API(7)Miscellaneous Information ManualAPI(7)

api — scripts and CI over HTTPS

Where ssh is awkward, in CI runners for instance, the same commands run over HTTPS with a token. A token is an account key with limits: which commands, which VM, until when. Removing the key revokes the token.

$ ssh chroot.dev ssh-key generate-api-key --label ci \
    --cmds new,ls,rm --exp 30d

Without --cmds the token runs help, ls, new, whoami, ssh-key list and share show.

POST the command line to /exec; the answer is the --json output of the command:

$ curl -X POST -H "Authorization: Bearer $TOKEN" \
    -d 'new -n ci-1234 -w' https://chroot.run/exec

‘ssh name command’ runs command in the VM. Output and errors come back together; the exit status is in the ‘X-Fcm-Exit’ header:

$ curl -sD - -X POST -H "Authorization: Bearer $TOKEN" \
    -d 'ssh ci-1234 make test' https://chroot.run/exec

$ ssh chroot.dev ssh-key rm ci

intro(1), ssh-key(1)

chroot.devOctober 7, 2026API(7)