What you can automate by product
Compare public API, CLI, hosted MCP and local MCP coverage before building an integration.
Choose the product first, then the interface. The public API, Python CLI, hosted MCP and local MCP are separate interfaces: an endpoint being available does not mean every client exposes it.
Contract 2026-10-07.1 describes 182 public operations, SDK/CLI 0.1.17 and hosted MCP. Check all endpoint contracts, GET /v1/version and GET /v1/capabilities for deployed availability. Supported actions also depend on provider availability. Product availability, stock, prices, operating systems and permissions remain account-specific; discover them at request time.
CLI names
Use bf for new integrations. bf-api is an actively supported compatibility alias of the same CLI, not a separate lower-level interface. Both are included in the Python SDK package and use the same commands, authentication and version.
Current purchase and operation workflows
SDK/CLI 0.1.17 supports contract 2026-10-07.1. Read GET /v1/version and GET /v1/capabilities, then discover product purchase policies and requirements before configuring a purchase. A quote is optional: discovery can lead directly to an authorized deployment. Quotes do not reserve stock or lock prices; send an authorized max_total ceiling for the full final order amount.
Draft order creation does not charge the account. Atomic deployment is the documented exception: it combines order creation, payment of the full final order amount from account balance and queued provisioning. Paid is not ready; accepted is not completed. Service lifecycle status is separate from runtime power state.
Supported tracked deployment, VPS and dedicated writes can return a canonical operation receipt and be recovered using their original idempotency key. This does not extend recovery to every write or historical request. See HTTP, SDK, CLI and MCP examples. DNSSEC uses its separate endpoint and state contract.
Product coverage
| Product | Public API | Python CLI | Hosted MCP | Local MCP |
|---|---|---|---|---|
| VPS | Status, scoped recorded credentials, browser-console link, power, reinstall, password reset, SSH keys, firewall, snapshots and backups | bf vps |
Status, browser-console link, power, reinstall, firewall, snapshots and backups; no passwords | Status, console link, snapshots/backup reads, opt-in credentials and power writes; no full management parity |
| Dedicated servers | Catalog, unpaid deployment, status, credentials, browser-console link, power, reinstall, rescue, password reset, tasks and statistics | bf dedicated |
Status, console link, power, reinstall, rescue, tasks and statistics; no dedicated deployment or password/credential tool | Dedicated catalog/deployment/status/console/tasks/options/statistics; credentials and writes are separately opt-in |
| DNS | Zones, records, imports/previews and templates | bf dns |
Zones, records, templates, import preview and creation | Zone/record reads and basic opt-in zone/record writes; no template/import-preview tools |
| Website Protection | Record protection, proxy/origin settings, SSL/custom loading page and country policy | bf dns protection, dns country-policy, service dns waf |
Safe settings, record protection, proxy/origin and country changes | No dedicated Website Protection tools |
| TCP Proxy | Backend, ports, limits, source/country rules and traffic statistics | bf tcp-proxy |
Configuration/statistics and backend, port and access-policy changes | No dedicated TCP Proxy tools |
| Domains | Availability, catalog, owned domains, contacts, nameservers, transfer status, lock, privacy, authorization code and DNSSEC | bf domain |
Owned domain/status/transfer reads; nameserver, lock and privacy changes | Availability/catalog/contact/status/DNSSEC reads; DNSSEC update is separately opt-in |
| Storage volumes | List, eligible attach targets, attach, detach and rename | bf storage list/attach-options/attach/detach/rename |
List, attach options and attach/detach/rename | Volume listing only |
| cPanel hosting | Generic service/catalog/billing operations, not cPanel website/mail/file administration | bf service and billing |
Generic service and billing tools | Generic service and billing reads |
| Billing | Catalog/options, quotes, orders, invoices, balance payments and transactions | bf billing; selected service settings |
Products, VPS order options, unpaid orders, balance payment, invoices and transactions | Balance/invoice reads; no generic order/payment tools |
| SSH keys and firewall | Key and policy management; applying supported settings to VPS | bf ssh, firewall, vps |
Public key and firewall policy reads/changes | Key/policy listing only |
Local MCP viewing tools are enabled by default. Its write tools require BF_API_MCP_ENABLE_MUTATIONS=1 and the corresponding API-key permissions. Hosted MCP uses OAuth and the selected connection policy instead. Tool names also differ: hosted get_vps_status versus local bf_vps_status.
Important boundaries
- Draft orders and invoice payment are separate requests. The atomic
POST /v1/deploy/...workflow pays the full amount from wallet credit and queues provisioning in one request. Quote optionally; inspect the final invoice before authorizing balance payment. Catalog options do not reserve capacity. - Dedicated installation may require administrator approval. Service lifecycle (active/suspended/terminated), server power and installation tasks are different states.
- DNS zone creation does not register a domain or switch its registrar nameservers. Website Protection is not the same as proxy routing.
- Registered-domain DNSSEC is available through the public HTTP API: read/refresh with domains.read; enable/disable with domains.write, acknowledgement and a stable retry key. HTTP 202 is asynchronous; poll the same domain’s DNSSEC status. See the DNSSEC workflow. SDK/CLI 0.1.17 includes DNSSEC commands and local MCP tools; hosted MCP has none.
- API/CLI/MCP console tools return login-protected browser links, not raw VNC connections. The browser checks account ownership before connecting. cPanel administration remains dashboard-specific. Hosted MCP never returns passwords or private keys.
- Connectivity and extra-IP options depend on the selected dedicated product and provisioning support. A recorded bandwidth entitlement is not proof that a network rate limit has been applied.
- Do not assume customer S3/object-storage, license-management, affiliate or reseller administration APIs. Only the advertised catalog and documented customer routes are supported. Snabb is a separate platform and does not use these tools.
Service filters and access
Use GET /v1/services?status=suspended&type=vps,dedicated to list suspended VPS and dedicated services. Filters are applied before pagination; status=all includes all lifecycle states. Safe summaries include recorded hostname and service type, never passwords.
VPS GET /v1/vps/{serviceId}/credentials requires vps.credentials.read; dedicated credential reads require dedicated.credentials.read. A VPS password is the platform record, not a live guest verification, and can become stale after a manual OS change. Handle credential responses privately.
Download a brief
Each plain-text brief includes purpose, API routes, working CLI examples, hosted/local MCP coverage and limits. Start with the brief index, then download the product you need:
- VPS · Dedicated servers
- cPanel hosting · Domains
- DNS · Website Protection
- TCP Proxy · Storage volumes
- Backups and snapshots
- SSH keys and firewall · Billing and orders
- Affiliate rewards and partnerships
- Catalog discovery · Integration workflows
Current briefs: Catalog discovery and Integration workflows.
Read authentication, CLI workflows and local MCP before making changes.

