InvAPI Control Panel API Documentation¶
This documentation describes the overall design and principles of the API, along with specific endpoints and usage examples.
Overview
The invapi.hostkey.com control panel is built on top of this API.
Making API Requests¶
All API requests must be made over HTTPS to ensure encryption of data in transit.
Use the POST method for all requests unless otherwise specified.
API Example Format¶
Examples in this documentation use curl, a command-line HTTP client. curl is pre-installed on most Linux and macOS systems and is available for download on all major platforms, including Windows.
Each example is split across multiple lines using the \ line continuation character, which is compatible with bash. A typical request looks like this:
Example POST Request:
The -X flag specifies the HTTP method. For consistency, the method is included in all examples, even when not explicitly required for GET requests.
Examples that require a JSON payload in the request body pass the data via the --data parameter.
All API responses are returned in JSON format and formatted in this documentation for readability.
Tip: Environment Variables
To avoid repeating your API token in every example, you can export it once as an environment variable in your terminal. On Linux or macOS:
The token will then be automatically substituted in your requests.
Disclaimer
All values shown in this documentation are for illustrative purposes only. Do not rely on operating system IDs, plan identifiers, or other example values. Always use your actual server, network, or domain identifiers when querying or creating resources. In some cases, only the account API key will work, not the specific server key (and vice versa), so if you encounter method authorization errors, try switching the API key type.
api_keys.php¶
API key management module: creation, editing, deletion, viewing history, and retrieving lists of keys for customers and servers.
| Method | Description |
|---|---|
add | Creates a new API key for a customer or a specific server. The customer must have active servers. |
delete | Deletes the specified API key from the system. |
edit | Modifies parameters of an existing API key (name, IP, status, expiration). |
history | Returns the history of actions performed on API keys (creation, modification, deletion). |
list | Returns a list of all API keys for the current customer. |
list_for_server | Returns a list of API keys bound to a specific server. |
view | Returns detailed information about a single API key. |
auth.php¶
Authentication and authorization module: session management, login via WHMCS, LDAP, API keys, and SSO (Google, GitHub, VK), 2FA verification, SMS and email, as well as customer tag management.
| Method | Description |
|---|---|
2fa_check | Validates the two-factor authentication code for the current user session. |
2fa_resend | Resends the two-factor authentication code to the specified method (Email or SMS) for the current session. |
billing_list | Returns a list of available payment systems (billings) configured for the current user or administrator. |
email_check | Checks if a customer exists by email in the specified billing location. If the customer is not found, a new profile is created. Sends a verification code to the email. |
flip_tag | Creates or removes the specified tag for the customer. If the tag already exists, it will be removed; if it does not exist, it will be added. |
get_log | Returns the authorization event log for a specified period or by token. |
get_log_details | Returns detailed information about authentication events for a user via their token. |
github_init | Initiates the authorization process via GitHub, generates a unique state, and returns client data to redirect the user to GitHub. |
github_signin | Initiates the OAuth authorization process via GitHub. Generates a temporary state and token for subsequent code-to-session exchange. |
google_signin | Performs login using a Google ID Token. If the token is valid, it attaches it to the current session or links it to an existing user account. |
info | Returns detailed information about the current user session, including role, permissions, customer data, and a list of available servers. |
login | Authorizes a user via the provided API key, establishes a session, and returns data regarding permissions and available servers. |
logout | Deletes the current active access token, terminating the user session. |
session_reset | Terminates all active user sessions based on their email and reset token. Performs cleanup of tags (sessions) in the database. |
set_tag | Creates or removes a tag for the customer. For regular users, only the 'auto_credit' tag is allowed. |
tg_verify | Binds the user's Telegram username to their account and returns a link to the bot for notifications. |
vk_init | Initiates the OAuth authorization process via VK, generating temporary data (state, code_challenge) and saving it in the database for subsequent verification. |
vk_signin | Initiates the user authorization process through the VKontakte social network. Creates temporary tags to complete the OAuth process and redirects to a confirmation page. |
whmcslogin | Performs login. Supports standard email/password authorization, as well as login via third-party services (Google, GitHub, VK) and automatic billing selection. |
eq.php¶
Equipment Management Module (eq.php): API for server deployment, power management, IPMI, backups, searching, and retrieving detailed hardware configuration information.
| Method | Description |
|---|---|
abort_reinstall | Stops the server reinstallation process, removes associated tags (reinstall_start, autodeploy_start, autodeploy_timeout), and restores VLAN settings. |
add_ipmi_admin | Creates a new user with administrator privileges for IPMI management. If the user already exists, returns their data. |
add_ipmi_user | Adds a new user to the IPMI management system for a specific server. If the user is an administrator, parameters may be overridden. |
announceip | Performs announcement of a specified subnet or a specific IP address for the server. |
backup_get_schedule | Returns the current automatic backup schedule for the specified server. |
backup_list | Returns a list of available backups for the specified equipment (server). |
backup_save_schedule | Saves the configured backup schedule for the specified server. |
boot_dev | Requests switching the server boot mode (PXE or disk) to use bootable media. |
check_backup_lock | Checks if there is an active lock on performing backup operations for the specified server. |
check_pin | Checks the PIN code for operations. |
clear_pxe | Clears the current PXE configuration for the specified host. If the hostname parameter is not provided, the server ID is used. |
console | Requests the launch of the server management console via IPMI/NoVNC. |
create_backup | Initiates the backup creation process for the specified server. The operation is performed asynchronously. |
create_pxe | Initiates the PXE configuration creation process for server reinstallation. Supports configuring hostname, SSH keys, and post-install scripts. |
delete_backup | Deletes the specified server backup by its name. |
deploy | Starts the deployment process of an existing server by its ID or from a preset. Supports OS selection, disk parameter configuration, SSH keys, and custom domains. |
get_ipmi | Returns a list of available IPMI interfaces for the specified server, including IP address and vendor model. |
get_traffic | Returns IPv4 traffic usage data for the specified server. |
get_upgrade_key | Returns an upgrade key for the server, linked to a specific invoice via tags. |
getserversforannounce | Returns a list of available servers (status rent or power_off) matching IPv4 mask constraints, belonging to the current owner or their subaccount. |
groups | Returns a list of groups for the specified server. |
hard_off | Sends a request for a hard stop or reboot of the hardware via IPMI/OpenStack. |
history | Returns the server event history. |
list | Returns a list of available servers and equipment with support for advanced search by various parameters (location, status, type, IP, MAC, etc.). |
off | Turns off the server. |
on | Turns on the server. |
order_instance | Starts the deployment process of a new server from a preset or reinstallation of an existing server with OS, software, and network parameter selection. |
ovirt_novnc | Requests the launch of a noVNC console for the server via the oVirt interface. Requires access rights to the server. |
reboot | Sends a request to reboot the hardware. If the server is in standby mode, confirmation via callback may be required. |
reinstall | Starts the server reinstallation preparation process (PXE configuration creation). Returns an operation key and stage status. |
remove_ipmi_user | Removes an additional IPMI user for the specified server. |
request_backup_link | Requests generation of a temporary link to download a server backup. |
restore_backup | Starts the server restoration process from a specified backup. The operation is asynchronous and returns a callback for status tracking. |
search | Returns a list of available servers and instances based on various filtering criteria (group, location, status, IP, MAC, type, etc.). |
sensors | Returns current sensor readings (temperature, fan speed, etc.) for the specified server. |
set_pin | Sets a PIN code for operations. |
show | Returns detailed information about the server, including hardware (hwconfig), operating system, IP addresses, interfaces, and IPMI. |
status | Returns the current equipment status, including state data (power_off, rent, etc.), hardware configuration, IP addresses, interfaces, and IPMI. |
status_check | Returns the current equipment status (availability, state, etc.) without requiring authorization. |
suspend | Requests suspension (suspend) or resumption (unsuspend) of server maintenance. Requires access rights and, in some cases, an administrator lock check to perform the operation. |
traffic_add | Increases the outbound traffic limit for the server and creates a corresponding invoice in WHMCS. |
unified_server_search | Unified server search by query. |
unit_reset | Requests a reset of the IPMI module for the specified server. If the request is successful, a callback key is returned to track the task. |
unsuspend | Unlocks the server (unsuspend) if it was previously locked by an administrator. |
eq_callback.php¶
Module for processing asynchronous responses from workers to manage hardware (EQ) and virtual machines. It processes task statuses (deploy, reinstall, backup, network), updates billing, and sends noti
| Method | Description |
|---|---|
check | Checks the execution status of an asynchronous job by key. Returns current state, context, and debug information. |
reinstall | Starts the operating system reinstallation process on the server. If the deploy_options=reinstall parameter is specified in the request, a full cleanup of tags and configuration is performed upon completion. |
ip.php¶
IP address and network infrastructure management module: retrieving IP information, managing PTR records, traffic monitoring, working with subnets and VLANs.
| Method | Description |
|---|---|
get_client_ip | Returns the current IP address of the client making the request to the API |
get_ip | Returns full network configuration information for a specific IP address (mask, network, etc.) |
get_ptr | Checks whether the specified IP address belongs to the server with the given ID and returns the current PTR record for this IP in the specified location. |
get_traffic | Returns inbound and outbound traffic data for the specified IP address for a selected period. Can return both summary information and detailed timestamps. |
list_free_ip | Returns a list of unused IP addresses for the specified location based on Route Reflector tags. Used by internal mechanisms to prevent scanning. |
set_main | Sets the specified IP address as the primary (main) one for the server's network interface. |
update_ptr | Updates the reverse DNS record (PTR) for an IP address belonging to a server. Requires permission verification and proof of IP ownership by the server. |
iso.php¶
ISO Image Management Module: uploading, deleting, mounting, and unmounting images on servers, as well as retrieving lists of available and uploaded images.
| Method | Description |
|---|---|
add | Adds a new ISO image or updates an existing one by name. |
delete | Deletes an ISO image by ID. |
list_iso | Returns a list of available ISO images. |
mount_iso | Mounts an ISO image on the specified server. |
unmount_iso | Unmounts an ISO image from the specified server. |
upload | Uploads an ISO image via URL. |
uploaded | Returns a list of uploaded ISO images for a client or staff member. |
jenkins.php¶
Jenkins integration module for task management: retrieving the list of available tasks and executing them for servers.
| Method | Description |
|---|---|
get_tasks | Returns the list of available Jenkins tasks accessible to the current user or client. |
jira.php¶
Jira integration module for creating support tickets for server management (power, reboot, KVM) and sales assistance requests.
| Method | Description |
|---|---|
request_PXEboot | Creates a Jira ticket for manual PXE booting of the server if remote control is unavailable. |
request_assistance | Sends a request for technical or commercial assistance by creating a Jira ticket, checking for duplicates, and collecting server and billing data. |
request_check | Creates a Jira ticket to check the server and boot it into the OS if remote control is unavailable. |
request_kvm | Creates a Jira ticket to connect IP KVM to the server. |
request_poff | Creates a Jira ticket for manual power off of the server. |
request_pon | Creates a Jira ticket for manual power on of the server. |
request_reboot | Creates a Jira ticket for manual reboot of the server. |
nat.php¶
Static NAT management module: adding and removing IP address forwarding rules via MikroTik.
| Method | Description |
|---|---|
add_static_nat | Creates a static NAT passthrough via Microtic for the specified server with ACL and TTL support. |
remove_static_nat | Removes the static NAT passthrough for the specified server or white IP. |
net.php¶
Network infrastructure management module: adding and removing IP addresses, blocking traffic, managing network port status, retrieving statistics, and displaying Cacti graphs.
| Method | Description |
|---|---|
add_ipv4 | Adds the specified number of IPv4 addresses to a server or assigns specific IP addresses. Supports automatic search for free IPs in a VLAN or manual specification of a list. |
block_ip | Blocks the specified IP address on the server via BIRD or blackhole. Requires authentication. |
get_status | Returns the current status and configuration of the server's network port. Requires authentication. |
port_off | Disables the specified server network port and adds a block tag with the specified reason. |
port_on | Enables the specified server network port, removing the block (tag 'block') if it was not set by an administrator. |
remove_ipv4 | Removes the specified IPv4 address from the server. If the remove_all flag is passed, all addresses are removed. |
show_cacti | Returns traffic monitoring graph data for the specified server and port from the Cacti system. |
show_ipv4_free | Returns a list of available IPv4 addresses for the specified server and interface in a given VLAN. Requires authentication. |
unblock_ip | Removes the block from the specified IP address on the server. Requires access rights verification. |
os.php¶
Operating system management module: provides methods for adding, removing, updating, and retrieving a list of OS with filtering by hardware compatibility and licenses.
| Method | Description |
|---|---|
list | Returns a list of operating systems. If id or instance_id is specified, filters OS by compatibility with hardware or preset. Also returns a list of excluded OS. |
pdns.php¶
DNS record and zone management module: adding, deleting, and viewing domains, subdomains, and zones, as well as retrieving callback-URL information.
| Method | Description |
|---|---|
add_dns | Adds a new DNS record to the specified zone. |
add_domain | Adds a new domain to the DNS system for the specified client. |
delete_dns | Deletes the specified DNS record. |
delete_domain | Deletes the domain and all associated records. |
get_cb_url | Returns the URL for callback notifications. |
list_domains | Returns the list of client domains. |
list_zones | Returns the list of DNS zones. |
view_zone | Returns details of the specified DNS zone. |
presets.php¶
Server preset management module: retrieving lists, grouping, searching for suitable servers, and detailed configurations with prices in different currencies.
| Method | Description |
|---|---|
groups | Returns a list of available preset groups |
info | Returns a list of available currencies for displaying preset prices. By default, it returns EUR and RUB. |
list | Returns a list of available server presets with filtering by location and access rights |
search | Returns a list of servers matching the specified preset parameters (name, location, search area) |
show | Returns information about a preset by ID or name. Supports filtering and limits. |
rhr.php¶
Remote Hands Requests Management Module: creation, filtering, status updates, and communication regarding requests.
| Method | Description |
|---|---|
add | Creates a new Remote Hands Request (RHR) specifying the type and equipment. |
chat | Adds a client-visible message to the request history. |
discard | Recursively changes the request status to canceled or closed. |
list | Returns a list of available RHR tasks with filtering by location, status, and date. |
s3.php¶
S3 storage management module: creating and deleting accounts, managing buckets and files, obtaining usage statistics, managing pricing plans and billing.
| Method | Description |
|---|---|
cancel_payment_account_deletion | Cancels the S3 account deletion process initiated via a deletion request. Restores the service status. |
create_account | Creates a new S3 account based on the selected pricing plan, checks free account limits and user credits, and creates an order in the billing system. |
create_bucket | Creates a new S3 bucket for an existing user account. Requires an active s3uid belonging to the client. |
create_order | Creates a new S3 account (bucket) for the user, links it to a pricing plan, and places an order in the billing system. |
delete_account | Deletes the user's S3 account, cancels associated services, and performs action auditing. |
delete_bucket | Deletes the specified S3 bucket after verifying its ownership by the user and its presence in the list of available buckets. |
delete_file | Deletes the specified file from the S3 bucket. Requires a valid s3uid of the account owner. |
delete_payment_account | Requests subscription cancellation and S3 account deletion. If successful, the service is moved to cancellation status. |
get_buckets | Returns a list of S3 buckets, traffic information, and snapshots for the specified account. |
get_buckets_rmq | Returns the user's bucket list, storage usage information, billing data, and S3 access credentials. |
get_files | Returns a list of files and folders in the specified S3 bucket with pagination support via continuation token. |
get_users | Returns a list of S3 accounts with detailed information on plans, traffic, and storage usage. Supports filtering by plan_id, email, s3uid, billing, and location. |
history | Returns the action history associated with a specific ID (likely an account or user). |
list_plans | Returns a list of available S3 plans including VAT rate and user currency. For administrators, it can return a specific plan by ID. |
show_key | Returns the decrypted secret key or public access key for the specified account. |
software.php¶
Software management module: provides methods to get a list of available software filtered by server characteristics or preset, as well as selecting compatible presets and operating systems for specifi
| Method | Description |
|---|---|
list | Returns a list of software suitable for a specific server (id) or preset (instance_id), taking into account licenses, hardware specifications, and promotions. |
stocks.php¶
Server inventory management module: provides lists of available servers with filtering by locations and groups, as well as detailed information about a specific server.
| Method | Description |
|---|---|
list | Returns a list of available servers in inventory with the ability to filter by location and group. |
show | Returns detailed information about a specific server by its identifier. |
tags.php¶
Tag management module for infrastructure components: adding, removing, clearing, searching, and displaying tag lists for servers and variables.
| Method | Description |
|---|---|
add | Adds a custom tag to a server or component. Supports bulk addition via an ID list. |
clear | Clears all or non-essential tags from a component. For clients, only public tags are available. |
get | Retrieves tags for a component. (Implementation is empty in code, method is in whitelist) |
list | Returns a list of tags for a specific server or component. For clients, there is a restriction by component type (eq, vars). |
remove | Removes a tag by its name for a specific component or removes all specified tags from an ID list. If id_list is passed, the operation is performed in bulk. |
search | Searches for components matching a specific tag and value. |
search_user | Searches for user equipment by tag value. Used in global search form. |
show | Shows possible tags for a component. (Implementation is empty in code, method is in whitelist) |
traffic_plans.php¶
Traffic tariff plan management module: creation, deletion, updating, and retrieval of available plans with filtering by server or location and price conversion.
| Method | Description |
|---|---|
list | Returns a list of suitable traffic tariff plans for the specified server (id) or location. Supports filtering by hardware type and price conversion to EUR/USD. |
vm.php¶
Virtual Machine (VM) management module providing an API for creating, retrieving, deleting, and restoring snapshots, as well as loading statistics.
| Method | Description |
|---|---|
create_snapshot | Initiates the creation of a snapshot for the specified virtual machine. Returns a task key for status tracking. |
get_snapshot | Returns a list of snapshots and settings for the specified virtual machine. |
load_stats | Initiates the loading of resource usage statistics for the virtual machine. |
remove_snapshot | Initiates the deletion of a snapshot with the specified name. |
restore_snapshot | Initiates the restoration of the virtual machine state from a snapshot. |
update_restore_settings | Updates automatic restore and snapshot rotation settings for the specified virtual machine. |
whmcs.php¶
WHMCS integration module for managing customers, invoices, credit, order cancellations, and server billing data.
| Method | Description |
|---|---|
add_contact | Adds a new additional contact for the customer in WHMCS. If request type is not specified, a random contact with a random email is created. |
apply_credit | Applies available balance (credit) of the customer to pay a selected invoice in WHMCS. If the invoice status changes to 'Paid' after payment, traffic overage is automatically cleared. |
create_addfunds | Creates an invoice in WHMCS for topping up the customer's balance. If the subscribe option is enabled, automatic renewal will be configured. |
delete_cancellation_request | Deletes an existing cancellation request for a specific server, allowing the invoice status to be restored or a new one to be generated. |
delete_contact | Deletes an additional contact linked to the customer in WHMCS. |
download_invoice | Returns a PDF file of the invoice in base64 format for viewing or downloading. |
generate_due_invoice | Generates the next due invoice in WHMCS. Blocked if the customer has unpaid invoices or if the current billing cycle is not yet completed. |
get_billing_data | Returns detailed information about the billing parameters of a specific server, including EU B2C data (right of withdrawal) and license details in case of cancellation under EU rules. |
get_cancellation_requests | Returns a list of active service cancellation requests for a specific server or user with filtering by date, type, and payment status. |
get_client | Returns detailed information about the authenticated client, including WHMCS data (profile, group, currency) and internal system data (tags, verification status). If the full parameter is provided, an extended dataset is returned. |
get_clientgroups | Returns a list of available client groups from WHMCS for the specified location. |
get_contacts | Returns a list of additional contacts linked to the customer in WHMCS. If email subaccount is specified, only those contacts that have corresponding access rights are returned. |
get_invoice | Returns detailed information about an invoice from WHMCS, including customer data and a list of items. |
get_invoices | Returns a list of all invoices associated with the customer in WHMCS. If the client is authenticated, only their invoices are returned. |
get_related_invoices | Returns a list of invoices associated with a specific server or customer account in WHMCS |
getcredits | Returns information about available credits on the customer's account in the specified WHMCS location. |
getpaymentgw | Returns a list of available payment methods (gateways) for a specific invoice with support for link formatting and HTML button code. |
mass_pay | Creates one single invoice to pay multiple selected customer invoices. |
request_cancellation | Initiates the process of canceling an order or subscription in WHMCS. Checks for active licenses, invoice payment status, and refund eligibility (including EU B2C rules). If there are traffic debts, it may calculate the withholding amount. |
request_subscription_cancellation | Initiates the bank subscription cancellation process for a server, creating a JIRA ticket and tagging the server accordingly. |
reset_password | Allows initiating the password reset process (sending a link via email) or completing it using a recovery token and 2FA code. |
transactions | Returns a list of user financial transactions from WHMCS by the specified ID or within the current session. |
update_client | Updates customer information in WHMCS and the local database, including contact details, 2FA settings, IP-ACL, and custom fields. Changing email or phone may require re-verification. |
update_contact | Updates existing customer contact data (first name, last name, email, phone) in the WHMCS system. Changing email or phone may require re-verification. |