hosting
POST /v1/sites/{siteId}/backups/transfer-in
Move an externally hosted site onto Zinn® hosting from a backup we hold.
Pengesahan
Hantar kunci API sebagai token pembawa. Kunci tersebut mesti membawa kebenaran hosting.backup.manage; kunci yang tidak mempunyainya akan ditolak dengan 403, bukan 404.
Titik akhir ini tidak memerlukan id organisasi. Kunci anda telah mengenal pasti organisasi kepunyaannya, dan respons dis skopkan kepadanya.
Cuba
Gantikan apa sahaja di dalam kurungan sudut dengan nilai anda sendiri, dan pemegang tempat kunci dengan kunci dari papan pemuka anda.
curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/backups/transfer-in \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "backup_id": <Uuid>, "source_site_id": <Uuid> }'Sudah log masuk? Konsol API dalam papan pemuka anda mengisi id organisasi sebenar dan kunci anda sendiri, serta menjalankan permintaan terhadap API langsung supaya anda boleh melihat respons sebenar. Buka penamat ini dalam konsol API
Butiran
⛔ **Destructive.** Restores a backup taken from a site hosted somewhere else onto `siteId`, overwriting that site's live database and files. This is what makes an external-site backup subscription a migration path: because we already hold the archive, moving onto our hosting is a restore rather than a migration. Both sites must belong to the same organisation, `source_site_id` must be a site we do **not** host, `siteId` must be an active site we do, and the backup must be a completed full backup. Anything else is 422. Requires `hosting.backup.manage` on the destination. ⭐ Nothing is sent to the origin host: it is not contacted, nothing there is deleted, and its backup connection keeps running. Disconnecting it is a separate, customer-initiated act, so the original stays a working fallback until the customer is happy with the copy.
Parameter
| Nama | Jenis | Diperlukan | Apakah ia |
|---|---|---|---|
siteId (path) | Uuid | Ya | Site ID (UUIDv7). |
Idempotency-Key (header) | string | Tidak | Client-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats. |
Badan permintaan
| Nama | Jenis | Diperlukan | Apakah ia |
|---|---|---|---|
backup_id | Uuid | Ya | The backup to land on this site. It must belong to `source_site_id` and must have completed successfully. |
source_site_id | Uuid | Ya | The externally hosted site the backup was taken from. Named explicitly rather than derived from `backup_id`, so a mistyped backup id cannot silently move a different site onto t… |
Respons
| Nama | Jenis | Diperlukan | Apakah ia |
|---|---|---|---|
site_id | Uuid | Ya | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
backups | SiteBackup[] | Ya | — |
can_backup | boolean | Ya | False while a backup is in flight, when this site's hosting platform cannot take one at all, or when the site's on-demand allowance for the last 24 hours is spent. |
in_progress | boolean | Ya | — |
on_demand_backups | boolean | Ya | Always true. On-demand backups are included on every plan (owner ruling 2026-08-10); what bounds them is `on_demand_limit` per rolling 24 hours, not the plan. Retained for compa… |
unsupported_reason | string | Tidak | A stable machine identifier saying why this site's hosting platform cannot be backed up at all, or empty when it can. The client renders it as a localised sentence. Distinct fro… |
on_demand_limit | integer | Ya | On-demand backups allowed per rolling 24 hours, per site. |
on_demand_used | integer | Ya | On-demand backups taken in the last 24 hours. Failed attempts are not counted — the customer got nothing from them. |
on_demand_remaining | integer | Ya | How many the customer may still take right now. |
on_demand_next_at | string | Ya | When the next on-demand slot opens, as the oldest counted backup ages out of the rolling window. Null whenever `on_demand_remaining` is above zero. |
daily_backups | boolean | Ya | The plan's `daily_backups` entitlement — whether the nightly sweep selects this site. |
retention_days | integer | Ya | The plan's `backup_retention_days` entitlement, clamped to the platform maximum. |
offsite_enabled | boolean | Ya | Whether object storage is configured. False means every backup stays on the worker host it was taken on. |
immutable | boolean | Ya | Whether backup immutability is enforced **and proven recently**. True only when the platform's last reconciliation actually attempted to delete a canary object under the backup… |
immutable_days | integer | Ya | How many days a written backup cannot be altered or deleted by anyone — us, a compromised site, or a stolen token. 30 by owner ruling (2026-08-12), matching sold retention; `0`… |
immutability_verified_at | string | Ya | When a delete was last actually attempted against the protected prefix and refused. ⛔ Not when the configuration was last read, and not when the reconciler last ran: a run that… |
immutability_reason | string | Ya | A stable machine identifier saying why immutability is not currently provable — `never_checked`, `no_rule`, `delete_succeeded`, `credential_missing`, `canary_write_failed`, `ven… |
restore_drill_passed | boolean | Ya | Whether the platform's weekly restore drill last **passed**, and recently enough to still mean something. The drill restores a real stored backup onto a platform-owned site and… |
restore_drill_at | string | Ya | When the last drill finished, whatever its outcome. Null when no drill has ever completed. |
restore_drill_reason | string | Ya | A stable machine identifier saying why restores are not currently proven — `never_drilled`, `no_drill_site`, `no_recent_backup`, `canary_unavailable`, `restore_failed`, `fence_r… |
Ralat yang boleh dikembalikan oleh titik akhir ini
401 · 403 · 404 · 422 · 429 · 503