Account & Team
API endpoints
Every endpoint an API token can call, and the permission each needs
These are the 171 endpoints you can call with an API token on https://api.magicwp.io. Every path starts with /v1. Anything not listed here answers 404 on the API host: member management, payments, plan purchases and your account settings stay in the dashboard.
The Permission column is what the token must carry, and what your role in the workspace must allow. Any member means any role; any token means any valid token, for catalogue data that is the same for everyone. Site permissions apply to the site in the path.
Sites
| Endpoint | What it does | Permission |
|---|---|---|
GET /v1/sites | List the workspace's sites | any member; lists only the sites you reach |
POST /v1/sites | Create a new site | sites.create |
POST /v1/sites/demo | Create the workspace's demo site | sites.create |
GET /v1/sites/limits | Check site creation limits | any member; plan figures only with billing.view; can_create needs sites.create |
GET /v1/sites/{site_id} | Get site details | site.view |
PATCH /v1/sites/{site_id} | Update site settings (status 'deleted' deletes the site) | site.view to reach; per field: site_label → site.notes, maintenance_mode → site.power, status: deleted → site.delete |
GET /v1/sites/{site_id}/activity | List activity for a site | site.view; IP addresses only with activity.view |
POST /v1/sites/{site_id}/clone | Clone a site into a new site | site.view on the source + sites.create |
POST /v1/sites/{site_id}/clone-into | Clone a site into an existing site | site.view on the source + site.restore on the target |
POST /v1/sites/{site_id}/fix | Fix the site (re-run Redis and MagicWP plugin setup) | site.power |
PATCH /v1/sites/{site_id}/notes | Edit the site's notes | site.notes |
PATCH /v1/sites/{site_id}/quota | Change the site's storage quota | site.performance; the plan's storage check needs billing.view |
POST /v1/sites/{site_id}/reset | Reset site (wipe data, reinstall WordPress) | site.restore |
POST /v1/sites/{site_id}/restart | Restart the site's services | site.power |
GET /v1/sites/{site_id}/tasks | List a site's tasks, newest first | site.view |
WordPress
| Endpoint | What it does | Permission |
|---|---|---|
GET /v1/sites/{site_id}/wp/auto-update | Get WordPress core auto-update status | site.view |
POST /v1/sites/{site_id}/wp/auto-update | Enable or disable WordPress core auto-update | wp.updates |
POST /v1/sites/{site_id}/wp/auto-update/bulk | Bulk enable/disable theme/plugin auto-update | wp.updates |
GET /v1/sites/{site_id}/wp/auto-update/extended | Bulk theme/plugin auto-update status | site.view |
POST /v1/sites/{site_id}/wp/cache/flush | Flush cache | site.power |
GET /v1/sites/{site_id}/wp/cache/redis | Get Redis object-cache plugin status | site.view |
POST /v1/sites/{site_id}/wp/cache/redis | Toggle Redis object cache (enable/disable) | site.performance |
POST /v1/sites/{site_id}/wp/cache/redis/install | Install Redis object-cache plugin | site.performance |
GET /v1/sites/{site_id}/wp/core/check | Check for WordPress updates | site.view |
POST /v1/sites/{site_id}/wp/core/update | Update WordPress core | wp.updates |
POST /v1/sites/{site_id}/wp/core/verify-checksums | Verify WordPress core file checksums | wp.updates |
POST /v1/sites/{site_id}/wp/database/cleanup | Delete database clutter | database.manage |
POST /v1/sites/{site_id}/wp/database/optimize | Optimize database tables | database.manage |
GET /v1/sites/{site_id}/wp/database/stats | Table sizes, overhead and cleanup counts | site.view |
POST /v1/sites/{site_id}/wp/db-prefix | Change the database table prefix | database.manage |
GET /v1/sites/{site_id}/wp/debug | Get WordPress debug constants | site.view |
POST /v1/sites/{site_id}/wp/debug | Set WordPress debug constants | wp.settings |
GET /v1/sites/{site_id}/wp/magic-link | Generate admin magic login link | wp.login |
GET /v1/sites/{site_id}/wp/maintenance | Get WordPress maintenance mode status | site.view |
POST /v1/sites/{site_id}/wp/maintenance | Toggle WordPress maintenance mode | site.power |
GET /v1/sites/{site_id}/wp/plugins | List installed plugins | site.view |
POST /v1/sites/{site_id}/wp/plugins/activate | Activate a plugin | wp.extensions |
POST /v1/sites/{site_id}/wp/plugins/auto-update | Enable or disable auto-update for a plugin | wp.updates |
POST /v1/sites/{site_id}/wp/plugins/deactivate | Deactivate a plugin | wp.extensions |
POST /v1/sites/{site_id}/wp/plugins/delete | Delete plugins | wp.extensions |
POST /v1/sites/{site_id}/wp/plugins/install | Install plugins | wp.extensions |
GET /v1/sites/{site_id}/wp/plugins/search | Search WordPress.org plugin directory | wp.extensions |
POST /v1/sites/{site_id}/wp/plugins/update | Update plugin(s) | wp.updates |
POST /v1/sites/{site_id}/wp/search-replace | Search and replace in database | database.manage |
POST /v1/sites/{site_id}/wp/search-replace/dry-run | Preview search and replace | database.manage |
GET /v1/sites/{site_id}/wp/settings | Get WordPress settings | site.view |
PATCH /v1/sites/{site_id}/wp/settings | Update WordPress settings | wp.settings |
POST /v1/sites/{site_id}/wp/shuffle-salts | Regenerate wp-config.php keys and salts | wp.settings |
GET /v1/sites/{site_id}/wp/themes | List installed themes | site.view |
POST /v1/sites/{site_id}/wp/themes/activate | Activate a theme | wp.extensions |
POST /v1/sites/{site_id}/wp/themes/auto-update | Enable or disable auto-update for a theme | wp.updates |
POST /v1/sites/{site_id}/wp/themes/delete | Delete themes | wp.extensions |
POST /v1/sites/{site_id}/wp/themes/install | Install themes | wp.extensions |
GET /v1/sites/{site_id}/wp/themes/search | Search WordPress.org theme directory | wp.extensions |
POST /v1/sites/{site_id}/wp/themes/update | Update theme(s) | wp.updates |
GET /v1/sites/{site_id}/wp/users | List WordPress users | wp.users |
POST /v1/sites/{site_id}/wp/users | Create a WordPress user | wp.users |
POST /v1/sites/{site_id}/wp/users/reset-password | Reset WordPress user password | wp.users |
DELETE /v1/sites/{site_id}/wp/users/{wp_user_id} | Delete a WordPress user | wp.users |
POST /v1/sites/{site_id}/wp/users/{wp_user_id} | Update a WordPress user | wp.users |
POST /v1/sites/{site_id}/wp/users/{wp_user_id}/password | Set a WordPress user's password | wp.users |
POST /v1/sites/{site_id}/wp/users/{wp_user_id}/role | Set a WordPress user's role | wp.users |
PHP
| Endpoint | What it does | Permission |
|---|---|---|
GET /v1/sites/{site_id}/php | Get current PHP version | site.view |
GET /v1/sites/{site_id}/php/extensions | List toggleable PHP extensions and their state | site.view |
PATCH /v1/sites/{site_id}/php/extensions | Enable/disable PHP extensions | site.performance |
GET /v1/sites/{site_id}/php/fpm | Get PHP-FPM (www.conf) settings | site.view |
PATCH /v1/sites/{site_id}/php/fpm | Update PHP-FPM (www.conf) settings | site.performance |
GET /v1/sites/{site_id}/php/ini | Get php.ini settings | site.view |
PATCH /v1/sites/{site_id}/php/ini | Update php.ini settings | site.performance |
GET /v1/sites/{site_id}/php/opcache | Get OPcache status | site.view |
POST /v1/sites/{site_id}/php/opcache/reset | Reset (flush) OPcache | site.power |
POST /v1/sites/{site_id}/php/reset | Reset php.ini and PHP-FPM config to defaults | site.performance |
POST /v1/sites/{site_id}/php/version | Change PHP version | site.performance |
Caching (nginx)
| Endpoint | What it does | Permission |
|---|---|---|
POST /v1/sites/{site_id}/nginx/cache/flush | Flush nginx FastCGI cache | site.power |
GET /v1/sites/{site_id}/nginx/cache/ttl | Get page cache expiration (TTL) | site.view |
POST /v1/sites/{site_id}/nginx/cache/ttl | Set page cache expiration (TTL) | site.performance |
GET /v1/sites/{site_id}/nginx/features | List nginx feature statuses | site.view |
POST /v1/sites/{site_id}/nginx/features/{feature} | Toggle nginx feature | site.performance |
Database
| Endpoint | What it does | Permission |
|---|---|---|
GET /v1/sites/{site_id}/database | Get database credentials | credentials.database |
POST /v1/sites/{site_id}/database/change-password | Change database password | credentials.database |
DELETE /v1/sites/{site_id}/database/phpmyadmin | Close the temporary phpMyAdmin session | credentials.database |
GET /v1/sites/{site_id}/database/phpmyadmin | Get temporary phpMyAdmin session status | credentials.database |
POST /v1/sites/{site_id}/database/phpmyadmin | Open a temporary phpMyAdmin session (2 hours) | credentials.database |
SFTP
| Endpoint | What it does | Permission |
|---|---|---|
GET /v1/sites/{site_id}/sftp | Get SFTP credentials | credentials.sftp |
POST /v1/sites/{site_id}/sftp/change-password | Change SFTP password | credentials.sftp |
| Endpoint | What it does | Permission |
|---|---|---|
GET /v1/sites/{site_id}/email-settings | Get email configuration | email.manage |
POST /v1/sites/{site_id}/email-settings/activate | Set active email provider | email.manage |
POST /v1/sites/{site_id}/email-settings/disable | Disable email sending | email.manage |
POST /v1/sites/{site_id}/email-settings/enable | Enable email sending | email.manage |
POST /v1/sites/{site_id}/email-settings/providers | Add or update email provider | email.manage |
PATCH /v1/sites/{site_id}/email-settings/providers/{provider_name} | Update a provider (status='deleted' to remove) | email.manage |
POST /v1/sites/{site_id}/email-settings/test | Send a test email | email.manage |
Domains
| Endpoint | What it does | Permission |
|---|---|---|
GET /v1/sites/{site_id}/domains | List domains for a site | site.view |
POST /v1/sites/{site_id}/domains | Add and verify custom domain | domains.manage |
PATCH /v1/sites/{site_id}/domains/{domain_id} | Update a domain (status='deleted' to remove) | domains.manage |
POST /v1/sites/{site_id}/domains/{domain_id}/connect | Connect domain to site | domains.manage |
POST /v1/sites/{site_id}/domains/{domain_id}/disconnect | Disconnect domain from site | domains.manage |
GET /v1/sites/{site_id}/domains/{domain_id}/records | The DNS records this domain needs | site.view |
POST /v1/sites/{site_id}/domains/{domain_id}/verify | Re-check a pending domain's DNS | domains.manage |
Cloudflare
| Endpoint | What it does | Permission |
|---|---|---|
DELETE /v1/sites/{site_id}/cloudflare | Forget the Cloudflare token | domains.manage |
GET /v1/sites/{site_id}/cloudflare | Cloudflare connection, record and zone settings | site.view |
GET /v1/sites/{site_id}/cloudflare/accounts | Cloudflare accounts this grant can see | domains.manage |
POST /v1/sites/{site_id}/cloudflare/connect | Store a Cloudflare API token and list its zones | domains.manage |
DELETE /v1/sites/{site_id}/cloudflare/dns | Remove the records we wrote, and keep the connection | domains.manage |
POST /v1/sites/{site_id}/cloudflare/dns | Point a domain at this site, and toggle the proxy | domains.manage |
POST /v1/sites/{site_id}/cloudflare/oauth/revoke | Hand the Cloudflare grant back | domains.manage |
POST /v1/sites/{site_id}/cloudflare/purge | Purge the Cloudflare cache, or just some URLs | domains.manage |
PATCH /v1/sites/{site_id}/cloudflare/settings | SSL mode, Always Use HTTPS, development mode | domains.manage |
GET /v1/sites/{site_id}/cloudflare/zones | Zones this token can see | domains.manage |
Redirects
| Endpoint | What it does | Permission |
|---|---|---|
GET /v1/sites/{site_id}/redirects | List redirect rules | site.view |
POST /v1/sites/{site_id}/redirects | Add a redirect rule | redirects.manage |
POST /v1/sites/{site_id}/redirects/bulk | Bulk import redirect rules | redirects.manage |
POST /v1/sites/{site_id}/redirects/bulk-delete | Delete multiple redirect rules | redirects.manage |
DELETE /v1/sites/{site_id}/redirects/{redirect_id} | Delete a redirect rule | redirects.manage |
PATCH /v1/sites/{site_id}/redirects/{redirect_id} | Update a redirect rule | redirects.manage |
Backups
| Endpoint | What it does | Permission |
|---|---|---|
GET /v1/sites/{site_id}/backups | List backups for a site | site.view; download URLs only with backups.manage |
POST /v1/sites/{site_id}/backups/download | Create a download backup | backups.manage |
DELETE /v1/sites/{site_id}/backups/{backup_id} | Delete a download-type backup | backups.manage |
PATCH /v1/sites/{site_id}/backups/{backup_id} | Rename a snapshot | backups.manage |
POST /v1/sites/{site_id}/backups/{backup_id}/download | Export an existing backup for download (emailed link) | backups.manage |
POST /v1/sites/{site_id}/backups/{backup_id}/restore | Restore site from backup | site.restore |
GET /v1/snapshots | List full backups (snapshots) across the workspace's sites | any member; the sites where you hold site.view |
POST /v1/snapshots/{source_backup_id}/restore | Restore a snapshot onto another site | site.view on the source + site.restore on the target |
Staging
| Endpoint | What it does | Permission |
|---|---|---|
GET /v1/sites/{site_id}/staging | This site's staging copy, and whether it may have one | site.view |
POST /v1/sites/{site_id}/staging | Create this site's staging copy | site.staging |
POST /v1/sites/{site_id}/staging/extend | Extend a staging site's expiry | site.staging |
POST /v1/sites/{site_id}/staging/push | Push a staging site over its live site | site.restore |
GET /v1/sites/{site_id}/staging/push-preview | Preview what pushing staging to live will change | site.staging |
GET /v1/sites/{site_id}/staging/revert-points | Backups taken before each push to this site | site.view |
Updates
| Endpoint | What it does | Permission |
|---|---|---|
GET /v1/sites/{site_id}/updates | Updates for one site | site.view |
POST /v1/sites/{site_id}/updates/apply | Update items on one site | wp.updates |
PUT /v1/sites/{site_id}/updates/auto-update | Set auto-update on one site | wp.updates |
POST /v1/sites/{site_id}/updates/check | Check one site against WordPress.org now | wp.updates |
POST /v1/sites/{site_id}/updates/refresh | Re-read one site's local state | site.view |
GET /v1/updates | Updates across every site | site.view on each site |
POST /v1/updates/apply | Update items across sites | wp.updates on each site named |
PUT /v1/updates/auto-update | Set auto-update across sites | wp.updates on each site named |
POST /v1/updates/check | Check several sites against WordPress.org now | wp.updates on each site named |
POST /v1/updates/refresh | Re-read the local state of several sites | site.view on each site named |
Metrics
| Endpoint | What it does | Permission |
|---|---|---|
GET /v1/sites/{site_id}/metrics/daily | Today, ~40-min decimated samples | site.view |
GET /v1/sites/{site_id}/metrics/live | Last 30 raw samples (5-min) | site.view |
GET /v1/sites/{site_id}/metrics/monthly | Last 30 days, daily average | site.view |
Transfers
| Endpoint | What it does | Permission |
|---|---|---|
GET /v1/sites/{site_id}/transfer | Current pending transfer for a site | site.transfer |
POST /v1/sites/{site_id}/transfer | Initiate a site transfer | site.transfer |
POST /v1/sites/{site_id}/transfer/{transfer_id}/cancel | Cancel a pending transfer | site.transfer |
Tasks
| Endpoint | What it does | Permission |
|---|---|---|
GET /v1/tasks | Running tasks across the sites I can reach | any member |
GET /v1/tasks/{task_id} | Get task status | site.view on the task's site |
Workspace
| Endpoint | What it does | Permission |
|---|---|---|
GET /v1/workspace/activity | The workspace activity log | activity.view |
GET /v1/workspaces/current | The current workspace, and what this caller may do in it | any member; billing details only with billing.view |
Billing
| Endpoint | What it does | Permission |
|---|---|---|
POST /v1/coupons/verify | Verify / preview coupon | billing.manage |
GET /v1/invoices | List invoices | billing.view |
GET /v1/invoices/{invoice_id} | One invoice | billing.view |
GET /v1/subscriptions/me | The workspace's subscriptions | billing.view |
POST /v1/subscriptions/preview | Preview subscription price before purchase | billing.manage |
GET /v1/subscriptions/trial-eligibility | Whether the workspace can start a free trial | billing.view |
POST /v1/subscriptions/{sub_id}/addons/preview | Preview addon price before purchase | billing.manage |
POST /v1/subscriptions/{sub_id}/addons/{addon_record_id}/cancel/preview | Preview addon cancellation | billing.manage |
POST /v1/subscriptions/{sub_id}/cancel/preview | Preview cancellation before confirming | billing.manage |
POST /v1/subscriptions/{sub_id}/upgrade/preview | Preview upgrade pricing before confirming | billing.manage |
Support
| Endpoint | What it does | Permission |
|---|---|---|
GET /v1/tickets | List the workspace's tickets | support.view |
POST /v1/tickets | Open a ticket | support.manage |
GET /v1/tickets/{ticket_id} | One ticket with its replies | support.view; IP addresses only to their author or with activity.view |
POST /v1/tickets/{ticket_id}/replies | Reply to a ticket | support.manage |
Catalogue
| Endpoint | What it does | Permission |
|---|---|---|
GET /v1/departments | List support departments | any token |
GET /v1/plans | List plans and their prices | any token |
GET /v1/plans/addons | List add-ons | any token |
GET /v1/sites/domains | List available base domains | any token |
GET /v1/sites/domains/random | Pick a random base domain from the active list | any token |
GET /v1/sites/regions | List server regions available for new sites | any token |
GET /v1/templates | Templates the workspace can build from | any token |
GET /v1/templates/{slug} | One template by slug | any token |
Permission names
The names used above and when you create a token.
| Permission | Applies to | Allows |
|---|---|---|
sites.create | the workspace | Create sites (counts against the plan) |
billing.view | the workspace | See subscription, plan, limits and invoices |
billing.pay | the workspace | Pay invoices with their own card |
billing.manage | the workspace | Subscribe, change plan, addons, coupons, cancel |
support.view | the workspace | See the workspace's tickets |
support.manage | the workspace | Open and reply to tickets |
activity.view | the workspace | See the workspace activity log |
members.view | the workspace | See members and pending invitations |
site.view | every site you can reach | See the site, its metrics, activity and settings |
site.notes | every site you can reach | Edit the site's label and notes |
site.power | every site you can reach | Restart, fix, maintenance mode, flush caches |
site.restore | every site you can reach | Reset, restore backups, overwrite from another site or staging |
site.staging | every site you can reach | Create and extend staging |
site.delete | every site you can reach | Delete the site |
site.transfer | every site you can reach | Transfer the site out of the workspace |
wp.login | every site you can reach | Magic login as a WordPress administrator |
wp.extensions | every site you can reach | Install, activate, deactivate and delete plugins and themes |
wp.updates | every site you can reach | Apply updates and change auto-updates |
wp.settings | every site you can reach | WordPress settings, debug and salts |
wp.users | every site you can reach | Manage WordPress users |
site.performance | every site you can reach | PHP settings, caching and Redis |
domains.manage | every site you can reach | Domains and Cloudflare |
redirects.manage | every site you can reach | Manage redirects |
email.manage | every site you can reach | Email provider settings (holds API keys) |
backups.manage | every site you can reach | Create, download, rename and delete backups |
credentials.sftp | every site you can reach | See and change SFTP credentials |
credentials.database | every site you can reach | See and change database credentials, phpMyAdmin |
database.manage | every site you can reach | Optimize, clean up, change prefix, search-replace |