## GET /api/v2/vps/{id}/ssh-access

**Get live VPS SSH access**

Read the actual public-key entries that currently grant SSH access inside the VPS. The inventory includes keys added inside the guest and options-prefixed forced-command entries. Raw key material and forced-command values are not returned. If the VPS is stopped or the guest agent cannot verify the file, `available` is false and `entries` is empty; callers must not substitute saved account keys or cloud-init metadata as a complete access list.

### Related Endpoints

- `PATCH /api/v2/vps/{id}/ssh-access`: Update live VPS SSH access
- `GET /api/v2/vps/{id}`: Get VPS details
- `GET /api/v2/vps/{id}/iso`: List VPS ISO media

### Headers

- `Accept`: application/json
- `Authorization`: Bearer YOUR_API_KEY
- Required API scope: `read:vm`

### Parameters

- `id` (path, string, required): Public VPS ID from `GET /api/v2/vps` `data[].id`. Do not invent this value; use the exact ID returned by the referenced API response. Example: `vps_01hxa3b4c5d6e7f8g9h0j1k2m3`

### Request Example

```bash
curl -X GET "https://cloud.hostup.se/api/v2/vps/vps_01hxa3b4c5d6e7f8g9h0j1k2m3/ssh-access" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Accept: application/json"
```

### Response Schema

- `available` (boolean, required)
- `unavailableReason` (string, required, nullable): Nullable (may be null when not applicable).
  Allowed values: vps_not_ready, vm_not_running, guest_exec_disabled, guest_agent_unavailable, unsupported_guest
- `unavailableMessage` (string, required, nullable): Nullable (may be null when not applicable).
- `loginUser` (string, required): Guest login user whose authorized_keys file was inspected. Example: `root`
- `checkedAt` (string, required)
- `revision` (string, required, nullable): Nullable (may be null when not applicable).
- `entries` (array<object>, required)
- `entries[].id` (string, required)
- `entries[].keyType` (string, required) Example: `ssh-ed25519`
- `entries[].fingerprint` (string, required) Example: `SHA256:exampleFingerprint`
- `entries[].comment` (string, required, nullable): Nullable (may be null when not applicable). Example: `certificate-signer`
- `entries[].restricted` (boolean, required)
- `entries[].restrictions` (array<string>, required)
- `entries[].savedKeyId` (string, required, nullable): Nullable (may be null when not applicable).
- `entries[].savedKeyName` (string, required, nullable): Nullable (may be null when not applicable).
- `savedKeys` (array<object>, required)
- `savedKeys[].id` (string, required)
- `savedKeys[].name` (string, required)
- `savedKeys[].fingerprint` (string, required, nullable): Nullable (may be null when not applicable).
- `savedKeys[].active` (boolean, required)
- `savedKeys[].activeEntryIds` (array<string>, required)

### Responses

#### 200 - Verified live SSH access state, or an explicit unavailable state.
```json
{
  "available": true,
  "unavailableReason": null,
  "unavailableMessage": null,
  "loginUser": "root",
  "checkedAt": "2026-08-13T10:00:00.000Z",
  "revision": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
  "entries": [
    {
      "id": "ak_aaaaaaaaaaaaaaaaaaaaaaaaaa",
      "keyType": "ssh-ed25519",
      "fingerprint": "SHA256:exampleFingerprint",
      "comment": "certificate-signer",
      "restricted": true,
      "restrictions": [
        "forced_command",
        "pty_disabled",
        "port_forwarding_disabled"
      ],
      "savedKeyId": null,
      "savedKeyName": null
    }
  ],
  "savedKeys": []
}
```

#### 400 - Invalid request. The response body is an RFC 7807 Problem Details document.
```json
{
  "type": "https://developer.hostup.se/errors/invalid_request",
  "title": "Invalid request",
  "status": 400,
  "detail": "The request body failed validation.",
  "code": "invalid_request",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z",
  "errors": [
    {
      "pointer": "/items/0/domainName",
      "detail": "`domainName` is required.",
      "code": "invalid_request"
    }
  ]
}
```

#### 401 - Unauthorized. Authentication is required.
```json
{
  "type": "https://developer.hostup.se/errors/unauthorized",
  "title": "Unauthorized",
  "status": 401,
  "detail": "Authentication is required.",
  "code": "unauthorized",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```

#### 403 - Forbidden. The caller lacks a required scope or does not own the resource.
```json
{
  "type": "https://developer.hostup.se/errors/forbidden",
  "title": "Forbidden",
  "status": 403,
  "detail": "The caller lacks a required scope or does not own the resource.",
  "code": "forbidden",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```

#### 404 - Not found. The resource does not exist or is not owned by the caller.
```json
{
  "type": "https://developer.hostup.se/errors/not_found",
  "title": "Not found",
  "status": 404,
  "detail": "The requested resource could not be found.",
  "code": "not_found",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```

#### 429 - Rate limited. Retry after the limit resets. 429 responses include `Retry-After` seconds plus `X-RateLimit-*` headers.
```json
{
  "type": "https://developer.hostup.se/errors/rate_limit_exceeded",
  "title": "Too many requests",
  "status": 429,
  "detail": "Too many requests. Retry after the limit resets.",
  "code": "rate_limit_exceeded",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```

#### 500 - Internal error. Retry later or contact support if the issue persists.
```json
{
  "type": "https://developer.hostup.se/errors/internal_error",
  "title": "Internal server error",
  "status": 500,
  "detail": "An unexpected error occurred. Retry later or contact support if the issue persists.",
  "code": "internal_error",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```
