hosting
GET /v1/sites/{siteId}/quota/resources
What this site is allowed per resource, what it is using, and what more costs.
Authentication
Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/quota/resources \
-H "Authorization: Bearer zdk_live_…"Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
The **lifecycle** view, where `GET /v1/sites/{siteId}/quota` is the live read of what the box is enforcing right now. Owner ruling 2026-08-16: a plan grants **site slots**; disk, inodes and bandwidth are **per-site** resources with an admin-set default and a paid per-site upgrade. Each entry decomposes the allowance into `base` (the site's own copied default), `granted` (live grants — staff gestures and purchased upgrades) and `total`, because a card showing only the total cannot explain why the number changed when a grant expired. `reverts_at` is when the ceiling next **drops** because a temporary grant ends, so a customer learns before it happens rather than after. `measured_at` is surfaced deliberately: a bar drawn from a two-day-old reading looks identical to one drawn from a fresh reading, and `null` means nothing has ever measured this site. `price_minor` is `null` when no price is published in the caller's currency, and the client must then offer **no upgrade control** rather than one that cannot complete. Only resources this site's driver can actually enforce are listed. On a managed shared package the disk ceiling belongs to the package *type* and an inode limit does not exist at any level, so the list is empty there — the control is absent rather than inert. Requires `sites.view`.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
siteId (path) | Uuid | Yes | Site ID (UUIDv7). |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
frozen | boolean | Yes | Whether the platform has restricted this site **for being over a quota**. It is deliberately not "is this site restricted": that rung is shared with the malware and abuse ladder… |
resources | SiteQuotaResource[] | Yes | Only resources this site's driver can actually enforce. Empty on a managed hosting package, where the disk ceiling belongs to the package type and inodes do not exist. |
Errors this endpoint can return
401 · 403 · 404 · 429