hosting

POST /v1/sites/{siteId}/wordpress/cli

Run one allow-listed WP-CLI command on the site.

모든 hosting 엔드포인트

모든 개발자 문서

인증

Bearer 토큰으로 API 키를 전송하세요. 키는 반드시 sites.view 권한을 가지고 있어야 하며, 권한이 없는 키는 404가 아닌 403으로 거부됩니다.

이 엔드포인트는 조직 ID를 받지 않습니다. 사용자의 키가 이미 속한 조직을 식별하며, 응답은 해당 조직으로 한정됩니다.

무료 체험하기

대괄호 안에 있는 모든 내용을 사용자 지정 값으로 바꾸고, 키 플레이스홀더는 대시보드의 키로 바꾸세요.

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/wordpress/cli \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "command": <string> }'

로그인하셨나요? 대시보드의 API 콘솔이 실제 조직 ID와 본인의 키를 자동으로 채우고 라이브 API를 대상으로 요청을 실행하므로 실제 응답을 확인할 수 있습니다. API 콘솔에서 이 엔드포인트를 여세요

상세 정보

An audited WP-CLI console. Every invocation is recorded in the site's WordPress activity log with its argv and exit code — never its output. ⛔ Allow-listed, never arbitrary. An unrestricted passthrough is remote code execution as the site user: wp eval runs arbitrary PHP, wp db query runs arbitrary SQL, and wp --require=/tmp/x.php loads code the caller chose before WP-CLI decides what to do. The permitted commands are reads and idempotent cache operations, listed by listWordPressCliCommands; anything else answers 422 naming the whole list. ⛔ config get and config list are deliberately absent — they read wp-config.php, whose constants include the database password and the authentication salts. ⛔ A non-zero exit_code still answers 200. The console's product is what WP-CLI said, and mapping a bad argument onto a 4xx would put our error page over the diagnosis the customer asked for. A 422 means we refused the command, which is a different answer. ⛔ The command travels in the body, not the path, so it never reaches a proxy or edge access log — option get names options a plugin may have stored a credential in. ⛔ Fleet only — refused where wp_cli is false. Requires sites.view and sites.panel_access.

매개변수

이름유형필수설명
siteId (path)UuidSite ID (UUIDv7).

요청 본문

이름유형필수설명
commandstringThe WP-CLI command, with or without a leading wp.

응답

이름유형필수설명
argvstring[]What actually ran, after the allow-list normalised it — echoed back so wp plugin list and plugin list are visibly the same command.
exit_codeintegerWP-CLI's exit code. 0 is success.
stdoutstringWhat WP-CLI printed, up to the console's cap.
stderrstringWP-CLI's diagnostics, carried separately and never merged into stdout — WP-CLI writes PHP notices here on runs that succeed, so folding them together would corrupt the JSON…
truncatedbooleanTrue when stdout was cut at the cap. ⛔ Stated rather than hidden: a silently cut-off JSON document is worse than none, because it nearly parses.

이 엔드포인트가 반환할 수 있는 오류

401 · 403 · 404 · 422 · 429 · 503