API endpoint reference
Find each public endpoint's parameters, required permissions and responses.
BlazingFast Customer API
Automate account billing, VPS and dedicated servers, DNS and Website Protection, TCP Proxy, domains, SSH keys, firewall policies and storage. Use an official SDK for HMAC-signed requests, or a bearer-mode API key. Generic OpenAPI-generated clients do not implement BlazingFast HMAC signing automatically. Pagination is endpoint-specific: follow the documented page/limit, cursor/next_cursor or offset/next_offset model. limit is the canonical page-size parameter; page_size and pageSize are deprecated compatibility aliases only where documented. Begin by reading the resource, confirm changes, and inspect the result or returned task. Draft order creation does not charge the account. Atomic deployment is the documented exception: order + full final order amount paid from account balance + queued provisioning. Payment is not successful provisioning; accepted is not completed. Access depends on key scopes and account permissions.
Billing
Browse products and valid order options, check prices, create unpaid orders, and view invoices, transactions and account balance. Paying an invoice from balance is a separate action.
Authentication
SignedAuth
SignedAuth is represented by x-api-key for discovery only. Generic OpenAPI-generated clients do not automatically implement BlazingFast HMAC signing. Use BearerAuth with a bearer-mode credential or an official SDK, unless you implement the signing algorithm manually. Signed-key mode requires all five headers. SDKs send x-api-key, x-ts (Unix seconds), x-nonce, x-content-sha256 (Base64 SHA-256 of the exact body), and x-signature (Base64 HMAC-SHA256). Custom signing is explained in the API authentication guide. Every HTTP attempt needs a fresh timestamp and nonce; an action retry retains its original idempotency key and payload. Key expiry, IP restrictions, account permissions and scopes still apply.
BearerAuth
Alternative mode for integrations that prefer Authorization: Bearer <prefix.secret>. Key status, expiry, scope checks, IP policy, and rate limits still apply.
Endpoints
/v1/billing/invoices/{id}/pay
Pay invoice from wallet
Operation ID: payInvoice
Attempts to settle the target invoice using account balance. This is the customer API path for balance-driven payment automation.
| Parameter | Location | Type | Required | Description |
|---|---|---|---|---|
| id | path | string | Yes | Invoice UUID. |
| x-client-request-id | header | string | No | Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key. |
| x-ts | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-nonce | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-content-sha256 | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-signature | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
Request body
No request body
Responses
Invoice payment result.
Canonical nested error envelope: use error.code, error.message, error.request_id and error.field_errors. Deprecated flat fields may be included for legacy clients. Generic server failures use service_unavailable without internal details. An interrupted connection may leave a write outcome unknown.
Request example
bash
curl --disable -sS --globoff --max-time 30 -X POST "https://api.blazingfast.io/v1/billing/invoices/${BF_PATH_ID}/pay" -H "Authorization: Bearer $BF_API_BEARER" -H "Idempotency-Key: $BF_REQUEST_KEY"Setup and request inputs
Create a bearer-mode key in Settings → API with the scopes shown above. Set BF_API_BEARER privately to its full prefix.secret value. These are request snippets, not complete applications. This page does not send requests.
Bash · cURL 7.87+. Supply URL-encoded path values; query values are encoded by cURL.
BF_PATH_ID — path parameter id (required). Invoice UUID.
BF_HEADER_X_CLIENT_REQUEST_ID — header parameter x-client-request-id (optional). Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
BF_REQUEST_KEY — header parameter Idempotency-Key (required). Reuse the same key and payload for retries of one intended operation.
Review the target and payload before running. For a payment, check the invoice and outstanding amount first. Reuse BF_REQUEST_KEY for retries of the same operation; check status after an interrupted request.
Check the HTTP status and handle errors in your application. Examples validate TLS, have a 30-second request limit, and never automatically retry or follow redirects. Run cURL on a private workstation: expanded tokens appear in process arguments, so disable shell tracing and command logging. Do not log passwords or share credential responses.
Example response · HTTP 200
json
{
"ok": true,
"paidNow": "100",
"partial": false,
"fullyPaid": true,
"invoiceId": "00000000-0000-4000-8000-000000000001",
"orderId": null,
"status": "paid",
"meta": {
"createdServices": 0,
"renewedServices": 1,
"createdServiceIds": [],
"provisioning": null
}
}Illustrative values, not a live result.
/v1/billing/orders/draft
Start draft order
Operation ID: billingOrderDraft
Creates a draft order from one or more items so you can continue into invoice creation and payment.
| Parameter | Location | Type | Required | Description |
|---|---|---|---|---|
| x-client-request-id | header | string | No | Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key. |
| x-ts | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-nonce | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-content-sha256 | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-signature | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
Request body
application/json schema
{
"type": "object",
"properties": {
"idempotency_key": {
"type": "string",
"minLength": 1,
"maxLength": 200
},
"currency": {
"type": "string",
"enum": [
"USD",
"EUR",
"UAH",
"GBP",
"PLN",
"BRL",
"INR",
"IDR",
"CNY"
]
},
"items": {
"type": "array",
"items": {
"type": "object",
"properties": {
"product_id": {
"type": "string",
"format": "uuid"
},
"variant_id": {
"type": "string",
"format": "uuid"
},
"qty": {
"type": "integer",
"minimum": 1,
"maximum": 100
},
"user_config": {
"anyOf": [
{
"type": "string"
},
{
"type": "number"
},
{
"type": "boolean"
},
{
"type": "null"
},
{
"type": "array",
"items": {
"description": "JSON value; product-specific fields are discovered through order-options."
}
},
{
"type": "object",
"additionalProperties": {
"description": "JSON value; product-specific fields are discovered through order-options."
}
}
]
},
"attributes": {
"anyOf": [
{
"type": "string"
},
{
"type": "number"
},
{
"type": "boolean"
},
{
"type": "null"
},
{
"type": "array",
"items": {
"description": "JSON value; product-specific fields are discovered through order-options."
}
},
{
"type": "object",
"additionalProperties": {
"description": "JSON value; product-specific fields are discovered through order-options."
}
}
]
},
"billing": {
"type": "object",
"properties": {
"unit": {
"type": "string",
"enum": [
"ONCE",
"HOUR",
"DAY",
"WEEK",
"MONTH",
"QUARTAL",
"SEMIANNUAL",
"YEAR"
]
},
"count": {
"type": "integer",
"minimum": 1,
"maximum": 120
}
},
"required": [
"unit",
"count"
],
"additionalProperties": false
},
"addons": {
"type": "array",
"items": {
"type": "object",
"properties": {
"key": {
"type": "string",
"minLength": 1,
"maxLength": 120,
"pattern": "^[A-Za-z0-9_.:-]+$"
},
"qty": {
"type": "integer",
"minimum": 1,
"maximum": 100
}
},
"required": [
"key",
"qty"
],
"additionalProperties": false
},
"maxItems": 50
}
},
"required": [
"product_id",
"variant_id",
"qty",
"billing"
],
"additionalProperties": false
},
"minItems": 1,
"maxItems": 50
}
},
"required": [
"currency",
"items"
],
"additionalProperties": false,
"example": {
"currency": "EUR",
"items": [
{
"product_id": "00000000-0000-4000-8000-000000000001",
"variant_id": "00000000-0000-4000-8000-000000000002",
"qty": 1,
"billing": {
"unit": "MONTH",
"count": 1
},
"user_config": {
"hostname": "example",
"location": "NL",
"os": {
"code": "debian-13"
}
},
"addons": []
}
]
},
"description": "Illustrative VPS cart. Replace IDs, required user_config fields, billing period and add-ons with the selected public plan’s order-options. The server validates ownership, eligibility and prices; caller-supplied hardware/price cannot change the plan. Quotes require complete billing details and use account currency."
}Responses
Created draft order and related billing payload.
Canonical nested error envelope: use error.code, error.message, error.request_id and error.field_errors. Deprecated flat fields may be included for legacy clients. Generic server failures use service_unavailable without internal details. An interrupted connection may leave a write outcome unknown.
Request example
bash
curl --disable -sS --globoff --max-time 30 -X POST "https://api.blazingfast.io/v1/billing/orders/draft" -H "Authorization: Bearer $BF_API_BEARER" -H "Idempotency-Key: $BF_REQUEST_KEY" -H 'Content-Type: application/json' --data '{"currency":"EUR","items":[{"product_id":"00000000-0000-4000-8000-000000000001","variant_id":"00000000-0000-4000-8000-000000000002","qty":1,"billing":{"unit":"MONTH","count":1},"user_config":{"hostname":"example","location":"NL","os":{"code":"debian-13"}},"addons":[]}]}'Setup and request inputs
Create a bearer-mode key in Settings → API with the scopes shown above. Set BF_API_BEARER privately to its full prefix.secret value. These are request snippets, not complete applications. This page does not send requests.
Bash · cURL 7.87+. Supply URL-encoded path values; query values are encoded by cURL.
BF_HEADER_X_CLIENT_REQUEST_ID — header parameter x-client-request-id (optional). Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
BF_REQUEST_KEY — header parameter Idempotency-Key (required). Reuse the same key and payload for retries of one intended operation.
Replace example body values with your configuration. Discover compatible profile IDs and account-owned key IDs before use.
Review the target and payload before running. For a payment, check the invoice and outstanding amount first. Reuse BF_REQUEST_KEY for retries of the same operation; check status after an interrupted request.
Check the HTTP status and handle errors in your application. Examples validate TLS, have a 30-second request limit, and never automatically retry or follow redirects. Run cURL on a private workstation: expanded tokens appear in process arguments, so disable shell tracing and command logging. Do not log passwords or share credential responses.
Example response · HTTP 200
json
{
"ok": true,
"orderId": "00000000-0000-4000-8000-000000000001",
"invoiceId": "00000000-0000-4000-8000-000000000002",
"invoiceNumber": "INV-EXAMPLE-000001",
"total": "100.00",
"currency": "EUR",
"status": "unpaid"
}Illustrative values, not a live result.
/v1/billing/orders/preview
Preview order total
Operation ID: billingOrderPreview
Submit the same complete cart as order creation, including userConfig and public add-on key/qty selections. Uses checkout validation and pricing, equivalent billing periods, account currency and tax. Requires complete billing details. Returns reserved=false: no reservation, order, invoice or payment is created. A quote does not guarantee later stock or prices. The older single-item preview body is accepted and normalized to the same cart.
| Parameter | Location | Type | Required | Description |
|---|---|---|---|---|
| x-client-request-id | header | string | No | Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key. |
| x-ts | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-nonce | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-content-sha256 | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-signature | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
Request body
application/json schema
{
"anyOf": [
{
"type": "object",
"properties": {
"idempotency_key": {
"type": "string",
"minLength": 1,
"maxLength": 200
},
"currency": {
"type": "string",
"enum": [
"USD",
"EUR",
"UAH",
"GBP",
"PLN",
"BRL",
"INR",
"IDR",
"CNY"
]
},
"items": {
"type": "array",
"items": {
"type": "object",
"properties": {
"product_id": {
"type": "string",
"format": "uuid"
},
"variant_id": {
"type": "string",
"format": "uuid"
},
"qty": {
"type": "integer",
"minimum": 1,
"maximum": 100
},
"user_config": {
"anyOf": [
{
"type": "string"
},
{
"type": "number"
},
{
"type": "boolean"
},
{
"type": "null"
},
{
"type": "array",
"items": {
"description": "JSON value; product-specific fields are discovered through order-options."
}
},
{
"type": "object",
"additionalProperties": {
"description": "JSON value; product-specific fields are discovered through order-options."
}
}
]
},
"attributes": {
"anyOf": [
{
"type": "string"
},
{
"type": "number"
},
{
"type": "boolean"
},
{
"type": "null"
},
{
"type": "array",
"items": {
"description": "JSON value; product-specific fields are discovered through order-options."
}
},
{
"type": "object",
"additionalProperties": {
"description": "JSON value; product-specific fields are discovered through order-options."
}
}
]
},
"billing": {
"type": "object",
"properties": {
"unit": {
"type": "string",
"enum": [
"ONCE",
"HOUR",
"DAY",
"WEEK",
"MONTH",
"QUARTAL",
"SEMIANNUAL",
"YEAR"
]
},
"count": {
"type": "integer",
"minimum": 1,
"maximum": 120
}
},
"required": [
"unit",
"count"
],
"additionalProperties": false
},
"addons": {
"type": "array",
"items": {
"type": "object",
"properties": {
"key": {
"type": "string",
"minLength": 1,
"maxLength": 120,
"pattern": "^[A-Za-z0-9_.:-]+$"
},
"qty": {
"type": "integer",
"minimum": 1,
"maximum": 100
}
},
"required": [
"key",
"qty"
],
"additionalProperties": false
},
"maxItems": 50
}
},
"required": [
"product_id",
"variant_id",
"qty",
"billing"
],
"additionalProperties": false
},
"minItems": 1,
"maxItems": 50
}
},
"required": [
"currency",
"items"
],
"additionalProperties": false
},
{
"type": "object",
"properties": {
"product_id": {
"type": "string",
"format": "uuid"
},
"variant_id": {
"type": "string",
"format": "uuid"
},
"currency": {
"type": "string",
"maxLength": 3,
"minLength": 3
},
"unit": {
"type": "string",
"minLength": 1,
"maxLength": 20
},
"count": {
"type": "integer",
"minimum": 1,
"maximum": 120
},
"quantity": {
"type": "integer",
"minimum": 1,
"maximum": 100,
"default": 1
},
"user_config": {
"anyOf": [
{
"type": "string"
},
{
"type": "number"
},
{
"type": "boolean"
},
{
"type": "null"
},
{
"type": "array",
"items": {
"description": "JSON value; product-specific fields are discovered through order-options."
}
},
{
"type": "object",
"additionalProperties": {
"description": "JSON value; product-specific fields are discovered through order-options."
}
}
]
},
"addons": {
"type": "array",
"items": {
"type": "object",
"properties": {
"key": {
"type": "string",
"minLength": 1,
"maxLength": 120,
"pattern": "^[A-Za-z0-9_.:-]+$"
},
"qty": {
"type": "integer",
"minimum": 1,
"maximum": 100
}
},
"required": [
"key",
"qty"
],
"additionalProperties": false
},
"maxItems": 50
}
},
"required": [
"product_id",
"variant_id",
"currency",
"unit",
"count"
],
"additionalProperties": false
}
],
"example": {
"currency": "EUR",
"items": [
{
"product_id": "00000000-0000-4000-8000-000000000001",
"variant_id": "00000000-0000-4000-8000-000000000002",
"qty": 1,
"billing": {
"unit": "MONTH",
"count": 1
},
"user_config": {
"hostname": "example",
"location": "NL",
"os": {
"code": "debian-13"
}
},
"addons": []
}
]
},
"description": "Illustrative VPS cart. Replace IDs, required user_config fields, billing period and add-ons with the selected public plan’s order-options. The server validates ownership, eligibility and prices; caller-supplied hardware/price cannot change the plan. Quotes require complete billing details and use account currency."
}Responses
Order preview with calculated totals.
Canonical nested error envelope: use error.code, error.message, error.request_id and error.field_errors. Deprecated flat fields may be included for legacy clients. Generic server failures use service_unavailable without internal details. An interrupted connection may leave a write outcome unknown.
Request example
bash
curl --disable -sS --globoff --max-time 30 -X POST "https://api.blazingfast.io/v1/billing/orders/preview" -H "Authorization: Bearer $BF_API_BEARER" -H 'Content-Type: application/json' --data '{"currency":"EUR","items":[{"product_id":"00000000-0000-4000-8000-000000000001","variant_id":"00000000-0000-4000-8000-000000000002","qty":1,"billing":{"unit":"MONTH","count":1},"user_config":{"hostname":"example","location":"NL","os":{"code":"debian-13"}},"addons":[]}]}'Setup and request inputs
Create a bearer-mode key in Settings → API with the scopes shown above. Set BF_API_BEARER privately to its full prefix.secret value. These are request snippets, not complete applications. This page does not send requests.
Bash · cURL 7.87+. Supply URL-encoded path values; query values are encoded by cURL.
BF_HEADER_X_CLIENT_REQUEST_ID — header parameter x-client-request-id (optional). Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
Replace example body values with your configuration. Discover compatible profile IDs and account-owned key IDs before use.
Review the target and payload before running. For a payment, check the invoice and outstanding amount first. Reuse BF_REQUEST_KEY for retries of the same operation; check status after an interrupted request.
Check the HTTP status and handle errors in your application. Examples validate TLS, have a 30-second request limit, and never automatically retry or follow redirects. Run cURL on a private workstation: expanded tokens appear in process arguments, so disable shell tracing and command logging. Do not log passwords or share credential responses.
Example response · HTTP 200
json
{
"ok": true,
"currency": "EUR",
"subtotal": "100.00",
"tax": "0.00",
"total": "100.00",
"reserved": false,
"breakdown": {
"base_price": "100.00",
"addons": "0.00",
"setup_fee": "0.00",
"tax": "0.00",
"total": "100.00"
},
"items": [
{
"productId": "00000000-0000-4000-8000-000000000001",
"variantId": "00000000-0000-4000-8000-000000000002",
"productName": "Example VPS",
"sku": "4G",
"quantity": 1,
"billing": {
"unit": "MONTH",
"count": 1
},
"unitPrice": "100",
"setupFee": "0",
"subtotal": "100",
"addons": []
}
]
}Illustrative values, not a live result.
/v1/billing/balance
Check wallet balance
Operation ID: billingBalance
Returns current account credit and currency so billing dashboards or automation can decide whether balance payment is available.
| Parameter | Location | Type | Required | Description |
|---|---|---|---|---|
| x-client-request-id | header | string | No | Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key. |
| x-ts | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-nonce | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-content-sha256 | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-signature | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
Request body
No request body
Responses
Current balance details.
Canonical nested error envelope: use error.code, error.message, error.request_id and error.field_errors. Deprecated flat fields may be included for legacy clients. Generic server failures use service_unavailable without internal details. An interrupted connection may leave a write outcome unknown.
Request example
bash
curl --disable -sS --globoff --max-time 30 -X GET "https://api.blazingfast.io/v1/billing/balance" -H "Authorization: Bearer $BF_API_BEARER"Setup and request inputs
Create a bearer-mode key in Settings → API with the scopes shown above. Set BF_API_BEARER privately to its full prefix.secret value. These are request snippets, not complete applications. This page does not send requests.
Bash · cURL 7.87+. Supply URL-encoded path values; query values are encoded by cURL.
BF_HEADER_X_CLIENT_REQUEST_ID — header parameter x-client-request-id (optional). Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
Check the HTTP status and handle errors in your application. Examples validate TLS, have a 30-second request limit, and never automatically retry or follow redirects. Run cURL on a private workstation: expanded tokens appear in process arguments, so disable shell tracing and command logging. Do not log passwords or share credential responses.
Example response · HTTP 200
json
{
"ok": true,
"exists": true,
"currency": "EUR",
"credit": "100",
"vcredit": "0"
}Illustrative values, not a live result.
/v1/billing/invoices
Browse invoices
Operation ID: listInvoices
Returns paginated customer invoices. Use this to build invoice history views, overdue checks, or reconciliation jobs.
| Parameter | Location | Type | Required | Description |
|---|---|---|---|---|
| page | query | integer | No | Page number for pagination. |
| limit | query | integer | No | Maximum items to return (default 50; range 1–100). Canonical page-size parameter. Deprecated page_size and pageSize aliases remain accepted; supplied size values must match. |
| page_size Deprecated | query | integer | No | Deprecated compatibility alias for limit; values must match when supplied together. |
| pageSize Deprecated | query | integer | No | Deprecated compatibility alias for limit; range 1–100, default 50. |
| x-client-request-id | header | string | No | Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key. |
| x-ts | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-nonce | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-content-sha256 | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-signature | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
Request body
No request body
Responses
Paginated invoice list.
Canonical nested error envelope: use error.code, error.message, error.request_id and error.field_errors. Deprecated flat fields may be included for legacy clients. Generic server failures use service_unavailable without internal details. An interrupted connection may leave a write outcome unknown.
Request example
bash
curl --disable -sS --globoff --max-time 30 -X GET "https://api.blazingfast.io/v1/billing/invoices" -H "Authorization: Bearer $BF_API_BEARER"Setup and request inputs
Create a bearer-mode key in Settings → API with the scopes shown above. Set BF_API_BEARER privately to its full prefix.secret value. These are request snippets, not complete applications. This page does not send requests.
Bash · cURL 7.87+. Supply URL-encoded path values; query values are encoded by cURL.
BF_QUERY_PAGE — query parameter page (optional). Page number for pagination. Supply the unencoded value; only required query parameters are included in the snippet.
BF_QUERY_LIMIT — query parameter limit (optional). Maximum items to return (default 50; range 1–100). Canonical page-size parameter. Deprecated page_size and pageSize aliases remain accepted; supplied size values must match. Supply the unencoded value; only required query parameters are included in the snippet.
BF_HEADER_X_CLIENT_REQUEST_ID — header parameter x-client-request-id (optional). Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
Check the HTTP status and handle errors in your application. Examples validate TLS, have a 30-second request limit, and never automatically retry or follow redirects. Run cURL on a private workstation: expanded tokens appear in process arguments, so disable shell tracing and command logging. Do not log passwords or share credential responses.
Example response · HTTP 200
json
{
"ok": true,
"page": 1,
"pageSize": 50,
"total": 1,
"pages": 1,
"items": [
{
"id": "00000000-0000-4000-8000-000000000001",
"number": "INV-EXAMPLE-000001",
"status": "unpaid",
"total": "100.00",
"paidTotal": "0.00",
"currency": "EUR",
"type": "purchase",
"refundedTotal": "0.00",
"createdAt": "2026-10-01T00:00:00.000Z",
"dueDate": "2026-11-01T00:00:00.000Z",
"payDate": null,
"order": null
}
]
}Illustrative values, not a live result.
/v1/billing/invoices/unpaid-total
Check unpaid total
Operation ID: billingUnpaidTotal
Returns the current unpaid amount across customer invoices. This is useful for dashboard badges and automation that should pause when debt exists.
| Parameter | Location | Type | Required | Description |
|---|---|---|---|---|
| x-client-request-id | header | string | No | Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key. |
| x-ts | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-nonce | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-content-sha256 | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-signature | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
Request body
No request body
Responses
Current unpaid invoice summary.
Canonical nested error envelope: use error.code, error.message, error.request_id and error.field_errors. Deprecated flat fields may be included for legacy clients. Generic server failures use service_unavailable without internal details. An interrupted connection may leave a write outcome unknown.
Request example
bash
curl --disable -sS --globoff --max-time 30 -X GET "https://api.blazingfast.io/v1/billing/invoices/unpaid-total" -H "Authorization: Bearer $BF_API_BEARER"Setup and request inputs
Create a bearer-mode key in Settings → API with the scopes shown above. Set BF_API_BEARER privately to its full prefix.secret value. These are request snippets, not complete applications. This page does not send requests.
Bash · cURL 7.87+. Supply URL-encoded path values; query values are encoded by cURL.
BF_HEADER_X_CLIENT_REQUEST_ID — header parameter x-client-request-id (optional). Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
Check the HTTP status and handle errors in your application. Examples validate TLS, have a 30-second request limit, and never automatically retry or follow redirects. Run cURL on a private workstation: expanded tokens appear in process arguments, so disable shell tracing and command logging. Do not log passwords or share credential responses.
Example response · HTTP 200
json
{
"ok": true,
"data": {
"unpaidTotal": 0,
"currency": "EUR"
}
}Illustrative values, not a live result.
/v1/billing/orders
Browse orders
Operation ID: billingOrders
Returns paginated customer orders and supports filtering by order or payment status for reporting and customer portals.
| Parameter | Location | Type | Required | Description |
|---|---|---|---|---|
| page | query | integer | No | Page number for pagination. |
| limit | query | integer | No | Maximum items to return (default 50; range 1–100). Canonical page-size parameter. Deprecated page_size and pageSize aliases remain accepted; supplied size values must match. |
| page_size Deprecated | query | integer | No | Deprecated compatibility alias for limit; values must match when supplied together. |
| pageSize Deprecated | query | integer | No | Deprecated compatibility alias for limit; range 1–100, default 50. |
| status | query | string | No | Optional order status filter. |
| paymentStatus | query | string | No | Optional payment status filter. |
| external_id | query | string | No | Exact customer reference on an owned order item; applied before pagination. |
| x-client-request-id | header | string | No | Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key. |
| x-ts | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-nonce | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-content-sha256 | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-signature | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
Request body
No request body
Responses
Paginated order list.
Canonical nested error envelope: use error.code, error.message, error.request_id and error.field_errors. Deprecated flat fields may be included for legacy clients. Generic server failures use service_unavailable without internal details. An interrupted connection may leave a write outcome unknown.
Request example
bash
curl --disable -sS --globoff --max-time 30 -X GET "https://api.blazingfast.io/v1/billing/orders" -H "Authorization: Bearer $BF_API_BEARER"Setup and request inputs
Create a bearer-mode key in Settings → API with the scopes shown above. Set BF_API_BEARER privately to its full prefix.secret value. These are request snippets, not complete applications. This page does not send requests.
Bash · cURL 7.87+. Supply URL-encoded path values; query values are encoded by cURL.
BF_QUERY_PAGE — query parameter page (optional). Page number for pagination. Supply the unencoded value; only required query parameters are included in the snippet.
BF_QUERY_LIMIT — query parameter limit (optional). Maximum items to return (default 50; range 1–100). Canonical page-size parameter. Deprecated page_size and pageSize aliases remain accepted; supplied size values must match. Supply the unencoded value; only required query parameters are included in the snippet.
BF_QUERY_STATUS — query parameter status (optional). Optional order status filter. Supply the unencoded value; only required query parameters are included in the snippet.
BF_QUERY_PAYMENT_STATUS — query parameter paymentStatus (optional). Optional payment status filter. Supply the unencoded value; only required query parameters are included in the snippet.
BF_QUERY_EXTERNAL_ID — query parameter external_id (optional). Exact customer reference on an owned order item; applied before pagination. Supply the unencoded value; only required query parameters are included in the snippet.
BF_HEADER_X_CLIENT_REQUEST_ID — header parameter x-client-request-id (optional). Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
Check the HTTP status and handle errors in your application. Examples validate TLS, have a 30-second request limit, and never automatically retry or follow redirects. Run cURL on a private workstation: expanded tokens appear in process arguments, so disable shell tracing and command logging. Do not log passwords or share credential responses.
Example response · HTTP 200
json
{
"ok": true,
"page": 1,
"pageSize": 50,
"total": 1,
"pages": 1,
"items": [
{
"id": "00000000-0000-4000-8000-000000000001",
"status": "pending",
"currency": "EUR",
"total": "100.00",
"paymentStatus": "unpaid",
"paymentMethod": null,
"createdAt": "2026-10-01T00:00:00.000Z",
"invoice": {
"id": "00000000-0000-4000-8000-000000000001",
"number": "INV-EXAMPLE-000001",
"status": "unpaid",
"total": "100.00",
"paidTotal": "0.00",
"currency": "EUR"
}
}
]
}Illustrative values, not a live result.
/v1/billing/products
Browse product catalog
Operation ID: billingProducts
Returns product catalog entries that can be used for storefront search, quoting, and pre-checkout selection flows.
| Parameter | Location | Type | Required | Description |
|---|---|---|---|---|
| page | query | integer | No | Page number for pagination. |
| limit | query | integer | No | Maximum items to return (default 50; range 1–100). Canonical page-size parameter. Deprecated page_size and pageSize aliases remain accepted; supplied size values must match. |
| page_size Deprecated | query | integer | No | Deprecated compatibility alias for limit; values must match when supplied together. |
| pageSize Deprecated | query | integer | No | Deprecated compatibility alias for limit; range 1–100, default 50. |
| category | query | string | No | Optional category filter. |
| q | query | string | No | Optional free-text search query. |
| x-client-request-id | header | string | No | Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key. |
| x-ts | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-nonce | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-content-sha256 | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-signature | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
Request body
No request body
Responses
Paginated product list.
Canonical nested error envelope: use error.code, error.message, error.request_id and error.field_errors. Deprecated flat fields may be included for legacy clients. Generic server failures use service_unavailable without internal details. An interrupted connection may leave a write outcome unknown.
Request example
bash
curl --disable -sS --globoff --max-time 30 -X GET "https://api.blazingfast.io/v1/billing/products" -H "Authorization: Bearer $BF_API_BEARER"Setup and request inputs
Create a bearer-mode key in Settings → API with the scopes shown above. Set BF_API_BEARER privately to its full prefix.secret value. These are request snippets, not complete applications. This page does not send requests.
Bash · cURL 7.87+. Supply URL-encoded path values; query values are encoded by cURL.
BF_QUERY_PAGE — query parameter page (optional). Page number for pagination. Supply the unencoded value; only required query parameters are included in the snippet.
BF_QUERY_LIMIT — query parameter limit (optional). Maximum items to return (default 50; range 1–100). Canonical page-size parameter. Deprecated page_size and pageSize aliases remain accepted; supplied size values must match. Supply the unencoded value; only required query parameters are included in the snippet.
BF_QUERY_CATEGORY — query parameter category (optional). Optional category filter. Supply the unencoded value; only required query parameters are included in the snippet.
BF_QUERY_Q — query parameter q (optional). Optional free-text search query. Supply the unencoded value; only required query parameters are included in the snippet.
BF_HEADER_X_CLIENT_REQUEST_ID — header parameter x-client-request-id (optional). Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
Check the HTTP status and handle errors in your application. Examples validate TLS, have a 30-second request limit, and never automatically retry or follow redirects. Run cURL on a private workstation: expanded tokens appear in process arguments, so disable shell tracing and command logging. Do not log passwords or share credential responses.
Example response · HTTP 200
json
{
"ok": true,
"page": 1,
"pageSize": 50,
"total": 1,
"pages": 1,
"items": [
{
"id": "00000000-0000-4000-8000-000000000001",
"name": "Example VPS",
"category": "vps",
"variants": [
{
"id": "00000000-0000-4000-8000-000000000002",
"productId": "00000000-0000-4000-8000-000000000001",
"sku": "4G",
"serviceType": "vps",
"attributes": {
"compute": {
"CPU": 2,
"RAM": 4
},
"storage": {
"DISK_SPACE": 40
}
},
"addons": [],
"billingOptions": [
{
"unit": "MONTH",
"count": 1,
"currency": "EUR",
"price": "100.00",
"setupFee": "0.00"
}
]
}
]
}
]
}Illustrative values, not a live result.
/v1/billing/products/{productId}/variants/{variantId}/order-options
Discover product order options
Operation ID: billingProductOrderOptions
Read-only complete configuration discovery for a public, active product and variant. Returns required and optional fields, conditional requirements, priced add-ons, billing options and eligible OS/regions. VPS uses userConfig.location and userConfig.os.code. Managed dedicated uses userConfig.dedicated.configurationCode, regionCode, osProfileId and hostname; optional sshKeyId must belong to your account. Includes physical/default connectivity, purchasable bandwidth add-ons, IPv4 limits and reservation TTL. supported=false means dashboard-only. No capacity is reserved; compatible catalog stock is not a reservation. Domain pricingMode=domain_quote requires a domain-specific quote. No infrastructure secrets are returned.
| Parameter | Location | Type | Required | Description |
|---|---|---|---|---|
| productId | path | string | Yes | Product UUID from the catalog. |
| variantId | path | string | Yes | Variant UUID belonging to this product. |
| region | query | string | No | Region code from GET /v1/regions, for example nl or pt. Case-insensitive. |
| currency | query | string | No | Pricing currency, default EUR. |
| x-client-request-id | header | string | No | Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key. |
| x-ts | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-nonce | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-content-sha256 | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-signature | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
Request body
No request body
Responses
Product-specific location and OS options. A catalog outage returns an error, never fallback options.
Canonical nested error envelope: use error.code, error.message, error.request_id and error.field_errors. Deprecated flat fields may be included for legacy clients. Generic server failures use service_unavailable without internal details. An interrupted connection may leave a write outcome unknown.
Request example
bash
curl --disable -sS --globoff --max-time 30 -X GET "https://api.blazingfast.io/v1/billing/products/${BF_PATH_PRODUCT_ID}/variants/${BF_PATH_VARIANT_ID}/order-options" -H "Authorization: Bearer $BF_API_BEARER"Setup and request inputs
Create a bearer-mode key in Settings → API with the scopes shown above. Set BF_API_BEARER privately to its full prefix.secret value. These are request snippets, not complete applications. This page does not send requests.
Bash · cURL 7.87+. Supply URL-encoded path values; query values are encoded by cURL.
BF_PATH_PRODUCT_ID — path parameter productId (required). Product UUID from the catalog.
BF_PATH_VARIANT_ID — path parameter variantId (required). Variant UUID belonging to this product.
BF_QUERY_REGION — query parameter region (optional). Region code from GET /v1/regions, for example nl or pt. Case-insensitive. Supply the unencoded value; only required query parameters are included in the snippet.
BF_QUERY_CURRENCY — query parameter currency (optional). Pricing currency, default EUR. Supply the unencoded value; only required query parameters are included in the snippet.
BF_HEADER_X_CLIENT_REQUEST_ID — header parameter x-client-request-id (optional). Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
Check the HTTP status and handle errors in your application. Examples validate TLS, have a 30-second request limit, and never automatically retry or follow redirects. Run cURL on a private workstation: expanded tokens appear in process arguments, so disable shell tracing and command logging. Do not log passwords or share credential responses.
Example response · HTTP 200
json
{
"ok": true,
"productId": "00000000-0000-4000-8000-000000000001",
"variantId": "00000000-0000-4000-8000-000000000002",
"supported": true,
"capacityVerified": false,
"requiredFields": [
{
"field": "hostname",
"label": "Hostname",
"description": "Server hostname.",
"format": "hostname"
},
{
"field": "location",
"label": "Location",
"description": "Location code."
},
{
"field": "os.code",
"label": "Operating system",
"description": "Operating system code."
}
],
"locations": [
{
"code": "NL",
"name": "Netherlands",
"operatingSystems": [
{
"code": "debian-13",
"name": "Debian",
"family": "debian",
"version": "13",
"arch": "amd64",
"isDefault": true
}
]
}
]
}Illustrative values, not a live result.
/v1/billing/services
Browse billable services
Operation ID: billingServices
Returns the billing-facing service list. Use this endpoint when the main goal is commercial visibility rather than grouped customer dashboards.
| Parameter | Location | Type | Required | Description |
|---|---|---|---|---|
| page | query | integer | No | Page number for pagination. |
| limit | query | integer | No | Maximum items to return (default 50; range 1–100). Canonical page-size parameter. Deprecated page_size and pageSize aliases remain accepted; supplied size values must match. |
| page_size Deprecated | query | integer | No | Deprecated compatibility alias for limit; values must match when supplied together. |
| pageSize Deprecated | query | integer | No | Deprecated compatibility alias for limit; range 1–100, default 50. |
| x-client-request-id | header | string | No | Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key. |
| x-ts | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-nonce | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-content-sha256 | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-signature | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
Request body
No request body
Responses
Paginated billing service list.
Canonical nested error envelope: use error.code, error.message, error.request_id and error.field_errors. Deprecated flat fields may be included for legacy clients. Generic server failures use service_unavailable without internal details. An interrupted connection may leave a write outcome unknown.
Request example
bash
curl --disable -sS --globoff --max-time 30 -X GET "https://api.blazingfast.io/v1/billing/services" -H "Authorization: Bearer $BF_API_BEARER"Setup and request inputs
Create a bearer-mode key in Settings → API with the scopes shown above. Set BF_API_BEARER privately to its full prefix.secret value. These are request snippets, not complete applications. This page does not send requests.
Bash · cURL 7.87+. Supply URL-encoded path values; query values are encoded by cURL.
BF_QUERY_PAGE — query parameter page (optional). Page number for pagination. Supply the unencoded value; only required query parameters are included in the snippet.
BF_QUERY_LIMIT — query parameter limit (optional). Maximum items to return (default 50; range 1–100). Canonical page-size parameter. Deprecated page_size and pageSize aliases remain accepted; supplied size values must match. Supply the unencoded value; only required query parameters are included in the snippet.
BF_HEADER_X_CLIENT_REQUEST_ID — header parameter x-client-request-id (optional). Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
Check the HTTP status and handle errors in your application. Examples validate TLS, have a 30-second request limit, and never automatically retry or follow redirects. Run cURL on a private workstation: expanded tokens appear in process arguments, so disable shell tracing and command logging. Do not log passwords or share credential responses.
Example response · HTTP 200
json
{
"ok": true,
"page": 1,
"pageSize": 50,
"total": 1,
"pages": 1,
"items": [
{
"id": "00000000-0000-4000-8000-000000000001",
"status": "active",
"displayName": "Example VPS",
"hostname": "server.example.com",
"type": "vps",
"createdAt": "2026-10-01T00:00:00.000Z",
"dueDate": "2026-11-01T00:00:00.000Z",
"billingUnit": "MONTH",
"billingCount": 1,
"sku": "4G",
"ipv4": "192.0.2.10",
"ipv6": null,
"meta": {
"serviceType": "vps"
}
}
]
}Illustrative values, not a live result.
/v1/billing/transactions
Browse transactions
Operation ID: billingTransactions
Returns paginated financial transaction records for account history and payment auditing.
| Parameter | Location | Type | Required | Description |
|---|---|---|---|---|
| page | query | integer | No | Page number for pagination. |
| limit | query | integer | No | Maximum items to return (default 50; range 1–100). Canonical page-size parameter. Deprecated page_size and pageSize aliases remain accepted; supplied size values must match. |
| page_size Deprecated | query | integer | No | Deprecated compatibility alias for limit; values must match when supplied together. |
| pageSize Deprecated | query | integer | No | Deprecated compatibility alias for limit; range 1–100, default 50. |
| x-client-request-id | header | string | No | Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key. |
| x-ts | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-nonce | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-content-sha256 | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
| x-signature | header | string | For SignedAuth | Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually. |
Request body
No request body
Responses
Paginated transaction list.
Canonical nested error envelope: use error.code, error.message, error.request_id and error.field_errors. Deprecated flat fields may be included for legacy clients. Generic server failures use service_unavailable without internal details. An interrupted connection may leave a write outcome unknown.
Request example
bash
curl --disable -sS --globoff --max-time 30 -X GET "https://api.blazingfast.io/v1/billing/transactions" -H "Authorization: Bearer $BF_API_BEARER"Setup and request inputs
Create a bearer-mode key in Settings → API with the scopes shown above. Set BF_API_BEARER privately to its full prefix.secret value. These are request snippets, not complete applications. This page does not send requests.
Bash · cURL 7.87+. Supply URL-encoded path values; query values are encoded by cURL.
BF_QUERY_PAGE — query parameter page (optional). Page number for pagination. Supply the unencoded value; only required query parameters are included in the snippet.
BF_QUERY_LIMIT — query parameter limit (optional). Maximum items to return (default 50; range 1–100). Canonical page-size parameter. Deprecated page_size and pageSize aliases remain accepted; supplied size values must match. Supply the unencoded value; only required query parameters are included in the snippet.
BF_HEADER_X_CLIENT_REQUEST_ID — header parameter x-client-request-id (optional). Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
Check the HTTP status and handle errors in your application. Examples validate TLS, have a 30-second request limit, and never automatically retry or follow redirects. Run cURL on a private workstation: expanded tokens appear in process arguments, so disable shell tracing and command logging. Do not log passwords or share credential responses.
Example response · HTTP 200
json
{
"ok": true,
"page": 1,
"pageSize": 50,
"total": 1,
"pages": 1,
"items": [
{
"id": "00000000-0000-4000-8000-000000000001",
"createdAt": "2026-10-01T00:00:00.000Z",
"status": "completed",
"type": "payment",
"currency": "EUR",
"amountIn": "100.00",
"amountOut": "0.00",
"fee": "0.00",
"gateway": null,
"invoiceId": "00000000-0000-4000-8000-000000000002",
"meta": null
}
]
}Illustrative values, not a live result.
Errors and safe retries
Use HTTP status and error.code for decisions. The canonical envelope contains error.message, error.request_id and error.field_errors. Flat code, message, request_id, field_errors, details and status fields are legacy compatibility fields and may still appear; new integrations should read the nested error.
json
{
"ok": false,
"error": {
"code": "scope_denied",
"message": "Required scope is missing",
"request_id": "00000000-0000-4000-8000-000000000001",
"field_errors": []
}
}Error code reference
Server failures and interrupted connections
Generic API server failures intentionally omit internal error codes and provider details and use the same nested envelope with service_unavailable. An edge/network failure can also return non-JSON or no response at all.
json
{
"ok": false,
"error": {
"code": "service_unavailable",
"message": "The service is temporarily unavailable.",
"request_id": "00000000-0000-4000-8000-000000000001",
"field_errors": []
}
}Read-only GET requests can be retried with bounded backoff and jitter. SDKs perform limited retries for selected transient read failures; they do not automatically retry writes. A timeout or 5xx on a write does not prove it failed: check the resource, invoice or task before retrying. Where supported, reuse the same Idempotency-Key and identical request. Do not create a new operation key just because the response was lost.
For 429, honor the HTTP Retry-After header. SDK timeout, network_error and response_too_large codes describe client-side failures, not API error responses. For persistent errors, send support the request ID, HTTP status, method, endpoint and UTC time—never API secrets or passwords.
See error handling in PHP, Node.js, Python and GoThis reference is generated from the current OpenAPI schema and documents 182 public operations. Each operation has a stable operationId and shows its method, path, parameters, required permissions and response models. cURL is selected by default; switch to Node.js, PHP, Python or Go for native HTTP examples. Download the OpenAPI JSON for client generation.
Use the integration guide for SDK/CLI 0.1.17 installation, authentication, pagination, retries, idempotency, webhooks and workflows. Generic OpenAPI clients do not automatically implement HMAC signing; use Bearer authentication or an official SDK unless you implement signing yourself.
Current purchase and operation workflows
SDK/CLI 0.1.17 supports contract 2026-10-07.1. Read GET /v1/version and GET /v1/capabilities, then discover product purchase policies and requirements before configuring a purchase. A quote is optional: discovery can lead directly to an authorized deployment. Quotes do not reserve stock or lock prices; send an authorized max_total ceiling for the full final order amount.
Draft order creation does not charge the account. Atomic deployment is the documented exception: it combines order creation, payment of the full final order amount from account balance and queued provisioning. Paid is not ready; accepted is not completed. Service lifecycle status is separate from runtime power state.
Supported tracked deployment, VPS and dedicated writes can return a canonical operation receipt and be recovered using their original idempotency key. This does not extend recovery to every write or historical request. See HTTP, SDK, CLI and MCP examples. DNSSEC uses its separate endpoint and state contract.
Pagination is endpoint-specific. Follow each endpoint's page/limit, cursor/next_cursor or offset/next_offset contract. limit is the canonical page-size request parameter; page_size and pageSize are deprecated compatibility aliases only where documented.
For service lists, ownership and filters are applied server-side before pagination. GET /v1/services defaults to active and suspended. group_by=type groups only the current page; GET /v1/services/grouped returns the complete inventory under its documented status/type filters, with its legacy active-only default. Pass status explicitly for this compatibility endpoint; prefer /v1/services?statuses=active,suspended&group_by=type for new automation.
API errors use the canonical nested error.code, error.message, error.request_id and error.field_errors structure. Flat error fields remain legacy compatibility fields. Most CLI lifecycle --request-key flags are optional; DNSSEC enable/disable require an explicit key. Preserve generated keys for retries. Examples describe requests and responses; this page does not send API requests.
On this page

