hosting
GET /v1/sites/{siteId}/vendor-snapshots
List a site's vendor restore points.
Authentication
Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/vendor-snapshots \
-H "Authorization: Bearer zdk_live_…"Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
The website, database and mailbox restore points the hosting platform holds for this site. Until this resource existed, a plan chip reading *"Point-in-time backups you can restore yourself"* was served by an endpoint that refuses. ⛔ **Three different "no"s are reported separately and must not be collapsed**, because they need three different sentences and only one of them is answered by the customer doing anything: `available: false` is the site's platform having no timeline surface (our gap), `permitted: false` is the vendor package type excluding it (an upgrade answers this), and `attached: false` is no Timeline Storage service being attached to the package. `timestamp` on a restore point is the platform's own string and is the handle a restore sends back — it is **not** display text; `as_of` is what a date formatter reads, and is null when no exact instant was given. `404` for a site with no vendor hosting package, or one that is not the caller's. Requires `sites.view`.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
siteId (path) | Uuid | Yes | Site ID (UUIDv7). |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
available | boolean | Yes | Whether the site's hosting platform has a timeline surface at all. False is **our** gap, and nothing the customer can do changes it. |
permitted | boolean | Yes | Whether the vendor package type includes it. False is answered by an upgrade. |
pro | boolean | Yes | Whether the package carries the paid tier rather than the included one. |
attached | boolean | Yes | Whether a Timeline Storage service is actually attached to the package. False is the third "no", and it is neither of the other two. |
can_back_up | boolean | Yes | Whether `takeSiteVendorSnapshot` would be accepted right now. Read rather than recomputed from the three flags above, so a screen never offers a button the engine refuses. |
has_dead_web | boolean | Yes | Whether the platform reports the website's timeline as broken. It is surfaced rather than hidden: a customer whose restore points stopped being taken needs to know before they n… |
in_progress | boolean | Yes | Whether any snapshot or restore job is running. This is what a client polls on, and only while it is true. |
web | SiteVendorSnapshotItem | Yes | The website's timeline, or null when the platform holds none. |
databases | SiteVendorSnapshotItem[] | Yes | Each database's timeline. |
mailboxes | SiteVendorSnapshotItem[] | Yes | Each mailbox's timeline. |
Errors this endpoint can return
401 · 403 · 404 · 422 · 429 · 503