hosting

POST /v1/sites/{siteId}/migrations/{migrationId}/rollback

Put the site back to how it was before this migration.

All hosting endpoints

All developer docs

Authentication

Send an API key as a bearer token. The key must carry the hosting.backup.manage permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/migrations/{migrationId}/rollback \
  -H "Authorization: Bearer zdk_live_…"

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Restores the backup taken in the seconds before the migration replaced the site. ⛔ This overwrites the site's live files and database — with the version from before the migration, which is the point, but overwriting all the same: anything the customer has done since is inside the window the restore covers. Its own route rather than a flag on the detail endpoint, and it does not re-implement the restore — it starts the same SiteRestoreWorkflow the Backups screen uses, which the weekly restore drill already exercises. Refused with 422 and a machine code when the migration replaced nothing (nothing_was_replaced), has already been rolled back (already_rolled_back), is still running (migration_not_finished — the answer there is to cancel it), has no usable archive (no_safety_backup:<state>, safety_backup_gone) or is past its 30 days (window_expired). Requires hosting.backup.managenot hosting.import.manage. Starting a migration and destroying what is on a site now are different powers, and this is the same permission POST /v1/sites/{siteId}/backups/restore requires for the identical act.

Parameters

NameTypeRequiredWhat it is
siteId (path)UuidYesSite ID (UUIDv7).
migrationId (path)UuidYesThe migration job's id (UUIDv7), as listSiteMigrations reports it. Ours, minted when the row was written — never anything the source host knows about.

Response

NameTypeRequiredWhat it is
idUuidYesUUIDv7 identifier — sortable by creation time (docs/02 §8).
site_idUuidYesUUIDv7 identifier — sortable by creation time (docs/02 §8).
sourceMigrationSourceYesThe kind of hosting the site is being pulled from. ⛔ plesk is offered so the refusal can be specific and actionable, not because it is supported: pleskbackup is reachable…
statusSiteMigrationStatusYesauthenticating, inventorying and transferring are separate states rather than one running because they fail for opposite reasons and the customer's next action differs: a…
status_reasonstringNoA machine code the dashboard renders through its own catalogue — never an English sentence composed by the engine, which could be shown to none of the other 57 locales.
include_mailbooleanYes
source_hoststringNoThe hostname the estate is being pulled from. Host only: no port, no username, and never a secret.
files_totalintegerYes
files_doneintegerYes
databases_totalintegerYes
databases_doneintegerYes
mailboxes_totalintegerYes
mailboxes_doneintegerYes
items_failedintegerYes⛔ Counted separately from the *_done fields, never folded into them. "We could not get it" reported as "done" makes the completion report a lie.
bytes_transferredintegerYes
warningsstring[]YesMachine warning codes the dashboard localises.
mail_synced_atstringNoWhen the mail delta last ran. null and a timestamp are different states, and the cutover control reads this to tell them apart.
dns_records_capturedintegerNoHow many records were read off the source's zone and will be published on cutover. ⛔ Counted separately from dns_records_unsupported, never as one total: "we captured 14…
dns_records_unsupportedintegerNoReal records the source holds that our DNS editor cannot express (an SSHFP, a TLSA, an MX with no preference). Stored and listed on the detail endpoint rather than dropped —…
dns_captured_atstringNoWhen the source's zone was read. null means never attempted, which is NOT the same as attempted-and-the-panel-holds-no-zone; only the first is worth retrying.
verified_atstringNoWhen the migrated site was last fetched over HTTP and compared with the source. null means the destination has never been looked at.
verification_codestringNoA machine code the dashboard localises. Empty means the destination is serving the site as well as the source was. ⛔ The migration's own counters cannot answer this: they travel…
destination_statusintegerNoThe HTTP status the migrated site returned, fetched at its origin address with a Host: header — before cutover the customer's domain still resolves to the OLD host, so asking…
source_statusintegerNoThe HTTP status the source returned. ⭐ Reported beside destination_status because the interesting failure is the PAIR: a destination 200 against a source 500 means we faithfully…
replaces_existingbooleanNoWhether this migration landed on a site that already held a website. Stamped when the job is created and never recomputed: after the apply step the site is occupied…
safety_backup_statestring<not_needed, pending, taken, unsupported, failed>NoWhat became of the backup taken immediately before the apply step replaced the site. ⛔ Five values rather than a boolean: "there is no safety backup" is one rendered sentence…
safety_backup_idstringNoThe SiteBackup id, or "". ⛔ Still reported after the archive has been pruned by retention, so a rollback can say "that archive has expired" rather than looking like a…
rolled_back_atstringNoWhen the customer put the site back. Set once — restoring the pre-migration archive over a site that is already the pre-migration archive can only lose work done since.
rollbackMigrationRollbackNoWhether this migration can be put back, and — when it cannot — why not. ⛔⛔ reason travels with available, always. Six different facts render as the same absent button…
started_atstringNo
finished_atstringNo
created_atstringYes

Errors this endpoint can return

401 · 403 · 404 · 422 · 429 · 503