links
POST /v1/site-links/ingest
Receive one batch of a site's outbound-link scan (signed webhook).
Authentification
Cet point de terminaison est public. Il ne nécessite aucun identifiant ni aucune organisation : c'est ce que notre propre site marketing et nos moteurs de réponse IA lisent.
Cet endpoint ne prend aucun identifiant d'organisation. Votre clé identifie déjà l'organisation à laquelle elle appartient, et la réponse y est limitée.
Essayer
Remplacez tout ce qui se trouve entre crochets par vos propres valeurs, et le espace réservé à la clé par une clé de votre tableau de bord.
curl -X POST https://api.zinndigital.com/v1/site-links/ingest \
-H "Content-Type: application/json" \
-d '{ "site": <string>, "scan_id": <string> }'Connecté ? La console d'API de votre tableau de bord saisit votre véritable ID d'organisation ainsi que votre propre clé, et exécute la requête sur l'API de production afin que vous puissiez voir la réponse réelle. Ouvrir ce point de terminaison dans la console API
Détails
What a site's Zinn® plugin POSTs when its scheduled link scan runs: the posts it looked at, and for each one every outbound `<a>` tag it found, with how many times that tag appears in that post. **Machine-to-machine; there is no principal.** Authentication is the **same HMAC scheme** `ingestSiteEvents` uses — SHA-256 over `"<timestamp>\n<body>"` in `X-Zinn-Cache-Signature`, with `X-Zinn-Cache-Timestamp` carrying the unix seconds, against a secret **derived** per site from the platform master key. ⛔ Deliberately not a second scheme: one secret, one derivation, one place for the two ends to agree. The organisation comes from the **resolved site** and never from the body. **A scan is a SNAPSHOT, delivered in batches.** One pass over a site carries one `scan_id` across as many requests as it takes; the request carrying `complete: true` triggers reconciliation, which deletes every post and placement for that site not stamped with that pass. ⛔ That is what makes a link the customer **removed** disappear from the report — an append-only index rots into a permanent overcount and looks authoritative while it does. ⛔ **An abandoned pass deletes nothing.** No completing batch, no sweep: the report goes stale rather than wrong-by-deletion. ⛔ **A batch from a superseded pass is ignored whole** and answers `ignored: true`. The plugin's POST is fire-and-forget with a two-second timeout, so a batch landing after the next cron tick has begun is expected; mixing it in would let a finished pass sweep away the live one's rows. **Every refusal is uninformative on purpose** — an unknown hostname is a bare `404` and a bad signature a bare `401`, because a chattier answer would tell anyone who can guess a hostname which domains this platform hosts.
Paramètres
| Nom | Type | Obligatoire | Qu'est-ce que c'est |
|---|---|---|---|
X-Zinn-Cache-Timestamp (header) | string | Oui | Unix seconds. Signed as part of the material, which is what bounds a replay. |
X-Zinn-Cache-Signature (header) | string | Oui | `sha256=<hex>`. |
Corps de la requête
| Nom | Type | Obligatoire | Qu'est-ce que c'est |
|---|---|---|---|
site | string | Oui | The site's own `home_url()`. **An untrusted claim** — it selects which site's derived secret the signature is checked against, and nothing more. |
scan_id | string | Oui | Identifies the **pass**, not the request. Minted by the plugin, because one pass spans many requests and the engine cannot mint it. Opaque: nothing is inferred from its value, a… |
complete | boolean | Non | ⛔ Only a literal `true` ends the pass. A missing key, a `null` or the string `"false"` all mean "not complete", because reading one as complete would sweep away every post the s… |
posts_sent | integer | Non | Posts this **pass** has sent so far, cumulative across batches, as counted by the site. ⛔⛔ Load-bearing on the completing batch: the POST is non-blocking, so a site never learns… |
posts | object[] | Non | — |
Réponse
| Nom | Type | Obligatoire | Qu'est-ce que c'est |
|---|---|---|---|
accepted | boolean | Oui | — |
ignored | boolean | Oui | The batch belonged to a **superseded** pass and was dropped whole. Expected occasionally: the plugin's POST is fire-and-forget with a two-second timeout. |
posts | integer | Oui | — |
links | integer | Oui | — |
truncated | boolean | Oui | A post reported more links than the per-post ceiling and the tail was dropped. Surfaced rather than swallowed — a report that silently under-counts is worse than one that says i… |
reconciled | boolean | Oui | This batch completed the pass, so the snapshot sweep ran. |
removed | integer | Oui | Rows the sweep deleted. ⭐ The only externally visible proof the snapshot reconciliation works: a site whose links change while this stays `0` on every pass is the append-only ro… |
refused | string | Non | Why a **completing** batch was not swept, when it was not — a lost batch, or one whose post list was truncated. ⛔ Reported rather than swallowed: a pass that keeps completing wi… |
Erreurs que cet point de terminaison peut renvoyer
401 · 404 · 422 · 503