plugin-support
POST /v1/plugin-support/connections
Connect a WordPress site to Zinn® plugin support.
Authentication
This endpoint is public. It takes no credential and no organisation — it is what our own marketing site and AI answer engines read.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X POST https://api.zinndigital.com/v1/plugin-support/connections \
-H "Content-Type: application/json" \
-d '{ "email": <string>, "product": <string>, "site_url": <string>, "consent": <boolean> }'Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
Called server-side by a Zinn® WordPress plugin (Tranzly, Page Builder Sandwich) after the site owner agreed on the plugin's consent screen (WordPress.org Guideline 7). Creates — or reuses — a support contact for the e-mail address and returns a scoped, revocable connection token once. ADR 0035; contract docs/plugins-overhaul/x1-x7-contract.md §2.1. ⛔ A contact is never an organization. Nothing here creates an org, a user or a membership; a contact whose address matches a platform user is linked for staff to see and nothing more (owner, D33). ⛔ The engine stores only sha256(token). The token's scopes are support.tickets and support.diagnostics and nothing else — no scope administers or logs into the site. Anonymous: no session, CSRF-exempt. Budgets: 10/hour per IP (charged before the body is parsed) and 5/hour per e-mail, 429 with Retry-After. A filled website honeypot answers 202 and stores nothing.
Request body
| Name | Type | Required | What it is |
|---|---|---|---|
email | string | Yes | — |
name | string | No | — |
product | string | Yes | — |
site_url | string | Yes | — |
site_name | string | No | — |
plugin_version | string | No | — |
wp_version | string | No | — |
php_version | string | No | — |
locale | string | No | The WordPress locale (fr_FR); mail to the contact is rendered in it. |
consent | boolean | Yes | Must be literally true — the site owner agreed on the consent screen (WordPress.org Guideline 7). Anything else is 422. |
website | string | No | Honeypot. Must be empty. |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
connection_id | string | Yes | — |
token | string | Yes | zps_ + 43 URL-safe characters. Returned ONCE; the engine keeps only its SHA-256. The plugin stores it sealed (libsodium secretbox, ADR 0034's key scheme). |
scopes | string<support.tickets, support.diagnostics>[] | Yes | — |
contact | object | Yes | — |
Errors this endpoint can return
422 · 429