Use the CLI on Windows, macOS and Linux
Install the Python CLI, configure credentials and follow read-first product workflows.
Use bf for new integrations. bf-api is an actively supported compatibility alias of the same CLI, not a separate lower-level interface. Both are included in the Python SDK package and use the same commands, authentication and version. It calls the public API from your computer; it does not execute a remote shell command inside your server. Server power/reinstall actions run remotely only after the API accepts them. The separate Snabb CLI is not interchangeable.
Install and configure
Download the current Python archive and SHA256SUMS from Settings → API. Python 3.10+ is required. Use a virtual environment and keep TLS verification enabled.
Linux and macOS:
python3 -m venv .venv
source .venv/bin/activate
python -m pip install ./bf-sdk-python-0.1.17.tar.gz
export BF_API_BASE_URL="https://api.blazingfast.io"
export BF_API_KEY="YOUR_KEY_PREFIX"
export BF_API_SECRET="YOUR_ONE_TIME_SECRET"
bf --version
bf service listWindows PowerShell (activation is not required when using the full executable path):
py -3 -m venv .venv
.\.venv\Scripts\python.exe -m pip install .\bf-sdk-python-0.1.17.tar.gz
$env:BF_API_BASE_URL = "https://api.blazingfast.io"
$env:BF_API_KEY = "YOUR_KEY_PREFIX"
$env:BF_API_SECRET = "YOUR_ONE_TIME_SECRET"
.\.venv\Scripts\bf.exe service listThe values above are placeholders. Set real secrets through your private configuration; do not paste them into chat, commit them or include them in shared terminal transcripts. Use either signed credentials or the complete issued BF_API_BEARER, not your portal password. Environment files are not loaded automatically.
Read before changing
bf billing balance
bf billing invoices
bf service list vps --status suspended
bf service list dedicated --status suspended
bf vps status SERVICE_UUID
bf dedicated status SERVICE_UUID
bf vps console SERVICE_UUID
bf dedicated console SERVICE_UUID
bf dns record list example.com
bf tcp-proxy show SERVICE_UUIDChoose IDs from your service list. Service UUID, product UUID, variant UUID, invoice UUID, order UUID and dedicated OS profile ID are different identifiers. Use --help for the intended command; not every API operation has a CLI equivalent.
Console commands return a browser URL. Sign in as the service owner to connect; copying the URL does not grant another account access. They do not provide a native VNC tunnel. For explicit credential reads in a private terminal, use bf vps credentials SERVICE_UUID or bf dedicated credentials SERVICE_UUID with the separate credential permission. Do not log the output.
Dedicated server example
Read the catalog and select its exact configuration code, region, numeric OS profile and supported billing option. A saved SSH key must belong to your account.
bf dedicated catalog
bf dedicated deploy --configuration CONFIGURATION_CODE --region REGION_CODE --os-profile 123 --hostname myserver --ssh-key-id SSH_KEY_UUID --idempotency-key order-dedicated-001
bf dedicated deployment ORDER_UUIDReplace 123 with a returned profile ID; it is not a universal image ID. Deployment creates an unpaid order. Do not add --pay-from-balance unless you explicitly authorize payment. Installation starts after payment and any required administrator approval.
For an active server, after confirming that interruption is acceptable:
bf dedicated power SERVICE_UUID restart --idempotency-key restart-dedicated-001
bf dedicated tasks SERVICE_UUID
bf dedicated task SERVICE_UUID TASK_UUIDReinstall requires --confirm-erase; rescue requires --confirm-rescue. Both need a compatible profile. --wait on deployment/password reset can reveal credentials: use only a private terminal and do not log that output.
Optional quote, deployment and recovery
Discover the actual region, product, variant and configuration values first. The following purchase command charges the account; run it only after authorizing the target and final spending ceiling. deployment.json contains the canonical billing_cycle, hostname, os, optional ssh_key_id and max_total fields for the selected VPS, plus any discovered add-ons. Do not mix these with legacy billing/userConfig/maxTotal fields.
bf version
bf capabilities
bf catalog list REGION_CODE vps
bf catalog options REGION_CODE vps VARIANT_CODE
bf billing deploy REGION_CODE vps VARIANT_CODE --file deployment.json --quote
bf billing deploy REGION_CODE vps VARIANT_CODE --file deployment.json --request-key purchase-example-001 --operation-response --wait
bf operations recover --request-key ORIGINAL_KEY --method POST --path /v1/vps/SERVICE_UUID/reboot --wait
bf operations get OPERATION_ID
bf operations wait OPERATION_ID --wait-timeout 300The --quote invocation is a preview, not a purchase, and is optional. --operation-response requests the canonical receipt; --wait polls without resubmitting. Most supported CLI writes generate, save and print an omitted key before dispatch. Retain it: a new invocation without a key represents a new action. Recovery requires the ORIGINAL_KEY and never generates one. The recovery method and path describe the original write; pass both together when disambiguation is needed. DNSSEC enable/disable still require an explicit --request-key.
A wait timeout does not cancel the operation or establish failure. Recover the original receipt before deciding whether to retry the identical write. A 404 lookup is not proof of no execution; 409 requires more precise selectors; 410 requires reconciling resources and billing. Recovery scope and retention remain endpoint-specific.
Orders, payment and retries
Use the order and payment guide. Draft order creation does not pay. Atomic bf deploy is the combined wallet-payment and provisioning workflow; see the guide for both options. Balance payment can be partial and may start provisioning; inspect the returned result.
Most CLI lifecycle write keys are optional in 0.1.17; DNSSEC enable/disable require --request-key explicitly. If omitted, the CLI generates, saves locally and prints a key before sending. Reuse that key with identical arguments after a timeout; a new invocation without a key represents a new action. Different actions need different keys. If a write times out, check its task, order or invoice before retrying. The SDK does not automatically retry writes. A returned task means accepted, not completed.
See the product coverage matrix for unsupported CLI operations, and endpoint-specific limits. Storage commands are supported: bf storage list, attach-options, attach, detach and rename. Writes require the appropriate scope and confirmation.

