The REST API
Everything the panel does is available over HTTP, at https://panel.example.com/api. Your own
tools call it with an API key, at the level you give the key.


Create a key
Section titled “Create a key”- Open Integrations → API keys and choose New key.
- Give it a Name that says what uses it, and pick its Access.
- Choose Create, and copy the token. It is shown only this once.
A key’s level is fixed for its life. Make one key per integration, so the Jobs list and the activity log say which one did what. Revoke ends a key at once.
| Level | For | What it can do |
|---|---|---|
| Read only | Dashboards and reports | See sites, servers, jobs, backups, the WordPress inventory, mail, traffic and settings, and list files. Never a file’s contents, a command’s output or a password |
| Manage | Tools that work on sites | Also what each site’s WordPress admin could do: create sites, plugins, themes, WP-CLI, shell and REST calls, files, logins, backups and restores, custom schedules |
| Full | Tools that run the panel | Also the panel itself: servers, settings, mail, DNS, offsite destinations, the catalog and recipes, blocked addresses, the backup policy, deleting and moving sites, updates |
The API reference names the level each endpoint needs.
Send a request
Section titled “Send a request”Send the key as a Bearer token. No cookie, CSRF header or login call is needed.
curl -s "https://panel.example.com/api/sites" -H "Authorization: Bearer wpl7_..."Every error has the same shape:
{"error": {"code": "...", "message": "..."}}. An unknown or revoked key gets
401 unauthorized. A key below an endpoint’s level gets 403 forbidden, which names both levels.
Over 300 requests a minute get 429 rate_limited. While the panel updates itself, changes get
503 maintenance.
Follow a job
Section titled “Follow a job”Anything slow answers 202 with a job and a Location: /api/jobs/<id> header. Poll the job until
its status is succeeded, failed or canceled:
curl -s "https://panel.example.com/api/jobs/17?logAfter=0" -H "Authorization: Bearer wpl7_..."The answer holds the job, its new log lines and lastSeq. Pass lastSeq as the next logAfter
to get only new lines. Poll about once a second. A site takes one job at a time, so a second change
meanwhile gets 409 job_conflict.
Test a key and see what it did
Section titled “Test a key and see what it did”The Console on API keys → Docs sends real requests to your panel. To check a new key, turn on Send as an API key instead of this browser session, paste the Token and choose Send.
API keys → Activity lists every request made with a key, refused ones included, with the job each one started. The panel’s own browser session is not recorded. Requests are kept for 30 days by default, set under Keep requests for.

Create a site and take it live
Section titled “Create a site and take it live”-
Create the site on its dev domain. A Manage key is enough.
Terminal window curl -sX POST "https://panel.example.com/api/sites" -H "Authorization: Bearer wpl7_..." -H 'content-type: application/json' -d '{"title": "Northwind Bakery", "slug": "northwind-bakery", "domainMode": "dev", "adminUser": "northwind", "adminEmail": "[email protected]"}' -
Poll the job from the
Locationheader. When it succeeds, itsresultholds the site’surl, such ashttps://northwind-bakery.dev.example.com, and the generatedadminPassword. -
Point the customer’s domain at the server, then go live. The dev address stays as a redirect.
Terminal window curl -sX POST "https://panel.example.com/api/sites/northwind-bakery/go-live" -H "Authorization: Bearer wpl7_..." -H 'content-type: application/json' -d '{"domains": ["northwindbakery.example", "www.northwindbakery.example"], "keepDevAlias": true}'
Adding "manageDns": true creates the domain’s records through the Cloudflare token, and needs a
Full key.
Add a server and move a site
Section titled “Add a server and move a site”These steps need a Full key.
-
Fetch the panel’s SSH key. Add it to
rooton a fresh Ubuntu 26.04 VPS, through your provider’s account.Terminal window curl -s "https://panel.example.com/api/servers/ssh-public-key" -H "Authorization: Bearer wpl7_..." -
Register the VPS and let the panel set it up. The answer holds the new
serverand its setupjob.Terminal window curl -sX POST "https://panel.example.com/api/servers" -H "Authorization: Bearer wpl7_..." -H 'content-type: application/json' -d '{"name": "nyc1", "sshHost": "203.0.113.20", "devDomain": "dev.example.com", "provision": true, "acmeEmail": "[email protected]"}' -
Once the job succeeds, move the site to the server’s
id.Terminal window curl -sX POST "https://panel.example.com/api/sites/northwind-bakery/move" -H "Authorization: Bearer wpl7_..." -H 'content-type: application/json' -d '{"targetServerId": 2}'
The site keeps its hostnames. With a Cloudflare token, the panel updates their DNS records. Without one, the job log names the records to change, and the old server forwards traffic meanwhile.
Limits
Section titled “Limits”- A key belongs to the panel, not to a person. Two-factor authentication does not apply to it, and endpoints that ask for your own password refuse it.
- A Manage key can read whatever a site holds, license keys included. What it creates inside a site stays after you revoke it.
- The activity log keeps at most the newest 100,000 requests.
- There are no webhooks. Your tool polls jobs.