Create a sandbox from a Blueprint
Creates a sandbox and queues a Blueprint run. Poll the returned run and Site until they reach a terminal state.
Authorizations
Personal API token, sent as Authorization: Bearer <SANDYWP_API_KEY>. Obtain one from the dashboard account menu (API keys), sandywp auth login, or POST /api/account/tokens. A missing or invalid token returns 401 auth_required. Scoped OAuth tokens are limited to the Imports family and GET /api/account/me; see the top-level conventions.
Headers
Selects which of the caller's workspaces to act in, for accounts belonging to more than one (legacy alias: X-SandyWP-Organization). Defaults to the caller's own personal workspace when omitted. Every id in this API (sandboxes, Templates, repositories) is scoped to a single workspace, so this header changes which set of resources is visible.
Path Parameters
The Blueprint id.
Body
Defaults to the Blueprint name.
The sandbox's lifespan, interpreted per expirationMode. With expirationMode: fixed: 1h, 1d, 1w (default), 2w, 1m, or permanent. With expirationMode: inactivity: 10m, 30m, 1h, or 1d (there is no inactivity-mode permanent — a 400 invalid_expiration rejects that combination). 2w, 1m, and permanent additionally require a paid plan (402 duration_requires_paid_plan / 402 permanent_requires_paid_plan).
10m, 30m, 1h, 1d, 1w, 2w, 1m, permanent fixed expires a demo/idle-mode sandbox after a fixed lifetime from creation/launch; inactivity renews the deadline while it is actively used.
fixed, inactivity Optional worker selection where the account is permitted to choose one.
Response
The new Site and its queued Blueprint run.
The owner-facing view of a sandbox. Strips internal provisioning details (container/DB names, password hash, warm-pool ids, routing) and keeps only what a caller needs to use and log into the sandbox.
One execution of a Blueprint in create, apply, or bake mode. Poll this resource to follow asynchronous Blueprint work.

