hosting

POST /v1/sites/{siteId}/backups/{backupId}/download

Mint a time-limited download URL for one of a site's backups.

Tất cả các điểm cuối hosting

Xác thực

Gửi khóa API dưới dạng mã thông báo bearer. Khóa này phải có quyền hosting.backup.export; khóa không có quyền này sẽ bị từ chối với mã lỗi 403, không phải 404.

Endpoint này không nhận ID tổ chức. Khóa của bạn đã xác định tổ chức mà nó thuộc về và phản hồi được giới hạn trong phạm vi đó.

Dùng thử

Thay thế bất kỳ nội dung nào trong ngoعل (angle brackets) bằng giá trị của riêng bạn và trình giữ chỗ key bằng một key từ trang tổng quan của bạn.

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/backups/{backupId}/download \
  -H "Authorization: Bearer zdk_live_…"

Đã đăng nhập? Bảng điều khiển API trong trang quản lý của bạn sẽ tự điền ID tổ chức thực tế và khóa của riêng bạn, sau đó chạy yêu cầu đối với API trực tiếp để bạn có thể xem phản hồi thực tế. Mở điểm cuối này trong bảng điều khiển API

Chi tiết

Returns a presigned URL the customer's browser fetches **directly from object storage**; the archive never passes through the control plane. A site archive is measured in gigabytes, so proxying it would make the customer's site size our memory ceiling and hold a request thread for the length of the transfer. ⛔ **`POST`, despite reading nothing.** The response body is a bearer credential for the whole site — database included — so a `GET` would invite it into browser history, proxy logs and shared caches, and the audit row this writes would be created by every prefetch. The grant expires; take a new one rather than storing it. A backup that never produced a stored archive is `422` (`backup_not_downloadable`) rather than a signature over a key that is not there, which object storage would reject seconds later as an opaque `404`. Requires `hosting.backup.export` — or `hosting.backup.manage`, which every holder of the old gate still has — and never `sites.view`: reading a tenant's database out is never a viewer's. A per-site *editor* holds `hosting.backup.export`, which is how `zinnector pull` brings the files down for local development without being able to restore.

Tham số

TênLoạiBắt buộcNội dung này là gì
siteId (path)UuidSite ID (UUIDv7).
backupId (path)UuidThe backup's id (UUIDv7), as `getSiteBackups` reports it. **Ours**, minted when the row was written — never the storage key, which is an internal object path and is deliberately…

Phản hồi

TênLoạiBắt buộcNội dung này là gì
urlstringThe presigned object-storage URL to fetch the archive from. Hand it straight to the customer's browser and let it expire; take a fresh grant rather than caching this one.
expires_atstringWhen the signature stops working. A download that has already started is unaffected; a new one after this moment is refused by storage.
size_bytesintegerThe archive's size, as object storage reported it when the backup was stored — so a client can warn before a multi-gigabyte download.
etagstringThe stored object's entity tag, for a client that wants to verify the bytes it received are the bytes we hold. Empty when the backend did not report one.

Các lỗi điểm cuối này có thể trả về

401 · 403 · 404 · 422 · 429