Every endpoint. One platform.

182 published operations, grouped by purpose. Expand any endpoint for its parameters, JSON contract and required scopes. This is a contract map, not a claim that every provider action has been live-tested.

SDK/CLI 0.1.17

Check GET /v1/version and GET /v1/capabilities before using optional workflow features. Strict response validation is enforced.

This reference describes the public contract. Discover deployed features using GET /v1/capabilities; contract coverage does not imply every provider lifecycle has been qualified. See the integration guide for SDK installation, CLI and MCP setup, workflows, retries, idempotency and webhooks.

Pagination and service inventory

Pagination is endpoint-specific. Follow the pagination model documented for each endpoint; do not send page to a cursor- or offset-based endpoint.

Page-based lists such as GET /v1/services use page and limit, with page, pageSize, total and pages in the response. Example: GET /v1/services?page=2&limit=50. Stop when page >= pages or items is empty.

Cursor-based lists such as GET /v1/api-credentials use limit and cursor. Pass the returned next_cursor unchanged on the next request; null means finished.

Offset-based lists such as GET /v1/products and GET /v1/dns/zones?view=summary use limit and offset. Use the returned next_offset; null means finished. DNS zone summary has its own default limit, while the default legacy view is not paginated.

limit is the canonical page-size parameter. Deprecated page_size and pageSize request aliases are retained only on endpoints that explicitly document them; supplied size values must match. Defaults and maximum sizes are endpoint-specific. Page-based responses retain pageSize for compatibility.

GET /v1/services applies ownership, status, type, search, external_id and label filters server-side before pagination and counts. Default states are active and suspended; historical services require an explicit status selection. group_by=type groups only the current page. GET /v1/services/grouped returns the complete inventory under its documented status/type filters, without pagination; its legacy compatibility default is active only; MCP/automation clients should pass status explicitly and prefer the paginated service endpoint with statuses=active,suspended.

Authentication

SignedAuth is represented by x-api-key for discovery only. Generic OpenAPI-generated clients do not automatically implement BlazingFast HMAC signing. Use BearerAuth with a bearer-mode credential or an official SDK, unless you implement the signing algorithm manually. Signed-key mode requires all five headers. SDKs send x-api-key, x-ts (Unix seconds), x-nonce, x-content-sha256 (Base64 SHA-256 of the exact body), and x-signature (Base64 HMAC-SHA256). Custom signing is explained in the API authentication guide. Every HTTP attempt needs a fresh timestamp and nonce; an action retry retains its original idempotency key and payload. Key expiry, IP restrictions, account permissions and scopes still apply.

Generic OpenAPI-generated clients do not automatically implement BlazingFast HMAC signing. Use Bearer authentication or an official SDK unless you implement signing manually. Conditional signing headers are required only with SignedAuth.

Error responses

The canonical envelope is ok: false with nested error.code, error.message, error.request_id and error.field_errors. Flat fields are deprecated legacy compatibility fields; prefer the nested values.

{
  "ok": false,
  "error": {
    "code": "scope_denied",
    "message": "Required scope is missing",
    "request_id": "00000000-0000-4000-8000-000000000001",
    "field_errors": []
  }
}
DiscoverQuote · optionalDeploy & payWaitManageWebhooks
NL and PT use the same regional contract.

Use /v1/products/nl/list/vps or /v1/products/pt/list/vps, then the exact discovered SKU and compatible OS in /v1/deploy/{region}/vps/{variantCode}. Plans, images, price and stock can differ. Dedicated inventory must be configured for that region; a working route does not imply available servers.

Quotes are optional. Direct deployment validates configuration and price; use max_total and a stable Idempotency-Key. Existing region-independent endpoints remain unchanged. All API requests require appropriate authentication and ownership.

2Deployments

Configure and quote a regional deployment, then authorize the full final order amount from account balance and queue provisioning. A quote is read-only; deployment is a financial write.

24Integrations

Version and capability discovery, credentials, OAuth connections, account audit and integration metadata.

10Catalog

Simple read-only discovery of regions, flat products and eligible operating-system images. Requires an authenticated API key.

11Billing

Browse products and valid order options, check prices, create unpaid orders, and view invoices, transactions and account balance. Paying an invoice from balance is a separate action.

15Services

List services, inspect billing details, and manage supported renewals, upgrades, billing settings, autopay and termination.

25VPS

Read VPS status and usage, control power, reinstall an operating system, update SSH keys, and manage snapshots and backups. Reinstallation and restoration can overwrite data; inspect the target first.

17Dedicated Servers

Browse dedicated server options, create unpaid deployments, inspect progress and tasks, and manage power, reinstall, rescue or password reset. Reinstall erases disks. Credential reads require separate permissions and must not be logged.

21DNS

Create an empty zone or use a template, JSON records or a zone file. Preview imports, manage DNS records, and inspect record protection and country policies. A DNS zone is not a domain registration.

12Service DNS/WAF

Manage website proxying, protection, origins and SSL settings for a hosting service. For protection on an owned DNS record without a hosting service ID, use the DNS record-protection endpoints instead.

20Domains

Check domain availability and manage registrations, contacts, nameservers, transfer settings, locks and privacy.

10SSH

Manage saved SSH keys for server access. Use public-key names and fingerprints for routine automation; do not share private keys with an AI assistant.

7Firewall

Read and manage firewall policies and rules, then apply them to eligible VPS services. Check that changes preserve SSH and management access.

5Storage

List storage volumes, check eligible servers, and attach, detach or rename supported volumes. Volumes provide storage capacity; backups provide recovery.

3TCP Proxy

Customer TCP Proxy port mappings, traffic analytics, source/country policies and per-port limits.

182 endpoints

Deployments

POST/v1/deploy/{region}/{productCode}/{variantCode}Deploy product variant from wallet

Operation ID: productVariantDeploy

One call validates a public VPS, managed dedicated, TCP proxy, Website Protection or software-license variant, creates its order/invoice, charges the full final order amount to the account balance and queues normal provisioning. Insufficient funds returns HTTP 402 insufficient_credit with no committed order/payment. Uses account billing currency and authoritative prices including tax, setup and add-ons. max_total is an optional decimal-string spending ceiling in that currency. Requires both scopes. Idempotency-Key is required; reuse identical arguments after interruption. Never charges a card or tops up the wallet. Acceptance is not a ready server: inspect returned serviceIds. Dedicated admin approvals, inventory and license rollout gates still apply. Domains/free products are not supported by this convenience endpoint; legacy unpaid checkout/payment remain unchanged.

Required scopes: billing.order.create + billing.invoice.pay

Parameters

  • region · path · required — Region code, for example nl or pt.
  • productCode · path · required — Catalog product_code: vps, dedicated, tcp-proxy, waf or license.
  • variantCode · path · required — Exact public catalog variant_code/SKU, for example 2G or PTV4-1.
  • Idempotency-Key · header · required — Stable retry key, 8–128 characters. Never replace it after an uncertain response.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-bf-response-format · header — Opt into the canonical Operation receipt for this tracked write. Requires canonical_operation_responses enabled. Omit for the legacy response. Retried requests may replay their initial response format; use its operation_id or operation.id to poll.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "anyOf": [
    {
      "type": "object",
      "properties": {
        "billing": {
          "type": "object",
          "properties": {
            "unit": {
              "type": "string",
              "enum": [
                "ONCE",
                "HOUR",
                "DAY",
                "WEEK",
                "MONTH",
                "QUARTAL",
                "SEMIANNUAL",
                "YEAR"
              ]
            },
            "count": {
              "type": "integer",
              "minimum": 1,
              "maximum": 120
            }
          },
          "required": [
            "unit",
            "count"
          ],
          "additionalProperties": false
        },
        "userConfig": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "number"
            },
            {
              "type": "boolean"
            },
            {
              "type": "null"
            },
            {
              "type": "array",
              "items": {
                "description": "JSON value; product-specific fields are discovered through order-options."
              }
            },
            {
              "type": "object",
              "additionalProperties": {
                "description": "JSON value; product-specific fields are discovered through order-options."
              }
            }
          ]
        },
        "addons": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "key": {
                "type": "string",
                "minLength": 1,
                "maxLength": 120,
                "pattern": "^[A-Za-z0-9_.:-]+$"
              },
              "qty": {
                "type": "integer",
                "minimum": 1,
                "maximum": 100
              }
            },
            "required": [
              "key",
              "qty"
            ],
            "additionalProperties": false
          },
          "maxItems": 50
        },
        "maxTotal": {
          "type": "string",
          "pattern": "^(0|[1-9]\\d{0,9})(\\.\\d{1,2})?$"
        }
      },
      "required": [
        "billing"
      ],
      "additionalProperties": false,
      "deprecated": true,
      "description": "Deprecated compatibility deployment shape. Prefer the canonical snake_case payload; no sunset date has been assigned."
    },
    {
      "type": "object",
      "properties": {
        "billing_cycle": {
          "type": "string",
          "enum": [
            "monthly",
            "quarterly",
            "semi_annually",
            "annually",
            "biennially",
            "triennially",
            "hourly",
            "daily",
            "weekly",
            "one_time"
          ],
          "default": "monthly"
        },
        "hostname": {
          "type": "string",
          "maxLength": 253,
          "pattern": "^[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)*$"
        },
        "os": {
          "anyOf": [
            {
              "type": "string",
              "minLength": 1,
              "maxLength": 160
            },
            {
              "type": "integer",
              "exclusiveMinimum": 0
            }
          ]
        },
        "ssh_key_id": {
          "type": "string",
          "format": "uuid"
        },
        "connectivity_gbps": {
          "type": "number",
          "exclusiveMinimum": 0,
          "maximum": 100
        },
        "additional_ips": {
          "type": "integer",
          "minimum": 0,
          "maximum": 100
        },
        "backend_ip": {
          "type": "string"
        },
        "ports": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "listen": {
                "type": "integer",
                "minimum": 1,
                "maximum": 65535
              },
              "backend": {
                "type": "integer",
                "minimum": 1,
                "maximum": 65535
              }
            },
            "required": [
              "listen",
              "backend"
            ],
            "additionalProperties": false
          },
          "minItems": 1,
          "maxItems": 100
        },
        "domain": {
          "type": "string",
          "minLength": 1,
          "maxLength": 253
        },
        "license_ip": {
          "type": "string"
        },
        "parent_service_id": {
          "type": "string",
          "format": "uuid"
        },
        "addons": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "key": {
                "type": "string",
                "maxLength": 120,
                "pattern": "^[A-Za-z0-9_.:-]+$"
              },
              "qty": {
                "type": "integer",
                "minimum": 1,
                "maximum": 100
              }
            },
            "required": [
              "key",
              "qty"
            ],
            "additionalProperties": false
          },
          "maxItems": 50
        },
        "max_total": {
          "type": "string",
          "pattern": "^(0|[1-9]\\d{0,9})(\\.\\d{1,2})?$"
        },
        "external_id": {
          "type": "string",
          "minLength": 1,
          "maxLength": 120
        },
        "labels": {
          "type": "object",
          "additionalProperties": {
            "type": "string",
            "maxLength": 120
          }
        }
      },
      "additionalProperties": false
    }
  ],
  "example": {
    "billing_cycle": "monthly",
    "hostname": "test",
    "os": "debian-13",
    "max_total": "25.00"
  },
  "description": "Simple fields: billing_cycle, hostname, os, owned ssh_key_id, dedicated connectivity_gbps/additional_ips, TCP backend_ip/ports, external_id/labels, max_total. Use discovered choices; dedicated OS accepts its exact code or numeric ID. Path fixes region. Legacy billing/userConfig/addons/maxTotal remains accepted; never mix both shapes. Ceilings include tax/setup/add-ons in account currency."
}

Successful response · HTTP 200

{
  "anyOf": [
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "orderId": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "invoiceId": {
          "type": "string"
        },
        "invoiceNumber": {
          "type": "string"
        },
        "invoice": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "number": {
              "type": "string"
            },
            "status": {
              "type": "string"
            },
            "total": {
              "type": "string"
            },
            "paidTotal": {
              "type": "string"
            },
            "currency": {
              "type": "string"
            },
            "createdAt": {
              "type": "string"
            },
            "dueDate": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "payDate": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "refundedTotal": {
              "type": "string"
            }
          },
          "required": [
            "id",
            "number",
            "status",
            "total",
            "paidTotal",
            "currency"
          ],
          "additionalProperties": true
        },
        "total": {
          "type": "string"
        },
        "currency": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "paymentStatus": {
          "type": "string"
        },
        "serviceIds": {
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "message": {
          "type": "string"
        },
        "deploymentStatusUrl": {
          "type": "string"
        },
        "applied": {
          "type": "boolean"
        },
        "payNow": {
          "type": "string"
        },
        "paidNow": {
          "type": "string"
        },
        "fullyPaid": {
          "type": "boolean"
        },
        "provisioning": {
          "type": "string"
        },
        "operation_id": {
          "type": "string"
        },
        "operation_url": {
          "type": "string"
        }
      },
      "required": [
        "ok",
        "paidNow",
        "fullyPaid",
        "provisioning"
      ],
      "additionalProperties": true
    },
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string",
              "enum": [
                "deployment",
                "vps",
                "dedicated"
              ]
            },
            "action": {
              "type": "string"
            },
            "status": {
              "type": "string",
              "enum": [
                "pending",
                "running",
                "succeeded",
                "failed",
                "cancelled",
                "unknown"
              ]
            },
            "done": {
              "type": "boolean"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number",
                  "minimum": 0,
                  "maximum": 100
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "created_at": {
              "type": "string",
              "format": "date-time"
            },
            "updated_at": {
              "anyOf": [
                {
                  "type": "string",
                  "format": "date-time"
                },
                {
                  "type": "null"
                }
              ]
            },
            "service_ids": {
              "type": "array",
              "items": {
                "type": "string",
                "format": "uuid"
              }
            },
            "error": {
              "anyOf": [
                {
                  "type": "object",
                  "properties": {
                    "code": {
                      "type": "string"
                    },
                    "message": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "code",
                    "message"
                  ],
                  "additionalProperties": false
                },
                {
                  "type": "null"
                }
              ]
            },
            "result": {
              "anyOf": [
                {
                  "anyOf": [
                    {
                      "type": "object",
                      "properties": {
                        "service_ids": {
                          "type": "array",
                          "items": {
                            "type": "string",
                            "format": "uuid"
                          },
                          "minItems": 1,
                          "maxItems": 50
                        },
                        "order_id": {
                          "anyOf": [
                            {
                              "type": "string",
                              "format": "uuid"
                            },
                            {
                              "type": "null"
                            }
                          ]
                        },
                        "invoice_id": {
                          "type": "string",
                          "format": "uuid"
                        }
                      },
                      "required": [
                        "service_ids"
                      ],
                      "additionalProperties": false
                    },
                    {
                      "type": "object",
                      "properties": {
                        "service_id": {
                          "type": "string",
                          "format": "uuid"
                        },
                        "os": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "snapshot_name": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "power_state": {
                          "type": "string",
                          "enum": [
                            "running",
                            "stopped"
                          ]
                        }
                      },
                      "required": [
                        "service_id"
                      ],
                      "additionalProperties": false
                    }
                  ]
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id",
            "kind",
            "action",
            "status",
            "done",
            "progress",
            "stage",
            "created_at",
            "updated_at",
            "service_ids",
            "error"
          ],
          "additionalProperties": false
        },
        "links": {
          "type": "object",
          "properties": {
            "operation": {
              "type": "string",
              "pattern": "^\\/v1\\/operations\\/op_[A-Za-z0-9_-]+$"
            },
            "service": {
              "type": "string",
              "pattern": "^\\/v1\\/services\\/[0-9a-f-]{36}$"
            },
            "invoice": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/invoices\\/[0-9a-f-]{36}$"
            },
            "order": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/orders\\/[0-9a-f-]{36}$"
            }
          },
          "required": [
            "operation"
          ],
          "additionalProperties": false
        }
      },
      "required": [
        "ok",
        "operation"
      ],
      "additionalProperties": false
    }
  ],
  "description": "Legacy response by default; x-bf-response-format: operation opts into the canonical receipt when durable operations are enabled. Retries retain the initial cached response format."
}

Illustrative successful response

{
  "ok": true,
  "orderId": "00000000-0000-4000-8000-000000000001",
  "invoiceId": "00000000-0000-4000-8000-000000000002",
  "invoiceNumber": "INV-EXAMPLE-000001",
  "total": "100.00",
  "currency": "EUR",
  "status": "paid",
  "paidNow": "100.00",
  "fullyPaid": true,
  "serviceIds": [
    "00000000-0000-4000-8000-000000000003"
  ],
  "provisioning": "queued",
  "operation_id": "op_EXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLE",
  "operation_url": "/v1/operations/op_EXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLE"
}

API reference and code examples

POST/v1/deploy/{region}/{productCode}/{variantCode}/quoteQuote a configured product by code

Operation ID: productVariantQuote

Accepts exactly the same simple or legacy body as deployment. Uses authoritative account currency, configuration, tax and add-on prices. Returns a price breakdown and reserved=false; creates no order, invoice, reservation or payment. No Idempotency-Key required. The quote object adds an opaque diagnostic id, guaranteed=false, currency, final total, breakdown, pricing_revision and recommended_max_total. Pass recommended_max_total as max_total to deployment. The revision fingerprints this priced cart; it is not a price lock, reservation or redeemable quote. A quote is optional and is not a stock or price guarantee.

Required scopes: billing.products.read

Parameters

  • region · path · required — Eligible region, for example nl or pt. A single region is required.
  • productCode · path · required — Product family.
  • variantCode · path · required — Exact case-sensitive public SKU, for example 2G or PTV4-1. Never an internal inventory ID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "anyOf": [
    {
      "type": "object",
      "properties": {
        "billing": {
          "type": "object",
          "properties": {
            "unit": {
              "type": "string",
              "enum": [
                "ONCE",
                "HOUR",
                "DAY",
                "WEEK",
                "MONTH",
                "QUARTAL",
                "SEMIANNUAL",
                "YEAR"
              ]
            },
            "count": {
              "type": "integer",
              "minimum": 1,
              "maximum": 120
            }
          },
          "required": [
            "unit",
            "count"
          ],
          "additionalProperties": false
        },
        "userConfig": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "number"
            },
            {
              "type": "boolean"
            },
            {
              "type": "null"
            },
            {
              "type": "array",
              "items": {
                "description": "JSON value; product-specific fields are discovered through order-options."
              }
            },
            {
              "type": "object",
              "additionalProperties": {
                "description": "JSON value; product-specific fields are discovered through order-options."
              }
            }
          ]
        },
        "addons": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "key": {
                "type": "string",
                "minLength": 1,
                "maxLength": 120,
                "pattern": "^[A-Za-z0-9_.:-]+$"
              },
              "qty": {
                "type": "integer",
                "minimum": 1,
                "maximum": 100
              }
            },
            "required": [
              "key",
              "qty"
            ],
            "additionalProperties": false
          },
          "maxItems": 50
        },
        "maxTotal": {
          "type": "string",
          "pattern": "^(0|[1-9]\\d{0,9})(\\.\\d{1,2})?$"
        }
      },
      "required": [
        "billing"
      ],
      "additionalProperties": false,
      "deprecated": true,
      "description": "Deprecated compatibility deployment shape. Prefer the canonical snake_case payload; no sunset date has been assigned."
    },
    {
      "type": "object",
      "properties": {
        "billing_cycle": {
          "type": "string",
          "enum": [
            "monthly",
            "quarterly",
            "semi_annually",
            "annually",
            "biennially",
            "triennially",
            "hourly",
            "daily",
            "weekly",
            "one_time"
          ],
          "default": "monthly"
        },
        "hostname": {
          "type": "string",
          "maxLength": 253,
          "pattern": "^[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)*$"
        },
        "os": {
          "anyOf": [
            {
              "type": "string",
              "minLength": 1,
              "maxLength": 160
            },
            {
              "type": "integer",
              "exclusiveMinimum": 0
            }
          ]
        },
        "ssh_key_id": {
          "type": "string",
          "format": "uuid"
        },
        "connectivity_gbps": {
          "type": "number",
          "exclusiveMinimum": 0,
          "maximum": 100
        },
        "additional_ips": {
          "type": "integer",
          "minimum": 0,
          "maximum": 100
        },
        "backend_ip": {
          "type": "string"
        },
        "ports": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "listen": {
                "type": "integer",
                "minimum": 1,
                "maximum": 65535
              },
              "backend": {
                "type": "integer",
                "minimum": 1,
                "maximum": 65535
              }
            },
            "required": [
              "listen",
              "backend"
            ],
            "additionalProperties": false
          },
          "minItems": 1,
          "maxItems": 100
        },
        "domain": {
          "type": "string",
          "minLength": 1,
          "maxLength": 253
        },
        "license_ip": {
          "type": "string"
        },
        "parent_service_id": {
          "type": "string",
          "format": "uuid"
        },
        "addons": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "key": {
                "type": "string",
                "maxLength": 120,
                "pattern": "^[A-Za-z0-9_.:-]+$"
              },
              "qty": {
                "type": "integer",
                "minimum": 1,
                "maximum": 100
              }
            },
            "required": [
              "key",
              "qty"
            ],
            "additionalProperties": false
          },
          "maxItems": 50
        },
        "max_total": {
          "type": "string",
          "pattern": "^(0|[1-9]\\d{0,9})(\\.\\d{1,2})?$"
        },
        "external_id": {
          "type": "string",
          "minLength": 1,
          "maxLength": 120
        },
        "labels": {
          "type": "object",
          "additionalProperties": {
            "type": "string",
            "maxLength": 120
          }
        }
      },
      "additionalProperties": false
    }
  ],
  "example": {
    "billing_cycle": "monthly",
    "hostname": "test",
    "os": "debian-13",
    "max_total": "25.00"
  },
  "description": "Simple fields: billing_cycle, hostname, os, owned ssh_key_id, dedicated connectivity_gbps/additional_ips, TCP backend_ip/ports, external_id/labels, max_total. Use discovered choices; dedicated OS accepts its exact code or numeric ID. Path fixes region. Legacy billing/userConfig/addons/maxTotal remains accepted; never mix both shapes. Ceilings include tax/setup/add-ons in account currency."
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "currency": {
      "type": "string",
      "maxLength": 3,
      "minLength": 3
    },
    "reserved": {
      "type": "boolean",
      "const": false,
      "enum": [
        false
      ]
    },
    "subtotal": {
      "type": "string",
      "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
    },
    "tax": {
      "type": "string",
      "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
    },
    "total": {
      "type": "string",
      "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
    },
    "breakdown": {
      "type": "object",
      "properties": {
        "base_price": {
          "type": "string",
          "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
        },
        "addons": {
          "type": "string",
          "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
        },
        "setup_fee": {
          "type": "string",
          "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
        },
        "tax": {
          "type": "string",
          "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
        },
        "total": {
          "type": "string",
          "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
        }
      },
      "required": [
        "base_price",
        "addons",
        "setup_fee",
        "tax",
        "total"
      ],
      "additionalProperties": false
    },
    "quote": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string",
          "pattern": "^quo_[a-f0-9]{64}$"
        },
        "currency": {
          "type": "string",
          "maxLength": 3,
          "minLength": 3
        },
        "total": {
          "type": "string",
          "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
        },
        "breakdown": {
          "type": "object",
          "properties": {
            "base_price": {
              "type": "string",
              "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
            },
            "addons": {
              "type": "string",
              "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
            },
            "setup_fee": {
              "type": "string",
              "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
            },
            "tax": {
              "type": "string",
              "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
            },
            "total": {
              "type": "string",
              "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
            }
          },
          "required": [
            "base_price",
            "addons",
            "setup_fee",
            "tax",
            "total"
          ],
          "additionalProperties": false
        },
        "guaranteed": {
          "type": "boolean",
          "const": false,
          "enum": [
            false
          ]
        },
        "pricing_revision": {
          "type": "string",
          "pattern": "^sha256:[a-f0-9]{64}$"
        },
        "recommended_max_total": {
          "type": "string",
          "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
        }
      },
      "required": [
        "id",
        "currency",
        "total",
        "breakdown",
        "guaranteed",
        "pricing_revision",
        "recommended_max_total"
      ],
      "additionalProperties": false
    },
    "links": {
      "type": "object",
      "properties": {
        "deploy": {
          "type": "string",
          "pattern": "^\\/v1\\/deploy\\/[A-Za-z0-9._%/-]+$"
        }
      },
      "required": [
        "deploy"
      ],
      "additionalProperties": false
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "productId": {
            "type": "string",
            "format": "uuid"
          },
          "variantId": {
            "type": "string",
            "format": "uuid"
          },
          "productName": {
            "type": "string",
            "maxLength": 500
          },
          "sku": {
            "type": "string",
            "maxLength": 200
          },
          "quantity": {
            "type": "integer",
            "minimum": 1,
            "maximum": 100
          },
          "billing": {
            "type": "object",
            "properties": {
              "unit": {
                "type": "string",
                "maxLength": 20
              },
              "count": {
                "type": "integer",
                "minimum": 1,
                "maximum": 120
              }
            },
            "required": [
              "unit",
              "count"
            ],
            "additionalProperties": false
          },
          "unitPrice": {
            "type": "string",
            "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
          },
          "setupFee": {
            "type": "string",
            "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
          },
          "subtotal": {
            "type": "string",
            "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
          },
          "addons": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "key": {
                  "type": "string",
                  "maxLength": 120
                },
                "name": {
                  "type": "string",
                  "maxLength": 500
                },
                "qty": {
                  "type": "integer",
                  "minimum": 1,
                  "maximum": 100
                },
                "unitPrice": {
                  "anyOf": [
                    {
                      "type": "string",
                      "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
                    },
                    {
                      "type": "number",
                      "minimum": 0
                    }
                  ]
                },
                "setupFee": {
                  "anyOf": [
                    {
                      "type": "string",
                      "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
                    },
                    {
                      "type": "number",
                      "minimum": 0
                    }
                  ]
                },
                "chargeType": {
                  "type": "string",
                  "maxLength": 40
                },
                "billedSeparately": {
                  "type": "boolean"
                }
              },
              "required": [
                "key",
                "name",
                "qty",
                "unitPrice",
                "setupFee",
                "chargeType"
              ],
              "additionalProperties": false
            },
            "maxItems": 100
          }
        },
        "required": [
          "productId",
          "variantId",
          "productName",
          "sku",
          "quantity",
          "billing",
          "unitPrice",
          "setupFee",
          "subtotal",
          "addons"
        ],
        "additionalProperties": false
      },
      "maxItems": 50
    }
  },
  "required": [
    "ok",
    "currency",
    "reserved",
    "subtotal",
    "tax",
    "total",
    "breakdown",
    "items"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "currency": "EUR",
  "subtotal": "12.00",
  "tax": "0.00",
  "total": "12.00",
  "reserved": false,
  "breakdown": {
    "base_price": "12.00",
    "addons": "0.00",
    "setup_fee": "0.00",
    "tax": "0.00",
    "total": "12.00"
  },
  "items": [
    {
      "productId": "00000000-0000-4000-8000-000000000001",
      "variantId": "00000000-0000-4000-8000-000000000002",
      "productName": "Example VPS",
      "sku": "2G",
      "quantity": 1,
      "billing": {
        "unit": "MONTH",
        "count": 1
      },
      "unitPrice": "12",
      "setupFee": "0",
      "subtotal": "12",
      "addons": []
    }
  ]
}

API reference and code examples

Integrations

GET/v1/api-credentialsList your API credentialsSensitive

Operation ID: apiCredentials

Owner-only, secret-free inventory. Cursor pagination defaults to 50. Managed MCP credentials are read-only here.

Required scopes: api_credentials.read

Parameters

  • limit · query — Maximum items, default 50.
  • cursor · query — Next UUID cursor.
  • include_revoked · query — Include revoked keys.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "format": "uuid"
          },
          "name": {
            "type": "string",
            "maxLength": 80
          },
          "prefix": {
            "type": "string",
            "maxLength": 32
          },
          "mode": {
            "type": "string",
            "enum": [
              "signed",
              "bearer"
            ]
          },
          "enabled": {
            "type": "boolean"
          },
          "created_at": {
            "type": "string",
            "format": "date-time"
          },
          "expires_at": {
            "type": "string",
            "format": "date-time"
          },
          "revoked_at": {
            "anyOf": [
              {
                "type": "string",
                "format": "date-time"
              },
              {
                "type": "null"
              }
            ]
          },
          "last_used_at": {
            "anyOf": [
              {
                "type": "string",
                "format": "date-time"
              },
              {
                "type": "null"
              }
            ]
          },
          "last_used_ip": {
            "anyOf": [
              {
                "type": "string",
                "maxLength": 64
              },
              {
                "type": "null"
              }
            ]
          },
          "scopes": {
            "type": "array",
            "items": {
              "type": "string",
              "maxLength": 80
            }
          },
          "allowed_cidrs": {
            "type": "array",
            "items": {
              "type": "string",
              "maxLength": 64
            }
          }
        },
        "required": [
          "id",
          "name",
          "prefix",
          "mode",
          "enabled",
          "created_at",
          "expires_at",
          "revoked_at",
          "last_used_at",
          "last_used_ip",
          "scopes",
          "allowed_cidrs"
        ],
        "additionalProperties": false
      },
      "maxItems": 100
    },
    "next_cursor": {
      "anyOf": [
        {
          "type": "string",
          "format": "uuid"
        },
        {
          "type": "null"
        }
      ]
    }
  },
  "required": [
    "ok",
    "items",
    "next_cursor"
  ],
  "additionalProperties": false
}

API reference and code examples

POST/v1/api-credentialsCreate a restricted API credentialSensitive

Operation ID: apiCredentialCreate

Requires a stable Idempotency-Key. Requested scopes and allowed CIDRs cannot exceed the issuer; expiry is capped by the issuer. The secret is returned only on issuance or same-key retry within 24 hours. Managed MCP/support keys cannot delegate.

Required scopes: api_credentials.write

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 80
    },
    "scopes": {
      "type": "array",
      "items": {
        "type": "string",
        "enum": [
          "audit.read",
          "api_credentials.read",
          "api_credentials.write",
          "oauth.connections.read",
          "oauth.connections.write",
          "billing.balance.read",
          "billing.invoices.read",
          "billing.orders.read",
          "billing.products.read",
          "billing.services.read",
          "billing.services.write",
          "billing.transactions.read",
          "billing.unpaid_total.read",
          "billing.order.create",
          "billing.invoice.pay",
          "vps.read",
          "vps.credentials.read",
          "vps.write",
          "dedicated.read",
          "dedicated.credentials.read",
          "dedicated.write",
          "dns.read",
          "dns.write",
          "domains.read",
          "domains.write",
          "ssh.read",
          "ssh.write",
          "firewall.read",
          "firewall.write",
          "storage.read",
          "storage.write",
          "tcp_proxy.read",
          "tcp_proxy.write",
          "webhooks.read",
          "webhooks.write"
        ]
      },
      "minItems": 1,
      "maxItems": 35
    },
    "mode": {
      "type": "string",
      "enum": [
        "signed",
        "bearer"
      ],
      "default": "signed"
    },
    "ttl_days": {
      "type": "integer",
      "minimum": 1,
      "maximum": 365,
      "default": 30
    },
    "allowed_cidrs": {
      "type": "array",
      "items": {
        "type": "string",
        "minLength": 1,
        "maxLength": 64
      },
      "maxItems": 50
    }
  },
  "required": [
    "name",
    "scopes"
  ],
  "additionalProperties": false
}

Successful response · HTTP 201

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "item": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string",
          "format": "uuid"
        },
        "name": {
          "type": "string",
          "maxLength": 80
        },
        "prefix": {
          "type": "string",
          "maxLength": 32
        },
        "mode": {
          "type": "string",
          "enum": [
            "signed",
            "bearer"
          ]
        },
        "enabled": {
          "type": "boolean"
        },
        "created_at": {
          "type": "string",
          "format": "date-time"
        },
        "expires_at": {
          "type": "string",
          "format": "date-time"
        },
        "revoked_at": {
          "anyOf": [
            {
              "type": "string",
              "format": "date-time"
            },
            {
              "type": "null"
            }
          ]
        },
        "last_used_at": {
          "anyOf": [
            {
              "type": "string",
              "format": "date-time"
            },
            {
              "type": "null"
            }
          ]
        },
        "last_used_ip": {
          "anyOf": [
            {
              "type": "string",
              "maxLength": 64
            },
            {
              "type": "null"
            }
          ]
        },
        "scopes": {
          "type": "array",
          "items": {
            "type": "string",
            "maxLength": 80
          }
        },
        "allowed_cidrs": {
          "type": "array",
          "items": {
            "type": "string",
            "maxLength": 64
          }
        }
      },
      "required": [
        "id",
        "name",
        "prefix",
        "mode",
        "enabled",
        "created_at",
        "expires_at",
        "revoked_at",
        "last_used_at",
        "last_used_ip",
        "scopes",
        "allowed_cidrs"
      ],
      "additionalProperties": false
    },
    "secret": {
      "type": "string",
      "pattern": "^sk_[A-Za-z0-9_-]{43}$"
    }
  },
  "required": [
    "ok",
    "item",
    "secret"
  ],
  "additionalProperties": false
}

API reference and code examples

DELETE/v1/api-credentials/{id}Revoke an API credentialSensitive

Operation ID: apiCredentialRevoke

Disables an owned ordinary credential; does not delete history. Managed MCP grants use connection revocation instead.

Required scopes: api_credentials.write

Parameters

  • id · path · required — Owned credential UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": false
}

API reference and code examples

GET/v1/api-credentials/{id}Read your credential metadataSensitive

Operation ID: apiCredential

Never returns signing secrets.

Required scopes: api_credentials.read

Parameters

  • id · path · required — Owned credential UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "item": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string",
          "format": "uuid"
        },
        "name": {
          "type": "string",
          "maxLength": 80
        },
        "prefix": {
          "type": "string",
          "maxLength": 32
        },
        "mode": {
          "type": "string",
          "enum": [
            "signed",
            "bearer"
          ]
        },
        "enabled": {
          "type": "boolean"
        },
        "created_at": {
          "type": "string",
          "format": "date-time"
        },
        "expires_at": {
          "type": "string",
          "format": "date-time"
        },
        "revoked_at": {
          "anyOf": [
            {
              "type": "string",
              "format": "date-time"
            },
            {
              "type": "null"
            }
          ]
        },
        "last_used_at": {
          "anyOf": [
            {
              "type": "string",
              "format": "date-time"
            },
            {
              "type": "null"
            }
          ]
        },
        "last_used_ip": {
          "anyOf": [
            {
              "type": "string",
              "maxLength": 64
            },
            {
              "type": "null"
            }
          ]
        },
        "scopes": {
          "type": "array",
          "items": {
            "type": "string",
            "maxLength": 80
          }
        },
        "allowed_cidrs": {
          "type": "array",
          "items": {
            "type": "string",
            "maxLength": 64
          }
        }
      },
      "required": [
        "id",
        "name",
        "prefix",
        "mode",
        "enabled",
        "created_at",
        "expires_at",
        "revoked_at",
        "last_used_at",
        "last_used_ip",
        "scopes",
        "allowed_cidrs"
      ],
      "additionalProperties": false
    }
  },
  "required": [
    "ok",
    "item"
  ],
  "additionalProperties": false
}

API reference and code examples

PATCH/v1/api-credentials/{id}Update a restricted API credentialSensitive

Operation ID: apiCredentialUpdate

Change name, scopes, expiry, enabled state or allowed CIDRs without exceeding the current issuer. Revoked or managed credentials cannot be reactivated.

Required scopes: api_credentials.write

Parameters

  • id · path · required — Owned credential UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 80
    },
    "scopes": {
      "type": "array",
      "items": {
        "type": "string",
        "enum": [
          "audit.read",
          "api_credentials.read",
          "api_credentials.write",
          "oauth.connections.read",
          "oauth.connections.write",
          "billing.balance.read",
          "billing.invoices.read",
          "billing.orders.read",
          "billing.products.read",
          "billing.services.read",
          "billing.services.write",
          "billing.transactions.read",
          "billing.unpaid_total.read",
          "billing.order.create",
          "billing.invoice.pay",
          "vps.read",
          "vps.credentials.read",
          "vps.write",
          "dedicated.read",
          "dedicated.credentials.read",
          "dedicated.write",
          "dns.read",
          "dns.write",
          "domains.read",
          "domains.write",
          "ssh.read",
          "ssh.write",
          "firewall.read",
          "firewall.write",
          "storage.read",
          "storage.write",
          "tcp_proxy.read",
          "tcp_proxy.write",
          "webhooks.read",
          "webhooks.write"
        ]
      },
      "minItems": 1,
      "maxItems": 35
    },
    "allowed_cidrs": {
      "type": "array",
      "items": {
        "type": "string",
        "minLength": 1,
        "maxLength": 64
      },
      "maxItems": 50
    },
    "enabled": {
      "type": "boolean"
    },
    "expires_at": {
      "type": "string",
      "format": "date-time"
    }
  },
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "item": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string",
          "format": "uuid"
        },
        "name": {
          "type": "string",
          "maxLength": 80
        },
        "prefix": {
          "type": "string",
          "maxLength": 32
        },
        "mode": {
          "type": "string",
          "enum": [
            "signed",
            "bearer"
          ]
        },
        "enabled": {
          "type": "boolean"
        },
        "created_at": {
          "type": "string",
          "format": "date-time"
        },
        "expires_at": {
          "type": "string",
          "format": "date-time"
        },
        "revoked_at": {
          "anyOf": [
            {
              "type": "string",
              "format": "date-time"
            },
            {
              "type": "null"
            }
          ]
        },
        "last_used_at": {
          "anyOf": [
            {
              "type": "string",
              "format": "date-time"
            },
            {
              "type": "null"
            }
          ]
        },
        "last_used_ip": {
          "anyOf": [
            {
              "type": "string",
              "maxLength": 64
            },
            {
              "type": "null"
            }
          ]
        },
        "scopes": {
          "type": "array",
          "items": {
            "type": "string",
            "maxLength": 80
          }
        },
        "allowed_cidrs": {
          "type": "array",
          "items": {
            "type": "string",
            "maxLength": 64
          }
        }
      },
      "required": [
        "id",
        "name",
        "prefix",
        "mode",
        "enabled",
        "created_at",
        "expires_at",
        "revoked_at",
        "last_used_at",
        "last_used_ip",
        "scopes",
        "allowed_cidrs"
      ],
      "additionalProperties": false
    }
  },
  "required": [
    "ok",
    "item"
  ],
  "additionalProperties": false
}

API reference and code examples

POST/v1/api-credentials/{id}/rotateRotate an API credentialSensitive

Operation ID: apiCredentialRotate

Requires Idempotency-Key. Replaces prefix and secret immediately; old authentication stops working. Use a different management key, or the dashboard, to rotate the key used by an integration. Self-rotation is rejected to avoid losing access after an interrupted response. Superseded receipts never reveal obsolete secrets.

Required scopes: api_credentials.write

Parameters

  • id · path · required — Owned ordinary credential UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · optional

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "item": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string",
          "format": "uuid"
        },
        "name": {
          "type": "string",
          "maxLength": 80
        },
        "prefix": {
          "type": "string",
          "maxLength": 32
        },
        "mode": {
          "type": "string",
          "enum": [
            "signed",
            "bearer"
          ]
        },
        "enabled": {
          "type": "boolean"
        },
        "created_at": {
          "type": "string",
          "format": "date-time"
        },
        "expires_at": {
          "type": "string",
          "format": "date-time"
        },
        "revoked_at": {
          "anyOf": [
            {
              "type": "string",
              "format": "date-time"
            },
            {
              "type": "null"
            }
          ]
        },
        "last_used_at": {
          "anyOf": [
            {
              "type": "string",
              "format": "date-time"
            },
            {
              "type": "null"
            }
          ]
        },
        "last_used_ip": {
          "anyOf": [
            {
              "type": "string",
              "maxLength": 64
            },
            {
              "type": "null"
            }
          ]
        },
        "scopes": {
          "type": "array",
          "items": {
            "type": "string",
            "maxLength": 80
          }
        },
        "allowed_cidrs": {
          "type": "array",
          "items": {
            "type": "string",
            "maxLength": 64
          }
        }
      },
      "required": [
        "id",
        "name",
        "prefix",
        "mode",
        "enabled",
        "created_at",
        "expires_at",
        "revoked_at",
        "last_used_at",
        "last_used_ip",
        "scopes",
        "allowed_cidrs"
      ],
      "additionalProperties": false
    },
    "secret": {
      "type": "string",
      "pattern": "^sk_[A-Za-z0-9_-]{43}$"
    }
  },
  "required": [
    "ok",
    "item",
    "secret"
  ],
  "additionalProperties": false
}

API reference and code examples

GET/v1/audit/actionsList durable customer API action events

Operation ID: auditActions

Requested intent is saved before entering a write handler; accepted is not completion. Terminal operation results are recorded separately. Covers customer API and hosted MCP writes. Broader Billing dashboard/admin/committed state observations are available through audit/business. Updates are blocked; privileged retention deletes after the configured period.

Required scopes: audit.read

Parameters

  • limit · query — Maximum items, default 50.
  • cursor · query — Next event cursor.
  • resource_id · query — Resource ID or zone name.
  • phase · query — Action phase.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "next_cursor": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "request_id": {
            "type": "string",
            "format": "uuid"
          },
          "actor": {
            "type": "object",
            "properties": {
              "type": {
                "type": "string",
                "enum": [
                  "api_key",
                  "hosted_mcp",
                  "oauth_app",
                  "user",
                  "system",
                  "local_mcp",
                  "support",
                  "unknown"
                ]
              },
              "id": {
                "anyOf": [
                  {
                    "type": "string",
                    "format": "uuid"
                  },
                  {
                    "type": "null"
                  }
                ]
              }
            },
            "required": [
              "type",
              "id"
            ],
            "additionalProperties": false
          },
          "action": {
            "type": "string",
            "maxLength": 300
          },
          "resource_id": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "phase": {
            "type": "string",
            "enum": [
              "requested",
              "accepted",
              "rejected",
              "unknown",
              "succeeded",
              "failed",
              "cancelled"
            ]
          },
          "operation_id": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "created_at": {
            "type": "string",
            "format": "date-time"
          }
        },
        "required": [
          "id",
          "request_id",
          "actor",
          "action",
          "resource_id",
          "phase",
          "operation_id",
          "created_at"
        ],
        "additionalProperties": false
      },
      "maxItems": 100
    }
  },
  "required": [
    "ok",
    "next_cursor",
    "items"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "items": [
    {
      "id": "1",
      "request_id": "00000000-0000-4000-8000-000000000002",
      "actor": {
        "type": "api_key",
        "id": "00000000-0000-4000-8000-000000000001"
      },
      "action": "POST /v1/vps/:serviceId/reboot",
      "resource_id": "00000000-0000-4000-8000-000000000001",
      "phase": "accepted",
      "operation_id": null,
      "created_at": "2026-10-01T00:00:00.000Z"
    }
  ],
  "next_cursor": null
}

API reference and code examples

GET/v1/audit/businessList account-owned business audit events

Operation ID: auditBusiness

Durable Billing dashboard/admin request acceptance and committed service/invoice/order/lifecycle observations. A committed lifecycle log row is not proof of task completion. Database transitions without a verified human identity use system; identities are never inferred from metadata. Admin identity is withheld from customer responses. No payloads, credentials, provider errors or financial customer details are logged. This does not cover every action of other services or constitute a WORM export.

Required scopes: audit.read

Parameters

  • limit · query — Maximum items, default 50 (1–100).
  • cursor · query — Exclusive cursor returned as next_cursor.
  • actor_type · query — Verified actor category.
  • resource_type · query — service, invoice, order or account.
  • resource_id · query — Owned resource UUID.
  • request_id · query — Correlation UUID.
  • action · query — Exact action.
  • phase · query — requested, accepted, rejected, unknown or committed.
  • from · query — Inclusive ISO timestamp.
  • to · query — Inclusive ISO timestamp.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "next_cursor": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "request_id": {
            "anyOf": [
              {
                "type": "string",
                "format": "uuid"
              },
              {
                "type": "null"
              }
            ]
          },
          "actor": {
            "type": "object",
            "properties": {
              "type": {
                "type": "string",
                "enum": [
                  "user",
                  "admin",
                  "api",
                  "api_key",
                  "hosted_mcp",
                  "system",
                  "unknown"
                ]
              },
              "id": {
                "anyOf": [
                  {
                    "type": "string",
                    "format": "uuid"
                  },
                  {
                    "type": "null"
                  }
                ]
              }
            },
            "required": [
              "type",
              "id"
            ],
            "additionalProperties": false
          },
          "source": {
            "type": "string",
            "enum": [
              "dashboard",
              "admin",
              "api",
              "database",
              "lifecycle"
            ]
          },
          "action": {
            "type": "string",
            "maxLength": 300
          },
          "canonical_action": {
            "type": "string",
            "maxLength": 300
          },
          "resource_type": {
            "type": "string",
            "enum": [
              "service",
              "invoice",
              "order",
              "account"
            ]
          },
          "resource_id": {
            "anyOf": [
              {
                "type": "string",
                "format": "uuid"
              },
              {
                "type": "null"
              }
            ]
          },
          "phase": {
            "type": "string",
            "enum": [
              "requested",
              "accepted",
              "rejected",
              "unknown",
              "committed"
            ]
          },
          "changes": {
            "type": "object",
            "properties": {
              "before": {
                "type": "object",
                "additionalProperties": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "number"
                    },
                    {
                      "type": "boolean"
                    },
                    {
                      "type": "null"
                    }
                  ]
                }
              },
              "after": {
                "type": "object",
                "additionalProperties": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "number"
                    },
                    {
                      "type": "boolean"
                    },
                    {
                      "type": "null"
                    }
                  ]
                }
              }
            },
            "additionalProperties": false
          },
          "created_at": {
            "type": "string",
            "format": "date-time"
          }
        },
        "required": [
          "id",
          "request_id",
          "actor",
          "source",
          "action",
          "resource_type",
          "resource_id",
          "phase",
          "changes",
          "created_at"
        ],
        "additionalProperties": false
      },
      "maxItems": 100
    }
  },
  "required": [
    "ok",
    "next_cursor",
    "items"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "items": [
    {
      "id": "1",
      "request_id": null,
      "actor": {
        "type": "system",
        "id": null
      },
      "source": "database",
      "action": "service.changed",
      "resource_type": "service",
      "resource_id": "00000000-0000-4000-8000-000000000001",
      "phase": "committed",
      "changes": {
        "before": {
          "status": "active"
        },
        "after": {
          "status": "suspended"
        }
      },
      "created_at": "2026-10-01T00:00:00.000Z"
    }
  ],
  "next_cursor": null
}

API reference and code examples

GET/v1/audit/eventsRead account audit history

Operation ID: auditEvents

Default view=requests preserves request history. view=activity merges durable API/MCP actions and Billing business events with actor/action/resource/status filters. Activity partial=true means a history source was unavailable; available_sources lists confirmed sources. Reuse opaque cursors with the same filters; ownership is always enforced. Acceptance is not provider completion. No passwords, tokens, private keys or webhook secrets. Activity source_ip follows the existing privacy masking policy.

Required scopes: audit.read

Parameters

  • limit · query — Maximum items, default 50 (1–100).
  • view · query — History view.
  • cursor · query — Reuse next_cursor exactly with the same owner and filters.
  • method · query — HTTP method; request view only.
  • actor_type · query — Verified actor category.
  • actor_id · query — Exact verified actor UUID.
  • action · query — Semantic action, for example vps.reinstall.
  • resource_type · query — Resource category.
  • resource_id · query — Exact resource identity.
  • status · query — Action phase.
  • request_id · query — Exact request UUID.
  • from · query — Inclusive ISO 8601 timestamp.
  • to · query — Inclusive ISO 8601 timestamp.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "anyOf": [
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "next_cursor": {
          "anyOf": [
            {
              "type": "string",
              "pattern": "^\\d+$"
            },
            {
              "type": "null"
            }
          ]
        },
        "items": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "id": {
                "type": "string",
                "pattern": "^\\d+$"
              },
              "occurred_at": {
                "type": "string",
                "format": "date-time"
              },
              "actor": {
                "type": "object",
                "properties": {
                  "type": {
                    "type": "string",
                    "const": "api_key",
                    "enum": [
                      "api_key"
                    ]
                  },
                  "api_key_prefix": {
                    "type": "string",
                    "maxLength": 32
                  }
                },
                "required": [
                  "type",
                  "api_key_prefix"
                ],
                "additionalProperties": false
              },
              "type": {
                "type": "string",
                "const": "api_request",
                "enum": [
                  "api_request"
                ]
              },
              "method": {
                "type": "string",
                "maxLength": 10
              },
              "path": {
                "type": "string",
                "maxLength": 300
              },
              "http_status": {
                "type": "integer",
                "minimum": 100,
                "maximum": 599
              },
              "request_id": {
                "anyOf": [
                  {
                    "type": "string",
                    "maxLength": 80
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "outcome": {
                "type": "string",
                "enum": [
                  "accepted",
                  "rejected",
                  "unknown"
                ]
              }
            },
            "required": [
              "id",
              "occurred_at",
              "actor",
              "type",
              "method",
              "path",
              "http_status",
              "request_id",
              "outcome"
            ],
            "additionalProperties": false
          },
          "maxItems": 100
        }
      },
      "required": [
        "ok",
        "next_cursor",
        "items"
      ],
      "additionalProperties": false
    },
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "partial": {
          "type": "boolean"
        },
        "next_cursor": {
          "anyOf": [
            {
              "type": "string",
              "maxLength": 800
            },
            {
              "type": "null"
            }
          ]
        },
        "available_sources": {
          "type": "array",
          "items": {
            "type": "string",
            "enum": [
              "api",
              "billing"
            ]
          }
        },
        "items": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "id": {
                "type": "string",
                "maxLength": 80
              },
              "actor": {
                "type": "object",
                "properties": {
                  "type": {
                    "type": "string",
                    "enum": [
                      "user",
                      "api_key",
                      "oauth_app",
                      "hosted_mcp",
                      "local_mcp",
                      "support",
                      "system",
                      "unknown"
                    ]
                  },
                  "id": {
                    "anyOf": [
                      {
                        "type": "string",
                        "format": "uuid"
                      },
                      {
                        "type": "null"
                      }
                    ]
                  }
                },
                "required": [
                  "type",
                  "id"
                ],
                "additionalProperties": false
              },
              "action": {
                "type": "string",
                "maxLength": 300
              },
              "resource_type": {
                "type": "string",
                "maxLength": 40
              },
              "resource_id": {
                "anyOf": [
                  {
                    "type": "string",
                    "maxLength": 253
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "request_id": {
                "anyOf": [
                  {
                    "type": "string",
                    "format": "uuid"
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "idempotency_key": {
                "anyOf": [
                  {
                    "type": "string",
                    "maxLength": 128
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "source_ip": {
                "anyOf": [
                  {
                    "type": "string",
                    "maxLength": 64
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "status": {
                "type": "string",
                "enum": [
                  "requested",
                  "accepted",
                  "rejected",
                  "unknown",
                  "succeeded",
                  "failed",
                  "cancelled",
                  "committed"
                ]
              },
              "created_at": {
                "type": "string",
                "format": "date-time"
              }
            },
            "required": [
              "id",
              "actor",
              "action",
              "resource_type",
              "resource_id",
              "request_id",
              "idempotency_key",
              "source_ip",
              "status",
              "created_at"
            ],
            "additionalProperties": false
          },
          "maxItems": 100
        }
      },
      "required": [
        "ok",
        "partial",
        "next_cursor",
        "available_sources",
        "items"
      ],
      "additionalProperties": false
    }
  ]
}

Illustrative successful response

{
  "ok": true,
  "next_cursor": null,
  "items": []
}

API reference and code examples

GET/v1/capabilitiesDiscover capabilities and effective permissions

Operation ID: apiCapabilities

Distinguishes implemented support, environment enabled state and effective key permissions. enabled=null and availability=unconfirmed mean the backend could not confirm a gate, not that it is disabled. partial=true indicates incomplete discovery. Does not guarantee region inventory, provider health or order approval. Networking and generic metrics are reported not_implemented until supported.

Required scopes: See authentication contract

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "contract_revision": {
      "type": "string",
      "const": "2026-10-07.1",
      "enum": [
        "2026-10-07.1"
      ]
    },
    "dependency_revision": {
      "anyOf": [
        {
          "type": "string",
          "pattern": "^[A-Za-z0-9._-]{1,80}$"
        },
        {
          "type": "null"
        }
      ]
    },
    "partial": {
      "type": "boolean"
    },
    "features": {
      "type": "object",
      "additionalProperties": {
        "type": "object",
        "properties": {
          "implemented": {
            "type": "boolean"
          },
          "enabled": {
            "anyOf": [
              {
                "type": "boolean"
              },
              {
                "type": "null"
              }
            ]
          },
          "permitted": {
            "type": "boolean"
          },
          "availability": {
            "type": "string",
            "enum": [
              "enabled",
              "disabled",
              "unconfirmed",
              "not_implemented"
            ]
          }
        },
        "required": [
          "implemented",
          "enabled",
          "permitted",
          "availability"
        ],
        "additionalProperties": false
      }
    },
    "operation_policy": {
      "type": "object",
      "properties": {
        "kinds": {
          "type": "array",
          "items": {
            "type": "string",
            "enum": [
              "deployment",
              "vps",
              "dedicated"
            ]
          }
        },
        "terminal_retention_days": {
          "type": "integer",
          "exclusiveMinimum": 0
        },
        "pending_retention": {
          "type": "string",
          "const": "until_reconciled",
          "enum": [
            "until_reconciled"
          ]
        },
        "lookup_identity_retention": {
          "type": "string",
          "const": "indefinite",
          "enum": [
            "indefinite"
          ]
        },
        "key_scope": {
          "type": "string",
          "const": "account_credential_method_path",
          "enum": [
            "account_credential_method_path"
          ]
        },
        "response_header": {
          "type": "string",
          "const": "x-bf-response-format",
          "enum": [
            "x-bf-response-format"
          ]
        },
        "response_value": {
          "type": "string",
          "const": "operation",
          "enum": [
            "operation"
          ]
        }
      },
      "required": [
        "kinds",
        "terminal_retention_days",
        "pending_retention",
        "lookup_identity_retention",
        "key_scope",
        "response_header",
        "response_value"
      ],
      "additionalProperties": false
    }
  },
  "required": [
    "ok",
    "contract_revision",
    "dependency_revision",
    "partial",
    "features"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "contract_revision": "2026-10-07.1",
  "dependency_revision": null,
  "partial": true,
  "features": {
    "webhooks": {
      "implemented": true,
      "enabled": null,
      "permitted": true,
      "availability": "unconfirmed"
    },
    "private_networks": {
      "implemented": false,
      "enabled": false,
      "permitted": false,
      "availability": "not_implemented"
    }
  }
}

API reference and code examples

GET/v1/oauth/connectionsList connected applications

Operation ID: oauthConnections

Owner-only hosted MCP OAuth connection inventory. Does not expose access tokens, refresh tokens or internal client credentials. Connection-management transport must be configured.

Required scopes: oauth.connections.read

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "format": "uuid"
          },
          "application": {
            "type": "string",
            "maxLength": 200
          },
          "scopes": {
            "type": "array",
            "items": {
              "type": "string",
              "maxLength": 100
            },
            "maxItems": 100
          },
          "created_at": {
            "type": "string",
            "format": "date-time"
          },
          "expires_at": {
            "type": "string",
            "format": "date-time"
          },
          "policy": {
            "type": "string",
            "enum": [
              "read_only",
              "approval",
              "full",
              "legacy"
            ]
          },
          "revoked": {
            "type": "boolean"
          },
          "enabled": {
            "type": "boolean"
          },
          "last_used_at": {
            "anyOf": [
              {
                "type": "string",
                "format": "date-time"
              },
              {
                "type": "null"
              }
            ]
          },
          "access_policy": {
            "type": "string",
            "enum": [
              "read_only",
              "approval",
              "full_access",
              "legacy"
            ]
          }
        },
        "required": [
          "id",
          "application",
          "scopes",
          "created_at",
          "expires_at",
          "policy",
          "revoked",
          "enabled",
          "last_used_at",
          "access_policy"
        ],
        "additionalProperties": false
      },
      "maxItems": 100
    }
  },
  "required": [
    "ok",
    "items"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "items": [
    {
      "id": "00000000-0000-4000-8000-000000000001",
      "application": "Example application",
      "scopes": [
        "billing.services.read"
      ],
      "created_at": "2026-10-01T00:00:00.000Z",
      "expires_at": "2026-11-01T00:00:00.000Z",
      "policy": "read_only",
      "access_policy": "read_only",
      "enabled": true,
      "last_used_at": null,
      "revoked": false
    }
  ]
}

API reference and code examples

DELETE/v1/oauth/connections/{id}Revoke a connected application

Operation ID: oauthConnectionRevoke

Revokes only this account’s grant using the existing fenced revocation flow. Repeating revocation is safe. Does not grant or expand permissions.

Required scopes: oauth.connections.write

Parameters

  • id · path · required — Connection UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true
}

API reference and code examples

GET/v1/operationsRecover an operation by idempotency key

Operation ID: recoverOperation

Lookup is confined to the authenticated account and permitted operation kinds. Keys are scoped to the original credential, HTTP method and exact path. Supply method/path together and optionally credential_id to disambiguate a key reused across endpoints or credentials (409 operation_lookup_ambiguous). Only new tracked deployment/VPS/dedicated writes with a retained identity are recoverable. 404 operation_not_found does not prove the write never executed. Identities remain after terminal receipt retention (90 days by default); 410 operation_expired means the original receipt is no longer available. Pending/unknown receipts are retained for reconciliation. Never generate a new key to repeat an uncertain write.

Required scopes: billing.services.read OR vps.read OR dedicated.read

Parameters

  • idempotency_key · query · required — Original Idempotency-Key; 8–128 letters, digits, dot, underscore, colon or dash.
  • method · query — Original HTTP method; supply with path.
  • path · query — Exact original /v1/ path without query string; supply with method.
  • credential_id · query — Original credential UUID, when needed for disambiguation.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "operation": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "kind": {
          "type": "string",
          "enum": [
            "deployment",
            "vps",
            "dedicated"
          ]
        },
        "action": {
          "type": "string"
        },
        "status": {
          "type": "string",
          "enum": [
            "pending",
            "running",
            "succeeded",
            "failed",
            "cancelled",
            "unknown"
          ]
        },
        "done": {
          "type": "boolean"
        },
        "progress": {
          "anyOf": [
            {
              "type": "number",
              "minimum": 0,
              "maximum": 100
            },
            {
              "type": "null"
            }
          ]
        },
        "stage": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "created_at": {
          "type": "string",
          "format": "date-time"
        },
        "updated_at": {
          "anyOf": [
            {
              "type": "string",
              "format": "date-time"
            },
            {
              "type": "null"
            }
          ]
        },
        "service_ids": {
          "type": "array",
          "items": {
            "type": "string",
            "format": "uuid"
          }
        },
        "error": {
          "anyOf": [
            {
              "type": "object",
              "properties": {
                "code": {
                  "type": "string"
                },
                "message": {
                  "type": "string"
                }
              },
              "required": [
                "code",
                "message"
              ],
              "additionalProperties": false
            },
            {
              "type": "null"
            }
          ]
        },
        "result": {
          "anyOf": [
            {
              "anyOf": [
                {
                  "type": "object",
                  "properties": {
                    "service_ids": {
                      "type": "array",
                      "items": {
                        "type": "string",
                        "format": "uuid"
                      },
                      "minItems": 1,
                      "maxItems": 50
                    },
                    "order_id": {
                      "anyOf": [
                        {
                          "type": "string",
                          "format": "uuid"
                        },
                        {
                          "type": "null"
                        }
                      ]
                    },
                    "invoice_id": {
                      "type": "string",
                      "format": "uuid"
                    }
                  },
                  "required": [
                    "service_ids"
                  ],
                  "additionalProperties": false
                },
                {
                  "type": "object",
                  "properties": {
                    "service_id": {
                      "type": "string",
                      "format": "uuid"
                    },
                    "os": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 160,
                      "pattern": "^[A-Za-z0-9._:-]+$"
                    },
                    "snapshot_name": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 160,
                      "pattern": "^[A-Za-z0-9._:-]+$"
                    },
                    "power_state": {
                      "type": "string",
                      "enum": [
                        "running",
                        "stopped"
                      ]
                    }
                  },
                  "required": [
                    "service_id"
                  ],
                  "additionalProperties": false
                }
              ]
            },
            {
              "type": "null"
            }
          ]
        }
      },
      "required": [
        "id",
        "kind",
        "action",
        "status",
        "done",
        "progress",
        "stage",
        "created_at",
        "updated_at",
        "service_ids",
        "error"
      ],
      "additionalProperties": false
    },
    "links": {
      "type": "object",
      "properties": {
        "operation": {
          "type": "string",
          "pattern": "^\\/v1\\/operations\\/op_[A-Za-z0-9_-]+$"
        },
        "service": {
          "type": "string",
          "pattern": "^\\/v1\\/services\\/[0-9a-f-]{36}$"
        },
        "invoice": {
          "type": "string",
          "pattern": "^\\/v1\\/billing\\/invoices\\/[0-9a-f-]{36}$"
        },
        "order": {
          "type": "string",
          "pattern": "^\\/v1\\/billing\\/orders\\/[0-9a-f-]{36}$"
        }
      },
      "required": [
        "operation"
      ],
      "additionalProperties": false
    }
  },
  "required": [
    "ok",
    "operation"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "operation": {
    "id": "op_EXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLE",
    "kind": "vps",
    "action": "reboot",
    "status": "succeeded",
    "done": true,
    "progress": 100,
    "stage": null,
    "created_at": "2026-10-01T00:00:00.000Z",
    "updated_at": "2026-10-01T00:00:00.000Z",
    "service_ids": [
      "00000000-0000-4000-8000-000000000001"
    ],
    "error": null,
    "result": {
      "service_id": "00000000-0000-4000-8000-000000000001"
    }
  },
  "links": {
    "operation": "/v1/operations/op_EXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLE",
    "service": "/v1/services/00000000-0000-4000-8000-000000000001"
  }
}

API reference and code examples

GET/v1/operations/{operationId}Read operation status

Operation ID: getOperation

Poll the opaque operation_id returned by supported wallet deployments and VPS/dedicated actions. Owner checks and the underlying read scope are enforced on every read. When durable_operations is enabled, new handles are stored independently of encryption keys and the first observed terminal outcome is immutable. Terminal receipts retain 90 days by default; pending/unknown receipts remain for reconciliation. Legacy encrypted handles remain readable but can be invalidated by encryption-key rotation. Deployment readiness respects historical activation; a service error alone is not proof of permanent provisioning failure. The canonical operation has status, done, progress, stage and optional typed result. Result is populated only on succeeded; failed/cancelled are terminal, unknown is nonterminal and is not success. Tracked writes accept x-bf-response-format: operation; the default response preserves legacy fields. DNSSEC and other untracked workflows retain their documented polling contracts. Client wait timeout never repeats/cancels a purchase.

Required scopes: billing.services.read OR vps.read OR dedicated.read

Parameters

  • operationId · path · required — Opaque op_ token from the accepted response.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "operation": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "kind": {
          "type": "string",
          "enum": [
            "deployment",
            "vps",
            "dedicated"
          ]
        },
        "action": {
          "type": "string"
        },
        "status": {
          "type": "string",
          "enum": [
            "pending",
            "running",
            "succeeded",
            "failed",
            "cancelled",
            "unknown"
          ]
        },
        "done": {
          "type": "boolean"
        },
        "progress": {
          "anyOf": [
            {
              "type": "number",
              "minimum": 0,
              "maximum": 100
            },
            {
              "type": "null"
            }
          ]
        },
        "stage": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "created_at": {
          "type": "string",
          "format": "date-time"
        },
        "updated_at": {
          "anyOf": [
            {
              "type": "string",
              "format": "date-time"
            },
            {
              "type": "null"
            }
          ]
        },
        "service_ids": {
          "type": "array",
          "items": {
            "type": "string",
            "format": "uuid"
          }
        },
        "error": {
          "anyOf": [
            {
              "type": "object",
              "properties": {
                "code": {
                  "type": "string"
                },
                "message": {
                  "type": "string"
                }
              },
              "required": [
                "code",
                "message"
              ],
              "additionalProperties": false
            },
            {
              "type": "null"
            }
          ]
        },
        "result": {
          "anyOf": [
            {
              "anyOf": [
                {
                  "type": "object",
                  "properties": {
                    "service_ids": {
                      "type": "array",
                      "items": {
                        "type": "string",
                        "format": "uuid"
                      },
                      "minItems": 1,
                      "maxItems": 50
                    },
                    "order_id": {
                      "anyOf": [
                        {
                          "type": "string",
                          "format": "uuid"
                        },
                        {
                          "type": "null"
                        }
                      ]
                    },
                    "invoice_id": {
                      "type": "string",
                      "format": "uuid"
                    }
                  },
                  "required": [
                    "service_ids"
                  ],
                  "additionalProperties": false
                },
                {
                  "type": "object",
                  "properties": {
                    "service_id": {
                      "type": "string",
                      "format": "uuid"
                    },
                    "os": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 160,
                      "pattern": "^[A-Za-z0-9._:-]+$"
                    },
                    "snapshot_name": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 160,
                      "pattern": "^[A-Za-z0-9._:-]+$"
                    },
                    "power_state": {
                      "type": "string",
                      "enum": [
                        "running",
                        "stopped"
                      ]
                    }
                  },
                  "required": [
                    "service_id"
                  ],
                  "additionalProperties": false
                }
              ]
            },
            {
              "type": "null"
            }
          ]
        }
      },
      "required": [
        "id",
        "kind",
        "action",
        "status",
        "done",
        "progress",
        "stage",
        "created_at",
        "updated_at",
        "service_ids",
        "error"
      ],
      "additionalProperties": false
    },
    "links": {
      "type": "object",
      "properties": {
        "operation": {
          "type": "string",
          "pattern": "^\\/v1\\/operations\\/op_[A-Za-z0-9_-]+$"
        },
        "service": {
          "type": "string",
          "pattern": "^\\/v1\\/services\\/[0-9a-f-]{36}$"
        },
        "invoice": {
          "type": "string",
          "pattern": "^\\/v1\\/billing\\/invoices\\/[0-9a-f-]{36}$"
        },
        "order": {
          "type": "string",
          "pattern": "^\\/v1\\/billing\\/orders\\/[0-9a-f-]{36}$"
        }
      },
      "required": [
        "operation"
      ],
      "additionalProperties": false
    }
  },
  "required": [
    "ok",
    "operation"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "operation": {
    "id": "op_EXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLE",
    "kind": "vps",
    "action": "reboot",
    "status": "succeeded",
    "done": true,
    "progress": 100,
    "stage": null,
    "created_at": "2026-10-01T00:00:00.000Z",
    "updated_at": "2026-10-01T00:00:00.000Z",
    "service_ids": [
      "00000000-0000-4000-8000-000000000001"
    ],
    "error": null
  }
}

API reference and code examples

PATCH/v1/services/{serviceId}/metadataReplace customer integration metadata

Operation ID: serviceMetadataUpdate

Replaces only this owned service’s external_id and labels; omitted fields are cleared. Does not change hardware, price, credentials or lifecycle. Up to 20 bounded labels. Do not store secrets in labels. Searches use external_id or label=key=value.

Required scopes: billing.services.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "external_id": {
      "type": "string",
      "minLength": 1,
      "maxLength": 120
    },
    "labels": {
      "type": "object",
      "additionalProperties": {
        "type": "string",
        "maxLength": 120
      }
    }
  },
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "service_id": {
      "type": "string",
      "format": "uuid"
    },
    "external_id": {
      "anyOf": [
        {
          "type": "string",
          "maxLength": 120
        },
        {
          "type": "null"
        }
      ]
    },
    "labels": {
      "type": "object",
      "additionalProperties": {
        "type": "string",
        "maxLength": 120
      }
    }
  },
  "required": [
    "ok",
    "service_id",
    "external_id",
    "labels"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "service_id": "00000000-0000-4000-8000-000000000001",
  "external_id": "example-vps-1",
  "labels": {
    "environment": "test"
  }
}

API reference and code examples

GET/v1/versionRead API contract revision

Operation ID: apiVersion

Authenticated discovery. release is a configured public release label or null, not an internal image or provider identifier. A contract revision is not proof of product availability.

Required scopes: See authentication contract

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "api_version": {
      "type": "string",
      "const": "1",
      "enum": [
        "1"
      ]
    },
    "contract_revision": {
      "type": "string",
      "const": "2026-10-07.1",
      "enum": [
        "2026-10-07.1"
      ]
    },
    "release": {
      "anyOf": [
        {
          "type": "string",
          "pattern": "^[A-Za-z0-9][A-Za-z0-9._-]{0,79}$"
        },
        {
          "type": "null"
        }
      ]
    },
    "deployment": {
      "anyOf": [
        {
          "type": "string",
          "pattern": "^[A-Za-z0-9][A-Za-z0-9._-]{0,79}$"
        },
        {
          "type": "null"
        }
      ]
    },
    "released_at": {
      "anyOf": [
        {
          "type": "string",
          "format": "date-time"
        },
        {
          "type": "null"
        }
      ]
    }
  },
  "required": [
    "ok",
    "api_version",
    "contract_revision",
    "release",
    "deployment",
    "released_at"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "api_version": "1",
  "contract_revision": "2026-10-07.1",
  "release": null,
  "deployment": null,
  "released_at": null
}

API reference and code examples

GET/v1/webhooksList webhook endpoints

Operation ID: listWebhooks

Owned endpoints without signing secrets. Maximum five per account; feature must be enabled for this environment.

Required scopes: webhooks.read

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "format": "uuid"
          },
          "url": {
            "type": "string",
            "format": "uri",
            "maxLength": 2048
          },
          "events": {
            "type": "array",
            "items": {
              "type": "string",
              "enum": [
                "invoice.paid",
                "service.ready",
                "service.suspended",
                "service.terminated",
                "operation.failed",
                "operation.succeeded",
                "operation.cancelled",
                "invoice.created",
                "invoice.overdue",
                "service.provisioning",
                "service.expiring",
                "operation.started",
                "backup.started",
                "backup.completed",
                "backup.failed",
                "snapshot.created",
                "snapshot.failed",
                "dns.changed",
                "service.power_changed",
                "domain.verification_required",
                "domain.renewal_pending",
                "domain.renewed",
                "domain.transfer_updated"
              ]
            },
            "maxItems": 23
          },
          "enabled": {
            "type": "boolean"
          },
          "createdAt": {
            "type": "string",
            "format": "date-time"
          }
        },
        "required": [
          "id",
          "url",
          "events",
          "enabled",
          "createdAt"
        ],
        "additionalProperties": false
      },
      "maxItems": 5
    }
  },
  "required": [
    "ok",
    "items"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "items": []
}

API reference and code examples

POST/v1/webhooksRegister a signed webhook

Operation ID: webhookCreate

HTTPS port 443, public IPv4 destinations only. Verified TLS, pinned DNS, no redirects. Events: invoice.paid, service.ready, service.suspended, service.terminated and operation.failed (Billing provisioning-job failures, not all power/reinstall failures). No historical backfill. Sensitive signing_secret is returned on creation or identical retry while the endpoint exists: never log it or send it to AI. At-least-once delivery: verify raw-body HMAC and timestamp, deduplicate event IDs, return 2xx promptly. Off by default until migration and worker deployment.

Required scopes: webhooks.write

Parameters

  • Idempotency-Key · header · required — Stable action key: 8–128 letters, digits, dot, underscore, colon or hyphen. Reuse the same key and payload on retries; inspect task state after a timeout.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "format": "uri",
      "maxLength": 2048
    },
    "events": {
      "type": "array",
      "items": {
        "type": "string",
        "enum": [
          "invoice.paid",
          "service.ready",
          "service.suspended",
          "service.terminated",
          "operation.failed",
          "operation.succeeded",
          "operation.cancelled",
          "invoice.created",
          "invoice.overdue",
          "service.provisioning",
          "service.expiring",
          "operation.started",
          "backup.started",
          "backup.completed",
          "backup.failed",
          "snapshot.created",
          "snapshot.failed",
          "dns.changed",
          "service.power_changed",
          "domain.verification_required",
          "domain.renewal_pending",
          "domain.renewed",
          "domain.transfer_updated"
        ]
      },
      "minItems": 1,
      "maxItems": 23
    }
  },
  "required": [
    "url",
    "events"
  ],
  "additionalProperties": false
}

Successful response · HTTP 201

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "item": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string",
          "format": "uuid"
        },
        "url": {
          "type": "string",
          "format": "uri",
          "maxLength": 2048
        },
        "events": {
          "type": "array",
          "items": {
            "type": "string",
            "enum": [
              "invoice.paid",
              "service.ready",
              "service.suspended",
              "service.terminated",
              "operation.failed",
              "operation.succeeded",
              "operation.cancelled",
              "invoice.created",
              "invoice.overdue",
              "service.provisioning",
              "service.expiring",
              "operation.started",
              "backup.started",
              "backup.completed",
              "backup.failed",
              "snapshot.created",
              "snapshot.failed",
              "dns.changed",
              "service.power_changed",
              "domain.verification_required",
              "domain.renewal_pending",
              "domain.renewed",
              "domain.transfer_updated"
            ]
          },
          "maxItems": 23
        },
        "enabled": {
          "type": "boolean"
        },
        "createdAt": {
          "type": "string",
          "format": "date-time"
        }
      },
      "required": [
        "id",
        "url",
        "events",
        "enabled",
        "createdAt"
      ],
      "additionalProperties": false
    },
    "signing_secret": {
      "type": "string",
      "pattern": "^whsec_[A-Za-z0-9_-]{43}$"
    }
  },
  "required": [
    "ok",
    "item",
    "signing_secret"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "item": {
    "id": "00000000-0000-4000-8000-000000000001",
    "url": "https://example.com/hooks",
    "events": [
      "invoice.paid"
    ],
    "enabled": true,
    "createdAt": "2026-10-01T00:00:00.000Z"
  },
  "signing_secret": "whsec_XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX"
}

API reference and code examples

DELETE/v1/webhooks/{id}Delete a webhook endpoint

Operation ID: webhookDelete

Deletes the endpoint and its delivery history. An in-flight attempt may finish. Use a new retry key for an intentional replacement.

Required scopes: webhooks.write

Parameters

  • id · path · required — Owned endpoint UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true
}

API reference and code examples

PATCH/v1/webhooks/{id}Enable or pause webhook deliveries

Operation ID: webhookUpdate

Pauses new and queued deliveries; an in-flight attempt may finish. Re-enable resumes pending deliveries.

Required scopes: webhooks.write

Parameters

  • id · path · required — Owned endpoint UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "enabled": {
      "type": "boolean"
    }
  },
  "required": [
    "enabled"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "item": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string",
          "format": "uuid"
        },
        "url": {
          "type": "string",
          "format": "uri",
          "maxLength": 2048
        },
        "events": {
          "type": "array",
          "items": {
            "type": "string",
            "enum": [
              "invoice.paid",
              "service.ready",
              "service.suspended",
              "service.terminated",
              "operation.failed",
              "operation.succeeded",
              "operation.cancelled",
              "invoice.created",
              "invoice.overdue",
              "service.provisioning",
              "service.expiring",
              "operation.started",
              "backup.started",
              "backup.completed",
              "backup.failed",
              "snapshot.created",
              "snapshot.failed",
              "dns.changed",
              "service.power_changed",
              "domain.verification_required",
              "domain.renewal_pending",
              "domain.renewed",
              "domain.transfer_updated"
            ]
          },
          "maxItems": 23
        },
        "enabled": {
          "type": "boolean"
        },
        "createdAt": {
          "type": "string",
          "format": "date-time"
        }
      },
      "required": [
        "id",
        "url",
        "events",
        "enabled",
        "createdAt"
      ],
      "additionalProperties": false
    }
  },
  "required": [
    "ok",
    "item"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "item": {
    "id": "00000000-0000-4000-8000-000000000001",
    "url": "https://example.com/hooks",
    "events": [
      "invoice.paid"
    ],
    "enabled": false,
    "createdAt": "2026-10-01T00:00:00.000Z"
  }
}

API reference and code examples

GET/v1/webhooks/{id}/deliveriesRead webhook delivery history

Operation ID: webhookDeliveries

Owned delivery results, no response bodies or signing secrets. Delivered records retain 30 days, failed records 90 days. Paused pending events remain until deletion. Up to 12 attempts with exponential backoff capped at six hours.

Required scopes: webhooks.read

Parameters

  • id · path · required — Owned endpoint UUID.
  • limit · query — Maximum items, default 50 (1–100).
  • offset · query — Start offset, default 0. Use next_offset from the response; null means finished. This contract has no page or pageSize fields.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "next_offset": {
      "anyOf": [
        {
          "type": "integer",
          "minimum": 0
        },
        {
          "type": "null"
        }
      ]
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "format": "uuid"
          },
          "eventId": {
            "type": "string",
            "format": "uuid"
          },
          "status": {
            "type": "string",
            "enum": [
              "pending",
              "delivered",
              "failed"
            ]
          },
          "attempts": {
            "type": "integer",
            "minimum": 0
          },
          "lastHttpStatus": {
            "anyOf": [
              {
                "type": "integer"
              },
              {
                "type": "null"
              }
            ]
          },
          "createdAt": {
            "type": "string",
            "format": "date-time"
          },
          "deliveredAt": {
            "anyOf": [
              {
                "type": "string",
                "format": "date-time"
              },
              {
                "type": "null"
              }
            ]
          },
          "payload": {
            "type": "object",
            "properties": {
              "id": {
                "type": "string",
                "format": "uuid"
              },
              "type": {
                "anyOf": [
                  {
                    "type": "string",
                    "enum": [
                      "invoice.paid",
                      "service.ready",
                      "service.suspended",
                      "service.terminated",
                      "operation.failed",
                      "operation.succeeded",
                      "operation.cancelled",
                      "invoice.created",
                      "invoice.overdue",
                      "service.provisioning",
                      "service.expiring",
                      "operation.started",
                      "backup.started",
                      "backup.completed",
                      "backup.failed",
                      "snapshot.created",
                      "snapshot.failed",
                      "dns.changed",
                      "service.power_changed",
                      "domain.verification_required",
                      "domain.renewal_pending",
                      "domain.renewed",
                      "domain.transfer_updated"
                    ]
                  },
                  {
                    "type": "string",
                    "const": "webhook.test",
                    "enum": [
                      "webhook.test"
                    ]
                  }
                ]
              },
              "created_at": {
                "type": "string",
                "format": "date-time"
              },
              "schema_version": {
                "type": "number",
                "const": 1,
                "enum": [
                  1
                ]
              },
              "api_version": {
                "type": "string",
                "const": "1",
                "enum": [
                  "1"
                ]
              },
              "data": {
                "type": "object",
                "properties": {
                  "job_id": {
                    "type": "string",
                    "format": "uuid"
                  },
                  "service_id": {
                    "type": "string",
                    "format": "uuid"
                  },
                  "invoice_id": {
                    "type": "string",
                    "format": "uuid"
                  },
                  "endpoint_id": {
                    "type": "string",
                    "format": "uuid"
                  },
                  "zone_id": {
                    "anyOf": [
                      {
                        "type": "string",
                        "format": "uuid"
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "zone_name": {
                    "type": "string",
                    "maxLength": 253
                  },
                  "change_id": {
                    "type": "string",
                    "format": "uuid"
                  },
                  "action": {
                    "type": "string",
                    "maxLength": 64
                  },
                  "due_at": {
                    "type": "string",
                    "format": "date-time"
                  },
                  "status": {
                    "type": "string",
                    "maxLength": 40
                  },
                  "currency": {
                    "type": "string",
                    "maxLength": 3,
                    "minLength": 3
                  },
                  "total": {
                    "type": "string",
                    "maxLength": 50
                  },
                  "operation_type": {
                    "type": "string",
                    "pattern": "^[a-z_-]{1,40}$"
                  },
                  "code": {
                    "type": "string",
                    "const": "operation_failed",
                    "enum": [
                      "operation_failed"
                    ]
                  },
                  "operation_id": {
                    "type": "string",
                    "maxLength": 80
                  },
                  "service_ids": {
                    "type": "array",
                    "items": {
                      "type": "string",
                      "format": "uuid"
                    },
                    "maxItems": 50
                  }
                },
                "additionalProperties": false
              }
            },
            "required": [
              "id",
              "type",
              "created_at",
              "data"
            ],
            "additionalProperties": false
          }
        },
        "required": [
          "id",
          "eventId",
          "status",
          "attempts",
          "lastHttpStatus",
          "createdAt",
          "deliveredAt",
          "payload"
        ],
        "additionalProperties": false
      },
      "maxItems": 100
    }
  },
  "required": [
    "ok",
    "next_offset",
    "items"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "items": [],
  "next_offset": null
}

API reference and code examples

POST/v1/webhooks/{id}/deliveries/{deliveryId}/retryRetry an exhausted delivery

Operation ID: webhookRetry

Only failed deliveries on your enabled endpoint can be retried. Pending/leased/successful events cannot be replayed; repeating this request returns delivery_not_retryable. Event ID is preserved.

Required scopes: webhooks.write

Parameters

  • id · path · required — Owned endpoint UUID.
  • deliveryId · path · required — Failed delivery UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · optional

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "delivery_id": {
      "type": "string",
      "format": "uuid"
    },
    "status": {
      "type": "string",
      "const": "pending",
      "enum": [
        "pending"
      ]
    }
  },
  "required": [
    "ok",
    "delivery_id",
    "status"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "delivery_id": "00000000-0000-4000-8000-000000000002",
  "status": "pending"
}

API reference and code examples

POST/v1/webhooks/{id}/rotate-secretRotate webhook signing secret

Operation ID: webhookRotateSecret

Replaces the signing secret for an owned endpoint immediately. An already in-flight delivery may still use the old secret; accept both briefly at your receiver. Idempotency-Key is required. Identical retries return the same secret for 24 hours unless a subsequent rotation superseded it; superseded or expired keys never rotate again. Sensitive signing_secret: never log or send it to AI. Empty request body. Requires webhook_management capability.

Required scopes: webhooks.write

Parameters

  • id · path · required — Owned endpoint UUID.
  • Idempotency-Key · header · required — Stable action key: 8–128 letters, digits, dot, underscore, colon or hyphen. Reuse the same key and payload on retries; inspect task state after a timeout.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · optional

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "endpoint_id": {
      "type": "string",
      "format": "uuid"
    },
    "signing_secret": {
      "type": "string",
      "pattern": "^whsec_[A-Za-z0-9_-]{43}$"
    },
    "rotated_at": {
      "type": "string",
      "format": "date-time"
    }
  },
  "required": [
    "ok",
    "endpoint_id",
    "signing_secret",
    "rotated_at"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "endpoint_id": "00000000-0000-4000-8000-000000000001",
  "signing_secret": "whsec_XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX",
  "rotated_at": "2026-10-01T00:00:00.000Z"
}

API reference and code examples

POST/v1/webhooks/{id}/testQueue a signed webhook test

Operation ID: webhookTest

Queues a synthetic webhook.test event through the normal delivery worker. HTTP 202 means queued, not delivered. Read delivery history to check the result. Enabled owned endpoints only; one new test per endpoint per minute. Idempotency-Key is required; identical retries return the same delivery. Empty request body. Requires webhook_management capability.

Required scopes: webhooks.write

Parameters

  • id · path · required — Owned endpoint UUID.
  • Idempotency-Key · header · required — Stable action key: 8–128 letters, digits, dot, underscore, colon or hyphen. Reuse the same key and payload on retries; inspect task state after a timeout.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · optional

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

Successful response · HTTP 202

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "endpoint_id": {
      "type": "string",
      "format": "uuid"
    },
    "delivery_id": {
      "type": "string",
      "format": "uuid"
    },
    "event_id": {
      "type": "string",
      "format": "uuid"
    },
    "status": {
      "type": "string",
      "const": "pending",
      "enum": [
        "pending"
      ]
    }
  },
  "required": [
    "ok",
    "endpoint_id",
    "delivery_id",
    "event_id",
    "status"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "endpoint_id": "00000000-0000-4000-8000-000000000001",
  "delivery_id": "00000000-0000-4000-8000-000000000002",
  "event_id": "00000000-0000-4000-8000-000000000002",
  "status": "pending"
}

API reference and code examples

Catalog

GET/v1/dedicated/imagesList dedicated images

Operation ID: dedicatedImages

Returns compatible OS profile IDs for public dedicated configurations with available stock. Filter by region and configuration_code from the product catalog. An image ID can occur in several configurations; preserve its region/configuration context. Supply the numeric id as osProfileId when creating a dedicated deployment.

Required scopes: dedicated.read

Parameters

  • limit · query — Maximum items, default 50 (1–100).
  • offset · query — Start offset, default 0. Use next_offset from the response; null means finished. This contract has no page or pageSize fields.
  • region · query — Region code from GET /v1/regions, for example nl or pt. Case-insensitive.
  • configuration_code · query — Dedicated configuration code from GET /v1/products.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "integer",
            "exclusiveMinimum": 0
          },
          "name": {
            "type": "string",
            "maxLength": 200
          },
          "region": {
            "type": "string",
            "pattern": "^[a-z0-9][a-z0-9-]{1,15}$"
          },
          "configuration_code": {
            "type": "string",
            "maxLength": 200
          },
          "ssh_keys_supported": {
            "type": "boolean"
          }
        },
        "required": [
          "id",
          "name",
          "region",
          "configuration_code",
          "ssh_keys_supported"
        ],
        "additionalProperties": false
      }
    },
    "next_offset": {
      "anyOf": [
        {
          "type": "number"
        },
        {
          "type": "null"
        }
      ]
    },
    "compatibility_verified": {
      "type": "boolean"
    }
  },
  "required": [
    "ok",
    "items",
    "next_offset"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "items": [
    {
      "id": 1,
      "name": "Debian 13",
      "region": "pt",
      "configuration_code": "EXAMPLE-PT",
      "ssh_keys_supported": true
    }
  ],
  "next_offset": null
}

API reference and code examples

GET/v1/productsList products

Operation ID: products

Flat public, active product variants with public, active parent products. type is the high-level normalized service family; product_code is the more specific purchasable product family. tcp-proxy maps to type=other, waf to type=dns, and license to type=other. Do not substitute product_code values into a type filter. id is the readable SKU; product_id and variant_id are order identifiers. Region and type eligibility are applied before pagination. CPU is vCPUs for VPS or sockets for dedicated; ram is MiB and disk is GiB. billing_cycles contains server-configured or converted period prices in the requested currency, exact decimal strings, unit/count and setup_fee. price prefers the monthly option. Account currency governs quotes and orders. configuration_url discovers required fields, defaults, compatible OS choices, connectivity and IP add-ons. Add-ons and tax are excluded from catalog prices: quote the complete cart before ordering. Domain pricing requires a live domain quote. available is not a reservation; capacity_verified=false for VPS. Dedicated available_stock is known compatible stock. A backend outage returns partial=true, unavailable_types and availability=unknown where possible; unknown stock is null, not zero. Image/stock snapshots are cached internally up to 15 seconds; checkout revalidates.

Required scopes: billing.products.read

Parameters

  • limit · query — Maximum items, default 50 (1–100).
  • offset · query — Start offset, default 0. Use next_offset from the response; null means finished. This contract has no page or pageSize fields.
  • product_code · query — More specific purchasable product family; distinct from type. tcp-proxy maps to other, waf to dns, license to other.
  • region · query — Region code from GET /v1/regions, for example nl or pt. Case-insensitive.
  • type · query — High-level normalized type filter; tcp-proxy/license use other and waf uses dns. Distinct from product_code; applied before pagination.
  • currency · query — Configured pricing currency, default EUR.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "maxLength": 200
          },
          "product_id": {
            "type": "string",
            "format": "uuid"
          },
          "variant_id": {
            "type": "string",
            "format": "uuid"
          },
          "name": {
            "anyOf": [
              {
                "type": "string",
                "maxLength": 200
              },
              {
                "type": "null"
              }
            ]
          },
          "type": {
            "type": "string",
            "enum": [
              "vps",
              "dedicated",
              "webhosting",
              "storage",
              "dns",
              "domain",
              "other"
            ]
          },
          "purchase": {
            "type": "object",
            "properties": {
              "draft_order": {
                "type": "object",
                "properties": {
                  "implemented": {
                    "type": "boolean"
                  },
                  "enabled": {
                    "type": "boolean"
                  },
                  "eligible": {
                    "type": "boolean"
                  },
                  "requires_approval": {
                    "type": "boolean"
                  },
                  "payment_required": {
                    "type": "boolean"
                  },
                  "payment_methods": {
                    "type": "array",
                    "items": {
                      "type": "string",
                      "const": "balance",
                      "enum": [
                        "balance"
                      ]
                    }
                  },
                  "partial_payment": {
                    "type": "boolean"
                  },
                  "idempotency_required": {
                    "type": "boolean"
                  },
                  "permitted": {
                    "type": "boolean"
                  }
                },
                "required": [
                  "implemented",
                  "enabled",
                  "eligible",
                  "requires_approval",
                  "payment_required",
                  "payment_methods",
                  "partial_payment",
                  "idempotency_required"
                ],
                "additionalProperties": false
              },
              "atomic_deploy": {
                "type": "object",
                "properties": {
                  "implemented": {
                    "type": "boolean"
                  },
                  "enabled": {
                    "type": "boolean"
                  },
                  "eligible": {
                    "type": "boolean"
                  },
                  "requires_approval": {
                    "type": "boolean"
                  },
                  "payment_required": {
                    "type": "boolean"
                  },
                  "payment_methods": {
                    "type": "array",
                    "items": {
                      "type": "string",
                      "const": "balance",
                      "enum": [
                        "balance"
                      ]
                    }
                  },
                  "partial_payment": {
                    "type": "boolean"
                  },
                  "idempotency_required": {
                    "type": "boolean"
                  },
                  "permitted": {
                    "type": "boolean"
                  }
                },
                "required": [
                  "implemented",
                  "enabled",
                  "eligible",
                  "requires_approval",
                  "payment_required",
                  "payment_methods",
                  "partial_payment",
                  "idempotency_required"
                ],
                "additionalProperties": false
              }
            },
            "required": [
              "draft_order",
              "atomic_deploy"
            ],
            "additionalProperties": false
          },
          "requirements_url": {
            "type": "string",
            "pattern": "^\\/v1\\/"
          },
          "product_code": {
            "anyOf": [
              {
                "type": "string",
                "enum": [
                  "vps",
                  "dedicated",
                  "tcp-proxy",
                  "waf",
                  "license",
                  "webhosting",
                  "storage",
                  "dns",
                  "domain",
                  "other"
                ]
              },
              {
                "type": "null"
              }
            ]
          },
          "variant_code": {
            "type": "string",
            "maxLength": 200
          },
          "region": {
            "anyOf": [
              {
                "type": "string",
                "pattern": "^[a-z0-9][a-z0-9-]{1,15}$"
              },
              {
                "type": "null"
              }
            ]
          },
          "regions": {
            "type": "array",
            "items": {
              "type": "string",
              "pattern": "^[a-z0-9][a-z0-9-]{1,15}$"
            },
            "maxItems": 100
          },
          "cpu": {
            "anyOf": [
              {
                "type": "number",
                "exclusiveMinimum": 0
              },
              {
                "type": "null"
              }
            ]
          },
          "cpu_unit": {
            "anyOf": [
              {
                "type": "string",
                "enum": [
                  "vcpus",
                  "sockets"
                ]
              },
              {
                "type": "null"
              }
            ]
          },
          "ram": {
            "anyOf": [
              {
                "type": "number",
                "exclusiveMinimum": 0
              },
              {
                "type": "null"
              }
            ]
          },
          "ram_unit": {
            "type": "string",
            "const": "MiB",
            "enum": [
              "MiB"
            ]
          },
          "disk": {
            "anyOf": [
              {
                "type": "number",
                "exclusiveMinimum": 0
              },
              {
                "type": "null"
              }
            ]
          },
          "disk_unit": {
            "type": "string",
            "const": "GiB",
            "enum": [
              "GiB"
            ]
          },
          "price": {
            "anyOf": [
              {
                "type": "string",
                "pattern": "^(?:0|[1-9]\\d{0,13})(?:\\.\\d{1,4})?$"
              },
              {
                "type": "null"
              }
            ]
          },
          "billing_cycle": {
            "anyOf": [
              {
                "type": "string",
                "maxLength": 200
              },
              {
                "type": "null"
              }
            ]
          },
          "billing_cycles": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "billing_cycle": {
                  "type": "string",
                  "maxLength": 200
                },
                "unit": {
                  "type": "string",
                  "maxLength": 200
                },
                "count": {
                  "type": "integer",
                  "exclusiveMinimum": 0
                },
                "period_months": {
                  "anyOf": [
                    {
                      "type": "number",
                      "exclusiveMinimum": 0
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "price": {
                  "type": "string",
                  "pattern": "^(?:0|[1-9]\\d{0,13})(?:\\.\\d{1,4})?$"
                },
                "setup_fee": {
                  "anyOf": [
                    {
                      "type": "string",
                      "pattern": "^(?:0|[1-9]\\d{0,13})(?:\\.\\d{1,4})?$"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "currency": {
                  "type": "string",
                  "enum": [
                    "EUR",
                    "USD",
                    "GBP",
                    "UAH",
                    "PLN",
                    "BRL",
                    "INR",
                    "IDR",
                    "CNY"
                  ]
                }
              },
              "required": [
                "billing_cycle",
                "unit",
                "count",
                "period_months",
                "price",
                "setup_fee",
                "currency"
              ],
              "additionalProperties": false
            },
            "maxItems": 100
          },
          "currency": {
            "type": "string",
            "enum": [
              "EUR",
              "USD",
              "GBP",
              "UAH",
              "PLN",
              "BRL",
              "INR",
              "IDR",
              "CNY"
            ]
          },
          "available": {
            "type": "boolean"
          },
          "capacity_verified": {
            "type": "boolean"
          },
          "configuration_code": {
            "anyOf": [
              {
                "type": "string",
                "maxLength": 200
              },
              {
                "type": "null"
              }
            ]
          },
          "available_stock": {
            "anyOf": [
              {
                "type": "integer",
                "minimum": 0
              },
              {
                "type": "null"
              }
            ]
          },
          "pricing_mode": {
            "type": "string",
            "enum": [
              "domain_quote",
              "configured"
            ]
          },
          "availability": {
            "type": "string",
            "enum": [
              "available",
              "unavailable",
              "unknown"
            ]
          },
          "configuration_url": {
            "type": "string",
            "pattern": "^\\/v1\\/billing\\/products\\/[0-9a-f-]+\\/variants\\/[0-9a-f-]+\\/order-options$"
          }
        },
        "required": [
          "id",
          "product_id",
          "variant_id",
          "name",
          "type",
          "region",
          "regions",
          "cpu",
          "cpu_unit",
          "ram",
          "ram_unit",
          "disk",
          "disk_unit",
          "price",
          "billing_cycle",
          "billing_cycles",
          "currency",
          "available",
          "capacity_verified",
          "configuration_code",
          "available_stock"
        ],
        "additionalProperties": false
      },
      "maxItems": 100
    },
    "next_offset": {
      "anyOf": [
        {
          "type": "integer",
          "minimum": 0
        },
        {
          "type": "null"
        }
      ]
    },
    "partial": {
      "type": "boolean"
    },
    "unavailable_types": {
      "type": "array",
      "items": {
        "type": "string",
        "enum": [
          "vps",
          "dedicated"
        ]
      }
    }
  },
  "required": [
    "ok",
    "items",
    "next_offset"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "items": [
    {
      "id": "8G",
      "product_id": "00000000-0000-4000-8000-000000000001",
      "variant_id": "00000000-0000-4000-8000-000000000002",
      "name": "Example VPS",
      "type": "vps",
      "product_code": "vps",
      "variant_code": "8G",
      "region": "nl",
      "regions": [
        "nl"
      ],
      "cpu": 4,
      "cpu_unit": "vcpus",
      "ram": 8192,
      "ram_unit": "MiB",
      "disk": 100,
      "disk_unit": "GiB",
      "price": "12.00",
      "billing_cycle": "monthly",
      "billing_cycles": [
        {
          "billing_cycle": "monthly",
          "unit": "MONTH",
          "count": 1,
          "period_months": 1,
          "price": "12.00",
          "setup_fee": "0",
          "currency": "EUR"
        },
        {
          "billing_cycle": "quarterly",
          "unit": "QUARTAL",
          "count": 1,
          "period_months": 3,
          "price": "30.00",
          "setup_fee": "0",
          "currency": "EUR"
        }
      ],
      "currency": "EUR",
      "available": true,
      "capacity_verified": false,
      "configuration_code": null,
      "available_stock": null
    }
  ],
  "next_offset": null
}

API reference and code examples

GET/v1/products/{region}List products in a region

Operation ID: getProductsByRegion

Flat public, active product variants with public, active parent products. type is the high-level normalized service family; product_code is the more specific purchasable product family. tcp-proxy maps to type=other, waf to type=dns, and license to type=other. Do not substitute product_code values into a type filter. id is the readable SKU; product_id and variant_id are order identifiers. Region and type eligibility are applied before pagination. CPU is vCPUs for VPS or sockets for dedicated; ram is MiB and disk is GiB. billing_cycles contains server-configured or converted period prices in the requested currency, exact decimal strings, unit/count and setup_fee. price prefers the monthly option. Account currency governs quotes and orders. configuration_url discovers required fields, defaults, compatible OS choices, connectivity and IP add-ons. Add-ons and tax are excluded from catalog prices: quote the complete cart before ordering. Domain pricing requires a live domain quote. available is not a reservation; capacity_verified=false for VPS. Dedicated available_stock is known compatible stock. A backend outage returns partial=true, unavailable_types and availability=unknown where possible; unknown stock is null, not zero. Image/stock snapshots are cached internally up to 15 seconds; checkout revalidates. Applies region restrictions on the server before pagination. A conflicting region query parameter is rejected.

Required scopes: billing.products.read

Parameters

  • region · path · required — Region code, for example nl or pt; all includes every eligible region.
  • limit · query — Maximum items, default 50 (1–100).
  • offset · query — Start offset, default 0. Use next_offset from the response; null means finished. This contract has no page or pageSize fields.
  • product_code · query — More specific purchasable product family; distinct from type. tcp-proxy maps to other, waf to dns, license to other.
  • type · query — High-level normalized type filter; tcp-proxy/license use other and waf uses dns. Distinct from product_code.
  • currency · query — Configured pricing currency, default EUR.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "maxLength": 200
          },
          "product_id": {
            "type": "string",
            "format": "uuid"
          },
          "variant_id": {
            "type": "string",
            "format": "uuid"
          },
          "name": {
            "anyOf": [
              {
                "type": "string",
                "maxLength": 200
              },
              {
                "type": "null"
              }
            ]
          },
          "type": {
            "type": "string",
            "enum": [
              "vps",
              "dedicated",
              "webhosting",
              "storage",
              "dns",
              "domain",
              "other"
            ]
          },
          "purchase": {
            "type": "object",
            "properties": {
              "draft_order": {
                "type": "object",
                "properties": {
                  "implemented": {
                    "type": "boolean"
                  },
                  "enabled": {
                    "type": "boolean"
                  },
                  "eligible": {
                    "type": "boolean"
                  },
                  "requires_approval": {
                    "type": "boolean"
                  },
                  "payment_required": {
                    "type": "boolean"
                  },
                  "payment_methods": {
                    "type": "array",
                    "items": {
                      "type": "string",
                      "const": "balance",
                      "enum": [
                        "balance"
                      ]
                    }
                  },
                  "partial_payment": {
                    "type": "boolean"
                  },
                  "idempotency_required": {
                    "type": "boolean"
                  },
                  "permitted": {
                    "type": "boolean"
                  }
                },
                "required": [
                  "implemented",
                  "enabled",
                  "eligible",
                  "requires_approval",
                  "payment_required",
                  "payment_methods",
                  "partial_payment",
                  "idempotency_required"
                ],
                "additionalProperties": false
              },
              "atomic_deploy": {
                "type": "object",
                "properties": {
                  "implemented": {
                    "type": "boolean"
                  },
                  "enabled": {
                    "type": "boolean"
                  },
                  "eligible": {
                    "type": "boolean"
                  },
                  "requires_approval": {
                    "type": "boolean"
                  },
                  "payment_required": {
                    "type": "boolean"
                  },
                  "payment_methods": {
                    "type": "array",
                    "items": {
                      "type": "string",
                      "const": "balance",
                      "enum": [
                        "balance"
                      ]
                    }
                  },
                  "partial_payment": {
                    "type": "boolean"
                  },
                  "idempotency_required": {
                    "type": "boolean"
                  },
                  "permitted": {
                    "type": "boolean"
                  }
                },
                "required": [
                  "implemented",
                  "enabled",
                  "eligible",
                  "requires_approval",
                  "payment_required",
                  "payment_methods",
                  "partial_payment",
                  "idempotency_required"
                ],
                "additionalProperties": false
              }
            },
            "required": [
              "draft_order",
              "atomic_deploy"
            ],
            "additionalProperties": false
          },
          "requirements_url": {
            "type": "string",
            "pattern": "^\\/v1\\/"
          },
          "product_code": {
            "anyOf": [
              {
                "type": "string",
                "enum": [
                  "vps",
                  "dedicated",
                  "tcp-proxy",
                  "waf",
                  "license",
                  "webhosting",
                  "storage",
                  "dns",
                  "domain",
                  "other"
                ]
              },
              {
                "type": "null"
              }
            ]
          },
          "variant_code": {
            "type": "string",
            "maxLength": 200
          },
          "region": {
            "anyOf": [
              {
                "type": "string",
                "pattern": "^[a-z0-9][a-z0-9-]{1,15}$"
              },
              {
                "type": "null"
              }
            ]
          },
          "regions": {
            "type": "array",
            "items": {
              "type": "string",
              "pattern": "^[a-z0-9][a-z0-9-]{1,15}$"
            },
            "maxItems": 100
          },
          "cpu": {
            "anyOf": [
              {
                "type": "number",
                "exclusiveMinimum": 0
              },
              {
                "type": "null"
              }
            ]
          },
          "cpu_unit": {
            "anyOf": [
              {
                "type": "string",
                "enum": [
                  "vcpus",
                  "sockets"
                ]
              },
              {
                "type": "null"
              }
            ]
          },
          "ram": {
            "anyOf": [
              {
                "type": "number",
                "exclusiveMinimum": 0
              },
              {
                "type": "null"
              }
            ]
          },
          "ram_unit": {
            "type": "string",
            "const": "MiB",
            "enum": [
              "MiB"
            ]
          },
          "disk": {
            "anyOf": [
              {
                "type": "number",
                "exclusiveMinimum": 0
              },
              {
                "type": "null"
              }
            ]
          },
          "disk_unit": {
            "type": "string",
            "const": "GiB",
            "enum": [
              "GiB"
            ]
          },
          "price": {
            "anyOf": [
              {
                "type": "string",
                "pattern": "^(?:0|[1-9]\\d{0,13})(?:\\.\\d{1,4})?$"
              },
              {
                "type": "null"
              }
            ]
          },
          "billing_cycle": {
            "anyOf": [
              {
                "type": "string",
                "maxLength": 200
              },
              {
                "type": "null"
              }
            ]
          },
          "billing_cycles": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "billing_cycle": {
                  "type": "string",
                  "maxLength": 200
                },
                "unit": {
                  "type": "string",
                  "maxLength": 200
                },
                "count": {
                  "type": "integer",
                  "exclusiveMinimum": 0
                },
                "period_months": {
                  "anyOf": [
                    {
                      "type": "number",
                      "exclusiveMinimum": 0
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "price": {
                  "type": "string",
                  "pattern": "^(?:0|[1-9]\\d{0,13})(?:\\.\\d{1,4})?$"
                },
                "setup_fee": {
                  "anyOf": [
                    {
                      "type": "string",
                      "pattern": "^(?:0|[1-9]\\d{0,13})(?:\\.\\d{1,4})?$"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "currency": {
                  "type": "string",
                  "enum": [
                    "EUR",
                    "USD",
                    "GBP",
                    "UAH",
                    "PLN",
                    "BRL",
                    "INR",
                    "IDR",
                    "CNY"
                  ]
                }
              },
              "required": [
                "billing_cycle",
                "unit",
                "count",
                "period_months",
                "price",
                "setup_fee",
                "currency"
              ],
              "additionalProperties": false
            },
            "maxItems": 100
          },
          "currency": {
            "type": "string",
            "enum": [
              "EUR",
              "USD",
              "GBP",
              "UAH",
              "PLN",
              "BRL",
              "INR",
              "IDR",
              "CNY"
            ]
          },
          "available": {
            "type": "boolean"
          },
          "capacity_verified": {
            "type": "boolean"
          },
          "configuration_code": {
            "anyOf": [
              {
                "type": "string",
                "maxLength": 200
              },
              {
                "type": "null"
              }
            ]
          },
          "available_stock": {
            "anyOf": [
              {
                "type": "integer",
                "minimum": 0
              },
              {
                "type": "null"
              }
            ]
          },
          "pricing_mode": {
            "type": "string",
            "enum": [
              "domain_quote",
              "configured"
            ]
          },
          "availability": {
            "type": "string",
            "enum": [
              "available",
              "unavailable",
              "unknown"
            ]
          },
          "configuration_url": {
            "type": "string",
            "pattern": "^\\/v1\\/billing\\/products\\/[0-9a-f-]+\\/variants\\/[0-9a-f-]+\\/order-options$"
          }
        },
        "required": [
          "id",
          "product_id",
          "variant_id",
          "name",
          "type",
          "region",
          "regions",
          "cpu",
          "cpu_unit",
          "ram",
          "ram_unit",
          "disk",
          "disk_unit",
          "price",
          "billing_cycle",
          "billing_cycles",
          "currency",
          "available",
          "capacity_verified",
          "configuration_code",
          "available_stock"
        ],
        "additionalProperties": false
      },
      "maxItems": 100
    },
    "next_offset": {
      "anyOf": [
        {
          "type": "integer",
          "minimum": 0
        },
        {
          "type": "null"
        }
      ]
    },
    "partial": {
      "type": "boolean"
    },
    "unavailable_types": {
      "type": "array",
      "items": {
        "type": "string",
        "enum": [
          "vps",
          "dedicated"
        ]
      }
    }
  },
  "required": [
    "ok",
    "items",
    "next_offset"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "items": [
    {
      "id": "8G",
      "product_id": "00000000-0000-4000-8000-000000000001",
      "variant_id": "00000000-0000-4000-8000-000000000002",
      "name": "Example VPS",
      "type": "vps",
      "product_code": "vps",
      "variant_code": "8G",
      "region": "nl",
      "regions": [
        "nl"
      ],
      "cpu": 4,
      "cpu_unit": "vcpus",
      "ram": 8192,
      "ram_unit": "MiB",
      "disk": 100,
      "disk_unit": "GiB",
      "price": "12.00",
      "billing_cycle": "monthly",
      "billing_cycles": [
        {
          "billing_cycle": "monthly",
          "unit": "MONTH",
          "count": 1,
          "period_months": 1,
          "price": "12.00",
          "setup_fee": "0",
          "currency": "EUR"
        },
        {
          "billing_cycle": "quarterly",
          "unit": "QUARTAL",
          "count": 1,
          "period_months": 3,
          "price": "30.00",
          "setup_fee": "0",
          "currency": "EUR"
        }
      ],
      "currency": "EUR",
      "available": true,
      "capacity_verified": false,
      "configuration_code": null,
      "available_stock": null
    }
  ],
  "next_offset": null
}

API reference and code examples

GET/v1/products/{region}/{productCode}/{variantCode}Read a product by public code

Operation ID: getProduct

Exact eligible region/family/SKU lookup. Returns safe hardware, public billing prices, availability, order UUIDs and links to prices/options/quote/deployment. Duplicate public SKUs in the family/region return catalog_variant_ambiguous (409); no plan is silently selected. Missing or hidden plans return 404. Provider outages may return unknown availability; they are never represented as known zero stock. This read is not a reservation.

Required scopes: billing.products.read

Parameters

  • region · path · required — Eligible region, for example nl or pt. A single region is required.
  • productCode · path · required — Product family.
  • variantCode · path · required — Exact case-sensitive public SKU, for example 2G or PTV4-1. Never an internal inventory ID.
  • currency · query — Pricing currency; defaults to EUR. Quotes and orders use account currency.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "item": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string",
          "maxLength": 200
        },
        "product_id": {
          "type": "string",
          "format": "uuid"
        },
        "variant_id": {
          "type": "string",
          "format": "uuid"
        },
        "name": {
          "anyOf": [
            {
              "type": "string",
              "maxLength": 200
            },
            {
              "type": "null"
            }
          ]
        },
        "type": {
          "type": "string",
          "enum": [
            "vps",
            "dedicated",
            "webhosting",
            "storage",
            "dns",
            "domain",
            "other"
          ]
        },
        "purchase": {
          "type": "object",
          "properties": {
            "draft_order": {
              "type": "object",
              "properties": {
                "implemented": {
                  "type": "boolean"
                },
                "enabled": {
                  "type": "boolean"
                },
                "eligible": {
                  "type": "boolean"
                },
                "requires_approval": {
                  "type": "boolean"
                },
                "payment_required": {
                  "type": "boolean"
                },
                "payment_methods": {
                  "type": "array",
                  "items": {
                    "type": "string",
                    "const": "balance",
                    "enum": [
                      "balance"
                    ]
                  }
                },
                "partial_payment": {
                  "type": "boolean"
                },
                "idempotency_required": {
                  "type": "boolean"
                },
                "permitted": {
                  "type": "boolean"
                }
              },
              "required": [
                "implemented",
                "enabled",
                "eligible",
                "requires_approval",
                "payment_required",
                "payment_methods",
                "partial_payment",
                "idempotency_required"
              ],
              "additionalProperties": false
            },
            "atomic_deploy": {
              "type": "object",
              "properties": {
                "implemented": {
                  "type": "boolean"
                },
                "enabled": {
                  "type": "boolean"
                },
                "eligible": {
                  "type": "boolean"
                },
                "requires_approval": {
                  "type": "boolean"
                },
                "payment_required": {
                  "type": "boolean"
                },
                "payment_methods": {
                  "type": "array",
                  "items": {
                    "type": "string",
                    "const": "balance",
                    "enum": [
                      "balance"
                    ]
                  }
                },
                "partial_payment": {
                  "type": "boolean"
                },
                "idempotency_required": {
                  "type": "boolean"
                },
                "permitted": {
                  "type": "boolean"
                }
              },
              "required": [
                "implemented",
                "enabled",
                "eligible",
                "requires_approval",
                "payment_required",
                "payment_methods",
                "partial_payment",
                "idempotency_required"
              ],
              "additionalProperties": false
            }
          },
          "required": [
            "draft_order",
            "atomic_deploy"
          ],
          "additionalProperties": false
        },
        "requirements_url": {
          "type": "string",
          "pattern": "^\\/v1\\/"
        },
        "product_code": {
          "type": "string",
          "enum": [
            "vps",
            "dedicated",
            "tcp-proxy",
            "waf",
            "license",
            "webhosting",
            "storage",
            "dns",
            "domain",
            "other"
          ]
        },
        "variant_code": {
          "type": "string",
          "pattern": "^[A-Za-z0-9][A-Za-z0-9._-]{0,159}$"
        },
        "region": {
          "type": "string",
          "pattern": "^[a-z0-9][a-z0-9-]{1,15}$"
        },
        "regions": {
          "type": "array",
          "items": {
            "type": "string",
            "pattern": "^[a-z0-9][a-z0-9-]{1,15}$"
          },
          "maxItems": 100
        },
        "cpu": {
          "anyOf": [
            {
              "type": "number",
              "exclusiveMinimum": 0
            },
            {
              "type": "null"
            }
          ]
        },
        "cpu_unit": {
          "anyOf": [
            {
              "type": "string",
              "enum": [
                "vcpus",
                "sockets"
              ]
            },
            {
              "type": "null"
            }
          ]
        },
        "ram": {
          "anyOf": [
            {
              "type": "number",
              "exclusiveMinimum": 0
            },
            {
              "type": "null"
            }
          ]
        },
        "ram_unit": {
          "type": "string",
          "const": "MiB",
          "enum": [
            "MiB"
          ]
        },
        "disk": {
          "anyOf": [
            {
              "type": "number",
              "exclusiveMinimum": 0
            },
            {
              "type": "null"
            }
          ]
        },
        "disk_unit": {
          "type": "string",
          "const": "GiB",
          "enum": [
            "GiB"
          ]
        },
        "price": {
          "anyOf": [
            {
              "type": "string",
              "pattern": "^(?:0|[1-9]\\d{0,13})(?:\\.\\d{1,4})?$"
            },
            {
              "type": "null"
            }
          ]
        },
        "billing_cycle": {
          "anyOf": [
            {
              "type": "string",
              "maxLength": 200
            },
            {
              "type": "null"
            }
          ]
        },
        "billing_cycles": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "billing_cycle": {
                "type": "string",
                "maxLength": 200
              },
              "unit": {
                "type": "string",
                "maxLength": 200
              },
              "count": {
                "type": "integer",
                "exclusiveMinimum": 0
              },
              "period_months": {
                "anyOf": [
                  {
                    "type": "number",
                    "exclusiveMinimum": 0
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "price": {
                "type": "string",
                "pattern": "^(?:0|[1-9]\\d{0,13})(?:\\.\\d{1,4})?$"
              },
              "setup_fee": {
                "anyOf": [
                  {
                    "type": "string",
                    "pattern": "^(?:0|[1-9]\\d{0,13})(?:\\.\\d{1,4})?$"
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "currency": {
                "type": "string",
                "enum": [
                  "EUR",
                  "USD",
                  "GBP",
                  "UAH",
                  "PLN",
                  "BRL",
                  "INR",
                  "IDR",
                  "CNY"
                ]
              }
            },
            "required": [
              "billing_cycle",
              "unit",
              "count",
              "period_months",
              "price",
              "setup_fee",
              "currency"
            ],
            "additionalProperties": false
          },
          "maxItems": 100
        },
        "currency": {
          "type": "string",
          "enum": [
            "EUR",
            "USD",
            "GBP",
            "UAH",
            "PLN",
            "BRL",
            "INR",
            "IDR",
            "CNY"
          ]
        },
        "available": {
          "type": "boolean"
        },
        "capacity_verified": {
          "type": "boolean"
        },
        "configuration_code": {
          "anyOf": [
            {
              "type": "string",
              "maxLength": 200
            },
            {
              "type": "null"
            }
          ]
        },
        "available_stock": {
          "anyOf": [
            {
              "type": "integer",
              "minimum": 0
            },
            {
              "type": "null"
            }
          ]
        },
        "pricing_mode": {
          "type": "string",
          "enum": [
            "domain_quote",
            "configured"
          ]
        },
        "availability": {
          "type": "string",
          "enum": [
            "available",
            "unavailable",
            "unknown"
          ]
        },
        "configuration_url": {
          "type": "string",
          "pattern": "^\\/v1\\/billing\\/products\\/[0-9a-f-]+\\/variants\\/[0-9a-f-]+\\/order-options$"
        },
        "prices_url": {
          "type": "string",
          "maxLength": 512,
          "pattern": "^\\/v1\\/products\\/"
        },
        "options_url": {
          "type": "string",
          "maxLength": 512,
          "pattern": "^\\/v1\\/products\\/"
        },
        "quote_url": {
          "type": "string",
          "const": "/v1/billing/orders/preview",
          "enum": [
            "/v1/billing/orders/preview"
          ]
        },
        "deploy_url": {
          "type": "string",
          "maxLength": 512,
          "pattern": "^\\/v1\\/deploy\\/"
        }
      },
      "required": [
        "id",
        "product_id",
        "variant_id",
        "name",
        "type",
        "product_code",
        "variant_code",
        "region",
        "regions",
        "cpu",
        "cpu_unit",
        "ram",
        "ram_unit",
        "disk",
        "disk_unit",
        "price",
        "billing_cycle",
        "billing_cycles",
        "currency",
        "available",
        "capacity_verified",
        "configuration_code",
        "available_stock",
        "prices_url",
        "options_url",
        "quote_url"
      ],
      "additionalProperties": false
    },
    "partial": {
      "type": "boolean"
    },
    "unavailable_types": {
      "type": "array",
      "items": {
        "type": "string",
        "enum": [
          "vps",
          "dedicated"
        ]
      }
    }
  },
  "required": [
    "ok",
    "item"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "item": {
    "id": "8G",
    "product_id": "00000000-0000-4000-8000-000000000001",
    "variant_id": "00000000-0000-4000-8000-000000000002",
    "name": "Example VPS",
    "type": "vps",
    "product_code": "vps",
    "variant_code": "8G",
    "region": "nl",
    "regions": [
      "nl"
    ],
    "cpu": 4,
    "cpu_unit": "vcpus",
    "ram": 8192,
    "ram_unit": "MiB",
    "disk": 100,
    "disk_unit": "GiB",
    "price": "12.00",
    "billing_cycle": "monthly",
    "billing_cycles": [
      {
        "billing_cycle": "monthly",
        "unit": "MONTH",
        "count": 1,
        "period_months": 1,
        "price": "12.00",
        "setup_fee": "0",
        "currency": "EUR"
      },
      {
        "billing_cycle": "quarterly",
        "unit": "QUARTAL",
        "count": 1,
        "period_months": 3,
        "price": "30.00",
        "setup_fee": "0",
        "currency": "EUR"
      }
    ],
    "currency": "EUR",
    "available": true,
    "capacity_verified": false,
    "configuration_code": null,
    "available_stock": null,
    "prices_url": "/v1/products/nl/vps/8G/prices",
    "options_url": "/v1/products/nl/vps/8G/options",
    "quote_url": "/v1/billing/orders/preview",
    "deploy_url": "/v1/deploy/nl/vps/8G"
  }
}

API reference and code examples

GET/v1/products/{region}/{productCode}/{variantCode}/optionsRead configuration options by public code

Operation ID: productOptions

Same authoritative configuration discovery as the UUID order-options endpoint, resolved by eligible region, family and exact SKU. Returns required inputs, defaults, compatible OS choices, owned SSH-key selection fields, connectivity options and IP/add-on limits. No private provider settings, inventory identities or credentials. Discovery does not reserve stock or pay.

Required scopes: billing.products.read

Parameters

  • region · path · required — Eligible region, for example nl or pt. A single region is required.
  • productCode · path · required — Product family.
  • variantCode · path · required — Exact case-sensitive public SKU, for example 2G or PTV4-1. Never an internal inventory ID.
  • currency · query — Pricing currency; defaults to EUR. Quotes and orders use account currency.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "productId": {
      "type": "string",
      "format": "uuid"
    },
    "variantId": {
      "type": "string",
      "format": "uuid"
    },
    "supported": {
      "type": "boolean"
    },
    "capacityVerified": {
      "type": "boolean"
    },
    "purchase": {
      "type": "object",
      "properties": {
        "draft_order": {
          "type": "object",
          "properties": {
            "implemented": {
              "type": "boolean"
            },
            "enabled": {
              "type": "boolean"
            },
            "eligible": {
              "type": "boolean"
            },
            "requires_approval": {
              "type": "boolean"
            },
            "payment_required": {
              "type": "boolean"
            },
            "payment_methods": {
              "type": "array",
              "items": {
                "type": "string",
                "const": "balance",
                "enum": [
                  "balance"
                ]
              }
            },
            "partial_payment": {
              "type": "boolean"
            },
            "idempotency_required": {
              "type": "boolean"
            },
            "permitted": {
              "type": "boolean"
            }
          },
          "required": [
            "implemented",
            "enabled",
            "eligible",
            "requires_approval",
            "payment_required",
            "payment_methods",
            "partial_payment",
            "idempotency_required"
          ],
          "additionalProperties": false
        },
        "atomic_deploy": {
          "type": "object",
          "properties": {
            "implemented": {
              "type": "boolean"
            },
            "enabled": {
              "type": "boolean"
            },
            "eligible": {
              "type": "boolean"
            },
            "requires_approval": {
              "type": "boolean"
            },
            "payment_required": {
              "type": "boolean"
            },
            "payment_methods": {
              "type": "array",
              "items": {
                "type": "string",
                "const": "balance",
                "enum": [
                  "balance"
                ]
              }
            },
            "partial_payment": {
              "type": "boolean"
            },
            "idempotency_required": {
              "type": "boolean"
            },
            "permitted": {
              "type": "boolean"
            }
          },
          "required": [
            "implemented",
            "enabled",
            "eligible",
            "requires_approval",
            "payment_required",
            "payment_methods",
            "partial_payment",
            "idempotency_required"
          ],
          "additionalProperties": false
        }
      },
      "required": [
        "draft_order",
        "atomic_deploy"
      ],
      "additionalProperties": false
    },
    "requirements": {
      "type": "object",
      "properties": {
        "atomic_deploy": {
          "type": "object",
          "additionalProperties": {
            "type": "object",
            "properties": {
              "required": {
                "type": "boolean"
              },
              "type": {
                "type": "string",
                "enum": [
                  "string",
                  "integer",
                  "number",
                  "array"
                ]
              },
              "format": {
                "type": "string",
                "enum": [
                  "hostname",
                  "domain",
                  "uuid",
                  "ipv4"
                ]
              },
              "source": {
                "type": "string",
                "pattern": "^\\/v1\\/"
              },
              "min_items": {
                "type": "integer",
                "exclusiveMinimum": 0
              },
              "max_items": {
                "type": "integer",
                "exclusiveMinimum": 0
              },
              "allowed_values": {
                "type": "array",
                "items": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "number"
                    }
                  ]
                },
                "maxItems": 100
              }
            },
            "required": [
              "required",
              "type"
            ],
            "additionalProperties": false
          }
        }
      },
      "required": [
        "atomic_deploy"
      ],
      "additionalProperties": false
    },
    "reason": {
      "type": "string",
      "enum": [
        "unsupported_product_type",
        "unsupported_location"
      ]
    },
    "serviceType": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "requiredFields": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "field": {
            "type": "string"
          },
          "label": {
            "type": "string"
          },
          "description": {
            "type": "string"
          },
          "format": {
            "type": "string",
            "enum": [
              "hostname",
              "domain",
              "uuid"
            ]
          },
          "minLength": {
            "type": "number"
          }
        },
        "required": [
          "field",
          "label",
          "description"
        ],
        "additionalProperties": false
      }
    },
    "conditionalRequiredFields": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "whenField": {
            "type": "string"
          },
          "whenEquals": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              },
              {
                "type": "boolean"
              },
              {
                "type": "null"
              }
            ]
          },
          "fields": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "field": {
                  "type": "string"
                },
                "label": {
                  "type": "string"
                },
                "description": {
                  "type": "string"
                },
                "format": {
                  "type": "string",
                  "enum": [
                    "hostname",
                    "domain",
                    "uuid"
                  ]
                },
                "minLength": {
                  "type": "number"
                }
              },
              "required": [
                "field",
                "label",
                "description"
              ],
              "additionalProperties": false
            }
          }
        },
        "required": [
          "whenField",
          "whenEquals",
          "fields"
        ],
        "additionalProperties": false
      }
    },
    "optionalFields": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "field": {
            "type": "string"
          },
          "description": {
            "type": "string"
          },
          "format": {
            "type": "string"
          }
        },
        "required": [
          "field",
          "description",
          "format"
        ],
        "additionalProperties": false
      }
    },
    "defaults": {
      "type": "object",
      "properties": {
        "location": {
          "type": "string"
        }
      },
      "additionalProperties": false
    },
    "addons": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "key": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "chargeType": {
            "type": "string"
          },
          "maxQty": {
            "anyOf": [
              {
                "type": "number"
              },
              {
                "type": "null"
              }
            ]
          },
          "kind": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "speedGbps": {
            "anyOf": [
              {
                "type": "number"
              },
              {
                "type": "null"
              }
            ]
          },
          "billingOptions": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "unit": {
                  "type": "string"
                },
                "count": {
                  "type": "number"
                },
                "currency": {
                  "type": "string"
                },
                "price": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "number"
                    }
                  ]
                },
                "setupFee": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "number"
                    },
                    {
                      "type": "null"
                    }
                  ]
                }
              },
              "required": [
                "unit",
                "count",
                "currency",
                "price"
              ],
              "additionalProperties": false
            }
          }
        },
        "required": [
          "key",
          "name",
          "chargeType",
          "maxQty",
          "kind",
          "speedGbps",
          "billingOptions"
        ],
        "additionalProperties": false
      }
    },
    "billingOptions": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "unit": {
            "type": "string"
          },
          "count": {
            "type": "number"
          },
          "currency": {
            "type": "string"
          },
          "price": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              }
            ]
          },
          "setupFee": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              },
              {
                "type": "null"
              }
            ]
          }
        },
        "required": [
          "unit",
          "count",
          "currency",
          "price"
        ],
        "additionalProperties": false
      }
    },
    "currency": {
      "type": "string",
      "enum": [
        "USD",
        "EUR",
        "UAH",
        "GBP",
        "PLN",
        "BRL",
        "INR",
        "IDR",
        "CNY"
      ]
    },
    "quoteUrl": {
      "type": "string",
      "const": "/v1/billing/orders/preview",
      "enum": [
        "/v1/billing/orders/preview"
      ]
    },
    "orderUrl": {
      "type": "string",
      "const": "/v1/billing/orders/draft",
      "enum": [
        "/v1/billing/orders/draft"
      ]
    },
    "checkoutEnabled": {
      "type": "boolean"
    },
    "pricingMode": {
      "type": "string",
      "enum": [
        "configured",
        "domain_quote"
      ]
    },
    "connectivity": {
      "type": "object",
      "properties": {
        "physicalCapacityGbps": {
          "anyOf": [
            {
              "type": "number"
            },
            {
              "type": "null"
            }
          ]
        },
        "defaultGbps": {
          "anyOf": [
            {
              "type": "number"
            },
            {
              "type": "null"
            }
          ]
        },
        "options": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "speedGbps": {
                "type": "number",
                "exclusiveMinimum": 0
              }
            },
            "required": [
              "speedGbps"
            ],
            "additionalProperties": false
          }
        }
      },
      "required": [
        "physicalCapacityGbps",
        "defaultGbps",
        "options"
      ],
      "additionalProperties": false
    },
    "ipv4": {
      "type": "object",
      "properties": {
        "included": {
          "type": "integer",
          "minimum": 0
        },
        "maxAdditional": {
          "type": "integer",
          "minimum": 0
        }
      },
      "required": [
        "included",
        "maxAdditional"
      ],
      "additionalProperties": false
    },
    "orderExpirationMinutes": {
      "type": "number",
      "exclusiveMinimum": 0
    },
    "tcpProxy": {
      "type": "object",
      "properties": {
        "includedPorts": {
          "type": "integer",
          "exclusiveMinimum": 0
        },
        "maxPorts": {
          "type": "integer",
          "exclusiveMinimum": 0
        }
      },
      "required": [
        "includedPorts",
        "maxPorts"
      ],
      "additionalProperties": false
    },
    "locations": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "code": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "configurationCode": {
            "type": "string"
          },
          "availableStock": {
            "type": "integer",
            "minimum": 0
          },
          "operatingSystems": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "code": {
                  "type": "string"
                },
                "id": {
                  "type": "number",
                  "exclusiveMinimum": 0
                },
                "name": {
                  "type": "string"
                },
                "family": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "version": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "arch": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "isDefault": {
                  "type": "boolean"
                },
                "sshKeysSupported": {
                  "type": "boolean"
                }
              },
              "required": [
                "code",
                "name",
                "family",
                "version",
                "arch",
                "isDefault"
              ],
              "additionalProperties": false
            }
          }
        },
        "required": [
          "code",
          "name",
          "operatingSystems"
        ],
        "additionalProperties": false
      }
    },
    "region": {
      "type": "string",
      "pattern": "^[a-z0-9][a-z0-9-]{1,15}$"
    },
    "product_code": {
      "type": "string",
      "enum": [
        "vps",
        "dedicated",
        "tcp-proxy",
        "waf",
        "license",
        "webhosting",
        "storage",
        "dns",
        "domain",
        "other"
      ]
    },
    "variant_code": {
      "type": "string",
      "pattern": "^[A-Za-z0-9][A-Za-z0-9._-]{0,159}$"
    }
  },
  "required": [
    "ok",
    "productId",
    "variantId",
    "supported",
    "capacityVerified",
    "requiredFields",
    "locations",
    "region",
    "product_code",
    "variant_code"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "region": "nl",
  "product_code": "vps",
  "variant_code": "8G",
  "productId": "00000000-0000-4000-8000-000000000001",
  "variantId": "00000000-0000-4000-8000-000000000002",
  "supported": true,
  "capacityVerified": false,
  "requiredFields": [
    {
      "field": "hostname",
      "label": "Hostname",
      "description": "Server hostname.",
      "format": "hostname"
    },
    {
      "field": "location",
      "label": "Location",
      "description": "Location code."
    },
    {
      "field": "os.code",
      "label": "Operating system",
      "description": "Operating system code."
    }
  ],
  "locations": [
    {
      "code": "NL",
      "name": "Netherlands",
      "operatingSystems": [
        {
          "code": "debian-13",
          "name": "Debian",
          "family": "debian",
          "version": "13",
          "arch": "amd64",
          "isDefault": true
        }
      ]
    }
  ]
}

API reference and code examples

GET/v1/products/{region}/{productCode}/{variantCode}/pricesRead billing prices by public code

Operation ID: productPrices

Base-plan prices only, as exact decimal strings with unit/count, setup_fee and currency. Optional billing_cycle filters configured periods; an unavailable period returns billing_cycle_not_available (400). An omitted period returns all public prices in the requested currency. Add-ons and tax require POST /v1/billing/orders/preview using the returned order UUIDs. Domain prices require a domain quote. price_scope=base_plan is not a final payable amount.

Required scopes: billing.products.read

Parameters

  • region · path · required — Eligible region, for example nl or pt. A single region is required.
  • productCode · path · required — Product family.
  • variantCode · path · required — Exact case-sensitive public SKU, for example 2G or PTV4-1. Never an internal inventory ID.
  • currency · query — Pricing currency; defaults to EUR. Quotes and orders use account currency.
  • billing_cycle · query — Optional billing period from the returned values.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "region": {
      "type": "string",
      "pattern": "^[a-z0-9][a-z0-9-]{1,15}$"
    },
    "product_code": {
      "type": "string",
      "enum": [
        "vps",
        "dedicated",
        "tcp-proxy",
        "waf",
        "license",
        "webhosting",
        "storage",
        "dns",
        "domain",
        "other"
      ]
    },
    "variant_code": {
      "type": "string",
      "pattern": "^[A-Za-z0-9][A-Za-z0-9._-]{0,159}$"
    },
    "currency": {
      "type": "string",
      "enum": [
        "EUR",
        "USD",
        "GBP",
        "UAH",
        "PLN",
        "BRL",
        "INR",
        "IDR",
        "CNY"
      ]
    },
    "prices": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "billing_cycle": {
            "type": "string",
            "maxLength": 200
          },
          "unit": {
            "type": "string",
            "maxLength": 200
          },
          "count": {
            "type": "integer",
            "exclusiveMinimum": 0
          },
          "period_months": {
            "anyOf": [
              {
                "type": "number",
                "exclusiveMinimum": 0
              },
              {
                "type": "null"
              }
            ]
          },
          "price": {
            "type": "string",
            "pattern": "^(?:0|[1-9]\\d{0,13})(?:\\.\\d{1,4})?$"
          },
          "setup_fee": {
            "anyOf": [
              {
                "type": "string",
                "pattern": "^(?:0|[1-9]\\d{0,13})(?:\\.\\d{1,4})?$"
              },
              {
                "type": "null"
              }
            ]
          },
          "currency": {
            "type": "string",
            "enum": [
              "EUR",
              "USD",
              "GBP",
              "UAH",
              "PLN",
              "BRL",
              "INR",
              "IDR",
              "CNY"
            ]
          }
        },
        "required": [
          "billing_cycle",
          "unit",
          "count",
          "period_months",
          "price",
          "setup_fee",
          "currency"
        ],
        "additionalProperties": false
      },
      "maxItems": 100
    },
    "pricing_mode": {
      "type": "string",
      "enum": [
        "domain_quote",
        "configured"
      ]
    },
    "price_scope": {
      "type": "string",
      "const": "base_plan",
      "enum": [
        "base_plan"
      ]
    },
    "quote_url": {
      "type": "string",
      "const": "/v1/billing/orders/preview",
      "enum": [
        "/v1/billing/orders/preview"
      ]
    }
  },
  "required": [
    "ok",
    "region",
    "product_code",
    "variant_code",
    "currency",
    "prices",
    "pricing_mode",
    "price_scope",
    "quote_url"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "region": "nl",
  "product_code": "vps",
  "variant_code": "8G",
  "currency": "EUR",
  "prices": [
    {
      "billing_cycle": "monthly",
      "unit": "MONTH",
      "count": 1,
      "period_months": 1,
      "price": "12.00",
      "setup_fee": "0",
      "currency": "EUR"
    },
    {
      "billing_cycle": "quarterly",
      "unit": "QUARTAL",
      "count": 1,
      "period_months": 3,
      "price": "30.00",
      "setup_fee": "0",
      "currency": "EUR"
    }
  ],
  "price_scope": "base_plan",
  "pricing_mode": "configured",
  "quote_url": "/v1/billing/orders/preview"
}

API reference and code examples

GET/v1/products/{region}/listList product codes by region

Operation ID: productCodes

Compact grouped public variant codes: products maps each family to an array of exact SKUs. Region eligibility is applied before pagination. limit counts variants across all families, not families; default 50. Follow next_offset until null and merge groups. Codes do not prove available stock; read the variant details and options. all includes all eligible regions; use a specific region for details and deployment. partial=true means collection is incomplete, not known zero stock. Existing flat catalog endpoints remain unchanged.

Required scopes: billing.products.read

Parameters

  • region · path · required — Region code or all.
  • limit · query — Maximum items, default 50 (1–100).
  • offset · query — Start offset, default 0. Use next_offset from the response; null means finished. This contract has no page or pageSize fields.
  • currency · query — Pricing currency; defaults to EUR. Quotes and orders use account currency.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "region": {
      "type": "string",
      "pattern": "^[a-z0-9][a-z0-9-]{1,15}$"
    },
    "products": {
      "type": "object",
      "additionalProperties": {
        "type": "array",
        "items": {
          "type": "string",
          "pattern": "^[A-Za-z0-9][A-Za-z0-9._-]{0,159}$"
        },
        "maxItems": 100
      }
    },
    "next_offset": {
      "anyOf": [
        {
          "type": "integer",
          "minimum": 0
        },
        {
          "type": "null"
        }
      ]
    },
    "partial": {
      "type": "boolean"
    },
    "unavailable_types": {
      "type": "array",
      "items": {
        "type": "string",
        "enum": [
          "vps",
          "dedicated"
        ]
      }
    }
  },
  "required": [
    "ok",
    "region",
    "products",
    "next_offset"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "region": "nl",
  "products": {
    "vps": [
      "8G"
    ]
  },
  "next_offset": null
}

API reference and code examples

GET/v1/products/{region}/list/{productCode}List variant codes for a family

Operation ID: getProductsByRegionListByProductCode

Same compact grouped response, restricted to the selected product family before pagination. An empty family array means no matching public plans on this page. Read detail availability separately; this does not reserve stock.

Required scopes: billing.products.read

Parameters

  • region · path · required — Eligible region, for example nl or pt. A single region is required.
  • productCode · path · required — Product family.
  • limit · query — Maximum items, default 50 (1–100).
  • offset · query — Start offset, default 0. Use next_offset from the response; null means finished. This contract has no page or pageSize fields.
  • currency · query — Pricing currency; defaults to EUR. Quotes and orders use account currency.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "region": {
      "type": "string",
      "pattern": "^[a-z0-9][a-z0-9-]{1,15}$"
    },
    "products": {
      "type": "object",
      "additionalProperties": {
        "type": "array",
        "items": {
          "type": "string",
          "pattern": "^[A-Za-z0-9][A-Za-z0-9._-]{0,159}$"
        },
        "maxItems": 100
      }
    },
    "next_offset": {
      "anyOf": [
        {
          "type": "integer",
          "minimum": 0
        },
        {
          "type": "null"
        }
      ]
    },
    "partial": {
      "type": "boolean"
    },
    "unavailable_types": {
      "type": "array",
      "items": {
        "type": "string",
        "enum": [
          "vps",
          "dedicated"
        ]
      }
    }
  },
  "required": [
    "ok",
    "region",
    "products",
    "next_offset"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "region": "nl",
  "products": {
    "vps": [
      "8G"
    ]
  },
  "next_offset": null
}

API reference and code examples

GET/v1/regionsList regions

Operation ID: regions

Lists regions with VPS image choices or public orderable dedicated stock. Codes are lowercase; this does not reserve capacity.

Required scopes: billing.products.read

Parameters

  • limit · query — Maximum items, default 50 (1–100).
  • offset · query — Start offset, default 0. Use next_offset from the response; null means finished. This contract has no page or pageSize fields.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "pattern": "^[a-z0-9][a-z0-9-]{1,15}$"
          },
          "name": {
            "type": "string",
            "maxLength": 200
          }
        },
        "required": [
          "id",
          "name"
        ],
        "additionalProperties": false
      }
    },
    "next_offset": {
      "anyOf": [
        {
          "type": "number"
        },
        {
          "type": "null"
        }
      ]
    }
  },
  "required": [
    "ok",
    "items",
    "next_offset"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "items": [
    {
      "id": "nl",
      "name": "Netherlands"
    },
    {
      "id": "pt",
      "name": "Portugal"
    }
  ],
  "next_offset": null
}

API reference and code examples

GET/v1/vps/imagesList VPS images

Operation ID: vpsImages

Returns VM-template OS codes and their region, family, version, architecture and default flag, without internal template references. Optional product_id and variant_id must be supplied together to restrict to a public VPS plan and its region. For full plan-specific configuration use the existing order-options endpoint. compatibility_verified=false means this is catalog discovery, not a physical capacity or placement guarantee. New VPS order configuration uses userConfig.os.code and uppercase userConfig.location.

Required scopes: billing.products.read

Parameters

  • limit · query — Maximum items, default 50 (1–100).
  • offset · query — Start offset, default 0. Use next_offset from the response; null means finished. This contract has no page or pageSize fields.
  • region · query — Region code from GET /v1/regions, for example nl or pt. Case-insensitive.
  • product_id · query — Public product UUID; supply with variant_id.
  • variant_id · query — Public VPS variant UUID; supply with product_id.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "maxLength": 200
          },
          "name": {
            "type": "string",
            "maxLength": 200
          },
          "family": {
            "anyOf": [
              {
                "type": "string",
                "maxLength": 200
              },
              {
                "type": "null"
              }
            ]
          },
          "version": {
            "anyOf": [
              {
                "type": "string",
                "maxLength": 200
              },
              {
                "type": "null"
              }
            ]
          },
          "arch": {
            "anyOf": [
              {
                "type": "string",
                "maxLength": 200
              },
              {
                "type": "null"
              }
            ]
          },
          "is_default": {
            "type": "boolean"
          },
          "region": {
            "type": "string",
            "pattern": "^[a-z0-9][a-z0-9-]{1,15}$"
          }
        },
        "required": [
          "id",
          "name",
          "family",
          "version",
          "arch",
          "is_default",
          "region"
        ],
        "additionalProperties": false
      }
    },
    "next_offset": {
      "anyOf": [
        {
          "type": "number"
        },
        {
          "type": "null"
        }
      ]
    },
    "compatibility_verified": {
      "type": "boolean"
    }
  },
  "required": [
    "ok",
    "items",
    "next_offset"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "items": [
    {
      "id": "debian-13",
      "name": "Debian",
      "family": "debian",
      "version": "13",
      "arch": "amd64",
      "is_default": true,
      "region": "nl"
    }
  ],
  "next_offset": null,
  "compatibility_verified": false
}

API reference and code examples

Billing

GET/v1/billing/balanceCheck wallet balance

Operation ID: billingBalance

Returns current account credit and currency so billing dashboards or automation can decide whether balance payment is available.

Required scopes: billing.balance.read

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "exists": {
      "type": "boolean"
    },
    "currency": {
      "type": "string"
    },
    "credit": {
      "type": "string"
    },
    "vcredit": {
      "type": "string"
    }
  },
  "required": [
    "ok",
    "exists",
    "currency",
    "credit",
    "vcredit"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "exists": true,
  "currency": "EUR",
  "credit": "100",
  "vcredit": "0"
}

API reference and code examples

GET/v1/billing/invoicesBrowse invoices

Operation ID: listInvoices

Returns paginated customer invoices. Use this to build invoice history views, overdue checks, or reconciliation jobs.

Required scopes: billing.invoices.read

Parameters

  • page · query — Page number for pagination.
  • limit · query — Maximum items to return (default 50; range 1–100). Canonical page-size parameter. Deprecated page_size and pageSize aliases remain accepted; supplied size values must match.
  • page_size · query · deprecated compatibility alias — Deprecated compatibility alias for limit; values must match when supplied together.
  • pageSize · query · deprecated compatibility alias — Deprecated compatibility alias for limit; range 1–100, default 50.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "page": {
      "type": "integer",
      "exclusiveMinimum": 0
    },
    "pageSize": {
      "type": "integer",
      "exclusiveMinimum": 0
    },
    "total": {
      "type": "integer",
      "minimum": 0
    },
    "pages": {
      "type": "integer",
      "exclusiveMinimum": 0
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "number": {
            "type": "string"
          },
          "status": {
            "type": "string"
          },
          "total": {
            "type": "string"
          },
          "paidTotal": {
            "type": "string"
          },
          "refundedTotal": {
            "type": "string"
          },
          "currency": {
            "type": "string"
          },
          "type": {
            "type": "string"
          },
          "createdAt": {
            "type": "string"
          },
          "dueDate": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "payDate": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "order": {
            "anyOf": [
              {
                "type": "object",
                "properties": {
                  "id": {
                    "type": "string"
                  },
                  "status": {
                    "type": "string"
                  }
                },
                "required": [
                  "id",
                  "status"
                ],
                "additionalProperties": true
              },
              {
                "type": "null"
              }
            ]
          }
        },
        "required": [
          "id",
          "number",
          "status",
          "total",
          "paidTotal",
          "currency"
        ],
        "additionalProperties": true
      }
    }
  },
  "required": [
    "ok",
    "items"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "page": 1,
  "pageSize": 50,
  "total": 1,
  "pages": 1,
  "items": [
    {
      "id": "00000000-0000-4000-8000-000000000001",
      "number": "INV-EXAMPLE-000001",
      "status": "unpaid",
      "total": "100.00",
      "paidTotal": "0.00",
      "currency": "EUR",
      "type": "purchase",
      "refundedTotal": "0.00",
      "createdAt": "2026-10-01T00:00:00.000Z",
      "dueDate": "2026-11-01T00:00:00.000Z",
      "payDate": null,
      "order": null
    }
  ]
}

API reference and code examples

POST/v1/billing/invoices/{id}/payPay invoice from wallet

Operation ID: payInvoice

Attempts to settle the target invoice using account balance. This is the customer API path for balance-driven payment automation.

Required scopes: billing.invoice.pay

Parameters

  • id · path · required — Invoice UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "paidNow": {
      "type": "string"
    },
    "partial": {
      "type": "boolean"
    },
    "fullyPaid": {
      "type": "boolean"
    },
    "invoiceId": {
      "type": "string"
    },
    "orderId": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "status": {
      "type": "string"
    },
    "meta": {
      "type": "object",
      "properties": {
        "createdServices": {
          "type": "number"
        },
        "renewedServices": {
          "type": "number"
        },
        "createdServiceIds": {
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "provisioning": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        }
      },
      "additionalProperties": true
    }
  },
  "required": [
    "ok",
    "paidNow",
    "partial",
    "fullyPaid",
    "invoiceId",
    "orderId",
    "status",
    "meta"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "paidNow": "100",
  "partial": false,
  "fullyPaid": true,
  "invoiceId": "00000000-0000-4000-8000-000000000001",
  "orderId": null,
  "status": "paid",
  "meta": {
    "createdServices": 0,
    "renewedServices": 1,
    "createdServiceIds": [],
    "provisioning": null
  }
}

API reference and code examples

GET/v1/billing/invoices/unpaid-totalCheck unpaid total

Operation ID: billingUnpaidTotal

Returns the current unpaid amount across customer invoices. This is useful for dashboard badges and automation that should pause when debt exists.

Required scopes: billing.unpaid_total.read

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "data": {
      "type": "object",
      "properties": {
        "unpaidTotal": {
          "type": "number"
        },
        "currency": {
          "type": "string"
        }
      },
      "required": [
        "unpaidTotal",
        "currency"
      ],
      "additionalProperties": true
    }
  },
  "required": [
    "ok",
    "data"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "data": {
    "unpaidTotal": 0,
    "currency": "EUR"
  }
}

API reference and code examples

GET/v1/billing/ordersBrowse orders

Operation ID: billingOrders

Returns paginated customer orders and supports filtering by order or payment status for reporting and customer portals.

Required scopes: billing.orders.read

Parameters

  • page · query — Page number for pagination.
  • limit · query — Maximum items to return (default 50; range 1–100). Canonical page-size parameter. Deprecated page_size and pageSize aliases remain accepted; supplied size values must match.
  • page_size · query · deprecated compatibility alias — Deprecated compatibility alias for limit; values must match when supplied together.
  • pageSize · query · deprecated compatibility alias — Deprecated compatibility alias for limit; range 1–100, default 50.
  • status · query — Optional order status filter.
  • paymentStatus · query — Optional payment status filter.
  • external_id · query — Exact customer reference on an owned order item; applied before pagination.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "page": {
      "type": "integer",
      "exclusiveMinimum": 0
    },
    "pageSize": {
      "type": "integer",
      "exclusiveMinimum": 0
    },
    "total": {
      "type": "integer",
      "minimum": 0
    },
    "pages": {
      "type": "integer",
      "exclusiveMinimum": 0
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "status": {
            "type": "string"
          },
          "currency": {
            "type": "string"
          },
          "total": {
            "type": "string"
          },
          "paymentStatus": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "paymentMethod": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "createdAt": {
            "type": "string"
          },
          "invoice": {
            "anyOf": [
              {
                "type": "object",
                "properties": {
                  "id": {
                    "type": "string"
                  },
                  "number": {
                    "type": "string"
                  },
                  "status": {
                    "type": "string"
                  },
                  "total": {
                    "type": "string"
                  },
                  "paidTotal": {
                    "type": "string"
                  },
                  "refundedTotal": {
                    "type": "string"
                  },
                  "currency": {
                    "type": "string"
                  },
                  "type": {
                    "type": "string"
                  },
                  "createdAt": {
                    "type": "string"
                  },
                  "dueDate": {
                    "anyOf": [
                      {
                        "type": "string"
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "payDate": {
                    "anyOf": [
                      {
                        "type": "string"
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "order": {
                    "anyOf": [
                      {
                        "type": "object",
                        "properties": {
                          "id": {
                            "type": "string"
                          },
                          "status": {
                            "type": "string"
                          }
                        },
                        "required": [
                          "id",
                          "status"
                        ],
                        "additionalProperties": true
                      },
                      {
                        "type": "null"
                      }
                    ]
                  }
                },
                "required": [
                  "id",
                  "number",
                  "status",
                  "total",
                  "paidTotal",
                  "currency"
                ],
                "additionalProperties": true
              },
              {
                "type": "null"
              }
            ]
          },
          "items": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "id": {
                  "type": "string"
                },
                "productId": {
                  "type": "string"
                },
                "variantId": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "quantity": {
                  "type": "integer"
                },
                "external_id": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "labels": {
                  "type": "object",
                  "additionalProperties": {
                    "type": "string"
                  }
                }
              },
              "required": [
                "id",
                "productId",
                "variantId",
                "quantity"
              ],
              "additionalProperties": false
            }
          }
        },
        "required": [
          "id",
          "status",
          "currency",
          "total"
        ],
        "additionalProperties": true
      }
    }
  },
  "required": [
    "ok",
    "items"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "page": 1,
  "pageSize": 50,
  "total": 1,
  "pages": 1,
  "items": [
    {
      "id": "00000000-0000-4000-8000-000000000001",
      "status": "pending",
      "currency": "EUR",
      "total": "100.00",
      "paymentStatus": "unpaid",
      "paymentMethod": null,
      "createdAt": "2026-10-01T00:00:00.000Z",
      "invoice": {
        "id": "00000000-0000-4000-8000-000000000001",
        "number": "INV-EXAMPLE-000001",
        "status": "unpaid",
        "total": "100.00",
        "paidTotal": "0.00",
        "currency": "EUR"
      }
    }
  ]
}

API reference and code examples

POST/v1/billing/orders/draftStart draft order

Operation ID: billingOrderDraft

Creates a draft order from one or more items so you can continue into invoice creation and payment.

Required scopes: billing.order.create

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "idempotency_key": {
      "type": "string",
      "minLength": 1,
      "maxLength": 200
    },
    "currency": {
      "type": "string",
      "enum": [
        "USD",
        "EUR",
        "UAH",
        "GBP",
        "PLN",
        "BRL",
        "INR",
        "IDR",
        "CNY"
      ]
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "product_id": {
            "type": "string",
            "format": "uuid"
          },
          "variant_id": {
            "type": "string",
            "format": "uuid"
          },
          "qty": {
            "type": "integer",
            "minimum": 1,
            "maximum": 100
          },
          "user_config": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              },
              {
                "type": "boolean"
              },
              {
                "type": "null"
              },
              {
                "type": "array",
                "items": {
                  "description": "JSON value; product-specific fields are discovered through order-options."
                }
              },
              {
                "type": "object",
                "additionalProperties": {
                  "description": "JSON value; product-specific fields are discovered through order-options."
                }
              }
            ]
          },
          "attributes": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              },
              {
                "type": "boolean"
              },
              {
                "type": "null"
              },
              {
                "type": "array",
                "items": {
                  "description": "JSON value; product-specific fields are discovered through order-options."
                }
              },
              {
                "type": "object",
                "additionalProperties": {
                  "description": "JSON value; product-specific fields are discovered through order-options."
                }
              }
            ]
          },
          "billing": {
            "type": "object",
            "properties": {
              "unit": {
                "type": "string",
                "enum": [
                  "ONCE",
                  "HOUR",
                  "DAY",
                  "WEEK",
                  "MONTH",
                  "QUARTAL",
                  "SEMIANNUAL",
                  "YEAR"
                ]
              },
              "count": {
                "type": "integer",
                "minimum": 1,
                "maximum": 120
              }
            },
            "required": [
              "unit",
              "count"
            ],
            "additionalProperties": false
          },
          "addons": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "key": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 120,
                  "pattern": "^[A-Za-z0-9_.:-]+$"
                },
                "qty": {
                  "type": "integer",
                  "minimum": 1,
                  "maximum": 100
                }
              },
              "required": [
                "key",
                "qty"
              ],
              "additionalProperties": false
            },
            "maxItems": 50
          }
        },
        "required": [
          "product_id",
          "variant_id",
          "qty",
          "billing"
        ],
        "additionalProperties": false
      },
      "minItems": 1,
      "maxItems": 50
    }
  },
  "required": [
    "currency",
    "items"
  ],
  "additionalProperties": false,
  "example": {
    "currency": "EUR",
    "items": [
      {
        "product_id": "00000000-0000-4000-8000-000000000001",
        "variant_id": "00000000-0000-4000-8000-000000000002",
        "qty": 1,
        "billing": {
          "unit": "MONTH",
          "count": 1
        },
        "user_config": {
          "hostname": "example",
          "location": "NL",
          "os": {
            "code": "debian-13"
          }
        },
        "addons": []
      }
    ]
  },
  "description": "Illustrative VPS cart. Replace IDs, required user_config fields, billing period and add-ons with the selected public plan’s order-options. The server validates ownership, eligibility and prices; caller-supplied hardware/price cannot change the plan. Quotes require complete billing details and use account currency."
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "orderId": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "invoiceId": {
      "type": "string"
    },
    "invoiceNumber": {
      "type": "string"
    },
    "invoice": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "number": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "total": {
          "type": "string"
        },
        "paidTotal": {
          "type": "string"
        },
        "currency": {
          "type": "string"
        },
        "createdAt": {
          "type": "string"
        },
        "dueDate": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "payDate": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "refundedTotal": {
          "type": "string"
        }
      },
      "required": [
        "id",
        "number",
        "status",
        "total",
        "paidTotal",
        "currency"
      ],
      "additionalProperties": true
    },
    "total": {
      "type": "string"
    },
    "currency": {
      "type": "string"
    },
    "status": {
      "type": "string"
    },
    "paymentStatus": {
      "type": "string"
    },
    "serviceIds": {
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "message": {
      "type": "string"
    },
    "deploymentStatusUrl": {
      "type": "string"
    },
    "applied": {
      "type": "boolean"
    },
    "payNow": {
      "type": "string"
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "orderId": "00000000-0000-4000-8000-000000000001",
  "invoiceId": "00000000-0000-4000-8000-000000000002",
  "invoiceNumber": "INV-EXAMPLE-000001",
  "total": "100.00",
  "currency": "EUR",
  "status": "unpaid"
}

API reference and code examples

POST/v1/billing/orders/previewPreview order total

Operation ID: billingOrderPreview

Submit the same complete cart as order creation, including userConfig and public add-on key/qty selections. Uses checkout validation and pricing, equivalent billing periods, account currency and tax. Requires complete billing details. Returns reserved=false: no reservation, order, invoice or payment is created. A quote does not guarantee later stock or prices. The older single-item preview body is accepted and normalized to the same cart.

Required scopes: billing.products.read

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "anyOf": [
    {
      "type": "object",
      "properties": {
        "idempotency_key": {
          "type": "string",
          "minLength": 1,
          "maxLength": 200
        },
        "currency": {
          "type": "string",
          "enum": [
            "USD",
            "EUR",
            "UAH",
            "GBP",
            "PLN",
            "BRL",
            "INR",
            "IDR",
            "CNY"
          ]
        },
        "items": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "product_id": {
                "type": "string",
                "format": "uuid"
              },
              "variant_id": {
                "type": "string",
                "format": "uuid"
              },
              "qty": {
                "type": "integer",
                "minimum": 1,
                "maximum": 100
              },
              "user_config": {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "number"
                  },
                  {
                    "type": "boolean"
                  },
                  {
                    "type": "null"
                  },
                  {
                    "type": "array",
                    "items": {
                      "description": "JSON value; product-specific fields are discovered through order-options."
                    }
                  },
                  {
                    "type": "object",
                    "additionalProperties": {
                      "description": "JSON value; product-specific fields are discovered through order-options."
                    }
                  }
                ]
              },
              "attributes": {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "number"
                  },
                  {
                    "type": "boolean"
                  },
                  {
                    "type": "null"
                  },
                  {
                    "type": "array",
                    "items": {
                      "description": "JSON value; product-specific fields are discovered through order-options."
                    }
                  },
                  {
                    "type": "object",
                    "additionalProperties": {
                      "description": "JSON value; product-specific fields are discovered through order-options."
                    }
                  }
                ]
              },
              "billing": {
                "type": "object",
                "properties": {
                  "unit": {
                    "type": "string",
                    "enum": [
                      "ONCE",
                      "HOUR",
                      "DAY",
                      "WEEK",
                      "MONTH",
                      "QUARTAL",
                      "SEMIANNUAL",
                      "YEAR"
                    ]
                  },
                  "count": {
                    "type": "integer",
                    "minimum": 1,
                    "maximum": 120
                  }
                },
                "required": [
                  "unit",
                  "count"
                ],
                "additionalProperties": false
              },
              "addons": {
                "type": "array",
                "items": {
                  "type": "object",
                  "properties": {
                    "key": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 120,
                      "pattern": "^[A-Za-z0-9_.:-]+$"
                    },
                    "qty": {
                      "type": "integer",
                      "minimum": 1,
                      "maximum": 100
                    }
                  },
                  "required": [
                    "key",
                    "qty"
                  ],
                  "additionalProperties": false
                },
                "maxItems": 50
              }
            },
            "required": [
              "product_id",
              "variant_id",
              "qty",
              "billing"
            ],
            "additionalProperties": false
          },
          "minItems": 1,
          "maxItems": 50
        }
      },
      "required": [
        "currency",
        "items"
      ],
      "additionalProperties": false
    },
    {
      "type": "object",
      "properties": {
        "product_id": {
          "type": "string",
          "format": "uuid"
        },
        "variant_id": {
          "type": "string",
          "format": "uuid"
        },
        "currency": {
          "type": "string",
          "maxLength": 3,
          "minLength": 3
        },
        "unit": {
          "type": "string",
          "minLength": 1,
          "maxLength": 20
        },
        "count": {
          "type": "integer",
          "minimum": 1,
          "maximum": 120
        },
        "quantity": {
          "type": "integer",
          "minimum": 1,
          "maximum": 100,
          "default": 1
        },
        "user_config": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "number"
            },
            {
              "type": "boolean"
            },
            {
              "type": "null"
            },
            {
              "type": "array",
              "items": {
                "description": "JSON value; product-specific fields are discovered through order-options."
              }
            },
            {
              "type": "object",
              "additionalProperties": {
                "description": "JSON value; product-specific fields are discovered through order-options."
              }
            }
          ]
        },
        "addons": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "key": {
                "type": "string",
                "minLength": 1,
                "maxLength": 120,
                "pattern": "^[A-Za-z0-9_.:-]+$"
              },
              "qty": {
                "type": "integer",
                "minimum": 1,
                "maximum": 100
              }
            },
            "required": [
              "key",
              "qty"
            ],
            "additionalProperties": false
          },
          "maxItems": 50
        }
      },
      "required": [
        "product_id",
        "variant_id",
        "currency",
        "unit",
        "count"
      ],
      "additionalProperties": false
    }
  ],
  "example": {
    "currency": "EUR",
    "items": [
      {
        "product_id": "00000000-0000-4000-8000-000000000001",
        "variant_id": "00000000-0000-4000-8000-000000000002",
        "qty": 1,
        "billing": {
          "unit": "MONTH",
          "count": 1
        },
        "user_config": {
          "hostname": "example",
          "location": "NL",
          "os": {
            "code": "debian-13"
          }
        },
        "addons": []
      }
    ]
  },
  "description": "Illustrative VPS cart. Replace IDs, required user_config fields, billing period and add-ons with the selected public plan’s order-options. The server validates ownership, eligibility and prices; caller-supplied hardware/price cannot change the plan. Quotes require complete billing details and use account currency."
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "currency": {
      "type": "string",
      "maxLength": 3,
      "minLength": 3
    },
    "reserved": {
      "type": "boolean",
      "const": false,
      "enum": [
        false
      ]
    },
    "subtotal": {
      "type": "string",
      "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
    },
    "tax": {
      "type": "string",
      "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
    },
    "total": {
      "type": "string",
      "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
    },
    "breakdown": {
      "type": "object",
      "properties": {
        "base_price": {
          "type": "string",
          "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
        },
        "addons": {
          "type": "string",
          "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
        },
        "setup_fee": {
          "type": "string",
          "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
        },
        "tax": {
          "type": "string",
          "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
        },
        "total": {
          "type": "string",
          "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
        }
      },
      "required": [
        "base_price",
        "addons",
        "setup_fee",
        "tax",
        "total"
      ],
      "additionalProperties": false
    },
    "quote": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string",
          "pattern": "^quo_[a-f0-9]{64}$"
        },
        "currency": {
          "type": "string",
          "maxLength": 3,
          "minLength": 3
        },
        "total": {
          "type": "string",
          "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
        },
        "breakdown": {
          "type": "object",
          "properties": {
            "base_price": {
              "type": "string",
              "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
            },
            "addons": {
              "type": "string",
              "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
            },
            "setup_fee": {
              "type": "string",
              "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
            },
            "tax": {
              "type": "string",
              "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
            },
            "total": {
              "type": "string",
              "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
            }
          },
          "required": [
            "base_price",
            "addons",
            "setup_fee",
            "tax",
            "total"
          ],
          "additionalProperties": false
        },
        "guaranteed": {
          "type": "boolean",
          "const": false,
          "enum": [
            false
          ]
        },
        "pricing_revision": {
          "type": "string",
          "pattern": "^sha256:[a-f0-9]{64}$"
        },
        "recommended_max_total": {
          "type": "string",
          "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
        }
      },
      "required": [
        "id",
        "currency",
        "total",
        "breakdown",
        "guaranteed",
        "pricing_revision",
        "recommended_max_total"
      ],
      "additionalProperties": false
    },
    "links": {
      "type": "object",
      "properties": {
        "deploy": {
          "type": "string",
          "pattern": "^\\/v1\\/deploy\\/[A-Za-z0-9._%/-]+$"
        }
      },
      "required": [
        "deploy"
      ],
      "additionalProperties": false
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "productId": {
            "type": "string",
            "format": "uuid"
          },
          "variantId": {
            "type": "string",
            "format": "uuid"
          },
          "productName": {
            "type": "string",
            "maxLength": 500
          },
          "sku": {
            "type": "string",
            "maxLength": 200
          },
          "quantity": {
            "type": "integer",
            "minimum": 1,
            "maximum": 100
          },
          "billing": {
            "type": "object",
            "properties": {
              "unit": {
                "type": "string",
                "maxLength": 20
              },
              "count": {
                "type": "integer",
                "minimum": 1,
                "maximum": 120
              }
            },
            "required": [
              "unit",
              "count"
            ],
            "additionalProperties": false
          },
          "unitPrice": {
            "type": "string",
            "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
          },
          "setupFee": {
            "type": "string",
            "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
          },
          "subtotal": {
            "type": "string",
            "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
          },
          "addons": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "key": {
                  "type": "string",
                  "maxLength": 120
                },
                "name": {
                  "type": "string",
                  "maxLength": 500
                },
                "qty": {
                  "type": "integer",
                  "minimum": 1,
                  "maximum": 100
                },
                "unitPrice": {
                  "anyOf": [
                    {
                      "type": "string",
                      "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
                    },
                    {
                      "type": "number",
                      "minimum": 0
                    }
                  ]
                },
                "setupFee": {
                  "anyOf": [
                    {
                      "type": "string",
                      "pattern": "^\\d{1,20}(\\.\\d{1,10})?$"
                    },
                    {
                      "type": "number",
                      "minimum": 0
                    }
                  ]
                },
                "chargeType": {
                  "type": "string",
                  "maxLength": 40
                },
                "billedSeparately": {
                  "type": "boolean"
                }
              },
              "required": [
                "key",
                "name",
                "qty",
                "unitPrice",
                "setupFee",
                "chargeType"
              ],
              "additionalProperties": false
            },
            "maxItems": 100
          }
        },
        "required": [
          "productId",
          "variantId",
          "productName",
          "sku",
          "quantity",
          "billing",
          "unitPrice",
          "setupFee",
          "subtotal",
          "addons"
        ],
        "additionalProperties": false
      },
      "maxItems": 50
    }
  },
  "required": [
    "ok",
    "currency",
    "reserved",
    "subtotal",
    "tax",
    "total",
    "breakdown",
    "items"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "currency": "EUR",
  "subtotal": "100.00",
  "tax": "0.00",
  "total": "100.00",
  "reserved": false,
  "breakdown": {
    "base_price": "100.00",
    "addons": "0.00",
    "setup_fee": "0.00",
    "tax": "0.00",
    "total": "100.00"
  },
  "items": [
    {
      "productId": "00000000-0000-4000-8000-000000000001",
      "variantId": "00000000-0000-4000-8000-000000000002",
      "productName": "Example VPS",
      "sku": "4G",
      "quantity": 1,
      "billing": {
        "unit": "MONTH",
        "count": 1
      },
      "unitPrice": "100",
      "setupFee": "0",
      "subtotal": "100",
      "addons": []
    }
  ]
}

API reference and code examples

GET/v1/billing/productsBrowse product catalog

Operation ID: billingProducts

Returns product catalog entries that can be used for storefront search, quoting, and pre-checkout selection flows.

Required scopes: billing.products.read

Parameters

  • page · query — Page number for pagination.
  • limit · query — Maximum items to return (default 50; range 1–100). Canonical page-size parameter. Deprecated page_size and pageSize aliases remain accepted; supplied size values must match.
  • page_size · query · deprecated compatibility alias — Deprecated compatibility alias for limit; values must match when supplied together.
  • pageSize · query · deprecated compatibility alias — Deprecated compatibility alias for limit; range 1–100, default 50.
  • category · query — Optional category filter.
  • q · query — Optional free-text search query.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "page": {
      "type": "number"
    },
    "pageSize": {
      "type": "number"
    },
    "total": {
      "type": "number"
    },
    "pages": {
      "type": "number"
    },
    "next_offset": {
      "anyOf": [
        {
          "type": "number"
        },
        {
          "type": "null"
        }
      ]
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "category": {
            "type": "string"
          },
          "variants": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "id": {
                  "type": "string"
                },
                "productId": {
                  "type": "string"
                },
                "sku": {
                  "type": "string"
                },
                "serviceType": {
                  "type": "string"
                },
                "attributes": {
                  "type": "object",
                  "additionalProperties": {
                    "$ref": "#/$defs/JsonValue"
                  }
                },
                "addons": {
                  "type": "array",
                  "items": {
                    "type": "object",
                    "properties": {
                      "key": {
                        "type": "string"
                      },
                      "name": {
                        "type": "string"
                      },
                      "quantity": {
                        "type": "number"
                      },
                      "qty": {
                        "type": "number"
                      },
                      "price": {
                        "type": "string"
                      },
                      "unitPrice": {
                        "anyOf": [
                          {
                            "type": "string"
                          },
                          {
                            "type": "number"
                          }
                        ]
                      },
                      "setupFee": {
                        "anyOf": [
                          {
                            "type": "string"
                          },
                          {
                            "type": "number"
                          }
                        ]
                      },
                      "chargeType": {
                        "type": "string"
                      },
                      "billedSeparately": {
                        "type": "boolean"
                      }
                    },
                    "required": [
                      "key"
                    ],
                    "additionalProperties": true
                  }
                },
                "billingOptions": {
                  "type": "array",
                  "items": {
                    "type": "object",
                    "properties": {
                      "unit": {
                        "type": "string"
                      },
                      "count": {
                        "type": "number"
                      },
                      "currency": {
                        "type": "string"
                      },
                      "price": {
                        "type": "string"
                      },
                      "setupFee": {
                        "type": "string"
                      }
                    },
                    "required": [
                      "unit",
                      "count",
                      "currency",
                      "price"
                    ],
                    "additionalProperties": true
                  }
                }
              },
              "required": [
                "id",
                "productId",
                "sku",
                "serviceType",
                "attributes",
                "addons",
                "billingOptions"
              ],
              "additionalProperties": true
            }
          }
        },
        "required": [
          "id",
          "name",
          "category",
          "variants"
        ],
        "additionalProperties": true
      }
    }
  },
  "required": [
    "ok",
    "items"
  ],
  "additionalProperties": true,
  "$defs": {
    "JsonValue": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "number"
        },
        {
          "type": "boolean"
        },
        {
          "type": "null"
        },
        {
          "type": "array",
          "items": {
            "$ref": "#/$defs/JsonValue"
          }
        },
        {
          "type": "object",
          "additionalProperties": {
            "$ref": "#/$defs/JsonValue"
          }
        }
      ]
    }
  }
}

Illustrative successful response

{
  "ok": true,
  "page": 1,
  "pageSize": 50,
  "total": 1,
  "pages": 1,
  "items": [
    {
      "id": "00000000-0000-4000-8000-000000000001",
      "name": "Example VPS",
      "category": "vps",
      "variants": [
        {
          "id": "00000000-0000-4000-8000-000000000002",
          "productId": "00000000-0000-4000-8000-000000000001",
          "sku": "4G",
          "serviceType": "vps",
          "attributes": {
            "compute": {
              "CPU": 2,
              "RAM": 4
            },
            "storage": {
              "DISK_SPACE": 40
            }
          },
          "addons": [],
          "billingOptions": [
            {
              "unit": "MONTH",
              "count": 1,
              "currency": "EUR",
              "price": "100.00",
              "setupFee": "0.00"
            }
          ]
        }
      ]
    }
  ]
}

API reference and code examples

GET/v1/billing/products/{productId}/variants/{variantId}/order-optionsDiscover product order options

Operation ID: billingProductOrderOptions

Read-only complete configuration discovery for a public, active product and variant. Returns required and optional fields, conditional requirements, priced add-ons, billing options and eligible OS/regions. VPS uses userConfig.location and userConfig.os.code. Managed dedicated uses userConfig.dedicated.configurationCode, regionCode, osProfileId and hostname; optional sshKeyId must belong to your account. Includes physical/default connectivity, purchasable bandwidth add-ons, IPv4 limits and reservation TTL. supported=false means dashboard-only. No capacity is reserved; compatible catalog stock is not a reservation. Domain pricingMode=domain_quote requires a domain-specific quote. No infrastructure secrets are returned.

Required scopes: billing.products.read

Parameters

  • productId · path · required — Product UUID from the catalog.
  • variantId · path · required — Variant UUID belonging to this product.
  • region · query — Region code from GET /v1/regions, for example nl or pt. Case-insensitive.
  • currency · query — Pricing currency, default EUR.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "productId": {
      "type": "string",
      "format": "uuid"
    },
    "variantId": {
      "type": "string",
      "format": "uuid"
    },
    "supported": {
      "type": "boolean"
    },
    "capacityVerified": {
      "type": "boolean"
    },
    "purchase": {
      "type": "object",
      "properties": {
        "draft_order": {
          "type": "object",
          "properties": {
            "implemented": {
              "type": "boolean"
            },
            "enabled": {
              "type": "boolean"
            },
            "eligible": {
              "type": "boolean"
            },
            "requires_approval": {
              "type": "boolean"
            },
            "payment_required": {
              "type": "boolean"
            },
            "payment_methods": {
              "type": "array",
              "items": {
                "type": "string",
                "const": "balance",
                "enum": [
                  "balance"
                ]
              }
            },
            "partial_payment": {
              "type": "boolean"
            },
            "idempotency_required": {
              "type": "boolean"
            },
            "permitted": {
              "type": "boolean"
            }
          },
          "required": [
            "implemented",
            "enabled",
            "eligible",
            "requires_approval",
            "payment_required",
            "payment_methods",
            "partial_payment",
            "idempotency_required"
          ],
          "additionalProperties": false
        },
        "atomic_deploy": {
          "type": "object",
          "properties": {
            "implemented": {
              "type": "boolean"
            },
            "enabled": {
              "type": "boolean"
            },
            "eligible": {
              "type": "boolean"
            },
            "requires_approval": {
              "type": "boolean"
            },
            "payment_required": {
              "type": "boolean"
            },
            "payment_methods": {
              "type": "array",
              "items": {
                "type": "string",
                "const": "balance",
                "enum": [
                  "balance"
                ]
              }
            },
            "partial_payment": {
              "type": "boolean"
            },
            "idempotency_required": {
              "type": "boolean"
            },
            "permitted": {
              "type": "boolean"
            }
          },
          "required": [
            "implemented",
            "enabled",
            "eligible",
            "requires_approval",
            "payment_required",
            "payment_methods",
            "partial_payment",
            "idempotency_required"
          ],
          "additionalProperties": false
        }
      },
      "required": [
        "draft_order",
        "atomic_deploy"
      ],
      "additionalProperties": false
    },
    "requirements": {
      "type": "object",
      "properties": {
        "atomic_deploy": {
          "type": "object",
          "additionalProperties": {
            "type": "object",
            "properties": {
              "required": {
                "type": "boolean"
              },
              "type": {
                "type": "string",
                "enum": [
                  "string",
                  "integer",
                  "number",
                  "array"
                ]
              },
              "format": {
                "type": "string",
                "enum": [
                  "hostname",
                  "domain",
                  "uuid",
                  "ipv4"
                ]
              },
              "source": {
                "type": "string",
                "pattern": "^\\/v1\\/"
              },
              "min_items": {
                "type": "integer",
                "exclusiveMinimum": 0
              },
              "max_items": {
                "type": "integer",
                "exclusiveMinimum": 0
              },
              "allowed_values": {
                "type": "array",
                "items": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "number"
                    }
                  ]
                },
                "maxItems": 100
              }
            },
            "required": [
              "required",
              "type"
            ],
            "additionalProperties": false
          }
        }
      },
      "required": [
        "atomic_deploy"
      ],
      "additionalProperties": false
    },
    "reason": {
      "type": "string",
      "enum": [
        "unsupported_product_type",
        "unsupported_location"
      ]
    },
    "serviceType": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "requiredFields": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "field": {
            "type": "string"
          },
          "label": {
            "type": "string"
          },
          "description": {
            "type": "string"
          },
          "format": {
            "type": "string",
            "enum": [
              "hostname",
              "domain",
              "uuid"
            ]
          },
          "minLength": {
            "type": "number"
          }
        },
        "required": [
          "field",
          "label",
          "description"
        ],
        "additionalProperties": false
      }
    },
    "conditionalRequiredFields": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "whenField": {
            "type": "string"
          },
          "whenEquals": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              },
              {
                "type": "boolean"
              },
              {
                "type": "null"
              }
            ]
          },
          "fields": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "field": {
                  "type": "string"
                },
                "label": {
                  "type": "string"
                },
                "description": {
                  "type": "string"
                },
                "format": {
                  "type": "string",
                  "enum": [
                    "hostname",
                    "domain",
                    "uuid"
                  ]
                },
                "minLength": {
                  "type": "number"
                }
              },
              "required": [
                "field",
                "label",
                "description"
              ],
              "additionalProperties": false
            }
          }
        },
        "required": [
          "whenField",
          "whenEquals",
          "fields"
        ],
        "additionalProperties": false
      }
    },
    "optionalFields": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "field": {
            "type": "string"
          },
          "description": {
            "type": "string"
          },
          "format": {
            "type": "string"
          }
        },
        "required": [
          "field",
          "description",
          "format"
        ],
        "additionalProperties": false
      }
    },
    "defaults": {
      "type": "object",
      "properties": {
        "location": {
          "type": "string"
        }
      },
      "additionalProperties": false
    },
    "addons": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "key": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "chargeType": {
            "type": "string"
          },
          "maxQty": {
            "anyOf": [
              {
                "type": "number"
              },
              {
                "type": "null"
              }
            ]
          },
          "kind": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "speedGbps": {
            "anyOf": [
              {
                "type": "number"
              },
              {
                "type": "null"
              }
            ]
          },
          "billingOptions": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "unit": {
                  "type": "string"
                },
                "count": {
                  "type": "number"
                },
                "currency": {
                  "type": "string"
                },
                "price": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "number"
                    }
                  ]
                },
                "setupFee": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "number"
                    },
                    {
                      "type": "null"
                    }
                  ]
                }
              },
              "required": [
                "unit",
                "count",
                "currency",
                "price"
              ],
              "additionalProperties": false
            }
          }
        },
        "required": [
          "key",
          "name",
          "chargeType",
          "maxQty",
          "kind",
          "speedGbps",
          "billingOptions"
        ],
        "additionalProperties": false
      }
    },
    "billingOptions": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "unit": {
            "type": "string"
          },
          "count": {
            "type": "number"
          },
          "currency": {
            "type": "string"
          },
          "price": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              }
            ]
          },
          "setupFee": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              },
              {
                "type": "null"
              }
            ]
          }
        },
        "required": [
          "unit",
          "count",
          "currency",
          "price"
        ],
        "additionalProperties": false
      }
    },
    "currency": {
      "type": "string",
      "enum": [
        "USD",
        "EUR",
        "UAH",
        "GBP",
        "PLN",
        "BRL",
        "INR",
        "IDR",
        "CNY"
      ]
    },
    "quoteUrl": {
      "type": "string",
      "const": "/v1/billing/orders/preview",
      "enum": [
        "/v1/billing/orders/preview"
      ]
    },
    "orderUrl": {
      "type": "string",
      "const": "/v1/billing/orders/draft",
      "enum": [
        "/v1/billing/orders/draft"
      ]
    },
    "checkoutEnabled": {
      "type": "boolean"
    },
    "pricingMode": {
      "type": "string",
      "enum": [
        "configured",
        "domain_quote"
      ]
    },
    "connectivity": {
      "type": "object",
      "properties": {
        "physicalCapacityGbps": {
          "anyOf": [
            {
              "type": "number"
            },
            {
              "type": "null"
            }
          ]
        },
        "defaultGbps": {
          "anyOf": [
            {
              "type": "number"
            },
            {
              "type": "null"
            }
          ]
        },
        "options": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "speedGbps": {
                "type": "number",
                "exclusiveMinimum": 0
              }
            },
            "required": [
              "speedGbps"
            ],
            "additionalProperties": false
          }
        }
      },
      "required": [
        "physicalCapacityGbps",
        "defaultGbps",
        "options"
      ],
      "additionalProperties": false
    },
    "ipv4": {
      "type": "object",
      "properties": {
        "included": {
          "type": "integer",
          "minimum": 0
        },
        "maxAdditional": {
          "type": "integer",
          "minimum": 0
        }
      },
      "required": [
        "included",
        "maxAdditional"
      ],
      "additionalProperties": false
    },
    "orderExpirationMinutes": {
      "type": "number",
      "exclusiveMinimum": 0
    },
    "tcpProxy": {
      "type": "object",
      "properties": {
        "includedPorts": {
          "type": "integer",
          "exclusiveMinimum": 0
        },
        "maxPorts": {
          "type": "integer",
          "exclusiveMinimum": 0
        }
      },
      "required": [
        "includedPorts",
        "maxPorts"
      ],
      "additionalProperties": false
    },
    "locations": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "code": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "configurationCode": {
            "type": "string"
          },
          "availableStock": {
            "type": "integer",
            "minimum": 0
          },
          "operatingSystems": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "code": {
                  "type": "string"
                },
                "id": {
                  "type": "number",
                  "exclusiveMinimum": 0
                },
                "name": {
                  "type": "string"
                },
                "family": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "version": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "arch": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "isDefault": {
                  "type": "boolean"
                },
                "sshKeysSupported": {
                  "type": "boolean"
                }
              },
              "required": [
                "code",
                "name",
                "family",
                "version",
                "arch",
                "isDefault"
              ],
              "additionalProperties": false
            }
          }
        },
        "required": [
          "code",
          "name",
          "operatingSystems"
        ],
        "additionalProperties": false
      }
    }
  },
  "required": [
    "ok",
    "productId",
    "variantId",
    "supported",
    "capacityVerified",
    "requiredFields",
    "locations"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "productId": "00000000-0000-4000-8000-000000000001",
  "variantId": "00000000-0000-4000-8000-000000000002",
  "supported": true,
  "capacityVerified": false,
  "requiredFields": [
    {
      "field": "hostname",
      "label": "Hostname",
      "description": "Server hostname.",
      "format": "hostname"
    },
    {
      "field": "location",
      "label": "Location",
      "description": "Location code."
    },
    {
      "field": "os.code",
      "label": "Operating system",
      "description": "Operating system code."
    }
  ],
  "locations": [
    {
      "code": "NL",
      "name": "Netherlands",
      "operatingSystems": [
        {
          "code": "debian-13",
          "name": "Debian",
          "family": "debian",
          "version": "13",
          "arch": "amd64",
          "isDefault": true
        }
      ]
    }
  ]
}

API reference and code examples

GET/v1/billing/servicesBrowse billable services

Operation ID: billingServices

Returns the billing-facing service list. Use this endpoint when the main goal is commercial visibility rather than grouped customer dashboards.

Required scopes: billing.services.read

Parameters

  • page · query — Page number for pagination.
  • limit · query — Maximum items to return (default 50; range 1–100). Canonical page-size parameter. Deprecated page_size and pageSize aliases remain accepted; supplied size values must match.
  • page_size · query · deprecated compatibility alias — Deprecated compatibility alias for limit; values must match when supplied together.
  • pageSize · query · deprecated compatibility alias — Deprecated compatibility alias for limit; range 1–100, default 50.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "page": {
      "type": "integer",
      "exclusiveMinimum": 0
    },
    "pageSize": {
      "type": "integer",
      "exclusiveMinimum": 0
    },
    "total": {
      "type": "integer",
      "minimum": 0
    },
    "pages": {
      "type": "integer",
      "exclusiveMinimum": 0
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "status": {
            "type": "string"
          },
          "displayName": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "hostname": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "region": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "type": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "createdAt": {
            "type": "string"
          },
          "activationAt": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "dueDate": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "billingUnit": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "billingCount": {
            "anyOf": [
              {
                "type": "integer"
              },
              {
                "type": "null"
              }
            ]
          },
          "sku": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "productName": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "ipv4": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "ipv6": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "external_id": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "labels": {
            "type": "object",
            "additionalProperties": {
              "type": "string"
            }
          },
          "provisioning_status": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "meta": {
            "anyOf": [
              {
                "type": "object",
                "properties": {
                  "serviceType": {
                    "type": "string"
                  },
                  "includedByDefault": {
                    "type": "boolean"
                  },
                  "instanceIndex": {
                    "type": "number"
                  }
                },
                "additionalProperties": false
              },
              {
                "type": "null"
              }
            ]
          }
        },
        "required": [
          "id"
        ],
        "additionalProperties": true
      }
    },
    "counts": {
      "type": "object",
      "additionalProperties": {
        "type": "integer",
        "minimum": 0
      }
    },
    "group_by": {
      "type": "string",
      "const": "type",
      "enum": [
        "type"
      ]
    },
    "groups": {
      "type": "object",
      "additionalProperties": {
        "type": "array",
        "items": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "status": {
              "type": "string"
            },
            "displayName": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "hostname": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "region": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "type": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "createdAt": {
              "type": "string"
            },
            "activationAt": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "dueDate": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "billingUnit": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "billingCount": {
              "anyOf": [
                {
                  "type": "integer"
                },
                {
                  "type": "null"
                }
              ]
            },
            "sku": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "productName": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "ipv4": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "ipv6": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "external_id": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "labels": {
              "type": "object",
              "additionalProperties": {
                "type": "string"
              }
            },
            "provisioning_status": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "meta": {
              "anyOf": [
                {
                  "type": "object",
                  "properties": {
                    "serviceType": {
                      "type": "string"
                    },
                    "includedByDefault": {
                      "type": "boolean"
                    },
                    "instanceIndex": {
                      "type": "number"
                    }
                  },
                  "additionalProperties": false
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        }
      }
    }
  },
  "required": [
    "ok",
    "items"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "page": 1,
  "pageSize": 50,
  "total": 1,
  "pages": 1,
  "items": [
    {
      "id": "00000000-0000-4000-8000-000000000001",
      "status": "active",
      "displayName": "Example VPS",
      "hostname": "server.example.com",
      "type": "vps",
      "createdAt": "2026-10-01T00:00:00.000Z",
      "dueDate": "2026-11-01T00:00:00.000Z",
      "billingUnit": "MONTH",
      "billingCount": 1,
      "sku": "4G",
      "ipv4": "192.0.2.10",
      "ipv6": null,
      "meta": {
        "serviceType": "vps"
      }
    }
  ]
}

API reference and code examples

GET/v1/billing/transactionsBrowse transactions

Operation ID: billingTransactions

Returns paginated financial transaction records for account history and payment auditing.

Required scopes: billing.transactions.read

Parameters

  • page · query — Page number for pagination.
  • limit · query — Maximum items to return (default 50; range 1–100). Canonical page-size parameter. Deprecated page_size and pageSize aliases remain accepted; supplied size values must match.
  • page_size · query · deprecated compatibility alias — Deprecated compatibility alias for limit; values must match when supplied together.
  • pageSize · query · deprecated compatibility alias — Deprecated compatibility alias for limit; range 1–100, default 50.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "page": {
      "type": "number"
    },
    "pageSize": {
      "type": "number"
    },
    "total": {
      "type": "number"
    },
    "pages": {
      "type": "number"
    },
    "next_offset": {
      "anyOf": [
        {
          "type": "number"
        },
        {
          "type": "null"
        }
      ]
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "createdAt": {
            "type": "string"
          },
          "status": {
            "type": "string"
          },
          "type": {
            "type": "string"
          },
          "currency": {
            "type": "string"
          },
          "amountIn": {
            "type": "string"
          },
          "amountOut": {
            "type": "string"
          },
          "fee": {
            "type": "string"
          },
          "gateway": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "invoiceId": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "meta": {
            "anyOf": [
              {
                "type": "object",
                "additionalProperties": {
                  "$ref": "#/$defs/JsonValue"
                }
              },
              {
                "type": "null"
              }
            ]
          }
        },
        "required": [
          "id",
          "createdAt",
          "status",
          "type",
          "currency",
          "amountIn",
          "amountOut",
          "fee",
          "gateway",
          "invoiceId",
          "meta"
        ],
        "additionalProperties": true
      }
    }
  },
  "required": [
    "ok",
    "items"
  ],
  "additionalProperties": true,
  "$defs": {
    "JsonValue": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "number"
        },
        {
          "type": "boolean"
        },
        {
          "type": "null"
        },
        {
          "type": "array",
          "items": {
            "$ref": "#/$defs/JsonValue"
          }
        },
        {
          "type": "object",
          "additionalProperties": {
            "$ref": "#/$defs/JsonValue"
          }
        }
      ]
    }
  }
}

Illustrative successful response

{
  "ok": true,
  "page": 1,
  "pageSize": 50,
  "total": 1,
  "pages": 1,
  "items": [
    {
      "id": "00000000-0000-4000-8000-000000000001",
      "createdAt": "2026-10-01T00:00:00.000Z",
      "status": "completed",
      "type": "payment",
      "currency": "EUR",
      "amountIn": "100.00",
      "amountOut": "0.00",
      "fee": "0.00",
      "gateway": null,
      "invoiceId": "00000000-0000-4000-8000-000000000002",
      "meta": null
    }
  ]
}

API reference and code examples

Services

GET/v1/my/servicesList my purchased services

Operation ID: listMyServices

Read-only alias of GET /v1/services with identical ownership, scope, filters and response contract. Defaults to active+suspended; terminated services require an explicit filter. Lifecycle status is separate from runtime power. Hostname and region are included when known; passwords are available only from separately scoped credential endpoints.

Required scopes: billing.services.read

Parameters

  • status · query — Service lifecycle status; defaults to active and suspended when no status filter is supplied. Power state is separate.
  • type · query — High-level normalized service family: vps, dedicated, webhosting, storage, dns, domain or other (comma-separated). Distinct from catalog product_code: tcp-proxy and license map to other; waf maps to dns. Applied before pagination; use discovered product_code for purchasing.
  • statuses · query — Comma-separated lifecycle statuses, for example active,suspended. Use this or status, not both. Filtering and counts use service status, never runtime power state.
  • types · query — Comma-separated service types. Alias for type; do not supply both.
  • search · query — Search hostname, customer IPv4/IPv6, display name, product name, SKU or full service UUID; maximum 200 characters. Applied before pagination.
  • external_id · query — Exact customer integration reference; applied before pagination.
  • label · query — Exact metadata label match: key=value. Applied before pagination.
  • include_counts · query — Request counts only for selected statuses, with the same ownership, type and search filters. Omitted by default.
  • group_by · query — Group the current page by type, retaining items and pagination.
  • page · query — Page number for pagination.
  • limit · query — Maximum items to return (default 50; range 1–100). Canonical page-size parameter. Deprecated page_size and pageSize aliases remain accepted; supplied size values must match.
  • page_size · query · deprecated compatibility alias — Deprecated compatibility alias for limit; values must match when supplied together.
  • pageSize · query · deprecated compatibility alias — Deprecated compatibility alias for limit; range 1–100, default 50.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "page": {
      "type": "integer",
      "exclusiveMinimum": 0
    },
    "pageSize": {
      "type": "integer",
      "exclusiveMinimum": 0
    },
    "total": {
      "type": "integer",
      "minimum": 0
    },
    "pages": {
      "type": "integer",
      "exclusiveMinimum": 0
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "status": {
            "type": "string"
          },
          "displayName": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "hostname": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "region": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "type": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "createdAt": {
            "type": "string"
          },
          "activationAt": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "dueDate": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "billingUnit": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "billingCount": {
            "anyOf": [
              {
                "type": "integer"
              },
              {
                "type": "null"
              }
            ]
          },
          "sku": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "productName": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "ipv4": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "ipv6": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "external_id": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "labels": {
            "type": "object",
            "additionalProperties": {
              "type": "string"
            }
          },
          "provisioning_status": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "meta": {
            "anyOf": [
              {
                "type": "object",
                "properties": {
                  "serviceType": {
                    "type": "string"
                  },
                  "includedByDefault": {
                    "type": "boolean"
                  },
                  "instanceIndex": {
                    "type": "number"
                  }
                },
                "additionalProperties": false
              },
              {
                "type": "null"
              }
            ]
          }
        },
        "required": [
          "id"
        ],
        "additionalProperties": true
      }
    },
    "counts": {
      "type": "object",
      "additionalProperties": {
        "type": "integer",
        "minimum": 0
      }
    },
    "group_by": {
      "type": "string",
      "const": "type",
      "enum": [
        "type"
      ]
    },
    "groups": {
      "type": "object",
      "additionalProperties": {
        "type": "array",
        "items": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "status": {
              "type": "string"
            },
            "displayName": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "hostname": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "region": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "type": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "createdAt": {
              "type": "string"
            },
            "activationAt": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "dueDate": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "billingUnit": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "billingCount": {
              "anyOf": [
                {
                  "type": "integer"
                },
                {
                  "type": "null"
                }
              ]
            },
            "sku": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "productName": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "ipv4": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "ipv6": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "external_id": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "labels": {
              "type": "object",
              "additionalProperties": {
                "type": "string"
              }
            },
            "provisioning_status": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "meta": {
              "anyOf": [
                {
                  "type": "object",
                  "properties": {
                    "serviceType": {
                      "type": "string"
                    },
                    "includedByDefault": {
                      "type": "boolean"
                    },
                    "instanceIndex": {
                      "type": "number"
                    }
                  },
                  "additionalProperties": false
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        }
      }
    }
  },
  "required": [
    "ok",
    "items"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "page": 1,
  "pageSize": 50,
  "total": 1,
  "pages": 1,
  "items": [
    {
      "id": "00000000-0000-4000-8000-000000000001",
      "status": "active",
      "displayName": "Example VPS",
      "hostname": "server.example.com",
      "type": "vps",
      "createdAt": "2026-10-01T00:00:00.000Z",
      "dueDate": "2026-11-01T00:00:00.000Z",
      "billingUnit": "MONTH",
      "billingCount": 1,
      "sku": "4G",
      "ipv4": "192.0.2.10",
      "ipv6": null,
      "meta": {
        "serviceType": "vps"
      }
    }
  ]
}

API reference and code examples

GET/v1/servicesBrowse services

Operation ID: listServices

Returns customer service summaries with hostname and recorded region code. Region uses provider/migration metadata, falling back to original order location; use VPS status for the currently assigned region. Null means unavailable. Does not disclose internal node or cluster identifiers. Ownership, status, type, search, external_id and label filters are applied server-side before pagination and counts. The default is active plus suspended; historical states require an explicit status filter. group_by=type groups only the current page, not the complete inventory.

Required scopes: billing.services.read

Parameters

  • status · query — Service lifecycle status; defaults to active and suspended when no status filter is supplied. Power state is separate.
  • type · query — High-level normalized service family: vps, dedicated, webhosting, storage, dns, domain or other (comma-separated). Distinct from catalog product_code: tcp-proxy and license map to other; waf maps to dns. Applied before pagination; use discovered product_code for purchasing.
  • statuses · query — Comma-separated lifecycle statuses, for example active,suspended. Use this or status, not both. Filtering and counts use service status, never runtime power state.
  • types · query — Comma-separated service types. Alias for type; do not supply both.
  • search · query — Search hostname, customer IPv4/IPv6, display name, product name, SKU or full service UUID; maximum 200 characters. Applied before pagination.
  • external_id · query — Exact customer integration reference; applied before pagination.
  • label · query — Exact metadata label match: key=value. Applied before pagination.
  • include_counts · query — Request counts only for selected statuses, with the same ownership, type and search filters. Omitted by default.
  • group_by · query — Group the current page by type, retaining items and pagination.
  • page · query — Page number for pagination.
  • limit · query — Maximum items to return (default 50; range 1–100). Canonical page-size parameter. Deprecated page_size and pageSize aliases remain accepted; supplied size values must match.
  • page_size · query · deprecated compatibility alias — Deprecated compatibility alias for limit; values must match when supplied together.
  • pageSize · query · deprecated compatibility alias — Deprecated compatibility alias for limit; range 1–100, default 50.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "page": {
      "type": "integer",
      "exclusiveMinimum": 0
    },
    "pageSize": {
      "type": "integer",
      "exclusiveMinimum": 0
    },
    "total": {
      "type": "integer",
      "minimum": 0
    },
    "pages": {
      "type": "integer",
      "exclusiveMinimum": 0
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "status": {
            "type": "string"
          },
          "displayName": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "hostname": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "region": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "type": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "createdAt": {
            "type": "string"
          },
          "activationAt": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "dueDate": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "billingUnit": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "billingCount": {
            "anyOf": [
              {
                "type": "integer"
              },
              {
                "type": "null"
              }
            ]
          },
          "sku": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "productName": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "ipv4": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "ipv6": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "external_id": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "labels": {
            "type": "object",
            "additionalProperties": {
              "type": "string"
            }
          },
          "provisioning_status": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "meta": {
            "anyOf": [
              {
                "type": "object",
                "properties": {
                  "serviceType": {
                    "type": "string"
                  },
                  "includedByDefault": {
                    "type": "boolean"
                  },
                  "instanceIndex": {
                    "type": "number"
                  }
                },
                "additionalProperties": false
              },
              {
                "type": "null"
              }
            ]
          }
        },
        "required": [
          "id"
        ],
        "additionalProperties": true
      }
    },
    "counts": {
      "type": "object",
      "additionalProperties": {
        "type": "integer",
        "minimum": 0
      }
    },
    "group_by": {
      "type": "string",
      "const": "type",
      "enum": [
        "type"
      ]
    },
    "groups": {
      "type": "object",
      "additionalProperties": {
        "type": "array",
        "items": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "status": {
              "type": "string"
            },
            "displayName": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "hostname": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "region": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "type": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "createdAt": {
              "type": "string"
            },
            "activationAt": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "dueDate": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "billingUnit": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "billingCount": {
              "anyOf": [
                {
                  "type": "integer"
                },
                {
                  "type": "null"
                }
              ]
            },
            "sku": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "productName": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "ipv4": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "ipv6": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "external_id": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "labels": {
              "type": "object",
              "additionalProperties": {
                "type": "string"
              }
            },
            "provisioning_status": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "meta": {
              "anyOf": [
                {
                  "type": "object",
                  "properties": {
                    "serviceType": {
                      "type": "string"
                    },
                    "includedByDefault": {
                      "type": "boolean"
                    },
                    "instanceIndex": {
                      "type": "number"
                    }
                  },
                  "additionalProperties": false
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        }
      }
    }
  },
  "required": [
    "ok",
    "items"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "page": 1,
  "pageSize": 50,
  "total": 1,
  "pages": 1,
  "items": [
    {
      "id": "00000000-0000-4000-8000-000000000001",
      "status": "active",
      "displayName": "Example VPS",
      "hostname": "server.example.com",
      "type": "vps",
      "createdAt": "2026-10-01T00:00:00.000Z",
      "dueDate": "2026-11-01T00:00:00.000Z",
      "billingUnit": "MONTH",
      "billingCount": 1,
      "sku": "4G",
      "ipv4": "192.0.2.10",
      "ipv6": null,
      "meta": {
        "serviceType": "vps"
      }
    }
  ]
}

API reference and code examples

GET/v1/services/{serviceId}Open service detail

Operation ID: getService

Returns the customer-facing detail view for one service.

Required scopes: billing.services.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "item": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "displayName": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "hostname": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "region": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "type": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "createdAt": {
          "type": "string"
        },
        "activationAt": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "dueDate": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "billingUnit": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "billingCount": {
          "anyOf": [
            {
              "type": "integer"
            },
            {
              "type": "null"
            }
          ]
        },
        "sku": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "productName": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "ipv4": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "ipv6": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "external_id": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "labels": {
          "type": "object",
          "additionalProperties": {
            "type": "string"
          }
        },
        "provisioning_status": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "meta": {
          "anyOf": [
            {
              "type": "object",
              "properties": {
                "serviceType": {
                  "type": "string"
                },
                "includedByDefault": {
                  "type": "boolean"
                },
                "instanceIndex": {
                  "type": "number"
                }
              },
              "additionalProperties": false
            },
            {
              "type": "null"
            }
          ]
        }
      },
      "required": [
        "id"
      ],
      "additionalProperties": true
    }
  },
  "required": [
    "ok",
    "item"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "item": {
    "id": "00000000-0000-4000-8000-000000000001",
    "status": "active",
    "displayName": "Example VPS",
    "hostname": "server.example.com",
    "type": "vps",
    "createdAt": "2026-10-01T00:00:00.000Z",
    "dueDate": "2026-11-01T00:00:00.000Z",
    "billingUnit": "MONTH",
    "billingCount": 1,
    "sku": "4G",
    "ipv4": "192.0.2.10",
    "ipv6": null,
    "meta": {
      "serviceType": "vps"
    }
  }
}

API reference and code examples

PATCH/v1/services/{serviceId}/autopayToggle wallet autopay

Operation ID: serviceAutopay

Enables or disables autopay for a supported service so future renewal invoices can be handled automatically when policy allows it.

Required scopes: billing.services.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "enabled": {
      "type": "boolean"
    }
  },
  "required": [
    "enabled"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "serviceId": {
      "type": "string"
    },
    "autopayEnabled": {
      "type": "boolean"
    }
  },
  "required": [
    "ok",
    "serviceId",
    "autopayEnabled"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "serviceId": "00000000-0000-4000-8000-000000000001",
  "autopayEnabled": true
}

API reference and code examples

POST/v1/services/{serviceId}/billing/change/checkoutStart billing-cycle change

Operation ID: serviceBillingChangeCheckout

Creates a prorated checkout when a customer changes the service billing cycle.

Required scopes: billing.services.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "unit": {
      "type": "string",
      "minLength": 1
    },
    "count": {
      "type": "integer",
      "minimum": 1
    }
  },
  "required": [
    "unit",
    "count"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "orderId": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "invoiceId": {
      "type": "string"
    },
    "invoiceNumber": {
      "type": "string"
    },
    "invoice": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "number": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "total": {
          "type": "string"
        },
        "paidTotal": {
          "type": "string"
        },
        "currency": {
          "type": "string"
        },
        "createdAt": {
          "type": "string"
        },
        "dueDate": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "payDate": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "refundedTotal": {
          "type": "string"
        }
      },
      "required": [
        "id",
        "number",
        "status",
        "total",
        "paidTotal",
        "currency"
      ],
      "additionalProperties": true
    },
    "total": {
      "type": "string"
    },
    "currency": {
      "type": "string"
    },
    "status": {
      "type": "string"
    },
    "paymentStatus": {
      "type": "string"
    },
    "serviceIds": {
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "message": {
      "type": "string"
    },
    "deploymentStatusUrl": {
      "type": "string"
    },
    "applied": {
      "type": "boolean"
    },
    "payNow": {
      "type": "string"
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "applied": true,
  "payNow": "0.00",
  "currency": "EUR"
}

API reference and code examples

GET/v1/services/{serviceId}/billing/change/optionsReview billing-cycle options

Operation ID: serviceBillingChangeOptions

Returns the proration-aware billing-cycle change choices for a service before checkout.

Required scopes: billing.services.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "currency": {
      "type": "string"
    },
    "current": {
      "type": "object",
      "properties": {
        "unit": {
          "type": "string"
        },
        "count": {
          "type": "number"
        },
        "price": {
          "type": "string"
        },
        "recurringUnitPrice": {
          "type": "string"
        },
        "variantId": {
          "type": "string"
        },
        "sku": {
          "type": "string"
        },
        "dims": {
          "type": "object",
          "properties": {
            "cpu": {
              "type": "number"
            },
            "ram": {
              "type": "number"
            },
            "disk": {
              "type": "number"
            }
          },
          "required": [
            "cpu",
            "ram",
            "disk"
          ],
          "additionalProperties": true
        }
      },
      "additionalProperties": true
    },
    "options": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "unit": {
            "type": "string"
          },
          "count": {
            "type": "number"
          },
          "price": {
            "type": "string"
          },
          "targetRecurringUnitPrice": {
            "type": "string"
          },
          "credit": {
            "type": "string"
          },
          "payNow": {
            "type": "string"
          },
          "variantId": {
            "type": "string"
          },
          "sku": {
            "type": "string"
          }
        },
        "additionalProperties": true
      }
    },
    "billing": {
      "type": "object",
      "properties": {
        "unit": {
          "type": "string"
        },
        "count": {
          "type": "number"
        }
      },
      "required": [
        "unit",
        "count"
      ],
      "additionalProperties": true
    },
    "proration": {
      "type": "object",
      "properties": {
        "fraction": {
          "type": "number"
        },
        "multiplier": {
          "type": "number"
        },
        "periodStart": {
          "type": "string"
        },
        "periodEnd": {
          "type": "string"
        }
      },
      "additionalProperties": true
    },
    "extraDiskGB": {
      "type": "number"
    },
    "keepExtraDisk": {
      "type": "boolean"
    },
    "service": {
      "type": "object",
      "properties": {
        "category": {
          "type": "string"
        },
        "isCpanel": {
          "type": "boolean"
        }
      },
      "additionalProperties": true
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "currency": "EUR",
  "current": {
    "unit": "MONTH",
    "count": 1,
    "value": "MONTH:1",
    "label": "Monthly",
    "recurringUnitPrice": "100.00"
  },
  "proration": {
    "fraction": 1,
    "periodStart": "2026-10-01T00:00:00.000Z",
    "periodEnd": "2026-11-01T00:00:00.000Z"
  },
  "options": [
    {
      "unit": "MONTH",
      "count": 1,
      "value": "MONTH:1",
      "label": "Monthly",
      "targetRecurringUnitPrice": "100.00",
      "credit": "100.00",
      "payNow": "0.00"
    }
  ]
}

API reference and code examples

GET/v1/services/{serviceId}/billing/optionsReview billing options

Operation ID: serviceBillingOptions

Returns the current billing-cycle choices exposed for the selected service.

Required scopes: billing.services.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "currency": {
      "type": "string"
    },
    "current": {
      "type": "object",
      "properties": {
        "unit": {
          "type": "string"
        },
        "count": {
          "type": "number"
        },
        "price": {
          "type": "string"
        },
        "recurringUnitPrice": {
          "type": "string"
        },
        "variantId": {
          "type": "string"
        },
        "sku": {
          "type": "string"
        },
        "dims": {
          "type": "object",
          "properties": {
            "cpu": {
              "type": "number"
            },
            "ram": {
              "type": "number"
            },
            "disk": {
              "type": "number"
            }
          },
          "required": [
            "cpu",
            "ram",
            "disk"
          ],
          "additionalProperties": true
        }
      },
      "additionalProperties": true
    },
    "options": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "unit": {
            "type": "string"
          },
          "count": {
            "type": "number"
          },
          "price": {
            "type": "string"
          },
          "targetRecurringUnitPrice": {
            "type": "string"
          },
          "credit": {
            "type": "string"
          },
          "payNow": {
            "type": "string"
          },
          "variantId": {
            "type": "string"
          },
          "sku": {
            "type": "string"
          }
        },
        "additionalProperties": true
      }
    },
    "billing": {
      "type": "object",
      "properties": {
        "unit": {
          "type": "string"
        },
        "count": {
          "type": "number"
        }
      },
      "required": [
        "unit",
        "count"
      ],
      "additionalProperties": true
    },
    "proration": {
      "type": "object",
      "properties": {
        "fraction": {
          "type": "number"
        },
        "multiplier": {
          "type": "number"
        },
        "periodStart": {
          "type": "string"
        },
        "periodEnd": {
          "type": "string"
        }
      },
      "additionalProperties": true
    },
    "extraDiskGB": {
      "type": "number"
    },
    "keepExtraDisk": {
      "type": "boolean"
    },
    "service": {
      "type": "object",
      "properties": {
        "category": {
          "type": "string"
        },
        "isCpanel": {
          "type": "boolean"
        }
      },
      "additionalProperties": true
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "currency": "EUR",
  "current": {
    "unit": "MONTH",
    "count": 1,
    "value": "MONTH:1",
    "label": "Monthly"
  },
  "options": [
    {
      "unit": "MONTH",
      "count": 1,
      "value": "MONTH:1",
      "label": "Monthly",
      "price": "100.00"
    }
  ]
}

API reference and code examples

POST/v1/services/{serviceId}/cancelRequest service cancellation

Operation ID: serviceCancel

Convenience alias for service termination. Use this when the customer intent is straightforward cancellation.

Required scopes: billing.services.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • Idempotency-Key · header — Recommended stable retry key. CLI 0.1.17 makes the flag optional: an omitted key is generated once, saved locally before dispatch and printed for explicit retries. Reuse the same key and exact payload. With durable_writes enabled, the API retains the dispatch identity after its encrypted response expires in 24 hours. An unknown outcome requires inspecting service/operation state; never generate a new key to retry it. Missing keys keep legacy behavior.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true
}

API reference and code examples

GET/v1/services/{serviceId}/dns/waf/record/configRead Website Protection settings

Operation ID: getServiceDnsWafConfig

Read-only HTTPS/origin and custom-loader flags. Unknown settings are null; no raw provider configuration, private keys or scripts.

Required scopes: dns.read

Parameters

  • serviceId · path · required — Your DNS zone name (example.com) or an owned service UUID. A name selects the owned zone directly; a UUID also requires domain in the query/body.
  • domain · query — Owned DNS zone; required only with a UUID selector. Must match a domain-name selector when supplied.
  • name · query — A record name, e.g. @ or www.; default @.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "settings": {
      "type": "object",
      "properties": {
        "ssl_schema": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "force_ssl": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "ssl": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "custom_loader": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        }
      },
      "required": [
        "ssl_schema",
        "force_ssl",
        "ssl",
        "custom_loader"
      ],
      "additionalProperties": true
    },
    "domain": {
      "type": "string"
    },
    "name": {
      "type": "string"
    }
  },
  "required": [
    "ok",
    "settings"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "settings": {
    "ssl_schema": null,
    "force_ssl": null,
    "ssl": null,
    "custom_loader": null
  }
}

API reference and code examples

POST/v1/services/{serviceId}/renewalRenew and pay using the current billing cycle

Operation ID: serviceRenewal

Renews the existing plan and billing cycle from account balance in one call. Reuses an eligible unpaid renewal invoice or creates one; never pays a purchase, upgrade, changed-cycle or mixed-service invoice. Full payment only: insufficient credit or max_total violation rolls back new invoices and any debit. Idempotency-Key is required: reuse the same key and exact body after an interrupted response. The financial receipt is durable. Optional max_total caps the outstanding amount in invoice/account currency; it is not a supplied price. Domain renewals can return renewal_pending=true: paid_through remains the last confirmed date until provider processing completes. Manual suspensions are not cleared by this request.

Required scopes: billing.services.write + billing.invoice.pay

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • Idempotency-Key · header · required — Unique renewal attempt key, 8–128 letters, digits or . _ : -. Reuse it on retries; a new key authorizes another cycle.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · optional

{
  "type": "object",
  "properties": {
    "max_total": {
      "type": "string",
      "pattern": "^(0|[1-9]\\d{0,9})(\\.\\d{1,2})?$"
    }
  },
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "service_id": {
      "type": "string"
    },
    "invoice_id": {
      "type": "string"
    },
    "invoice_number": {
      "type": "string"
    },
    "status": {
      "type": "string"
    },
    "invoice_status": {
      "type": "string"
    },
    "paid_now": {
      "type": "string"
    },
    "currency": {
      "type": "string"
    },
    "billing": {
      "type": "object",
      "properties": {
        "unit": {
          "type": "string"
        },
        "count": {
          "type": "number"
        }
      },
      "required": [
        "unit",
        "count"
      ],
      "additionalProperties": true
    },
    "paid_through": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "renewal_pending": {
      "type": "boolean"
    }
  },
  "required": [
    "ok",
    "service_id",
    "invoice_id",
    "invoice_number",
    "status",
    "invoice_status",
    "paid_now",
    "currency",
    "billing",
    "paid_through",
    "renewal_pending"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "service_id": "00000000-0000-4000-8000-000000000001",
  "invoice_id": "00000000-0000-4000-8000-000000000002",
  "invoice_number": "INV-EXAMPLE-001",
  "status": "paid",
  "invoice_status": "paid",
  "paid_now": "10.00",
  "currency": "EUR",
  "billing": {
    "unit": "MONTH",
    "count": 1
  },
  "paid_through": "2026-11-01T00:00:00.000Z",
  "renewal_pending": false
}

API reference and code examples

POST/v1/services/{serviceId}/renewal/checkoutStart renewal checkout

Operation ID: serviceRenewalCheckout

Creates a renewal billing flow for the selected service and renewal period.

Required scopes: billing.services.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "unit": {
      "type": "string",
      "minLength": 1
    },
    "count": {
      "type": "integer",
      "minimum": 1
    }
  },
  "required": [
    "unit",
    "count"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "orderId": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "invoiceId": {
      "type": "string"
    },
    "invoiceNumber": {
      "type": "string"
    },
    "invoice": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "number": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "total": {
          "type": "string"
        },
        "paidTotal": {
          "type": "string"
        },
        "currency": {
          "type": "string"
        },
        "createdAt": {
          "type": "string"
        },
        "dueDate": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "payDate": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "refundedTotal": {
          "type": "string"
        }
      },
      "required": [
        "id",
        "number",
        "status",
        "total",
        "paidTotal",
        "currency"
      ],
      "additionalProperties": true
    },
    "total": {
      "type": "string"
    },
    "currency": {
      "type": "string"
    },
    "status": {
      "type": "string"
    },
    "paymentStatus": {
      "type": "string"
    },
    "serviceIds": {
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "message": {
      "type": "string"
    },
    "deploymentStatusUrl": {
      "type": "string"
    },
    "applied": {
      "type": "boolean"
    },
    "payNow": {
      "type": "string"
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "orderId": null,
  "invoiceId": "00000000-0000-4000-8000-000000000002",
  "invoiceNumber": "INV-EXAMPLE-000001",
  "total": "100.00",
  "currency": "EUR",
  "status": "unpaid"
}

API reference and code examples

GET/v1/services/{serviceId}/renewal/optionsReview renewal options

Operation ID: serviceRenewalOptions

Returns valid renewal units or counts for the target service before you create a renewal checkout.

Required scopes: billing.services.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "currency": {
      "type": "string"
    },
    "current": {
      "type": "object",
      "properties": {
        "unit": {
          "type": "string"
        },
        "count": {
          "type": "number"
        },
        "price": {
          "type": "string"
        },
        "recurringUnitPrice": {
          "type": "string"
        },
        "variantId": {
          "type": "string"
        },
        "sku": {
          "type": "string"
        },
        "dims": {
          "type": "object",
          "properties": {
            "cpu": {
              "type": "number"
            },
            "ram": {
              "type": "number"
            },
            "disk": {
              "type": "number"
            }
          },
          "required": [
            "cpu",
            "ram",
            "disk"
          ],
          "additionalProperties": true
        }
      },
      "additionalProperties": true
    },
    "options": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "unit": {
            "type": "string"
          },
          "count": {
            "type": "number"
          },
          "price": {
            "type": "string"
          },
          "targetRecurringUnitPrice": {
            "type": "string"
          },
          "credit": {
            "type": "string"
          },
          "payNow": {
            "type": "string"
          },
          "variantId": {
            "type": "string"
          },
          "sku": {
            "type": "string"
          }
        },
        "additionalProperties": true
      }
    },
    "billing": {
      "type": "object",
      "properties": {
        "unit": {
          "type": "string"
        },
        "count": {
          "type": "number"
        }
      },
      "required": [
        "unit",
        "count"
      ],
      "additionalProperties": true
    },
    "proration": {
      "type": "object",
      "properties": {
        "fraction": {
          "type": "number"
        },
        "multiplier": {
          "type": "number"
        },
        "periodStart": {
          "type": "string"
        },
        "periodEnd": {
          "type": "string"
        }
      },
      "additionalProperties": true
    },
    "extraDiskGB": {
      "type": "number"
    },
    "keepExtraDisk": {
      "type": "boolean"
    },
    "service": {
      "type": "object",
      "properties": {
        "category": {
          "type": "string"
        },
        "isCpanel": {
          "type": "boolean"
        }
      },
      "additionalProperties": true
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "currency": "EUR",
  "current": {
    "unit": "MONTH",
    "count": 1,
    "value": "MONTH:1",
    "label": "Monthly",
    "recurringUnitPrice": "100.00"
  },
  "options": [
    {
      "unit": "MONTH",
      "count": 1,
      "value": "MONTH:1",
      "label": "Monthly",
      "price": "100.00"
    }
  ]
}

API reference and code examples

POST/v1/services/{serviceId}/upgrade/checkoutStart upgrade checkout

Operation ID: serviceUpgradeCheckout

Creates or applies an upgrade flow for the selected service and variant.

Required scopes: billing.services.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "variant_id": {
      "type": "string",
      "format": "uuid"
    }
  },
  "required": [
    "variant_id"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "orderId": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "invoiceId": {
      "type": "string"
    },
    "invoiceNumber": {
      "type": "string"
    },
    "invoice": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "number": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "total": {
          "type": "string"
        },
        "paidTotal": {
          "type": "string"
        },
        "currency": {
          "type": "string"
        },
        "createdAt": {
          "type": "string"
        },
        "dueDate": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "payDate": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "refundedTotal": {
          "type": "string"
        }
      },
      "required": [
        "id",
        "number",
        "status",
        "total",
        "paidTotal",
        "currency"
      ],
      "additionalProperties": true
    },
    "total": {
      "type": "string"
    },
    "currency": {
      "type": "string"
    },
    "status": {
      "type": "string"
    },
    "paymentStatus": {
      "type": "string"
    },
    "serviceIds": {
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "message": {
      "type": "string"
    },
    "deploymentStatusUrl": {
      "type": "string"
    },
    "applied": {
      "type": "boolean"
    },
    "payNow": {
      "type": "string"
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "orderId": "00000000-0000-4000-8000-000000000001",
  "invoiceId": "00000000-0000-4000-8000-000000000002",
  "invoiceNumber": "INV-EXAMPLE-000001",
  "total": "100.00",
  "currency": "EUR",
  "status": "unpaid"
}

API reference and code examples

GET/v1/services/{serviceId}/upgrade/optionsReview upgrade options

Operation ID: serviceUpgradeOptions

Returns supported upgrade choices for the selected service.

Required scopes: billing.services.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "currency": {
      "type": "string"
    },
    "current": {
      "type": "object",
      "properties": {
        "unit": {
          "type": "string"
        },
        "count": {
          "type": "number"
        },
        "price": {
          "type": "string"
        },
        "recurringUnitPrice": {
          "type": "string"
        },
        "variantId": {
          "type": "string"
        },
        "sku": {
          "type": "string"
        },
        "dims": {
          "type": "object",
          "properties": {
            "cpu": {
              "type": "number"
            },
            "ram": {
              "type": "number"
            },
            "disk": {
              "type": "number"
            }
          },
          "required": [
            "cpu",
            "ram",
            "disk"
          ],
          "additionalProperties": true
        }
      },
      "additionalProperties": true
    },
    "options": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "unit": {
            "type": "string"
          },
          "count": {
            "type": "number"
          },
          "price": {
            "type": "string"
          },
          "targetRecurringUnitPrice": {
            "type": "string"
          },
          "credit": {
            "type": "string"
          },
          "payNow": {
            "type": "string"
          },
          "variantId": {
            "type": "string"
          },
          "sku": {
            "type": "string"
          }
        },
        "additionalProperties": true
      }
    },
    "billing": {
      "type": "object",
      "properties": {
        "unit": {
          "type": "string"
        },
        "count": {
          "type": "number"
        }
      },
      "required": [
        "unit",
        "count"
      ],
      "additionalProperties": true
    },
    "proration": {
      "type": "object",
      "properties": {
        "fraction": {
          "type": "number"
        },
        "multiplier": {
          "type": "number"
        },
        "periodStart": {
          "type": "string"
        },
        "periodEnd": {
          "type": "string"
        }
      },
      "additionalProperties": true
    },
    "extraDiskGB": {
      "type": "number"
    },
    "keepExtraDisk": {
      "type": "boolean"
    },
    "service": {
      "type": "object",
      "properties": {
        "category": {
          "type": "string"
        },
        "isCpanel": {
          "type": "boolean"
        }
      },
      "additionalProperties": true
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "extraDiskGB": 0,
  "keepExtraDisk": false,
  "service": {
    "category": "vps",
    "isCpanel": false
  },
  "current": {
    "variantId": "00000000-0000-4000-8000-000000000001",
    "sku": "4G",
    "dims": {
      "cpu": 2,
      "ram": 4,
      "disk": 40
    }
  },
  "currency": "EUR",
  "billing": {
    "unit": "MONTH",
    "count": 1
  },
  "proration": {
    "multiplier": 1,
    "fraction": 1,
    "periodStart": "2026-10-01T00:00:00.000Z",
    "periodEnd": "2026-11-01T00:00:00.000Z"
  },
  "options": []
}

API reference and code examples

GET/v1/services/groupedBrowse services by type

Operation ID: listServicesGrouped

Returns the complete filtered customer-safe inventory grouped by type, without pagination. Intended for dashboard inventory. This is a legacy compatibility endpoint. Its default is active only, retained for backward compatibility; automation and MCP clients should pass status explicitly and prefer /v1/services?statuses=active,suspended&group_by=type for relevant lifecycle states. status=suspended or status=all explicitly includes other states. This differs from GET /v1/services?group_by=type, which groups only its current paginated result set. This endpoint supports status and type filters; use /v1/services for search and integration-metadata filters.

Required scopes: billing.services.read

Parameters

  • status · query — Legacy default active; pass this explicitly. Filter by service status. Use all to disable status filtering.
  • type · query — Optional comma-separated list of service types to keep in the grouped response.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "status": {
      "type": "string"
    },
    "type": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "services": {
      "type": "object",
      "additionalProperties": {
        "type": "array",
        "items": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "status": {
              "type": "string"
            },
            "hostname": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "displayName": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "region": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "sku": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "productName": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "ipv4": {
              "anyOf": [
                {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                {
                  "type": "array",
                  "items": {
                    "type": "string"
                  }
                }
              ]
            },
            "ipv6": {
              "anyOf": [
                {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                {
                  "type": "array",
                  "items": {
                    "type": "string"
                  }
                }
              ]
            },
            "dueDate": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "createdAt": {
              "type": "string"
            },
            "power": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        }
      }
    }
  },
  "required": [
    "ok",
    "status",
    "type",
    "services"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "status": "active",
  "type": null,
  "services": {
    "dns": [],
    "vps": [],
    "dedicated": [],
    "webhosting": []
  }
}

API reference and code examples

VPS

GET/v1/vps/{serviceId}/actions/{actionId}Check action status

Operation ID: vpsActionStatus

Polls the current state of a long-running VPS action such as power, backup, or reinstall work.

Required scopes: vps.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • actionId · path · required — Action UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "action": {
      "anyOf": [
        {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "type": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "phase": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "status": {
              "type": "string"
            },
            "done": {
              "type": "boolean"
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        },
        {
          "type": "null"
        }
      ]
    }
  },
  "required": [
    "ok",
    "action"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "action": {
    "id": "00000000-0000-4000-8000-000000000002",
    "type": "start",
    "phase": "completed",
    "createdAt": "2026-10-01T00:00:00.000Z",
    "updatedAt": "2026-10-01T00:00:00.000Z"
  }
}

API reference and code examples

DELETE/v1/vps/{serviceId}/backupDelete backup files

Operation ID: vpsBackupDelete

Deletes the current backup record or configured backup object for the VPS.

Required scopes: vps.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "deleted": {
      "type": "number"
    }
  },
  "required": [
    "ok",
    "deleted"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "deleted": 1
}

API reference and code examples

GET/v1/vps/{serviceId}/backupCheck backup status

Operation ID: getVpsBackup

Returns current backup information for the VPS.

Required scopes: vps.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "storageId": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "usedBytes": {
      "type": "number"
    },
    "backupCount": {
      "type": "number"
    },
    "poolUsedBytes": {
      "type": "number"
    },
    "poolBackupCount": {
      "type": "number"
    },
    "quota": {
      "type": "object",
      "properties": {
        "freeGiB": {
          "type": "number"
        },
        "purchasedGiB": {
          "type": "number"
        },
        "limitBytes": {
          "type": "number"
        },
        "freeBytes": {
          "type": "number"
        }
      },
      "required": [
        "freeGiB",
        "purchasedGiB",
        "limitBytes",
        "freeBytes"
      ],
      "additionalProperties": true
    },
    "files": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "volid": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "size": {
            "type": "number"
          },
          "ctime": {
            "type": "number"
          },
          "format": {
            "type": "string"
          }
        },
        "additionalProperties": true
      }
    },
    "backup": {
      "$ref": "#/$defs/JsonValue"
    },
    "os": {
      "anyOf": [
        {
          "type": "object",
          "properties": {
            "id": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "number"
                }
              ]
            },
            "code": {
              "type": "string"
            },
            "name": {
              "type": "string"
            },
            "family": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "version": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "arch": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "isDefault": {
              "type": "boolean"
            },
            "allowSshKeys": {
              "type": "boolean"
            }
          },
          "additionalProperties": true
        },
        {
          "type": "null"
        }
      ]
    }
  },
  "required": [
    "ok",
    "storageId",
    "usedBytes",
    "backupCount",
    "poolUsedBytes",
    "poolBackupCount",
    "quota",
    "files",
    "backup",
    "os"
  ],
  "additionalProperties": true,
  "$defs": {
    "JsonValue": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "number"
        },
        {
          "type": "boolean"
        },
        {
          "type": "null"
        },
        {
          "type": "array",
          "items": {
            "$ref": "#/$defs/JsonValue"
          }
        },
        {
          "type": "object",
          "additionalProperties": {
            "$ref": "#/$defs/JsonValue"
          }
        }
      ]
    }
  }
}

Illustrative successful response

{
  "ok": true,
  "storageId": "example-backup-storage",
  "usedBytes": 0,
  "backupCount": 0,
  "poolUsedBytes": 0,
  "poolBackupCount": 0,
  "quota": {
    "freeGiB": 10,
    "purchasedGiB": 0,
    "limitBytes": 10737418240,
    "freeBytes": 10737418240
  },
  "files": [],
  "backup": null,
  "os": null
}

API reference and code examples

POST/v1/vps/{serviceId}/backup/cancelCancel backup run

Operation ID: vpsBackupCancel

Requests cancellation of an active backup job.

Required scopes: vps.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "cancelled": {
      "type": "boolean"
    }
  },
  "required": [
    "ok",
    "cancelled"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "cancelled": true
}

API reference and code examples

GET/v1/vps/{serviceId}/backup/progressCheck backup progress

Operation ID: vpsBackupProgress

Returns current progress for an active backup job.

Required scopes: vps.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "running": {
      "type": "boolean"
    },
    "done": {
      "type": "boolean"
    },
    "progress": {
      "anyOf": [
        {
          "type": "number"
        },
        {
          "type": "null"
        }
      ]
    },
    "phase": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "stage": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "status": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "action": {
      "anyOf": [
        {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "type": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "phase": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "status": {
              "type": "string"
            },
            "done": {
              "type": "boolean"
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        },
        {
          "type": "null"
        }
      ]
    },
    "actionId": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "target": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "error": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "inProgress": false,
  "actionId": null,
  "lastRequestedAt": null,
  "lastResult": null
}

API reference and code examples

POST/v1/vps/{serviceId}/backup/restoreStart backup restore

Operation ID: vpsBackupRestore

Starts a restore from the current or selected VPS backup artifact.

Required scopes: vps.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-bf-response-format · header — Opt into the canonical Operation receipt for this tracked write. Requires canonical_operation_responses enabled. Omit for the legacy response. Retried requests may replay their initial response format; use its operation_id or operation.id to poll.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "auto_start": {
      "type": "boolean"
    },
    "file": {
      "anyOf": [
        {
          "type": "string",
          "minLength": 1,
          "maxLength": 255
        },
        {
          "type": "null"
        }
      ]
    }
  },
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "anyOf": [
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "actionId": {
          "type": "string"
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "type": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "phase": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "status": {
              "type": "string"
            },
            "done": {
              "type": "boolean"
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        },
        "operation_id": {
          "type": "string"
        },
        "operation_url": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "phase": {
          "type": "string"
        },
        "already": {
          "type": "boolean"
        },
        "queued": {
          "type": "boolean"
        },
        "task": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "status": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "error": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            },
            "finishedAt": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        }
      },
      "required": [
        "ok"
      ],
      "additionalProperties": true
    },
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string",
              "enum": [
                "deployment",
                "vps",
                "dedicated"
              ]
            },
            "action": {
              "type": "string"
            },
            "status": {
              "type": "string",
              "enum": [
                "pending",
                "running",
                "succeeded",
                "failed",
                "cancelled",
                "unknown"
              ]
            },
            "done": {
              "type": "boolean"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number",
                  "minimum": 0,
                  "maximum": 100
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "created_at": {
              "type": "string",
              "format": "date-time"
            },
            "updated_at": {
              "anyOf": [
                {
                  "type": "string",
                  "format": "date-time"
                },
                {
                  "type": "null"
                }
              ]
            },
            "service_ids": {
              "type": "array",
              "items": {
                "type": "string",
                "format": "uuid"
              }
            },
            "error": {
              "anyOf": [
                {
                  "type": "object",
                  "properties": {
                    "code": {
                      "type": "string"
                    },
                    "message": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "code",
                    "message"
                  ],
                  "additionalProperties": false
                },
                {
                  "type": "null"
                }
              ]
            },
            "result": {
              "anyOf": [
                {
                  "anyOf": [
                    {
                      "type": "object",
                      "properties": {
                        "service_ids": {
                          "type": "array",
                          "items": {
                            "type": "string",
                            "format": "uuid"
                          },
                          "minItems": 1,
                          "maxItems": 50
                        },
                        "order_id": {
                          "anyOf": [
                            {
                              "type": "string",
                              "format": "uuid"
                            },
                            {
                              "type": "null"
                            }
                          ]
                        },
                        "invoice_id": {
                          "type": "string",
                          "format": "uuid"
                        }
                      },
                      "required": [
                        "service_ids"
                      ],
                      "additionalProperties": false
                    },
                    {
                      "type": "object",
                      "properties": {
                        "service_id": {
                          "type": "string",
                          "format": "uuid"
                        },
                        "os": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "snapshot_name": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "power_state": {
                          "type": "string",
                          "enum": [
                            "running",
                            "stopped"
                          ]
                        }
                      },
                      "required": [
                        "service_id"
                      ],
                      "additionalProperties": false
                    }
                  ]
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id",
            "kind",
            "action",
            "status",
            "done",
            "progress",
            "stage",
            "created_at",
            "updated_at",
            "service_ids",
            "error"
          ],
          "additionalProperties": false
        },
        "links": {
          "type": "object",
          "properties": {
            "operation": {
              "type": "string",
              "pattern": "^\\/v1\\/operations\\/op_[A-Za-z0-9_-]+$"
            },
            "service": {
              "type": "string",
              "pattern": "^\\/v1\\/services\\/[0-9a-f-]{36}$"
            },
            "invoice": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/invoices\\/[0-9a-f-]{36}$"
            },
            "order": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/orders\\/[0-9a-f-]{36}$"
            }
          },
          "required": [
            "operation"
          ],
          "additionalProperties": false
        }
      },
      "required": [
        "ok",
        "operation"
      ],
      "additionalProperties": false
    }
  ],
  "description": "Legacy response by default; x-bf-response-format: operation opts into the canonical receipt when durable operations are enabled. Retries retain the initial cached response format."
}

Illustrative successful response

{
  "ok": true,
  "actionId": "00000000-0000-4000-8000-000000000002"
}

API reference and code examples

GET/v1/vps/{serviceId}/backup/restore/progressCheck restore progress

Operation ID: vpsBackupRestoreProgress

Returns progress for an active backup restore.

Required scopes: vps.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "running": {
      "type": "boolean"
    },
    "done": {
      "type": "boolean"
    },
    "progress": {
      "anyOf": [
        {
          "type": "number"
        },
        {
          "type": "null"
        }
      ]
    },
    "phase": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "stage": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "status": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "action": {
      "anyOf": [
        {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "type": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "phase": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "status": {
              "type": "string"
            },
            "done": {
              "type": "boolean"
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        },
        {
          "type": "null"
        }
      ]
    },
    "actionId": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "target": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "error": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "inProgress": false,
  "actionId": null,
  "lastRequestedAt": null,
  "lastResult": null
}

API reference and code examples

POST/v1/vps/{serviceId}/backup/runStart backup

Operation ID: vpsBackupRun

Starts an on-demand backup for the selected VPS.

Required scopes: vps.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-bf-response-format · header — Opt into the canonical Operation receipt for this tracked write. Requires canonical_operation_responses enabled. Omit for the legacy response. Retried requests may replay their initial response format; use its operation_id or operation.id to poll.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "anyOf": [
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "actionId": {
          "type": "string"
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "type": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "phase": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "status": {
              "type": "string"
            },
            "done": {
              "type": "boolean"
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        },
        "operation_id": {
          "type": "string"
        },
        "operation_url": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "phase": {
          "type": "string"
        },
        "already": {
          "type": "boolean"
        },
        "queued": {
          "type": "boolean"
        },
        "task": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "status": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "error": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            },
            "finishedAt": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        }
      },
      "required": [
        "ok"
      ],
      "additionalProperties": true
    },
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string",
              "enum": [
                "deployment",
                "vps",
                "dedicated"
              ]
            },
            "action": {
              "type": "string"
            },
            "status": {
              "type": "string",
              "enum": [
                "pending",
                "running",
                "succeeded",
                "failed",
                "cancelled",
                "unknown"
              ]
            },
            "done": {
              "type": "boolean"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number",
                  "minimum": 0,
                  "maximum": 100
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "created_at": {
              "type": "string",
              "format": "date-time"
            },
            "updated_at": {
              "anyOf": [
                {
                  "type": "string",
                  "format": "date-time"
                },
                {
                  "type": "null"
                }
              ]
            },
            "service_ids": {
              "type": "array",
              "items": {
                "type": "string",
                "format": "uuid"
              }
            },
            "error": {
              "anyOf": [
                {
                  "type": "object",
                  "properties": {
                    "code": {
                      "type": "string"
                    },
                    "message": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "code",
                    "message"
                  ],
                  "additionalProperties": false
                },
                {
                  "type": "null"
                }
              ]
            },
            "result": {
              "anyOf": [
                {
                  "anyOf": [
                    {
                      "type": "object",
                      "properties": {
                        "service_ids": {
                          "type": "array",
                          "items": {
                            "type": "string",
                            "format": "uuid"
                          },
                          "minItems": 1,
                          "maxItems": 50
                        },
                        "order_id": {
                          "anyOf": [
                            {
                              "type": "string",
                              "format": "uuid"
                            },
                            {
                              "type": "null"
                            }
                          ]
                        },
                        "invoice_id": {
                          "type": "string",
                          "format": "uuid"
                        }
                      },
                      "required": [
                        "service_ids"
                      ],
                      "additionalProperties": false
                    },
                    {
                      "type": "object",
                      "properties": {
                        "service_id": {
                          "type": "string",
                          "format": "uuid"
                        },
                        "os": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "snapshot_name": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "power_state": {
                          "type": "string",
                          "enum": [
                            "running",
                            "stopped"
                          ]
                        }
                      },
                      "required": [
                        "service_id"
                      ],
                      "additionalProperties": false
                    }
                  ]
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id",
            "kind",
            "action",
            "status",
            "done",
            "progress",
            "stage",
            "created_at",
            "updated_at",
            "service_ids",
            "error"
          ],
          "additionalProperties": false
        },
        "links": {
          "type": "object",
          "properties": {
            "operation": {
              "type": "string",
              "pattern": "^\\/v1\\/operations\\/op_[A-Za-z0-9_-]+$"
            },
            "service": {
              "type": "string",
              "pattern": "^\\/v1\\/services\\/[0-9a-f-]{36}$"
            },
            "invoice": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/invoices\\/[0-9a-f-]{36}$"
            },
            "order": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/orders\\/[0-9a-f-]{36}$"
            }
          },
          "required": [
            "operation"
          ],
          "additionalProperties": false
        }
      },
      "required": [
        "ok",
        "operation"
      ],
      "additionalProperties": false
    }
  ],
  "description": "Legacy response by default; x-bf-response-format: operation opts into the canonical receipt when durable operations are enabled. Retries retain the initial cached response format."
}

Illustrative successful response

{
  "ok": true,
  "actionId": "00000000-0000-4000-8000-000000000002"
}

API reference and code examples

GET/v1/vps/{serviceId}/backup/scheduleView backup schedule

Operation ID: getVpsBackupSchedule

Returns current backup schedule settings for the VPS.

Required scopes: vps.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "schedule": {
      "type": "object",
      "properties": {
        "enabled": {
          "type": "boolean"
        },
        "cadence": {
          "type": "string"
        },
        "atHour": {
          "type": "number"
        },
        "atMinute": {
          "type": "number"
        },
        "dayOfWeek": {
          "type": "number"
        },
        "timezone": {
          "type": "string"
        }
      },
      "required": [
        "enabled"
      ],
      "additionalProperties": true
    }
  },
  "required": [
    "ok",
    "schedule"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "schedule": {
    "enabled": false
  }
}

API reference and code examples

PUT/v1/vps/{serviceId}/backup/scheduleChange backup schedule

Operation ID: vpsBackupSchedulePut

Creates or updates the backup schedule for the VPS.

Required scopes: vps.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "enabled": {
      "type": "boolean"
    },
    "cadence": {
      "type": "string",
      "enum": [
        "daily",
        "weekly"
      ]
    },
    "at_hour": {
      "type": "integer",
      "minimum": 0,
      "maximum": 23
    },
    "at_minute": {
      "type": "integer",
      "minimum": 0,
      "maximum": 59
    },
    "day_of_week": {
      "type": "integer",
      "minimum": 0,
      "maximum": 6
    }
  },
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "schedule": {
      "type": "object",
      "properties": {
        "enabled": {
          "type": "boolean"
        },
        "cadence": {
          "type": "string"
        },
        "atHour": {
          "type": "number"
        },
        "atMinute": {
          "type": "number"
        },
        "dayOfWeek": {
          "type": "number"
        },
        "timezone": {
          "type": "string"
        }
      },
      "required": [
        "enabled"
      ],
      "additionalProperties": true
    }
  },
  "required": [
    "ok",
    "schedule"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "schedule": {
    "enabled": false
  }
}

API reference and code examples

GET/v1/vps/{serviceId}/consoleOpen browser console

Operation ID: vpsConsole

Returns an authenticated portal console URL, not a raw VNC connection or provider ticket. Browser login and service access are checked before connecting.

Required scopes: vps.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "serviceId": {
      "type": "string"
    },
    "consoleUrl": {
      "type": "string"
    },
    "requiresBrowserLogin": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "transport": {
      "type": "string",
      "const": "browser",
      "enum": [
        "browser"
      ]
    }
  },
  "required": [
    "ok",
    "serviceId",
    "consoleUrl",
    "requiresBrowserLogin",
    "transport"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "serviceId": "00000000-0000-4000-8000-000000000001",
  "consoleUrl": "https://my.blazingfast.io/manage/vps/00000000-0000-4000-8000-000000000001/vnc",
  "requiresBrowserLogin": true,
  "transport": "browser"
}

API reference and code examples

GET/v1/vps/{serviceId}/credentialsReveal recorded VPS credentialsSensitive

Operation ID: vpsCredentials

Explicit, audited, no-store password retrieval. The platform-recorded root password may differ if changed inside the guest. Never log output or send it to a hosted AI conversation.

Required scopes: vps.credentials.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "serviceId": {
      "type": "string"
    },
    "hostname": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "ipv4": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "ipv6": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "rootPassword": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "credentialSource": {
      "type": "string"
    },
    "guestVerified": {
      "type": "boolean"
    }
  },
  "required": [
    "ok",
    "serviceId",
    "hostname",
    "ipv4",
    "ipv6",
    "rootPassword",
    "credentialSource",
    "guestVerified"
  ],
  "additionalProperties": true
}

API reference and code examples

POST/v1/vps/{serviceId}/password/resetReset root password

Operation ID: vpsPasswordReset

Generates and applies a new root password, then returns it once to the caller.

Required scopes: vps.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • Idempotency-Key · header — Recommended stable retry key. CLI 0.1.17 makes the flag optional: an omitted key is generated once, saved locally before dispatch and printed for explicit retries. Reuse the same key and exact payload. With durable_writes enabled, the API retains the dispatch identity after its encrypted response expires in 24 hours. An unknown outcome requires inspecting service/operation state; never generate a new key to retry it. Missing keys keep legacy behavior.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-bf-response-format · header — Opt into the canonical Operation receipt for this tracked write. Requires canonical_operation_responses enabled. Omit for the legacy response. Retried requests may replay their initial response format; use its operation_id or operation.id to poll.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "anyOf": [
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "newPassword": {
          "type": "string"
        },
        "credentialSynced": {
          "type": "boolean"
        },
        "actionId": {
          "type": "string"
        },
        "operation_id": {
          "type": "string"
        },
        "operation_url": {
          "type": "string"
        }
      },
      "required": [
        "ok",
        "newPassword",
        "credentialSynced"
      ],
      "additionalProperties": true
    },
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string",
              "enum": [
                "deployment",
                "vps",
                "dedicated"
              ]
            },
            "action": {
              "type": "string"
            },
            "status": {
              "type": "string",
              "enum": [
                "pending",
                "running",
                "succeeded",
                "failed",
                "cancelled",
                "unknown"
              ]
            },
            "done": {
              "type": "boolean"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number",
                  "minimum": 0,
                  "maximum": 100
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "created_at": {
              "type": "string",
              "format": "date-time"
            },
            "updated_at": {
              "anyOf": [
                {
                  "type": "string",
                  "format": "date-time"
                },
                {
                  "type": "null"
                }
              ]
            },
            "service_ids": {
              "type": "array",
              "items": {
                "type": "string",
                "format": "uuid"
              }
            },
            "error": {
              "anyOf": [
                {
                  "type": "object",
                  "properties": {
                    "code": {
                      "type": "string"
                    },
                    "message": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "code",
                    "message"
                  ],
                  "additionalProperties": false
                },
                {
                  "type": "null"
                }
              ]
            },
            "result": {
              "anyOf": [
                {
                  "anyOf": [
                    {
                      "type": "object",
                      "properties": {
                        "service_ids": {
                          "type": "array",
                          "items": {
                            "type": "string",
                            "format": "uuid"
                          },
                          "minItems": 1,
                          "maxItems": 50
                        },
                        "order_id": {
                          "anyOf": [
                            {
                              "type": "string",
                              "format": "uuid"
                            },
                            {
                              "type": "null"
                            }
                          ]
                        },
                        "invoice_id": {
                          "type": "string",
                          "format": "uuid"
                        }
                      },
                      "required": [
                        "service_ids"
                      ],
                      "additionalProperties": false
                    },
                    {
                      "type": "object",
                      "properties": {
                        "service_id": {
                          "type": "string",
                          "format": "uuid"
                        },
                        "os": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "snapshot_name": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "power_state": {
                          "type": "string",
                          "enum": [
                            "running",
                            "stopped"
                          ]
                        }
                      },
                      "required": [
                        "service_id"
                      ],
                      "additionalProperties": false
                    }
                  ]
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id",
            "kind",
            "action",
            "status",
            "done",
            "progress",
            "stage",
            "created_at",
            "updated_at",
            "service_ids",
            "error"
          ],
          "additionalProperties": false
        },
        "links": {
          "type": "object",
          "properties": {
            "operation": {
              "type": "string",
              "pattern": "^\\/v1\\/operations\\/op_[A-Za-z0-9_-]+$"
            },
            "service": {
              "type": "string",
              "pattern": "^\\/v1\\/services\\/[0-9a-f-]{36}$"
            },
            "invoice": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/invoices\\/[0-9a-f-]{36}$"
            },
            "order": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/orders\\/[0-9a-f-]{36}$"
            }
          },
          "required": [
            "operation"
          ],
          "additionalProperties": false
        }
      },
      "required": [
        "ok",
        "operation"
      ],
      "additionalProperties": false
    }
  ],
  "description": "Legacy response by default; x-bf-response-format: operation opts into the canonical receipt when durable operations are enabled. Retries retain the initial cached response format."
}

Illustrative successful response

{
  "ok": true,
  "newPassword": "<generated-password>",
  "credentialSynced": true
}

API reference and code examples

POST/v1/vps/{serviceId}/rebootReboot server

Operation ID: rebootVps

Triggers a reboot action for the selected VPS.

Required scopes: vps.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • Idempotency-Key · header — Recommended stable retry key. CLI 0.1.17 makes the flag optional: an omitted key is generated once, saved locally before dispatch and printed for explicit retries. Reuse the same key and exact payload. With durable_writes enabled, the API retains the dispatch identity after its encrypted response expires in 24 hours. An unknown outcome requires inspecting service/operation state; never generate a new key to retry it. Missing keys keep legacy behavior.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-bf-response-format · header — Opt into the canonical Operation receipt for this tracked write. Requires canonical_operation_responses enabled. Omit for the legacy response. Retried requests may replay their initial response format; use its operation_id or operation.id to poll.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "anyOf": [
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "actionId": {
          "type": "string"
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "type": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "phase": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "status": {
              "type": "string"
            },
            "done": {
              "type": "boolean"
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        },
        "operation_id": {
          "type": "string"
        },
        "operation_url": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "phase": {
          "type": "string"
        },
        "already": {
          "type": "boolean"
        },
        "queued": {
          "type": "boolean"
        },
        "task": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "status": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "error": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            },
            "finishedAt": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        }
      },
      "required": [
        "ok"
      ],
      "additionalProperties": true
    },
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string",
              "enum": [
                "deployment",
                "vps",
                "dedicated"
              ]
            },
            "action": {
              "type": "string"
            },
            "status": {
              "type": "string",
              "enum": [
                "pending",
                "running",
                "succeeded",
                "failed",
                "cancelled",
                "unknown"
              ]
            },
            "done": {
              "type": "boolean"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number",
                  "minimum": 0,
                  "maximum": 100
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "created_at": {
              "type": "string",
              "format": "date-time"
            },
            "updated_at": {
              "anyOf": [
                {
                  "type": "string",
                  "format": "date-time"
                },
                {
                  "type": "null"
                }
              ]
            },
            "service_ids": {
              "type": "array",
              "items": {
                "type": "string",
                "format": "uuid"
              }
            },
            "error": {
              "anyOf": [
                {
                  "type": "object",
                  "properties": {
                    "code": {
                      "type": "string"
                    },
                    "message": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "code",
                    "message"
                  ],
                  "additionalProperties": false
                },
                {
                  "type": "null"
                }
              ]
            },
            "result": {
              "anyOf": [
                {
                  "anyOf": [
                    {
                      "type": "object",
                      "properties": {
                        "service_ids": {
                          "type": "array",
                          "items": {
                            "type": "string",
                            "format": "uuid"
                          },
                          "minItems": 1,
                          "maxItems": 50
                        },
                        "order_id": {
                          "anyOf": [
                            {
                              "type": "string",
                              "format": "uuid"
                            },
                            {
                              "type": "null"
                            }
                          ]
                        },
                        "invoice_id": {
                          "type": "string",
                          "format": "uuid"
                        }
                      },
                      "required": [
                        "service_ids"
                      ],
                      "additionalProperties": false
                    },
                    {
                      "type": "object",
                      "properties": {
                        "service_id": {
                          "type": "string",
                          "format": "uuid"
                        },
                        "os": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "snapshot_name": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "power_state": {
                          "type": "string",
                          "enum": [
                            "running",
                            "stopped"
                          ]
                        }
                      },
                      "required": [
                        "service_id"
                      ],
                      "additionalProperties": false
                    }
                  ]
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id",
            "kind",
            "action",
            "status",
            "done",
            "progress",
            "stage",
            "created_at",
            "updated_at",
            "service_ids",
            "error"
          ],
          "additionalProperties": false
        },
        "links": {
          "type": "object",
          "properties": {
            "operation": {
              "type": "string",
              "pattern": "^\\/v1\\/operations\\/op_[A-Za-z0-9_-]+$"
            },
            "service": {
              "type": "string",
              "pattern": "^\\/v1\\/services\\/[0-9a-f-]{36}$"
            },
            "invoice": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/invoices\\/[0-9a-f-]{36}$"
            },
            "order": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/orders\\/[0-9a-f-]{36}$"
            }
          },
          "required": [
            "operation"
          ],
          "additionalProperties": false
        }
      },
      "required": [
        "ok",
        "operation"
      ],
      "additionalProperties": false
    }
  ],
  "description": "Legacy response by default; x-bf-response-format: operation opts into the canonical receipt when durable operations are enabled. Retries retain the initial cached response format."
}

Illustrative successful response

{
  "ok": true,
  "actionId": "00000000-0000-4000-8000-000000000002",
  "operation_id": "op_EXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLE",
  "operation_url": "/v1/operations/op_EXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLE"
}

API reference and code examples

POST/v1/vps/{serviceId}/reinstallStart reinstall

Operation ID: vpsReinstall

Queues a durable reinstall and returns HTTP 202 with an action ID and operation URL. Poll the operation URL until completion, then read VPS credentials separately with vps.credentials.read. Acceptance does not mean the guest is ready.

Required scopes: vps.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • Idempotency-Key · header — Recommended stable retry key. CLI 0.1.17 makes the flag optional: an omitted key is generated once, saved locally before dispatch and printed for explicit retries. Reuse the same key and exact payload. With durable_writes enabled, the API retains the dispatch identity after its encrypted response expires in 24 hours. An unknown outcome requires inspecting service/operation state; never generate a new key to retry it. Missing keys keep legacy behavior.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-bf-response-format · header — Opt into the canonical Operation receipt for this tracked write. Requires canonical_operation_responses enabled. Omit for the legacy response. Retried requests may replay their initial response format; use its operation_id or operation.id to poll.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "os_code": {
      "type": "string",
      "minLength": 1
    },
    "hostname": {
      "type": "string",
      "minLength": 1,
      "maxLength": 255
    },
    "ssh_key_id": {
      "anyOf": [
        {
          "type": "string",
          "format": "uuid"
        },
        {
          "type": "null"
        }
      ]
    },
    "ssh_public_key": {
      "anyOf": [
        {
          "type": "string",
          "minLength": 1
        },
        {
          "type": "null"
        }
      ]
    },
    "firewall_policy_id": {
      "anyOf": [
        {
          "type": "string",
          "minLength": 1,
          "maxLength": 128
        },
        {
          "type": "string",
          "const": "__DEFAULT__",
          "enum": [
            "__DEFAULT__"
          ]
        },
        {
          "type": "null"
        }
      ]
    },
    "os_name": {
      "type": "string",
      "minLength": 1
    },
    "os_version": {
      "type": "string",
      "minLength": 1
    },
    "os_arch": {
      "type": "string",
      "minLength": 1
    }
  },
  "required": [
    "os_code"
  ],
  "additionalProperties": false
}

Successful response · HTTP 202

{
  "anyOf": [
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "actionId": {
          "type": "string"
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "type": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "phase": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "status": {
              "type": "string"
            },
            "done": {
              "type": "boolean"
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        },
        "operation_id": {
          "type": "string"
        },
        "operation_url": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "phase": {
          "type": "string"
        },
        "already": {
          "type": "boolean"
        },
        "queued": {
          "type": "boolean"
        },
        "task": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "status": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "error": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            },
            "finishedAt": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        },
        "message": {
          "type": "string"
        },
        "osCode": {
          "type": "string"
        },
        "vmid": {
          "type": "number"
        },
        "newPassword": {
          "type": "string"
        },
        "credentialSynced": {
          "type": "boolean"
        },
        "serviceConfigSynced": {
          "type": "boolean"
        }
      },
      "required": [
        "ok"
      ],
      "additionalProperties": true
    },
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string",
              "enum": [
                "deployment",
                "vps",
                "dedicated"
              ]
            },
            "action": {
              "type": "string"
            },
            "status": {
              "type": "string",
              "enum": [
                "pending",
                "running",
                "succeeded",
                "failed",
                "cancelled",
                "unknown"
              ]
            },
            "done": {
              "type": "boolean"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number",
                  "minimum": 0,
                  "maximum": 100
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "created_at": {
              "type": "string",
              "format": "date-time"
            },
            "updated_at": {
              "anyOf": [
                {
                  "type": "string",
                  "format": "date-time"
                },
                {
                  "type": "null"
                }
              ]
            },
            "service_ids": {
              "type": "array",
              "items": {
                "type": "string",
                "format": "uuid"
              }
            },
            "error": {
              "anyOf": [
                {
                  "type": "object",
                  "properties": {
                    "code": {
                      "type": "string"
                    },
                    "message": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "code",
                    "message"
                  ],
                  "additionalProperties": false
                },
                {
                  "type": "null"
                }
              ]
            },
            "result": {
              "anyOf": [
                {
                  "anyOf": [
                    {
                      "type": "object",
                      "properties": {
                        "service_ids": {
                          "type": "array",
                          "items": {
                            "type": "string",
                            "format": "uuid"
                          },
                          "minItems": 1,
                          "maxItems": 50
                        },
                        "order_id": {
                          "anyOf": [
                            {
                              "type": "string",
                              "format": "uuid"
                            },
                            {
                              "type": "null"
                            }
                          ]
                        },
                        "invoice_id": {
                          "type": "string",
                          "format": "uuid"
                        }
                      },
                      "required": [
                        "service_ids"
                      ],
                      "additionalProperties": false
                    },
                    {
                      "type": "object",
                      "properties": {
                        "service_id": {
                          "type": "string",
                          "format": "uuid"
                        },
                        "os": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "snapshot_name": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "power_state": {
                          "type": "string",
                          "enum": [
                            "running",
                            "stopped"
                          ]
                        }
                      },
                      "required": [
                        "service_id"
                      ],
                      "additionalProperties": false
                    }
                  ]
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id",
            "kind",
            "action",
            "status",
            "done",
            "progress",
            "stage",
            "created_at",
            "updated_at",
            "service_ids",
            "error"
          ],
          "additionalProperties": false
        },
        "links": {
          "type": "object",
          "properties": {
            "operation": {
              "type": "string",
              "pattern": "^\\/v1\\/operations\\/op_[A-Za-z0-9_-]+$"
            },
            "service": {
              "type": "string",
              "pattern": "^\\/v1\\/services\\/[0-9a-f-]{36}$"
            },
            "invoice": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/invoices\\/[0-9a-f-]{36}$"
            },
            "order": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/orders\\/[0-9a-f-]{36}$"
            }
          },
          "required": [
            "operation"
          ],
          "additionalProperties": false
        }
      },
      "required": [
        "ok",
        "operation"
      ],
      "additionalProperties": false
    }
  ],
  "description": "Legacy response by default; x-bf-response-format: operation opts into the canonical receipt when durable operations are enabled. Retries retain the initial cached response format."
}

Illustrative successful response

{
  "ok": true,
  "actionId": "00000000-0000-4000-8000-000000000002",
  "queued": true,
  "status": "queued",
  "operation_id": "op_aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
  "operation_url": "/v1/operations/op_aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
}

API reference and code examples

GET/v1/vps/{serviceId}/reinstall/osBrowse reinstall images

Operation ID: vpsReinstallOs

Returns operating system choices available for VPS reinstall.

Required scopes: vps.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "osTemplates": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              }
            ]
          },
          "code": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "family": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "version": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "arch": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "isDefault": {
            "type": "boolean"
          },
          "allowSshKeys": {
            "type": "boolean"
          }
        },
        "additionalProperties": true
      }
    }
  },
  "required": [
    "ok",
    "osTemplates"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "osTemplates": [
    {
      "code": "debian-13",
      "name": "Debian",
      "version": "13",
      "arch": "amd64"
    }
  ]
}

API reference and code examples

GET/v1/vps/{serviceId}/snapshotsBrowse snapshots

Operation ID: listVpsSnapshots

Returns existing snapshots for the target VPS.

Required scopes: vps.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "snapshots": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string"
          },
          "description": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "running": {
            "type": "number"
          },
          "snaptime": {
            "type": "number"
          },
          "parent": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          }
        },
        "required": [
          "name"
        ],
        "additionalProperties": true
      }
    }
  },
  "required": [
    "ok",
    "snapshots"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "snapshots": [
    {
      "name": "before-upgrade",
      "description": "Before upgrade",
      "running": 0
    }
  ]
}

API reference and code examples

POST/v1/vps/{serviceId}/snapshotsTake snapshot

Operation ID: vpsSnapshotCreate

Creates a new snapshot for the target VPS.

Required scopes: vps.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-bf-response-format · header — Opt into the canonical Operation receipt for this tracked write. Requires canonical_operation_responses enabled. Omit for the legacy response. Retried requests may replay their initial response format; use its operation_id or operation.id to poll.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 120
    },
    "description": {
      "type": "string",
      "minLength": 1,
      "maxLength": 200
    },
    "include_ram": {
      "type": "boolean"
    }
  },
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "anyOf": [
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "actionId": {
          "type": "string"
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "type": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "phase": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "status": {
              "type": "string"
            },
            "done": {
              "type": "boolean"
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        },
        "operation_id": {
          "type": "string"
        },
        "operation_url": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "phase": {
          "type": "string"
        },
        "already": {
          "type": "boolean"
        },
        "queued": {
          "type": "boolean"
        },
        "task": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "status": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "error": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            },
            "finishedAt": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        },
        "snapname": {
          "type": "string"
        }
      },
      "required": [
        "ok"
      ],
      "additionalProperties": true
    },
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string",
              "enum": [
                "deployment",
                "vps",
                "dedicated"
              ]
            },
            "action": {
              "type": "string"
            },
            "status": {
              "type": "string",
              "enum": [
                "pending",
                "running",
                "succeeded",
                "failed",
                "cancelled",
                "unknown"
              ]
            },
            "done": {
              "type": "boolean"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number",
                  "minimum": 0,
                  "maximum": 100
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "created_at": {
              "type": "string",
              "format": "date-time"
            },
            "updated_at": {
              "anyOf": [
                {
                  "type": "string",
                  "format": "date-time"
                },
                {
                  "type": "null"
                }
              ]
            },
            "service_ids": {
              "type": "array",
              "items": {
                "type": "string",
                "format": "uuid"
              }
            },
            "error": {
              "anyOf": [
                {
                  "type": "object",
                  "properties": {
                    "code": {
                      "type": "string"
                    },
                    "message": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "code",
                    "message"
                  ],
                  "additionalProperties": false
                },
                {
                  "type": "null"
                }
              ]
            },
            "result": {
              "anyOf": [
                {
                  "anyOf": [
                    {
                      "type": "object",
                      "properties": {
                        "service_ids": {
                          "type": "array",
                          "items": {
                            "type": "string",
                            "format": "uuid"
                          },
                          "minItems": 1,
                          "maxItems": 50
                        },
                        "order_id": {
                          "anyOf": [
                            {
                              "type": "string",
                              "format": "uuid"
                            },
                            {
                              "type": "null"
                            }
                          ]
                        },
                        "invoice_id": {
                          "type": "string",
                          "format": "uuid"
                        }
                      },
                      "required": [
                        "service_ids"
                      ],
                      "additionalProperties": false
                    },
                    {
                      "type": "object",
                      "properties": {
                        "service_id": {
                          "type": "string",
                          "format": "uuid"
                        },
                        "os": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "snapshot_name": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "power_state": {
                          "type": "string",
                          "enum": [
                            "running",
                            "stopped"
                          ]
                        }
                      },
                      "required": [
                        "service_id"
                      ],
                      "additionalProperties": false
                    }
                  ]
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id",
            "kind",
            "action",
            "status",
            "done",
            "progress",
            "stage",
            "created_at",
            "updated_at",
            "service_ids",
            "error"
          ],
          "additionalProperties": false
        },
        "links": {
          "type": "object",
          "properties": {
            "operation": {
              "type": "string",
              "pattern": "^\\/v1\\/operations\\/op_[A-Za-z0-9_-]+$"
            },
            "service": {
              "type": "string",
              "pattern": "^\\/v1\\/services\\/[0-9a-f-]{36}$"
            },
            "invoice": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/invoices\\/[0-9a-f-]{36}$"
            },
            "order": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/orders\\/[0-9a-f-]{36}$"
            }
          },
          "required": [
            "operation"
          ],
          "additionalProperties": false
        }
      },
      "required": [
        "ok",
        "operation"
      ],
      "additionalProperties": false
    }
  ],
  "description": "Legacy response by default; x-bf-response-format: operation opts into the canonical receipt when durable operations are enabled. Retries retain the initial cached response format."
}

Illustrative successful response

{
  "ok": true,
  "actionId": "00000000-0000-4000-8000-000000000002",
  "snapname": "before-upgrade"
}

API reference and code examples

DELETE/v1/vps/{serviceId}/snapshots/{name}Remove snapshot

Operation ID: vpsSnapshotDelete

Deletes the named VPS snapshot.

Required scopes: vps.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • name · path · required — Snapshot name.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-bf-response-format · header — Opt into the canonical Operation receipt for this tracked write. Requires canonical_operation_responses enabled. Omit for the legacy response. Retried requests may replay their initial response format; use its operation_id or operation.id to poll.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "anyOf": [
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "actionId": {
          "type": "string"
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "type": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "phase": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "status": {
              "type": "string"
            },
            "done": {
              "type": "boolean"
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        },
        "operation_id": {
          "type": "string"
        },
        "operation_url": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "phase": {
          "type": "string"
        },
        "already": {
          "type": "boolean"
        },
        "queued": {
          "type": "boolean"
        },
        "task": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "status": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "error": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            },
            "finishedAt": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        }
      },
      "required": [
        "ok"
      ],
      "additionalProperties": true
    },
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string",
              "enum": [
                "deployment",
                "vps",
                "dedicated"
              ]
            },
            "action": {
              "type": "string"
            },
            "status": {
              "type": "string",
              "enum": [
                "pending",
                "running",
                "succeeded",
                "failed",
                "cancelled",
                "unknown"
              ]
            },
            "done": {
              "type": "boolean"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number",
                  "minimum": 0,
                  "maximum": 100
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "created_at": {
              "type": "string",
              "format": "date-time"
            },
            "updated_at": {
              "anyOf": [
                {
                  "type": "string",
                  "format": "date-time"
                },
                {
                  "type": "null"
                }
              ]
            },
            "service_ids": {
              "type": "array",
              "items": {
                "type": "string",
                "format": "uuid"
              }
            },
            "error": {
              "anyOf": [
                {
                  "type": "object",
                  "properties": {
                    "code": {
                      "type": "string"
                    },
                    "message": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "code",
                    "message"
                  ],
                  "additionalProperties": false
                },
                {
                  "type": "null"
                }
              ]
            },
            "result": {
              "anyOf": [
                {
                  "anyOf": [
                    {
                      "type": "object",
                      "properties": {
                        "service_ids": {
                          "type": "array",
                          "items": {
                            "type": "string",
                            "format": "uuid"
                          },
                          "minItems": 1,
                          "maxItems": 50
                        },
                        "order_id": {
                          "anyOf": [
                            {
                              "type": "string",
                              "format": "uuid"
                            },
                            {
                              "type": "null"
                            }
                          ]
                        },
                        "invoice_id": {
                          "type": "string",
                          "format": "uuid"
                        }
                      },
                      "required": [
                        "service_ids"
                      ],
                      "additionalProperties": false
                    },
                    {
                      "type": "object",
                      "properties": {
                        "service_id": {
                          "type": "string",
                          "format": "uuid"
                        },
                        "os": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "snapshot_name": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "power_state": {
                          "type": "string",
                          "enum": [
                            "running",
                            "stopped"
                          ]
                        }
                      },
                      "required": [
                        "service_id"
                      ],
                      "additionalProperties": false
                    }
                  ]
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id",
            "kind",
            "action",
            "status",
            "done",
            "progress",
            "stage",
            "created_at",
            "updated_at",
            "service_ids",
            "error"
          ],
          "additionalProperties": false
        },
        "links": {
          "type": "object",
          "properties": {
            "operation": {
              "type": "string",
              "pattern": "^\\/v1\\/operations\\/op_[A-Za-z0-9_-]+$"
            },
            "service": {
              "type": "string",
              "pattern": "^\\/v1\\/services\\/[0-9a-f-]{36}$"
            },
            "invoice": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/invoices\\/[0-9a-f-]{36}$"
            },
            "order": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/orders\\/[0-9a-f-]{36}$"
            }
          },
          "required": [
            "operation"
          ],
          "additionalProperties": false
        }
      },
      "required": [
        "ok",
        "operation"
      ],
      "additionalProperties": false
    }
  ],
  "description": "Legacy response by default; x-bf-response-format: operation opts into the canonical receipt when durable operations are enabled. Retries retain the initial cached response format."
}

Illustrative successful response

{
  "ok": true,
  "actionId": "00000000-0000-4000-8000-000000000002"
}

API reference and code examples

POST/v1/vps/{serviceId}/snapshots/{name}/rollbackRestore snapshot

Operation ID: vpsSnapshotRollback

Restores the VPS from the named snapshot.

Required scopes: vps.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • name · path · required — Snapshot name.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-bf-response-format · header — Opt into the canonical Operation receipt for this tracked write. Requires canonical_operation_responses enabled. Omit for the legacy response. Retried requests may replay their initial response format; use its operation_id or operation.id to poll.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "anyOf": [
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "actionId": {
          "type": "string"
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "type": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "phase": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "status": {
              "type": "string"
            },
            "done": {
              "type": "boolean"
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        },
        "operation_id": {
          "type": "string"
        },
        "operation_url": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "phase": {
          "type": "string"
        },
        "already": {
          "type": "boolean"
        },
        "queued": {
          "type": "boolean"
        },
        "task": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "status": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "error": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            },
            "finishedAt": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        }
      },
      "required": [
        "ok"
      ],
      "additionalProperties": true
    },
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string",
              "enum": [
                "deployment",
                "vps",
                "dedicated"
              ]
            },
            "action": {
              "type": "string"
            },
            "status": {
              "type": "string",
              "enum": [
                "pending",
                "running",
                "succeeded",
                "failed",
                "cancelled",
                "unknown"
              ]
            },
            "done": {
              "type": "boolean"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number",
                  "minimum": 0,
                  "maximum": 100
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "created_at": {
              "type": "string",
              "format": "date-time"
            },
            "updated_at": {
              "anyOf": [
                {
                  "type": "string",
                  "format": "date-time"
                },
                {
                  "type": "null"
                }
              ]
            },
            "service_ids": {
              "type": "array",
              "items": {
                "type": "string",
                "format": "uuid"
              }
            },
            "error": {
              "anyOf": [
                {
                  "type": "object",
                  "properties": {
                    "code": {
                      "type": "string"
                    },
                    "message": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "code",
                    "message"
                  ],
                  "additionalProperties": false
                },
                {
                  "type": "null"
                }
              ]
            },
            "result": {
              "anyOf": [
                {
                  "anyOf": [
                    {
                      "type": "object",
                      "properties": {
                        "service_ids": {
                          "type": "array",
                          "items": {
                            "type": "string",
                            "format": "uuid"
                          },
                          "minItems": 1,
                          "maxItems": 50
                        },
                        "order_id": {
                          "anyOf": [
                            {
                              "type": "string",
                              "format": "uuid"
                            },
                            {
                              "type": "null"
                            }
                          ]
                        },
                        "invoice_id": {
                          "type": "string",
                          "format": "uuid"
                        }
                      },
                      "required": [
                        "service_ids"
                      ],
                      "additionalProperties": false
                    },
                    {
                      "type": "object",
                      "properties": {
                        "service_id": {
                          "type": "string",
                          "format": "uuid"
                        },
                        "os": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "snapshot_name": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "power_state": {
                          "type": "string",
                          "enum": [
                            "running",
                            "stopped"
                          ]
                        }
                      },
                      "required": [
                        "service_id"
                      ],
                      "additionalProperties": false
                    }
                  ]
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id",
            "kind",
            "action",
            "status",
            "done",
            "progress",
            "stage",
            "created_at",
            "updated_at",
            "service_ids",
            "error"
          ],
          "additionalProperties": false
        },
        "links": {
          "type": "object",
          "properties": {
            "operation": {
              "type": "string",
              "pattern": "^\\/v1\\/operations\\/op_[A-Za-z0-9_-]+$"
            },
            "service": {
              "type": "string",
              "pattern": "^\\/v1\\/services\\/[0-9a-f-]{36}$"
            },
            "invoice": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/invoices\\/[0-9a-f-]{36}$"
            },
            "order": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/orders\\/[0-9a-f-]{36}$"
            }
          },
          "required": [
            "operation"
          ],
          "additionalProperties": false
        }
      },
      "required": [
        "ok",
        "operation"
      ],
      "additionalProperties": false
    }
  ],
  "description": "Legacy response by default; x-bf-response-format: operation opts into the canonical receipt when durable operations are enabled. Retries retain the initial cached response format."
}

Illustrative successful response

{
  "ok": true,
  "actionId": "00000000-0000-4000-8000-000000000002"
}

API reference and code examples

GET/v1/vps/{serviceId}/snapshots/progressCheck snapshot progress

Operation ID: vpsSnapshotsProgress

Returns the current progress state for an in-flight snapshot operation.

Required scopes: vps.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "inProgress": {
      "type": "boolean"
    },
    "actionId": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "action": {
      "anyOf": [
        {
          "type": "string",
          "enum": [
            "create",
            "rollback",
            "delete"
          ]
        },
        {
          "type": "null"
        }
      ]
    },
    "target": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "lastRequestedAt": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "lastResult": {
      "anyOf": [
        {
          "type": "string",
          "enum": [
            "success",
            "failed"
          ]
        },
        {
          "type": "null"
        }
      ]
    }
  },
  "required": [
    "ok",
    "inProgress",
    "actionId",
    "action",
    "target",
    "lastRequestedAt",
    "lastResult"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "inProgress": false,
  "actionId": null,
  "lastRequestedAt": null,
  "lastResult": null,
  "action": null,
  "target": null
}

API reference and code examples

PUT/v1/vps/{serviceId}/sshkeyUpdate VPS SSH key

Operation ID: vpsSshkeySet

Applies a public SSH key or a saved SSH key reference to the target VPS.

Required scopes: vps.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "ssh_key_id": {
      "type": "string",
      "format": "uuid"
    },
    "public_key": {
      "type": "string",
      "minLength": 1,
      "maxLength": 8192
    }
  },
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true
}

API reference and code examples

POST/v1/vps/{serviceId}/startStart server

Operation ID: vpsStart

Starts a stopped VPS.

Required scopes: vps.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • Idempotency-Key · header — Recommended stable retry key. CLI 0.1.17 makes the flag optional: an omitted key is generated once, saved locally before dispatch and printed for explicit retries. Reuse the same key and exact payload. With durable_writes enabled, the API retains the dispatch identity after its encrypted response expires in 24 hours. An unknown outcome requires inspecting service/operation state; never generate a new key to retry it. Missing keys keep legacy behavior.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-bf-response-format · header — Opt into the canonical Operation receipt for this tracked write. Requires canonical_operation_responses enabled. Omit for the legacy response. Retried requests may replay their initial response format; use its operation_id or operation.id to poll.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "anyOf": [
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "actionId": {
          "type": "string"
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "type": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "phase": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "status": {
              "type": "string"
            },
            "done": {
              "type": "boolean"
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        },
        "operation_id": {
          "type": "string"
        },
        "operation_url": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "phase": {
          "type": "string"
        },
        "already": {
          "type": "boolean"
        },
        "queued": {
          "type": "boolean"
        },
        "task": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "status": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "error": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            },
            "finishedAt": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        }
      },
      "required": [
        "ok"
      ],
      "additionalProperties": true
    },
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string",
              "enum": [
                "deployment",
                "vps",
                "dedicated"
              ]
            },
            "action": {
              "type": "string"
            },
            "status": {
              "type": "string",
              "enum": [
                "pending",
                "running",
                "succeeded",
                "failed",
                "cancelled",
                "unknown"
              ]
            },
            "done": {
              "type": "boolean"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number",
                  "minimum": 0,
                  "maximum": 100
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "created_at": {
              "type": "string",
              "format": "date-time"
            },
            "updated_at": {
              "anyOf": [
                {
                  "type": "string",
                  "format": "date-time"
                },
                {
                  "type": "null"
                }
              ]
            },
            "service_ids": {
              "type": "array",
              "items": {
                "type": "string",
                "format": "uuid"
              }
            },
            "error": {
              "anyOf": [
                {
                  "type": "object",
                  "properties": {
                    "code": {
                      "type": "string"
                    },
                    "message": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "code",
                    "message"
                  ],
                  "additionalProperties": false
                },
                {
                  "type": "null"
                }
              ]
            },
            "result": {
              "anyOf": [
                {
                  "anyOf": [
                    {
                      "type": "object",
                      "properties": {
                        "service_ids": {
                          "type": "array",
                          "items": {
                            "type": "string",
                            "format": "uuid"
                          },
                          "minItems": 1,
                          "maxItems": 50
                        },
                        "order_id": {
                          "anyOf": [
                            {
                              "type": "string",
                              "format": "uuid"
                            },
                            {
                              "type": "null"
                            }
                          ]
                        },
                        "invoice_id": {
                          "type": "string",
                          "format": "uuid"
                        }
                      },
                      "required": [
                        "service_ids"
                      ],
                      "additionalProperties": false
                    },
                    {
                      "type": "object",
                      "properties": {
                        "service_id": {
                          "type": "string",
                          "format": "uuid"
                        },
                        "os": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "snapshot_name": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "power_state": {
                          "type": "string",
                          "enum": [
                            "running",
                            "stopped"
                          ]
                        }
                      },
                      "required": [
                        "service_id"
                      ],
                      "additionalProperties": false
                    }
                  ]
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id",
            "kind",
            "action",
            "status",
            "done",
            "progress",
            "stage",
            "created_at",
            "updated_at",
            "service_ids",
            "error"
          ],
          "additionalProperties": false
        },
        "links": {
          "type": "object",
          "properties": {
            "operation": {
              "type": "string",
              "pattern": "^\\/v1\\/operations\\/op_[A-Za-z0-9_-]+$"
            },
            "service": {
              "type": "string",
              "pattern": "^\\/v1\\/services\\/[0-9a-f-]{36}$"
            },
            "invoice": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/invoices\\/[0-9a-f-]{36}$"
            },
            "order": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/orders\\/[0-9a-f-]{36}$"
            }
          },
          "required": [
            "operation"
          ],
          "additionalProperties": false
        }
      },
      "required": [
        "ok",
        "operation"
      ],
      "additionalProperties": false
    }
  ],
  "description": "Legacy response by default; x-bf-response-format: operation opts into the canonical receipt when durable operations are enabled. Retries retain the initial cached response format."
}

Illustrative successful response

{
  "ok": true,
  "actionId": "00000000-0000-4000-8000-000000000002",
  "operation_id": "op_EXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLE",
  "operation_url": "/v1/operations/op_EXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLE"
}

API reference and code examples

GET/v1/vps/{serviceId}/statusCheck VPS status

Operation ID: vpsStatus

Returns hostname, assigned region code (for example NL or PT), customer IPv4/IPv6, power state and selected runtime metrics. Region describes the hosting country, not a specific datacenter building; null means unavailable. Does not disclose internal node or cluster identifiers. Ownership, status, type, search, external_id and label filters are applied server-side before pagination and counts. The default is active plus suspended; historical states require an explicit status filter. group_by=type groups only the current page, not the complete inventory.

Required scopes: vps.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "vm": {
      "type": "object",
      "properties": {
        "status": {
          "type": "string"
        },
        "power": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "hostname": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "os": {
          "anyOf": [
            {
              "type": "object",
              "properties": {
                "name": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "version": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "family": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "source": {
                  "type": "string"
                },
                "guestVerified": {
                  "type": "boolean"
                }
              },
              "required": [
                "name",
                "version",
                "family",
                "source",
                "guestVerified"
              ],
              "additionalProperties": true
            },
            {
              "type": "null"
            }
          ]
        },
        "ipv4": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "ipv6": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "uptime": {
          "anyOf": [
            {
              "type": "number"
            },
            {
              "type": "null"
            }
          ]
        },
        "cpus": {
          "anyOf": [
            {
              "type": "number"
            },
            {
              "type": "null"
            }
          ]
        },
        "cpu": {
          "anyOf": [
            {
              "type": "number"
            },
            {
              "type": "null"
            }
          ]
        },
        "mem": {
          "anyOf": [
            {
              "type": "number"
            },
            {
              "type": "null"
            }
          ]
        },
        "maxmem": {
          "anyOf": [
            {
              "type": "number"
            },
            {
              "type": "null"
            }
          ]
        },
        "disk": {
          "anyOf": [
            {
              "type": "number"
            },
            {
              "type": "null"
            }
          ]
        },
        "maxdisk": {
          "anyOf": [
            {
              "type": "number"
            },
            {
              "type": "null"
            }
          ]
        },
        "netin": {
          "anyOf": [
            {
              "type": "number"
            },
            {
              "type": "null"
            }
          ]
        },
        "netout": {
          "anyOf": [
            {
              "type": "number"
            },
            {
              "type": "null"
            }
          ]
        },
        "diskread": {
          "anyOf": [
            {
              "type": "number"
            },
            {
              "type": "null"
            }
          ]
        },
        "diskwrite": {
          "anyOf": [
            {
              "type": "number"
            },
            {
              "type": "null"
            }
          ]
        }
      },
      "required": [
        "status"
      ],
      "additionalProperties": true
    }
  },
  "required": [
    "ok",
    "vm"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "vm": {
    "status": "running",
    "power": "on",
    "hostname": "server.example.com",
    "os": {
      "name": "Debian",
      "version": "13",
      "family": "debian",
      "source": "provisioning_metadata",
      "guestVerified": false
    },
    "ipv4": "192.0.2.10",
    "ipv6": null,
    "uptime": 3600,
    "cpus": 2,
    "cpu": 0.05,
    "mem": 536870912,
    "maxmem": 4294967296,
    "disk": 0,
    "maxdisk": 42949672960,
    "netin": 0,
    "netout": 0,
    "diskread": 0,
    "diskwrite": 0
  }
}

API reference and code examples

POST/v1/vps/{serviceId}/stopStop server

Operation ID: vpsStop

Stops a running VPS.

Required scopes: vps.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • Idempotency-Key · header — Recommended stable retry key. CLI 0.1.17 makes the flag optional: an omitted key is generated once, saved locally before dispatch and printed for explicit retries. Reuse the same key and exact payload. With durable_writes enabled, the API retains the dispatch identity after its encrypted response expires in 24 hours. An unknown outcome requires inspecting service/operation state; never generate a new key to retry it. Missing keys keep legacy behavior.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-bf-response-format · header — Opt into the canonical Operation receipt for this tracked write. Requires canonical_operation_responses enabled. Omit for the legacy response. Retried requests may replay their initial response format; use its operation_id or operation.id to poll.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "anyOf": [
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "actionId": {
          "type": "string"
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "type": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "phase": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "status": {
              "type": "string"
            },
            "done": {
              "type": "boolean"
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        },
        "operation_id": {
          "type": "string"
        },
        "operation_url": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "phase": {
          "type": "string"
        },
        "already": {
          "type": "boolean"
        },
        "queued": {
          "type": "boolean"
        },
        "task": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "status": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "error": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            },
            "finishedAt": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        }
      },
      "required": [
        "ok"
      ],
      "additionalProperties": true
    },
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string",
              "enum": [
                "deployment",
                "vps",
                "dedicated"
              ]
            },
            "action": {
              "type": "string"
            },
            "status": {
              "type": "string",
              "enum": [
                "pending",
                "running",
                "succeeded",
                "failed",
                "cancelled",
                "unknown"
              ]
            },
            "done": {
              "type": "boolean"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number",
                  "minimum": 0,
                  "maximum": 100
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "created_at": {
              "type": "string",
              "format": "date-time"
            },
            "updated_at": {
              "anyOf": [
                {
                  "type": "string",
                  "format": "date-time"
                },
                {
                  "type": "null"
                }
              ]
            },
            "service_ids": {
              "type": "array",
              "items": {
                "type": "string",
                "format": "uuid"
              }
            },
            "error": {
              "anyOf": [
                {
                  "type": "object",
                  "properties": {
                    "code": {
                      "type": "string"
                    },
                    "message": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "code",
                    "message"
                  ],
                  "additionalProperties": false
                },
                {
                  "type": "null"
                }
              ]
            },
            "result": {
              "anyOf": [
                {
                  "anyOf": [
                    {
                      "type": "object",
                      "properties": {
                        "service_ids": {
                          "type": "array",
                          "items": {
                            "type": "string",
                            "format": "uuid"
                          },
                          "minItems": 1,
                          "maxItems": 50
                        },
                        "order_id": {
                          "anyOf": [
                            {
                              "type": "string",
                              "format": "uuid"
                            },
                            {
                              "type": "null"
                            }
                          ]
                        },
                        "invoice_id": {
                          "type": "string",
                          "format": "uuid"
                        }
                      },
                      "required": [
                        "service_ids"
                      ],
                      "additionalProperties": false
                    },
                    {
                      "type": "object",
                      "properties": {
                        "service_id": {
                          "type": "string",
                          "format": "uuid"
                        },
                        "os": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "snapshot_name": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "power_state": {
                          "type": "string",
                          "enum": [
                            "running",
                            "stopped"
                          ]
                        }
                      },
                      "required": [
                        "service_id"
                      ],
                      "additionalProperties": false
                    }
                  ]
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id",
            "kind",
            "action",
            "status",
            "done",
            "progress",
            "stage",
            "created_at",
            "updated_at",
            "service_ids",
            "error"
          ],
          "additionalProperties": false
        },
        "links": {
          "type": "object",
          "properties": {
            "operation": {
              "type": "string",
              "pattern": "^\\/v1\\/operations\\/op_[A-Za-z0-9_-]+$"
            },
            "service": {
              "type": "string",
              "pattern": "^\\/v1\\/services\\/[0-9a-f-]{36}$"
            },
            "invoice": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/invoices\\/[0-9a-f-]{36}$"
            },
            "order": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/orders\\/[0-9a-f-]{36}$"
            }
          },
          "required": [
            "operation"
          ],
          "additionalProperties": false
        }
      },
      "required": [
        "ok",
        "operation"
      ],
      "additionalProperties": false
    }
  ],
  "description": "Legacy response by default; x-bf-response-format: operation opts into the canonical receipt when durable operations are enabled. Retries retain the initial cached response format."
}

Illustrative successful response

{
  "ok": true,
  "actionId": "00000000-0000-4000-8000-000000000002",
  "operation_id": "op_EXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLE",
  "operation_url": "/v1/operations/op_EXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLE"
}

API reference and code examples

Dedicated Servers

GET/v1/dedicated/{serviceId}Check dedicated server

Operation ID: dedicatedStatus

Returns the owned server lifecycle, hardware, operating system, IP, power state, and recent operations.

Required scopes: dedicated.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "lifecycleStatus": {
      "type": "string"
    },
    "service": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "state": {
          "type": "string"
        },
        "configurationCode": {
          "type": "string"
        },
        "regionCode": {
          "type": "string"
        },
        "hostname": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "osName": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "hardware": {
          "type": "object",
          "properties": {
            "lineName": {
              "type": "string"
            },
            "cpuSockets": {
              "type": "number"
            },
            "ramGb": {
              "type": "number"
            },
            "storageGb": {
              "type": "number"
            },
            "linkGbps": {
              "type": "number"
            },
            "physicalLinkGbps": {
              "type": "number"
            },
            "cpuDescription": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "ramDescription": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "storageDescription": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "additionalProperties": true
        },
        "primaryIp": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "power": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "powerCheckedAt": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "rescueMode": {
          "type": "boolean"
        },
        "canManage": {
          "type": "boolean"
        },
        "canConsole": {
          "type": "boolean"
        },
        "canReinstall": {
          "type": "boolean"
        },
        "canRescue": {
          "type": "boolean"
        },
        "suspensionReason": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        }
      },
      "additionalProperties": true
    },
    "operations": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "type": {
            "type": "string"
          },
          "kind": {
            "type": "string"
          },
          "state": {
            "type": "string"
          },
          "phase": {
            "type": "string"
          },
          "progress": {
            "anyOf": [
              {
                "type": "number"
              },
              {
                "type": "null"
              }
            ]
          },
          "stage": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "status": {
            "type": "string"
          },
          "done": {
            "type": "boolean"
          },
          "createdAt": {
            "type": "string"
          },
          "updatedAt": {
            "type": "string"
          }
        },
        "required": [
          "id"
        ],
        "additionalProperties": true
      }
    }
  },
  "required": [
    "ok",
    "lifecycleStatus",
    "service",
    "operations"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "lifecycleStatus": "active",
  "service": {
    "state": "active",
    "configurationCode": "EXAMPLE",
    "regionCode": "PT",
    "hostname": "server.example.com",
    "osName": "Debian 13",
    "hardware": {
      "lineName": "Example dedicated server",
      "cpuSockets": 2,
      "ramGb": 256,
      "storageGb": 240,
      "linkGbps": 10,
      "physicalLinkGbps": 10,
      "cpuDescription": "Example CPU",
      "ramDescription": "DDR4 ECC",
      "storageDescription": "SSD"
    },
    "primaryIp": "192.0.2.10",
    "power": "online",
    "powerCheckedAt": "2026-10-01T00:00:00.000Z",
    "rescueMode": false,
    "canManage": true,
    "canConsole": true,
    "canReinstall": true,
    "canRescue": true
  },
  "operations": []
}

API reference and code examples

GET/v1/dedicated/{serviceId}/consoleOpen browser console

Operation ID: dedicatedConsole

Returns an authenticated portal console URL. No provider address or VNC password is exposed. Sign in to connect.

Required scopes: dedicated.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "serviceId": {
      "type": "string"
    },
    "consoleUrl": {
      "type": "string"
    },
    "requiresBrowserLogin": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "transport": {
      "type": "string",
      "const": "browser",
      "enum": [
        "browser"
      ]
    }
  },
  "required": [
    "ok",
    "serviceId",
    "consoleUrl",
    "requiresBrowserLogin",
    "transport"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "serviceId": "00000000-0000-4000-8000-000000000001",
  "consoleUrl": "https://my.blazingfast.io/manage/dedicated/00000000-0000-4000-8000-000000000001/console",
  "requiresBrowserLogin": true,
  "transport": "browser"
}

API reference and code examples

GET/v1/dedicated/{serviceId}/credentialsReveal current credentialsSensitive

Operation ID: dedicatedCredentials

Explicit no-store credential endpoint. Returns the owned server IP, username, and current generated password after activation.

Required scopes: dedicated.credentials.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "serviceId": {
      "type": "string"
    },
    "ip": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "username": {
      "type": "string"
    },
    "password": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "credentialKind": {
      "type": "string"
    },
    "operationId": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    }
  },
  "required": [
    "ok",
    "serviceId",
    "ip",
    "username",
    "password"
  ],
  "additionalProperties": true
}

API reference and code examples

POST/v1/dedicated/{serviceId}/password-resetReset dedicated password

Operation ID: dedicatedPasswordReset

Interrupts connections while maintenance replaces the OS administrator password. Track the returned task; retrieve the result privately only after success.

Required scopes: dedicated.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • Idempotency-Key · header · required — Stable action key: 8–128 letters, digits, dot, underscore, colon or hyphen. Reuse the same key and payload on retries; inspect task state after a timeout.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-bf-response-format · header — Opt into the canonical Operation receipt for this tracked write. Requires canonical_operation_responses enabled. Omit for the legacy response. Retried requests may replay their initial response format; use its operation_id or operation.id to poll.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 202

{
  "anyOf": [
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "actionId": {
          "type": "string"
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "type": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "phase": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "status": {
              "type": "string"
            },
            "done": {
              "type": "boolean"
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        },
        "operation_id": {
          "type": "string"
        },
        "operation_url": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "phase": {
          "type": "string"
        },
        "already": {
          "type": "boolean"
        },
        "queued": {
          "type": "boolean"
        },
        "task": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "status": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "error": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            },
            "finishedAt": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        }
      },
      "required": [
        "ok"
      ],
      "additionalProperties": true
    },
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string",
              "enum": [
                "deployment",
                "vps",
                "dedicated"
              ]
            },
            "action": {
              "type": "string"
            },
            "status": {
              "type": "string",
              "enum": [
                "pending",
                "running",
                "succeeded",
                "failed",
                "cancelled",
                "unknown"
              ]
            },
            "done": {
              "type": "boolean"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number",
                  "minimum": 0,
                  "maximum": 100
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "created_at": {
              "type": "string",
              "format": "date-time"
            },
            "updated_at": {
              "anyOf": [
                {
                  "type": "string",
                  "format": "date-time"
                },
                {
                  "type": "null"
                }
              ]
            },
            "service_ids": {
              "type": "array",
              "items": {
                "type": "string",
                "format": "uuid"
              }
            },
            "error": {
              "anyOf": [
                {
                  "type": "object",
                  "properties": {
                    "code": {
                      "type": "string"
                    },
                    "message": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "code",
                    "message"
                  ],
                  "additionalProperties": false
                },
                {
                  "type": "null"
                }
              ]
            },
            "result": {
              "anyOf": [
                {
                  "anyOf": [
                    {
                      "type": "object",
                      "properties": {
                        "service_ids": {
                          "type": "array",
                          "items": {
                            "type": "string",
                            "format": "uuid"
                          },
                          "minItems": 1,
                          "maxItems": 50
                        },
                        "order_id": {
                          "anyOf": [
                            {
                              "type": "string",
                              "format": "uuid"
                            },
                            {
                              "type": "null"
                            }
                          ]
                        },
                        "invoice_id": {
                          "type": "string",
                          "format": "uuid"
                        }
                      },
                      "required": [
                        "service_ids"
                      ],
                      "additionalProperties": false
                    },
                    {
                      "type": "object",
                      "properties": {
                        "service_id": {
                          "type": "string",
                          "format": "uuid"
                        },
                        "os": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "snapshot_name": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "power_state": {
                          "type": "string",
                          "enum": [
                            "running",
                            "stopped"
                          ]
                        }
                      },
                      "required": [
                        "service_id"
                      ],
                      "additionalProperties": false
                    }
                  ]
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id",
            "kind",
            "action",
            "status",
            "done",
            "progress",
            "stage",
            "created_at",
            "updated_at",
            "service_ids",
            "error"
          ],
          "additionalProperties": false
        },
        "links": {
          "type": "object",
          "properties": {
            "operation": {
              "type": "string",
              "pattern": "^\\/v1\\/operations\\/op_[A-Za-z0-9_-]+$"
            },
            "service": {
              "type": "string",
              "pattern": "^\\/v1\\/services\\/[0-9a-f-]{36}$"
            },
            "invoice": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/invoices\\/[0-9a-f-]{36}$"
            },
            "order": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/orders\\/[0-9a-f-]{36}$"
            }
          },
          "required": [
            "operation"
          ],
          "additionalProperties": false
        }
      },
      "required": [
        "ok",
        "operation"
      ],
      "additionalProperties": false
    }
  ],
  "description": "Legacy response by default; x-bf-response-format: operation opts into the canonical receipt when durable operations are enabled. Retries retain the initial cached response format."
}

Illustrative successful response

{
  "ok": true,
  "operation": {
    "id": "00000000-0000-4000-8000-000000000002",
    "state": "waiting_provider"
  },
  "operation_id": "op_EXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLE",
  "operation_url": "/v1/operations/op_EXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLE"
}

API reference and code examples

GET/v1/dedicated/{serviceId}/password-reset-credentialReveal reset passwordSensitive

Operation ID: dedicatedPasswordResetCredential

Explicit no-store endpoint returning the generated password after successful reset. Sensitive output: do not log or send to an AI conversation.

Required scopes: dedicated.credentials.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • operationId · query — Optional password-reset operation UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "operationId": {
      "type": "string"
    },
    "password": {
      "type": "string"
    }
  },
  "required": [
    "ok",
    "operationId",
    "password"
  ],
  "additionalProperties": true
}

API reference and code examples

POST/v1/dedicated/{serviceId}/powerQueue power action

Operation ID: dedicatedPower

Body action: start, stop, restart or exit_rescue. Exiting rescue boots the installed system from disk. Interrupting actions require explicit intent. Task acceptance is not completion; inspect the returned task.

Required scopes: dedicated.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • Idempotency-Key · header · required — Stable action key: 8–128 letters, digits, dot, underscore, colon or hyphen. Reuse the same key and payload on retries; inspect task state after a timeout.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-bf-response-format · header — Opt into the canonical Operation receipt for this tracked write. Requires canonical_operation_responses enabled. Omit for the legacy response. Retried requests may replay their initial response format; use its operation_id or operation.id to poll.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "action": {
      "type": "string",
      "enum": [
        "start",
        "stop",
        "restart",
        "exit_rescue"
      ]
    }
  },
  "required": [
    "action"
  ],
  "additionalProperties": false
}

Successful response · HTTP 202

{
  "anyOf": [
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "actionId": {
          "type": "string"
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "type": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "phase": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "status": {
              "type": "string"
            },
            "done": {
              "type": "boolean"
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        },
        "operation_id": {
          "type": "string"
        },
        "operation_url": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "phase": {
          "type": "string"
        },
        "already": {
          "type": "boolean"
        },
        "queued": {
          "type": "boolean"
        },
        "task": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "status": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "error": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            },
            "finishedAt": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        }
      },
      "required": [
        "ok"
      ],
      "additionalProperties": true
    },
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string",
              "enum": [
                "deployment",
                "vps",
                "dedicated"
              ]
            },
            "action": {
              "type": "string"
            },
            "status": {
              "type": "string",
              "enum": [
                "pending",
                "running",
                "succeeded",
                "failed",
                "cancelled",
                "unknown"
              ]
            },
            "done": {
              "type": "boolean"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number",
                  "minimum": 0,
                  "maximum": 100
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "created_at": {
              "type": "string",
              "format": "date-time"
            },
            "updated_at": {
              "anyOf": [
                {
                  "type": "string",
                  "format": "date-time"
                },
                {
                  "type": "null"
                }
              ]
            },
            "service_ids": {
              "type": "array",
              "items": {
                "type": "string",
                "format": "uuid"
              }
            },
            "error": {
              "anyOf": [
                {
                  "type": "object",
                  "properties": {
                    "code": {
                      "type": "string"
                    },
                    "message": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "code",
                    "message"
                  ],
                  "additionalProperties": false
                },
                {
                  "type": "null"
                }
              ]
            },
            "result": {
              "anyOf": [
                {
                  "anyOf": [
                    {
                      "type": "object",
                      "properties": {
                        "service_ids": {
                          "type": "array",
                          "items": {
                            "type": "string",
                            "format": "uuid"
                          },
                          "minItems": 1,
                          "maxItems": 50
                        },
                        "order_id": {
                          "anyOf": [
                            {
                              "type": "string",
                              "format": "uuid"
                            },
                            {
                              "type": "null"
                            }
                          ]
                        },
                        "invoice_id": {
                          "type": "string",
                          "format": "uuid"
                        }
                      },
                      "required": [
                        "service_ids"
                      ],
                      "additionalProperties": false
                    },
                    {
                      "type": "object",
                      "properties": {
                        "service_id": {
                          "type": "string",
                          "format": "uuid"
                        },
                        "os": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "snapshot_name": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "power_state": {
                          "type": "string",
                          "enum": [
                            "running",
                            "stopped"
                          ]
                        }
                      },
                      "required": [
                        "service_id"
                      ],
                      "additionalProperties": false
                    }
                  ]
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id",
            "kind",
            "action",
            "status",
            "done",
            "progress",
            "stage",
            "created_at",
            "updated_at",
            "service_ids",
            "error"
          ],
          "additionalProperties": false
        },
        "links": {
          "type": "object",
          "properties": {
            "operation": {
              "type": "string",
              "pattern": "^\\/v1\\/operations\\/op_[A-Za-z0-9_-]+$"
            },
            "service": {
              "type": "string",
              "pattern": "^\\/v1\\/services\\/[0-9a-f-]{36}$"
            },
            "invoice": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/invoices\\/[0-9a-f-]{36}$"
            },
            "order": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/orders\\/[0-9a-f-]{36}$"
            }
          },
          "required": [
            "operation"
          ],
          "additionalProperties": false
        }
      },
      "required": [
        "ok",
        "operation"
      ],
      "additionalProperties": false
    }
  ],
  "description": "Legacy response by default; x-bf-response-format: operation opts into the canonical receipt when durable operations are enabled. Retries retain the initial cached response format."
}

Illustrative successful response

{
  "ok": true,
  "operation": {
    "id": "00000000-0000-4000-8000-000000000002",
    "kind": "power_on",
    "state": "queued"
  },
  "operation_id": "op_EXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLE",
  "operation_url": "/v1/operations/op_EXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLE"
}

API reference and code examples

GET/v1/dedicated/{serviceId}/power-statsRead electrical power statistics

Operation ID: dedicatedStats

Electrical consumption in watts, not CPU utilization. Any estimated energy value is not a billing meter. Hardware may not expose measurements.

Required scopes: dedicated.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "available": {
      "type": "boolean"
    },
    "period": {
      "type": "string"
    },
    "points": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "time": {
            "type": "string"
          },
          "timestamp": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              }
            ]
          },
          "bytesIn": {
            "type": "number"
          },
          "bytesOut": {
            "type": "number"
          },
          "rx": {
            "type": "number"
          },
          "tx": {
            "type": "number"
          },
          "watts": {
            "anyOf": [
              {
                "type": "number"
              },
              {
                "type": "null"
              }
            ]
          },
          "value": {
            "anyOf": [
              {
                "type": "number"
              },
              {
                "type": "null"
              }
            ]
          },
          "connections": {
            "type": "number"
          },
          "errors": {
            "type": "number"
          },
          "blockedPackets": {
            "type": "number"
          }
        },
        "additionalProperties": true
      }
    },
    "summary": {
      "type": "object",
      "properties": {
        "currentWatts": {
          "anyOf": [
            {
              "type": "number"
            },
            {
              "type": "null"
            }
          ]
        },
        "averageWatts": {
          "anyOf": [
            {
              "type": "number"
            },
            {
              "type": "null"
            }
          ]
        },
        "peakWatts": {
          "anyOf": [
            {
              "type": "number"
            },
            {
              "type": "null"
            }
          ]
        },
        "estimatedKwh": {
          "anyOf": [
            {
              "type": "number"
            },
            {
              "type": "null"
            }
          ]
        }
      },
      "required": [
        "currentWatts",
        "averageWatts",
        "peakWatts",
        "estimatedKwh"
      ],
      "additionalProperties": true
    }
  },
  "required": [
    "ok",
    "available",
    "period",
    "points",
    "summary"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "available": false,
  "period": "24h",
  "points": [],
  "summary": {
    "currentWatts": null,
    "averageWatts": null,
    "peakWatts": null,
    "estimatedKwh": null
  }
}

API reference and code examples

POST/v1/dedicated/{serviceId}/reinstallErase and reinstall the server

Operation ID: dedicatedReinstall

Irreversibly overwrites installed data. Read compatible profiles first; use an account-owned SSH key when supported. Inspect the returned task rather than submitting another installation.

Required scopes: dedicated.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • Idempotency-Key · header · required — Stable action key: 8–128 letters, digits, dot, underscore, colon or hyphen. Reuse the same key and payload on retries; inspect task state after a timeout.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-bf-response-format · header — Opt into the canonical Operation receipt for this tracked write. Requires canonical_operation_responses enabled. Omit for the legacy response. Retried requests may replay their initial response format; use its operation_id or operation.id to poll.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "profile_id": {
      "type": "integer",
      "exclusiveMinimum": 0
    },
    "hostname": {
      "type": "string",
      "pattern": "^(?=.{1,253}$)[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)*$"
    },
    "ssh_key_id": {
      "type": "string",
      "format": "uuid"
    },
    "confirmation": {
      "type": "string",
      "const": "ERASE",
      "enum": [
        "ERASE"
      ]
    }
  },
  "required": [
    "profile_id",
    "confirmation"
  ],
  "additionalProperties": false
}

Successful response · HTTP 202

{
  "anyOf": [
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "actionId": {
          "type": "string"
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "type": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "phase": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "status": {
              "type": "string"
            },
            "done": {
              "type": "boolean"
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        },
        "operation_id": {
          "type": "string"
        },
        "operation_url": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "phase": {
          "type": "string"
        },
        "already": {
          "type": "boolean"
        },
        "queued": {
          "type": "boolean"
        },
        "task": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "status": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "error": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            },
            "finishedAt": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        }
      },
      "required": [
        "ok"
      ],
      "additionalProperties": true
    },
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string",
              "enum": [
                "deployment",
                "vps",
                "dedicated"
              ]
            },
            "action": {
              "type": "string"
            },
            "status": {
              "type": "string",
              "enum": [
                "pending",
                "running",
                "succeeded",
                "failed",
                "cancelled",
                "unknown"
              ]
            },
            "done": {
              "type": "boolean"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number",
                  "minimum": 0,
                  "maximum": 100
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "created_at": {
              "type": "string",
              "format": "date-time"
            },
            "updated_at": {
              "anyOf": [
                {
                  "type": "string",
                  "format": "date-time"
                },
                {
                  "type": "null"
                }
              ]
            },
            "service_ids": {
              "type": "array",
              "items": {
                "type": "string",
                "format": "uuid"
              }
            },
            "error": {
              "anyOf": [
                {
                  "type": "object",
                  "properties": {
                    "code": {
                      "type": "string"
                    },
                    "message": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "code",
                    "message"
                  ],
                  "additionalProperties": false
                },
                {
                  "type": "null"
                }
              ]
            },
            "result": {
              "anyOf": [
                {
                  "anyOf": [
                    {
                      "type": "object",
                      "properties": {
                        "service_ids": {
                          "type": "array",
                          "items": {
                            "type": "string",
                            "format": "uuid"
                          },
                          "minItems": 1,
                          "maxItems": 50
                        },
                        "order_id": {
                          "anyOf": [
                            {
                              "type": "string",
                              "format": "uuid"
                            },
                            {
                              "type": "null"
                            }
                          ]
                        },
                        "invoice_id": {
                          "type": "string",
                          "format": "uuid"
                        }
                      },
                      "required": [
                        "service_ids"
                      ],
                      "additionalProperties": false
                    },
                    {
                      "type": "object",
                      "properties": {
                        "service_id": {
                          "type": "string",
                          "format": "uuid"
                        },
                        "os": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "snapshot_name": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "power_state": {
                          "type": "string",
                          "enum": [
                            "running",
                            "stopped"
                          ]
                        }
                      },
                      "required": [
                        "service_id"
                      ],
                      "additionalProperties": false
                    }
                  ]
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id",
            "kind",
            "action",
            "status",
            "done",
            "progress",
            "stage",
            "created_at",
            "updated_at",
            "service_ids",
            "error"
          ],
          "additionalProperties": false
        },
        "links": {
          "type": "object",
          "properties": {
            "operation": {
              "type": "string",
              "pattern": "^\\/v1\\/operations\\/op_[A-Za-z0-9_-]+$"
            },
            "service": {
              "type": "string",
              "pattern": "^\\/v1\\/services\\/[0-9a-f-]{36}$"
            },
            "invoice": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/invoices\\/[0-9a-f-]{36}$"
            },
            "order": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/orders\\/[0-9a-f-]{36}$"
            }
          },
          "required": [
            "operation"
          ],
          "additionalProperties": false
        }
      },
      "required": [
        "ok",
        "operation"
      ],
      "additionalProperties": false
    }
  ],
  "description": "Legacy response by default; x-bf-response-format: operation opts into the canonical receipt when durable operations are enabled. Retries retain the initial cached response format."
}

Illustrative successful response

{
  "ok": true,
  "operation": {
    "id": "00000000-0000-4000-8000-000000000002",
    "state": "waiting_provider"
  },
  "operation_id": "op_EXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLE",
  "operation_url": "/v1/operations/op_EXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLE"
}

API reference and code examples

GET/v1/dedicated/{serviceId}/reinstall-optionsList compatible installation images

Operation ID: dedicatedReinstallOptions

Read compatible numeric profile IDs before requesting reinstall. Reading options does not start an installation.

Required scopes: dedicated.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "enabled": {
      "type": "boolean"
    },
    "profiles": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              }
            ]
          },
          "name": {
            "type": "string"
          },
          "allowSshKeys": {
            "type": "boolean"
          },
          "version": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "family": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "enabled": {
            "type": "boolean"
          }
        },
        "required": [
          "id",
          "name"
        ],
        "additionalProperties": true
      }
    },
    "currentProfileId": {
      "anyOf": [
        {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "number"
            }
          ]
        },
        {
          "type": "null"
        }
      ]
    }
  },
  "required": [
    "ok",
    "enabled",
    "profiles"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "enabled": true,
  "currentProfileId": 1,
  "profiles": [
    {
      "id": 1,
      "name": "Debian 13",
      "allowSshKeys": true
    }
  ]
}

API reference and code examples

POST/v1/dedicated/{serviceId}/rescueBoot a rescue environment

Operation ID: dedicatedRescue

Interrupts applications and connections; does not itself reinstall the OS. Use a compatible rescue profile, then exit_rescue to return to installed-system boot.

Required scopes: dedicated.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • Idempotency-Key · header · required — Stable action key: 8–128 letters, digits, dot, underscore, colon or hyphen. Reuse the same key and payload on retries; inspect task state after a timeout.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-bf-response-format · header — Opt into the canonical Operation receipt for this tracked write. Requires canonical_operation_responses enabled. Omit for the legacy response. Retried requests may replay their initial response format; use its operation_id or operation.id to poll.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "profile_id": {
      "type": "integer",
      "exclusiveMinimum": 0
    },
    "confirmation": {
      "type": "string",
      "const": "RESCUE",
      "enum": [
        "RESCUE"
      ]
    }
  },
  "required": [
    "profile_id",
    "confirmation"
  ],
  "additionalProperties": false
}

Successful response · HTTP 202

{
  "anyOf": [
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "actionId": {
          "type": "string"
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "type": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "phase": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "status": {
              "type": "string"
            },
            "done": {
              "type": "boolean"
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        },
        "operation_id": {
          "type": "string"
        },
        "operation_url": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "phase": {
          "type": "string"
        },
        "already": {
          "type": "boolean"
        },
        "queued": {
          "type": "boolean"
        },
        "task": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string"
            },
            "state": {
              "type": "string"
            },
            "status": {
              "type": "string"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number"
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "error": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "createdAt": {
              "type": "string"
            },
            "updatedAt": {
              "type": "string"
            },
            "finishedAt": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id"
          ],
          "additionalProperties": true
        }
      },
      "required": [
        "ok"
      ],
      "additionalProperties": true
    },
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "operation": {
          "type": "object",
          "properties": {
            "id": {
              "type": "string"
            },
            "kind": {
              "type": "string",
              "enum": [
                "deployment",
                "vps",
                "dedicated"
              ]
            },
            "action": {
              "type": "string"
            },
            "status": {
              "type": "string",
              "enum": [
                "pending",
                "running",
                "succeeded",
                "failed",
                "cancelled",
                "unknown"
              ]
            },
            "done": {
              "type": "boolean"
            },
            "progress": {
              "anyOf": [
                {
                  "type": "number",
                  "minimum": 0,
                  "maximum": 100
                },
                {
                  "type": "null"
                }
              ]
            },
            "stage": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "created_at": {
              "type": "string",
              "format": "date-time"
            },
            "updated_at": {
              "anyOf": [
                {
                  "type": "string",
                  "format": "date-time"
                },
                {
                  "type": "null"
                }
              ]
            },
            "service_ids": {
              "type": "array",
              "items": {
                "type": "string",
                "format": "uuid"
              }
            },
            "error": {
              "anyOf": [
                {
                  "type": "object",
                  "properties": {
                    "code": {
                      "type": "string"
                    },
                    "message": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "code",
                    "message"
                  ],
                  "additionalProperties": false
                },
                {
                  "type": "null"
                }
              ]
            },
            "result": {
              "anyOf": [
                {
                  "anyOf": [
                    {
                      "type": "object",
                      "properties": {
                        "service_ids": {
                          "type": "array",
                          "items": {
                            "type": "string",
                            "format": "uuid"
                          },
                          "minItems": 1,
                          "maxItems": 50
                        },
                        "order_id": {
                          "anyOf": [
                            {
                              "type": "string",
                              "format": "uuid"
                            },
                            {
                              "type": "null"
                            }
                          ]
                        },
                        "invoice_id": {
                          "type": "string",
                          "format": "uuid"
                        }
                      },
                      "required": [
                        "service_ids"
                      ],
                      "additionalProperties": false
                    },
                    {
                      "type": "object",
                      "properties": {
                        "service_id": {
                          "type": "string",
                          "format": "uuid"
                        },
                        "os": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "snapshot_name": {
                          "type": "string",
                          "minLength": 1,
                          "maxLength": 160,
                          "pattern": "^[A-Za-z0-9._:-]+$"
                        },
                        "power_state": {
                          "type": "string",
                          "enum": [
                            "running",
                            "stopped"
                          ]
                        }
                      },
                      "required": [
                        "service_id"
                      ],
                      "additionalProperties": false
                    }
                  ]
                },
                {
                  "type": "null"
                }
              ]
            }
          },
          "required": [
            "id",
            "kind",
            "action",
            "status",
            "done",
            "progress",
            "stage",
            "created_at",
            "updated_at",
            "service_ids",
            "error"
          ],
          "additionalProperties": false
        },
        "links": {
          "type": "object",
          "properties": {
            "operation": {
              "type": "string",
              "pattern": "^\\/v1\\/operations\\/op_[A-Za-z0-9_-]+$"
            },
            "service": {
              "type": "string",
              "pattern": "^\\/v1\\/services\\/[0-9a-f-]{36}$"
            },
            "invoice": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/invoices\\/[0-9a-f-]{36}$"
            },
            "order": {
              "type": "string",
              "pattern": "^\\/v1\\/billing\\/orders\\/[0-9a-f-]{36}$"
            }
          },
          "required": [
            "operation"
          ],
          "additionalProperties": false
        }
      },
      "required": [
        "ok",
        "operation"
      ],
      "additionalProperties": false
    }
  ],
  "description": "Legacy response by default; x-bf-response-format: operation opts into the canonical receipt when durable operations are enabled. Retries retain the initial cached response format."
}

Illustrative successful response

{
  "ok": true,
  "operation": {
    "id": "00000000-0000-4000-8000-000000000002",
    "state": "waiting_provider"
  },
  "operation_id": "op_EXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLE",
  "operation_url": "/v1/operations/op_EXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLE"
}

API reference and code examples

GET/v1/dedicated/{serviceId}/rescue-optionsList compatible rescue images

Operation ID: dedicatedRescueOptions

Read compatible numeric rescue profile IDs before requesting maintenance boot.

Required scopes: dedicated.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "enabled": {
      "type": "boolean"
    },
    "profiles": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              }
            ]
          },
          "name": {
            "type": "string"
          },
          "allowSshKeys": {
            "type": "boolean"
          },
          "version": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "family": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "enabled": {
            "type": "boolean"
          }
        },
        "required": [
          "id",
          "name"
        ],
        "additionalProperties": true
      }
    },
    "currentProfileId": {
      "anyOf": [
        {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "number"
            }
          ]
        },
        {
          "type": "null"
        }
      ]
    }
  },
  "required": [
    "ok",
    "enabled",
    "profiles"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "enabled": true,
  "profiles": [
    {
      "id": 2,
      "name": "Example rescue image"
    }
  ]
}

API reference and code examples

GET/v1/dedicated/{serviceId}/tasksList dedicated tasks

Operation ID: dedicatedTasks

Returns customer-visible operations for the owned server. Read history before repeating an uncertain action.

Required scopes: dedicated.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "tasks": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "kind": {
            "type": "string"
          },
          "state": {
            "type": "string"
          },
          "status": {
            "type": "string"
          },
          "progress": {
            "anyOf": [
              {
                "type": "number"
              },
              {
                "type": "null"
              }
            ]
          },
          "stage": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "error": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "createdAt": {
            "type": "string"
          },
          "updatedAt": {
            "type": "string"
          },
          "finishedAt": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          }
        },
        "required": [
          "id"
        ],
        "additionalProperties": true
      }
    }
  },
  "required": [
    "ok",
    "tasks"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "tasks": [
    {
      "id": "00000000-0000-4000-8000-000000000002",
      "kind": "reinstall",
      "status": "in_progress",
      "stage": "installing",
      "errorCode": null,
      "createdAt": "2026-10-01T00:00:00.000Z",
      "updatedAt": "2026-10-01T00:00:00.000Z"
    }
  ]
}

API reference and code examples

GET/v1/dedicated/{serviceId}/tasks/{taskId}Check dedicated task

Operation ID: dedicatedTask

Returns bounded customer-safe status for a power or maintenance task.

Required scopes: dedicated.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • taskId · path · required — Dedicated operation UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "task": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "kind": {
          "type": "string"
        },
        "state": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "progress": {
          "anyOf": [
            {
              "type": "number"
            },
            {
              "type": "null"
            }
          ]
        },
        "stage": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "error": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "createdAt": {
          "type": "string"
        },
        "updatedAt": {
          "type": "string"
        },
        "finishedAt": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        }
      },
      "required": [
        "id"
      ],
      "additionalProperties": true
    }
  },
  "required": [
    "ok",
    "task"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "task": {
    "id": "00000000-0000-4000-8000-000000000002",
    "kind": "reinstall",
    "status": "in_progress",
    "stage": "installing",
    "errorCode": null,
    "createdAt": "2026-10-01T00:00:00.000Z",
    "updatedAt": "2026-10-01T00:00:00.000Z"
  }
}

API reference and code examples

GET/v1/dedicated/{serviceId}/trafficRead network traffic

Operation ID: getDedicatedByServiceIdTraffic

Returns available network samples. Rates are bits per second and traffic totals are bytes. Missing statistics are not zero traffic. Does not report guest resource usage.

Required scopes: dedicated.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "available": {
      "type": "boolean"
    },
    "period": {
      "type": "string"
    },
    "interfaces": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "points": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "time": {
                  "type": "string"
                },
                "timestamp": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "number"
                    }
                  ]
                },
                "bytesIn": {
                  "type": "number"
                },
                "bytesOut": {
                  "type": "number"
                },
                "rx": {
                  "type": "number"
                },
                "tx": {
                  "type": "number"
                },
                "watts": {
                  "anyOf": [
                    {
                      "type": "number"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "value": {
                  "anyOf": [
                    {
                      "type": "number"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "connections": {
                  "type": "number"
                },
                "errors": {
                  "type": "number"
                },
                "blockedPackets": {
                  "type": "number"
                }
              },
              "additionalProperties": true
            }
          },
          "rx": {
            "type": "number"
          },
          "tx": {
            "type": "number"
          }
        },
        "additionalProperties": true
      }
    }
  },
  "required": [
    "ok",
    "available",
    "period",
    "interfaces"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "available": false,
  "period": "24h",
  "interfaces": []
}

API reference and code examples

GET/v1/dedicated/catalogBrowse dedicated inventory

Operation ID: dedicatedCatalog

Returns currently sellable configurations, regions, hardware, billing periods, and compatible operating-system profiles.

Required scopes: dedicated.read

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "code": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "region": {
            "type": "object",
            "properties": {
              "code": {
                "type": "string"
              },
              "name": {
                "type": "string"
              },
              "operatingSystems": {
                "type": "array",
                "items": {
                  "type": "object",
                  "properties": {
                    "id": {
                      "anyOf": [
                        {
                          "type": "string"
                        },
                        {
                          "type": "number"
                        }
                      ]
                    },
                    "code": {
                      "type": "string"
                    },
                    "name": {
                      "type": "string"
                    },
                    "family": {
                      "anyOf": [
                        {
                          "type": "string"
                        },
                        {
                          "type": "null"
                        }
                      ]
                    },
                    "version": {
                      "anyOf": [
                        {
                          "type": "string"
                        },
                        {
                          "type": "null"
                        }
                      ]
                    },
                    "arch": {
                      "anyOf": [
                        {
                          "type": "string"
                        },
                        {
                          "type": "null"
                        }
                      ]
                    },
                    "isDefault": {
                      "type": "boolean"
                    },
                    "allowSshKeys": {
                      "type": "boolean"
                    }
                  },
                  "additionalProperties": true
                }
              }
            },
            "required": [
              "code"
            ],
            "additionalProperties": true
          },
          "hardware": {
            "type": "object",
            "properties": {
              "lineName": {
                "type": "string"
              },
              "cpuSockets": {
                "type": "number"
              },
              "ramGb": {
                "type": "number"
              },
              "storageGb": {
                "type": "number"
              },
              "linkGbps": {
                "type": "number"
              },
              "physicalLinkGbps": {
                "type": "number"
              },
              "cpuDescription": {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "ramDescription": {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "storageDescription": {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "null"
                  }
                ]
              }
            },
            "additionalProperties": true
          },
          "availableStock": {
            "anyOf": [
              {
                "type": "number"
              },
              {
                "type": "null"
              }
            ]
          },
          "osProfiles": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "id": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "number"
                    }
                  ]
                },
                "name": {
                  "type": "string"
                },
                "allowSshKeys": {
                  "type": "boolean"
                },
                "version": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "family": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "enabled": {
                  "type": "boolean"
                }
              },
              "required": [
                "id",
                "name"
              ],
              "additionalProperties": true
            }
          },
          "billingProductId": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "billingVariantId": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          }
        },
        "required": [
          "code"
        ],
        "additionalProperties": true
      }
    }
  },
  "required": [
    "ok",
    "items"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "items": []
}

API reference and code examples

POST/v1/dedicated/deploymentsCreate dedicated deployment

Operation ID: dedicatedDeploy

Creates an unpaid order and invoice using catalog configurationCode, regionCode, numeric osProfileId, hostname, optional owned sshKeyId, billing and selectable add-ons. Use order-options to discover valid add-on keys and quantities, and preview the same complete configuration before ordering. Provisioning begins only after payment and any configured approval. Never invent configuration or OS IDs.

Required scopes: dedicated.write

Parameters

  • Idempotency-Key · header · required — Stable action key: 8–128 letters, digits, dot, underscore, colon or hyphen. Reuse the same key and payload on retries; inspect task state after a timeout.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "configuration_code": {
      "type": "string",
      "minLength": 1,
      "maxLength": 160
    },
    "region_code": {
      "type": "string",
      "pattern": "^[A-Z0-9-]{2,16}$"
    },
    "os_profile_id": {
      "type": "integer",
      "exclusiveMinimum": 0
    },
    "hostname": {
      "type": "string",
      "minLength": 1,
      "maxLength": 253,
      "pattern": "^(?=.{1,253}$)[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)*$"
    },
    "ssh_key_id": {
      "type": "string",
      "format": "uuid"
    },
    "addons": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "key": {
            "type": "string",
            "minLength": 1,
            "maxLength": 120,
            "pattern": "^[A-Za-z0-9_.:-]+$"
          },
          "qty": {
            "type": "integer",
            "minimum": 1,
            "maximum": 100
          }
        },
        "required": [
          "key",
          "qty"
        ],
        "additionalProperties": false
      },
      "maxItems": 50
    },
    "currency": {
      "type": "string",
      "enum": [
        "USD",
        "EUR",
        "UAH",
        "GBP",
        "PLN",
        "BRL",
        "INR",
        "IDR",
        "CNY"
      ],
      "default": "EUR"
    },
    "billing": {
      "type": "object",
      "properties": {
        "unit": {
          "type": "string",
          "enum": [
            "MONTH",
            "QUARTAL",
            "SEMIANNUAL",
            "YEAR"
          ],
          "default": "MONTH"
        },
        "count": {
          "type": "integer",
          "minimum": 1,
          "maximum": 120,
          "default": 1
        }
      },
      "additionalProperties": false,
      "default": {
        "unit": "MONTH",
        "count": 1
      }
    }
  },
  "required": [
    "configuration_code",
    "region_code",
    "os_profile_id",
    "hostname"
  ],
  "additionalProperties": false
}

Successful response · HTTP 201

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "orderId": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "invoiceId": {
      "type": "string"
    },
    "invoiceNumber": {
      "type": "string"
    },
    "invoice": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "number": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "total": {
          "type": "string"
        },
        "paidTotal": {
          "type": "string"
        },
        "currency": {
          "type": "string"
        },
        "createdAt": {
          "type": "string"
        },
        "dueDate": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "payDate": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "refundedTotal": {
          "type": "string"
        }
      },
      "required": [
        "id",
        "number",
        "status",
        "total",
        "paidTotal",
        "currency"
      ],
      "additionalProperties": true
    },
    "total": {
      "type": "string"
    },
    "currency": {
      "type": "string"
    },
    "status": {
      "type": "string"
    },
    "paymentStatus": {
      "type": "string"
    },
    "serviceIds": {
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "message": {
      "type": "string"
    },
    "deploymentStatusUrl": {
      "type": "string"
    },
    "applied": {
      "type": "boolean"
    },
    "payNow": {
      "type": "string"
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "orderId": "00000000-0000-4000-8000-000000000001",
  "invoiceId": "00000000-0000-4000-8000-000000000002",
  "invoiceNumber": "INV-EXAMPLE-000001",
  "total": "100.00",
  "currency": "EUR",
  "status": "unpaid",
  "deploymentStatusUrl": "/v1/dedicated/deployments/00000000-0000-4000-8000-000000000001",
  "message": "Invoice created. Provisioning begins after payment and any configured approval."
}

API reference and code examples

GET/v1/dedicated/deployments/{orderId}Check deployment

Operation ID: dedicatedDeployment

Returns payment, provisioning, service, IP, power, OS, and operation state for a dedicated order without exposing its password.

Required scopes: dedicated.read

Parameters

  • orderId · path · required — Dedicated deployment order UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "deployment": {
      "type": "object",
      "properties": {
        "orderId": {
          "type": "string"
        },
        "orderStatus": {
          "type": "string"
        },
        "paymentStatus": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "invoice": {
          "anyOf": [
            {
              "type": "object",
              "properties": {
                "id": {
                  "type": "string"
                },
                "number": {
                  "type": "string"
                },
                "status": {
                  "type": "string"
                },
                "total": {
                  "type": "string"
                },
                "paidTotal": {
                  "type": "string"
                },
                "currency": {
                  "type": "string"
                },
                "createdAt": {
                  "type": "string"
                },
                "dueDate": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "payDate": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "refundedTotal": {
                  "type": "string"
                }
              },
              "required": [
                "id",
                "number",
                "status",
                "total",
                "paidTotal",
                "currency"
              ],
              "additionalProperties": true
            },
            {
              "type": "null"
            }
          ]
        },
        "serviceId": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "serviceStatus": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "ip": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "power": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "hostname": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "osName": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "operations": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "id": {
                "type": "string"
              },
              "type": {
                "type": "string"
              },
              "kind": {
                "type": "string"
              },
              "state": {
                "type": "string"
              },
              "phase": {
                "type": "string"
              },
              "progress": {
                "anyOf": [
                  {
                    "type": "number"
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "stage": {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "status": {
                "type": "string"
              },
              "done": {
                "type": "boolean"
              },
              "createdAt": {
                "type": "string"
              },
              "updatedAt": {
                "type": "string"
              }
            },
            "required": [
              "id"
            ],
            "additionalProperties": true
          }
        }
      },
      "required": [
        "orderId",
        "orderStatus",
        "paymentStatus",
        "invoice",
        "serviceId",
        "serviceStatus",
        "ip",
        "power",
        "hostname",
        "osName",
        "operations"
      ],
      "additionalProperties": true
    }
  },
  "required": [
    "ok",
    "deployment"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "deployment": {
    "orderId": "00000000-0000-4000-8000-000000000001",
    "orderStatus": "pending",
    "paymentStatus": "unpaid",
    "invoice": {
      "id": "00000000-0000-4000-8000-000000000001",
      "number": "INV-EXAMPLE-000001",
      "status": "unpaid",
      "total": "100.00",
      "paidTotal": "0.00",
      "currency": "EUR"
    },
    "serviceId": null,
    "serviceStatus": null,
    "ip": null,
    "power": null,
    "hostname": null,
    "osName": null,
    "operations": []
  }
}

API reference and code examples

DNS

GET/v1/dns/templatesBrowse DNS templates

Operation ID: listDnsTemplates

Returns reusable DNS templates that can be applied during zone creation.

Required scopes: dns.read

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "templates": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "description": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "records": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "name": {
                  "type": "string"
                },
                "type": {
                  "type": "string"
                },
                "ttl": {
                  "type": "number"
                },
                "values": {
                  "type": "array",
                  "items": {
                    "type": "string"
                  }
                },
                "proxied": {
                  "type": "boolean"
                },
                "originValues": {
                  "anyOf": [
                    {
                      "type": "array",
                      "items": {
                        "type": "string"
                      }
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "protection": {
                  "type": "boolean"
                }
              },
              "required": [
                "name",
                "type",
                "ttl",
                "values"
              ],
              "additionalProperties": true
            }
          },
          "rrsets": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "name": {
                  "type": "string"
                },
                "type": {
                  "type": "string"
                },
                "ttl": {
                  "type": "number"
                },
                "records": {
                  "type": "array",
                  "items": {
                    "type": "object",
                    "properties": {
                      "content": {
                        "type": "string"
                      },
                      "disabled": {
                        "type": "boolean"
                      }
                    },
                    "required": [
                      "content"
                    ],
                    "additionalProperties": true
                  }
                },
                "changetype": {
                  "type": "string"
                },
                "comments": {
                  "type": "array",
                  "items": {
                    "type": "object",
                    "properties": {
                      "content": {
                        "type": "string"
                      },
                      "account": {
                        "type": "string"
                      },
                      "modified_at": {
                        "type": "number"
                      }
                    },
                    "additionalProperties": true
                  }
                }
              },
              "required": [
                "name",
                "type",
                "ttl",
                "records"
              ],
              "additionalProperties": true
            }
          },
          "createdAt": {
            "type": "string"
          },
          "updatedAt": {
            "type": "string"
          },
          "system": {
            "type": "boolean"
          },
          "visibility": {
            "type": "string"
          },
          "isHidden": {
            "type": "boolean"
          }
        },
        "required": [
          "id",
          "name"
        ],
        "additionalProperties": true
      }
    }
  },
  "required": [
    "ok",
    "templates"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "templates": [
    {
      "id": "00000000-0000-4000-8000-000000000001",
      "name": "Example template",
      "createdAt": "2026-10-01T00:00:00.000Z",
      "updatedAt": "2026-10-01T00:00:00.000Z",
      "system": false,
      "visibility": "private",
      "isHidden": false
    }
  ]
}

API reference and code examples

POST/v1/dns/templatesSave DNS template

Operation ID: dnsTemplateCreate

Creates a reusable DNS template from a zone-file fragment.

Required scopes: dns.write

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 64
    },
    "zone_file": {
      "type": "string",
      "minLength": 1,
      "maxLength": 500000
    }
  },
  "required": [
    "name",
    "zone_file"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "template": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "name": {
          "type": "string"
        },
        "description": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "records": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "name": {
                "type": "string"
              },
              "type": {
                "type": "string"
              },
              "ttl": {
                "type": "number"
              },
              "values": {
                "type": "array",
                "items": {
                  "type": "string"
                }
              },
              "proxied": {
                "type": "boolean"
              },
              "originValues": {
                "anyOf": [
                  {
                    "type": "array",
                    "items": {
                      "type": "string"
                    }
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "protection": {
                "type": "boolean"
              }
            },
            "required": [
              "name",
              "type",
              "ttl",
              "values"
            ],
            "additionalProperties": true
          }
        },
        "rrsets": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "name": {
                "type": "string"
              },
              "type": {
                "type": "string"
              },
              "ttl": {
                "type": "number"
              },
              "records": {
                "type": "array",
                "items": {
                  "type": "object",
                  "properties": {
                    "content": {
                      "type": "string"
                    },
                    "disabled": {
                      "type": "boolean"
                    }
                  },
                  "required": [
                    "content"
                  ],
                  "additionalProperties": true
                }
              },
              "changetype": {
                "type": "string"
              },
              "comments": {
                "type": "array",
                "items": {
                  "type": "object",
                  "properties": {
                    "content": {
                      "type": "string"
                    },
                    "account": {
                      "type": "string"
                    },
                    "modified_at": {
                      "type": "number"
                    }
                  },
                  "additionalProperties": true
                }
              }
            },
            "required": [
              "name",
              "type",
              "ttl",
              "records"
            ],
            "additionalProperties": true
          }
        },
        "createdAt": {
          "type": "string"
        },
        "updatedAt": {
          "type": "string"
        },
        "system": {
          "type": "boolean"
        },
        "visibility": {
          "type": "string"
        },
        "isHidden": {
          "type": "boolean"
        }
      },
      "required": [
        "id",
        "name"
      ],
      "additionalProperties": true
    }
  },
  "required": [
    "ok",
    "template"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "template": {
    "id": "00000000-0000-4000-8000-000000000001",
    "name": "Example template",
    "zoneFile": "@ 300 IN A 192.0.2.10",
    "createdAt": "2026-10-01T00:00:00.000Z",
    "updatedAt": "2026-10-01T00:00:00.000Z",
    "system": false,
    "visibility": "private"
  }
}

API reference and code examples

DELETE/v1/dns/templates/{id}Remove DNS template

Operation ID: dnsTemplateDelete

Deletes a DNS template.

Required scopes: dns.write

Parameters

  • id · path · required — DNS template UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true
}

API reference and code examples

GET/v1/dns/templates/{id}Open DNS template

Operation ID: getDnsTemplate

Returns an owned or public system template by name or UUID. Name matching is case-insensitive and checks your templates first; public system defaults are a fallback. Other accounts are excluded. Only duplicate names within the selected scope return template_identifier_ambiguous. Edit/delete routes still require UUIDs.

Required scopes: dns.read

Parameters

  • id · path · required — Your template name (cpanel2 or My template) or UUID; URL-encode spaces and Unicode.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "template": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "name": {
          "type": "string"
        },
        "description": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "records": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "name": {
                "type": "string"
              },
              "type": {
                "type": "string"
              },
              "ttl": {
                "type": "number"
              },
              "values": {
                "type": "array",
                "items": {
                  "type": "string"
                }
              },
              "proxied": {
                "type": "boolean"
              },
              "originValues": {
                "anyOf": [
                  {
                    "type": "array",
                    "items": {
                      "type": "string"
                    }
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "protection": {
                "type": "boolean"
              }
            },
            "required": [
              "name",
              "type",
              "ttl",
              "values"
            ],
            "additionalProperties": true
          }
        },
        "rrsets": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "name": {
                "type": "string"
              },
              "type": {
                "type": "string"
              },
              "ttl": {
                "type": "number"
              },
              "records": {
                "type": "array",
                "items": {
                  "type": "object",
                  "properties": {
                    "content": {
                      "type": "string"
                    },
                    "disabled": {
                      "type": "boolean"
                    }
                  },
                  "required": [
                    "content"
                  ],
                  "additionalProperties": true
                }
              },
              "changetype": {
                "type": "string"
              },
              "comments": {
                "type": "array",
                "items": {
                  "type": "object",
                  "properties": {
                    "content": {
                      "type": "string"
                    },
                    "account": {
                      "type": "string"
                    },
                    "modified_at": {
                      "type": "number"
                    }
                  },
                  "additionalProperties": true
                }
              }
            },
            "required": [
              "name",
              "type",
              "ttl",
              "records"
            ],
            "additionalProperties": true
          }
        },
        "createdAt": {
          "type": "string"
        },
        "updatedAt": {
          "type": "string"
        },
        "system": {
          "type": "boolean"
        },
        "visibility": {
          "type": "string"
        },
        "isHidden": {
          "type": "boolean"
        }
      },
      "required": [
        "id",
        "name"
      ],
      "additionalProperties": true
    }
  },
  "required": [
    "ok",
    "template"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "template": {
    "id": "00000000-0000-4000-8000-000000000001",
    "name": "Example template",
    "zoneFile": "@ 300 IN A 192.0.2.10",
    "createdAt": "2026-10-01T00:00:00.000Z",
    "updatedAt": "2026-10-01T00:00:00.000Z",
    "system": false,
    "visibility": "private"
  }
}

API reference and code examples

PATCH/v1/dns/templates/{id}Edit DNS template

Operation ID: dnsTemplateUpdate

Updates the name or zone-file content of an existing template.

Required scopes: dns.write

Parameters

  • id · path · required — DNS template UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 64
    },
    "zone_file": {
      "type": "string",
      "minLength": 1,
      "maxLength": 500000
    }
  },
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "template": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "name": {
          "type": "string"
        },
        "description": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "records": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "name": {
                "type": "string"
              },
              "type": {
                "type": "string"
              },
              "ttl": {
                "type": "number"
              },
              "values": {
                "type": "array",
                "items": {
                  "type": "string"
                }
              },
              "proxied": {
                "type": "boolean"
              },
              "originValues": {
                "anyOf": [
                  {
                    "type": "array",
                    "items": {
                      "type": "string"
                    }
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "protection": {
                "type": "boolean"
              }
            },
            "required": [
              "name",
              "type",
              "ttl",
              "values"
            ],
            "additionalProperties": true
          }
        },
        "rrsets": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "name": {
                "type": "string"
              },
              "type": {
                "type": "string"
              },
              "ttl": {
                "type": "number"
              },
              "records": {
                "type": "array",
                "items": {
                  "type": "object",
                  "properties": {
                    "content": {
                      "type": "string"
                    },
                    "disabled": {
                      "type": "boolean"
                    }
                  },
                  "required": [
                    "content"
                  ],
                  "additionalProperties": true
                }
              },
              "changetype": {
                "type": "string"
              },
              "comments": {
                "type": "array",
                "items": {
                  "type": "object",
                  "properties": {
                    "content": {
                      "type": "string"
                    },
                    "account": {
                      "type": "string"
                    },
                    "modified_at": {
                      "type": "number"
                    }
                  },
                  "additionalProperties": true
                }
              }
            },
            "required": [
              "name",
              "type",
              "ttl",
              "records"
            ],
            "additionalProperties": true
          }
        },
        "createdAt": {
          "type": "string"
        },
        "updatedAt": {
          "type": "string"
        },
        "system": {
          "type": "boolean"
        },
        "visibility": {
          "type": "string"
        },
        "isHidden": {
          "type": "boolean"
        }
      },
      "required": [
        "id",
        "name"
      ],
      "additionalProperties": true
    }
  },
  "required": [
    "ok",
    "template"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "template": {
    "id": "00000000-0000-4000-8000-000000000001",
    "name": "Example template",
    "zoneFile": "@ 300 IN A 192.0.2.10",
    "createdAt": "2026-10-01T00:00:00.000Z",
    "updatedAt": "2026-10-01T00:00:00.000Z",
    "system": false,
    "visibility": "private"
  }
}

API reference and code examples

GET/v1/dns/zonesBrowse DNS zones

Operation ID: listDnsZones

Returns owned customer DNS zones. Use view=summary for a lightweight, read-only inventory with name search before pagination; it returns total, limit, offset and zones. The default legacy view remains unchanged. Summary results sort by zone name and do not contact nameservers or change billing links.

Required scopes: dns.read

Parameters

  • q · query — Optional zone name search filter.
  • sort · query — Optional legacy-view sort key; summary always sorts by name.
  • view · query — Use summary for lightweight paginated zone cards.
  • limit · query — Summary only: maximum zones returned.
  • offset · query — Summary only: number of matching zones to skip.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "zones": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string"
          },
          "status": {
            "type": "string"
          },
          "createdAt": {
            "type": "string"
          }
        },
        "required": [
          "name",
          "status",
          "createdAt"
        ],
        "additionalProperties": true
      }
    }
  },
  "required": [
    "ok",
    "zones"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "zones": [
    {
      "name": "example.com",
      "status": "active",
      "createdAt": "2026-10-01T00:00:00.000Z"
    }
  ]
}

API reference and code examples

POST/v1/dns/zonesCreate or preview DNS zone

Operation ID: createDnsZone

Body: name; at most one of templateId UUID, zoneFile text (100000 characters max), or records array ({name,type,ttl,values}, max 200 sets, 50 values/set, TTL 1–86400 seconds). Omit all sources for an empty zone. dryRun:true validates and returns records/notes without creating or reserving a zone; requires an existing active DNS service. Use separate Idempotency-Keys for preview and creation. Platform apex NS replaces imported NS and SOA is managed automatically. Zone files support IN records, relative names, $ORIGIN, $TTL and multiline records; external includes/generation and foreign owners are rejected. Resolve template names via GET /v1/dns/templates and inspect their details; templates must be owned or public. Existing zones are never overwritten. A records may be proxied by the existing protection policy. Does not register domains or change registrar delegation.

Required scopes: dns.write

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 253
    },
    "template_id": {
      "type": "string",
      "format": "uuid"
    },
    "zone_file": {
      "type": "string",
      "minLength": 1,
      "maxLength": 100000
    },
    "records": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string",
            "minLength": 1,
            "maxLength": 253
          },
          "type": {
            "type": "string",
            "enum": [
              "A",
              "AAAA",
              "CNAME",
              "MX",
              "TXT",
              "NS",
              "SOA",
              "PTR",
              "SRV",
              "CAA",
              "SSHFP",
              "TLSA",
              "NAPTR",
              "LOC",
              "DS",
              "DNSKEY"
            ]
          },
          "ttl": {
            "type": "integer",
            "minimum": 1,
            "maximum": 86400
          },
          "values": {
            "type": "array",
            "items": {
              "type": "string",
              "minLength": 1,
              "maxLength": 4096
            },
            "minItems": 1,
            "maxItems": 50
          }
        },
        "required": [
          "name",
          "type",
          "values"
        ],
        "additionalProperties": false
      },
      "maxItems": 200
    },
    "dry_run": {
      "type": "boolean"
    }
  },
  "required": [
    "name"
  ],
  "additionalProperties": false,
  "description": "At most one of templateId, zoneFile or records. Omit all three for an empty zone. Names and record ownership are validated by the backend."
}

Successful response · HTTP 200

{
  "anyOf": [
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "zoneId": {
          "type": "string"
        },
        "zone": {
          "$ref": "#/$defs/JsonValue"
        }
      },
      "required": [
        "ok",
        "zoneId",
        "zone"
      ],
      "additionalProperties": true
    },
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "dryRun": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "name": {
          "type": "string"
        },
        "records": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "name": {
                "type": "string"
              },
              "type": {
                "type": "string"
              },
              "ttl": {
                "type": "number"
              },
              "values": {
                "type": "array",
                "items": {
                  "type": "string"
                }
              },
              "proxied": {
                "type": "boolean"
              },
              "originValues": {
                "anyOf": [
                  {
                    "type": "array",
                    "items": {
                      "type": "string"
                    }
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "protection": {
                "type": "boolean"
              }
            },
            "required": [
              "name",
              "type",
              "ttl",
              "values"
            ],
            "additionalProperties": true
          }
        },
        "notes": {
          "type": "array",
          "items": {
            "type": "string"
          }
        }
      },
      "required": [
        "ok",
        "dryRun",
        "name",
        "records",
        "notes"
      ],
      "additionalProperties": true
    }
  ],
  "$defs": {
    "JsonValue": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "number"
        },
        {
          "type": "boolean"
        },
        {
          "type": "null"
        },
        {
          "type": "array",
          "items": {
            "$ref": "#/$defs/JsonValue"
          }
        },
        {
          "type": "object",
          "additionalProperties": {
            "$ref": "#/$defs/JsonValue"
          }
        }
      ]
    }
  }
}

Illustrative successful response

{
  "ok": true,
  "zoneId": "00000000-0000-4000-8000-000000000001",
  "zone": null
}

API reference and code examples

DELETE/v1/dns/zones/{name}Remove DNS zone

Operation ID: dnsZoneDelete

Deletes a DNS zone.

Required scopes: dns.write

Parameters

  • name · path · required — Zone or domain name.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true
}

API reference and code examples

GET/v1/dns/zones/{name}Open DNS zone

Operation ID: getDnsZone

Returns one DNS zone and its customer-facing detail view.

Required scopes: dns.read

Parameters

  • name · path · required — Zone or domain name.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "domain": {
      "type": "object",
      "properties": {
        "name": {
          "type": "string"
        },
        "zoneId": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "adminLock": {
          "type": "boolean"
        },
        "createdAt": {
          "type": "string"
        },
        "updatedAt": {
          "type": "string"
        }
      },
      "required": [
        "name",
        "zoneId",
        "status",
        "adminLock",
        "createdAt",
        "updatedAt"
      ],
      "additionalProperties": true
    }
  },
  "required": [
    "ok",
    "domain"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "domain": {
    "name": "example.com",
    "zoneId": "00000000-0000-4000-8000-000000000001",
    "status": "active",
    "adminLock": false,
    "createdAt": "2026-10-01T00:00:00.000Z",
    "updatedAt": "2026-10-01T00:00:00.000Z"
  }
}

API reference and code examples

GET/v1/dns/zones/{name}/country-policyRead website country policy

Operation ID: getDnsCountryPolicy

For an owned, active, proxied A record.

Required scopes: dns.read

Parameters

  • name · path · required — Zone or domain name.
  • record · query — Record name; default @.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "hostname": {
      "type": "string"
    },
    "policy": {
      "type": "object",
      "properties": {
        "mode": {
          "type": "string"
        },
        "countries": {
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "unknown": {
          "type": "string"
        },
        "whitelist_bypass": {
          "type": "boolean"
        }
      },
      "required": [
        "mode",
        "countries",
        "unknown",
        "whitelist_bypass"
      ],
      "additionalProperties": true
    },
    "saved": {
      "type": "boolean"
    },
    "synchronized": {
      "type": "boolean"
    }
  },
  "required": [
    "ok",
    "hostname",
    "policy"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "hostname": "example.com",
  "policy": {
    "mode": "off",
    "countries": [],
    "unknown": "allow",
    "whitelist_bypass": true
  }
}

API reference and code examples

PUT/v1/dns/zones/{name}/country-policyReplace website country policy

Operation ID: dnsCountryPolicySet

Body: record and policy containing mode (off/allow/deny), countries (ISO alpha-2), optional unknown (allow/deny) and whitelist_bypass. Replacement can block visitors. Send an Idempotency-Key. Check saved and synchronized independently.

Required scopes: dns.write

Parameters

  • name · path · required — Zone or domain name.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "record": {
      "type": "string",
      "minLength": 1,
      "maxLength": 253
    },
    "policy": {
      "type": "object",
      "properties": {
        "mode": {
          "type": "string",
          "enum": [
            "off",
            "allow",
            "deny"
          ]
        },
        "countries": {
          "type": "array",
          "items": {
            "type": "string"
          },
          "maxItems": 249,
          "default": []
        },
        "unknown": {
          "type": "string",
          "enum": [
            "allow",
            "deny"
          ]
        },
        "whitelist_bypass": {
          "type": "boolean",
          "default": false
        }
      },
      "required": [
        "mode"
      ],
      "additionalProperties": false
    }
  },
  "required": [
    "record",
    "policy"
  ],
  "additionalProperties": false,
  "description": "Use valid ISO alpha-2 country codes. allow/deny requires at least one country; off disables the policy."
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "hostname": {
      "type": "string"
    },
    "policy": {
      "type": "object",
      "properties": {
        "mode": {
          "type": "string"
        },
        "countries": {
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "unknown": {
          "type": "string"
        },
        "whitelist_bypass": {
          "type": "boolean"
        }
      },
      "required": [
        "mode",
        "countries",
        "unknown",
        "whitelist_bypass"
      ],
      "additionalProperties": true
    },
    "saved": {
      "type": "boolean"
    },
    "synchronized": {
      "type": "boolean"
    }
  },
  "required": [
    "ok",
    "hostname",
    "policy"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "hostname": "example.com",
  "policy": {
    "mode": "off",
    "countries": [],
    "unknown": "allow",
    "whitelist_bypass": true
  },
  "saved": true,
  "synchronized": true
}

API reference and code examples

GET/v1/dns/zones/{name}/historyList DNS change history

Operation ID: dnsHistory

Owned-zone changes with DNS values and protection state. Stable cursor continuation; only this owner’s history is returned.

Required scopes: dns.read

Parameters

  • name · path · required — Zone or domain name.
  • limit · query — Maximum changes (default 10; 1–50).
  • cursor · query — nextCursor returned by the preceding response; scoped to this owner and zone.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "nextCursor": {
      "anyOf": [
        {
          "type": "string",
          "maxLength": 2048
        },
        {
          "type": "null"
        }
      ]
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "format": "uuid"
          },
          "action": {
            "type": "string",
            "maxLength": 100
          },
          "status": {
            "type": "string",
            "maxLength": 30
          },
          "actorType": {
            "type": "string",
            "maxLength": 30
          },
          "restoredFromId": {
            "anyOf": [
              {
                "type": "string",
                "format": "uuid"
              },
              {
                "type": "null"
              }
            ]
          },
          "changes": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "name": {
                  "type": "string",
                  "maxLength": 253
                },
                "type": {
                  "type": "string",
                  "maxLength": 16
                },
                "changetype": {
                  "type": "string",
                  "maxLength": 16
                },
                "beforeTtl": {
                  "anyOf": [
                    {
                      "type": "integer"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "afterTtl": {
                  "anyOf": [
                    {
                      "type": "integer"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "beforeValues": {
                  "type": "array",
                  "items": {
                    "type": "string",
                    "maxLength": 65535
                  },
                  "maxItems": 1000
                },
                "afterValues": {
                  "type": "array",
                  "items": {
                    "type": "string",
                    "maxLength": 65535
                  },
                  "maxItems": 1000
                }
              },
              "required": [
                "name",
                "type",
                "changetype",
                "beforeTtl",
                "afterTtl",
                "beforeValues",
                "afterValues"
              ],
              "additionalProperties": false
            },
            "maxItems": 1000
          },
          "protectionChanges": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "name": {
                  "type": "string",
                  "maxLength": 253
                },
                "before": {
                  "anyOf": [
                    {
                      "type": "object",
                      "properties": {
                        "proxied": {
                          "type": "boolean"
                        },
                        "protection": {
                          "type": "boolean"
                        },
                        "values": {
                          "type": "array",
                          "items": {
                            "type": "string",
                            "maxLength": 253
                          },
                          "maxItems": 1000
                        }
                      },
                      "required": [
                        "proxied",
                        "protection",
                        "values"
                      ],
                      "additionalProperties": false
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "after": {
                  "anyOf": [
                    {
                      "type": "object",
                      "properties": {
                        "proxied": {
                          "type": "boolean"
                        },
                        "protection": {
                          "type": "boolean"
                        },
                        "values": {
                          "type": "array",
                          "items": {
                            "type": "string",
                            "maxLength": 253
                          },
                          "maxItems": 1000
                        }
                      },
                      "required": [
                        "proxied",
                        "protection",
                        "values"
                      ],
                      "additionalProperties": false
                    },
                    {
                      "type": "null"
                    }
                  ]
                }
              },
              "required": [
                "name",
                "before",
                "after"
              ],
              "additionalProperties": false
            },
            "maxItems": 1000
          },
          "beforeRecordCount": {
            "type": "integer",
            "minimum": 0
          },
          "afterRecordCount": {
            "type": "integer",
            "minimum": 0
          },
          "createdAt": {
            "type": "string",
            "format": "date-time"
          }
        },
        "required": [
          "id",
          "action",
          "status",
          "actorType",
          "restoredFromId",
          "changes",
          "protectionChanges",
          "beforeRecordCount",
          "afterRecordCount",
          "createdAt"
        ],
        "additionalProperties": false
      },
      "maxItems": 50
    }
  },
  "required": [
    "ok",
    "nextCursor",
    "items"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "items": [
    {
      "id": "00000000-0000-4000-8000-000000000002",
      "action": "records.update",
      "status": "applied",
      "actorType": "userapi",
      "restoredFromId": null,
      "changes": [
        {
          "name": "example.com.",
          "type": "A",
          "changetype": "REPLACE",
          "beforeTtl": 300,
          "afterTtl": 300,
          "beforeValues": [
            "192.0.2.9"
          ],
          "afterValues": [
            "192.0.2.10"
          ]
        }
      ],
      "protectionChanges": [],
      "beforeRecordCount": 3,
      "afterRecordCount": 3,
      "createdAt": "2026-10-01T00:00:00.000Z"
    }
  ],
  "nextCursor": null
}

API reference and code examples

POST/v1/dns/zones/{name}/history/{changeId}/restoreRestore DNS change

Operation ID: dnsHistoryRestore

Restores the state before the selected applied change, including protection and origin addresses. Requires acknowledgement, a stable retry key and current entitlements. A locked or ambiguous zone is not modified.

Required scopes: dns.write

Parameters

  • name · path · required — Zone or domain name.
  • changeId · path · required — Owned DNS change UUID.
  • Idempotency-Key · header · required — Stable retry key.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "acknowledge": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    }
  },
  "required": [
    "acknowledge"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "anyOf": [
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "already": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        }
      },
      "required": [
        "ok",
        "already"
      ],
      "additionalProperties": false
    },
    {
      "type": "object",
      "properties": {
        "ok": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "appliedTo": {
          "type": "string",
          "enum": [
            "snapshot",
            "live_dns"
          ]
        },
        "changeId": {
          "type": "string",
          "format": "uuid"
        },
        "restoredFromId": {
          "type": "string",
          "format": "uuid"
        }
      },
      "required": [
        "ok",
        "appliedTo",
        "changeId",
        "restoredFromId"
      ],
      "additionalProperties": false
    }
  ]
}

Illustrative successful response

{
  "ok": true,
  "appliedTo": "live_dns",
  "changeId": "00000000-0000-4000-8000-000000000001",
  "restoredFromId": "00000000-0000-4000-8000-000000000002"
}

API reference and code examples

GET/v1/dns/zones/{name}/recordsBrowse raw rrsets

Operation ID: getDnsRrsets

Returns advanced rrset data for customers that need lower-level DNS editing.

Required scopes: dns.read

Parameters

  • name · path · required — Zone or domain name.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "source": {
      "type": "string"
    },
    "rrsets": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string"
          },
          "type": {
            "type": "string"
          },
          "ttl": {
            "type": "number"
          },
          "records": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "content": {
                  "type": "string"
                },
                "disabled": {
                  "type": "boolean"
                }
              },
              "required": [
                "content"
              ],
              "additionalProperties": true
            }
          },
          "changetype": {
            "type": "string"
          },
          "comments": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "content": {
                  "type": "string"
                },
                "account": {
                  "type": "string"
                },
                "modified_at": {
                  "type": "number"
                }
              },
              "additionalProperties": true
            }
          }
        },
        "required": [
          "name",
          "type",
          "ttl",
          "records"
        ],
        "additionalProperties": true
      }
    }
  },
  "required": [
    "ok",
    "source",
    "rrsets"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "source": "powerdns",
  "rrsets": [
    {
      "name": "example.com.",
      "type": "A",
      "ttl": 300,
      "records": [
        {
          "content": "192.0.2.10",
          "disabled": false
        }
      ]
    }
  ]
}

API reference and code examples

PATCH/v1/dns/zones/{name}/recordsApply rrset changes

Operation ID: dnsRrsetsPatch

Applies advanced rrset changes using REPLACE or DELETE style operations.

Required scopes: dns.write

Parameters

  • name · path · required — Zone or domain name.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "rrsets": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string",
            "minLength": 1,
            "maxLength": 253
          },
          "type": {
            "type": "string",
            "minLength": 1,
            "maxLength": 16
          },
          "ttl": {
            "type": "integer",
            "minimum": 0,
            "maximum": 2147483647
          },
          "changetype": {
            "type": "string",
            "enum": [
              "REPLACE",
              "DELETE"
            ]
          },
          "records": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "content": {
                  "type": "string"
                },
                "disabled": {
                  "type": "boolean"
                }
              },
              "required": [
                "content"
              ],
              "additionalProperties": false
            }
          }
        },
        "required": [
          "name",
          "type"
        ],
        "additionalProperties": false
      }
    }
  },
  "required": [
    "rrsets"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "appliedTo": {
      "type": "string"
    },
    "changeId": {
      "type": "string"
    }
  },
  "required": [
    "ok",
    "appliedTo"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "appliedTo": "powerdns",
  "changeId": "00000000-0000-4000-8000-000000000002"
}

API reference and code examples

GET/v1/dns/zones/{name}/records/configRead Website Protection record settings

Operation ID: dnsRecordConfig

Read-only safe HTTPS/origin and custom-loader flags for an active, owned, proxied A record. No service UUID or domain registration is needed. Unknown flags are null; no raw provider configuration, scripts or keys are exposed.

Required scopes: dns.read

Parameters

  • name · path · required — Zone or domain name.
  • name · query — Record name, e.g. @ or www.; default @.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "settings": {
      "type": "object",
      "properties": {
        "ssl_schema": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "force_ssl": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "ssl": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "custom_loader": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        }
      },
      "required": [
        "ssl_schema",
        "force_ssl",
        "ssl",
        "custom_loader"
      ],
      "additionalProperties": true
    },
    "domain": {
      "type": "string"
    },
    "name": {
      "type": "string"
    }
  },
  "required": [
    "ok",
    "settings"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "domain": "example.com",
  "name": "www",
  "settings": {
    "ssl_schema": "https",
    "force_ssl": "1",
    "ssl": "ecc",
    "custom_loader": "0"
  }
}

API reference and code examples

GET/v1/dns/zones/{name}/records/protectionRead DNS record protection

Operation ID: getDnsRecordProtection

Read saved mitigation state for an owned, active, proxied A record, including external origins. No hosting service ID required. Null protection/stateUnknown must not be interpreted as disabled.

Required scopes: dns.read

Parameters

  • name · path · required — Zone or domain name.
  • name · query — A record name; default @.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "fqdn": {
      "type": "string",
      "description": "Lowercase hostname without a trailing root dot, for example example.com. Inputs accept either form. DNS RRset names and record values retain DNS notation."
    },
    "type": {
      "type": "string"
    },
    "proxied": {
      "type": "boolean"
    },
    "protection": {
      "type": "boolean"
    },
    "originValues": {
      "anyOf": [
        {
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        {
          "type": "null"
        }
      ]
    },
    "ttl": {
      "type": "number"
    },
    "stateUnknown": {
      "type": "boolean"
    },
    "pending": {
      "type": "boolean"
    },
    "lastSyncedAt": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "changeId": {
      "type": "string"
    }
  },
  "required": [
    "ok",
    "fqdn",
    "type",
    "proxied",
    "protection"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "fqdn": "example.com",
  "type": "A",
  "proxied": true,
  "protection": true,
  "originValues": [
    "192.0.2.10"
  ],
  "ttl": 300,
  "stateUnknown": false,
  "pending": false,
  "lastSyncedAt": "2026-10-01T00:00:00.000Z"
}

API reference and code examples

POST/v1/dns/zones/{name}/records/protectionChange DNS record protection

Operation ID: dnsRecordProtectionSet

Toggle mitigation only; preserves proxy routing, origin addresses, DNS values and TTL. Enabling requires an active entitlement or eligible origin IPs. Send an Idempotency-Key. MCP requests require dashboard approval. A failed/unconfirmed response may have changed provider state; never assume it did not execute.

Required scopes: dns.write

Parameters

  • name · path · required — Zone or domain name.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 253
    },
    "enabled": {
      "type": "boolean"
    }
  },
  "required": [
    "name",
    "enabled"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "fqdn": {
      "type": "string",
      "description": "Lowercase hostname without a trailing root dot, for example example.com. Inputs accept either form. DNS RRset names and record values retain DNS notation."
    },
    "type": {
      "type": "string"
    },
    "proxied": {
      "type": "boolean"
    },
    "protection": {
      "type": "boolean"
    },
    "originValues": {
      "anyOf": [
        {
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        {
          "type": "null"
        }
      ]
    },
    "ttl": {
      "type": "number"
    },
    "stateUnknown": {
      "type": "boolean"
    },
    "pending": {
      "type": "boolean"
    },
    "lastSyncedAt": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "changeId": {
      "type": "string"
    }
  },
  "required": [
    "ok",
    "fqdn",
    "type",
    "proxied",
    "protection"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "fqdn": "example.com",
  "type": "A",
  "proxied": true,
  "protection": true,
  "stateUnknown": false,
  "changeId": "00000000-0000-4000-8000-000000000002"
}

API reference and code examples

DELETE/v1/dns/zones/{name}/records/simpleRemove simple record

Operation ID: dnsRecordsSimpleDelete

Deletes a simplified DNS record set from the zone.

Required scopes: dns.write

Parameters

  • name · path · required — Zone or domain name.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 253
    },
    "type": {
      "type": "string",
      "minLength": 1,
      "maxLength": 16
    }
  },
  "required": [
    "name",
    "type"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "appliedTo": {
      "type": "string"
    },
    "changeId": {
      "type": "string"
    }
  },
  "required": [
    "ok",
    "appliedTo"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "appliedTo": "powerdns",
  "changeId": "00000000-0000-4000-8000-000000000002"
}

API reference and code examples

GET/v1/dns/zones/{name}/records/simpleBrowse simple records

Operation ID: listDnsRecordsSimple

Returns simplified DNS records for a zone.

Required scopes: dns.read

Parameters

  • name · path · required — Zone or domain name.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "service": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "suspendedReason": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        }
      },
      "required": [
        "id",
        "status",
        "suspendedReason"
      ],
      "additionalProperties": true
    },
    "records": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string"
          },
          "type": {
            "type": "string"
          },
          "ttl": {
            "type": "number"
          },
          "values": {
            "type": "array",
            "items": {
              "type": "string"
            }
          },
          "proxied": {
            "type": "boolean"
          },
          "originValues": {
            "anyOf": [
              {
                "type": "array",
                "items": {
                  "type": "string"
                }
              },
              {
                "type": "null"
              }
            ]
          },
          "protection": {
            "type": "boolean"
          }
        },
        "required": [
          "name",
          "type",
          "ttl",
          "values"
        ],
        "additionalProperties": true
      }
    }
  },
  "required": [
    "ok",
    "service",
    "records"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "service": {
    "id": "00000000-0000-4000-8000-000000000001",
    "status": "active",
    "suspendedReason": null
  },
  "records": [
    {
      "name": "@",
      "type": "A",
      "ttl": 300,
      "values": [
        "192.0.2.10"
      ],
      "proxied": false,
      "originValues": null,
      "protection": false,
      "wafEligible": false,
      "protectionMode": "none"
    }
  ]
}

API reference and code examples

POST/v1/dns/zones/{name}/records/simpleSave simple record

Operation ID: dnsRecordsSimpleSet

Creates or replaces a simplified DNS record set.

Required scopes: dns.write

Parameters

  • name · path · required — Zone or domain name.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "mode": {
      "type": "string",
      "enum": [
        "append",
        "replace"
      ]
    },
    "record": {
      "type": "object",
      "properties": {
        "name": {
          "type": "string",
          "minLength": 1,
          "maxLength": 253
        },
        "type": {
          "type": "string",
          "minLength": 1,
          "maxLength": 16
        },
        "ttl": {
          "type": "integer",
          "minimum": 1,
          "maximum": 86400
        },
        "values": {
          "type": "array",
          "items": {
            "type": "string"
          },
          "minItems": 1,
          "maxItems": 50
        },
        "protect": {
          "type": "boolean"
        }
      },
      "required": [
        "name",
        "type",
        "values"
      ],
      "additionalProperties": false
    }
  },
  "required": [
    "record"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "appliedTo": {
      "type": "string"
    },
    "changeId": {
      "type": "string"
    }
  },
  "required": [
    "ok",
    "appliedTo"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "appliedTo": "powerdns",
  "changeId": "00000000-0000-4000-8000-000000000002"
}

API reference and code examples

Service DNS/WAF

GET/v1/dns/zones/{name}/statsRead Website Protection statistics

Operation ID: dnsStats

Website Protection (WAF) traffic aggregates for your owned zone and subdomains, bounded to current ownership. This compatibility route does not report authoritative DNS query statistics. Requests, bytes, latency, cache-hit percentage, decisions, countries and automation categories. No individual visitor identities or raw logs. Missing collection is an error, not zero traffic.

Required scopes: dns.read

Parameters

  • name · path · required — Zone or domain name.
  • range · query — Window; defaults to 24h.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "domain": {
      "type": "string",
      "maxLength": 253
    },
    "range": {
      "type": "string",
      "enum": [
        "1h",
        "24h",
        "7d"
      ]
    },
    "since": {
      "type": "string",
      "format": "date-time"
    },
    "until": {
      "type": "string",
      "format": "date-time"
    },
    "updatedAt": {
      "type": "string",
      "format": "date-time"
    },
    "lastEventAt": {
      "anyOf": [
        {
          "type": "string",
          "format": "date-time"
        },
        {
          "type": "null"
        }
      ]
    },
    "coverage": {
      "type": "string",
      "const": "proxy_network",
      "enum": [
        "proxy_network"
      ]
    },
    "coverageNote": {
      "type": "string",
      "maxLength": 300
    },
    "summary": {
      "type": "object",
      "properties": {
        "requests": {
          "type": "number",
          "minimum": 0
        },
        "bytes": {
          "type": "number",
          "minimum": 0
        },
        "averageResponseMs": {
          "type": "number",
          "minimum": 0
        },
        "cacheHitPercent": {
          "type": "number",
          "minimum": 0,
          "maximum": 100
        },
        "serverErrors": {
          "type": "number",
          "minimum": 0
        },
        "blocked": {
          "type": "number",
          "minimum": 0
        }
      },
      "required": [
        "requests",
        "bytes",
        "averageResponseMs",
        "cacheHitPercent",
        "serverErrors",
        "blocked"
      ],
      "additionalProperties": false
    },
    "traffic": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "at": {
            "type": "string",
            "format": "date-time"
          },
          "requests": {
            "type": "number",
            "minimum": 0
          },
          "bytes": {
            "type": "number",
            "minimum": 0
          }
        },
        "required": [
          "at",
          "requests",
          "bytes"
        ],
        "additionalProperties": false
      },
      "maxItems": 300
    },
    "countries": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string",
            "maxLength": 128
          },
          "requests": {
            "type": "number",
            "minimum": 0
          }
        },
        "required": [
          "name",
          "requests"
        ],
        "additionalProperties": false
      },
      "maxItems": 250
    },
    "automation": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string",
            "maxLength": 128
          },
          "requests": {
            "type": "number",
            "minimum": 0
          }
        },
        "required": [
          "name",
          "requests"
        ],
        "additionalProperties": false
      },
      "maxItems": 250
    },
    "statuses": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string",
            "maxLength": 128
          },
          "requests": {
            "type": "number",
            "minimum": 0
          }
        },
        "required": [
          "name",
          "requests"
        ],
        "additionalProperties": false
      },
      "maxItems": 250
    },
    "decisions": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string",
            "maxLength": 128
          },
          "requests": {
            "type": "number",
            "minimum": 0
          }
        },
        "required": [
          "name",
          "requests"
        ],
        "additionalProperties": false
      },
      "maxItems": 250
    }
  },
  "required": [
    "ok",
    "domain",
    "range",
    "since",
    "until",
    "updatedAt",
    "lastEventAt",
    "coverage",
    "coverageNote",
    "summary",
    "traffic",
    "countries",
    "automation",
    "statuses",
    "decisions"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "domain": "example.com",
  "range": "24h",
  "since": "2026-10-01T00:00:00.000Z",
  "until": "2026-11-01T00:00:00.000Z",
  "updatedAt": "2026-10-01T00:00:00.000Z",
  "lastEventAt": null,
  "coverage": "proxy_network",
  "coverageNote": "Proxy traffic only.",
  "summary": {
    "requests": 0,
    "bytes": 0,
    "averageResponseMs": 0,
    "cacheHitPercent": 0,
    "serverErrors": 0,
    "blocked": 0
  },
  "traffic": [],
  "countries": [],
  "automation": [],
  "statuses": [],
  "decisions": []
}

API reference and code examples

GET/v1/services/{serviceId}/dns/wafCheck DNS/WAF eligibility

Operation ID: serviceDnsWafStatus

Returns the protection mode and service eligibility for DNS proxy and WAF-related actions on the selected service.

Required scopes: dns.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "serviceId": {
      "type": "string"
    },
    "serviceStatus": {
      "type": "string"
    },
    "backendIpv4": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "dnsWaf": {
      "type": "object",
      "properties": {
        "serviceId": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "active": {
          "type": "boolean"
        }
      },
      "required": [
        "serviceId",
        "active"
      ],
      "additionalProperties": true
    },
    "free": {
      "type": "object",
      "properties": {
        "eligible": {
          "type": "boolean"
        }
      },
      "required": [
        "eligible"
      ],
      "additionalProperties": true
    },
    "eligible": {
      "type": "boolean"
    },
    "mode": {
      "type": "string"
    }
  },
  "required": [
    "ok",
    "serviceId",
    "serviceStatus",
    "backendIpv4",
    "dnsWaf",
    "free",
    "eligible",
    "mode"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "serviceId": "00000000-0000-4000-8000-000000000001",
  "serviceStatus": "active",
  "backendIpv4": "192.0.2.10",
  "dnsWaf": {
    "serviceId": null,
    "active": false
  },
  "free": {
    "eligible": true
  },
  "eligible": true,
  "mode": "free"
}

API reference and code examples

GET/v1/services/{serviceId}/dns/waf/recordInspect protected record

Operation ID: getServiceDnsWafRecord

Returns the current proxy, protection, and origin values for one service-scoped DNS record.

Required scopes: dns.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • domain · query · required — Zone or apex domain for the protected record.
  • name · query · required — Record name such as @ or www.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "serviceId": {
      "type": "string"
    },
    "serviceStatus": {
      "type": "string"
    },
    "backendIpv4": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "domain": {
      "type": "string"
    },
    "record": {
      "type": "object",
      "properties": {
        "name": {
          "type": "string"
        },
        "type": {
          "type": "string"
        },
        "ttl": {
          "type": "number"
        },
        "values": {
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "proxied": {
          "type": "boolean"
        },
        "originValues": {
          "anyOf": [
            {
              "type": "array",
              "items": {
                "type": "string"
              }
            },
            {
              "type": "null"
            }
          ]
        },
        "protection": {
          "type": "boolean"
        }
      },
      "required": [
        "name",
        "type",
        "ttl",
        "values"
      ],
      "additionalProperties": true
    }
  },
  "required": [
    "ok",
    "serviceId",
    "serviceStatus",
    "backendIpv4",
    "domain",
    "record"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "serviceId": "00000000-0000-4000-8000-000000000001",
  "serviceStatus": "active",
  "backendIpv4": "192.0.2.10",
  "domain": "example.com",
  "record": {
    "name": "example.com.",
    "type": "A",
    "ttl": 300,
    "values": [
      "192.0.2.10"
    ],
    "proxied": false,
    "originValues": null,
    "protection": false
  }
}

API reference and code examples

POST/v1/services/{serviceId}/dns/waf/record/origin-syncRun origin sync

Operation ID: serviceDnsWafRecordOriginSync

Refreshes the protected record origin target so the proxy backend follows the current service IP.

Required scopes: dns.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "minLength": 1
    },
    "name": {
      "type": "string",
      "minLength": 1
    }
  },
  "required": [
    "domain",
    "name"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "fqdn": {
      "type": "string",
      "description": "Lowercase hostname without a trailing root dot, for example example.com. Inputs accept either form. DNS RRset names and record values retain DNS notation."
    },
    "backendIpv4": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    }
  },
  "required": [
    "ok",
    "fqdn",
    "backendIpv4"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "fqdn": "example.com",
  "backendIpv4": "192.0.2.10"
}

API reference and code examples

POST/v1/services/{serviceId}/dns/waf/record/protectionToggle protection mode

Operation ID: serviceDnsWafRecordProtection

Enables or disables the protection layer for a proxied record.

Required scopes: dns.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "minLength": 1
    },
    "name": {
      "type": "string",
      "minLength": 1
    },
    "enabled": {
      "type": "boolean"
    }
  },
  "required": [
    "domain",
    "name",
    "enabled"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "fqdn": {
      "type": "string",
      "description": "Lowercase hostname without a trailing root dot, for example example.com. Inputs accept either form. DNS RRset names and record values retain DNS notation."
    },
    "protection": {
      "type": "boolean"
    }
  },
  "required": [
    "ok",
    "fqdn",
    "protection"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "fqdn": "example.com",
  "protection": true
}

API reference and code examples

POST/v1/services/{serviceId}/dns/waf/record/proxyToggle proxy mode

Operation ID: serviceDnsWafRecordProxy

Enables or disables proxy mode for a service-scoped record. This is the main action for moving a record behind the managed proxy layer.

Required scopes: dns.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "minLength": 1
    },
    "name": {
      "type": "string",
      "minLength": 1
    },
    "enabled": {
      "type": "boolean"
    },
    "ttl": {
      "type": "integer",
      "minimum": 1,
      "maximum": 86400
    }
  },
  "required": [
    "domain",
    "name",
    "enabled"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "appliedTo": {
      "type": "string"
    },
    "proxied": {
      "type": "boolean"
    },
    "providerBackends": {
      "type": "array",
      "items": {
        "type": "string"
      }
    }
  },
  "required": [
    "ok",
    "appliedTo",
    "proxied"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "appliedTo": "powerdns",
  "proxied": true,
  "providerBackends": [
    "192.0.2.10"
  ]
}

API reference and code examples

POST/v1/services/{serviceId}/dns/waf/record/proxy-config/get-loaderView custom loader

Operation ID: serviceDnsWafProxyConfigGetLoader

Returns the currently configured custom loader or response page for a protected record.

Required scopes: dns.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "minLength": 1
    },
    "name": {
      "type": "string",
      "minLength": 1
    }
  },
  "required": [
    "domain",
    "name"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "data": {
      "$ref": "#/$defs/JsonValue"
    },
    "html": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    }
  },
  "required": [
    "ok",
    "data"
  ],
  "additionalProperties": true,
  "$defs": {
    "JsonValue": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "number"
        },
        {
          "type": "boolean"
        },
        {
          "type": "null"
        },
        {
          "type": "array",
          "items": {
            "$ref": "#/$defs/JsonValue"
          }
        },
        {
          "type": "object",
          "additionalProperties": {
            "$ref": "#/$defs/JsonValue"
          }
        }
      ]
    }
  }
}

Illustrative successful response

{
  "ok": true,
  "data": null
}

API reference and code examples

POST/v1/services/{serviceId}/dns/waf/record/proxy-config/get-sslView SSL settings

Operation ID: serviceDnsWafProxyConfigGetSsl

Returns certificate metadata and configuration readiness for the selected protected record. ready confirms a matching, currently valid certificate in the provider configuration; it does not confirm public DNS propagation or browser trust. Provider lookup failures return a safe error.

Required scopes: dns.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "minLength": 1
    },
    "name": {
      "type": "string",
      "minLength": 1
    }
  },
  "required": [
    "domain",
    "name"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "data": {
      "anyOf": [
        {
          "type": "object",
          "properties": {
            "hasCert": {
              "type": "boolean"
            },
            "ready": {
              "type": "boolean"
            },
            "status": {
              "type": "string",
              "enum": [
                "ready",
                "missing",
                "invalid",
                "expired",
                "not_yet_valid",
                "disabled",
                "pending",
                "unknown"
              ]
            },
            "mode": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "readiness_scope": {
              "type": "string",
              "const": "certificate_configuration",
              "enum": [
                "certificate_configuration"
              ]
            },
            "cert": {
              "type": "object",
              "properties": {
                "subject": {
                  "type": "string"
                },
                "issuer": {
                  "type": "string"
                },
                "validFrom": {
                  "type": "string"
                },
                "validTo": {
                  "type": "string"
                },
                "fingerprint256": {
                  "type": "string"
                },
                "serialNumber": {
                  "type": "string"
                },
                "subjectAltName": {
                  "type": "string"
                }
              },
              "required": [
                "subject",
                "issuer"
              ],
              "additionalProperties": true
            }
          },
          "required": [
            "hasCert"
          ],
          "additionalProperties": true
        },
        {
          "type": "null"
        }
      ]
    }
  },
  "required": [
    "ok",
    "data"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "data": {
    "hasCert": true,
    "ready": true,
    "status": "ready",
    "mode": "c",
    "readiness_scope": "certificate_configuration",
    "cert": {
      "subject": "CN=example.com",
      "issuer": "CN=Example CA",
      "validFrom": "2026-10-01T00:00:00.000Z",
      "validTo": "2027-10-06T00:00:00.000Z",
      "fingerprint256": "AA:BB:CC"
    }
  }
}

API reference and code examples

POST/v1/services/{serviceId}/dns/waf/record/proxy-config/showView proxy settings

Operation ID: serviceDnsWafProxyConfigShow

Returns the proxy configuration for an owned proxied record. Accepts an owned DNS zone name or service UUID. With a zone-name selector, domain is optional and must match when supplied; name defaults to @. Prefer the read-only GET /v1/dns/zones/{name}/records/config. This legacy POST can ensure proxy registration.

Required scopes: dns.read

Parameters

  • serviceId · path · required — Your DNS zone name (example.com) or an owned service UUID. A name selects the owned zone directly; a UUID also requires domain in the query/body.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "minLength": 1,
      "maxLength": 1024
    },
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 253,
      "default": "@"
    }
  },
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "data": {
      "$ref": "#/$defs/JsonValue"
    },
    "html": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    }
  },
  "required": [
    "ok",
    "data"
  ],
  "additionalProperties": true,
  "$defs": {
    "JsonValue": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "number"
        },
        {
          "type": "boolean"
        },
        {
          "type": "null"
        },
        {
          "type": "array",
          "items": {
            "$ref": "#/$defs/JsonValue"
          }
        },
        {
          "type": "object",
          "additionalProperties": {
            "$ref": "#/$defs/JsonValue"
          }
        }
      ]
    }
  }
}

Illustrative successful response

{
  "ok": true,
  "data": null
}

API reference and code examples

POST/v1/services/{serviceId}/dns/waf/record/proxy-config/update-settingChange proxy setting

Operation ID: serviceDnsWafProxyConfigUpdateSetting

Changes one supported proxy setting such as force SSL, SSL mode, or custom loader behavior.

Required scopes: dns.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "minLength": 1
    },
    "name": {
      "type": "string",
      "minLength": 1
    },
    "option": {
      "type": "string",
      "enum": [
        "ssl_schema",
        "force_ssl",
        "ssl",
        "custom_loader"
      ]
    },
    "value": {
      "type": "string",
      "minLength": 1
    }
  },
  "required": [
    "domain",
    "name",
    "option",
    "value"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true
}

API reference and code examples

POST/v1/services/{serviceId}/dns/waf/record/proxy-config/upload-loaderUpload custom loader

Operation ID: serviceDnsWafProxyConfigUploadLoader

Uploads custom HTML used by the proxy layer for the selected record.

Required scopes: dns.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "minLength": 1
    },
    "name": {
      "type": "string",
      "minLength": 1
    },
    "html": {
      "type": "string",
      "minLength": 1
    }
  },
  "required": [
    "domain",
    "name",
    "html"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "data": {
      "$ref": "#/$defs/JsonValue"
    },
    "html": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    }
  },
  "required": [
    "ok",
    "data"
  ],
  "additionalProperties": true,
  "$defs": {
    "JsonValue": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "number"
        },
        {
          "type": "boolean"
        },
        {
          "type": "null"
        },
        {
          "type": "array",
          "items": {
            "$ref": "#/$defs/JsonValue"
          }
        },
        {
          "type": "object",
          "additionalProperties": {
            "$ref": "#/$defs/JsonValue"
          }
        }
      ]
    }
  }
}

Illustrative successful response

{
  "ok": true,
  "data": null,
  "html": "<!doctype html><title>Loading</title>"
}

API reference and code examples

POST/v1/services/{serviceId}/dns/waf/record/proxy-config/upload-sslUpload custom SSL certificate

Operation ID: serviceDnsWafProxyConfigUploadSsl

Validates the hostname, validity dates, certificate chain syntax and matching private key before uploading. Domains may be configured before DNS points to the proxy. Returns certificate configuration readiness and expected_fingerprint256 after readback. pending or unknown means the accepted upload is not yet confirmed; check get-ssl before retrying. Private key material is never returned.

Required scopes: dns.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "minLength": 1
    },
    "name": {
      "type": "string",
      "minLength": 1
    },
    "mode": {
      "type": "string",
      "enum": [
        "c",
        "w"
      ]
    },
    "cert": {
      "type": "string",
      "minLength": 1
    },
    "pkey": {
      "type": "string",
      "minLength": 1
    },
    "bundle": {
      "type": "string",
      "default": ""
    }
  },
  "required": [
    "domain",
    "name",
    "mode",
    "cert",
    "pkey"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "data": {
      "type": "object",
      "properties": {
        "hasCert": {
          "type": "boolean"
        },
        "ready": {
          "type": "boolean"
        },
        "status": {
          "type": "string",
          "enum": [
            "ready",
            "missing",
            "invalid",
            "expired",
            "not_yet_valid",
            "disabled",
            "pending",
            "unknown"
          ]
        },
        "mode": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "readiness_scope": {
          "type": "string",
          "const": "certificate_configuration",
          "enum": [
            "certificate_configuration"
          ]
        },
        "cert": {
          "type": "object",
          "properties": {
            "subject": {
              "type": "string"
            },
            "issuer": {
              "type": "string"
            },
            "validFrom": {
              "type": "string"
            },
            "validTo": {
              "type": "string"
            },
            "fingerprint256": {
              "type": "string"
            },
            "serialNumber": {
              "type": "string"
            },
            "subjectAltName": {
              "type": "string"
            }
          },
          "required": [
            "subject",
            "issuer"
          ],
          "additionalProperties": true
        }
      },
      "required": [
        "hasCert"
      ],
      "additionalProperties": true
    },
    "expected_fingerprint256": {
      "type": "string"
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "data": {
    "hasCert": false,
    "ready": false,
    "status": "pending",
    "mode": "c",
    "readiness_scope": "certificate_configuration"
  },
  "expected_fingerprint256": "AA:BB:CC"
}

API reference and code examples

Domains

GET/v1/domainsBrowse domains

Operation ID: listDomains

Returns domain services already attached to the customer account.

Required scopes: domains.read

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "domains": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "domain": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "status": {
            "type": "string"
          },
          "dueDate": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "serviceId": {
            "type": "string"
          }
        },
        "required": [
          "id"
        ],
        "additionalProperties": true
      }
    }
  },
  "required": [
    "ok",
    "domains"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "domains": []
}

API reference and code examples

GET/v1/domains/{serviceId}Open domain detail

Operation ID: getDomain

Returns the current detail view for one domain service.

Required scopes: domains.read

Parameters

  • serviceId · path · required — Your registered domain name (example.com) or service UUID. Names are case-insensitive and normalized to IDNA ASCII; one trailing dot is accepted. Exact matches are restricted to your non-terminated domain services. Multiple matches return domain_identifier_ambiguous; use the UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "service_id": {
      "type": "string"
    },
    "domain_name": {
      "type": "string"
    },
    "service": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "status": {
          "type": "string"
        },
        "hostname": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "displayName": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "region": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "sku": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "productName": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "ipv4": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "ipv6": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "dueDate": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "createdAt": {
          "type": "string"
        }
      },
      "required": [
        "id"
      ],
      "additionalProperties": true
    },
    "domain": {
      "anyOf": [
        {
          "type": "object",
          "additionalProperties": {
            "$ref": "#/$defs/JsonValue"
          }
        },
        {
          "type": "null"
        }
      ]
    }
  },
  "required": [
    "ok",
    "service_id",
    "domain_name",
    "service",
    "domain"
  ],
  "additionalProperties": true,
  "$defs": {
    "JsonValue": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "number"
        },
        {
          "type": "boolean"
        },
        {
          "type": "null"
        },
        {
          "type": "array",
          "items": {
            "$ref": "#/$defs/JsonValue"
          }
        },
        {
          "type": "object",
          "additionalProperties": {
            "$ref": "#/$defs/JsonValue"
          }
        }
      ]
    }
  }
}

Illustrative successful response

{
  "ok": true,
  "service_id": "00000000-0000-4000-8000-000000000001",
  "domain_name": "example.com",
  "service": {
    "id": "00000000-0000-4000-8000-000000000001",
    "status": "active"
  },
  "domain": null
}

API reference and code examples

GET/v1/domains/{serviceId}/auth-codeView transfer code

Operation ID: domainAuthCode

Returns the current transfer authorization code when available.

Required scopes: domains.read

Parameters

  • serviceId · path · required — Your registered domain name (example.com) or service UUID. Names are case-insensitive and normalized to IDNA ASCII; one trailing dot is accepted. Exact matches are restricted to your non-terminated domain services. Multiple matches return domain_identifier_ambiguous; use the UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "auth_code": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    }
  },
  "required": [
    "ok",
    "auth_code"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "auth_code": "<transfer-code>"
}

API reference and code examples

PUT/v1/domains/{serviceId}/contactsAssign contacts

Operation ID: domainAssignContacts

Assigns registrant, admin, tech, or billing contacts to a domain service.

Required scopes: domains.write

Parameters

  • serviceId · path · required — Your registered domain name (example.com) or service UUID. Names are case-insensitive and normalized to IDNA ASCII; one trailing dot is accepted. Exact matches are restricted to your non-terminated domain services. Multiple matches return domain_identifier_ambiguous; use the UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "contact_ids": {
      "type": "object",
      "properties": {
        "registrant": {
          "type": "string",
          "format": "uuid"
        },
        "admin": {
          "type": "string",
          "format": "uuid"
        },
        "tech": {
          "type": "string",
          "format": "uuid"
        },
        "billing": {
          "type": "string",
          "format": "uuid"
        }
      },
      "additionalProperties": false
    }
  },
  "required": [
    "contact_ids"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true
}

API reference and code examples

GET/v1/domains/{serviceId}/dnssecRead DNSSEC status

Operation ID: domainDnssec

Returns the locally saved DNSSEC state for your registered domain. Use action refresh to check current registration state. Zone signing and parent propagation are separate from enabled registration status.

Required scopes: domains.read

Parameters

  • serviceId · path · required — Your registered domain name (example.com) or service UUID. Names are case-insensitive and normalized to IDNA ASCII; one trailing dot is accepted. Exact matches are restricted to your non-terminated domain services. Multiple matches return domain_identifier_ambiguous; use the UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "domain": {
      "type": "string",
      "maxLength": 253
    },
    "tld": {
      "type": "string",
      "maxLength": 253
    },
    "service_id": {
      "type": "string",
      "format": "uuid"
    },
    "domain_name": {
      "anyOf": [
        {
          "type": "string",
          "maxLength": 253
        },
        {
          "type": "null"
        }
      ]
    },
    "support": {
      "type": "string",
      "enum": [
        "supported",
        "unsupported",
        "unknown"
      ]
    },
    "nameservers": {
      "type": "array",
      "items": {
        "type": "string",
        "maxLength": 253
      },
      "maxItems": 13
    },
    "keys": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "flags": {
            "type": "number",
            "const": 257,
            "enum": [
              257
            ]
          },
          "protocol": {
            "type": "number",
            "const": 3,
            "enum": [
              3
            ]
          },
          "alg": {
            "type": "integer"
          },
          "pub_key": {
            "type": "string",
            "minLength": 40,
            "maxLength": 4096,
            "pattern": "^[A-Za-z0-9+/]+={0,2}$"
          }
        },
        "required": [
          "flags",
          "protocol",
          "alg",
          "pub_key"
        ],
        "additionalProperties": false
      },
      "maxItems": 32
    },
    "status": {
      "type": "string",
      "enum": [
        "registrar_configured",
        "not_configured"
      ]
    },
    "delegationStatus": {
      "type": "string",
      "const": "not_verified",
      "enum": [
        "not_verified"
      ]
    },
    "dnsProvider": {
      "type": "string",
      "enum": [
        "managed",
        "external"
      ]
    },
    "canEnable": {
      "type": "boolean"
    },
    "canDisable": {
      "type": "boolean"
    },
    "enabled": {
      "type": "boolean"
    },
    "checkedAt": {
      "type": "string",
      "format": "date-time"
    },
    "operation": {
      "type": "string",
      "enum": [
        "idle",
        "pending",
        "queued",
        "running",
        "unconfirmed",
        "failed"
      ]
    },
    "operationId": {
      "type": "string",
      "format": "uuid"
    },
    "requestedAction": {
      "type": "string",
      "enum": [
        "enable",
        "disable"
      ]
    },
    "operationUpdatedAt": {
      "type": "string",
      "format": "date-time"
    },
    "errorCode": {
      "type": "string",
      "maxLength": 80
    },
    "source": {
      "type": "string",
      "const": "local",
      "enum": [
        "local"
      ]
    }
  },
  "required": [
    "ok",
    "domain",
    "tld",
    "support",
    "nameservers",
    "keys",
    "status",
    "delegationStatus",
    "dnsProvider",
    "canEnable",
    "canDisable",
    "enabled",
    "checkedAt",
    "operation",
    "source"
  ],
  "additionalProperties": false
}

Illustrative successful response

{
  "ok": true,
  "domain": "example.com",
  "tld": "com",
  "support": "supported",
  "nameservers": [
    "dns1.blazingfast.io",
    "dns2.blazingfast.io"
  ],
  "keys": [],
  "status": "not_configured",
  "delegationStatus": "not_verified",
  "dnsProvider": "managed",
  "canEnable": true,
  "canDisable": false,
  "enabled": false,
  "checkedAt": "2026-10-01T00:00:00.000Z",
  "operation": "idle",
  "source": "local"
}

API reference and code examples

POST/v1/domains/{serviceId}/dnssecUpdate or check DNSSEC

Operation ID: domainDnssecUpdate

Enable managed signing or submit external public DNSKEY records, disable delegation without deleting signing keys, or refresh status. Enable/disable require acknowledgement and an Idempotency-Key. Refresh requires domains.read; changes require domains.write. HTTP 200 returns refresh state; HTTP 202 means enable/disable accepted, not completed: poll the same DNSSEC GET for operation and errorCode. operationId is a DNSSEC operation UUID, not a generic /v1/operations handle. queued/pending/running are ongoing; unconfirmed requires reconciliation; failed is not success. idle with the intended registrar status confirms registrar configuration only. delegationStatus=not_verified never proves parent-zone propagation. Do not repeat an unconfirmed change.

Required scopes: domains.read OR domains.write

Parameters

  • serviceId · path · required — Your registered domain name (example.com) or service UUID. Names are case-insensitive and normalized to IDNA ASCII; one trailing dot is accepted. Exact matches are restricted to your non-terminated domain services. Multiple matches return domain_identifier_ambiguous; use the UUID.
  • Idempotency-Key · header — Required for enable/disable: 8–128 letters, digits, dot, underscore, colon or hyphen. Reuse identical payloads; not required for refresh.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "anyOf": [
    {
      "type": "object",
      "properties": {
        "action": {
          "type": "string",
          "const": "enable",
          "enum": [
            "enable"
          ]
        },
        "mode": {
          "type": "string",
          "const": "managed",
          "enum": [
            "managed"
          ]
        },
        "acknowledge": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        }
      },
      "required": [
        "action",
        "mode",
        "acknowledge"
      ],
      "additionalProperties": false
    },
    {
      "type": "object",
      "properties": {
        "action": {
          "type": "string",
          "const": "enable",
          "enum": [
            "enable"
          ]
        },
        "mode": {
          "type": "string",
          "const": "external",
          "enum": [
            "external"
          ]
        },
        "acknowledge": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        },
        "keys": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "flags": {
                "type": "number",
                "const": 257,
                "enum": [
                  257
                ]
              },
              "protocol": {
                "type": "number",
                "const": 3,
                "enum": [
                  3
                ]
              },
              "alg": {
                "type": "integer"
              },
              "pub_key": {
                "type": "string",
                "minLength": 40,
                "maxLength": 4096,
                "pattern": "^[A-Za-z0-9+/]+={0,2}$"
              }
            },
            "required": [
              "flags",
              "protocol",
              "alg",
              "pub_key"
            ],
            "additionalProperties": false
          },
          "minItems": 1,
          "maxItems": 4
        }
      },
      "required": [
        "action",
        "mode",
        "acknowledge",
        "keys"
      ],
      "additionalProperties": false
    },
    {
      "type": "object",
      "properties": {
        "action": {
          "type": "string",
          "const": "disable",
          "enum": [
            "disable"
          ]
        },
        "acknowledge": {
          "type": "boolean",
          "const": true,
          "enum": [
            true
          ]
        }
      },
      "required": [
        "action",
        "acknowledge"
      ],
      "additionalProperties": false
    },
    {
      "type": "object",
      "properties": {
        "action": {
          "type": "string",
          "const": "refresh",
          "enum": [
            "refresh"
          ]
        }
      },
      "required": [
        "action"
      ],
      "additionalProperties": false
    }
  ]
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "domain": {
      "type": "string",
      "maxLength": 253
    },
    "tld": {
      "type": "string",
      "maxLength": 253
    },
    "service_id": {
      "type": "string",
      "format": "uuid"
    },
    "domain_name": {
      "anyOf": [
        {
          "type": "string",
          "maxLength": 253
        },
        {
          "type": "null"
        }
      ]
    },
    "support": {
      "type": "string",
      "enum": [
        "supported",
        "unsupported",
        "unknown"
      ]
    },
    "nameservers": {
      "type": "array",
      "items": {
        "type": "string",
        "maxLength": 253
      },
      "maxItems": 13
    },
    "keys": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "flags": {
            "type": "number",
            "const": 257,
            "enum": [
              257
            ]
          },
          "protocol": {
            "type": "number",
            "const": 3,
            "enum": [
              3
            ]
          },
          "alg": {
            "type": "integer"
          },
          "pub_key": {
            "type": "string",
            "minLength": 40,
            "maxLength": 4096,
            "pattern": "^[A-Za-z0-9+/]+={0,2}$"
          }
        },
        "required": [
          "flags",
          "protocol",
          "alg",
          "pub_key"
        ],
        "additionalProperties": false
      },
      "maxItems": 32
    },
    "status": {
      "type": "string",
      "enum": [
        "registrar_configured",
        "not_configured"
      ]
    },
    "delegationStatus": {
      "type": "string",
      "const": "not_verified",
      "enum": [
        "not_verified"
      ]
    },
    "dnsProvider": {
      "type": "string",
      "enum": [
        "managed",
        "external"
      ]
    },
    "canEnable": {
      "type": "boolean"
    },
    "canDisable": {
      "type": "boolean"
    },
    "enabled": {
      "type": "boolean"
    },
    "checkedAt": {
      "type": "string",
      "format": "date-time"
    },
    "operation": {
      "type": "string",
      "enum": [
        "idle",
        "pending",
        "queued",
        "running",
        "unconfirmed",
        "failed"
      ]
    },
    "operationId": {
      "type": "string",
      "format": "uuid"
    },
    "requestedAction": {
      "type": "string",
      "enum": [
        "enable",
        "disable"
      ]
    },
    "operationUpdatedAt": {
      "type": "string",
      "format": "date-time"
    },
    "errorCode": {
      "type": "string",
      "maxLength": 80
    },
    "source": {
      "type": "string",
      "const": "local",
      "enum": [
        "local"
      ]
    }
  },
  "required": [
    "ok",
    "domain",
    "tld",
    "support",
    "nameservers",
    "keys",
    "status",
    "delegationStatus",
    "dnsProvider",
    "canEnable",
    "canDisable",
    "enabled",
    "checkedAt",
    "operation",
    "source"
  ],
  "additionalProperties": false
}

API reference and code examples

PUT/v1/domains/{serviceId}/lockChange transfer lock

Operation ID: domainLock

Enables or disables the domain lock state.

Required scopes: domains.write

Parameters

  • serviceId · path · required — Your registered domain name (example.com) or service UUID. Names are case-insensitive and normalized to IDNA ASCII; one trailing dot is accepted. Exact matches are restricted to your non-terminated domain services. Multiple matches return domain_identifier_ambiguous; use the UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "locked": {
      "type": "boolean"
    }
  },
  "required": [
    "locked"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "locked": {
      "type": "boolean"
    }
  },
  "required": [
    "ok",
    "locked"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "locked": true
}

API reference and code examples

PUT/v1/domains/{serviceId}/nameserversUpdate nameservers

Operation ID: domainNameserversUpdate

Replaces nameserver configuration for a domain service.

Required scopes: domains.write

Parameters

  • serviceId · path · required — Your registered domain name (example.com) or service UUID. Names are case-insensitive and normalized to IDNA ASCII; one trailing dot is accepted. Exact matches are restricted to your non-terminated domain services. Multiple matches return domain_identifier_ambiguous; use the UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "nameservers": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string",
            "minLength": 1
          },
          "ip": {
            "type": "string"
          }
        },
        "required": [
          "name"
        ],
        "additionalProperties": false
      },
      "minItems": 2,
      "maxItems": 13
    }
  },
  "required": [
    "nameservers"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true
}

API reference and code examples

POST/v1/domains/{serviceId}/resend-verificationResend verification

Operation ID: domainResendVerification

Resends a verification step for a domain when the registrar flow requires it.

Required scopes: domains.write

Parameters

  • serviceId · path · required — Your registered domain name (example.com) or service UUID. Names are case-insensitive and normalized to IDNA ASCII; one trailing dot is accepted. Exact matches are restricted to your non-terminated domain services. Multiple matches return domain_identifier_ambiguous; use the UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true
}

API reference and code examples

GET/v1/domains/{serviceId}/statusCheck domain status

Operation ID: domainStatus

Returns current domain lifecycle or verification status for one domain service.

Required scopes: domains.read

Parameters

  • serviceId · path · required — Your registered domain name (example.com) or service UUID. Names are case-insensitive and normalized to IDNA ASCII; one trailing dot is accepted. Exact matches are restricted to your non-terminated domain services. Multiple matches return domain_identifier_ambiguous; use the UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "status": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "normalizedStatus": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "is_lockable": {
      "anyOf": [
        {
          "type": "boolean"
        },
        {
          "type": "null"
        }
      ]
    },
    "is_locked": {
      "type": "boolean"
    },
    "is_private_whois_enabled": {
      "type": "boolean"
    },
    "is_private_whois_allowed": {
      "type": "boolean"
    },
    "is_abusive": {
      "type": "boolean"
    },
    "is_deleted": {
      "type": "boolean"
    },
    "can_renew": {
      "type": "boolean"
    },
    "delete_status": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "soft_quarantine_expiry_date": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "restorable_until": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "expiration_date": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "renewal_date": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    }
  },
  "required": [
    "ok",
    "status"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "status": null
}

API reference and code examples

GET/v1/domains/{serviceId}/transfer-statusCheck transfer status

Operation ID: domainTransferStatus

Returns the current transfer state for a domain service.

Required scopes: domains.read

Parameters

  • serviceId · path · required — Your registered domain name (example.com) or service UUID. Names are case-insensitive and normalized to IDNA ASCII; one trailing dot is accepted. Exact matches are restricted to your non-terminated domain services. Multiple matches return domain_identifier_ambiguous; use the UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "transferStatus": {
      "type": "string"
    },
    "isActive": {
      "type": "boolean"
    }
  },
  "required": [
    "ok",
    "transferStatus",
    "isActive"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "transferStatus": "unknown",
  "isActive": false
}

API reference and code examples

PUT/v1/domains/{serviceId}/whois-privacyChange WHOIS privacy

Operation ID: domainWhoisPrivacy

Enables or disables WHOIS privacy when the domain and registrar flow allow it.

Required scopes: domains.write

Parameters

  • serviceId · path · required — Your registered domain name (example.com) or service UUID. Names are case-insensitive and normalized to IDNA ASCII; one trailing dot is accepted. Exact matches are restricted to your non-terminated domain services. Multiple matches return domain_identifier_ambiguous; use the UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "enabled": {
      "type": "boolean"
    }
  },
  "required": [
    "enabled"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "enabled": {
      "type": "boolean"
    }
  },
  "required": [
    "ok",
    "enabled"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "enabled": true
}

API reference and code examples

POST/v1/domains/checkCheck availability

Operation ID: domainCheck

Checks one or more domains for availability.

Required scopes: domains.read

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "domains": {
      "type": "array",
      "items": {
        "type": "string",
        "minLength": 3
      },
      "minItems": 1,
      "maxItems": 50
    }
  },
  "required": [
    "domains"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "results": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "domain": {
            "type": "string"
          },
          "available": {
            "type": "boolean"
          },
          "premium": {
            "type": "boolean"
          },
          "price": {
            "anyOf": [
              {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "number"
                  }
                ]
              },
              {
                "type": "null"
              }
            ]
          },
          "currency": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "renewalPrice": {
            "anyOf": [
              {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "number"
                  }
                ]
              },
              {
                "type": "null"
              }
            ]
          },
          "renewalCurrency": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "transferPrice": {
            "anyOf": [
              {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "number"
                  }
                ]
              },
              {
                "type": "null"
              }
            ]
          },
          "transferCurrency": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "is_private_whois_allowed": {
            "type": "boolean"
          }
        },
        "required": [
          "domain"
        ],
        "additionalProperties": true
      }
    },
    "hasMore": {
      "type": "boolean"
    },
    "page": {
      "type": "number"
    },
    "pageSize": {
      "type": "number"
    },
    "total": {
      "type": "number"
    }
  },
  "required": [
    "ok",
    "results"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "results": [
    {
      "domain": "example.com",
      "available": false,
      "premium": false,
      "price": null,
      "renewalPrice": null,
      "renewalCurrency": null,
      "currency": null,
      "transferPrice": null,
      "transferCurrency": null,
      "is_private_whois_allowed": false
    }
  ]
}

API reference and code examples

GET/v1/domains/contactsBrowse domain contacts

Operation ID: listDomainContacts

Returns saved domain contact records available for assignment.

Required scopes: domains.read

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "contacts": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "firstName": {
            "type": "string"
          },
          "lastName": {
            "type": "string"
          },
          "companyName": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "email": {
            "type": "string"
          },
          "country": {
            "type": "string"
          },
          "city": {
            "type": "string"
          },
          "address": {
            "type": "string"
          },
          "postalCode": {
            "type": "string"
          },
          "phone": {
            "type": "string"
          },
          "createdAt": {
            "type": "string"
          },
          "updatedAt": {
            "type": "string"
          },
          "handle": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          }
        },
        "required": [
          "id"
        ],
        "additionalProperties": true
      }
    }
  },
  "required": [
    "ok",
    "contacts"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "contacts": []
}

API reference and code examples

POST/v1/domains/contactsSave domain contact

Operation ID: domainContactCreate

Creates a reusable domain contact record.

Required scopes: domains.write

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "first_name": {
      "type": "string",
      "minLength": 1
    },
    "last_name": {
      "type": "string",
      "minLength": 1
    },
    "company_name": {
      "type": "string"
    },
    "email": {
      "type": "string",
      "format": "email"
    },
    "phone": {
      "type": "string",
      "minLength": 1
    },
    "address": {
      "type": "object",
      "properties": {
        "street": {
          "type": "string",
          "minLength": 1
        },
        "number": {
          "type": "string",
          "minLength": 1
        },
        "city": {
          "type": "string",
          "minLength": 1
        },
        "zipcode": {
          "type": "string",
          "minLength": 1
        },
        "state": {
          "type": "string"
        },
        "country": {
          "type": "string",
          "maxLength": 2,
          "minLength": 2
        }
      },
      "required": [
        "street",
        "number",
        "city",
        "zipcode",
        "country"
      ],
      "additionalProperties": false
    },
    "tag": {
      "type": "string"
    },
    "vat": {
      "type": "string",
      "maxLength": 30,
      "pattern": "^[A-Za-z0-9\\-. ]*$"
    },
    "passport_number": {
      "type": "string",
      "maxLength": 30,
      "pattern": "^[A-Za-z0-9\\- ]*$"
    },
    "tax_id": {
      "type": "string",
      "maxLength": 30,
      "pattern": "^[A-Za-z0-9\\-. ]*$"
    },
    "additional_data": {
      "type": "object",
      "additionalProperties": {}
    }
  },
  "required": [
    "first_name",
    "last_name",
    "email",
    "phone",
    "address"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "contact": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "firstName": {
          "type": "string"
        },
        "lastName": {
          "type": "string"
        },
        "companyName": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "email": {
          "type": "string"
        },
        "country": {
          "type": "string"
        },
        "city": {
          "type": "string"
        },
        "address": {
          "type": "string"
        },
        "postalCode": {
          "type": "string"
        },
        "phone": {
          "type": "string"
        },
        "createdAt": {
          "type": "string"
        },
        "updatedAt": {
          "type": "string"
        },
        "handle": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        }
      },
      "required": [
        "id"
      ],
      "additionalProperties": true
    },
    "handle": {
      "type": "string"
    }
  },
  "required": [
    "ok",
    "contact"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "contact": {
    "id": "00000000-0000-4000-8000-000000000001",
    "firstName": "Example",
    "lastName": "Customer",
    "country": "NL"
  },
  "handle": "EXAMPLE-HANDLE"
}

API reference and code examples

DELETE/v1/domains/contacts/{contactId}Remove domain contact

Operation ID: domainContactDelete

Deletes a saved domain contact record.

Required scopes: domains.write

Parameters

  • contactId · path · required — Domain contact UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true
}

API reference and code examples

PUT/v1/domains/contacts/{contactId}Edit domain contact

Operation ID: domainContactUpdate

Replaces a saved domain contact record.

Required scopes: domains.write

Parameters

  • contactId · path · required — Domain contact UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "first_name": {
      "type": "string",
      "minLength": 1
    },
    "last_name": {
      "type": "string",
      "minLength": 1
    },
    "company_name": {
      "type": "string"
    },
    "email": {
      "type": "string",
      "format": "email"
    },
    "phone": {
      "type": "string",
      "minLength": 1
    },
    "address": {
      "type": "object",
      "properties": {
        "street": {
          "type": "string",
          "minLength": 1
        },
        "number": {
          "type": "string",
          "minLength": 1
        },
        "city": {
          "type": "string",
          "minLength": 1
        },
        "zipcode": {
          "type": "string",
          "minLength": 1
        },
        "state": {
          "type": "string"
        },
        "country": {
          "type": "string",
          "maxLength": 2,
          "minLength": 2
        }
      },
      "required": [
        "street",
        "number",
        "city",
        "zipcode",
        "country"
      ],
      "additionalProperties": false
    },
    "tag": {
      "type": "string"
    },
    "vat": {
      "type": "string",
      "maxLength": 30,
      "pattern": "^[A-Za-z0-9\\-. ]*$"
    },
    "passport_number": {
      "type": "string",
      "maxLength": 30,
      "pattern": "^[A-Za-z0-9\\- ]*$"
    },
    "tax_id": {
      "type": "string",
      "maxLength": 30,
      "pattern": "^[A-Za-z0-9\\-. ]*$"
    },
    "additional_data": {
      "type": "object",
      "additionalProperties": {}
    }
  },
  "required": [
    "first_name",
    "last_name",
    "email",
    "phone",
    "address"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "contact": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "firstName": {
          "type": "string"
        },
        "lastName": {
          "type": "string"
        },
        "companyName": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "email": {
          "type": "string"
        },
        "country": {
          "type": "string"
        },
        "city": {
          "type": "string"
        },
        "address": {
          "type": "string"
        },
        "postalCode": {
          "type": "string"
        },
        "phone": {
          "type": "string"
        },
        "createdAt": {
          "type": "string"
        },
        "updatedAt": {
          "type": "string"
        },
        "handle": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        }
      },
      "required": [
        "id"
      ],
      "additionalProperties": true
    }
  },
  "required": [
    "ok",
    "contact"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "contact": {
    "id": "00000000-0000-4000-8000-000000000001",
    "firstName": "Example",
    "lastName": "Customer",
    "country": "NL"
  }
}

API reference and code examples

POST/v1/domains/searchSearch domains

Operation ID: domainSearch

Searches available domains by keyword with paging support.

Required scopes: domains.read

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "keyword": {
      "type": "string",
      "minLength": 1,
      "maxLength": 63
    },
    "page": {
      "type": "integer",
      "minimum": 0,
      "default": 0
    },
    "page_size": {
      "type": "integer",
      "minimum": 5,
      "maximum": 50,
      "default": 20
    }
  },
  "required": [
    "keyword"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "results": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "domain": {
            "type": "string"
          },
          "available": {
            "type": "boolean"
          },
          "premium": {
            "type": "boolean"
          },
          "price": {
            "anyOf": [
              {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "number"
                  }
                ]
              },
              {
                "type": "null"
              }
            ]
          },
          "currency": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "renewalPrice": {
            "anyOf": [
              {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "number"
                  }
                ]
              },
              {
                "type": "null"
              }
            ]
          },
          "renewalCurrency": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "transferPrice": {
            "anyOf": [
              {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "number"
                  }
                ]
              },
              {
                "type": "null"
              }
            ]
          },
          "transferCurrency": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "is_private_whois_allowed": {
            "type": "boolean"
          }
        },
        "required": [
          "domain"
        ],
        "additionalProperties": true
      }
    },
    "hasMore": {
      "type": "boolean"
    },
    "page": {
      "type": "number"
    },
    "pageSize": {
      "type": "number"
    },
    "total": {
      "type": "number"
    }
  },
  "required": [
    "ok",
    "results"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "results": [],
  "hasMore": false,
  "page": 0,
  "total": 0
}

API reference and code examples

POST/v1/domains/suggestSuggest domains

Operation ID: domainSuggest

Returns suggestion-style domain options derived from a keyword.

Required scopes: domains.read

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "keyword": {
      "type": "string",
      "minLength": 1,
      "maxLength": 253
    },
    "limit": {
      "type": "integer",
      "minimum": 1,
      "maximum": 100
    }
  },
  "required": [
    "keyword"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "suggestions": {
      "type": "array",
      "items": {
        "anyOf": [
          {
            "type": "string"
          },
          {
            "type": "object",
            "properties": {
              "domain": {
                "type": "string"
              },
              "available": {
                "type": "boolean"
              },
              "premium": {
                "type": "boolean"
              },
              "price": {
                "anyOf": [
                  {
                    "anyOf": [
                      {
                        "type": "string"
                      },
                      {
                        "type": "number"
                      }
                    ]
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "currency": {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "renewalPrice": {
                "anyOf": [
                  {
                    "anyOf": [
                      {
                        "type": "string"
                      },
                      {
                        "type": "number"
                      }
                    ]
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "renewalCurrency": {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "transferPrice": {
                "anyOf": [
                  {
                    "anyOf": [
                      {
                        "type": "string"
                      },
                      {
                        "type": "number"
                      }
                    ]
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "transferCurrency": {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "is_private_whois_allowed": {
                "type": "boolean"
              }
            },
            "required": [
              "domain"
            ],
            "additionalProperties": true
          }
        ]
      }
    }
  },
  "required": [
    "ok",
    "suggestions"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "suggestions": []
}

API reference and code examples

GET/v1/domains/tldsBrowse supported TLDs

Operation ID: domainTlds

Returns customer-searchable TLD data for domain purchase and transfer flows.

Required scopes: domains.read

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "tlds": {
      "type": "array",
      "items": {
        "anyOf": [
          {
            "type": "string"
          },
          {
            "type": "object",
            "properties": {
              "name": {
                "type": "string"
              },
              "tld": {
                "type": "string"
              },
              "price": {
                "type": "number"
              },
              "currency": {
                "type": "string"
              },
              "dnssec": {
                "type": "boolean"
              }
            },
            "required": [
              "name"
            ],
            "additionalProperties": true
          }
        ]
      }
    }
  },
  "required": [
    "ok",
    "tlds"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "tlds": []
}

API reference and code examples

SSH

GET/v1/ssh-keysList my SSH keys

Operation ID: getSshKeys

Read-only alias of GET /v1/ssh/keys. Returns only keys owned by the authenticated account with names, fingerprints and public-key metadata; no private keys. Keeps the existing keys response contract (not a paginated catalog collection). Retrieve a selected public key through /v1/ssh/keys/{id}/public when required for provisioning.

Required scopes: ssh.read

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "keys": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "publicKey": {
            "type": "string"
          },
          "fingerprint": {
            "type": "string"
          },
          "isPrimary": {
            "type": "boolean"
          },
          "hasPrivateKey": {
            "type": "boolean"
          },
          "type": {
            "type": "string"
          },
          "createdAt": {
            "type": "string"
          },
          "updatedAt": {
            "type": "string"
          }
        },
        "required": [
          "id"
        ],
        "additionalProperties": true
      }
    }
  },
  "required": [
    "ok",
    "keys"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "keys": [
    {
      "id": "00000000-0000-4000-8000-000000000001",
      "name": "Example key",
      "algorithm": "ed25519",
      "fingerprint": "SHA256:example-fingerprint",
      "isPrimary": false,
      "hasPrivateKey": false,
      "createdAt": "2026-10-01T00:00:00.000Z",
      "updatedAt": "2026-10-01T00:00:00.000Z"
    }
  ]
}

API reference and code examples

GET/v1/ssh/keysBrowse SSH keys

Operation ID: listSshKeys

Returns saved SSH keys for the customer account.

Required scopes: ssh.read

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "keys": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "publicKey": {
            "type": "string"
          },
          "fingerprint": {
            "type": "string"
          },
          "isPrimary": {
            "type": "boolean"
          },
          "hasPrivateKey": {
            "type": "boolean"
          },
          "type": {
            "type": "string"
          },
          "createdAt": {
            "type": "string"
          },
          "updatedAt": {
            "type": "string"
          }
        },
        "required": [
          "id"
        ],
        "additionalProperties": true
      }
    }
  },
  "required": [
    "ok",
    "keys"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "keys": [
    {
      "id": "00000000-0000-4000-8000-000000000001",
      "name": "Example key",
      "algorithm": "ed25519",
      "fingerprint": "SHA256:example-fingerprint",
      "isPrimary": false,
      "hasPrivateKey": false,
      "createdAt": "2026-10-01T00:00:00.000Z",
      "updatedAt": "2026-10-01T00:00:00.000Z"
    }
  ]
}

API reference and code examples

POST/v1/ssh/keysSave SSH key

Operation ID: sshKeyImport

Stores a new public SSH key for later provisioning or VPS assignment.

Required scopes: ssh.write

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 64
    },
    "public_key": {
      "type": "string",
      "minLength": 1,
      "maxLength": 8192
    }
  },
  "required": [
    "name",
    "public_key"
  ],
  "additionalProperties": false
}

Successful response · HTTP 201

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "key": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "name": {
          "type": "string"
        },
        "publicKey": {
          "type": "string"
        },
        "fingerprint": {
          "type": "string"
        },
        "isPrimary": {
          "type": "boolean"
        },
        "hasPrivateKey": {
          "type": "boolean"
        },
        "type": {
          "type": "string"
        },
        "createdAt": {
          "type": "string"
        },
        "updatedAt": {
          "type": "string"
        }
      },
      "required": [
        "id"
      ],
      "additionalProperties": true
    }
  },
  "required": [
    "ok",
    "key"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "key": {
    "id": "00000000-0000-4000-8000-000000000001",
    "name": "Example key",
    "algorithm": "ed25519",
    "fingerprint": "SHA256:example-fingerprint",
    "isPrimary": false,
    "hasPrivateKey": false,
    "createdAt": "2026-10-01T00:00:00.000Z",
    "updatedAt": "2026-10-01T00:00:00.000Z"
  }
}

API reference and code examples

DELETE/v1/ssh/keys/{id}Remove SSH key

Operation ID: sshKeyDelete

Deletes an SSH key from the customer account.

Required scopes: ssh.write

Parameters

  • id · path · required — SSH key UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true
}

API reference and code examples

PATCH/v1/ssh/keys/{id}Rename SSH key

Operation ID: sshKeyRename

Changes only the display name of an SSH key.

Required scopes: ssh.write

Parameters

  • id · path · required — SSH key UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 64
    }
  },
  "required": [
    "name"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "key": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "name": {
          "type": "string"
        },
        "publicKey": {
          "type": "string"
        },
        "fingerprint": {
          "type": "string"
        },
        "isPrimary": {
          "type": "boolean"
        },
        "hasPrivateKey": {
          "type": "boolean"
        },
        "type": {
          "type": "string"
        },
        "createdAt": {
          "type": "string"
        },
        "updatedAt": {
          "type": "string"
        }
      },
      "required": [
        "id"
      ],
      "additionalProperties": true
    }
  },
  "required": [
    "ok",
    "key"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "key": {
    "id": "00000000-0000-4000-8000-000000000001",
    "name": "Example key",
    "algorithm": "ed25519",
    "fingerprint": "SHA256:example-fingerprint",
    "isPrimary": false,
    "hasPrivateKey": false,
    "createdAt": "2026-10-01T00:00:00.000Z",
    "updatedAt": "2026-10-01T00:00:00.000Z"
  }
}

API reference and code examples

PUT/v1/ssh/keys/{id}Edit SSH key

Operation ID: sshKeyUpdate

Replaces the name and public key material of an existing SSH key record.

Required scopes: ssh.write

Parameters

  • id · path · required — SSH key UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 64
    },
    "public_key": {
      "type": "string",
      "minLength": 1,
      "maxLength": 8192
    }
  },
  "required": [
    "name",
    "public_key"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "key": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "name": {
          "type": "string"
        },
        "publicKey": {
          "type": "string"
        },
        "fingerprint": {
          "type": "string"
        },
        "isPrimary": {
          "type": "boolean"
        },
        "hasPrivateKey": {
          "type": "boolean"
        },
        "type": {
          "type": "string"
        },
        "createdAt": {
          "type": "string"
        },
        "updatedAt": {
          "type": "string"
        }
      },
      "required": [
        "id"
      ],
      "additionalProperties": true
    }
  },
  "required": [
    "ok",
    "key"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "key": {
    "id": "00000000-0000-4000-8000-000000000001",
    "name": "Example key",
    "algorithm": "ed25519",
    "fingerprint": "SHA256:example-fingerprint",
    "isPrimary": false,
    "hasPrivateKey": false,
    "createdAt": "2026-10-01T00:00:00.000Z",
    "updatedAt": "2026-10-01T00:00:00.000Z"
  }
}

API reference and code examples

PUT/v1/ssh/keys/{id}/primarySet primary SSH key

Operation ID: sshKeySetPrimary

Marks one SSH key as the primary default choice for relevant workflows.

Required scopes: ssh.write

Parameters

  • id · path · required — SSH key UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true
}

API reference and code examples

POST/v1/ssh/keys/{id}/privateExport private keySensitive

Operation ID: sshKeyPrivateExport

Exports the private portion of a generated SSH key when the correct passphrase is supplied.

Required scopes: ssh.write

Parameters

  • id · path · required — SSH key UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "passphrase": {
      "type": "string",
      "minLength": 1,
      "maxLength": 200
    }
  },
  "required": [
    "passphrase"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "privateKey": {
      "type": "string"
    }
  },
  "required": [
    "ok",
    "privateKey"
  ],
  "additionalProperties": true
}

API reference and code examples

GET/v1/ssh/keys/{id}/publicView public key

Operation ID: sshKeyPublic

Returns the public portion of one saved SSH key.

Required scopes: ssh.read

Parameters

  • id · path · required — SSH key UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "id": {
      "type": "string"
    },
    "publicKey": {
      "type": "string"
    }
  },
  "required": [
    "ok",
    "id",
    "publicKey"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "id": "00000000-0000-4000-8000-000000000001",
  "publicKey": "<public-ssh-key>"
}

API reference and code examples

POST/v1/ssh/keys/generateGenerate SSH keypair

Operation ID: sshKeyGenerate

Generates a new SSH keypair and returns the private key once.

Required scopes: ssh.write

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 64
    },
    "algorithm": {
      "type": "string",
      "minLength": 1
    },
    "format": {
      "type": "string",
      "minLength": 1
    },
    "passphrase": {
      "type": "string",
      "minLength": 8,
      "maxLength": 200
    }
  },
  "required": [
    "name",
    "passphrase"
  ],
  "additionalProperties": false
}

Successful response · HTTP 201

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "key": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "name": {
          "type": "string"
        },
        "publicKey": {
          "type": "string"
        },
        "fingerprint": {
          "type": "string"
        },
        "isPrimary": {
          "type": "boolean"
        },
        "hasPrivateKey": {
          "type": "boolean"
        },
        "type": {
          "type": "string"
        },
        "createdAt": {
          "type": "string"
        },
        "updatedAt": {
          "type": "string"
        }
      },
      "required": [
        "id"
      ],
      "additionalProperties": true
    },
    "privateKey": {
      "type": "string"
    }
  },
  "required": [
    "ok",
    "key",
    "privateKey"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "key": {
    "id": "00000000-0000-4000-8000-000000000001",
    "name": "Example key",
    "algorithm": "ed25519",
    "fingerprint": "SHA256:example-fingerprint",
    "isPrimary": false,
    "hasPrivateKey": true,
    "createdAt": "2026-10-01T00:00:00.000Z",
    "updatedAt": "2026-10-01T00:00:00.000Z"
  },
  "privateKey": "<private-key-returned-once>"
}

API reference and code examples

Firewall

GET/v1/firewall/policiesBrowse firewall policies

Operation ID: listFirewallPolicies

Returns reusable firewall policies available to the customer.

Required scopes: firewall.read

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "policies": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "description": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "isPrimary": {
            "type": "boolean"
          },
          "policyIn": {
            "type": "string"
          },
          "policyOut": {
            "type": "string"
          },
          "rules": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "id": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "number"
                    }
                  ]
                },
                "type": {
                  "type": "string"
                },
                "action": {
                  "type": "string"
                },
                "source": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "dest": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "proto": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "sport": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "dport": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "comment": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "enable": {
                  "anyOf": [
                    {
                      "type": "boolean"
                    },
                    {
                      "type": "number"
                    }
                  ]
                },
                "position": {
                  "type": "number"
                }
              },
              "additionalProperties": true
            }
          }
        },
        "required": [
          "id",
          "name"
        ],
        "additionalProperties": true
      }
    }
  },
  "required": [
    "ok",
    "policies"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "policies": [
    {
      "id": "00000000-0000-4000-8000-000000000001",
      "name": "Example policy",
      "description": null,
      "isPrimary": false,
      "policyIn": "DROP",
      "policyOut": "ACCEPT",
      "rules": []
    }
  ]
}

API reference and code examples

POST/v1/firewall/policiesSave firewall policy

Operation ID: firewallPolicyCreate

Creates a reusable firewall policy with default actions and optional rules.

Required scopes: firewall.write

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 128
    },
    "description": {
      "type": "string",
      "maxLength": 500
    },
    "policy_in": {
      "type": "string",
      "enum": [
        "DROP",
        "ACCEPT"
      ]
    },
    "policy_out": {
      "type": "string",
      "enum": [
        "DROP",
        "ACCEPT"
      ]
    },
    "rules": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "direction": {
            "type": "string",
            "enum": [
              "IN",
              "OUT"
            ]
          },
          "type": {
            "type": "string",
            "enum": [
              "in",
              "out"
            ]
          },
          "action": {
            "type": "string",
            "enum": [
              "ACCEPT",
              "DROP",
              "REJECT"
            ]
          },
          "proto": {
            "type": "string",
            "enum": [
              "tcp",
              "udp",
              "icmp",
              "TCP",
              "UDP",
              "ICMP",
              "any",
              "all",
              "ANY",
              "ALL"
            ]
          },
          "dport": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              }
            ]
          },
          "sport": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              }
            ]
          },
          "source": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              }
            ]
          },
          "destination": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              }
            ]
          },
          "dest": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              }
            ]
          },
          "comment": {
            "type": "string",
            "maxLength": 200
          },
          "enabled": {
            "anyOf": [
              {
                "type": "boolean"
              },
              {
                "type": "string"
              },
              {
                "type": "number"
              }
            ]
          },
          "enable": {
            "anyOf": [
              {
                "type": "boolean"
              },
              {
                "type": "string"
              },
              {
                "type": "number"
              }
            ]
          },
          "iface": {
            "type": "string",
            "maxLength": 64
          },
          "log": {
            "type": "string",
            "maxLength": 64
          }
        },
        "required": [
          "action"
        ],
        "additionalProperties": false
      }
    },
    "is_primary": {
      "type": "boolean"
    }
  },
  "required": [
    "name"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "policy": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "name": {
          "type": "string"
        },
        "description": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "isPrimary": {
          "type": "boolean"
        },
        "policyIn": {
          "type": "string"
        },
        "policyOut": {
          "type": "string"
        },
        "rules": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "id": {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "number"
                  }
                ]
              },
              "type": {
                "type": "string"
              },
              "action": {
                "type": "string"
              },
              "source": {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "dest": {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "proto": {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "sport": {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "dport": {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "comment": {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "enable": {
                "anyOf": [
                  {
                    "type": "boolean"
                  },
                  {
                    "type": "number"
                  }
                ]
              },
              "position": {
                "type": "number"
              }
            },
            "additionalProperties": true
          }
        }
      },
      "required": [
        "id",
        "name"
      ],
      "additionalProperties": true
    }
  },
  "required": [
    "ok",
    "policy"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "policy": {
    "id": "00000000-0000-4000-8000-000000000001",
    "name": "Example policy",
    "description": null,
    "isPrimary": false,
    "policyIn": "DROP",
    "policyOut": "ACCEPT",
    "rules": []
  }
}

API reference and code examples

DELETE/v1/firewall/policies/{policyId}Remove firewall policy

Operation ID: firewallPolicyDelete

Deletes a reusable firewall policy.

Required scopes: firewall.write

Parameters

  • policyId · path · required — Firewall policy UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true
}

API reference and code examples

PATCH/v1/firewall/policies/{policyId}Edit firewall policy

Operation ID: firewallPolicyUpdate

Updates policy metadata or replaces rules when a new rule list is provided.

Required scopes: firewall.write

Parameters

  • policyId · path · required — Firewall policy UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 128
    },
    "description": {
      "type": "string",
      "maxLength": 500
    },
    "policy_in": {
      "type": "string",
      "enum": [
        "DROP",
        "ACCEPT"
      ]
    },
    "policy_out": {
      "type": "string",
      "enum": [
        "DROP",
        "ACCEPT"
      ]
    },
    "rules": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "direction": {
            "type": "string",
            "enum": [
              "IN",
              "OUT"
            ]
          },
          "type": {
            "type": "string",
            "enum": [
              "in",
              "out"
            ]
          },
          "action": {
            "type": "string",
            "enum": [
              "ACCEPT",
              "DROP",
              "REJECT"
            ]
          },
          "proto": {
            "type": "string",
            "enum": [
              "tcp",
              "udp",
              "icmp",
              "TCP",
              "UDP",
              "ICMP",
              "any",
              "all",
              "ANY",
              "ALL"
            ]
          },
          "dport": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              }
            ]
          },
          "sport": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              }
            ]
          },
          "source": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              }
            ]
          },
          "destination": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              }
            ]
          },
          "dest": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              }
            ]
          },
          "comment": {
            "type": "string",
            "maxLength": 200
          },
          "enabled": {
            "anyOf": [
              {
                "type": "boolean"
              },
              {
                "type": "string"
              },
              {
                "type": "number"
              }
            ]
          },
          "enable": {
            "anyOf": [
              {
                "type": "boolean"
              },
              {
                "type": "string"
              },
              {
                "type": "number"
              }
            ]
          },
          "iface": {
            "type": "string",
            "maxLength": 64
          },
          "log": {
            "type": "string",
            "maxLength": 64
          }
        },
        "required": [
          "action"
        ],
        "additionalProperties": false
      }
    }
  },
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "policy": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "name": {
          "type": "string"
        },
        "description": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "isPrimary": {
          "type": "boolean"
        },
        "policyIn": {
          "type": "string"
        },
        "policyOut": {
          "type": "string"
        },
        "rules": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "id": {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "number"
                  }
                ]
              },
              "type": {
                "type": "string"
              },
              "action": {
                "type": "string"
              },
              "source": {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "dest": {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "proto": {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "sport": {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "dport": {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "comment": {
                "anyOf": [
                  {
                    "type": "string"
                  },
                  {
                    "type": "null"
                  }
                ]
              },
              "enable": {
                "anyOf": [
                  {
                    "type": "boolean"
                  },
                  {
                    "type": "number"
                  }
                ]
              },
              "position": {
                "type": "number"
              }
            },
            "additionalProperties": true
          }
        }
      },
      "required": [
        "id",
        "name"
      ],
      "additionalProperties": true
    }
  },
  "required": [
    "ok",
    "policy"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "policy": {
    "id": "00000000-0000-4000-8000-000000000001",
    "name": "Example policy",
    "description": null,
    "isPrimary": false,
    "policyIn": "DROP",
    "policyOut": "ACCEPT",
    "rules": []
  }
}

API reference and code examples

POST/v1/firewall/policies/{policyId}/primarySet primary firewall policy

Operation ID: firewallPolicySetPrimary

Marks a firewall policy as the primary default policy.

Required scopes: firewall.write

Parameters

  • policyId · path · required — Firewall policy UUID.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true
}

API reference and code examples

GET/v1/vps/{serviceId}/firewall/policyView VPS firewall policy

Operation ID: getVpsFirewallPolicy

Returns the effective firewall policy selection for a VPS.

Required scopes: vps.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "requestedPolicyId": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "primaryPolicyId": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "effectivePolicyId": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "effectiveMode": {
      "type": "string"
    }
  },
  "required": [
    "ok",
    "requestedPolicyId",
    "primaryPolicyId",
    "effectivePolicyId",
    "effectiveMode"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "requestedPolicyId": null,
  "primaryPolicyId": "00000000-0000-4000-8000-000000000001",
  "effectivePolicyId": "00000000-0000-4000-8000-000000000001",
  "effectiveMode": "primary"
}

API reference and code examples

POST/v1/vps/{serviceId}/firewall/policy/applyApply policy to VPS

Operation ID: vpsFirewallPolicyApply

Applies a selected firewall policy to a VPS service.

Required scopes: vps.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "policy_id": {
      "type": "string",
      "minLength": 1,
      "maxLength": 128
    }
  },
  "required": [
    "policy_id"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true
}

API reference and code examples

Storage

GET/v1/storage/volumesBrowse storage volumes

Operation ID: listStorageVolumes

Returns customer-visible storage volumes.

Required scopes: storage.read

Parameters

  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "serviceId": {
            "type": "string"
          },
          "billingServiceId": {
            "type": "string"
          },
          "name": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "status": {
            "type": "string"
          },
          "sizeGb": {
            "type": "number"
          },
          "sizeBytes": {
            "type": "number"
          },
          "attachedTo": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "attachedServiceId": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "hostname": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "region": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "ipv4": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          }
        },
        "additionalProperties": true
      }
    }
  },
  "required": [
    "ok",
    "items"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "items": []
}

API reference and code examples

POST/v1/storage/volumes/{serviceId}/attachAttach volume

Operation ID: storageVolumeAttach

Attaches the selected volume to a target service.

Required scopes: storage.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "target_service_id": {
      "type": "string",
      "format": "uuid"
    }
  },
  "required": [
    "target_service_id"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true
}

API reference and code examples

GET/v1/storage/volumes/{serviceId}/attach-optionsView attach options

Operation ID: storageVolumeAttachOptions

Returns eligible target services or VMs that can accept the selected volume.

Required scopes: storage.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "serviceId": {
            "type": "string"
          },
          "billingServiceId": {
            "type": "string"
          },
          "name": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "status": {
            "type": "string"
          },
          "sizeGb": {
            "type": "number"
          },
          "sizeBytes": {
            "type": "number"
          },
          "attachedTo": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "attachedServiceId": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "hostname": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "region": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          },
          "ipv4": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ]
          }
        },
        "additionalProperties": true
      }
    }
  },
  "required": [
    "ok",
    "items"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "items": []
}

API reference and code examples

POST/v1/storage/volumes/{serviceId}/detachDetach volume

Operation ID: storageVolumeDetach

Detaches the selected volume from its current target.

Required scopes: storage.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    }
  },
  "required": [
    "ok"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true
}

API reference and code examples

POST/v1/storage/volumes/{serviceId}/renameRename volume

Operation ID: storageVolumeRename

Changes the customer-visible volume name.

Required scopes: storage.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 64
    }
  },
  "required": [
    "name"
  ],
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "billingServiceId": {
      "type": "string"
    },
    "name": {
      "type": "string"
    }
  },
  "required": [
    "ok",
    "billingServiceId",
    "name"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "billingServiceId": "00000000-0000-4000-8000-000000000001",
  "name": "Example volume"
}

API reference and code examples

TCP Proxy

GET/v1/tcp-proxy/{serviceId}Read TCP Proxy configuration

Operation ID: getTcpProxy

Returns only customer configuration. Requires ownership or project service.view permission. tcpProxy is null for non-TCP services.

Required scopes: tcp_proxy.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "tcpProxy": {
      "type": "object",
      "properties": {
        "proxyIp": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "backendIp": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "ports": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "listen": {
                "type": "number"
              },
              "backend": {
                "type": "number"
              },
              "protocol": {
                "type": "string"
              }
            },
            "required": [
              "listen",
              "backend"
            ],
            "additionalProperties": true
          }
        },
        "includedPorts": {
          "type": "number"
        },
        "additionalPorts": {
          "type": "number"
        },
        "status": {
          "type": "string"
        },
        "allowedSourceCidrs": {
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "blockedSourceCidrs": {
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "countryPolicy": {
          "type": "object",
          "properties": {
            "mode": {
              "type": "string"
            },
            "countries": {
              "type": "array",
              "items": {
                "type": "string"
              }
            }
          },
          "required": [
            "mode",
            "countries"
          ],
          "additionalProperties": true
        },
        "defaults": {
          "type": "object",
          "additionalProperties": {
            "$ref": "#/$defs/JsonValue"
          }
        }
      },
      "additionalProperties": true
    }
  },
  "required": [
    "tcpProxy"
  ],
  "additionalProperties": true,
  "$defs": {
    "JsonValue": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "number"
        },
        {
          "type": "boolean"
        },
        {
          "type": "null"
        },
        {
          "type": "array",
          "items": {
            "$ref": "#/$defs/JsonValue"
          }
        },
        {
          "type": "object",
          "additionalProperties": {
            "$ref": "#/$defs/JsonValue"
          }
        }
      ]
    }
  }
}

Illustrative successful response

{
  "tcpProxy": {
    "proxyIp": "192.0.2.20",
    "backendIp": "192.0.2.10",
    "ports": [
      {
        "listen": 443,
        "backend": 443
      }
    ],
    "includedPorts": 1,
    "additionalPorts": 0,
    "defaults": {},
    "allowedSourceCidrs": [],
    "blockedSourceCidrs": [],
    "countryPolicy": {
      "mode": "disabled",
      "countries": []
    },
    "status": "active"
  }
}

API reference and code examples

PATCH/v1/tcp-proxy/{serviceId}Update TCP Proxy configuration

Operation ID: tcpProxyUpdate

Requires service.tcp-proxy.manage permission. Supply backendIp, ports, allowedSourceCidrs, blockedSourceCidrs or countryPolicy. Supplied arrays replace complete existing arrays; omitted fields remain unchanged. TCP country modes: disabled/allow/block. IPv4 only. Paid port entitlement is enforced. Send the same Idempotency-Key and body on retries; never retry an uncertain outcome with a new key.

Required scopes: tcp_proxy.write

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

JSON body · required

{
  "type": "object",
  "properties": {
    "backend_ip": {
      "type": "string"
    },
    "ports": {
      "type": "array",
      "items": {
        "anyOf": [
          {
            "type": "integer",
            "minimum": 1,
            "maximum": 65535
          },
          {
            "type": "object",
            "properties": {
              "listen": {
                "type": "integer",
                "minimum": 1,
                "maximum": 65535
              },
              "backend": {
                "type": "integer",
                "minimum": 1,
                "maximum": 65535
              },
              "backend_ip": {
                "type": "string"
              },
              "proxy_protocol_v2": {
                "type": "boolean"
              },
              "max_connections_per_ip": {
                "type": "integer",
                "minimum": 1,
                "maximum": 1000000
              },
              "max_new_connections_per_second_per_ip": {
                "type": "integer",
                "minimum": 1,
                "maximum": 1000000
              },
              "connection_burst": {
                "type": "integer",
                "minimum": 0,
                "maximum": 1000000
              },
              "max_packets_per_second_per_ip": {
                "type": "integer",
                "minimum": 1,
                "maximum": 10000000
              },
              "packet_burst": {
                "type": "integer",
                "minimum": 0,
                "maximum": 10000000
              }
            },
            "required": [
              "listen"
            ],
            "additionalProperties": false
          }
        ]
      },
      "minItems": 1,
      "maxItems": 512
    },
    "allowed_source_cidrs": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "maxItems": 256
    },
    "blocked_source_cidrs": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "maxItems": 256
    },
    "country_policy": {
      "type": "object",
      "properties": {
        "mode": {
          "type": "string",
          "enum": [
            "disabled",
            "allow",
            "block"
          ]
        },
        "countries": {
          "type": "array",
          "items": {
            "type": "string",
            "pattern": "^[A-Z]{2}$"
          },
          "maxItems": 256
        }
      },
      "required": [
        "mode",
        "countries"
      ],
      "additionalProperties": false
    }
  },
  "additionalProperties": false
}

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "tcpProxy": {
      "type": "object",
      "properties": {
        "proxyIp": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "backendIp": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ]
        },
        "ports": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "listen": {
                "type": "number"
              },
              "backend": {
                "type": "number"
              },
              "protocol": {
                "type": "string"
              }
            },
            "required": [
              "listen",
              "backend"
            ],
            "additionalProperties": true
          }
        },
        "includedPorts": {
          "type": "number"
        },
        "additionalPorts": {
          "type": "number"
        },
        "status": {
          "type": "string"
        },
        "allowedSourceCidrs": {
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "blockedSourceCidrs": {
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "countryPolicy": {
          "type": "object",
          "properties": {
            "mode": {
              "type": "string"
            },
            "countries": {
              "type": "array",
              "items": {
                "type": "string"
              }
            }
          },
          "required": [
            "mode",
            "countries"
          ],
          "additionalProperties": true
        },
        "defaults": {
          "type": "object",
          "additionalProperties": {
            "$ref": "#/$defs/JsonValue"
          }
        }
      },
      "additionalProperties": true
    }
  },
  "required": [
    "ok",
    "tcpProxy"
  ],
  "additionalProperties": true,
  "$defs": {
    "JsonValue": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "number"
        },
        {
          "type": "boolean"
        },
        {
          "type": "null"
        },
        {
          "type": "array",
          "items": {
            "$ref": "#/$defs/JsonValue"
          }
        },
        {
          "type": "object",
          "additionalProperties": {
            "$ref": "#/$defs/JsonValue"
          }
        }
      ]
    }
  }
}

Illustrative successful response

{
  "ok": true,
  "tcpProxy": {
    "proxyIp": "192.0.2.20",
    "backendIp": "192.0.2.10",
    "ports": [
      {
        "listen": 443,
        "backend": 443
      }
    ],
    "includedPorts": 1,
    "additionalPorts": 0,
    "defaults": {},
    "allowedSourceCidrs": [],
    "blockedSourceCidrs": [],
    "countryPolicy": {
      "mode": "disabled",
      "countries": []
    },
    "status": "active"
  }
}

API reference and code examples

GET/v1/tcp-proxy/{serviceId}/statsRead TCP Proxy analytics

Operation ID: tcpProxyStats

Window/bucket byte totals, observed connection events and blocked packet counts. Not instantaneous throughput or open sockets.

Required scopes: tcp_proxy.read

Parameters

  • serviceId · path · required — Customer-visible UUID of the service you want to inspect or change.
  • range · query — Time window (default 24h).
  • x-client-request-id · header — Optional client correlation label, 1–120 letters/digits/dots/underscores/colons/hyphens. Logged alongside the server request ID; never an idempotency key.
  • x-ts · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Unix timestamp in seconds; refresh it for every HTTP attempt. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-nonce · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Fresh nonce for every HTTP attempt; never reuse it when retrying. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-content-sha256 · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 SHA-256 of the exact transmitted body bytes; hash the empty body for bodyless requests. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.
  • x-signature · header · required with SignedAuth — Required when using SignedAuth with x-api-key; omitted for BearerAuth. Base64 HMAC-SHA256 signature produced by the documented signing algorithm. Generic OpenAPI clients do not compute HMAC signatures; use an official SDK or implement signing manually.

No JSON request body.

Successful response · HTTP 200

{
  "type": "object",
  "properties": {
    "ok": {
      "type": "boolean",
      "const": true,
      "enum": [
        true
      ]
    },
    "proxyIp": {
      "type": "string"
    },
    "range": {
      "type": "string"
    },
    "since": {
      "type": "string"
    },
    "until": {
      "type": "string"
    },
    "updatedAt": {
      "type": "string"
    },
    "lastEventAt": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "retentionDays": {
      "type": "number"
    },
    "summary": {
      "type": "object",
      "properties": {
        "connections": {
          "type": "number"
        },
        "bytesIn": {
          "type": "number"
        },
        "bytesOut": {
          "type": "number"
        },
        "limited": {
          "type": "number"
        },
        "errors": {
          "type": "number"
        },
        "averageDurationMs": {
          "type": "number"
        },
        "blockedPackets": {
          "type": "number"
        }
      },
      "required": [
        "connections",
        "bytesIn",
        "bytesOut",
        "limited",
        "errors",
        "averageDurationMs",
        "blockedPackets"
      ],
      "additionalProperties": true
    },
    "traffic": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "time": {
            "type": "string"
          },
          "timestamp": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              }
            ]
          },
          "bytesIn": {
            "type": "number"
          },
          "bytesOut": {
            "type": "number"
          },
          "rx": {
            "type": "number"
          },
          "tx": {
            "type": "number"
          },
          "watts": {
            "anyOf": [
              {
                "type": "number"
              },
              {
                "type": "null"
              }
            ]
          },
          "value": {
            "anyOf": [
              {
                "type": "number"
              },
              {
                "type": "null"
              }
            ]
          },
          "connections": {
            "type": "number"
          },
          "errors": {
            "type": "number"
          },
          "blockedPackets": {
            "type": "number"
          }
        },
        "additionalProperties": true
      }
    },
    "blockedTraffic": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "time": {
            "type": "string"
          },
          "timestamp": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "number"
              }
            ]
          },
          "bytesIn": {
            "type": "number"
          },
          "bytesOut": {
            "type": "number"
          },
          "rx": {
            "type": "number"
          },
          "tx": {
            "type": "number"
          },
          "watts": {
            "anyOf": [
              {
                "type": "number"
              },
              {
                "type": "null"
              }
            ]
          },
          "value": {
            "anyOf": [
              {
                "type": "number"
              },
              {
                "type": "null"
              }
            ]
          },
          "connections": {
            "type": "number"
          },
          "errors": {
            "type": "number"
          },
          "blockedPackets": {
            "type": "number"
          }
        },
        "additionalProperties": true
      }
    },
    "ports": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "port": {
            "type": "number"
          },
          "connections": {
            "type": "number"
          },
          "bytesIn": {
            "type": "number"
          },
          "bytesOut": {
            "type": "number"
          }
        },
        "additionalProperties": true
      }
    },
    "statuses": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "status": {
            "type": "string"
          },
          "count": {
            "type": "number"
          }
        },
        "additionalProperties": true
      }
    },
    "blockedPorts": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "port": {
            "type": "number"
          },
          "count": {
            "type": "number"
          }
        },
        "additionalProperties": true
      }
    }
  },
  "required": [
    "ok",
    "proxyIp",
    "range",
    "since",
    "until",
    "updatedAt",
    "lastEventAt",
    "retentionDays",
    "summary",
    "traffic",
    "blockedTraffic",
    "ports",
    "statuses",
    "blockedPorts"
  ],
  "additionalProperties": true
}

Illustrative successful response

{
  "ok": true,
  "proxyIp": "192.0.2.20",
  "range": "24h",
  "since": "2026-10-01T00:00:00.000Z",
  "until": "2026-10-02T00:00:00.000Z",
  "updatedAt": "2026-10-02T00:00:00.000Z",
  "lastEventAt": null,
  "retentionDays": 7,
  "summary": {
    "connections": 0,
    "bytesIn": 0,
    "bytesOut": 0,
    "limited": 0,
    "errors": 0,
    "averageDurationMs": 0,
    "blockedPackets": 0
  },
  "traffic": [],
  "blockedTraffic": [],
  "ports": [],
  "statuses": [],
  "blockedPorts": []
}

API reference and code examples

Green methods read data; amber methods may change state; red methods delete resources. Some POST endpoints are read-only quotes/previews; always follow the individual contract. Credential endpoints are separate privileged reads. No live secrets or customer data are embedded in this page.