hosting

GET /v1/sites/{siteId}/php-settings

Get a site's PHP extensions, php.ini settings and resource tier.

All hosting endpoints

Authentication

Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/php-settings \
  -H "Authorization: Bearer zdk_live_…"

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Everything the site's PHP screen needs, in one read. `extensions` lists Tier 0 and Tier 1 as `locked: true` — always on, not a choice — alongside the Tier 2 extensions the customer may switch. They are **rendered rather than hidden** because "does this host have ImageMagick?" is one of the commonest pre-sales and migration questions there is, and an empty list answers it worse than a locked switch does. `ini` carries only the two customer-editable bands. The staff-only band (`disable_functions`, `open_basedir`, `sendmail_path`, `upload_tmp_dir`, `expose_php` and extension loading itself) is **absent from the payload**, not merely hidden by the panel: those directives are the per-site isolation boundary, and a customer who can edit `disable_functions` can re-enable `shell_exec`. Each capped directive carries `cap` — the ceiling this site's **plan** allows — so the panel can stop the control at the right place rather than let the customer type a value and meet a refusal. `cap_raised_by_support` and `override_expires_at` are how a staff override is made **visible to the customer**, which is one of the three properties `docs/204` §7a requires of one. `lve` reports the site's resource tier and what each limit does when it is reached. ⭐ `ep` is the one that emits `508 Resource Limit Is Reached` — a status code that names no resource, no number and no remedy, so a customer who meets it concludes the host is broken. `applied_at` is `null` when no settings have ever been pushed to the machine — a different fact from "pushed and confirmed", and the only one of the two that needs an engineer. Requires `sites.view`.

Parameters

NameTypeRequiredWhat it is
siteId (path)UuidYesSite ID (UUIDv7).

Response

NameTypeRequiredWhat it is
php_versionstringYesThe alt-php version this site runs, dotted (`8.3`). Empty if unset.
extensionsSitePhpExtension[]Yes
iniSitePhpBandedOption[]Yes
lveSiteLveStateYesThe site's CloudLinux LVE resource tier — `docs/204` §7b. ⭐ `ep` is the limit that emits `508 Resource Limit Is Reached`, which is why this is on a customer screen at all: it co…
applied_atstringYesWhen these settings were last confirmed by the machine. `null` means they have never been pushed — a different fact from "pushed and matched", and the only one of the two that n…

Errors this endpoint can return

401 · 403 · 404 · 429