hosting

POST /v1/sites/{siteId}/backups/restore

Restore a site from one of its backups.

Alle hosting-eindpunten

Authenticatie

Stuur een API-sleutel mee als bearer token. De sleutel moet over de permissie hosting.backup.manage beschikken; een sleutel zonder deze permissie wordt geweigerd met een 403 in plaats van een 404.

Dit eindpunt vereist geen organisatie-id. Uw sleutel identificeert al de organisatie waartoe deze behoort, en het antwoord is hierop afgestemd.

Probeer het

Vervang alles tussen punthaakjes door uw eigen waarden en de sleutelplaatsvervanger door een sleutel uit uw dashboard.

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/backups/restore \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "backup_id": <Uuid> }'

Ingelogd? De API-console in je dashboard vult je echte organisatie-id en je eigen sleutel in, en voert het verzoek uit tegen de live API zodat je de daadwerkelijke respons kunt zien. Open dit eindpunt in de API-console

Details

⛔ **Destructive.** This overwrites the site's live database and files with the contents of the named backup. Its own path rather than a verb on the collection, so it can never be reached by varying the body of the endpoint that *takes* backups. The backup must belong to this site and must have completed successfully; anything else is 422. Requires `hosting.backup.manage`.

Parameters

NaamTypeVerplichtWat dit is
siteId (path)UuidJaSite ID (UUIDv7).
Idempotency-Key (header)stringNeeClient-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats.

Aanvraaglichaam

NaamTypeVerplichtWat dit is
backup_idUuidJaThe backup to restore. Always named explicitly — there is no "restore the latest", because a destructive operation must not depend on which row happens to sort first.

Reactie

NaamTypeVerplichtWat dit is
site_idUuidJaUUIDv7 identifier — sortable by creation time (docs/02 §8).
backupsSiteBackup[]Ja
can_backupbooleanJaFalse while a backup is in flight, when this site's hosting platform cannot take one at all, or when the site's on-demand allowance for the last 24 hours is spent.
in_progressbooleanJa
on_demand_backupsbooleanJaAlways true. On-demand backups are included on every plan (owner ruling 2026-08-10); what bounds them is `on_demand_limit` per rolling 24 hours, not the plan. Retained for compa…
unsupported_reasonstringNeeA stable machine identifier saying why this site's hosting platform cannot be backed up at all, or empty when it can. The client renders it as a localised sentence. Distinct fro…
on_demand_limitintegerJaOn-demand backups allowed per rolling 24 hours, per site.
on_demand_usedintegerJaOn-demand backups taken in the last 24 hours. Failed attempts are not counted — the customer got nothing from them.
on_demand_remainingintegerJaHow many the customer may still take right now.
on_demand_next_atstringJaWhen the next on-demand slot opens, as the oldest counted backup ages out of the rolling window. Null whenever `on_demand_remaining` is above zero.
daily_backupsbooleanJaThe plan's `daily_backups` entitlement — whether the nightly sweep selects this site.
retention_daysintegerJaThe plan's `backup_retention_days` entitlement, clamped to the platform maximum.
offsite_enabledbooleanJaWhether object storage is configured. False means every backup stays on the worker host it was taken on.
immutablebooleanJaWhether backup immutability is enforced **and proven recently**. True only when the platform's last reconciliation actually attempted to delete a canary object under the backup…
immutable_daysintegerJaHow many days a written backup cannot be altered or deleted by anyone — us, a compromised site, or a stolen token. 30 by owner ruling (2026-08-12), matching sold retention; `0`…
immutability_verified_atstringJaWhen a delete was last actually attempted against the protected prefix and refused. ⛔ Not when the configuration was last read, and not when the reconciler last ran: a run that…
immutability_reasonstringJaA stable machine identifier saying why immutability is not currently provable — `never_checked`, `no_rule`, `delete_succeeded`, `credential_missing`, `canary_write_failed`, `ven…
restore_drill_passedbooleanJaWhether the platform's weekly restore drill last **passed**, and recently enough to still mean something. The drill restores a real stored backup onto a platform-owned site and…
restore_drill_atstringJaWhen the last drill finished, whatever its outcome. Null when no drill has ever completed.
restore_drill_reasonstringJaA stable machine identifier saying why restores are not currently proven — `never_drilled`, `no_drill_site`, `no_recent_backup`, `canary_unavailable`, `restore_failed`, `fence_r…

Fouten die dit eindpunt kan retourneren

401 · 403 · 404 · 422 · 429 · 503