hosting
GET /v1/sites/{siteId}/wp-credentials
The WordPress admin login for a site.
Ìfàṣẹ́pọ̀
Fi bọ́ọ̀lù (bearer token) ranṣẹ gẹ́gẹ́ bí kọ́kọ́rọ́ API. Kọ́kọ́rọ́ náà gbọ́dọ̀ ní ìyọ̀ǹda sites.view; a ó kọ̀ ọ́ silẹ pẹlu 403, kii ṣe 404, ti kọ́kọ́rọ́ náà kò bá ní i.
Ojú abánisọ̀rọ̀ yìí kò gba id ajọ kankan. Kọ́kọ́rọ́ rẹ ti mọ ajọ ti o jẹ ti e, a o si fèsì nipa rẹ̀.
Gbiyanju rẹ
Rọ́pọ̀ èyíkéyìí nínú àwọn àmì ìtọ́ka < > pẹ̀lú iye tirẹ̀, àti àmì ìdánimọ̀ bọ́tìnnì náà pẹ̀lú bọ́tìnnì kan láti inú dásibọ̀ọ̀dù rẹ.
curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/wp-credentials \
-H "Authorization: Bearer zdk_live_…"Ṣé o ti wọlé? Iwọ̀n api ní nú ìgbékalẹ̀ rẹ kún id àjọ gidi rẹ ati bọtini tirẹ, o si nṣiṣẹ ibeere na lòdì si api gidi ki o le rii esi gidi na. Ṣí ojú abáná yìí sílẹ̀ nínú kọnsólù API
Àwọn kúlẹ̀kúlẹ̀
Requires `sites.view` and `sites.panel_access` — the key that already means "a customer reaching their own site". Every read is audit-logged: a password revealed by session alone is only safe if looking at it is attributable. Re-reads the site's own `wp_users` row before answering, so the screen a human is looking at is never stale. A site that cannot be reached is not an error: the stored record is returned unchanged and `checked_at` says when the platform last managed to look.
Àwọn ìpìlẹ̀
| Orúkọ | Iru | Tí a nílò | Kini o jẹ |
|---|---|---|---|
siteId (path) | Uuid | Bẹẹni | Site ID (UUIDv7). |
Idahun
| Orúkọ | Iru | Tí a nílò | Kini o jẹ |
|---|---|---|---|
site_id | Uuid | Bẹẹni | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
username | string | Bẹẹni | This site's own admin username, re-read from the site's `wp_users` row on every request. A customer who renames the account in phpMyAdmin, wp-admin or wp-cli sees the new name h… |
email | string | Bẹẹni | `wp_users.user_email` on the site itself — where a WordPress password reset would actually go. Empty until the platform has managed to read one. |
password | string | Bẹẹni | The current password, or empty when it cannot be shown — see `can_reveal`. It is derived from a platform key and the site's rotation epoch, never stored, so there is no per-site… |
can_reveal | boolean | Bẹẹni | False when the customer set their own password (nothing of ours to show) or the environment has no signing key. Rotating makes it true again. |
is_custom | boolean | Bẹẹni | The password in use was set by the customer through this app, so there is nothing of ours to show. Distinct from `changed_outside_app`. |
changed_outside_app | boolean | Bẹẹni | Proven: the password the platform holds no longer opens the site, so it was changed outside of the Zinn Digital® Hosting App — phpMyAdmin, wp-admin or wp-cli. WordPress stores `… |
checked_at | string | Bẹẹni | When the platform last managed to LOOK at the site's admin row. Null means never. |
verified_at | string | Bẹẹni | When the platform last PROVED these credentials are the live ones. Null means never. Deliberately separate from `checked_at`: "we have not been able to reach this site for a wee… |
login_url | string | Bẹẹni | Where to sign in. |
Awọn aṣiṣe ti ibudo ipari yii le da pada
401 · 403 · 404 · 422 · 429