BuyNow
Order one supported VM or container product with an explicit OS and optional compatible application recipe.
Endpoint: https://sive.host/modules/addons/shapi/sh-api.php
Method: POST using application/x-www-form-urlencoded.
Consequential action: may purchase, delete, replace credentials, or remove data. Access is limited to directly owned records or explicitly assigned Partner-managed client services after both relationships are verified.
Important behavior
- The account must have sufficient credit for the selected product and cycle.
- SHAPI validates the app belongs to the product and OS policy; omission always records the safe None selection.
Request parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | Exact SHAPI action name shown in this article. |
api_key | string | Yes | Client API key generated in the Sive.Host SHAPI page. |
api_secret | string | Yes | Secret paired with the API key. Send it only in the POST body. |
pid | product alias | Yes | Supported compute product alias from Product Codes. |
os | OS alias | Yes | Supported operating-system alias from Operating System Codes. |
app_option_id | positive integer | No | Compatible application ID returned by ListComputeOrderOptions. Omit to explicitly select App=None. |
hostname | domain/hostname | Yes | Hostname for the new server. |
username | string | Yes | Initial system username. |
rootpw | string | Yes | Initial strong root password. |
sshkey | string | No | Optional SSH public key. |
billingcycle | string | Yes | Supported billing cycle, normally monthly. |
nameserver1 | domain name | No | First nameserver. |
nameserver2 | domain name | No | Second nameserver. |
Example request
Set the four environment variables from the authenticated SHAPI page. Do not put credentials in source control or URLs.
curl --request POST 'https://sive.host/modules/addons/shapi/sh-api.php' \
--user "${SHAPI_HTTP_USER}:${SHAPI_HTTP_PASSWORD}" \
--header 'Accept: application/json' \
--data-urlencode "action=BuyNow" \
--data-urlencode "api_key=${SHAPI_API_KEY}" \
--data-urlencode "api_secret=${SHAPI_API_SECRET}" \
--data-urlencode "pid=benueriver" \
--data-urlencode "os=alma8" \
--data-urlencode "hostname=server.example.com" \
--data-urlencode "username=customer" \
--data-urlencode "rootpw=${NEW_ROOT_PASSWORD}" \
--data-urlencode "billingcycle=monthly"Response
SHAPI always returns JSON. Check result; panel responses can vary by the server module and DirectAdmin version.
{
"result": "success",
"orderid": 1001,
"serviceid": [
2001
],
"invoiceid": 3001,
"os_template": "ubuntu24.04lts",
"app": {
"name": "None",
"default_none": true
}
}Common errors
Unauthorized access!: source IP or HTTP Basic authentication failed.Invalid API Key or secret.: the customer key is wrong, disabled, or deleted.Unable to retrieve an active service owned by this client.: the service is inactive or belongs to another client.Missing required parameters.: one or more required fields were omitted.
SHAPI documentation version 2.0 — generated from the current endpoint contract.

