API, SDKs & AI assistants
Back to section

What you can automate by product

Compare public API, CLI, hosted MCP and local MCP coverage before building an integration.

Choose the product first, then the interface. The public API, Python CLI, hosted MCP and local MCP are separate interfaces: an endpoint being available does not mean every client exposes it.

Contract 2026-10-07.1 describes 182 public operations, SDK/CLI 0.1.17 and hosted MCP. Check all endpoint contracts, GET /v1/version and GET /v1/capabilities for deployed availability. Supported actions also depend on provider availability. Product availability, stock, prices, operating systems and permissions remain account-specific; discover them at request time.

CLI names

Use bf for new integrations. bf-api is an actively supported compatibility alias of the same CLI, not a separate lower-level interface. Both are included in the Python SDK package and use the same commands, authentication and version.

Current purchase and operation workflows

SDK/CLI 0.1.17 supports contract 2026-10-07.1. Read GET /v1/version and GET /v1/capabilities, then discover product purchase policies and requirements before configuring a purchase. A quote is optional: discovery can lead directly to an authorized deployment. Quotes do not reserve stock or lock prices; send an authorized max_total ceiling for the full final order amount.

Draft order creation does not charge the account. Atomic deployment is the documented exception: it combines order creation, payment of the full final order amount from account balance and queued provisioning. Paid is not ready; accepted is not completed. Service lifecycle status is separate from runtime power state.

Supported tracked deployment, VPS and dedicated writes can return a canonical operation receipt and be recovered using their original idempotency key. This does not extend recovery to every write or historical request. See HTTP, SDK, CLI and MCP examples. DNSSEC uses its separate endpoint and state contract.

Product coverage

Product Public API Python CLI Hosted MCP Local MCP
VPS Status, scoped recorded credentials, browser-console link, power, reinstall, password reset, SSH keys, firewall, snapshots and backups bf vps Status, browser-console link, power, reinstall, firewall, snapshots and backups; no passwords Status, console link, snapshots/backup reads, opt-in credentials and power writes; no full management parity
Dedicated servers Catalog, unpaid deployment, status, credentials, browser-console link, power, reinstall, rescue, password reset, tasks and statistics bf dedicated Status, console link, power, reinstall, rescue, tasks and statistics; no dedicated deployment or password/credential tool Dedicated catalog/deployment/status/console/tasks/options/statistics; credentials and writes are separately opt-in
DNS Zones, records, imports/previews and templates bf dns Zones, records, templates, import preview and creation Zone/record reads and basic opt-in zone/record writes; no template/import-preview tools
Website Protection Record protection, proxy/origin settings, SSL/custom loading page and country policy bf dns protection, dns country-policy, service dns waf Safe settings, record protection, proxy/origin and country changes No dedicated Website Protection tools
TCP Proxy Backend, ports, limits, source/country rules and traffic statistics bf tcp-proxy Configuration/statistics and backend, port and access-policy changes No dedicated TCP Proxy tools
Domains Availability, catalog, owned domains, contacts, nameservers, transfer status, lock, privacy, authorization code and DNSSEC bf domain Owned domain/status/transfer reads; nameserver, lock and privacy changes Availability/catalog/contact/status/DNSSEC reads; DNSSEC update is separately opt-in
Storage volumes List, eligible attach targets, attach, detach and rename bf storage list/attach-options/attach/detach/rename List, attach options and attach/detach/rename Volume listing only
cPanel hosting Generic service/catalog/billing operations, not cPanel website/mail/file administration bf service and billing Generic service and billing tools Generic service and billing reads
Billing Catalog/options, quotes, orders, invoices, balance payments and transactions bf billing; selected service settings Products, VPS order options, unpaid orders, balance payment, invoices and transactions Balance/invoice reads; no generic order/payment tools
SSH keys and firewall Key and policy management; applying supported settings to VPS bf ssh, firewall, vps Public key and firewall policy reads/changes Key/policy listing only

Local MCP viewing tools are enabled by default. Its write tools require BF_API_MCP_ENABLE_MUTATIONS=1 and the corresponding API-key permissions. Hosted MCP uses OAuth and the selected connection policy instead. Tool names also differ: hosted get_vps_status versus local bf_vps_status.

Important boundaries

  • Draft orders and invoice payment are separate requests. The atomic POST /v1/deploy/... workflow pays the full amount from wallet credit and queues provisioning in one request. Quote optionally; inspect the final invoice before authorizing balance payment. Catalog options do not reserve capacity.
  • Dedicated installation may require administrator approval. Service lifecycle (active/suspended/terminated), server power and installation tasks are different states.
  • DNS zone creation does not register a domain or switch its registrar nameservers. Website Protection is not the same as proxy routing.
  • Registered-domain DNSSEC is available through the public HTTP API: read/refresh with domains.read; enable/disable with domains.write, acknowledgement and a stable retry key. HTTP 202 is asynchronous; poll the same domain’s DNSSEC status. See the DNSSEC workflow. SDK/CLI 0.1.17 includes DNSSEC commands and local MCP tools; hosted MCP has none.
  • API/CLI/MCP console tools return login-protected browser links, not raw VNC connections. The browser checks account ownership before connecting. cPanel administration remains dashboard-specific. Hosted MCP never returns passwords or private keys.
  • Connectivity and extra-IP options depend on the selected dedicated product and provisioning support. A recorded bandwidth entitlement is not proof that a network rate limit has been applied.
  • Do not assume customer S3/object-storage, license-management, affiliate or reseller administration APIs. Only the advertised catalog and documented customer routes are supported. Snabb is a separate platform and does not use these tools.

Service filters and access

Use GET /v1/services?status=suspended&type=vps,dedicated to list suspended VPS and dedicated services. Filters are applied before pagination; status=all includes all lifecycle states. Safe summaries include recorded hostname and service type, never passwords.

VPS GET /v1/vps/{serviceId}/credentials requires vps.credentials.read; dedicated credential reads require dedicated.credentials.read. A VPS password is the platform record, not a live guest verification, and can become stale after a manual OS change. Handle credential responses privately.

Download a brief

Each plain-text brief includes purpose, API routes, working CLI examples, hosted/local MCP coverage and limits. Start with the brief index, then download the product you need:

Current briefs: Catalog discovery and Integration workflows.

Read authentication, CLI workflows and local MCP before making changes.