hosting

POST /v1/sites/{siteId}/backups/{backupId}/download

Mint a time-limited download URL for one of a site's backups.

Усі кінцеві точки hosting

Уся документація для розробників

Автентифікація

Надішліть ключ API як маркер носія (bearer token). Ключ повинен мати дозвіл hosting.backup.export; ключ без нього відхиляється з кодом 403, а не 404.

Цей кінцевий пункт не потребує ідентифікатора організації. Ваш ключ уже ідентифікує організацію, якій він належить, і відповідь обмежується її межами.

Спробувати

Замініть усе в кутових дужках власними значеннями, а заповнювач ключа — ключем із вашої панелі керування.

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/backups/{backupId}/download \
  -H "Authorization: Bearer zdk_live_…"

Увійшли в систему? Консоль API у вашій панелі керування автоматично підставляє ваш реальний ідентифікатор організації та ваш власний ключ, а також виконує запит до робочого API, щоб ви могли побачити справжню відповідь. Відкрийте цю кінцеву точку в консолі API

Деталі

Returns a presigned URL the customer's browser fetches directly from object storage; the archive never passes through the control plane. A site archive is measured in gigabytes, so proxying it would make the customer's site size our memory ceiling and hold a request thread for the length of the transfer. ⛔ POST, despite reading nothing. The response body is a bearer credential for the whole site — database included — so a GET would invite it into browser history, proxy logs and shared caches, and the audit row this writes would be created by every prefetch. The grant expires; take a new one rather than storing it. A backup that never produced a stored archive is 422 (backup_not_downloadable) rather than a signature over a key that is not there, which object storage would reject seconds later as an opaque 404. Requires hosting.backup.export — or hosting.backup.manage, which every holder of the old gate still has — and never sites.view: reading a tenant's database out is never a viewer's. A per-site editor holds hosting.backup.export, which is how zinnector pull brings the files down for local development without being able to restore.

Параметри

НазваТипОбов'язковеЩо це таке
siteId (path)UuidТакSite ID (UUIDv7).
backupId (path)UuidТакThe backup's id (UUIDv7), as getSiteBackups reports it. Ours, minted when the row was written — never the storage key, which is an internal object path and is deliberately…

Відповідь

НазваТипОбов'язковеЩо це таке
urlstringТакThe presigned object-storage URL to fetch the archive from. Hand it straight to the customer's browser and let it expire; take a fresh grant rather than caching this one.
expires_atstringТакWhen the signature stops working. A download that has already started is unaffected; a new one after this moment is refused by storage.
size_bytesintegerТакThe archive's size, as object storage reported it when the backup was stored — so a client can warn before a multi-gigabyte download.
etagstringТакThe stored object's entity tag, for a client that wants to verify the bytes it received are the bytes we hold. Empty when the backend did not report one.

Помилки, які може повертати ця кінцева точка

401 · 403 · 404 · 422 · 429