public

GET /v1/plugins/{slug}/download

The installable plugin zip.

所有 public 端点

身份验证

请将 API 密钥作为 bearer 令牌发送。此端点在规范中未指明具体的权限,因此请为您的密钥赋予所需的最小权限,并通过检查响应来确认,而不是盲目假设。

此端点不需要组织 ID。您的密钥已用于识别其所属的组织,且响应范围也仅限于该组织。

免费试用

将尖括号中的内容替换为您自己的值,并将键占位符替换为您仪表板中的一个键。

curl -X GET https://api.zinndigital.com/v1/plugins/{slug}/download \
  -H "Authorization: Bearer zdk_live_…"

已登录?您仪表板中的 API 控制台会自动填入您真实的组织 ID 和您自己的密钥,并针对实时 API 运行请求,以便您查看实际的响应。 在 API 控制台中打开此端点

详细信息

The archive itself, over TLS on our own hostname, with its SHA-256 in `X-Zinn-Package-SHA256` so a download is checkable without a second request. ⛔ The bytes are served rather than redirected, and that is a constraint the CLIENT imposes: the self-hosted updater shipped inside these plugins accepts a package only on our own host, so a redirect to a release asset or an object store is refused on every site. An `app-only` plugin is invisible here to an anonymous caller. A site we host reaches it with the **package ticket** (`site`, `exp`, `sig`) that `POST /v1/wp/plugin-update/{siteId}` puts in the `package` URL it returns — WordPress fetches that URL with no headers, so the proof has to travel in the query string. The ticket is bound to one plugin at one version and expires; an invalid one is the same `404` as an unknown plugin.

参数

名称类型必填内容简介
slug (path)stringThe plugin's directory name and text domain, e.g. `zinn-cache`.
site (query)stringThe site id a package ticket was minted for. Ignored for public plugins.
exp (query)integerUnix time the package ticket stops being accepted.
sig (query)stringHex HMAC-SHA256 over `slug:version:exp` with the site's own secret.

此端点可能返回的错误

404 · 429