API and tokens
The same API the web interface uses, with admin-only bearer tokens for integrations.
- Used by
- Admin
- Plan
- Free
- Status
- Available
- Category
- Integrations and business
What it is
Everything the interface does is available over HTTP on the admin port with Authorization: Bearer <token>. A token has a name and a mandatory expiry (at most one year), is shown once and stored as a hash.
What it is for
Billing systems and scripts that create clients, sites and suspensions.
Limits
A token never receives, sees or sets anyone's password or second factor, and cannot open sessions (terminal, mailbox, database, impersonation); those answer 403. It can create the login only for a client account that a token created, and the customer picks their own password from an emailed one-hour link. Listings are paginated with a hard cap of 200.