# POST /api/v1/wordpress/staging

> Create or push a WordPress staging copy

- Group: applications
- Tier: W
- Required scope: write:hosting
- Docs: https://api.inleed.com/reference/applications/manage-wordpress-staging

## Description

`action:create` clones `install_id` to a staging path and returns the result immediately. `action:push` syncs a `staging_id` copy back over `install_id` (production) — it overwrites production, so it returns `{status:"confirmation_required", confirmationUrl, …}` and syncs nothing on this call; show the human the URL to approve.

## Body

- `input` — string (required). A domain, email address, website URL, or Inleed service id — for example example.se, info@example.se or 42976. Resolved to the owning account automatically, and the resolved target is echoed back in the response.
- `install_id` — string (required). The production install, from list_wordpress_installs (installs[].id) — the clone source for create, the overwrite destination for push.
- `action` — enum (required). create to clone production to a staging copy; push to sync a staging copy back over production (overwrites production — confirmation-tier). One of create, push.
- `staging_id` — string. Required for push: the staging install to sync from, from list_wordpress_installs.
- `target_domain` — string. Optional for create: the domain to stage on. Omit to use the install's own domain.
- `target_path` — string. Up to 64 characters. Pattern ^[A-Za-z0-9._\/-]+$.
- `attempt_key` — string. Idempotency key for this intent. Keep it stable across retries so a timed-out retry cannot buy the same thing twice. Up to 128 characters.

## Request

```bash
curl -X POST "https://mcp.inleed.com/api/v1/wordpress/staging" \
  -H "Authorization: Bearer inl_live_…" \
  -H "Content-Type: application/json" \
  -d '{"input":"example.se","install_id":"res_01hx8n3k5p7q9r2s4t6v8w0y45","action":"create","staging_id":"res_01hx8n3k5p7q9r2s4t6v8w0y46","target_domain":"example.se","target_path":"example.se","attempt_key":"example.se"}'
```

## Errors

- **400**  — codes: invalid_request
- **401** No token was presented, or the token is revoked, expired or unknown. — codes: unauthorized, token_expired, token_revoked
- **403** The token lacks a required scope, or this account does not own the resource. — codes: insufficient_scope, domain_not_owned
- **404** No such resource for this account. — codes: not_found
- **422** Validation error — codes: validation_failed
- **429** The rate limit for this token is exhausted. See `Retry-After`. — codes: rate_limited
- **500** Something went wrong on our side. The failure is logged against `requestId`. — codes: internal_error

