hosting
GET /v1/sites/{siteId}/wp-credentials
The WordPress admin login for a site.
Pagpapatotoo
Magpadala ng API key bilang isang bearer token. Kailangang taglayin ng key ang pahintulot na sites.view; ang key na wala nito ay tatanggihan gamit ang 403, hindi 404.
Ang endpoint na ito ay hindi nangangailangan ng id ng organisasyon. Natutukoy na ng iyong key ang organisasyong kinabibilangan nito, at nakatuon ang tugon dito.
Subukan ito
Palitan ang anuman sa loob ng mga panaklong na may anggulo ng iyong sariling mga halaga, at ang placeholder ng key na may key mula sa iyong dashboard.
curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/wp-credentials \
-H "Authorization: Bearer zdk_live_…"Nakalagda? Ang API console sa iyong dashboard ay awtomatikong naglalagay ng iyong tunay na ID ng organisasyon at sariling susi, at pinapatakbo ang kahilingan laban sa live na API upang makita mo ang aktwal na tugon. Buksan ang endpoint na ito sa console ng API
Mga Detalye
Requires `sites.view` and `sites.panel_access` — the key that already means "a customer reaching their own site". Every read is audit-logged: a password revealed by session alone is only safe if looking at it is attributable. Re-reads the site's own `wp_users` row before answering, so the screen a human is looking at is never stale. A site that cannot be reached is not an error: the stored record is returned unchanged and `checked_at` says when the platform last managed to look.
Mga Parameter
| Pangalan | Uri | Kailangan | Ano ito |
|---|---|---|---|
siteId (path) | Uuid | Oo | Site ID (UUIDv7). |
Tugon
| Pangalan | Uri | Kailangan | Ano ito |
|---|---|---|---|
site_id | Uuid | Oo | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
username | string | Oo | This site's own admin username, re-read from the site's `wp_users` row on every request. A customer who renames the account in phpMyAdmin, wp-admin or wp-cli sees the new name h… |
email | string | Oo | `wp_users.user_email` on the site itself — where a WordPress password reset would actually go. Empty until the platform has managed to read one. |
password | string | Oo | The current password, or empty when it cannot be shown — see `can_reveal`. It is derived from a platform key and the site's rotation epoch, never stored, so there is no per-site… |
can_reveal | boolean | Oo | False when the customer set their own password (nothing of ours to show) or the environment has no signing key. Rotating makes it true again. |
is_custom | boolean | Oo | The password in use was set by the customer through this app, so there is nothing of ours to show. Distinct from `changed_outside_app`. |
changed_outside_app | boolean | Oo | Proven: the password the platform holds no longer opens the site, so it was changed outside of the Zinn Digital® Hosting App — phpMyAdmin, wp-admin or wp-cli. WordPress stores `… |
checked_at | string | Oo | When the platform last managed to LOOK at the site's admin row. Null means never. |
verified_at | string | Oo | When the platform last PROVED these credentials are the live ones. Null means never. Deliberately separate from `checked_at`: "we have not been able to reach this site for a wee… |
login_url | string | Oo | Where to sign in. |
Mga error na maibabalik ng endpoint na ito
401 · 403 · 404 · 422 · 429