POST · Applications
Get a WordPress site's status or run a site-wide action
Get a WordPress site's status or run a site-wide action
/api/v1/wordpress/site
This scope is inferred from the method and the endpoint's group — the OpenAPI document does
not carry one per operation. The wire is authoritative; whoami reports what your
token actually holds.
Description
action=status returns status {version, updateAvailable, latestVersion, home, siteUrl, theme, plugins, pages, posts, permalinkStructure, phpVersion} and needs only read access. The writes need write:hosting: update_core, update_plugins, update_themes, flush_cache, flush_rewrites, verify_checksums, set_custom_css (css, ≤ 80 KB — replaces the customizer's Additional css and returns {changed, postId}), and search_replace (search, replace; dry_run defaults to true and only reports replacements — with dry_run:false it returns {status:"confirmation_required", confirmationUrl, …} and runs nothing here).
Body
Send as application/json.
| Name | Type | Description |
|---|---|---|
input
required
|
string |
A domain, email address, website URL, or Inleed service id — for example example.se, [email protected] or 42976. Resolved to the owning account automatically, and the resolved target is echoed back in the response.
|
Responses
The specification does not describe this response body; the note in the rail says what to expect.
Every non-2xx response is an RFC 7807 problem with a stable
code.
Commonly returned errors
The codes this operation reaches on its own path: the auth stack, its own validation and
ownership checks, and the transport. Not a closed set — a shared code from the
full registry can still surface. Each links to the code’s own page,
the same URL its type dereferences to.