API and actions

The panel, the command palette and your scripts all call the same actions. If you can do it in the panel, you can do it from code.

One registry for everything

Every module declares its actions in its manifest: an id, a title, a permission, a risk level, whether it changes anything, whether it can preview itself, and a JSON schema for its parameters and result. Today's build has 769 actions across 29 modules, 188 of which can run as a dry run. Here is a real one, from the domains module:

- id: domains.create
  title: Add a domain
  permission: domains.manage
  risk: low
  mutates: true
  dry_run: true
  inverse: domains.delete
  params: schemas/create.params.json
  result: schemas/domain.json

The host checks the permission, the parameters (strict: unknown fields are refused), plan limits and risk before the module sees the call, and writes the audit row. The menu, the forms, the command palette and the API all come from the same entries.

Calling an action

Every action is a POST to its id, with the parameters as the JSON body. Reads are actions too.

curl -s https://panel.example.com:7443/api/v1/a/domains.list \
  -H "Authorization: Bearer $RC_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"limit": 50}'
  • GET /api/v1/actions lists the actions you may run, with their schemas.
  • GET /api/v1/modules lists the installed modules.
  • Send an Idempotency-Key header with changes you might retry.

Previewing a change

Add ?dry_run=1 to any action that supports it. Nothing changes; you get back a plan with the targets and their diffs, the same plan the panel shows before Apply changes. Dry runs are not recorded as changes.

curl -s "https://panel.example.com:7443/api/v1/a/domains.create?dry_run=1" \
  -H "Authorization: Bearer $RC_TOKEN" -H "Content-Type: application/json" \
  -d '{"name": "shop.example.com", "kind": "addon", "account_id": "…"}'

Actions that can be undone also name their inverse (for example domains.create is undone by domains.delete).

Signing in from code

  • API tokens: send Authorization: Bearer <token>. Tokens are created on your Security page, scoped, and revocable at once. They can never change sign-in settings.
  • Browser sessions use a secure, HTTP-only cookie plus a CSRF header on every call.
  • Every method and path is denied unless an action allows it.

Errors

Every error has the same shape:

{"error": {"code": "limit_exceeded", "message": "…", "details": {}, "request_id": "…"}}
StatusCodeMeaning
400 invalid_params A parameter failed the action's schema. details names the field.
401 unauthenticated No valid session or token.
403 forbidden Signed in, but not allowed to run this action on this resource.
403 step_up_required A high-risk or critical action needs a fresh confirmation first.
404 not_found The resource does not exist, or is outside what you can see.
409 conflict The change clashes with existing state, such as a name already taken.
422 limit_exceeded A plan limit would be exceeded. details names the limit.
422 precondition_failed Something the action needs is missing, such as a DNS zone for a wildcard certificate.
429 rate_limited Too many requests. Try again later.
502 agent_unreachable The server that should do the work did not answer. The desired state is kept for reconcile.
500 internal An unexpected error, logged with the request id.

Live events

GET /api/v1/events is a server-sent event stream of what modules emit (domains.created, ssl.cert.issued, security.firewall.reverted and so on), filtered to what you are allowed to see. The panel's live activity uses the same stream.

Coming soon A generated OpenAPI document, the respirecloudctl command-line tool, webhooks, and ready code snippets in eight languages.

Actions by module

ModuleActionsCan previewChange something
AI assistant and services 37 0 20
Apps 35 7 19
Backups 23 5 14
Branding 27 7 14
CDN 37 19 22
Cluster 44 15 28
Containers 25 5 15
Databases 46 18 31
DNS 40 22 27
Domain providers 29 7 16
Domains 5 2 3
Editor 16 0 9
Files and SSH 27 1 19
Hosting accounts 18 8 12
Importers 7 2 4
Integrations 22 0 16
Logs 11 0 5
Mail 55 17 41
Mobile app 5 0 2
Plans and sizing 15 6 9
Security 39 5 27
Software 39 14 23
SSL 17 4 12
Stats 15 0 7
Storage 27 4 15
Store and licence 22 1 13
Terminal 7 0 4
Webmail 39 0 24
Websites 40 19 27