hosting

DELETE /v1/sites/{siteId}

Schedule a site's permanent deletion.

Alle hosting-eindpunten

Authenticatie

Stuur een API-sleutel mee als bearer token. De sleutel moet over de permissie sites.view beschikken; een sleutel zonder deze permissie wordt geweigerd met een 403 in plaats van een 404.

Dit eindpunt vereist geen organisatie-id. Uw sleutel identificeert al de organisatie waartoe deze behoort, en het antwoord is hierop afgestemd.

Probeer het

Vervang alles tussen punthaakjes door uw eigen waarden en de sleutelplaatsvervanger door een sleutel uit uw dashboard.

curl -X DELETE https://api.zinndigital.com/v1/sites/{siteId} \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "confirm_domain": <string> }'

Ingelogd? De API-console in je dashboard vult je echte organisatie-id en je eigen sleutel in, en voert het verzoek uit tegen de live API zodat je de daadwerkelijke respons kunt zien. Open dit eindpunt in de API-console

Details

Starts the grace period after which the site, its vendor hosting package and everything on them are destroyed. Until this operation existed the driver could delete a package and the teardown workflow was in place, and a customer who wanted their own site gone had to open a ticket. The site is **not** suspended while the countdown runs — it serves normally, so waiting costs nothing. ⛔ **This operation carries a request body on `DELETE`.** RFC 9110 permits it and it is deliberate: the typed confirmation must travel with the request that acts on it, because a "confirm" call followed by an unconfirmed delete is two requests and the second one is the whole vulnerability. `confirm_domain` is compared against `SiteDeletion.primary_domain` — case-insensitively, ignoring surrounding whitespace and a trailing root dot, and never against an alias. `202` and not `200`: nothing has been destroyed yet. The body is the same `SiteDeletion` resource `getSiteDeletion` returns, so the client renders the countdown from the server's answer rather than from what it asked for. A deletion already scheduled is `409`. A confirmation that does not match, an absent `confirm_domain`, or a site whose state does not allow deletion is `422`. `503` means the teardown could not be armed and **nothing was scheduled** — the request is safe to repeat. A site with no vendor hosting package — anything on our own fleet, or a Zinn® VPS — has no such operation and returns `404`, exactly as an out-of-scope or unknown id does. Requires `sites.view` **and** `sites.delete`; the site lookup is scoped on `sites.delete`, so holding it in one organisation does not reach a site in another.

Parameters

NaamTypeVerplichtWat dit is
siteId (path)UuidJaSite ID (UUIDv7).

Aanvraaglichaam

NaamTypeVerplichtWat dit is
confirm_domainstringJaThe site's primary domain, as the customer typed it. Read the value to prompt for from `SiteDeletion.primary_domain` rather than from a `Site` object already on screen: one valu…

Reactie

NaamTypeVerplichtWat dit is
site_idstringJaThe site this deletion state belongs to.
primary_domainstringJa⛔ What the customer must type into `deleteSite`, and what the engine compares against. Read it from here rather than from a `Site` object already on screen: one value on both si…
statestring<none, scheduled, running, stalled, deleted>JaWhere the site is in its lifecycle. A stable machine value the client turns into a localised sentence — never English composed by the engine (§2.19). ⛔ `stalled` is `running` th…
deletablebooleanJaWhether a deletion could be requested right now. False on a site whose state does not allow it, so the form is explained rather than offered and refused.
scheduled_forstringJaWhen the teardown fires, or null when nothing is scheduled.
requested_atstringJaWhen the deletion was requested, or null when nothing is scheduled.
grace_daysintegerJaHow many days the countdown runs. Clamped at both ends — a floor of one day is what stops a misconfiguration meaning *delete now*.
grace_free_reasonstring<, internal, never_provisioned>JaWhy this site would skip the grace period entirely, or `""` when it would not. `never_provisioned` means the site is `failed` — provisioning never completed, so nothing was ever…
can_cancelbooleanJa⛔ **Its own field, and never recomputed as `state == "scheduled"`.** Once the teardown starts, the request row still says scheduled while the site is already being deleted; a cl…

Fouten die dit eindpunt kan retourneren

401 · 403 · 404 · 409 · 422 · 429 · 503