Install or deploy a plugin
Installs & activates a plugin on a ready, account-owned sandbox (async deploy_plugin job — poll with the returned jobId via the GET operation below). Accepts one of three request shapes: a multipart/form-data upload of a plugin ZIP, a JSON body naming a pluginSlug to install from wordpress.org, or a JSON body naming a previously-uploaded artifactId to redeploy. Not available on guest-owned sandboxes.
Authorizations
Personal API token, sent as Authorization: Bearer <SANDYWP_API_KEY>. Obtain one from the dashboard account menu (API keys), sandywp auth login, or POST /api/account/tokens. A missing or invalid token returns 401 auth_required. Scoped OAuth tokens are limited to the Imports family and GET /api/account/me; see the top-level conventions.
Headers
Selects which of the caller's workspaces to act in, for accounts belonging to more than one (legacy alias: X-SandyWP-Organization). Defaults to the caller's own personal workspace when omitted. Every id in this API (sandboxes, Templates, repositories) is scoped to a single workspace, so this header changes which set of resources is visible.
Path Parameters
The sandbox id.
Body
The plugin ZIP file. Capped at 50MB (413 plugin_too_large above that).
Response
The plugin install/deploy job was queued.
The queued plugin install/deploy job. Exactly one of artifactId (ZIP upload / artifact reuse) or pluginSlug (wordpress.org install) is present, mirroring which request variant was used.

