hosting
POST /v1/sites/{siteId}/wordpress/plugins
Install a plugin on a site's WordPress.
Authentification
Envoyez une clé API en tant que jeton du porteur. La clé doit posséder l'autorisation sites.view ; une clé qui ne l'a pas est refusée avec le code 403, et non 404.
Cet endpoint ne prend aucun identifiant d'organisation. Votre clé identifie déjà l'organisation à laquelle elle appartient, et la réponse y est limitée.
Essayer
Remplacez tout ce qui se trouve entre crochets par vos propres valeurs, et le espace réservé à la clé par une clé de votre tableau de bord.
curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/wordpress/plugins \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ }'Connecté ? La console d'API de votre tableau de bord saisit votre véritable ID d'organisation ainsi que votre propre clé, et exécute la requête sur l'API de production afin que vous puissiez voir la réponse réelle. Ouvrir ce point de terminaison dans la console API
Détails
Installs a plugin and, by default, activates it. Either from the wordpress.org directory by slug (what searchWordPressPluginDirectory returns), or from a zip the customer uploads. ⛔ Exactly one of slug and zip — never both. A request carrying both is refused 422 rather than resolved by precedence, because a caller that sent the wrong one would otherwise install something it did not ask for and be told it succeeded. Idempotent: a plugin already present is activated rather than reinstalled, and an upload of a plugin that is already there replaces it in place. Nothing is ever removed — use deleteSiteWordPressPlugin for that. ⚠️ An uploaded zip is the customer's own code running on their own site, and we do not review it. It is size-capped and rejected unless it is a valid archive containing a single top-level directory with a PHP plugin header, which is what WordPress itself requires — not a security review, and not presented as one. Refused 422 when the package type does not carry wp_plugins, or when WordPress is not installed. 404 for a site with no vendor hosting package. Requires sites.view and sites.panel_access.
Paramètres
| Nom | Type | Obligatoire | Qu'est-ce que c'est |
|---|---|---|---|
siteId (path) | Uuid | Oui | Site ID (UUIDv7). |
Corps de la requête
| Nom | Type | Obligatoire | Qu'est-ce que c'est |
|---|---|---|---|
slug | string | Non | A wordpress.org directory slug. Lower-case, digits and hyphens — the directory's own alphabet, enforced here so a path separator or a URL can never reach the box as a "slug". |
zip | string | Non | A base64-encoded plugin zip. Present instead of a multipart upload because every other write on this API is JSON and one exception would need its own auth, size and error handling. |
activate | boolean | Non | Activate after installing. false puts the files in place and leaves the plugin switched off — what a staged rollout of something risky wants. Deliberately not the default:… |
Réponse
| Nom | Type | Obligatoire | Qu'est-ce que c'est |
|---|---|---|---|
data | SiteWordPressPlugin[] | Oui | The installed plugins. |
stack_cache_installed | boolean | Oui | ⛔ Cannot be derived from data. this platform excludes its own server-side cache plugin from the listing, so a client deriving this flag from the rows would answer "not… |
Erreurs que cet point de terminaison peut renvoyer
401 · 403 · 404 · 409 · 413 · 422 · 429 · 503