Overview
The MagicWP API lets scripts, CI pipelines and your own tools do what you do in the dashboard: create and clone sites, take and restore backups, manage domains, redirects and WordPress, apply updates and follow the progress of every action. This section is the full reference, one page per endpoint, generated from the API's own description.
Base URL and authentication
Every request goes to https://api.magicwp.io, with paths starting with
/v1, and carries an API token as a bearer token:
curl https://api.magicwp.io/v1/sites \
-H "Authorization: Bearer mwp_your_token_here"Create a token under Settings → API tokens in the dashboard. A token works in one workspace and can do only what you allowed when you created it (and what your role allows). See API tokens for creating, limiting and revoking tokens.
How the API behaves
- Responses share one shape:
success,data,messageandstatus_code. On an error,codenames it in a way that never changes (not_found,site_busy,permission_denied, …). Program againstcode. - Long-running actions (create, clone, restore, back up, apply updates)
answer at once with a task. Follow it with
GET /v1/tasks/{task_id}. - Retries are safe on heavy actions: send an
Idempotency-Keyheader and a repeated request returns the first answer instead of starting again. - Lists come in pages:
data.itemsanddata.next_cursor, up to 100 per page with?limit=. - Rate limits: 300 reads and 60 writes per minute per token, reported in
the
X-RateLimit-*headers.
The details of each are in API tokens.
Using this reference
Each endpoint page lists its parameters, request body and responses, with example requests in several languages and the permission the token needs. The Try it panel sends a real request from your browser with the token you enter, so it acts on your real sites and workspace.
The same description is available as an OpenAPI 3.1 document at
https://api.magicwp.io/v1/openapi.json,
for Postman, Insomnia, code generators or AI assistants.