hosting

POST /v1/sites/{siteId}/wordpress/update

Update WordPress core on a site.

All hosting endpoints

Authentication

Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/wordpress/update \
  -H "Authorization: Bearer zdk_live_…"

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Asks the vendor to update WordPress itself. `202` and not `200`: the platform acknowledges and updates afterwards, so the state in the body is the install as it reads **now** and usually still shows the old version. Returning `200` with a version the site is not running is exactly the lie this status exists to avoid — the client re-reads `getSiteWordPress` rather than trusting the body as final. Refused `422` before the vendor is called when the package type does not carry `wp_updates`, or when WordPress is not installed. `404` for a site with no vendor hosting package. Requires `sites.view` and `sites.panel_access`.

Parameters

NameTypeRequiredWhat it is
siteId (path)UuidYesSite ID (UUIDv7).

Response

NameTypeRequiredWhat it is
installedbooleanYesWhether WordPress is on the package at all.
versionstringYesThe installed version, or `""` when the vendor did not state one.
is_latestbooleanYes⛔ **Tri-state.** Null means the vendor did not say, which is **not** "out of date": rendering an unknown as out of date invites a customer to run a core update on a live site fo…
is_multisitebooleanYesWhether the install is a WordPress network.
update_availablebooleanYesThe flag a screen should act on. Derived from the vendor's update object being non-empty rather than from a comparison between two version strings nobody parsed — ⛔ `{}` is how…
update_versionstringYesThe version waiting, or `""` when the install is current.
site_urlstringYesThe URL WordPress believes it is served from.
wizard_requiredbooleanYesWhether the install has never been through WordPress's own setup wizard — a half-installed site, not a broken one.
unavailable_reasonstring<, database, config, unreadable, not-routed>Yes⛔ **Read this before rendering `installed`.** Empty means `installed` is authoritative. Non-empty means it is **not**: the probe failed and we could not determine the answer, so…
capabilitiesobjectYesWhich of the eleven WordPress operations this package type permits, keyed by our **stable machine identifiers** — never a vendor string and never display text, so they are usabl…

Errors this endpoint can return

401 · 403 · 404 · 409 · 422 · 429 · 503