Download the existing SSH machine credentials for a range as a ZIP archive. Requires the Ludus Enterprise plugin. Use the normal Ludus API service, not the admin service.
Authenticate with a valid Ludus API key in X-API-KEY or a valid user JWT in Authorization. Non-admin users must have access to the selected range, including when their default range is used. Administrators may select another user's context with userID; access checks then use that user's privileges.
Pass rangeID to select a range. If omitted, the endpoint uses the authenticated or impersonated user's default range. URL-encode query parameter values.
The archive contains exactly README.txt (connection instructions), ssh/ludus_ed25519 (SSH private key, Unix mode 0600), and ssh/ludus_ed25519.pub (SSH public key, Unix mode 0644). These keys authenticate to Linux, macOS, and Windows hosts configured for the range's SSH key authentication. They are SSH keys, not CA-signed SSH certificates. No passwords or WinRM certificates are included.
This endpoint only reads existing credentials. It does not provision, regenerate, or rotate them. A missing credential set returns 404; an invalid or unreadable set returns 500.
Treat this archive as administrative access to the range. Store it privately and do not cache or log its contents. The attachment filename is -machine-credentials.zip, with slashes in the range ID replaced by hyphens. On Unix-like systems, set mode 0600 on the private key after extraction. Verify the guest host key and use the configured SSH username when connecting.
Run ludus range machine-credentials -r MYRANGE -o machine-credentials.zip. Omit -r to use your default range. The CLI saves the archive with owner-only permissions on Unix-like systems.
ludus range machine-credentials -r MYRANGE -o machine-credentials.zip{"error":"User JD from query parameter not found"}