There was a problem loading the comments.

Editing Your Sites With the API and AI Agents

Support Portal  »  Knowledgebase  »  Viewing Article

  Print
  • 5 October 2026 7:31 AM

The LaunchCDN API lets your own scripts, or an AI agent working for you, deploy domains and edit the sites in your account. Follow three rules when anything connects to your sites:

  1. Get each site's origin server from the API.
  2. Connect to that server directly, bypassing the CDN.
  3. Send a descriptive user agent that names your tool.

Edits made this way skip the CDN's cache, so they apply immediately.

1. Your API Credentials

Log in to your LaunchCDN account and open the API section to find your User ID and Auth Key. Every request is a POST to https://api.launchcdn.com/v1/<endpoint>/ with user and auth as form fields. Full documentation with examples is at api.launchcdn.com.

For ready-made LLM tool definitions, example prompts and agent workflows, see our API page.

Endpoint What it does
testconnection Checks that your credentials work
deploy Deploys a new WordPress or HTML/PHP site behind your chosen CDN
getalldomains Lists every site with its hosting type, origin server IP, name servers and login details
getsingledomain Returns one site's details, including its server hostname and FTP/DirectAdmin login
loginlink Returns a one-time sign-on link to a WordPress site's admin area

Keep API responses private. They contain passwords for your sites. Give your agent the Auth Key through an environment variable or secrets store rather than pasting it into a chat or prompt, and keep responses out of logs and shared files.

2. Find the Site's Origin Server

curl -A "AcmeContentAgent/1.0 (+https://acme.example)" \
  -d user=1001 -d auth=YOUR_AUTH_KEY \
  https://api.launchcdn.com/v1/getalldomains/

Each site in the response includes a serverip. That's the origin server to connect to:

{
  "result": "success",
  "results": 2,
  "data": [
    {
      "domain": "example.com",
      "hosting_type": "wordpress",
      "serverip": "203.0.113.10",
      "nameservers": ["ns1.example-dns.net", "ns2.example-dns.net"],
      ...
    },
    {
      "domain": "example.org",
      "hosting_type": "static",
      "serverhostname": "server1.example-host.net",
      "serverip": "203.0.113.20",
      "nameservers": ["ns1.example-dns.net", "ns2.example-dns.net"],
      ...
    }
  ]
}

Each site also includes its login details: the WordPress admin login for WordPress sites, and the DirectAdmin/FTP login for HTML/PHP sites.

getsingledomain returns the server hostname (ftpserver) rather than an IP. Look up its address (for example dig +short server1.example-host.net), or use serverip from getalldomains. For WordPress sites, getsingledomain also returns the account's FTP/DirectAdmin login as ftpusername and ftppassword.

The nameservers list is what to set at your registrar. An agent with API or MCP access to your registrar can do this for you.

3. Bypass the CDN

Your domain's public DNS points at the CDN, so a normal request to https://example.com goes through the CDN's cache. Agents should instead send requests for the domain to the origin server IP. With curl, --resolve does this without touching DNS or your hosts file:

curl --resolve example.com:443:203.0.113.10 -k \
  -A "AcmeContentAgent/1.0 (+https://acme.example)" \
  https://example.com/

The -k is needed because origin servers present the server's own certificate rather than one issued for your domain. That's expected here: you're connecting to an IP address you got from the API, not one found through DNS.

In PHP, use CURLOPT_RESOLVE with CURLOPT_USERAGENT:

$ch = curl_init('https://example.com/wp-json/wp/v2/posts?per_page=5');
curl_setopt_array($ch, [
    CURLOPT_RESOLVE        => ['example.com:443:203.0.113.10'],
    CURLOPT_USERAGENT      => 'AcmeContentAgent/1.0 (+https://acme.example)',
    CURLOPT_USERPWD        => 'jason:' . getenv('WP_APP_PASSWORD'),
    CURLOPT_SSL_VERIFYPEER => false,
    CURLOPT_SSL_VERIFYHOST => 0,
    CURLOPT_RETURNTRANSFER => true,
]);
$posts = json_decode(curl_exec($ch), true);

Other HTTP libraries have equivalent DNS-override options. To view a site on its origin server in your own browser, see Editing Hosts File to Bypass CDN.

4. Use Your Own User Agent

Set a descriptive user agent that names your tool, rather than your HTTP library's default. For example:

AcmeContentAgent/1.0 (+https://acme.example)

Use it for every request your scripts or agent make: API calls, WordPress REST calls, DirectAdmin and file transfers.

5. Editing WordPress Sites

Use the WordPress REST API with an Application Password, not your main admin password:

  1. Call loginlink with the domain to get a sign-on link to the WordPress dashboard, or log in normally.
  2. Go to Users → Profile, scroll to Application Passwords, enter a name such as "AI agent" and click Add New Application Password.
  3. Copy the password it shows (it's displayed once) and store it with your other secrets.

Then send REST requests to the origin server with your WordPress username and that Application Password. For example, to create a draft post:

curl --resolve example.com:443:203.0.113.10 -k \
  -A "AcmeContentAgent/1.0 (+https://acme.example)" \
  -u "jason:abcd efgh ijkl mnop qrst uvwx" \
  -H "Content-Type: application/json" \
  -d '{"title":"Best Standing Desks for 2026","content":"<p>...</p>","status":"draft"}' \
  https://example.com/wp-json/wp/v2/posts

You can revoke an Application Password from the same screen at any time without changing your admin login. If you don't see the Application Passwords section, open a ticket and we'll check the site.

WordPress sites also have FTP and DirectAdmin access (ftpusername and ftppassword from getsingledomain) for theme and file work.

6. Editing HTML/PHP Sites

Use the DirectAdmin/FTP login from the API:

  • FTP: connect to the server IP or hostname on port 21. Use FTPS (explicit TLS) if your client supports it. Files go in domains/example.org/public_html.
  • DirectAdmin: log in at https://SERVER_HOSTNAME:2222 with the same username and password. Scripts can upload and edit files through DirectAdmin's file manager API.

FTP and DirectAdmin connect to the server directly, so they never pass through the CDN. The custom user agent rule still applies to DirectAdmin API calls.

Troubleshooting

  • 403 Forbidden or an unexpected page: check that the domain is pinned to serverip (step 3) and that you're sending your own user agent (step 4).
  • Certificate error: expected when connecting to the origin server. Use -k (or your library's equivalent) for these requests only.
  • 401 from the WordPress REST API: use an Application Password (not your admin password), send it over HTTPS, and check the username.
  • A change shows on the origin server but not on the public site: visitors are served through the CDN, which may show its cached copy for a while.

Still stuck? Open a ticket with the domain and the time of the request. Aidan, our 24x7 support AI, picks tickets up straight away, and anything trickier goes to a server engineer. Please note that we do not offer support for the integrations/code that you develop.


Share via
Did you find this article useful?  

Related Articles


Comments

Add Comment

Replying to  

© LaunchCDN