Client area

PUT · SSL / TLS

Hold an HSTS change for confirmation

Hold an HSTS change for confirmation

PUT /api/v1/ssl/hsts
W Write

This scope is inferred from the method and the endpoint's group — the OpenAPI document does not carry one per operation. The wire is authoritative; whoami reports what your token actually holds.

Description

Validates the request and returns {status:"confirmation_required", confirmationUrl, …}. It applies nothing on this call. HSTS is a sticky browser commitment that is hard to undo, which is why it is held. Note: HSTS enforcement is not available on the current DirectAdmin nodes.

Body

Send as application/json.

Name Type Description
input required string A domain, email address, website URL, or Inleed service id — for example example.se, [email protected] or 42976. Resolved to the owning account automatically, and the resolved target is echoed back in the response. Up to 255 characters.
enabled required boolean
max_age integer Range 0–63072000.
include_subdomains boolean
attempt_key string Idempotency key for this intent. Keep it stable across retries so a timed-out retry cannot buy the same thing twice. Up to 128 characters.

Responses

A 200 response returns the shape shown in the rail. Every non-2xx response is an RFC 7807 problem with a stable code.

Commonly returned errors

The codes this operation reaches on its own path: the auth stack, its own validation and ownership checks, and the transport. Not a closed set — a shared code from the full registry can still surface. Each links to the code’s own page, the same URL its type dereferences to.

401 No token was presented, or the token is revoked, expired or unknown.
403 The token lacks a required scope, or this account does not own the resource.
404 No such resource for this account.
422 Validation error
429 The rate limit for this token is exhausted. See `Retry-After`.
500 Something went wrong on our side. The failure is logged against `requestId`.
Esc
navigate open Esc close