hosting

POST /v1/sites/{siteId}/backups/restore

Restore a site from one of its backups.

Todos os endpoints de hosting

Autenticação

Envie uma chave de API como um token de portador. A chave deve ter a permissão hosting.backup.manage; uma chave sem ela é recusada com 403, e não 404.

Este endpoint não requer um ID de organização. Sua chave já identifica a organização à qual pertence, e a resposta é delimitada a ela.

Experimente

Substitua qualquer item entre colchetes por seus próprios valores e o espaço reservado para a chave por uma chave do seu painel.

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/backups/restore \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "backup_id": <Uuid> }'

Conectado? O console da API no seu painel preenche o ID da sua organização real e a sua própria chave, e executa a requisição contra a API de produção para que você possa ver a resposta real. Abra este endpoint no console da API

Detalhes

⛔ **Destructive.** This overwrites the site's live database and files with the contents of the named backup. Its own path rather than a verb on the collection, so it can never be reached by varying the body of the endpoint that *takes* backups. The backup must belong to this site and must have completed successfully; anything else is 422. Requires `hosting.backup.manage`.

Parâmetros

NomeTipoObrigatórioO que é
siteId (path)UuidSimSite ID (UUIDv7).
Idempotency-Key (header)stringNãoClient-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats.

Corpo da requisição

NomeTipoObrigatórioO que é
backup_idUuidSimThe backup to restore. Always named explicitly — there is no "restore the latest", because a destructive operation must not depend on which row happens to sort first.

Resposta

NomeTipoObrigatórioO que é
site_idUuidSimUUIDv7 identifier — sortable by creation time (docs/02 §8).
backupsSiteBackup[]Sim
can_backupbooleanSimFalse while a backup is in flight, when this site's hosting platform cannot take one at all, or when the site's on-demand allowance for the last 24 hours is spent.
in_progressbooleanSim
on_demand_backupsbooleanSimAlways true. On-demand backups are included on every plan (owner ruling 2026-08-10); what bounds them is `on_demand_limit` per rolling 24 hours, not the plan. Retained for compa…
unsupported_reasonstringNãoA stable machine identifier saying why this site's hosting platform cannot be backed up at all, or empty when it can. The client renders it as a localised sentence. Distinct fro…
on_demand_limitintegerSimOn-demand backups allowed per rolling 24 hours, per site.
on_demand_usedintegerSimOn-demand backups taken in the last 24 hours. Failed attempts are not counted — the customer got nothing from them.
on_demand_remainingintegerSimHow many the customer may still take right now.
on_demand_next_atstringSimWhen the next on-demand slot opens, as the oldest counted backup ages out of the rolling window. Null whenever `on_demand_remaining` is above zero.
daily_backupsbooleanSimThe plan's `daily_backups` entitlement — whether the nightly sweep selects this site.
retention_daysintegerSimThe plan's `backup_retention_days` entitlement, clamped to the platform maximum.
offsite_enabledbooleanSimWhether object storage is configured. False means every backup stays on the worker host it was taken on.
immutablebooleanSimWhether backup immutability is enforced **and proven recently**. True only when the platform's last reconciliation actually attempted to delete a canary object under the backup…
immutable_daysintegerSimHow many days a written backup cannot be altered or deleted by anyone — us, a compromised site, or a stolen token. 30 by owner ruling (2026-08-12), matching sold retention; `0`…
immutability_verified_atstringSimWhen a delete was last actually attempted against the protected prefix and refused. ⛔ Not when the configuration was last read, and not when the reconciler last ran: a run that…
immutability_reasonstringSimA stable machine identifier saying why immutability is not currently provable — `never_checked`, `no_rule`, `delete_succeeded`, `credential_missing`, `canary_write_failed`, `ven…
restore_drill_passedbooleanSimWhether the platform's weekly restore drill last **passed**, and recently enough to still mean something. The drill restores a real stored backup onto a platform-owned site and…
restore_drill_atstringSimWhen the last drill finished, whatever its outcome. Null when no drill has ever completed.
restore_drill_reasonstringSimA stable machine identifier saying why restores are not currently proven — `never_drilled`, `no_drill_site`, `no_recent_backup`, `canary_unavailable`, `restore_failed`, `fence_r…

Erros que este endpoint pode retornar

401 · 403 · 404 · 422 · 429 · 503