hosting

POST /v1/sites/{siteId}/backups/restore

Restore a site from one of its backups.

Semua titik akhir hosting

Autentikasi

Kirim kunci API sebagai token bearer. Kunci tersebut harus memiliki izin hosting.backup.manage; kunci tanpa izin tersebut akan ditolak dengan status 403, bukan 404.

Endpoint ini tidak memerlukan id organisasi. Kunci Anda telah mengidentifikasi organisasi tempatnya berafiliasi, dan respons akan dibatasi untuk organisasi tersebut.

Coba

Ganti apa pun di dalam tanda kurung sudut dengan nilai Anda sendiri, dan placeholder kunci dengan kunci dari dasbor Anda.

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/backups/restore \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "backup_id": <Uuid> }'

Sudah masuk? Konsol API di dasbor Anda akan mengisi ID organisasi asli dan kunci Anda sendiri, serta menjalankan permintaan terhadap API langsung sehingga Anda dapat melihat respons aktualnya. Buka titik akhir ini di konsol API

Detail

⛔ **Destructive.** This overwrites the site's live database and files with the contents of the named backup. Its own path rather than a verb on the collection, so it can never be reached by varying the body of the endpoint that *takes* backups. The backup must belong to this site and must have completed successfully; anything else is 422. Requires `hosting.backup.manage`.

Parameter

NamaJenisWajibTentang apa ini
siteId (path)UuidYaSite ID (UUIDv7).
Idempotency-Key (header)stringTidakClient-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats.

Isi permintaan

NamaJenisWajibTentang apa ini
backup_idUuidYaThe backup to restore. Always named explicitly — there is no "restore the latest", because a destructive operation must not depend on which row happens to sort first.

Tanggapan

NamaJenisWajibTentang apa ini
site_idUuidYaUUIDv7 identifier — sortable by creation time (docs/02 §8).
backupsSiteBackup[]Ya
can_backupbooleanYaFalse while a backup is in flight, when this site's hosting platform cannot take one at all, or when the site's on-demand allowance for the last 24 hours is spent.
in_progressbooleanYa
on_demand_backupsbooleanYaAlways true. On-demand backups are included on every plan (owner ruling 2026-08-10); what bounds them is `on_demand_limit` per rolling 24 hours, not the plan. Retained for compa…
unsupported_reasonstringTidakA stable machine identifier saying why this site's hosting platform cannot be backed up at all, or empty when it can. The client renders it as a localised sentence. Distinct fro…
on_demand_limitintegerYaOn-demand backups allowed per rolling 24 hours, per site.
on_demand_usedintegerYaOn-demand backups taken in the last 24 hours. Failed attempts are not counted — the customer got nothing from them.
on_demand_remainingintegerYaHow many the customer may still take right now.
on_demand_next_atstringYaWhen the next on-demand slot opens, as the oldest counted backup ages out of the rolling window. Null whenever `on_demand_remaining` is above zero.
daily_backupsbooleanYaThe plan's `daily_backups` entitlement — whether the nightly sweep selects this site.
retention_daysintegerYaThe plan's `backup_retention_days` entitlement, clamped to the platform maximum.
offsite_enabledbooleanYaWhether object storage is configured. False means every backup stays on the worker host it was taken on.
immutablebooleanYaWhether backup immutability is enforced **and proven recently**. True only when the platform's last reconciliation actually attempted to delete a canary object under the backup…
immutable_daysintegerYaHow many days a written backup cannot be altered or deleted by anyone — us, a compromised site, or a stolen token. 30 by owner ruling (2026-08-12), matching sold retention; `0`…
immutability_verified_atstringYaWhen a delete was last actually attempted against the protected prefix and refused. ⛔ Not when the configuration was last read, and not when the reconciler last ran: a run that…
immutability_reasonstringYaA stable machine identifier saying why immutability is not currently provable — `never_checked`, `no_rule`, `delete_succeeded`, `credential_missing`, `canary_write_failed`, `ven…
restore_drill_passedbooleanYaWhether the platform's weekly restore drill last **passed**, and recently enough to still mean something. The drill restores a real stored backup onto a platform-owned site and…
restore_drill_atstringYaWhen the last drill finished, whatever its outcome. Null when no drill has ever completed.
restore_drill_reasonstringYaA stable machine identifier saying why restores are not currently proven — `never_drilled`, `no_drill_site`, `no_recent_backup`, `canary_unavailable`, `restore_failed`, `fence_r…

Kesalahan yang dapat dikembalikan oleh titik akhir ini

401 · 403 · 404 · 422 · 429 · 503