POST · Meta & discovery
Run one shell command as the account user
Run one shell command as the account user
/api/v1/shell/run
Description
Returns {command, cwd, exitCode, stdout, stderr, truncated:{stdout,stderr}, timedOut, durationMs, target}. A destructive command returns {status:"confirmation_required", …} instead and runs nothing until the customer approves.
Body
Send as application/json.
| Name | Type | Description |
|---|---|---|
input
required
|
string |
A domain, email address, website URL, or Inleed service id — for example example.se, [email protected] or 42976. Resolved to the owning account automatically, and the resolved target is echoed back in the response.
|
attempt_key
|
string | Idempotency key for this intent. Keep it stable across retries so a timed-out retry cannot buy the same thing twice. |
command
required
|
string |
The bash command line to run, exactly as the customer would type it (≤ 4000 chars). Pipes, redirects and && are fine; interactive programs are not.
|
cwd
|
string |
Working directory, relative to the account home (/ = home), e.g. /domains/example.se/public_html.
|
timeout
|
integer | Seconds before the command is killed (1–45, default 30). Keep commands short; a long job should be narrowed, not extended. |
Responses
The specification does not describe this response body; the note in the rail says what to expect.
Every non-2xx response is an RFC 7807 problem with a stable
code.
Commonly returned errors
The codes this operation reaches on its own path: the auth stack, its own validation and
ownership checks, and the transport. Not a closed set — a shared code from the
full registry can still surface. Each links to the code’s own page,
the same URL its type dereferences to.