WordPress on one site
The snapshot (/wp/status) is a database read and answers instantly, even for a stopped site. Anything that changes the install is a job.
Reading needs Read only and changes need Manage, unless an endpoint says otherwise. How to read this page.
GET /api/sites/:slug/wp/status
Section titled “GET /api/sites/:slug/wp/status”Plugins, themes, core and vulnerability counts from the last scan.
- Level: Read only
- Returns:
{core, plugins[], themes[], counts, feed, scannedAt}
POST /api/sites/:slug/wp/scan
Section titled “POST /api/sites/:slug/wp/scan”Re-read this site now and return the fresh snapshot.
- Level: Manage
- Returns:
the snapshot (sync, 5-20s, 10/min)
POST /api/sites/:slug/wp/bulk
Section titled “POST /api/sites/:slug/wp/bulk”Run several update/activate/deactivate/delete operations as one job.
- Level: Manage
- Notes: Job · Destructive
- Input:
{ops: [{kind, slug?, action}], backupFirst?: false, healthCheck?: true}
GET /api/sites/:slug/wp/plugins
Section titled “GET /api/sites/:slug/wp/plugins”Installed plugins read live from the container.
- Level: Read only
- Returns:
{items} (sync, 409 when stopped)
POST /api/sites/:slug/wp/plugins
Section titled “POST /api/sites/:slug/wp/plugins”Install a plugin from wordpress.org or the catalog.
- Level: Manage
- Notes: Job
- Input:
{source: {kind:"wporg",slug}|{kind:"catalog",id}, activate?}
POST /api/sites/:slug/wp/plugins/:name/activate
Section titled “POST /api/sites/:slug/wp/plugins/:name/activate”Activate a plugin.
- Level: Manage
- Notes: Job
POST /api/sites/:slug/wp/plugins/:name/deactivate
Section titled “POST /api/sites/:slug/wp/plugins/:name/deactivate”Deactivate a plugin.
- Level: Manage
- Notes: Job
POST /api/sites/:slug/wp/plugins/:name/update
Section titled “POST /api/sites/:slug/wp/plugins/:name/update”Update one plugin.
- Level: Manage
- Notes: Job
DELETE /api/sites/:slug/wp/plugins/:name
Section titled “DELETE /api/sites/:slug/wp/plugins/:name”Delete a plugin.
- Level: Manage
- Notes: Job · Destructive
POST /api/sites/:slug/wp/themes/:name/activate
Section titled “POST /api/sites/:slug/wp/themes/:name/activate”Activate a theme.
- Level: Manage
- Notes: Job
POST /api/sites/:slug/wp/themes/:name/update
Section titled “POST /api/sites/:slug/wp/themes/:name/update”Update one theme.
- Level: Manage
- Notes: Job
DELETE /api/sites/:slug/wp/themes/:name
Section titled “DELETE /api/sites/:slug/wp/themes/:name”Delete a theme (never the active one or its parent).
- Level: Manage
- Notes: Job · Destructive
POST /api/sites/:slug/wp/core-update
Section titled “POST /api/sites/:slug/wp/core-update”Update WordPress core.
- Level: Manage
- Notes: Job
GET /api/sites/:slug/wp/version
Section titled “GET /api/sites/:slug/wp/version”Core version and whether an update is waiting.
- Level: Read only
- Returns:
{version, update}
POST /api/sites/:slug/wp/users/reset-password
Section titled “POST /api/sites/:slug/wp/users/reset-password”Reset a WordPress user password; the new one is returned once and never stored.
- Level: Manage
- Notes: Destructive
- Input:
{user} - Returns:
{newPassword} (sync)
POST /api/sites/:slug/wp/admin-login
Section titled “POST /api/sites/:slug/wp/admin-login”Mint a single-use link that lands in wp-admin already signed in (120s).
- Level: Manage
- Returns:
{url, user, expiresInSeconds}
GET /api/sites/:slug/wp/maintenance
Section titled “GET /api/sites/:slug/wp/maintenance”Is maintenance mode on?
- Level: Read only
- Returns:
{enabled}
PUT /api/sites/:slug/wp/maintenance
Section titled “PUT /api/sites/:slug/wp/maintenance”Turn maintenance mode on or off.
- Level: Manage
- Input:
{enabled} - Returns:
{enabled} (sync)
GET /api/sites/:slug/wp/recipes
Section titled “GET /api/sites/:slug/wp/recipes”Where each plugin recipe stands on this site, from the last run.
- Level: Read only
- Returns:
{items: SiteLicense[]}
POST /api/sites/:slug/wp/recipes/apply
Section titled “POST /api/sites/:slug/wp/recipes/apply”Run the plugin recipes on this site now, or only verify them.
- Level: Manage
- Notes: Job · Destructive
- Input:
{recipeId?, hook?: "afterInstall"|"verify"}
POST /api/sites/:slug/wp/cli
Section titled “POST /api/sites/:slug/wp/cli”Run a wp-cli command in the container, or queue it as a job with async: true.
- Level: Manage
- Notes: Destructive
- Input:
{args: ["option","get","siteurl"], stdin?: text for a "-" value or --prompt, one line each (≤ 64 KB; in no summary or log), async?, timeoutMin?: 1-60} - a WP Godmode wait is never async - Returns:
{stdout, stderr, exitCode} (sync, 55s cap; 504 past it) | 202 {job} (async; output in the job log)
GET /api/sites/:slug/wp/cli/help
Section titled “GET /api/sites/:slug/wp/cli/help”WP-CLI’s help for a command, a plugin’s own included: read it before running a command you have not met.
- Level: Read only
- Input:
?command=<words, e.g. "godmode" or "godmode chat send"; none lists every command> - Returns:
{command, help (less WP-CLI's global parameters, the same for every command), panel?: how to reach these commands through the panel} | 404 when the site has no such command
GET /api/sites/:slug/godmode/chats
Section titled “GET /api/sites/:slug/godmode/chats”List the site’s WP Godmode chats and what each is doing, or a chat’s sub-chats (wp godmode chat list).
- Level: Manage. Runs WP-CLI in the site, and a chat can quote anything the site holds
- Input:
?parent=<chat or agent id> - Returns:
WP Godmode's JSON as printed, {ok:false, error} too: {chats: [{id, name, type, state, …}], total} | 409 without the plugin's commands
GET /api/sites/:slug/godmode/agents
Section titled “GET /api/sites/:slug/godmode/agents”List the site’s WP Godmode agents (wp godmode agent list); an agent’s id is a chat id.
- Level: Manage. Runs WP-CLI in the site, and an agent can quote anything the site holds
- Returns:
WP Godmode's JSON as printed, {ok:false, error} too | 409 without the plugin's commands
GET /api/sites/:slug/godmode/chats/:chatId
Section titled “GET /api/sites/:slug/godmode/chats/:chatId”Read a WP Godmode chat, or wait up to 40 s while it works (wp godmode chat read / wait).
- Level: Manage. Runs WP-CLI in the site, and a chat can quote anything the site holds
- Input:
?wait=0-40 (seconds; 0 reads at once), after=<the turn cursor an earlier answer gave; -1 = from the start>, last=1-50 (a read without after), pending=true (a read of the waiting cards alone, in full) - Returns:
WP Godmode's JSON as printed, {ok:false, error} too: a wait {state: working|waiting_for_input|idle|unknown, waiting_on, digest?, …}, a read {chat, turns, waiting_on, after, …} | 409 without the plugin's commands
POST /api/sites/:slug/shell
Section titled “POST /api/sites/:slug/shell”Queue a shell command in the site’s container, run as www-data in the WordPress folder.
- Level: Manage
- Notes: Job · Destructive
- Input:
{command: "ls -la wp-content", timeoutMin?: 1-60} - Returns:
202 {job}; output in the job log
POST /api/sites/:slug/wp/rest
Section titled “POST /api/sites/:slug/wp/rest”Call one of the site’s WordPress REST API routes, optionally signed in with an application password.
- Level: Manage
- Notes: Destructive
- Input:
{method?: "GET", route: "wp/v2/posts?per_page=5", body?, auth?: {username, applicationPassword}, async?, timeoutMin?: 1-60} - Returns:
{status, statusText, contentType, headers, body, truncated, sizeBytes, durationMs, error} (sync, 45s cap) | 202 {job} (async; the answer in the job log)
POST /api/sites/:slug/wp/test-email
Section titled “POST /api/sites/:slug/wp/test-email”Send a real wp_mail() test message.
- Level: Manage
- Input:
{to} - Returns:
{accepted, detail}