links

POST /v1/content/external-sites

Connect a WordPress site we do not host, with an application password.

All links endpoints

Authentication

Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.

Where your organisation id goes

This endpoint takes org_id as a query parameter. Leave it out and the call covers your whole tenancy subtree; send it to narrow the call to one organisation.

Your organisation id is on the API keys screen in your dashboard, beside the key itself. It is the same id in every call you make.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/content/external-sites \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "url": <string>, "username": <string>, "application_password": <string> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Gated on `links.edit`. The credential is **verified against the site before anything is stored**: if WordPress refuses it, nothing is created and the error says what to fix. The password goes to Vault; no secret is stored on the row. Generate the application password in that site's WordPress admin under Users → your user → Application Passwords. The user needs to be able to publish posts.

Parameters

NameTypeRequiredWhat it is
org_id (query)stringNo

Request body

NameTypeRequiredWhat it is
urlstringYesThe site's address, e.g. `https://example.com` or `https://example.com/blog`.
usernamestringYes
application_passwordstringYesThe application password WordPress generated. Spaces are ignored, so it may be pasted exactly as displayed.
namestringNo

Response

NameTypeRequiredWhat it is
site_idstringYes
primary_domainstringYes
namestringYes
is_externalbooleanYesAlways true here. The same site appears in `/v1/sites` badged External.
base_urlstringYesThe address we publish to, including any path (e.g. `https://example.com/blog`).
reachablebooleanNoWhat the last check found. **`null` means we have not checked**, which is not the same as "it does not work" — an unchecked site is never rendered as broken.
checked_atstringNo
detailstringNoWhat the site said last time, verbatim. Shown on the site's own screen.
detected_identitystringNo

Errors this endpoint can return

401 · 403 · 422