hosting
POST /v1/sites/{siteId}/backups/transfer-in
Move an externally hosted site onto Zinn® hosting from a backup we hold.
Autentikasi
Kirim kunci API sebagai token bearer. Kunci tersebut harus memiliki izin hosting.backup.manage; kunci tanpa izin tersebut akan ditolak dengan status 403, bukan 404.
Endpoint ini tidak memerlukan id organisasi. Kunci Anda telah mengidentifikasi organisasi tempatnya berafiliasi, dan respons akan dibatasi untuk organisasi tersebut.
Coba
Ganti apa pun di dalam tanda kurung sudut dengan nilai Anda sendiri, dan placeholder kunci dengan kunci dari dasbor Anda.
curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/backups/transfer-in \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "backup_id": <Uuid>, "source_site_id": <Uuid> }'Sudah masuk? Konsol API di dasbor Anda akan mengisi ID organisasi asli dan kunci Anda sendiri, serta menjalankan permintaan terhadap API langsung sehingga Anda dapat melihat respons aktualnya. Buka titik akhir ini di konsol API
Detail
⛔ **Destructive.** Restores a backup taken from a site hosted somewhere else onto `siteId`, overwriting that site's live database and files. This is what makes an external-site backup subscription a migration path: because we already hold the archive, moving onto our hosting is a restore rather than a migration. Both sites must belong to the same organisation, `source_site_id` must be a site we do **not** host, `siteId` must be an active site we do, and the backup must be a completed full backup. Anything else is 422. Requires `hosting.backup.manage` on the destination. ⭐ Nothing is sent to the origin host: it is not contacted, nothing there is deleted, and its backup connection keeps running. Disconnecting it is a separate, customer-initiated act, so the original stays a working fallback until the customer is happy with the copy.
Parameter
| Nama | Jenis | Wajib | Tentang apa ini |
|---|---|---|---|
siteId (path) | Uuid | Ya | Site ID (UUIDv7). |
Idempotency-Key (header) | string | Tidak | Client-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats. |
Isi permintaan
| Nama | Jenis | Wajib | Tentang apa ini |
|---|---|---|---|
backup_id | Uuid | Ya | The backup to land on this site. It must belong to `source_site_id` and must have completed successfully. |
source_site_id | Uuid | Ya | The externally hosted site the backup was taken from. Named explicitly rather than derived from `backup_id`, so a mistyped backup id cannot silently move a different site onto t… |
Tanggapan
| Nama | Jenis | Wajib | Tentang apa ini |
|---|---|---|---|
site_id | Uuid | Ya | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
backups | SiteBackup[] | Ya | — |
can_backup | boolean | Ya | False while a backup is in flight, when this site's hosting platform cannot take one at all, or when the site's on-demand allowance for the last 24 hours is spent. |
in_progress | boolean | Ya | — |
on_demand_backups | boolean | Ya | Always true. On-demand backups are included on every plan (owner ruling 2026-08-10); what bounds them is `on_demand_limit` per rolling 24 hours, not the plan. Retained for compa… |
unsupported_reason | string | Tidak | A stable machine identifier saying why this site's hosting platform cannot be backed up at all, or empty when it can. The client renders it as a localised sentence. Distinct fro… |
on_demand_limit | integer | Ya | On-demand backups allowed per rolling 24 hours, per site. |
on_demand_used | integer | Ya | On-demand backups taken in the last 24 hours. Failed attempts are not counted — the customer got nothing from them. |
on_demand_remaining | integer | Ya | How many the customer may still take right now. |
on_demand_next_at | string | Ya | When the next on-demand slot opens, as the oldest counted backup ages out of the rolling window. Null whenever `on_demand_remaining` is above zero. |
daily_backups | boolean | Ya | The plan's `daily_backups` entitlement — whether the nightly sweep selects this site. |
retention_days | integer | Ya | The plan's `backup_retention_days` entitlement, clamped to the platform maximum. |
offsite_enabled | boolean | Ya | Whether object storage is configured. False means every backup stays on the worker host it was taken on. |
immutable | boolean | Ya | Whether backup immutability is enforced **and proven recently**. True only when the platform's last reconciliation actually attempted to delete a canary object under the backup… |
immutable_days | integer | Ya | How many days a written backup cannot be altered or deleted by anyone — us, a compromised site, or a stolen token. 30 by owner ruling (2026-08-12), matching sold retention; `0`… |
immutability_verified_at | string | Ya | When a delete was last actually attempted against the protected prefix and refused. ⛔ Not when the configuration was last read, and not when the reconciler last ran: a run that… |
immutability_reason | string | Ya | A stable machine identifier saying why immutability is not currently provable — `never_checked`, `no_rule`, `delete_succeeded`, `credential_missing`, `canary_write_failed`, `ven… |
restore_drill_passed | boolean | Ya | Whether the platform's weekly restore drill last **passed**, and recently enough to still mean something. The drill restores a real stored backup onto a platform-owned site and… |
restore_drill_at | string | Ya | When the last drill finished, whatever its outcome. Null when no drill has ever completed. |
restore_drill_reason | string | Ya | A stable machine identifier saying why restores are not currently proven — `never_drilled`, `no_drill_site`, `no_recent_backup`, `canary_unavailable`, `restore_failed`, `fence_r… |
Kesalahan yang dapat dikembalikan oleh titik akhir ini
401 · 403 · 404 · 422 · 429 · 503