ScriptBoxConnecting to servers...
Skip to main content
ScriptBox logoScriptBox
HomeScripts
Domains
Login
API reference

Public data and installer API boundaries

Use the website endpoints for public hosting catalog data and the installer API for catalog discovery and authorized installation operations.

Read the getting-started guideContact support

On this page

  • Authenticated dashboard API
  • Conventions and base URLs
  • Website hosting catalog
  • Search the installer catalog
  • Read a catalog item
  • Authorization for installation operations
  • Responses and errors
01

Authenticated dashboard API

The browser uses same-origin /api/platform/* handlers backed by revocable server sessions. Website authentication uses a secure HttpOnly cookie and an anti-forgery token on mutations; raw access tokens are not stored in browser localStorage.

The server API uses /platform/auth/register, /platform/auth/verify and /platform/auth/login. Registration returns a verification challenge only after email delivery; completing verification establishes a session. Protected /platform routes require the current opaque bearer token. Old JWT account routes are retired.

RoutePurpose
GET /platform/instancesOwned APITHost hosting instances
GET /platform/scriptsPurchased and connected scripts
POST /platform/purchases/quoteCurrent script and hosting quote
POST /platform/purchasesPay the quote from the shared wallet
GET /platform/billingWallet, invoices and payment history
GET /platform/notifications/eventsOwned resumable notification events
POST /platform/ai/conversationsA conversation scoped to an owned installation or instance
Keep in mind: Mutation requests use requestKey for idempotency where documented. HTTP 402 means wallet funds or an AI spending limit prevent the request; 409 can indicate an ownership, confirmation or retry conflict. Queued operations return 202 and an operationId; poll GET /platform/operations/{id}. An accepted request is not proof that deployment or payment completed.
02

Conventions and base URLs

Website examples are relative to https://scriptbox.app. Installer examples use https://api.scriptbox.app/installer/v1. Send and accept JSON unless an artifact response explicitly uses another content type.

const website = 'https://scriptbox.app';
const installer = 'https://api.scriptbox.app/installer/v1';
Keep in mind: Do not put bearer tokens, license identifiers, or private origin proofs in URLs, logs, analytics, or client-side configuration.
03

Website hosting catalog

The same-origin website proxy exposes the live public hosting catalog used by the Header hosting chooser. The list response contains hostingTypes, currencies, and sourceCurrency. A detail response contains hostingType, currencies, and sourceCurrency.

GET /api/hosting/catalog
GET /api/hosting/catalog/{slug}

{
  "success": true,
  "data": {
    "hostingTypes": [],
    "currencies": [{ "code": "USD", "symbol": "$", "exchangeRate": 1 }],
    "sourceCurrency": "USD"
  }
}
04

Search the installer catalog

Catalog search accepts bounded filters. Use the returned meta and facets rather than assuming a fixed number of categories, price ranges, pages, or scripts.

  • sort: recent, popular, or rating
  • price_range: all, under20, 20to50, 50to100, or over100
  • per_page: 1 through 50
  • tags: up to 20 positive numeric identifiers
curl --request POST \
  'https://api.scriptbox.app/installer/v1/catalog/search' \
  --header 'Accept: application/json' \
  --header 'Content-Type: application/json' \
  --data '{"search":"commerce","sort":"recent","page":1,"per_page":12}'
05

Read a catalog item

Request a specific public script ID to obtain its sanitized detail projection. Media values are validated public references. Generic credentials and private delivery fields are excluded; a bounded demo access projection may be present when explicitly configured.

curl --fail --show-error \
  'https://api.scriptbox.app/installer/v1/catalog/SCR-001' \
  --header 'Accept: application/json'
06

Authorization for installation operations

Catalog reads above are public. License creation, artifact authorization, activation, uninstall, event, and session operations require a short-lived installer session token with the required scope. Protected calls bind the token to the installation origin.

  • Obtain a session through the approved installer verification flow.
  • Send the token only to the configured ScriptBox API origin.
  • Use the exact HTTPS installation origin bound to the session.
  • Treat download and authorization tokens as secrets, even when short-lived.
Authorization: Bearer <installer-session-token>
X-ScriptBox-Origin: https://your-site.example
07

Responses and errors

Installer endpoints use a stable envelope. Check the HTTP status and success field. Record request_id for support, but do not expose tokens or private request bodies. Rate-limited callers should honor Retry-After when it is returned.

{
  "success": false,
  "data": null,
  "error": {
    "code": "VALIDATION_ERROR",
    "message": "Request validation failed",
    "details": null
  },
  "request_id": "..."
}
StatusMeaningCaller action
400 / 422Invalid requestCorrect the request; do not retry unchanged.
401 / 403Missing, expired, or insufficient authorizationStart or refresh the approved session flow.
404Public item or route not foundRecheck the identifier or refresh catalog data.
429Rate limitedWait for Retry-After before retrying.
5xxService unavailable or server failureRetry with backoff and preserve the request ID.
ScriptBox logoScriptBox

Your one-stop destination for premium scripts, domains, and hosting solutions. Build faster, deploy smarter.

Product

  • Scripts
  • Hosting
  • Domains
  • Script Pricing

Resources

  • Documentation
  • API Reference
  • Tutorials
  • Blog

Company

  • About Us
  • Careers
  • Contact
  • Partners

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Licenses

Build with a clearer plan

Read practical articles about choosing scripts, preparing deployments, and maintaining your site.

Explore the blog

© 2026 ScriptBox. Made with by developers, for developers.

Built for developers