hosting

PUT /v1/sites/{siteId}/wordpress/users/{wpUserId}/role

Change a WordPress account's role.

Усі кінцеві точки hosting

Автентифікація

Надішліть ключ API як маркер носія (bearer token). Ключ повинен мати дозвіл sites.view; ключ без нього відхиляється з кодом 403, а не 404.

Цей кінцевий пункт не потребує ідентифікатора організації. Ваш ключ уже ідентифікує організацію, якій він належить, і відповідь обмежується її межами.

Спробувати

Замініть усе в кутових дужках власними значеннями, а заповнювач ключа — ключем із вашої панелі керування.

curl -X PUT https://api.zinndigital.com/v1/sites/{siteId}/wordpress/users/{wpUserId}/role \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "role": <string> }'

Увійшли в систему? Консоль API у вашій панелі керування автоматично підставляє ваш реальний ідентифікатор організації та ваш власний ключ, а також виконує запит до робочого API, щоб ви могли побачити справжню відповідь. Відкрийте цю кінцеву точку в консолі API

Деталі

Replaces the account's roles with exactly the one in the body — the other half of "add and remove administrators", and the half that lets a customer fix a mistake without deleting somebody's account and their authorship along with it. ⛔ **Replaces, never adds.** WordPress lets one account hold several roles at once, so granting the new role without removing the old one would leave a "demoted" administrator holding both — an account that reads as an editor on every screen and can still do everything. That outcome is indistinguishable from a successful demotion, which is why the distinction is stated here rather than left to the implementation. Its own path rather than a field on the user resource, for the same reason the password reset has one: a role change and a delete must not be two shapes of one request. **Promoting to `administrator` and demoting *from* one both** require the package's administrator-management capability, not merely `wp_users`. The promotion is obvious; the demotion matters just as much, because removing the last administrator's role locks every human out of the site as thoroughly as deleting them would. `422` for a role the install does not define, or a platform with no role field. `404` for a site with no vendor hosting package, and for an id that is not on it. Requires `sites.view` and `sites.panel_access`.

Параметри

НазваТипОбов'язковеЩо це таке
siteId (path)UuidТакSite ID (UUIDv7).
wpUserId (path)stringТакThe account's WordPress id, as `listSiteWordPressUsers` reports it.

Тіло запиту

НазваТипОбов'язковеЩо це таке
rolestringТакThe role the account should hold, from `listSiteWordPressRoles`.

Відповідь

НазваТипОбов'язковеЩо це таке
idstringТакThe account's WordPress id, carried as a string because it is the vendor's identifier rather than ours.
loginstringТакThe name the account signs in with.
display_namestringТакThe name shown on the site's posts and comments.
emailstringТакThe account's email address. Personal data about the customer's **own** users, which is why the whole listing is gated on `sites.panel_access`.
rolesstringТакThe account's roles, in the vendor's own spelling.
registered_atstringТакWhen WordPress recorded the account, in the vendor's own format. Not typed as a date-time: the platform does not guarantee one, and coercing it would invent precision.
is_administratorbooleanТакWhether the account is an administrator. ⛔ Set from **which vendor endpoint the row came from**, not guessed from the role string — the two lists sit behind two different capabi…

Помилки, які може повертати ця кінцева точка

401 · 403 · 404 · 409 · 422 · 429 · 503