hosting

GET /v1/sites/{siteId}/security

A site's malware state and live findings.

모든 hosting 엔드포인트

모든 개발자 문서

인증

Bearer 토큰으로 API 키를 전송하세요. 이 엔드포인트는 명세에 특정 권한을 명시하지 않으므로, 가정하기보다는 키에 필요한 최소한의 권한을 부여하고 응답을 확인하세요.

이 엔드포인트는 조직 ID를 받지 않습니다. 사용자의 키가 이미 속한 조직을 식별하며, 응답은 해당 조직으로 한정됩니다.

무료 체험하기

대괄호 안에 있는 모든 내용을 사용자 지정 값으로 바꾸고, 키 플레이스홀더는 대시보드의 키로 바꾸세요.

curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/security \
  -H "Authorization: Bearer zdk_live_…"

로그인하셨나요? 대시보드의 API 콘솔이 실제 조직 ID와 본인의 키를 자동으로 채우고 라이브 API를 대상으로 요청을 실행하므로 실제 응답을 확인할 수 있습니다. API 콘솔에서 이 엔드포인트를 여세요

상세 정보

The per-site Tools tab's Malware and security card — the scan verdict, when it last completed, and every live finding. RLS-scoped to a site the caller can view (sites.view); an out-of-scope or unknown id is a 404, exactly like getSite. This reads a stored projection and never calls the scanner. The card mounts with the Tools tab for every site and polls while a scan is in flight, so a vendor round-trip here would be an un-cached external call in a hot path (CLAUDE.md §2.16). A scan is a durable Temporal workflow (§2.9) that writes the row this returns. status: clean with last_scan_at: null means not scanned yet — one nullable timestamp rather than a fourth status. "We could not look" is deliberately distinguishable from "we looked and it is fine", because neither a failed nor an un-attempted scan stamps last_scan_at. ⛔ "We tried and could not" and "we have never tried" are different facts and arrive in different fields. last_scan_error carries the first (an attempt ran and broke — an unreachable host, a vendor error, a scan abandoned after timing out); unavailable_reason carries the second as a machine identifier (nothing is attached to scan this site, or its platform cannot be scanned at all). They are never both non-empty. Render the first as a warning and the second as a neutral notice: showing "we couldn't scan this site" over a scan that was never attempted tells a customer their site might be infected when nothing of the sort is known. detections[].path is always relative to the document root — an absolute path would disclose the host account handle and the fleet's filesystem layout (§2.4).

매개변수

이름유형필수설명
siteId (path)UuidSite ID (UUIDv7).

응답

이름유형필수설명
statusMalwareStatusA site's scan verdict. There is deliberately no unscanned member: a site nothing has looked at yet is clean with last_scan_at: null, which is one nullable timestamp…
last_scan_atobjectWhen a scan last completed. null = never scanned. A scan that failed does not stamp this, so a stale success can never be mistaken for a fresh one.
detectionsMalwareDetection[]
recent_resolutionsResolvedMalwareDetection[]Findings that were present and are not any more, most recently cleared first — the record of the protection having worked, which an all-clear alone cannot show. resolved_at
can_rescanbooleanWhether rescanSite will accept a request for this site: false while a scan is already running, false for a site that is not running at all (there is no document root to scan),…
last_scan_error_codestring<, scan_conflict, scanner_unreachable, scanner_missing, scan_failed>Why a scan that ran could not finish; empty when none has failed. Non-empty means an attempt was made against this site and broke — an unreachable host, a vendor error, a scan…
unavailable_reasonstringWhy no scan was attempted; empty when one was. A stable machine identifier for the client to localise, never a sentence and never a vendor name. vendor_unsupported — the…
runtimeSiteRuntimeSecurityWhat our runtime sensor saw happen on this site, and whether anything was watching it at all. The malware fields above are a verdict on files at rest; this is the other half —…

이 엔드포인트가 반환할 수 있는 오류

401 · 403 · 404 · 429