Skip to main content
POST
Turn SSH on/off, or issue a one-click ephemeral key

Authorizations

Authorization
string
header
required

Personal API token, sent as Authorization: Bearer <SANDYWP_API_KEY>. Obtain one from the dashboard account menu (API keys), sandywp auth login, or POST /api/account/tokens. A missing or invalid token returns 401 auth_required. Scoped OAuth tokens are limited to the Imports family and GET /api/account/me; see the top-level conventions.

Headers

X-SandyWP-Workspace
string

Selects which of the caller's workspaces to act in, for accounts belonging to more than one (legacy alias: X-SandyWP-Organization). Defaults to the caller's own personal workspace when omitted. Every id in this API (sandboxes, Templates, repositories) is scoped to a single workspace, so this header changes which set of resources is visible.

Path Parameters

id
string
required

The sandbox id.

Body

application/json
action
enum<string>
required

Required.

Available options:
set-access,
issue-ephemeral
enabled
boolean

set-access only. Turn SSH on/off. Defaults to true when omitted — only an explicit false disables it.

ttlMinutes
number

issue-ephemeral only. Requested private-key lifetime in minutes; clamped server-side to at most 24h and to the sandbox's remaining life. Defaults to the server's configured default when omitted.

Response

Result of the requested action.

connection
object
required

What a sandbox's owner needs in order to connect over SSH.