Skip to main content
POST
Install or deploy a plugin

Authorizations

Authorization
string
header
required

Personal API token, sent as Authorization: Bearer <SANDYWP_API_KEY>. Obtain one from the dashboard account menu (API keys), sandywp auth login, or POST /api/account/tokens. A missing or invalid token returns 401 auth_required. Scoped OAuth tokens are limited to the Imports family and GET /api/account/me; see the top-level conventions.

Headers

X-SandyWP-Workspace
string

Selects which of the caller's workspaces to act in, for accounts belonging to more than one (legacy alias: X-SandyWP-Organization). Defaults to the caller's own personal workspace when omitted. Every id in this API (sandboxes, Templates, repositories) is scoped to a single workspace, so this header changes which set of resources is visible.

Path Parameters

id
string
required

The sandbox id.

Body

file
file
required

The plugin ZIP file. Capped at 50MB (413 plugin_too_large above that).

Response

The plugin install/deploy job was queued.

The queued plugin install/deploy job. Exactly one of artifactId (ZIP upload / artifact reuse) or pluginSlug (wordpress.org install) is present, mirroring which request variant was used.

jobId
string
required
artifactId
string

Present when the source was a ZIP upload or a reused artifactId.

pluginSlug
string

Present when the source was a wordpress.org pluginSlug.