hosting

GET /v1/sites/{siteId}/ssh-keys

List a site's authorised SSH keys.

All hosting endpoints

Authentication

Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/ssh-keys \
  -H "Authorization: Bearer zdk_live_…"

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Every public key that can open a shell on the site's hosting package, together with whether the package restricts SSH to a list of addresses. `ssh` has been rendered as an included plan feature since the Hosting tab shipped — from a vendor flag that really is `true` on both package types we sell — with no way anywhere in the product to upload a key, so until this resource existed the entitlement was sold and read by nothing. ⛔ `ip_restricted` is its own field and must never be derived from `ip_allowlist == []`. The vendor answers "no restriction" as null, and an empty list rendered as a restriction would tell the customer they are protected when the truth is the opposite. `ip_allowlist_editable` is false today for a **vendor** reason rather than a plan one, so a client renders the list read-only instead of an editor that cannot save. A site that is not on a vendor hosting package has no such resource and returns `404`, exactly as an out-of-scope or unknown id does — never a `403`, never an existence oracle. Requires `sites.view` **and** `sites.panel_access`: the list is the access-control state of a shell on the customer's server, which is strictly more than the phpMyAdmin and file-manager access that key already names.

Parameters

NameTypeRequiredWhat it is
siteId (path)UuidYesSite ID (UUIDv7).

Response

NameTypeRequiredWhat it is
permittedbooleanYesWhether the package type includes SSH at all. This is the flag behind *"your plan does not include this"*.
can_createbooleanYes`permitted`, **and** the package has room for another key. Two fields rather than one because those are different sentences, and a single flag makes the screen say the wrong one.
keysSiteSshKey[]YesThe keys currently authorised on the package.
ip_allowliststring[]YesThe addresses SSH is restricted to, when it is restricted.
ip_restrictedbooleanYesWhether an address restriction is actually in force. ⛔ **Distinct from `ip_allowlist == []` and never derived from it.** The vendor answers "no restriction" as null, and an empt…
ip_allowlist_editablebooleanYesWhether the allow-list can be written. False today for a **vendor** reason rather than a plan one, so a client renders the list read-only instead of an editor that cannot save.

Errors this endpoint can return

401 · 403 · 404 · 422 · 429 · 503