## GET /api/v2/shared-hosting/{accountId}/diagnostics/files

**Inspect website files**

Inspect eligible website code and configuration using the existing account-scoped cPanel Fileman API. Source reads are limited to 1 MiB; large-log tails use the existing FTPS path. Config files return selected non-secret static settings. Private data, backups, keys, binary files and symbolic links are excluded by diagnostic policy. No commands or application code execute. Search is literal and bounded to 40 file reads, 2 MiB and 1000 entries; truncated results cannot prove absence. Paths are relative to the verified website root.

### Related Endpoints

- `GET /api/v2/shared-hosting/{accountId}/diagnostics/redis`: Inspect Redis socket metadata
- `GET /api/v2/shared-hosting/{accountId}`: Get shared-hosting account
- `PATCH /api/v2/shared-hosting/{accountId}`: Rename shared-hosting account

### Headers

- `Accept`: application/json
- `Authorization`: Bearer YOUR_API_KEY
- Required API scopes: `read:hosting`, `console:services`

### Parameters

- `domain` (query, string): Exact hosted domain. Defaults to the account main domain.
- `action` (query, string, required): What to do with path: list a directory (paged with offset), read one file (source lines, a config's settings, or a log tail), or search the tree for query.
  Allowed values: list, read, search
- `path` (query, string): Site-relative directory/file; empty string is the website root.
- `query` (query, string): Required for search only; literal substring, not regex.
- `startLine` (query, integer) [min: 1, max: 100000]: First source line for read; cannot combine with tail.
- `lines` (query, integer) [min: 1, max: 200]: read only: how many lines to return, counted from startLine or, with tail, from the end of the log. Each line is cut at 2000 characters.
- `tail` (query, boolean): For log reads only: return the end of the file.
- `offset` (query, integer) [min: 0, max: 100000]: List only: use nextOffset to read the next directory page. scanLimited indicates the overall scan cap was reached.
- `accountId` (path, string, required): Public shared-hosting account ID. Get it from `GET /api/v2/shared-hosting` `data[].id`. Do not invent this value; use the exact ID returned by the referenced API response. Example: `acct_01hxa3b4c5d6e7f8g9h0j1k2m3`

### Request Example

```bash
curl -X GET "https://cloud.hostup.se/api/v2/shared-hosting/acct_01hxa3b4c5d6e7f8g9h0j1k2m3/diagnostics/files?action=list" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Accept: application/json"
```

### Response Schema

- `domain` (string, required)
- `view` (string, optional)
  Allowed values: settings, source, log_tail
- `entries` (array<object>, optional)
- `entries[].name` (string, optional)
- `entries[].type` (string, optional)
  Allowed values: file, directory
- `entries[].sizeBytes` (integer, optional)
- `entries[].view` (string, optional)
  Allowed values: settings, source
- `settings` (object, optional)
- `lines` (array<object>, optional)
- `lines[].line` (integer, required, nullable): One-based source line; null for log tails/settings.
- `lines[].text` (string, required)
- `matches` (array<object>, optional)
- `matches[].path` (string, optional)
- `matches[].line` (integer, optional, nullable): One-based source line; null for log tails/settings.
- `matches[].text` (string, optional)
- `sizeBytes` (integer, optional)
- `inspectedEntries` (integer, optional)
- `truncated` (boolean, optional)
- `notice` (string, optional)
- `nextOffset` (integer, optional, nullable): Nullable (may be null when not applicable).
- `scanLimited` (boolean, optional)
- `filesRead` (integer, optional)

### Responses

#### 200 - Bounded read-only diagnostic snapshot.
```json
{
  "domain": "shop.example.com",
  "view": "settings",
  "settings": {
    "ps_caching": "CacheMemcached",
    "ps_cache_enable": false
  },
  "sizeBytes": 1005,
  "notice": "Only recognized non-secret static settings; omitted values are unknown."
}
```

#### 400 - Invalid query or path.

#### 401 - Authentication required.

#### 403 - Scope, domain or protected-path refusal.

#### 404 - Account or website path not found.

#### 422 - File exceeds source read limit.

#### 429 - Rate limited. Retry after the limit resets. 429 responses include `Retry-After` seconds plus `X-RateLimit-*` headers.
```json
{
  "type": "https://developer.hostup.se/errors/rate_limit_exceeded",
  "title": "Too many requests",
  "status": 429,
  "detail": "Too many requests. Retry after the limit resets.",
  "code": "rate_limit_exceeded",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```

#### 500 - Internal error. Retry later or contact support if the issue persists.
```json
{
  "type": "https://developer.hostup.se/errors/internal_error",
  "title": "Internal server error",
  "status": 500,
  "detail": "An unexpected error occurred. Retry later or contact support if the issue persists.",
  "code": "internal_error",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```

#### 502 - Diagnostic service unavailable or failed. State remains unknown.
