's database + panels yet. |
reason | string | No | Why a link or a figure is missing, in words a customer can act on. `available: false` alone cannot distinguish "this site has no server yet" from "we could not reach the box" fr… |
reason_code | string | No | A stable, machine-readable name for the reason above — the half a CLIENT should render. `reason` is English prose for staff, SDK consumers and support tickets; this platform shi… |
size_mb | object | Yes | Total database size in MB; null when unavailable. |
tables | object | Yes | Number of tables in the database; null when unavailable. |
phpmyadmin_sso_url | object | Yes | HTTPS single-use SSO link into phpMyAdmin, minted on read; null when the panel is not provisioned. Never a non-HTTPS URL. |
filemanager_sso_url | object | Yes | HTTPS single-use SSO link into the File Manager, minted on read; null when the panel is not provisioned. Never a non-HTTPS URL. |
web_ide_sso_url | object | Yes | HTTPS single-use SSO link into the Web IDE — real VS Code (`code-server`) running in the browser against this site's files. Minted on read; null when the site is not on one of o… |
Errors this endpoint can return
401 · 403 · 404 · 429