hosting

POST /v1/sites/{siteId}/vendor-snapshots/restore

Restore a site from a vendor restore point.

All hosting endpoints

Authentication

Send an API key as a bearer token. The key must carry the hosting.backup.manage permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/vendor-snapshots/restore \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "scope": <string<web, database, mailbox>>, "timestamp": <string> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Rolls the website, one database or one mailbox back to a named restore point. `202` and the whole surface's new state, for the same reason `takeSiteVendorSnapshot` returns it: the platform performs the restore afterwards and the client polls on `in_progress`. ⛔ **This is the destructive one, and its own path is part of how it is gated.** It overwrites the customer's live files and database, so it is deliberately not a verb on the collection that takes backups — it must not be reachable by sending a slightly different body to the endpoint beside it. A restore always **names its restore point**, never "the latest": `timestamp` is one of the values `getSiteVendorSnapshots` returned, and the engine re-checks it against the live listing before anything is sent, so a value a client composed cannot reach the vendor. `temp_mailbox` applies to mailboxes only, where the platform restores into a `temp-` prefixed mailbox instead of overwriting the original; it is offered as a choice rather than assumed. The action is audit-logged **after** the platform accepts it, so the trail never claims a restore a refusal never started. `404` for a site with no vendor hosting package, or one that is not the caller's; `422` for a restore point that is no longer in the listing or a scope that cannot be restored. Requires `hosting.backup.manage`.

Parameters

NameTypeRequiredWhat it is
siteId (path)UuidYesSite ID (UUIDv7).

Request body

NameTypeRequiredWhat it is
scopestring<web, database, mailbox>YesWhat to restore.
timestampstringYesThe restore point's handle, exactly as `getSiteVendorSnapshots` reported it.
item_idstringNoWhich database or mailbox. Empty for the website.
temp_mailboxbooleanNoMailboxes only. The platform restores into a `temp-` prefixed mailbox instead of overwriting the original, which is the safe default for mail — offered as a choice rather than a…

Response

NameTypeRequiredWhat it is
availablebooleanYesWhether the site's hosting platform has a timeline surface at all. False is **our** gap, and nothing the customer can do changes it.
permittedbooleanYesWhether the vendor package type includes it. False is answered by an upgrade.
probooleanYesWhether the package carries the paid tier rather than the included one.
attachedbooleanYesWhether a Timeline Storage service is actually attached to the package. False is the third "no", and it is neither of the other two.
can_back_upbooleanYesWhether `takeSiteVendorSnapshot` would be accepted right now. Read rather than recomputed from the three flags above, so a screen never offers a button the engine refuses.
has_dead_webbooleanYesWhether the platform reports the website's timeline as broken. It is surfaced rather than hidden: a customer whose restore points stopped being taken needs to know before they n…
in_progressbooleanYesWhether any snapshot or restore job is running. This is what a client polls on, and only while it is true.
webSiteVendorSnapshotItemYesThe website's timeline, or null when the platform holds none.
databasesSiteVendorSnapshotItem[]YesEach database's timeline.
mailboxesSiteVendorSnapshotItem[]YesEach mailbox's timeline.

Errors this endpoint can return

401 · 403 · 404 · 422 · 429 · 503