plugin-support

POST /v1/plugin-support/tickets

Open a plugin support ticket — from a plugin or a product website's form.

All plugin-support endpoints

All developer docs →

Authentication

Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/plugin-support/tickets \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "product": <string>, "subject": <string>, "message": <string> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

One intake for every plugin support request (X1, ADR 0035). Either a connection token (a connected plugin) or no credential and an email (the product websites' forms, zinndigital.com/support/plugins, and a plugin that has not connected). The ticket lands in the one Zinn-owned "Zinn® plugin support" organization, tagged with its product; staff see it in the ordinary ticket queue. diagnostics is stored ONLY when consent_diagnostics is true. Each credentials[].secret is written to Vault — never to the database, never logged, never returned by a list or read — and purged 30 days after the ticket closes (owner, D32). Staff read one with revealPluginSupportCredential, which is audited. licence is a claim. Priority is high only when the engine has VERIFIED the install and its licence with Freemius and the plan is Business or Agency (or a legacy plan covering more than one site, owner D34). An unverifiable claim files at normal and the staff screen says why. The contact gets the standard confirmation e-mail in their own language; staff replies reach them by e-mail with the reply in the message, and a reply from their address files onto the ticket as theirs. CORS is answered on this path for exactly https://tranzly.io, https://www.tranzly.io, https://pagebuildersandwich.com, https://www.pagebuildersandwich.com and https://zinndigital.com. Budgets: 10/hour per IP, 5/hour per e-mail, 30/day per connection (429 with Retry-After). A filled website honeypot answers 202 and stores nothing.

Request body

NameTypeRequiredWhat it is
emailstringNoRequired when no connection token is sent.
namestringNo—
productstringYes—
kindstring<help, bug, feedback, feature_request>No—
subjectstringYes—
messagestringYes—
localestringNo—
consent_diagnosticsbooleanNo—
diagnosticsPluginSupportDiagnosticsNoSite facts the plugin collected. Stored only when consent_diagnostics is true.
credentialsPluginSupportCredentialInput[]No—
licenceobjectNoA CLAIM, verified with Freemius before it changes priority.
websitestringNoHoneypot. Must be empty.

Response

NameTypeRequiredWhat it is
referencestringYes—
prioritystring<normal, high>Yes—

Errors this endpoint can return

401 · 422 · 429 · 503