public

POST /v1/wp/site-panel/{siteId}

What the must-use plugin renders on a hosted site's WordPress dashboard.

All public endpoints

All developer docs →

Authentication

Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/wp/site-panel/{siteId} \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{  }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Called by the Zinn® Platform must-use plugin on a site we host, not by a person. It returns that site's plan, its allowances and current usage, and the cards, plan links and admin-bar items the platform is currently showing — so changing what every hosted site displays is an edit on one admin screen rather than a plugin release. Authenticated by the site's own secret, never by a bearer token: the caller is a WordPress site, not a principal. The request carries X-Zinn-Cache-Signature: sha256=HMAC(timestamp + "\n" + body) keyed with that site's ZINN_UPDATE_SECRET, and the response is signed the same way in X-Zinn-Signature so a site can prove the answer came from us before rendering any of it. ⛔ Every unknown quantity is null, never 0. A resource this kind of hosting cannot measure — a database on a static host, for instance — is permanently null, and the plugin renders that as "not measured yet". A 0 would tell the customer their database is empty. ⛔ Anything unauthenticated, stale, unknown or deleted is a 404, never a 401, so this cannot become an oracle for which site ids exist.

Parameters

NameTypeRequiredWhat it is
siteId (path)UuidYesSite ID (UUIDv7).

Request body

NameTypeRequiredWhat it is
localestringNoThe WordPress locale of the administrator viewing the dashboard (de_DE, pt_BR). Resolved to one of the platform's languages; an unknown one gets English rather than an empty…
versionstringNoThe plugin version this site is running. ⭐ This is what makes the rollout figure real — it is reported by the site rather than inferred from what we pushed.

Response

NameTypeRequiredWhat it is
planobjectYesThe governing subscription's name and renewal date. ⛔ Empty when nothing governs this site — a staff-assigned or trial site — rather than a fabricated "Free" plan, which would…
allowancesSitePanelAllowance[]Yes—
plan_linksSitePanelLink[]Yes—
cardsSitePanelCard[]Yes—
admin_barSitePanelLink[]Yes—
ttlintegerYesHow long the plugin may serve this answer before asking again, in seconds. Sent rather than hard-coded in the plugin, so the refresh cadence can change on the estate without a…

Errors this endpoint can return

404 · 429