One registry for everything
Every module declares its actions in its manifest: an id, a title, a permission, a risk level, whether it changes anything, whether it can preview itself, and a JSON schema for its parameters and result. Today's build has 769 actions across 29 modules, 188 of which can run as a dry run. Here is a real one, from the domains module:
- id: domains.create
title: Add a domain
permission: domains.manage
risk: low
mutates: true
dry_run: true
inverse: domains.delete
params: schemas/create.params.json
result: schemas/domain.json The host checks the permission, the parameters (strict: unknown fields are refused), plan limits and risk before the module sees the call, and writes the audit row. The menu, the forms, the command palette and the API all come from the same entries.
Calling an action
Every action is a POST to its id, with the parameters as the JSON body. Reads are actions too.
curl -s https://panel.example.com:7443/api/v1/a/domains.list \
-H "Authorization: Bearer $RC_TOKEN" \
-H "Content-Type: application/json" \
-d '{"limit": 50}' GET /api/v1/actionslists the actions you may run, with their schemas.GET /api/v1/moduleslists the installed modules.- Send an
Idempotency-Keyheader with changes you might retry.
Previewing a change
Add ?dry_run=1 to any action that supports it. Nothing changes; you get back a plan with the targets and
their diffs, the same plan the panel shows before Apply changes. Dry runs are not recorded as changes.
curl -s "https://panel.example.com:7443/api/v1/a/domains.create?dry_run=1" \
-H "Authorization: Bearer $RC_TOKEN" -H "Content-Type: application/json" \
-d '{"name": "shop.example.com", "kind": "addon", "account_id": "…"}' Actions that can be undone also name their inverse (for example domains.create is undone by domains.delete).
Signing in from code
- API tokens: send
Authorization: Bearer <token>. Tokens are created on your Security page, scoped, and revocable at once. They can never change sign-in settings. - Browser sessions use a secure, HTTP-only cookie plus a CSRF header on every call.
- Every method and path is denied unless an action allows it.
Errors
Every error has the same shape:
{"error": {"code": "limit_exceeded", "message": "…", "details": {}, "request_id": "…"}} | Status | Code | Meaning |
|---|---|---|
| 400 | invalid_params | A parameter failed the action's schema. details names the field. |
| 401 | unauthenticated | No valid session or token. |
| 403 | forbidden | Signed in, but not allowed to run this action on this resource. |
| 403 | step_up_required | A high-risk or critical action needs a fresh confirmation first. |
| 404 | not_found | The resource does not exist, or is outside what you can see. |
| 409 | conflict | The change clashes with existing state, such as a name already taken. |
| 422 | limit_exceeded | A plan limit would be exceeded. details names the limit. |
| 422 | precondition_failed | Something the action needs is missing, such as a DNS zone for a wildcard certificate. |
| 429 | rate_limited | Too many requests. Try again later. |
| 502 | agent_unreachable | The server that should do the work did not answer. The desired state is kept for reconcile. |
| 500 | internal | An unexpected error, logged with the request id. |
Live events
GET /api/v1/events is a server-sent event stream of what modules emit (domains.created,
ssl.cert.issued, security.firewall.reverted and so on), filtered to what you are allowed to
see. The panel's live activity uses the same stream.
Coming soon A generated OpenAPI document, the respirecloudctl command-line tool, webhooks, and ready code snippets in eight languages.
Actions by module
| Module | Actions | Can preview | Change something |
|---|---|---|---|
| AI assistant and services | 37 | 0 | 20 |
| Apps | 35 | 7 | 19 |
| Backups | 23 | 5 | 14 |
| Branding | 27 | 7 | 14 |
| CDN | 37 | 19 | 22 |
| Cluster | 44 | 15 | 28 |
| Containers | 25 | 5 | 15 |
| Databases | 46 | 18 | 31 |
| DNS | 40 | 22 | 27 |
| Domain providers | 29 | 7 | 16 |
| Domains | 5 | 2 | 3 |
| Editor | 16 | 0 | 9 |
| Files and SSH | 27 | 1 | 19 |
| Hosting accounts | 18 | 8 | 12 |
| Importers | 7 | 2 | 4 |
| Integrations | 22 | 0 | 16 |
| Logs | 11 | 0 | 5 |
| 55 | 17 | 41 | |
| Mobile app | 5 | 0 | 2 |
| Plans and sizing | 15 | 6 | 9 |
| Security | 39 | 5 | 27 |
| Software | 39 | 14 | 23 |
| SSL | 17 | 4 | 12 |
| Stats | 15 | 0 | 7 |
| Storage | 27 | 4 | 15 |
| Store and licence | 22 | 1 | 13 |
| Terminal | 7 | 0 | 4 |
| Webmail | 39 | 0 | 24 |
| Websites | 40 | 19 | 27 |