Authentication
Send an API key as a bearer token. The key must carry the sites.create permission; a key without it is refused with 403, not 404.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X POST https://api.zinndigital.com/v1/sites/deleted/{deletedSiteId}/restore \
-H "Authorization: Bearer zdk_live_…"Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
Brings a deleted site back. Answers `202` — the site is rebuilt by a workflow, and returns to `suspended` rather than `active` until it is actually serving again. ⛔ **The guard is re-evaluated on this request, never trusted from the button.** Between the list rendering and the click the customer may have recreated a site on the same domain, the retention window may have closed, or the purge may have run. A `422` carries the machine-readable reason (`no_backup`, `purged`, `domain_in_use`, `already_restored`, `abuse_hold`) so the client can say which it was. Requires `sites.create` as well as `sites.view`: a restore *creates* a live site.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
deletedSiteId (path) | Uuid | Yes | The `DeletedSite` record id (not the site id). |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
id | Uuid | Yes | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
site_id | Uuid | Yes | The site this was. May no longer exist as a row. |
org_id | Uuid | Yes | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
primary_domain | string | Yes | — |
reason | string<dunning, customer, staff, abuse> | Yes | Why it was deleted. `abuse` is restorable by staff only — a one-click customer restore of a site removed for terms enforcement would undo the enforcement. |
deleted_at | string | Yes | Soft delete — removed from serving. The data is still here. |
deleted_by | string | No | — |
purge_due_at | string | No | **When the backup is purged and the site becomes permanently unrecoverable.** ⛔ Computed by the engine from the live retention policy, by the same function the purge sweep selec… |
purged_at | string | No | Hard delete. Non-null means the data is gone and no restore is possible. |
restored_at | string | No | — |
restorable | boolean | Yes | Whether a restore would succeed **right now**. Reflects a real check that the backup object exists in storage — not a status column. |
reason_code | string<, no_backup, purged, domain_in_use, already_restored, abuse_hold> | Yes | Empty when restorable. Otherwise one of `no_backup`, `purged`, `domain_in_use`, `already_restored`, `abuse_hold`. ⛔ A **code**, rendered by the client through its own catalogue… |
Errors this endpoint can return
401 · 403 · 404 · 422 · 429 · 503