hosting

POST /v1/sites/{siteId}/backups/{backupId}/download

Mint a time-limited download URL for one of a site's backups.

모든 hosting 엔드포인트

인증

Bearer 토큰으로 API 키를 전송하세요. 키는 반드시 hosting.backup.export 권한을 가지고 있어야 하며, 권한이 없는 키는 404가 아닌 403으로 거부됩니다.

이 엔드포인트는 조직 ID를 받지 않습니다. 사용자의 키가 이미 속한 조직을 식별하며, 응답은 해당 조직으로 한정됩니다.

무료 체험하기

대괄호 안에 있는 모든 내용을 사용자 지정 값으로 바꾸고, 키 플레이스홀더는 대시보드의 키로 바꾸세요.

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/backups/{backupId}/download \
  -H "Authorization: Bearer zdk_live_…"

로그인하셨나요? 대시보드의 API 콘솔이 실제 조직 ID와 본인의 키를 자동으로 채우고 라이브 API를 대상으로 요청을 실행하므로 실제 응답을 확인할 수 있습니다. API 콘솔에서 이 엔드포인트를 여세요

상세 정보

Returns a presigned URL the customer's browser fetches **directly from object storage**; the archive never passes through the control plane. A site archive is measured in gigabytes, so proxying it would make the customer's site size our memory ceiling and hold a request thread for the length of the transfer. ⛔ **`POST`, despite reading nothing.** The response body is a bearer credential for the whole site — database included — so a `GET` would invite it into browser history, proxy logs and shared caches, and the audit row this writes would be created by every prefetch. The grant expires; take a new one rather than storing it. A backup that never produced a stored archive is `422` (`backup_not_downloadable`) rather than a signature over a key that is not there, which object storage would reject seconds later as an opaque `404`. Requires `hosting.backup.export` — or `hosting.backup.manage`, which every holder of the old gate still has — and never `sites.view`: reading a tenant's database out is never a viewer's. A per-site *editor* holds `hosting.backup.export`, which is how `zinnector pull` brings the files down for local development without being able to restore.

매개변수

이름유형필수설명
siteId (path)UuidSite ID (UUIDv7).
backupId (path)UuidThe backup's id (UUIDv7), as `getSiteBackups` reports it. **Ours**, minted when the row was written — never the storage key, which is an internal object path and is deliberately…

응답

이름유형필수설명
urlstringThe presigned object-storage URL to fetch the archive from. Hand it straight to the customer's browser and let it expire; take a fresh grant rather than caching this one.
expires_atstringWhen the signature stops working. A download that has already started is unaffected; a new one after this moment is refused by storage.
size_bytesintegerThe archive's size, as object storage reported it when the backup was stored — so a client can warn before a multi-gigabyte download.
etagstringThe stored object's entity tag, for a client that wants to verify the bytes it received are the bytes we hold. Empty when the backend did not report one.

이 엔드포인트가 반환할 수 있는 오류

401 · 403 · 404 · 422 · 429