links
POST /v1/content/external-sites
Connect a WordPress site we do not host, with an application password.
Authentication
Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.
Where your organisation id goes
This endpoint takes org_id as a query parameter. Leave it out and the call covers your whole tenancy subtree; send it to narrow the call to one organisation.
Your organisation id is on the API keys screen in your dashboard, beside the key itself. It is the same id in every call you make.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X POST https://api.zinndigital.com/v1/content/external-sites \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "url": <string>, "username": <string>, "application_password": <string> }'Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
Gated on `links.edit`. The credential is **verified against the site before anything is stored**: if WordPress refuses it, nothing is created and the error says what to fix. The password goes to Vault; no secret is stored on the row. Generate the application password in that site's WordPress admin under Users → your user → Application Passwords. The user needs to be able to publish posts.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
org_id (query) | string | No | — |
Request body
| Name | Type | Required | What it is |
|---|---|---|---|
url | string | Yes | The site's address, e.g. `https://example.com` or `https://example.com/blog`. |
username | string | Yes | — |
application_password | string | Yes | The application password WordPress generated. Spaces are ignored, so it may be pasted exactly as displayed. |
name | string | No | — |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
site_id | string | Yes | — |
primary_domain | string | Yes | — |
name | string | Yes | — |
is_external | boolean | Yes | Always true here. The same site appears in `/v1/sites` badged External. |
base_url | string | Yes | The address we publish to, including any path (e.g. `https://example.com/blog`). |
reachable | boolean | No | What the last check found. **`null` means we have not checked**, which is not the same as "it does not work" — an unchecked site is never rendered as broken. |
checked_at | string | No | — |
detail | string | No | What the site said last time, verbatim. Shown on the site's own screen. |
detected_identity | string | No | — |
Errors this endpoint can return
401 · 403 · 422