compute
POST /v1/compute/servers/{serverId}/add-on
Buy an add-on for this machine.
Authentification
Envoyez une clé API en tant que jeton du porteur. La clé doit posséder l'autorisation sites.view ; une clé qui ne l'a pas est refusée avec le code 403, et non 404.
Cet endpoint ne prend aucun identifiant d'organisation. Votre clé identifie déjà l'organisation à laquelle elle appartient, et la réponse y est limitée.
Essayer
Remplacez tout ce qui se trouve entre crochets par vos propres valeurs, et le espace réservé à la clé par une clé de votre tableau de bord.
curl -X POST https://api.zinndigital.com/v1/compute/servers/{serverId}/add-on \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "code": <string> }'Connecté ? La console d'API de votre tableau de bord saisit votre véritable ID d'organisation ainsi que votre propre clé, et exécute la requête sur l'API de production afin que vous puissiez voir la réponse réelle. Ouvrir ce point de terminaison dans la console API
Détails
Requires `sites.view` and `billing.payment.manage`. ⛔⛔ **It was `billing.entitlement.manage` until 2026-08-17, which no customer role holds**, so the add-on designed to be turned on later could be turned on by nobody who owns a machine. The gate moved because the property behind it did: the add-on's price now joins the machine's subscription (priced into the cart line at order, moved from the next period when taken later), so this no longer spends Zinn®'s money and bills nobody. ⚖️ `billing.payment.manage` is the key the owner ruled for this class of control on 2026-08-17 (`docs/136` §2e) — `owner` and `billing`, and deliberately **not** `dev`: a developer creates sites, and does not commit the organisation to a recurring licence. ⛔ **A machine with no subscription is refused `422`** unless the caller also holds `billing.entitlement.manage`. Nothing would charge for the add-on there — that is the staff "on the house" path, and it stays deliberate rather than accidental. ⛔⛤ **AN ADD-ON WITH `applies_at` OF `running` OR `running_reboot` IS INSTALLED ON THE MACHINE AS IT STANDS, AND THE DATA ON IT IS NOT TOUCHED.** Until 2026-08-31 this endpoint refused every one of them with a sentence about rebuilding the disk. That sentence described a limitation of **cloud-init**, which runs only at create, and not of Plesk or CloudLinux — both of which ship installers whose documented purpose is converting a server that is already running. `docs/314` carries the vendor evidence. Such a request starts a Temporal workflow and answers `201` with `state` of `installing` (or `queued`, when a pooled licence is out of stock). The client polls `GET` for `install_step`. Plesk takes around fifteen minutes; CloudLinux restarts the machine once. ⛔⛔ **It requires `access` — one-time root credentials — and it is refused `422` without them.** This range hands SSH keys to the *customer* at build and the platform holds no key to any machine on it, so there is no standing credential to reach a running box with, and `docs/127` D4 chose deliberately never to create one. The credential is written to Vault under a path scoped to this one assignment, read only inside the install activities, kept out of the workflow history, and **deleted on every terminal outcome** — success, failure or refusal. ⛔ **A genuinely build-only add-on is still refused `422`** with a sentence naming the remedy. Nothing in the catalogue is build-only today; the refusal is kept for the day something is. ⛔ `503`, not `422`, when a pooled licence is out of stock **at order time**: the customer's next action is to try again, not to change their order. ⚖️ On a machine that is already running the same condition **queues** instead, by the owner's ruling of 2026-08-31 — the two paths differ because the moment differs, and at order time a refusal still reaches the customer before they have committed.
Paramètres
| Nom | Type | Obligatoire | Qu'est-ce que c'est |
|---|---|---|---|
serverId (path) | Uuid | Oui | The server's id, as `listComputeServers` reports it. **Ours** (UUIDv7), minted when the order row was written — never the provider's own identifier for the machine. |
Corps de la requête
| Nom | Type | Obligatoire | Qu'est-ce que c'est |
|---|---|---|---|
code | string | Oui | The add-on's catalogue code. `bare` records nothing. |
currency | string | Non | The currency to charge in. ⛔ Frozen onto the assignment at purchase, so a later admin repricing does not move an existing customer's bill. |
access | object | Non | One-time root access to the machine, required for any add-on whose `applies_at` is `running` or `running_reboot` and ignored for the rest. ⛔⛔ **Write-only. Never echoed in a res… |
Réponse
| Nom | Type | Obligatoire | Qu'est-ce que c'est |
|---|---|---|---|
data | object | Oui | — |
Erreurs que cet point de terminaison peut renvoyer
401 · 403 · 404 · 422 · 429 · 503