VorticPanel

API and billing

Authentication and tokens

API tokens

Create a token under Account → API tokens (staff: Admin → Account → API tokens). The secret is shown once. Send it as a bearer token:

Authorization: Bearer pnl_…

Tokens start with pnl_. Only a hash is stored, so a lost secret can’t be recovered; revoke the token and make a new one.

Setting Notes
Name 1–64 characters, unique for your account
Scopes What it may do. At least one.
IP allowlist Addresses or CIDR ranges it may be used from. Empty means anywhere.
Expires After 1–365 days, or never
  • An account can have up to 25 tokens.
  • A token can never do more than its owner: it holds only scopes the owner has, and the owner’s role and permissions still apply on every call.
  • A token stops working if its owner can’t sign in, and a customer’s tokens stop working while you switch off API tokens under Customer features.
  • Tokens can’t be created or revoked during a support session.
  • Creating a token asks for your password, and the account’s owner is emailed when one is created.
  • Tokens made in a staff member’s own client area work only while the staff member is active, only from the addresses staff can sign in from, and are revoked when the staff member is disabled or removed.
  • The token’s last use and address are shown on the tokens page, and actions are recorded in the audit log under the token’s name.

A request from outside the allowlist gets 403 ip_not_allowed. Behind a proxy, set PANEL_TRUSTED_PROXIES so the controller sees the caller’s real address.

Scopes

Scope Allows Available to
servers:read List servers, IPs, usage and jobs Everyone
servers:power Start, stop, restart and force off Everyone
servers:reinstall Wipe and reinstall from an image Everyone
servers:console Open VNC and serial console sessions Everyone
servers:rdns Change PTR records Everyone
servers:snapshots Take, restore and delete snapshots Everyone
servers:backups Change the schedule, back up and restore Everyone
servers:firewall Change firewall rules Everyone
servers:settings Hostname, rescue mode, ISO and boot order Everyone
ssh_keys:read List SSH keys Everyone
ssh_keys:write Add and remove SSH keys Everyone
dns:read List DNS zones and records Customers, when DNS hosting is on
dns:write Add, change and delete records, e.g. to get certificates Customers, when DNS hosting is on
networks:read Floating IPs and private networks Customers, when either is on
networks:write Move floating IPs for failover, change private networks Customers, when either is on
servers:create Provision servers for any customer when an order is paid Staff
servers:resize Upgrades, downgrades and extra IPv4 addresses Staff
servers:suspend Suspend and unsuspend servers for overdue invoices Staff
servers:terminate Destroy cancelled servers and free their addresses Staff
customers:read Look up customer accounts, their SSH keys and usage reports Staff
customers:write Create and update customer accounts from billing Staff
nodes:read Node health, usage and placement Staff
nodes:write Drain, resume and enroll nodes Staff
servers:move Move servers between nodes, empty nodes and cancel moves Staff
reseller:read Usage, quotas, locations, packages and customers Resellers
reseller:customers Sign up customers, with the client ID from your billing Resellers
reseller:servers Create, change, suspend and terminate customers’ servers Resellers

Presets

The token form has presets for common jobs:

Preset Scopes
Read-only servers:read, ssh_keys:read
Automation servers:read, servers:power, servers:rdns
Failover servers:read, networks:read, networks:write
Full server control Every servers:* scope above, ssh_keys:read, ssh_keys:write
Billing module (staff) servers:read, servers:create, servers:resize, servers:suspend, servers:terminate, servers:power, servers:reinstall, customers:read, customers:write
Billing module (resellers) reseller:read, reseller:customers, reseller:servers, servers:read, servers:power, servers:reinstall

Calls only the panel can make

Some calls work only from a signed-in browser session, never with a token: changing passwords, two-factor and passkeys, managing API tokens and sessions, team access, notification settings, and most staff administration (settings, staff, packages, IP pools, templates, the audit log). A token gets 403 token_not_allowed for these.

Browser sessions

The panel itself signs in with an HttpOnly session cookie (panel_session), never a token in JavaScript or browser storage. Every request that changes something must send an X-CSRF-Token header matching the csrf_token cookie, and requests from other sites are refused. Token requests skip these checks.

  • When the panel’s address is https://, the cookies are called __Host-panel_session and __Host-csrf_token. Browsers only keep cookies with that prefix for this exact host, so another site on the same domain can’t set or replace them. On a plain http:// test install they keep the names above.
  • A session ends after the inactivity time under Settings → Sign-in and sessions, and in any case 30 days after signing in.

Every word has to appear. ↑ ↓ to move, Enter to open.