Endpoints
Paths are relative to https://panel.example.com/api/v1. Scope is what a token needs; any one listed is enough. The owner’s own permissions still apply: a customer only reaches their own servers, a reseller their customers’, and staff what their role allows.
A scope of Signed in means the call only works from a signed-in panel session, not with an API token; None means it needs no sign-in at all.
For parameters and response types, use the panel’s built-in reference (/api-reference, or /admin/api/reference for staff), which is generated from the API client.
Status and identity
| Method | Path | What it does | Scope |
|---|---|---|---|
| GET | /me |
The account the token belongs to | servers:read |
| GET | /status |
Version, regions with uptime, branding, features and limits. Public. | None |
Your account
Signing in, two-factor, passkeys, sessions and API tokens. Calls marked Signed in work only from a browser session, not with a token.
| Method | Path | What it does | Scope |
|---|---|---|---|
| GET | /account/activity |
Your sign-ins and account changes, newest first, including when support signed in to help | Signed in |
| GET | /api-tokens |
List API tokens | Signed in |
| POST | /api-tokens |
Create API token | Signed in |
| DELETE | /api-tokens/{id} |
Revoke API token | Signed in |
| POST | /auth/impersonation/stop |
Stop impersonation | Signed in |
| GET | /auth/links/{token} |
What an emailed setup or reset link is for, and the two-factor key to scan when the account needs it from the start | None |
| POST | /auth/links/{token} |
Sets the password from an emailed link (and two-factor, when asked for), then signs in | None |
| POST | /auth/login |
Sign in with email and password | None |
| POST | /auth/logout |
Sign out | None |
| POST | /auth/passkey |
Signs in with the passkey's answer | None |
| POST | /auth/passkey/options |
Starts signing in with a passkey, without an email: options for navigator.credentials.get() | None |
| POST | /auth/password-reset |
Emails a link to choose a new password when the address has an account | None |
| POST | /auth/totp |
Finish signing in with a two-factor or recovery code | None |
| POST | /me/client-area |
Switches to their own client account (made the first time), for servers they use themselves. stopImpersonation comes back | Signed in |
| POST | /me/passkeys |
Finish passkey registration | Signed in |
| DELETE | /me/passkeys/{id} |
Delete passkey | Signed in |
| POST | /me/passkeys/options |
Starts adding a passkey to your account: options for navigator.credentials.create() | Signed in |
| POST | /me/password |
Change password | Signed in |
| POST | /me/recovery-codes |
Regenerate recovery codes | Signed in |
| GET | /me/security |
Your two-factor, passkeys, recovery codes and sessions | Signed in |
| DELETE | /me/sessions/{id} |
Revoke session | Signed in |
| POST | /me/sessions/revoke-others |
Revoke other sessions | Signed in |
| POST | /me/totp/confirm |
Confirm two-factor setup | Signed in |
| POST | /me/totp/disable |
Disable two-factor | Signed in |
| POST | /me/totp/setup |
Start two-factor setup | Signed in |
Servers
| Method | Path | What it does | Scope |
|---|---|---|---|
| GET | /gpu-instances |
List GPU instances | servers:read |
| GET | /gpu-instances/{id} |
Get GPU instance | servers:read |
| PATCH | /gpu-instances/{id} |
Rename GPU instance | servers:settings |
| POST | /gpu-instances/{id}/actions/change-image |
Makes the container again with this image (or the same one, to start clean); /workspace and how it's reached stay, and root's SSH keys are taken from the account again | servers:reinstall |
| POST | /gpu-instances/{id}/actions/power |
GPU instance action | servers:power |
| POST | /gpu-instances/{id}/console-token |
A terminal in the running container, through the same console connection as servers' | servers:console |
| GET | /gpu-instances/{id}/images |
The images the instance's offer allows | servers:read |
| GET | /gpu-instances/{id}/logs |
The container's last 500 lines of output | servers:console |
| PUT | /gpu-instances/{id}/ssh-keys |
Which of the owner's keys root's SSH login takes; at once, running or not | servers:reinstall |
| GET | /gpu-instances/{id}/stats |
Live usage: its cards, CPU, memory, /workspace and network, read from its host now | servers:read |
| GET | /gpu-instances/{id}/usage |
What it was doing in a period (default: this calendar month), for a billing portal; staff can ask about deleted ones too | servers:read |
| GET | /jobs |
Newest first | servers:read |
| GET | /jobs/{id} |
One job's progress | servers:read |
| GET | /self-service |
Your self-service allowance and what's left | servers:read |
| POST | /self-service/servers |
Deploy a server from your allowance | Signed in |
| GET | /servers |
List servers. Filters: q, status, owner_id, node_id, sort. |
servers:read |
| GET | /servers/{id} |
One server | servers:read |
| PATCH | /servers/{id} |
{ "hostname": "…" }: web01 or web01.example.com |
servers:settings |
| POST | /servers/{id}/actions/power |
{ "action": "start" | "stop" | "restart" | "force_off" } |
servers:power |
| POST | /servers/{id}/actions/reapply-network |
Sets the server's addresses inside it again, through its guest agent, after someone changed them by hand | servers:resize, servers:settings |
| POST | /servers/{id}/actions/reinstall |
{ imageId, access, snapshotFirst, scriptId? } |
servers:reinstall |
| POST | /servers/{id}/actions/rescue |
Boot into rescue mode | servers:settings |
| POST | /servers/{id}/actions/reset-password |
New root password through the guest agent, shown once | servers:settings |
| POST | /servers/{id}/actions/setup |
{ imageId, hostname, name?, access, scriptId? }, builds a server waiting for setup |
servers:reinstall |
| POST | /servers/{id}/actions/unrescue |
Leave rescue mode | servers:settings |
| GET | /servers/{id}/activity |
What happened to it | servers:read |
| PUT | /servers/{id}/boot-order |
{ "order": "disk" | "cdrom" } |
servers:settings |
| POST | /servers/{id}/console-token |
{ "kind": "vnc" | "serial" }, a single-use ticket good for 60 seconds |
servers:console |
| PUT | /servers/{id}/hardware |
Resources past the package's and the virtual hardware (firmware, buses, models) | servers:resize |
| PUT | /servers/{id}/ips/{address}/rdns |
{ "hostname": "…" }, or null to remove |
servers:rdns |
| PUT | /servers/{id}/iso |
{ "isoId": "…" }, or null to eject |
servers:settings |
| PUT | /servers/{id}/labels |
{ "labels": [ … ] } |
servers:settings |
| GET | /servers/{id}/metrics |
CPU, memory, disk and network over a range | servers:read |
| PATCH | /servers/{id}/name |
{ "name": "…" }, the name the panel shows; empty goes back to the hostname |
servers:settings |
| GET | /servers/{id}/traffic |
Traffic this month and history | servers:read |
Images, ISOs and scripts
| Method | Path | What it does | Scope |
|---|---|---|---|
| GET | /images |
OS images | servers:read |
| GET | /images/custom |
Custom images | servers:read |
| POST | /images/custom |
{ serverId, snapshotId, name } |
servers:snapshots |
| DELETE | /images/custom/{id} |
Delete a custom image | servers:snapshots |
| GET | /isos |
ISO library and your own ISOs | servers:read |
| POST | /isos |
{ name, url }, add your own ISO |
servers:settings |
| DELETE | /isos/{id} |
Remove your own ISO | servers:settings |
| GET | /scripts |
Startup scripts | servers:read |
| POST | /scripts |
Create script | servers:settings |
| PUT | /scripts/{id} |
Update script | servers:settings |
| DELETE | /scripts/{id} |
Delete script | servers:settings |
Scheduled tasks and alerts
| Method | Path | What it does | Scope |
|---|---|---|---|
| GET | /servers/{id}/alerts |
Alert rules | servers:read |
| POST | /servers/{id}/alerts |
Create alert rule | servers:settings |
| PATCH | /servers/{id}/alerts/{ruleId} |
Update alert rule | servers:settings |
| DELETE | /servers/{id}/alerts/{ruleId} |
Delete alert rule | servers:settings |
| GET | /servers/{id}/schedules |
Scheduled tasks | servers:read |
| POST | /servers/{id}/schedules |
Create scheduled task | servers:settings |
| PATCH | /servers/{id}/schedules/{taskId} |
Update scheduled task | servers:settings |
| DELETE | /servers/{id}/schedules/{taskId} |
Delete scheduled task | servers:settings |
Snapshots
| Method | Path | What it does | Scope |
|---|---|---|---|
| GET | /servers/{id}/snapshots |
List | servers:read |
| POST | /servers/{id}/snapshots |
{ "name": "…" } |
servers:snapshots |
| DELETE | /servers/{id}/snapshots/{snapshotId} |
Delete | servers:snapshots |
| POST | /servers/{id}/snapshots/{snapshotId}/restore |
Restore | servers:snapshots |
Backups
| Method | Path | What it does | Scope |
|---|---|---|---|
| GET | /servers/{id}/backups |
Backups and schedule | servers:read |
| POST | /servers/{id}/backups |
Back up now | servers:backups |
| DELETE | /servers/{id}/backups/{backupId} |
Delete, with the incrementals that depend on it | servers:backups |
| POST | /servers/{id}/backups/{backupId}/download |
A signed download link that lasts an hour | servers:backups |
| POST | /servers/{id}/backups/{backupId}/restore |
Restore here, or { targetServerId } onto another server |
servers:backups |
| PUT | /servers/{id}/backups/plan |
{ "planId": "…" }, null for none, or "package" for the package's default |
servers:resize, reseller:servers |
| PATCH | /servers/{id}/backups/schedule |
{ timeOverride?, paused? } |
servers:backups |
Firewall
| Method | Path | What it does | Scope |
|---|---|---|---|
| GET | /firewall-groups |
Shared rule sets | servers:read |
| POST | /firewall-groups |
Create firewall group | servers:firewall |
| PUT | /firewall-groups/{id} |
Applied straight away to every server the group is attached to | servers:firewall |
| DELETE | /firewall-groups/{id} |
Detaches it from its servers first; their own rules stay | servers:firewall |
| GET | /servers/{id}/firewall |
Rules and groups | servers:read |
| PUT | /servers/{id}/firewall |
Replace the rules | servers:firewall |
Billing actions
For staff billing tokens, and resellers on their customers' servers.
| Method | Path | What it does | Scope |
|---|---|---|---|
| GET | /customers/{id}/allowance |
A customer's self-service allowance | servers:resize, reseller:customers |
| PUT | /customers/{id}/allowance |
Set it | servers:resize, reseller:customers |
| GET | /reports/usage |
Every account, or one reseller's | reseller:read, customers:read |
| DELETE | /servers/{id} |
Terminate | servers:terminate, reseller:servers |
| POST | /servers/{id}/actions/change-package |
{ "packageId": "…" } |
servers:resize, reseller:servers |
| POST | /servers/{id}/actions/suspend |
{ "reason": "…" } |
servers:suspend, reseller:servers |
| POST | /servers/{id}/actions/unsuspend |
Unsuspend | servers:suspend, reseller:servers |
| POST | /servers/{id}/bandwidth |
{ "action": "add", "gb": 500 } or { "action": "reset" } |
servers:resize, reseller:servers |
| POST | /servers/{id}/ips |
{ "version": 4 }, add an address |
servers:resize, reseller:servers |
| DELETE | /servers/{id}/ips/{address} |
Remove an additional address | servers:resize, reseller:servers |
| GET | /servers/{id}/package-options |
Packages it can move to, and why others can't | servers:resize, reseller:servers, servers:read |
| PATCH | /servers/{id}/speed |
Override port, disk and CPU limits for one server | servers:resize, reseller:servers |
DNS
Customers, when DNS hosting is on.
| Method | Path | What it does | Scope |
|---|---|---|---|
| GET | /dns/zones |
List zones | dns:read |
| POST | /dns/zones |
{ domain, serverId? } |
dns:write |
| GET | /dns/zones/{id} |
A zone with its records | dns:read |
| DELETE | /dns/zones/{id} |
Delete a zone | dns:write |
| POST | /dns/zones/{id}/import |
{ zoneFile }, a BIND zone file |
dns:write |
| POST | /dns/zones/{id}/records |
Add a record | dns:write |
| PUT | /dns/zones/{id}/records/{recordId} |
Update DNS record | dns:write |
| DELETE | /dns/zones/{id}/records/{recordId} |
Delete DNS record | dns:write |
| POST | /dns/zones/{id}/verify |
Looks for the zone's verification TXT record (and its nameservers) now, rather than at the next check | dns:write |
Floating IPs and private networks
| Method | Path | What it does | Scope |
|---|---|---|---|
| GET | /floating-ips |
List | networks:read |
| POST | /floating-ips |
{ locationCode, serverId?, note? } |
networks:write |
| DELETE | /floating-ips/{id} |
Release | networks:write |
| POST | /floating-ips/{id}/assign |
{ "serverId": "…" }, or null to detach |
networks:write |
| GET | /private-networks |
List | networks:read |
| POST | /private-networks |
{ name, locationCode, subnet? } |
networks:write |
| PATCH | /private-networks/{id} |
{ name } |
networks:write |
| DELETE | /private-networks/{id} |
Delete an empty network | networks:write |
| POST | /private-networks/{id}/members |
{ serverId, address? } |
networks:write |
| DELETE | /private-networks/{id}/members/{serverId} |
Detach a server | networks:write |
SSH keys, notifications and announcements
| Method | Path | What it does | Scope |
|---|---|---|---|
| GET | /announcements |
Maintenance and incidents affecting your servers | servers:read |
| GET | /notifications |
The inbox | servers:read |
| POST | /notifications/read |
Marks the given notifications read, or all of them | Signed in |
| GET | /notifications/settings |
Get notification settings | Signed in |
| PATCH | /notifications/settings |
Update notification settings | Signed in |
| GET | /ssh-keys |
List | ssh_keys:read |
| POST | /ssh-keys |
{ name, publicKey } |
ssh_keys:write |
| DELETE | /ssh-keys/{id} |
Remove | ssh_keys:write |
Teams
Sharing servers with other accounts.
| Method | Path | What it does | Scope |
|---|---|---|---|
| GET | /team |
People they've given access to their servers | Signed in |
| POST | /team |
Sends an invitation; they sign in with their own account and two-factor | Signed in |
| PATCH | /team/{id} |
Update team member | Signed in |
| DELETE | /team/{id} |
Remove team member | Signed in |
| GET | /teams |
Teams the signed-in person was invited to | Signed in |
| POST | /teams/{id}/actions/accept |
Accept team invite | Signed in |
| POST | /teams/{id}/actions/leave |
Leave team | Signed in |
Webhooks
See Webhooks for the events and how to check signatures.
| Method | Path | What it does | Scope |
|---|---|---|---|
| POST | /webhook-deliveries/{id}/actions/redeliver |
Send a delivery again | reseller:customers |
| GET | /webhooks |
Staff see the platform's webhooks; resellers see their own, for events about their customers | reseller:read |
| POST | /webhooks |
Create webhook | reseller:customers |
| GET | /webhooks/{id} |
Get webhook | reseller:read |
| PATCH | /webhooks/{id} |
Update webhook | reseller:customers |
| DELETE | /webhooks/{id} |
Delete webhook | reseller:customers |
| POST | /webhooks/{id}/actions/rotate-secret |
The old secret keeps working for 24 hours so receivers can switch over | reseller:customers |
| POST | /webhooks/{id}/actions/test |
Test webhook | reseller:customers |
| GET | /webhooks/{id}/deliveries |
Delivery log | reseller:read |
Resellers
| Method | Path | What it does | Scope |
|---|---|---|---|
| GET | /reseller/account |
Usage, quotas, locations and packages | reseller:read |
| PUT | /reseller/branding |
Brand name, billing link, support email, nameservers | reseller:customers |
| GET | /reseller/customers |
List customers (q, cursor, limit) |
reseller:read |
| POST | /reseller/customers |
{ name, email, organization, externalId } |
reseller:customers |
| GET | /reseller/customers/{id} |
One customer | reseller:read |
| GET | /reseller/customers/{id}/ssh-keys |
A customer's SSH keys | reseller:read |
| POST | /reseller/servers |
Create a server. See billing. | reseller:servers |
Staff
Staff tokens, limited by the role's permissions as well as the token's scopes.
Nodes and fleet
| Method | Path | What it does | Scope |
|---|---|---|---|
| GET | /admin/capacity |
Capacity forecast by location | nodes:read |
| GET | /admin/fleet |
Fleet summary | nodes:read |
| GET | /admin/gpu-models |
Card models switched on across the fleet, with how many are free | servers:create, servers:resize, nodes:read |
| GET | /admin/node-enrollments |
Nodes enrolled in the panel whose agent hasn't connected yet, waiting or expired, newest first | nodes:read |
| POST | /admin/node-enrollments |
Start enrolling a node; returns the install command. kind is kvm (the default) or gpu_container for a GPU container host |
nodes:write |
| GET | /admin/node-enrollments/{id} |
Enrollment status | nodes:write |
| DELETE | /admin/node-enrollments/{id} |
Drops a node that was enrolled but never installed | nodes:write |
| POST | /admin/node-enrollments/{id}/actions/renew |
A new install command for a node still waiting: a fresh token for another hour | nodes:write |
| GET | /admin/node-groups |
List node groups | nodes:read |
| POST | /admin/node-groups |
Create node group | nodes:write |
| GET | /admin/node-groups/{id} |
Get node group | nodes:read |
| PATCH | /admin/node-groups/{id} |
Update node group | nodes:write |
| DELETE | /admin/node-groups/{id} |
Delete node group | nodes:write |
| POST | /admin/node-groups/{id}/placement-preview |
Where new servers would go | nodes:read |
| GET | /admin/nodes |
List nodes | nodes:read |
| GET | /admin/nodes/{id} |
Get node | nodes:read |
| PATCH | /admin/nodes/{id} |
Node settings, and kind (kvm or gpu_container) while no servers are on it |
nodes:write |
| DELETE | /admin/nodes/{id} |
Remove an empty node | nodes:write |
| POST | /admin/nodes/{id}/actions/drain |
Set node draining | nodes:write |
| POST | /admin/nodes/{id}/actions/rotate-certificate |
Rotate the agent's credential | nodes:write |
| POST | /admin/nodes/{id}/actions/undrain |
Set node draining | nodes:write |
| POST | /admin/nodes/{id}/actions/update-agent |
Gives the node the controller's agent | nodes:write |
| GET | /admin/nodes/{id}/assets |
A node's GPUs, whether IOMMU is on, and what stops each card | nodes:read |
| POST | /admin/nodes/{id}/assets/rescan |
Asks the node to look at its devices again | nodes:write |
| GET | /admin/nodes/{id}/evacuation |
Get node evacuation | nodes:read |
| POST | /admin/nodes/{id}/evacuation |
Start node evacuation | servers:move |
| DELETE | /admin/nodes/{id}/evacuation |
Cancel node evacuation | servers:move |
| GET | /admin/nodes/{id}/evacuation/plan |
Move every server off a node, a couple at a time | nodes:read |
| PATCH | /admin/nodes/{id}/gpus/{gpuId} |
{ enabled }: lets servers have a card, or not |
nodes:write |
| GET | /admin/nodes/{id}/metrics |
The node's load, memory, disk I/O and usage over a range | nodes:read |
| POST | /admin/nodes/{id}/storage |
Add storage pool | nodes:write |
| PATCH | /admin/nodes/{id}/storage/{poolId} |
Update storage pool | nodes:write |
| DELETE | /admin/nodes/{id}/storage/{poolId} |
Remove storage pool | nodes:write |
| GET | /admin/nodes/{id}/storage/candidates |
Volumes found but not registered | nodes:read |
| GET | /admin/nodes/{id}/usage |
What each server on a node uses, averaged over the window, to find the heavy ones | nodes:read |
| POST | /admin/nodes/assign-group |
Moves nodes into a group, or out of any group with null | nodes:write |
Servers
| Method | Path | What it does | Scope |
|---|---|---|---|
| GET | /admin/container-images |
Images GPU instances can run | servers:create |
| POST | /admin/container-images |
Create container image | Signed in |
| PATCH | /admin/container-images/{id} |
Update container image | Signed in |
| DELETE | /admin/container-images/{id} |
Only an image no instance runs and no offer names can go; hide it otherwise | Signed in |
| GET | /admin/dns-server |
The PowerDNS server that serves zones and reverse DNS, and whether it answers | nodes:read |
| PUT | /admin/dns-server |
Sets up the PowerDNS server, once it answers | Signed in |
| DELETE | /admin/dns-server |
Stops using the PowerDNS server set up here; what it has stays there | Signed in |
| POST | /admin/dns-server/actions/test |
Connects to a PowerDNS server without saving it | Signed in |
| POST | /admin/gpu-instances |
Staff, or a billing portal's module when an order is paid (servers:create) | servers:create |
| DELETE | /admin/gpu-instances/{id} |
Staff or billing (servers:terminate): the container and its /workspace go for good | servers:terminate |
| POST | /admin/gpu-instances/{id}/suspend |
Staff or billing (servers:suspend): stops it, and its owner can't start it | servers:suspend |
| POST | /admin/gpu-instances/{id}/unsuspend |
Unsuspend GPU instance | servers:suspend |
| GET | /admin/gpu-offers |
What GPU instances get, like packages for servers; billing modules map products to them | servers:create |
| POST | /admin/gpu-offers |
Create GPU offer | Signed in |
| PATCH | /admin/gpu-offers/{id} |
Update GPU offer | Signed in |
| POST | /admin/gpu-offers/{id}/archive |
Archive GPU offer | Signed in |
| GET | /admin/gpu-usage |
Every GPU instance's usage in a period, deleted ones included, for a billing run | servers:read |
| GET | /admin/license |
The panel's license and where it stands | Signed in |
| PUT | /admin/license |
Checks a license key with the license site and ties it to this panel ("License" permission) | Signed in |
| DELETE | /admin/license |
Frees the key so it can be used on another panel | Signed in |
| POST | /admin/license/refresh |
Checks the license with the license site now, rather than at the daily check | Signed in |
| GET | /admin/panel-host |
The machine the panel itself runs on: CPU, memory, disk, the panel's process and database | nodes:read |
| GET | /admin/reverse-zones |
The reverse zones PowerDNS has and the ones the IP pools need, with who the internet asks for each | nodes:read |
| POST | /admin/reverse-zones |
Creates a reverse zone in PowerDNS, with the nameservers from Settings → DNS hosting | network:write |
| DELETE | /admin/reverse-zones/{name} |
Deletes a reverse zone, and every record in it, from PowerDNS | network:write |
| POST | /admin/servers |
Create a server for a customer. See billing. | servers:create |
| POST | /admin/servers/{id}/actions/change-owner |
The previous owner loses access straight away | Signed in |
| POST | /admin/servers/{id}/actions/move |
Move to another node; storagePoolId picks the target's storage |
servers:move |
| POST | /admin/servers/{id}/actions/move-disk |
{ storagePoolId, diskId?, changeTier? }: a disk to other storage on its node, live when it's running |
servers:move |
| POST | /admin/servers/{id}/detect-os |
Asks the server's guest agent which operating system it runs, and shows that as its OS | servers:settings |
| POST | /admin/servers/{id}/disks |
Adds an empty disk to the server, on its own storage pool or another of its node's | servers:resize |
| PATCH | /admin/servers/{id}/disks/{diskId} |
Grows an additional disk; disks never shrink | servers:resize |
| DELETE | /admin/servers/{id}/disks/{diskId} |
Removes an additional disk and destroys its data | servers:resize |
| GET | /admin/servers/{id}/domain-xml |
The server's libvirt definition, as its node has it (or as the panel would write it, when the node can't be asked) | servers:read |
| POST | /admin/servers/{id}/gpus |
{ gpuId }: gives a server a card in its node, from its next stop and start |
servers:resize |
| DELETE | /admin/servers/{id}/gpus/{gpuId} |
Takes a card off a server | servers:resize |
| POST | /admin/servers/{id}/ips |
Adds IPv4 addresses (a chosen one, or the next free from a pool) or IPv6 prefixes | servers:resize |
| PUT | /admin/servers/{id}/ips/primary |
Makes an IPv4 address the primary one: the one shown everywhere, sent from, and whose pool's gateway is the default route | servers:resize |
| PUT | /admin/servers/{id}/lock |
Locks the server so its customer and their reseller can't change it (it keeps running), or unlocks it | servers:suspend |
| GET | /admin/servers/{id}/move-options |
Where a server can move | nodes:read |
| PUT | /admin/servers/{id}/note |
An empty text removes the note | Signed in |
| PUT | /admin/servers/{id}/source-filter |
Whether the node only lets the server send from its own addresses (on by default) | servers:resize |
| POST | /admin/servers/terminate |
Terminates several servers at once, after checking the caller's own panel password | servers:terminate |
| GET | /admin/sessions |
Everyone signed in now, staff included, most recently active first | Signed in |
Customers and resellers
| Method | Path | What it does | Scope |
|---|---|---|---|
| GET | /admin/customers |
List customers (q, filter, reseller, cursor, limit) |
customers:read |
| POST | /admin/customers |
{ name, email, organization } |
customers:write |
| GET | /admin/customers/{id} |
One customer | customers:read |
| PATCH | /admin/customers/{id} |
{ notes } |
customers:write |
| POST | /admin/customers/{id}/actions/impersonate |
Signs the staff member in as the customer for 30 minutes | Signed in |
| POST | /admin/customers/{id}/actions/lock |
Set customer locked | customers:write |
| POST | /admin/customers/{id}/actions/reset-2fa |
Reset customer two factor | Signed in |
| POST | /admin/customers/{id}/actions/sign-out |
Sign out customer | Signed in |
| POST | /admin/customers/{id}/actions/unlock |
Set customer locked | customers:write |
| GET | /admin/customers/{id}/ssh-keys |
A customer's SSH keys, for creating a server with them | customers:read |
| GET | /admin/resellers |
List resellers | Signed in |
| POST | /admin/resellers |
Creates the reseller's own account and sends it a sign-in invitation | Signed in |
| GET | /admin/resellers/{id} |
Get reseller | Signed in |
| PATCH | /admin/resellers/{id} |
Update reseller | Signed in |
| POST | /users/{id}/invitation |
Sends someone a new link to set up their account, e.g. when the first one expired | Signed in |
Packages, templates and ISOs
| Method | Path | What it does | Scope |
|---|---|---|---|
| POST | /admin/isos |
Adds an ISO every customer can mount, from an https link | Signed in |
| DELETE | /admin/isos/{id} |
Removes a library ISO that nothing has mounted | Signed in |
| GET | /admin/packages |
Packages with their IDs | servers:create, servers:resize |
| POST | /admin/packages |
Create package | Signed in |
| PATCH | /admin/packages/{id} |
Update package | Signed in |
| POST | /admin/packages/{id}/archive |
Archive package | Signed in |
| GET | /admin/templates |
List templates | Signed in |
| POST | /admin/templates |
Downloads the image, checks its SHA-256 and caches it on every node | Signed in |
| PATCH | /admin/templates/{id} |
Update template | Signed in |
| DELETE | /admin/templates/{id} |
Delete template | Signed in |
| POST | /admin/templates/{id}/actions/sync |
Sync template | Signed in |
| GET | /admin/templates/catalog |
Ready-made Linux cloud images from their distributions, and which are in the library already | Signed in |
| POST | /admin/templates/catalog/{id} |
Adds a catalog image as a template, with the checksum its distribution publishes now; it's imported like any other | Signed in |
IP pools, reverse DNS and firewall policies
| Method | Path | What it does | Scope |
|---|---|---|---|
| GET | /admin/firewall-policies |
The provider's firewall policies, which go on servers in front of their own rules | nodes:read, network:write |
| POST | /admin/firewall-policies |
Create firewall policy | network:write |
| PUT | /admin/firewall-policies/{id} |
Changes a policy; every server that has it picks up the new rules | network:write |
| DELETE | /admin/firewall-policies/{id} |
Deletes a policy and takes it off every server | network:write |
| POST | /admin/firewall-policies/{id}/apply |
Gives a policy to servers: chosen ones, a node's, a location's, a package's, or all | network:write |
| POST | /admin/firewall-policies/{id}/detach |
Takes a policy off servers, picked the same way | network:write |
| GET | /admin/firewall-policies/{id}/servers |
The servers a policy is on | nodes:read, network:write |
| GET | /admin/ip-pools |
List IP pools | nodes:read |
| POST | /admin/ip-pools |
Create IP pool | Signed in |
| GET | /admin/ip-pools/{id} |
Get IP pool | nodes:read |
| PATCH | /admin/ip-pools/{id} |
Update IP pool | Signed in |
| DELETE | /admin/ip-pools/{id} |
Only once no server, GPU instance, floating IP or unfinished import uses its addresses; its reservations go with it | Signed in |
| GET | /admin/ip-pools/{id}/addresses |
List pool addresses | nodes:read |
| POST | /admin/ip-pools/{id}/addresses/{address}/release |
Release address | Signed in |
| POST | /admin/ip-pools/{id}/addresses/{address}/reserve |
Reserve address | Signed in |
| GET | /admin/rdns |
Reverse DNS across every pool, and how the push to PowerDNS is going | nodes:read |
| GET | /admin/rdns/{id}/records |
An IPv4 pool's addresses with their PTR and where it comes from | nodes:read |
| PUT | /admin/rdns/{id}/template |
The PTR every IPv4 address in the pool gets until it has its own; null removes it | network:write |
| POST | /admin/rdns/actions/set |
Sets (or clears) the PTR of addresses or a range in a pool, from a hostname or pattern | network:write |
Backup plans and storage
| Method | Path | What it does | Scope |
|---|---|---|---|
| GET | /admin/backup-plans |
List backup plans | reseller:read, servers:resize |
| POST | /admin/backup-plans |
Create backup plan | Signed in |
| PATCH | /admin/backup-plans/{id} |
Applies from the next run to every server using the plan | Signed in |
| POST | /admin/backup-plans/{id}/archive |
Servers keep their backups; packages and servers using it move to no plan | Signed in |
| GET | /admin/backup-storage |
List backup destinations | Signed in |
| POST | /admin/backup-storage |
Create backup destination | Signed in |
| PATCH | /admin/backup-storage/{id} |
Update backup destination | Signed in |
| DELETE | /admin/backup-storage/{id} |
Delete backup destination | Signed in |
| POST | /admin/backup-storage/{id}/actions/test |
Uploads, reads back and deletes a small test file | Signed in |
| GET | /admin/backup-storage/ssh-key |
The public half of the panel's SSH key for SFTP backup storage, made the first time it's asked for | Signed in |
Jobs, transfers and logs
| Method | Path | What it does | Scope |
|---|---|---|---|
| GET | /admin/audit-log |
Who did what, newest first, filtered by actor, target or category | Signed in |
| GET | /admin/email-log |
Every email the panel tried to send, newest first | Signed in |
| GET | /admin/email-log/{id} |
One email with its message; passwords and sign-in links are blanked out | Signed in |
| GET | /admin/jobs |
Every job (power, reinstall, backup, snapshot, move), running ones first, then newest | servers:read |
| GET | /admin/jobs/{id} |
One job with its log, to follow while it runs | servers:read |
| GET | /admin/transfers |
Every move between nodes, newest first; active ones include live progress | nodes:read |
| GET | /admin/transfers/{id} |
Get transfer | nodes:read |
| POST | /admin/transfers/{id}/actions/cancel |
Cancel a move | servers:move |
| POST | /admin/transfers/{id}/actions/email-customer |
Emails the customer the new addresses a move gave their server (again, if they already were) | servers:move |
Imports
| Method | Path | What it does | Scope |
|---|---|---|---|
| GET | /admin/migrations |
List migrations | Signed in |
| POST | /admin/migrations |
Create migration | Signed in |
| GET | /admin/migrations/{id} |
Get migration | Signed in |
| PATCH | /admin/migrations/{id} |
Update migration | Signed in |
| DELETE | /admin/migrations/{id} |
Drops an import nothing has moved in yet, and deletes its API credentials | Signed in |
| POST | /admin/migrations/{id}/authorize-source |
Signs in to a source hypervisor as root with its password, once, from a node that copies off it, and adds the copying nodes' keys to root's authorized_keys there | Signed in |
| POST | /admin/migrations/{id}/dry-run |
Run dry run | Signed in |
| POST | /admin/migrations/{id}/finish |
Finish migration | Signed in |
| POST | /admin/migrations/{id}/rediscover |
Reads the source panel again, until migrating starts; mappings start afresh from what it finds | Signed in |
| POST | /admin/migrations/{id}/servers/{serverId}/recheck |
Runs a migrated server's checks again on its node, switching it to its new addresses first if it hasn't yet | Signed in |
| POST | /admin/migrations/{id}/servers/{serverId}/retry |
Retry migration server | Signed in |
| POST | /admin/migrations/{id}/servers/{serverId}/rollback |
Rollback migration server | Signed in |
| POST | /admin/migrations/{id}/source-removal |
After a finished Virtualizor import: staff's answer to taking Virtualizor off a hypervisor whose servers were adopted | Signed in |
| POST | /admin/migrations/{id}/source-removal/run |
Has the node's agent take Virtualizor off it, keeping what the servers' network needs; undone if a server is affected | Signed in |
| POST | /admin/migrations/{id}/start |
Start migration | Signed in |
Announcements
| Method | Path | What it does | Scope |
|---|---|---|---|
| POST | /admin/announcements |
Create announcement | Signed in |
| POST | /admin/announcements/{id}/actions/cancel |
Cancel announcement | Signed in |
| POST | /admin/announcements/{id}/updates |
Posts a timeline update; resolve ends an incident or maintenance |
Signed in |
| POST | /admin/announcements/preview |
How many servers and customers an audience reaches, before publishing | Signed in |
Settings, staff and roles
| Method | Path | What it does | Scope |
|---|---|---|---|
| GET | /admin/email-templates |
List email templates | Signed in |
| PUT | /admin/email-templates/{key} |
Update email template | Signed in |
| DELETE | /admin/email-templates/{key} |
Back to the built-in wording | Signed in |
| POST | /admin/email-templates/{key}/test |
Sends the saved template with example values | Signed in |
| GET | /admin/roles |
List roles | Signed in |
| POST | /admin/roles |
Create role | Signed in |
| PATCH | /admin/roles/{id} |
Update role | Signed in |
| DELETE | /admin/roles/{id} |
Delete role | Signed in |
| GET | /admin/settings |
Get platform settings | Signed in |
| PATCH | /admin/settings |
Update platform settings | Signed in |
| POST | /admin/settings/test-email |
Sends a test email with the saved SMTP settings | Signed in |
| GET | /admin/staff |
List staff | Signed in |
| POST | /admin/staff |
Invite staff | Signed in |
| GET | /admin/staff/{id} |
Get staff member | Signed in |
| PATCH | /admin/staff/{id} |
Update staff | Signed in |
| DELETE | /admin/staff/{id} |
Pending invitations and disabled accounts only | Signed in |
| POST | /admin/staff/{id}/reset-sign-in |
Emails them a link to choose a new password | Signed in |
| POST | /admin/staff/{id}/sign-out |
Ends all their sessions | Signed in |