Inspect website files

GET /api/v2/shared-hosting/{accountId}/diagnostics/files

Inspect eligible website code and configuration using the existing account-scoped cPanel Fileman API.

Source reads are limited to 1 MiB; large-log tails use the existing FTPS path.

Config files return selected non-secret static settings.

Private data, backups, keys, binary files and symbolic links are excluded by diagnostic policy.

No commands or application code execute.

Search is literal and bounded to 40 file reads, 2 MiB and 1000 entries; truncated results cannot prove absence.

Paths are relative to the verified website root.

Web Hosting Files

Authentication

Required API scopes: read:hostingconsole:services

Authenticate with an API key in the Authorization: Bearer <token> header.

Context

Path Parameters

accountId string required Example: acct_01hxa3b4c5d6e7f8g9h0j1k2m3

Public shared-hosting account ID. Get it from GET /api/v2/shared-hosting data[].id. Do not invent this value; use the exact ID returned by the referenced API response.

Query Parameters

domain string

Exact hosted domain. Defaults to the account main domain.

action string · enum required

What to do with path: list a directory (paged with offset), read one file (source lines, a config's settings, or a log tail), or search the tree for query.

list
read
search
path string · default:

Site-relative directory/file; empty string is the website root.

query string

Required for search only; literal substring, not regex.

startLine integer · min: 1 · max: 100000 · default: 1

First source line for read; cannot combine with tail.

lines integer · min: 1 · max: 200 · default: 100

read only: how many lines to return, counted from startLine or, with tail, from the end of the log. Each line is cut at 2000 characters.

tail boolean · default: false

For log reads only: return the end of the file.

offset integer · min: 0 · max: 100000 · default: 0

List only: use nextOffset to read the next directory page. scanLimited indicates the overall scan cap was reached.

Headers

Authorization Bearer <token>
Accept application/json

Responses

200 Bounded read-only diagnostic snapshot.
domain string required
view string · enum
settings
source
log_tail
entries array<object>
entries[].name string
entries[].type string · enum
file
directory
entries[].sizeBytes integer
entries[].view string · enum
settings
source
settings object
lines array<object>
lines[].line integer · nullable required

One-based source line; null for log tails/settings.

lines[].text string required
matches array<object>
matches[].path string
matches[].line integer · nullable

One-based source line; null for log tails/settings.

matches[].text string
sizeBytes integer
inspectedEntries integer
truncated boolean
notice string
nextOffset integer · nullable

scanLimited boolean
filesRead integer
400 Invalid query or path.

No response body

401 Authentication required.

No response body

403 Scope, domain or protected-path refusal.

No response body

404 Account or website path not found.

No response body

422 File exceeds source read limit.

No response body

429 Rate limited. Retry after the limit resets. 429 responses include Retry-After seconds plus X-RateLimit-* headers.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
500 Internal error. Retry later or contact support if the issue persists.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
502 Diagnostic service unavailable or failed. State remains unknown.

No response body

GET https://cloud.hostup.se/api/v2/shared-hosting/{accountId}/diagnostics/files
For AI assistants
View as Markdown
cURL
curl -X GET "https://cloud.hostup.se/api/v2/shared-hosting/acct_01hxa3b4c5d6e7f8g9h0j1k2m3/diagnostics/files?action=list" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Accept: application/json"
Response
{
  "domain": "shop.example.com",
  "view": "settings",
  "settings": {
    "ps_caching": "CacheMemcached",
    "ps_cache_enable": false
  },
  "sizeBytes": 1005,
  "notice": "Only recognized non-secret static settings; omitted values are unknown."
}