Skip to main content

API

Customer endpoints (session required):

MethodPathPurpose
GET/api/vmsList own servers with live status
GET/api/vms/:vmidDetail: specs, status, guest-agent IPs
POST/api/vms/:vmid/power/:actionstart, shutdown, reboot, stop
GET/api/vms/:vmid/rrd?timeframe=hourUsage graphs (hour, day, week, month)
GET/POST/api/vms/:vmid/snapshotsList / create (limited by MAX_SNAPSHOTS)
POST/api/vms/:vmid/snapshots/:name/rollbackRoll back
DELETE/api/vms/:vmid/snapshots/:nameDelete
POST/api/vms/:vmid/consoleCreate a one-time console session
GET (ws)/api/console/:sessionConsole websocket
GET/api/tasks/:upidProgress of a task this user started
GET/api/accountWhether the user may create servers, limits and usage
GET/api/templatesImages the user can create servers from
POST/api/vmsCreate a server (runs in the background)
DELETE/api/vms/:vmidDelete a server the customer created (must be stopped)
GET/api/vpnVPN status and the customer's devices
POST/api/vpn/devicesAdd a device; returns the config and QR code (only time the key is shown)
DELETE/api/vpn/devices/:idRemove a device
GET/POST/DELETE/api/vms/:vmid/tailscaleTailscale status / connect (auth key, mode, name) / disconnect
POST/api/auth/2fa/verify, /api/auth/2fa/setup, /api/auth/2fa/activateSecond sign-in step: code, or forced setup
GET/POST/api/account/2fa, …/setup, …/activate, …/disable, …/recovery-codesManage your own 2FA

Admin endpoints (admin port, admin session required): GET/POST /api/admin/users, PATCH/DELETE /api/admin/users/:id, GET /api/admin/vms, PUT/DELETE /api/admin/vms/:vmid, POST /api/admin/vms/:vmid/power/:action, DELETE /api/admin/vms/:vmid/server, GET /api/admin/users/:id/deletion-plan, GET /api/admin/tasks/:upid, GET /api/admin/templates, PUT/DELETE /api/admin/templates/:vmid, GET /api/admin/vpn, DELETE /api/admin/vpn/devices/:id, POST /api/admin/vpn/sync, GET /api/admin/audit.