plugin-support

POST /v1/plugin-support/connections

Connect a WordPress site to Zinn® plugin support.

All plugin-support endpoints

All developer docs →

Authentication

This endpoint is public. It takes no credential and no organisation — it is what our own marketing site and AI answer engines read.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/plugin-support/connections \
  -H "Content-Type: application/json" \
  -d '{ "email": <string>, "product": <string>, "site_url": <string>, "consent": <boolean> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Called server-side by a Zinn® WordPress plugin (Tranzly, Page Builder Sandwich) after the site owner agreed on the plugin's consent screen (WordPress.org Guideline 7). Creates — or reuses — a support contact for the e-mail address and returns a scoped, revocable connection token once. ADR 0035; contract docs/plugins-overhaul/x1-x7-contract.md §2.1. ⛔ A contact is never an organization. Nothing here creates an org, a user or a membership; a contact whose address matches a platform user is linked for staff to see and nothing more (owner, D33). ⛔ The engine stores only sha256(token). The token's scopes are support.tickets and support.diagnostics and nothing else — no scope administers or logs into the site. Anonymous: no session, CSRF-exempt. Budgets: 10/hour per IP (charged before the body is parsed) and 5/hour per e-mail, 429 with Retry-After. A filled website honeypot answers 202 and stores nothing.

Request body

NameTypeRequiredWhat it is
emailstringYes—
namestringNo—
productstringYes—
site_urlstringYes—
site_namestringNo—
plugin_versionstringNo—
wp_versionstringNo—
php_versionstringNo—
localestringNoThe WordPress locale (fr_FR); mail to the contact is rendered in it.
consentbooleanYesMust be literally true — the site owner agreed on the consent screen (WordPress.org Guideline 7). Anything else is 422.
websitestringNoHoneypot. Must be empty.

Response

NameTypeRequiredWhat it is
connection_idstringYes—
tokenstringYeszps_ + 43 URL-safe characters. Returned ONCE; the engine keeps only its SHA-256. The plugin stores it sealed (libsodium secretbox, ADR 0034's key scheme).
scopesstring<support.tickets, support.diagnostics>[]Yes—
contactobjectYes—

Errors this endpoint can return

422 · 429