hosting

GET /v1/sites/{siteId}/security

A site's malware state and live findings.

Lahat ng hosting endpoint

Pagpapatotoo

Magpadala ng API key bilang bearer token. Ang endpoint na ito ay hindi naglatag ng tiyak na pahintulot sa pagtutukoy, kaya ibigay sa iyong key ang pinakamababang kailangan nito at suriin ang tugon sa halip na umasa.

Ang endpoint na ito ay hindi nangangailangan ng id ng organisasyon. Natutukoy na ng iyong key ang organisasyong kinabibilangan nito, at nakatuon ang tugon dito.

Subukan ito

Palitan ang anuman sa loob ng mga panaklong na may anggulo ng iyong sariling mga halaga, at ang placeholder ng key na may key mula sa iyong dashboard.

curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/security \
  -H "Authorization: Bearer zdk_live_…"

Nakalagda? Ang API console sa iyong dashboard ay awtomatikong naglalagay ng iyong tunay na ID ng organisasyon at sariling susi, at pinapatakbo ang kahilingan laban sa live na API upang makita mo ang aktwal na tugon. Buksan ang endpoint na ito sa console ng API

Mga Detalye

The per-site Tools tab's *Malware and security* card — the scan verdict, when it last completed, and every live finding. RLS-scoped to a site the caller can view (`sites.view`); an out-of-scope or unknown id is a `404`, exactly like `getSite`. **This reads a stored projection and never calls the scanner.** The card mounts with the Tools tab for every site and polls while a scan is in flight, so a vendor round-trip here would be an un-cached external call in a hot path (CLAUDE.md §2.16). A scan is a durable Temporal workflow (§2.9) that writes the row this returns. `status: clean` with `last_scan_at: null` means **not scanned yet** — one nullable timestamp rather than a fourth status. "We could not look" is deliberately distinguishable from "we looked and it is fine", because neither a failed nor an un-attempted scan stamps `last_scan_at`. ⛔ **"We tried and could not" and "we have never tried" are different facts and arrive in different fields.** `last_scan_error` carries the first (an attempt ran and broke — an unreachable host, a vendor error, a scan abandoned after timing out); `unavailable_reason` carries the second as a machine identifier (nothing is attached to scan this site, or its platform cannot be scanned at all). They are never both non-empty. Render the first as a warning and the second as a neutral notice: showing *"we couldn't scan this site"* over a scan that was never attempted tells a customer their site might be infected when nothing of the sort is known. `detections[].path` is always **relative to the document root** — an absolute path would disclose the host account handle and the fleet's filesystem layout (§2.4).

Mga Parameter

PangalanUriKailanganAno ito
siteId (path)UuidOoSite ID (UUIDv7).

Tugon

PangalanUriKailanganAno ito
statusMalwareStatusOoA site's scan verdict. There is deliberately **no** `unscanned` member: a site nothing has looked at yet is `clean` with `last_scan_at: null`, which is one nullable timestamp ra…
last_scan_atobjectOoWhen a scan last **completed**. `null` = never scanned. A scan that failed does not stamp this, so a stale success can never be mistaken for a fresh one.
detectionsMalwareDetection[]Oo
recent_resolutionsResolvedMalwareDetection[]OoFindings that were present and are not any more, most recently cleared first — the record of the protection having worked, which an all-clear alone cannot show. `resolved_at` al…
can_rescanbooleanOoWhether `rescanSite` will accept a request for this site: false while a scan is already running, false for a site that is not running at all (there is no document root to scan),…
last_scan_error_codestring<, scan_conflict, scanner_unreachable, scanner_missing, scan_failed>OoWhy a scan that **ran** could not finish; empty when none has failed. Non-empty means an attempt was made against this site and broke — an unreachable host, a vendor error, a sc…
unavailable_reasonstringOoWhy **no scan was attempted**; empty when one was. A stable machine identifier for the client to localise, never a sentence and never a vendor name. `vendor_unsupported` — the h…
runtimeSiteRuntimeSecurityOoWhat our runtime sensor saw **happen** on this site, and whether anything was watching it at all. The malware fields above are a verdict on files at rest; this is the other half…

Mga error na maibabalik ng endpoint na ito

401 · 403 · 404 · 429