hosting

POST /v1/sites/{siteId}/backups/{backupId}/download

Mint a time-limited download URL for one of a site's backups.

所有 hosting 端点

所有开发者文档

身份验证

请将 API 密钥作为 bearer 令牌发送。该密钥必须具有 hosting.backup.export 权限;缺少该权限的密钥将被拒绝并返回 403 状态码,而非 404。

此端点不需要组织 ID。您的密钥已用于识别其所属的组织,且响应范围也仅限于该组织。

免费试用

将尖括号中的内容替换为您自己的值,并将键占位符替换为您仪表板中的一个键。

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/backups/{backupId}/download \
  -H "Authorization: Bearer zdk_live_…"

已登录?您仪表板中的 API 控制台会自动填入您真实的组织 ID 和您自己的密钥,并针对实时 API 运行请求,以便您查看实际的响应。 在 API 控制台中打开此端点

详细信息

Returns a presigned URL the customer's browser fetches directly from object storage; the archive never passes through the control plane. A site archive is measured in gigabytes, so proxying it would make the customer's site size our memory ceiling and hold a request thread for the length of the transfer. ⛔ POST, despite reading nothing. The response body is a bearer credential for the whole site — database included — so a GET would invite it into browser history, proxy logs and shared caches, and the audit row this writes would be created by every prefetch. The grant expires; take a new one rather than storing it. A backup that never produced a stored archive is 422 (backup_not_downloadable) rather than a signature over a key that is not there, which object storage would reject seconds later as an opaque 404. Requires hosting.backup.export — or hosting.backup.manage, which every holder of the old gate still has — and never sites.view: reading a tenant's database out is never a viewer's. A per-site editor holds hosting.backup.export, which is how zinnector pull brings the files down for local development without being able to restore.

参数

名称类型必填内容简介
siteId (path)UuidSite ID (UUIDv7).
backupId (path)UuidThe backup's id (UUIDv7), as getSiteBackups reports it. Ours, minted when the row was written — never the storage key, which is an internal object path and is deliberately…

响应

名称类型必填内容简介
urlstringThe presigned object-storage URL to fetch the archive from. Hand it straight to the customer's browser and let it expire; take a fresh grant rather than caching this one.
expires_atstringWhen the signature stops working. A download that has already started is unaffected; a new one after this moment is refused by storage.
size_bytesintegerThe archive's size, as object storage reported it when the backup was stored — so a client can warn before a multi-gigabyte download.
etagstringThe stored object's entity tag, for a client that wants to verify the bytes it received are the bytes we hold. Empty when the backend did not report one.

此端点可能返回的错误

401 · 403 · 404 · 422 · 429