API, SDKs & AI assistants
Back to section

Install an SDK or the command-line tool

Download Python, Node.js, PHP or Go, configure an API key and list your services.

Check GET /v1/version and GET /v1/capabilities before using optional workflow features. Strict response validation is enforced.

Use bf for new integrations. bf-api is an actively supported compatibility alias of the same CLI, not a separate lower-level interface. Both are included in the Python SDK package and use the same commands, authentication and version.

Use an SDK inside an application. Use the Python CLI for terminal commands. All four SDKs call the same public API and handle signed authentication.

Before you start

Create an API key using the authentication guide. Download the current archive from Settings → API → SDK downloads. Each archive contains a README with language-specific examples. Current immutable downloads: Python + CLI, Node.js, PHP and Go. Verify SHA256SUMS before installing. Public registry publication is separate from these downloads.

Package Minimum runtime Included tools
Python Python 3.10 SDK, bf CLI (bf-api alias) and local MCP server
Node.js Node.js 18 SDK library
PHP PHP 8.1 SDK library
Go Go 1.22 SDK library

Python and CLI quickstart

Download the Python archive, then install it in a virtual environment. Replace the filename below with the version you downloaded.

python3 -m venv .venv
source .venv/bin/activate
python -m pip install ./bf-sdk-python-VERSION.tar.gz
bf --version

On Windows PowerShell, activate with .\.venv\Scripts\Activate.ps1. If creating the environment fails, install your operating system's Python venv support.

Set BF_API_BASE_URL, BF_API_KEY and BF_API_SECRET in the active shell, then run:

bf service list
bf billing balance
bf dns zone list
bf vps status SERVICE_UUID

Replace SERVICE_UUID with a service ID returned by the list. Use bf --help or bf billing --help to discover commands.

In Python:

from bf_api import BfClient
client = BfClient()  # reads the environment variables
print(client.services_list(statuses=["active", "suspended"]))

Node.js quickstart

Install the downloaded archive inside your Node.js project:

npm install ./bf-sdk-nodejs-VERSION.tar.gz
const { BfClient } = require('bf-api');
async function main() {
  const client = new BfClient({
    baseUrl: process.env.BF_API_BASE_URL,
    apiKey: process.env.BF_API_KEY,
    apiSecret: process.env.BF_API_SECRET,
  });
  console.log(await client.services_list({ statuses: ["active", "suspended"] }));
}
main().catch(() => console.error("API request failed; check status, error code and request ID."));

PHP quickstart

Extract the PHP archive. In a Composer project, use the extracted directory as a local package:

tar -xzf bf-sdk-php-VERSION.tar.gz
composer config repositories.bf path ./bf-sdk-php-VERSION
composer require blazingfast/bf-api:@dev
<?php
require __DIR__ . '/vendor/autoload.php';
$client = new BfApi\BfClient([
    'baseUrl' => getenv('BF_API_BASE_URL'),
    'apiKey' => getenv('BF_API_KEY'),
    'apiSecret' => getenv('BF_API_SECRET'),
]);
print_r($client->services_list(['statuses' => ['active', 'suspended']]));

Go quickstart

Extract the Go archive. In a Go module, reference its local directory:

tar -xzf bf-sdk-go-VERSION.tar.gz
go mod edit -replace blazingfast.io/sdk/go=./bf-sdk-go-VERSION
go get blazingfast.io/sdk/go

Create a client with bfapi.NewClient(bfapi.Config{BaseURL: os.Getenv("BF_API_BASE_URL"), APIKey: os.Getenv("BF_API_KEY"), APISecret: os.Getenv("BF_API_SECRET")}), then call client.ServicesList(nil, nil). The archive README contains the complete Go program, including error handling.

Local MCP for desktop and coding assistants

For the hosted ChatGPT connection, follow Connect an AI assistant. Local MCP runs on your computer using the Python package and an API key.

After installation, bf-api-mcp starts the local server. Desktop apps may not use your terminal's PATH; find the full executable path with command -v bf-api-mcp and use it in the client configuration.

A basic JSON configuration is:

{
  "mcpServers": {
    "bf-api": {
      "command": "/ABSOLUTE/PATH/.venv/bin/bf-api-mcp",
      "args": [],
      "env": {
        "BF_API_BASE_URL": "https://api.blazingfast.io",
        "BF_API_KEY": "YOUR_KEY_PREFIX",
        "BF_API_SECRET": "YOUR_ONE_TIME_SECRET"
      }
    }
  }
}

The archive README includes Claude, Cursor and VS Code configuration examples. Restart or refresh the client after saving.

Local MCP exposes viewing tools by default. BF_API_MCP_ENABLE_MUTATIONS=1 enables selected write tools within your API-key permissions. Those API-key actions execute directly and do not use hosted AI dashboard approvals. Credential output has a separate opt-in; leave it disabled unless you specifically need it. Follow the local MCP guide for coverage limits and the distinction from hosted MCP.

Current purchase and operation workflows

SDK/CLI 0.1.17 supports contract 2026-10-07.1. Read GET /v1/version and GET /v1/capabilities, then discover product purchase policies and requirements before configuring a purchase. A quote is optional: discovery can lead directly to an authorized deployment. Quotes do not reserve stock or lock prices; send an authorized max_total ceiling for the full final order amount.

Draft order creation does not charge the account. Atomic deployment is the documented exception: it combines order creation, payment of the full final order amount from account balance and queued provisioning. Paid is not ready; accepted is not completed. Service lifecycle status is separate from runtime power state.

Supported tracked deployment, VPS and dedicated writes can return a canonical operation receipt and be recovered using their original idempotency key. This does not extend recovery to every write or historical request. See HTTP, SDK, CLI and MCP examples. DNSSEC uses its separate endpoint and state contract.

Use the native Python, Node.js, PHP and Go recovery examples. They also show each SDK's canonical operation-response option for atomic deployment.

Downloads and checksums

The SDK tab links to SHA256SUMS. Download it alongside your archive and use sha256sum --check --ignore-missing SHA256SUMS on Linux, or shasum -a 256 on macOS to compare the archive hash. A checksum detects a damaged or mismatched download.

See troubleshooting if a command is missing or a request fails.