hosting
POST /v1/migrations/discover
Identify a host from its hostname, with no site yet.
身份验证
请将 API 密钥作为 bearer 令牌发送。此端点在规范中未指明具体的权限,因此请为您的密钥赋予所需的最小权限,并通过检查响应来确认,而不是盲目假设。
此端点不需要组织 ID。您的密钥已用于识别其所属的组织,且响应范围也仅限于该组织。
免费试用
将尖括号中的内容替换为您自己的值,并将键占位符替换为您仪表板中的一个键。
curl -X POST https://api.zinndigital.com/v1/migrations/discover \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "host": <string> }'已登录?您仪表板中的 API 控制台会自动填入您真实的组织 ID 和您自己的密钥,并针对实时 API 运行请求,以便您查看实际的响应。 在 API 控制台中打开此端点
详细信息
The org-scoped twin of POST /v1/sites/{siteId}/migrations/discover. Same workflow, same 202-plus-poll shape, and the same owner ruling behind it: signed-in customers only, never a prospect — the hostname is attacker-supplied by construction and "probe this for me" is the classic shape of a request to reach something the caller cannot. It exists because the customer it serves has no sites at all, which is exactly the customer being asked "which control panel do you log in to?" by a form they cannot answer. hosting.import.manage is an org permission, so every run still has a named actor and an org to rate-limit; only the site-level anchor is dropped, and nothing about the ruling rested on it. POST rather than GET, and not because of a secret — there is none in the body. It knocks on a third party's administrative ports, which is an act rather than a lookup, and must not be repeated by a browser prefetch, a CDN revalidation or a back button. Name the organisation with X-Zinn-Org when you belong to more than one; a caller in exactly one org may omit it.
请求正文
| 名称 | 类型 | 必填 | 内容简介 |
|---|---|---|---|
host | string | 是 | The server address the current host gave them, e.g. server123.theirhost.com. A hostname, not a web address — no scheme and no path. The customer's own domain works too when it… |
响应
| 名称 | 类型 | 必填 | 内容简介 |
|---|---|---|---|
outcome | string<pending, identified, unidentified, unreachable> | 是 | pending while the discovery workflow is still probing — poll getMigrationDiscovery until it is one of the other three (D19865). ⛔ Three answers and never a boolean.… |
host | string | 是 | The hostname as it was normalised, which may differ from what was typed. |
source | string | 是 | The best candidate's MigrationSource, or "" when there is none. |
port | integer | 是 | The login port for that source, which is not necessarily the port the evidence came from: a banner read from cPanel's plaintext 2082 reports 2083, because that is where the… |
confidence | integer | 是 | — |
confident | boolean | 是 | May the credential form be pre-filled from this? |
candidates | MigrationDiscoveryCandidate[] | 是 | — |
expectations | string[] | 是 | Machine codes for what to expect from the winning source — e.g. ftp_files_only. ⛔ Expectations, not a capability claim: the authoritative answer comes from the credentialed… |
routes | MigrationDiscoveryRoute[] | 是 | Every way in that was tried. Read it when a panel is firewalled — a host with 2083 closed and 22 open can still have everything moved. |
proxy_fronted | boolean | 是 | This address is a CDN in front of a website, not a hosting account — several different panels' login ports accepted a connection at once and none of them answered with its own… |
refused | string | 是 | A customer-readable reason the hostname was rejected before any packet went out — a private address, an unresolvable name. "" otherwise. |
agent_used | boolean | 是 | Whether a language model was asked to read the sign-in page. It is asked only when the deterministic table produced no confident panel. |
agent_unavailable | string | 是 | Machine code when the model was asked and could not answer (ai_unavailable, ai_timeout, …). "" when it was not asked or it answered. ⛔ The deterministic answer stands either… |
discovery_id | string | 是 | The recorded run, for support. "" when the row could not be written — which never costs the customer their answer. |
此端点可能返回的错误
401 · 403 · 422 · 429 · 503