hosting
POST /v1/migrations
Create the site and start migrating onto it, in one call.
Автентифікація
Надішліть ключ API як маркер носія (bearer token). Ця кінцева точка не вказує конкретного дозволу в специфікації, тому надайте своєму ключу мінімально необхідні права та перевірте відповідь, замість того щоб припускати.
Цей кінцевий пункт не потребує ідентифікатора організації. Ваш ключ уже ідентифікує організацію, якій він належить, і відповідь обмежується її межами.
Спробувати
Замініть усе в кутових дужках власними значеннями, а заповнювач ключа — ключем із вашої панелі керування.
curl -X POST https://api.zinndigital.com/v1/migrations \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "source": <MigrationSource>, "host": <string>, "username": <string>, "ownership_attested": <boolean>, "site": <object> }'Увійшли в систему? Консоль API у вашій панелі керування автоматично підставляє ваш реальний ідентифікатор організації та ваш власний ключ, а також виконує запит до робочого API, щоб ви могли побачити справжню відповідь. Відкрийте цю кінцеву точку в консолі API
Деталі
The "deploy it and start the migration straight away" path, and the only one that works from an account with no sites yet. ⛔⛔ One endpoint rather than "call POST /v1/sites then POST /v1/sites/{id}/migrations", because the two-call version fails badly: a browser closed between them, or a migration refused for a bad password, leaves an orphan site the customer never asked for, holding one of their plan's site slots, with a hostname they must now delete. Each endpoint did exactly what it was asked and the customer is left holding it. So the ordering here is load-bearing: the source is probed first, and the site is created only once the credentials have been proven against the customer's old host and the estate enumerated. The two failures a customer will actually hit both happen while nothing has been created — and so do the attestation and mail refusals (ownership_not_attested, mailbox_passwords_required, source_cannot_migrate_mail), which until 2026-09-13 were asked only after the site existed. Send mailbox_passwords for the addresses POST /v1/migrations/probe lists. ⛔ Not idempotent, and it does not pretend to be — a retry is refused by the hostname uniqueness constraint, which is a clean conflict rather than a second site. Requires both sites.create and hosting.import.manage: it spends a site slot and connects to a third party's production server, and a principal holding one of those powers must not acquire the other by coming through this door.
Тіло запиту
| Назва | Тип | Обов'язкове | Що це таке |
|---|---|---|---|
source | MigrationSource | Так | The kind of hosting the site is being pulled from. ⛔ plesk is offered so the refusal can be specific and actionable, not because it is supported: pleskbackup is reachable… |
host | string | Так | The server's public hostname, e.g. server123.yourhost.com. Must resolve to a public address — a private or link-local target is refused with source_host_not_public at the door… |
username | string | Так | The login for the source panel or account. |
port | integer | Ні | 0 means the source driver's default for that panel. |
password | string | Ні | — |
private_key | string | Ні | An SSH private key in PEM form, for an ssh source. |
api_token | string | Ні | — |
include_mail | boolean | Ні | ⚖️ Defaults to true, and a source that cannot deliver mailboxes is refused rather than silently migrated without them — a migration that moves a website and loses the mail is… |
mailbox_passwords | object | Ні | address -> password, for every mailbox being moved. Required up front rather than discovered mid-sync: most panels will not hand over a mailbox without its own password, and… |
ownership_attested | boolean | Так | ⚠️ As on SiteMigrationCreate: recorded because it cannot be reconstructed afterwards, required, and not a legal control. |
site | object | Так | The site to create. ⛔ Nested rather than flattened, and the nesting is load-bearing: MigrationCredentials already has a host (the server we are migrating from) and this… |
Відповідь
| Назва | Тип | Обов'язкове | Що це таке |
|---|---|---|---|
id | Uuid | Так | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
site_id | Uuid | Так | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
source | MigrationSource | Так | The kind of hosting the site is being pulled from. ⛔ plesk is offered so the refusal can be specific and actionable, not because it is supported: pleskbackup is reachable… |
status | SiteMigrationStatus | Так | authenticating, inventorying and transferring are separate states rather than one running because they fail for opposite reasons and the customer's next action differs: a… |
status_reason | string | Ні | A machine code the dashboard renders through its own catalogue — never an English sentence composed by the engine, which could be shown to none of the other 57 locales. |
include_mail | boolean | Так | — |
source_host | string | Ні | The hostname the estate is being pulled from. Host only: no port, no username, and never a secret. |
files_total | integer | Так | — |
files_done | integer | Так | — |
databases_total | integer | Так | — |
databases_done | integer | Так | — |
mailboxes_total | integer | Так | — |
mailboxes_done | integer | Так | — |
items_failed | integer | Так | ⛔ Counted separately from the *_done fields, never folded into them. "We could not get it" reported as "done" makes the completion report a lie. |
bytes_transferred | integer | Так | — |
warnings | string[] | Так | Machine warning codes the dashboard localises. |
mail_synced_at | string | Ні | When the mail delta last ran. null and a timestamp are different states, and the cutover control reads this to tell them apart. |
dns_records_captured | integer | Ні | How many records were read off the source's zone and will be published on cutover. ⛔ Counted separately from dns_records_unsupported, never as one total: "we captured 14… |
dns_records_unsupported | integer | Ні | Real records the source holds that our DNS editor cannot express (an SSHFP, a TLSA, an MX with no preference). Stored and listed on the detail endpoint rather than dropped —… |
dns_captured_at | string | Ні | When the source's zone was read. null means never attempted, which is NOT the same as attempted-and-the-panel-holds-no-zone; only the first is worth retrying. |
verified_at | string | Ні | When the migrated site was last fetched over HTTP and compared with the source. null means the destination has never been looked at. |
verification_code | string | Ні | A machine code the dashboard localises. Empty means the destination is serving the site as well as the source was. ⛔ The migration's own counters cannot answer this: they travel… |
destination_status | integer | Ні | The HTTP status the migrated site returned, fetched at its origin address with a Host: header — before cutover the customer's domain still resolves to the OLD host, so asking… |
source_status | integer | Ні | The HTTP status the source returned. ⭐ Reported beside destination_status because the interesting failure is the PAIR: a destination 200 against a source 500 means we faithfully… |
replaces_existing | boolean | Ні | Whether this migration landed on a site that already held a website. Stamped when the job is created and never recomputed: after the apply step the site is occupied… |
safety_backup_state | string<not_needed, pending, taken, unsupported, failed> | Ні | What became of the backup taken immediately before the apply step replaced the site. ⛔ Five values rather than a boolean: "there is no safety backup" is one rendered sentence… |
safety_backup_id | string | Ні | The SiteBackup id, or "". ⛔ Still reported after the archive has been pruned by retention, so a rollback can say "that archive has expired" rather than looking like a… |
rolled_back_at | string | Ні | When the customer put the site back. Set once — restoring the pre-migration archive over a site that is already the pre-migration archive can only lose work done since. |
rollback | MigrationRollback | Ні | Whether this migration can be put back, and — when it cannot — why not. ⛔⛔ reason travels with available, always. Six different facts render as the same absent button… |
started_at | string | Ні | — |
finished_at | string | Ні | — |
created_at | string | Так | — |
site_name | string | Так | May be empty — a site's display name is optional, which is exactly the case for sites created by POST /v1/migrations, so a row rendered from this alone would be blank for them. |
site_domain | string | Так | — |
site_status | string | Так | — |
Помилки, які може повертати ця кінцева точка
401 · 403 · 409 · 422 · 429 · 503