Authentication
Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/deletion \
-H "Authorization: Bearer zdk_live_…"Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
Whether anything is scheduled for this site, when it fires, and whether it can still be stopped. This is also where the client reads `primary_domain` — the value the customer must type into `deleteSite` — so the instruction on screen and the check on the server come from one place and cannot drift apart. ⛔ **`can_cancel` is its own field and must never be recomputed as `state == "scheduled"`.** Once the teardown starts, the request row still says `scheduled` while the site is already being deleted; a client doing its own arithmetic would offer the cancel button at the exact moment it can only fail. Requires `sites.view` only — a read-only member learning that their site is about to be deleted is the whole point, and hiding the countdown from them would mean the first they hear of it is the site being gone. `404` for a site with no vendor hosting package, or one that is not theirs.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
siteId (path) | Uuid | Yes | Site ID (UUIDv7). |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
site_id | string | Yes | The site this deletion state belongs to. |
primary_domain | string | Yes | ⛔ What the customer must type into `deleteSite`, and what the engine compares against. Read it from here rather than from a `Site` object already on screen: one value on both si… |
state | string<none, scheduled, running, stalled, deleted> | Yes | Where the site is in its lifecycle. A stable machine value the client turns into a localised sentence — never English composed by the engine (§2.19). ⛔ `stalled` is `running` th… |
deletable | boolean | Yes | Whether a deletion could be requested right now. False on a site whose state does not allow it, so the form is explained rather than offered and refused. |
scheduled_for | string | Yes | When the teardown fires, or null when nothing is scheduled. |
requested_at | string | Yes | When the deletion was requested, or null when nothing is scheduled. |
grace_days | integer | Yes | How many days the countdown runs. Clamped at both ends — a floor of one day is what stops a misconfiguration meaning *delete now*. |
grace_free_reason | string<, internal, never_provisioned> | Yes | Why this site would skip the grace period entirely, or `""` when it would not. `never_provisioned` means the site is `failed` — provisioning never completed, so nothing was ever… |
can_cancel | boolean | Yes | ⛔ **Its own field, and never recomputed as `state == "scheduled"`.** Once the teardown starts, the request row still says scheduled while the site is already being deleted; a cl… |
Errors this endpoint can return
401 · 403 · 404 · 429 · 503