PUT · SSL / TLS
Hold an HSTS change for confirmation
Hold an HSTS change for confirmation
/api/v1/ssl/hsts
This scope is inferred from the method and the endpoint's group — the OpenAPI document does
not carry one per operation. The wire is authoritative; whoami reports what your
token actually holds.
Description
Validates the request and returns {status:"confirmation_required", confirmationUrl, …}. It applies nothing on this call. HSTS is a sticky browser commitment that is hard to undo, which is why it is held. Note: HSTS enforcement is not available on the current DirectAdmin nodes.
Body
Send as application/json.
| Name | Type | Description |
|---|---|---|
input
required
|
string |
A domain, email address, website URL, or Inleed service id — for example example.se, [email protected] or 42976. Resolved to the owning account automatically, and the resolved target is echoed back in the response. Up to 255 characters.
|
enabled
required
|
boolean | |
max_age
|
integer | Range 0–63072000. |
include_subdomains
|
boolean | |
attempt_key
|
string | Idempotency key for this intent. Keep it stable across retries so a timed-out retry cannot buy the same thing twice. Up to 128 characters. |
Responses
A 200 response returns the shape shown in the rail.
Every non-2xx response is an RFC 7807 problem with a stable
code.
Commonly returned errors
The codes this operation reaches on its own path: the auth stack, its own validation and
ownership checks, and the transport. Not a closed set — a shared code from the
full registry can still surface. Each links to the code’s own page,
the same URL its type dereferences to.