hosting

POST /v1/sites/{siteId}/hosting/applications

Install a one-click application onto a live site.

All hosting endpoints

Authentication

Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/hosting/applications \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "application": <string> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Installs `application` onto the site's hosting package. The submit is instant and the work runs as a durable workflow (§2.16), so this answers `202` with the install row — poll `GET` on this path and read `current` for its state. ⛔ **This is destructive**: a one-click install unpacks a whole application over the site's document root and creates a database, so it is gated on `hosting.applications.manage` rather than on `hosting.deploy.manage`, and only one install may run per site at a time (`409` otherwise). `404` for a site whose platform has no application catalogue at all — a site on our own fleet simply does not have this resource, and naming the platform it is *not* on would disclose which vendor a site runs on. `422` when the catalogue exists but that application is not offered: either the product line does not sell it, or the vendor no longer carries it. The application list is per **product line** — the footprint-free line deliberately offers a narrower set than mainstream — and it is read live, so a page left open can offer something that has since gone.

Parameters

NameTypeRequiredWhat it is
siteId (path)UuidYesSite ID (UUIDv7).

Request body

NameTypeRequiredWhat it is
applicationstringYesThe `key` of an application from this site's own list. Validated against the **live** catalogue rather than a fixed enum, because the range changes without a release on our side.
localestringNoThe language to install the site in, as a platform language code (`de`, `pt-BR`). Applies to `wordpress` only, and is saved to the site so a later reinstall keeps it. Omit to us…

Response

NameTypeRequiredWhat it is
idstringYes
application_keystringYes
application_namestringYesThe display name captured at the moment of installing — a snapshot, so history still reads correctly after the platform renames or retires an application.
statusstring<queued, installing, installed, failed>Yes
messagestringYesCustomer-facing English. Only meaningful when `failed`.
requested_bystringNoThe actor who asked for it, for the audit trail.
started_atstringNo
finished_atstringNo
created_atstringYes

Errors this endpoint can return

401 · 403 · 404 · 409 · 422 · 429 · 503