hosting

POST /v1/sites/{siteId}/wordpress/plugins

Install a plugin on a site's WordPress.

All hosting endpoints

Authentication

Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/wordpress/plugins \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{  }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Installs a plugin and, by default, activates it. Either from the **wordpress.org directory** by `slug` (what `searchWordPressPluginDirectory` returns), or from a **zip the customer uploads**. ⛔ Exactly one of `slug` and `zip` — never both. A request carrying both is refused `422` rather than resolved by precedence, because a caller that sent the wrong one would otherwise install something it did not ask for and be told it succeeded. Idempotent: a plugin already present is activated rather than reinstalled, and an upload of a plugin that is already there replaces it in place. Nothing is ever removed — use `deleteSiteWordPressPlugin` for that. ⚠️ An uploaded zip is **the customer's own code running on their own site**, and we do not review it. It is size-capped and rejected unless it is a valid archive containing a single top-level directory with a PHP plugin header, which is what WordPress itself requires — not a security review, and not presented as one. Refused `422` when the package type does not carry `wp_plugins`, or when WordPress is not installed. `404` for a site with no vendor hosting package. Requires `sites.view` and `sites.panel_access`.

Parameters

NameTypeRequiredWhat it is
siteId (path)UuidYesSite ID (UUIDv7).

Request body

NameTypeRequiredWhat it is
slugstringNoA wordpress.org directory slug. Lower-case, digits and hyphens — the directory's own alphabet, enforced here so a path separator or a URL can never reach the box as a "slug".
zipstringNoA base64-encoded plugin zip. Present instead of a multipart upload because every other write on this API is JSON and one exception would need its own auth, size and error handling.
activatebooleanNoActivate after installing. `false` puts the files in place and leaves the plugin switched off — what a staged rollout of something risky wants. Deliberately not the default: "in…

Response

NameTypeRequiredWhat it is
dataSiteWordPressPlugin[]YesThe installed plugins.
stack_cache_installedbooleanYes⛔ **Cannot be derived from `data`.** this platform excludes its own server-side cache plugin from the listing, so a client deriving this flag from the rows would answer "not ins…

Errors this endpoint can return

401 · 403 · 404 · 409 · 413 · 422 · 429 · 503