Authentication
Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/ssh-keys \
-H "Authorization: Bearer zdk_live_…"Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
Every public key that can open a shell on the site's hosting package, together with whether the package restricts SSH to a list of addresses. `ssh` has been rendered as an included plan feature since the Hosting tab shipped — from a vendor flag that really is `true` on both package types we sell — with no way anywhere in the product to upload a key, so until this resource existed the entitlement was sold and read by nothing. ⛔ `ip_restricted` is its own field and must never be derived from `ip_allowlist == []`. The vendor answers "no restriction" as null, and an empty list rendered as a restriction would tell the customer they are protected when the truth is the opposite. `ip_allowlist_editable` is false today for a **vendor** reason rather than a plan one, so a client renders the list read-only instead of an editor that cannot save. A site that is not on a vendor hosting package has no such resource and returns `404`, exactly as an out-of-scope or unknown id does — never a `403`, never an existence oracle. Requires `sites.view` **and** `sites.panel_access`: the list is the access-control state of a shell on the customer's server, which is strictly more than the phpMyAdmin and file-manager access that key already names.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
siteId (path) | Uuid | Yes | Site ID (UUIDv7). |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
permitted | boolean | Yes | Whether the package type includes SSH at all. This is the flag behind *"your plan does not include this"*. |
can_create | boolean | Yes | `permitted`, **and** the package has room for another key. Two fields rather than one because those are different sentences, and a single flag makes the screen say the wrong one. |
keys | SiteSshKey[] | Yes | The keys currently authorised on the package. |
ip_allowlist | string[] | Yes | The addresses SSH is restricted to, when it is restricted. |
ip_restricted | boolean | Yes | Whether an address restriction is actually in force. ⛔ **Distinct from `ip_allowlist == []` and never derived from it.** The vendor answers "no restriction" as null, and an empt… |
ip_allowlist_editable | boolean | Yes | Whether the allow-list can be written. False today for a **vendor** reason rather than a plan one, so a client renders the list read-only instead of an editor that cannot save. |
Errors this endpoint can return
401 · 403 · 404 · 422 · 429 · 503