DirectAdminLegacyWrite
Call a user-scoped DirectAdmin legacy CMD_API_* endpoint with POST for an owned DirectAdmin service.
Endpoint: https://sive.host/modules/addons/shapi/sh-api.php
Method: POST using application/x-www-form-urlencoded.
Consequential action: may purchase, delete, replace credentials, or remove data. Access is limited to directly owned records or explicitly assigned Partner-managed client services after both relationships are verified.
Important behavior
- Use focused SHAPI actions such as addEmail when available.
- Server/admin legacy command families are rejected.
Request parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | Exact SHAPI action name shown in this article. |
api_key | string | Yes | Client API key generated in the Sive.Host SHAPI page. |
api_secret | string | Yes | Secret paired with the API key. Send it only in the POST body. |
serviceid | positive integer | Yes | Active WHMCS service ID owned by the authenticated client. |
command | CMD_API_* string | Yes | Allowed customer legacy command. |
params | JSON object | No | POST parameters encoded as a JSON object. |
Example request
Set the four environment variables from the authenticated SHAPI page. Do not put credentials in source control or URLs.
curl --request POST 'https://sive.host/modules/addons/shapi/sh-api.php' \
--user "${SHAPI_HTTP_USER}:${SHAPI_HTTP_PASSWORD}" \
--header 'Accept: application/json' \
--data-urlencode "action=DirectAdminLegacyWrite" \
--data-urlencode "api_key=${SHAPI_API_KEY}" \
--data-urlencode "api_secret=${SHAPI_API_SECRET}" \
--data-urlencode "serviceid=12345" \
--data-urlencode "command=CMD_API_POP" \
--data-urlencode "params={\"action\":\"create\",\"domain\":\"example.com\",\"user\":\"mailbox\"}"Response
SHAPI always returns JSON. Check result; panel responses can vary by the server module and DirectAdmin version.
{
"result": "success",
"message": {
"action": "DirectAdminLegacyWrite",
"data": "Panel- or action-specific response"
}
}Common errors
Unauthorized access!: source IP or HTTP Basic authentication failed.Invalid API Key or secret.: the customer key is wrong, disabled, or deleted.Unable to retrieve an active service owned by this client.: the service is inactive or belongs to another client.Missing required parameters.: one or more required fields were omitted.
SHAPI documentation version 2.0 — generated from the current endpoint contract.

