Untuk ejen AI: markdown halaman ini — /docs-content-en/infra/access.md indeks dokumentasi — /llms.txt
Artikel dokumentasi kini tersedia dalam bahasa Inggeris.
Access and modes
Managing application visibility and server mode. The access policy (accessPolicy) determines who in Bitrix24 can open the application's HTTPS subdomain: only the owner, a list of specific users and departments, all Bitrix24 account users, or any visitor at all. The server mode (mode) toggles between Black Hole (everything closed behind the firewall) and OPEN (direct access by IP).
Changing
accessPolicyfromOWNER_ONLYto a more open value directly affects security. Never do it on a user's behalf without explicit confirmation — it opens the application to other people in the Bitrix24 account or to the entire internet.
Scope: vibe:infra
SSH credentials
GET /v1/infra/servers/:id/ssh
Returns the SSH connection credentials. Full SSH credentials (password, private key, and public key) are returned only for servers in OPEN mode. For BLACKHOLE, sshPassword, sshPrivateKey, sshPublicKey, and sshCommand are null, while sshUser and sshPort are omitted: the server is closed off by an iptables firewall, and direct SSH is not possible. For BLACKHOLE, use the Deploy API instead of SSH — /exec, /upload, /logs. Rate limit: up to 10 requests per minute per server. The exact value is provided in the x-ratelimit-limit header (the cap is divided across replicas).
Parameters
| Parameter | In | Type | Required | Description |
|---|---|---|---|---|
id |
path | string (UUID) | yes | Server ID |
Examples
curl — personal key
curl -H "X-Api-Key: YOUR_API_KEY" \
https://vibecode.bitrix24.com/v1/infra/servers/SERVER_ID/ssh
curl — OAuth application
curl -H "X-Api-Key: YOUR_APP_KEY" \
-H "Authorization: Bearer USER_SESSION_TOKEN" \
https://vibecode.bitrix24.com/v1/infra/servers/SERVER_ID/ssh
JavaScript — personal key
const res = await fetch(
`https://vibecode.bitrix24.com/v1/infra/servers/${serverId}/ssh`,
{ headers: { 'X-Api-Key': 'YOUR_API_KEY' } }
)
const { data } = await res.json()
if (data.mode === 'OPEN') {
console.log('Command:', data.sshCommand)
console.log('Password:', data.sshPassword) // if it was issued
} else {
console.log(data.note) // BLACKHOLE — use the Deploy API
}
JavaScript — OAuth application
const res = await fetch(
`https://vibecode.bitrix24.com/v1/infra/servers/${serverId}/ssh`,
{
headers: {
'X-Api-Key': 'YOUR_APP_KEY',
'Authorization': 'Bearer USER_SESSION_TOKEN',
},
}
)
Response fields
| Field | Type | Description |
|---|---|---|
success |
boolean | Always true on success |
data.mode |
string | OPEN or BLACKHOLE |
data.ip |
string | Public IP of the server |
data.sshDirect |
boolean | true for OPEN (SSH connects directly to the IP), false for BLACKHOLE (closed off by the firewall) |
data.sshUser |
string | SSH user: ubuntu or root. Omitted for BLACKHOLE |
data.sshPort |
number | SSH port: 22. Omitted for BLACKHOLE |
data.sshPassword |
string | null | Password. Always null for BLACKHOLE. For OPEN, the password the server generated when switching to OPEN, if any |
data.sshPrivateKey |
string | null | The platform's private key in OpenSSH format (ed25519). Always null for BLACKHOLE |
data.sshPublicKey |
string | null | Public key (ed25519) — the public part matching sshPrivateKey |
data.sshCommand |
string | null | Ready-to-copy command: ssh ubuntu@IP. null for BLACKHOLE |
data.appUrl |
string | The application's HTTPS address (present only for BLACKHOLE, where SSH is unavailable) |
data.note |
string | Explanation for BLACKHOLE: "BLACKHOLE servers do not expose SSH. Use the Deploy API…" |
Response example
OPEN server:
{
"success": true,
"data": {
"mode": "OPEN",
"ip": "111.88.251.211",
"sshUser": "ubuntu",
"sshPort": 22,
"sshPassword": "Oi9owBO6zMbueGmM75J9hg",
"sshPrivateKey": "-----BEGIN OPENSSH PRIVATE KEY-----\nb3BlbnNzaC1rZXktdjEAAAAABG5vbmU…\n-----END OPENSSH PRIVATE KEY-----\n",
"sshPublicKey": "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIM0JAP1EMGh0CkT7RkZ26pTSa4X1FsWXe61cB5Fiqqjz vibe-generated",
"sshCommand": "ssh ubuntu@111.88.251.211",
"sshDirect": true
}
}
BLACKHOLE server:
{
"success": true,
"data": {
"mode": "BLACKHOLE",
"ip": "93.77.184.167",
"sshDirect": false,
"sshPassword": null,
"sshPrivateKey": null,
"sshPublicKey": null,
"sshCommand": null,
"appUrl": "https://app-abc12345.vibecode.bitrix24.com",
"note": "BLACKHOLE servers do not expose SSH. Use the Deploy API (exec/upload/logs) instead."
}
}
Error response example
404 — the server does not exist:
{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Server not found"
}
}
Errors
| HTTP | Code | Description |
|---|---|---|
| 401 | MISSING_API_KEY |
The X-Api-Key header was not provided |
| 401 | INVALID_API_KEY |
The key is not recognized — no such key exists on the platform |
| 403 | SERVER_ROLE_FORBIDDEN |
You are on this server's development team with the Developer role, but this operation requires the Administrator role. error.hint includes your role, the minimum required role, and the API calls available to you. Role breakdown — List servers |
| 404 | NOT_FOUND |
The server does not exist or belongs to another API key while you are not on its development team |
| 409 | SERVER_NOT_READY |
The server has no assigned IP address yet |
| 429 | RATE_LIMITED |
The limit of 10 requests per minute per server or the platform's overall rate limit was exceeded. The exact value is provided in the x-ratelimit-limit header (the cap is divided across replicas) |
The full list of common API errors — Errors.
Known specifics
- Each BLACKHOLE → OPEN switch generates a new password. Old passwords (if any) become invalid. The same applies to a back-and-forth cycle BLACKHOLE → OPEN → BLACKHOLE → OPEN: each time the server enters OPEN, the platform generates a fresh
sshPassword. sshPrivateKeyandsshPublicKeyare the platform's key pair, not yours. The platform creates this key pair for every server, so inOPENmode both fields are returned even if you passed your ownsshPublicKeywhen creating the server viaPOST /v1/infra/servers. This request does not return your key: the platform does not store it. You can connect with your own key to either a machine created from scratch or a pre-provisioned machine if you supplied it when creating the server. To tell which machine you got, see "Known specifics" on the server creation page.sshCommandis a ready-to-copy string for AI agents and scripts. It is not a separate launch command — justssh ubuntu@IP. Authentication via password or key is a separate step on the SSH client side.- A separate limit of 10 requests per minute per server exists precisely because the returned data is sensitive. The exact value is provided in the
x-ratelimit-limitheader (the cap is divided across replicas). The platform's overall limit is higher, but/sshis throttled more strictly.