hosting

POST /v1/sites/{siteId}/wordpress/themes

Install a theme on a site's WordPress.

All hosting endpoints

Authentication

Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/wordpress/themes \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{  }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Installs a theme, from the **wordpress.org directory** by `slug` (what `searchWordPressThemeDirectory` returns) or from a **zip the customer uploads**. ⛔⛔ **This did not exist until W22-D, and its absence is the whole of the owner's complaint on 2026-08-16**: *"no way in this or the main site manager bit to add new theme or uplaod one"*. The platform could list, activate and delete a theme and had no way to put one on a site, so a customer could only ever choose among the three themes WordPress ships with — and could delete two of them. ⛔ Exactly one of `slug` and `zip` — never both, refused rather than resolved by precedence. ⛔ **`activate` defaults to `false` here and to `true` on the plugin path**, and the asymmetry is deliberate. Activating a plugin adds behaviour; activating a theme **replaces what every visitor sees**, immediately, on a live site. A customer uploading a theme to look at it must not have their shop re-skinned as a side effect of the upload. ⚠️ An uploaded zip is **the customer's own code running on their own site**, and we do not review it. It is size-capped at 96 MiB (themes run larger than plugins — commercial multipurpose themes ship demo imagery) and rejected unless it is a valid archive containing a single top-level directory whose `style.css` carries a `Theme Name:` header, which is what WordPress itself requires. Note that a theme is **not** validated the way a plugin is: a block theme can legitimately contain no PHP at all, so a PHP-file check would refuse valid modern themes. ⛔ **Fleet only.** this platform exposes no theme-install endpoint at any path, and its own control panel offers no install control on its Themes page either — both measured 2026-08-16. So this is refused on the managed hosting line, where `wp_theme_install` is `false`; the capability map on `getSiteWordPress` says so up front rather than letting the customer discover it by pressing the button. Requires `sites.view` and `sites.panel_access`.

Parameters

NameTypeRequiredWhat it is
siteId (path)UuidYesSite ID (UUIDv7).

Request body

NameTypeRequiredWhat it is
slugstringNoA wordpress.org directory slug. Lower-case, digits and hyphens — the directory's own alphabet, enforced here so a path separator or a URL can never reach the box as a "slug".
zipstringNoA base64-encoded theme zip. Present instead of a multipart upload because every other write on this API is JSON.
activatebooleanNoMake this the site's active theme after installing. Defaults to `false` — see the asymmetry with the plugin path above.

Response

NameTypeRequiredWhat it is
dataSiteWordPressTheme[]YesThe installed themes.

Errors this endpoint can return

401 · 403 · 404 · 413 · 422 · 429 · 503