compute

POST /v1/compute/servers/{serverId}/terminal

Mint a single-use ticket for one web terminal session on a server.

All compute endpoints

All developer docs

Authentication

Send an API key as a bearer token. The key must carry the sites.restart permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/compute/servers/{serverId}/terminal \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{  }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

⛔⛔ The ticket is a credential: one use, sixty seconds. Open wss://<this API's host><path> and send it as the FIRST message — {"type":"auth","ticket":"…","cols":N,"rows":N} — never in the URL, which access logs keep. After that, binary frames are keystrokes and terminal output; text frames are {"type":"resize",…} from the client and {"type":"status","state","code","message"} from the gateway. The gateway logs in over SSH with the organisation's terminal key and pins the machine's host key on first use; a changed key is refused (code: host_key_changed). Every ticket, connection, failure and close is audit-logged — who, when, how long and how many bytes, never what was typed. 422 when the terminal is off, the login name is not one a server accepts, or the machine has no public address. Requires sites.restart.

Parameters

NameTypeRequiredWhat it is
serverId (path)UuidYesThe server's id, as listComputeServers reports it. Ours (UUIDv7), minted when the order row was written — never the provider's own identifier for the machine.

Request body

NameTypeRequiredWhat it is
usernamestringNoThe login name. "" means root.

Response

NameTypeRequiredWhat it is
ticketstringYes
pathstringYesThe gateway path on this API's host — connect to wss://<host><path>.
expires_atintegerYesUnix seconds.
hoststringYesThe machine address the gateway will connect to.
usernamestringYes

Errors this endpoint can return

401 · 403 · 404 · 422 · 429 · 503