hosting

POST /v1/site-events/ingest

Receive a site's report about its own changes (signed webhook).

Lahat ng hosting endpoint

Pagpapatotoo

Ang endpoint na ito ay pampubliko. Wala itong kinukuha na kredensyal at organisasyon — ito ang binabasa ng aming sariling marketing site at mga AI answer engine.

Ang endpoint na ito ay hindi nangangailangan ng id ng organisasyon. Natutukoy na ng iyong key ang organisasyong kinabibilangan nito, at nakatuon ang tugon dito.

Subukan ito

Palitan ang anuman sa loob ng mga panaklong na may anggulo ng iyong sariling mga halaga, at ang placeholder ng key na may key mula sa iyong dashboard.

curl -X POST https://api.zinndigital.com/v1/site-events/ingest \
  -H "Content-Type: application/json" \
  -d '{ "site": <string> }'

Nakalagda? Ang API console sa iyong dashboard ay awtomatikong naglalagay ng iyong tunay na ID ng organisasyon at sariling susi, at pinapatakbo ang kahilingan laban sa live na API upang makita mo ang aktwal na tugon. Buksan ang endpoint na ito sa console ng API

Mga Detalye

What a site's Zinn® plugin POSTs when something changed on it — a plugin activated or deactivated, core or a theme updated, a theme switched — plus the PHP version it is running. **Machine-to-machine; there is no principal.** WordPress is talking, not a person, so there is no session, no API key and no organisation header. Authentication is an **HMAC-SHA256** over `"<timestamp>\n<body>"` in `X-Zinn-Cache-Signature` (`sha256=<hex>`), with `X-Zinn-Cache-Timestamp` carrying the unix seconds — the same scheme the plugin already uses for its cache-purge mirror. **The secret is derived, never stored.** The engine resolves `site` to a hosted site by primary domain, derives that site's webhook secret from the platform master key, and compares in constant time. The organisation comes from the **resolved site**: a valid signature proves the sender holds that site's secret and proves nothing whatsoever about any other tenant. **Every refusal is uninformative on purpose.** An unknown hostname is a bare `404` and a bad signature a bare `401`, because a chattier answer would tell anyone who can guess a hostname which domains this platform hosts. **Idempotent.** WordPress fires some of these hooks more than once per change and the POST is fire-and-forget, so a duplicate delivery is accepted with `stored: 0` rather than refused — replay safety lives in the database.

Mga Parameter

PangalanUriKailanganAno ito
X-Zinn-Cache-Timestamp (header)stringOoUnix seconds. Signed as part of the material, which is what makes the replay window meaningful — a signature over the body alone could be replayed for ever with a fresh header.
X-Zinn-Cache-Signature (header)stringOo`sha256=<hex>`.

Katawan ng kahilingan

PangalanUriKailanganAno ito
sitestringOoThe site's own `home_url()`. **An untrusted claim** — it selects which site's derived secret the signature is checked against, and nothing more. The organisation is taken from t…
php_versionstringHindiThe PHP version the site is running. The engine raises a `php_version_changed` event when it differs from the last one reported — a change is detectable by **comparison** rather…
eventsobject[]HindiA batch. WordPress bulk-updating 40 plugins fires one `upgrader_process_complete` describing all of them, so a batch is the normal case, not the edge case. `deploy` is rejected…

Tugon

PangalanUriKailanganAno ito
acceptedbooleanOo
storedintegerOoHow many rows were **new**. A duplicate delivery is accepted with `0` rather than refused: WordPress fires some of these hooks more than once per change and the POST is fire-and…

Mga error na maibabalik ng endpoint na ito

401 · 404 · 422 · 503