Skip to content
On this page

Developer documentation

WebRock API v1.0.0

Manage domains, DNS, SSL, FTP, databases, cron jobs, mail and backups from your own scripts, CI pipelines or control panel. Same isolation as the dashboard: every token acts strictly within your own account.

https://www.webrock.online/api/v1 OpenAPI 3.1 spec Sign in to get a token

Quickstart

  1. Book API access in the dashboard under Settings → API access (€22.61 per month incl. VAT, cancel monthly, requires an active hosting plan).
  2. Create a token on the same page. It is shown once — store it like a password.
  3. Send it as a bearer token:
curl -H "Authorization: Bearer wr_…" https://www.webrock.online/api/v1/account

# create a domain with a DNS zone
curl -X POST -H "Authorization: Bearer wr_…" -H "Content-Type: application/json" \
  -d '{"domain":"example.com","dns":true}' https://www.webrock.online/api/v1/domains

# issue a certificate, then poll the job
curl -X POST -H "Authorization: Bearer wr_…" https://www.webrock.online/api/v1/domains/example.com/ssl
curl -H "Authorization: Bearer wr_…" https://www.webrock.online/api/v1/jobs/ssl/example.com

Authentication

Every request except GET / and GET /openapi.json needs Authorization: Bearer wr_…. Tokens are 43 characters, prefixed wr_; we store only a hash.

Up to 10 active tokens per account, optional expiry, instant revocation in the dashboard. A revoked or expired token returns 401.

Subscription gate. Without an active API subscription every hosting endpoint returns 402 SUBSCRIPTION_REQUIRED. GET /account still works and tells you api_subscription.active, so scripts can fail early with a clear message. Tokens survive a lapse — after re-booking they simply work again.

Conventions

Envelope
Success: {"data": …, "request_id": "…"}. Error: {"error": {"code", "message", …}, "request_id"}. 204 has no body.
Request ID
Also sent as X-Request-Id. Quote it in support tickets — we can trace the exact request.
Bodies
JSON only (Content-Type: application/json). Invalid JSON returns 400 INVALID_JSON.
Rate limit
Per token, fixed 60-second window. Headers X-RateLimit-Limit, -Remaining, -Reset; on 429 honour Retry-After.
Async operations
SSL issuance, mail domain creation and backups return 202 with a job handle. Poll GET /jobs/{kind}/{key} until status is ok or error.
Generated secrets
Omit password when creating FTP, database or mail accounts and we generate one. It is returned once in that response and never again.
Timestamps
ISO 8601, UTC.
Stability
v1 is stable. Fields may be added without notice; nothing is removed or renamed within v1.

Error codes

Match on error.code, not on the message — messages may be reworded.

CodeHTTPMeaning
UNAUTHORIZED 401 Missing or invalid bearer token.
TOKEN_EXPIRED 401 The token has passed its expiry date.
SUBSCRIPTION_REQUIRED 402 No active API subscription. Book it in the dashboard.
ACCOUNT_SUSPENDED 403 The account is suspended.
FORBIDDEN 403 The operation is not allowed (e.g. deleting the primary FTP account).
NOT_FOUND 404 Endpoint or resource does not exist / does not belong to you.
METHOD_NOT_ALLOWED 405 Wrong HTTP method; see the `Allow` header.
NO_HOSTING 409 The account has no active hosting product.
ALREADY_EXISTS 409 A resource with that name already exists.
RESOURCE_LOCKED 409 The resource is locked (e.g. suspended).
RESOURCE_IN_USE 409 The resource is still referenced elsewhere.
INVALID_JSON 400 Request body is not valid JSON.
VALIDATION_ERROR 422 One or more fields are invalid; see `fields`.
QUOTA_EXCEEDED 422 The plan limit for this resource type is reached.
FEATURE_DISABLED 422 The feature is not enabled for this account.
RATE_LIMITED 429 Too many requests; wait `retry_after` seconds.
BACKEND_ERROR 502 The hosting service reported an error. Retry later.
BACKEND_UNAVAILABLE 503 The hosting service is temporarily unreachable. Retry with backoff.
MAINTENANCE 503 Planned maintenance. Wait for `Retry-After` and try again.
INTERNAL_ERROR 500 Unexpected error. Quote the `request_id` to support.

Account

GET / Health check

No authentication required.

Response 200 data: Health

FieldTypeDescription
namestring
versionstring
statusstring

GET /account Account and subscription status

Works without an active API subscription — use it to check `api_subscription.active` before making other calls.

Response 200 data: Account

FieldTypeDescription
idinteger
emailstring
hosting_activeboolean
planstring | nullHosting plan key or null.
term_ends_atstring | nullHosting term end (ISO 8601) or null.
suspendedboolean
api_subscriptionobject
tokenobject

GET /account/usage Storage and traffic usage

Response 200 data: Usage

FieldTypeDescription
storageobject
trafficobject

Domains

GET /domains List web domains

Response 200 data: Domain[]

FieldTypeDescription
domainstring
sslboolean
disk_mbnumber
bandwidth_mbnumber

POST /domains Create web domain

Optionally creates a DNS zone pointing at the server IP.

Request body DomainCreate

FieldTypeDescription
domain (required)stringHostname, e.g. example.com.
dnsbooleanAlso create a DNS zone. Default false.

Response 201 data: DomainCreated

FieldTypeDescription
domainstring
sslboolean
dnsbooleanWhether the DNS zone was created.
warningsarray<string>Non-fatal problems, e.g. DNS zone not created.

GET /domains/{domain} Get web domain

Path parameters

NameDescription
domainWeb domain, e.g. `example.com`.

Response 200 data: Domain

FieldTypeDescription
domainstring
sslboolean
disk_mbnumber
bandwidth_mbnumber

DELETE /domains/{domain} Delete web domain

Removes the web domain including its files. Irreversible.

Path parameters

NameDescription
domainWeb domain, e.g. `example.com`.

Response 204

GET /domains/{domain}/aliases List aliases

Path parameters

NameDescription
domainWeb domain, e.g. `example.com`.

Response 200 data: Alias[]

FieldTypeDescription
aliasstring

POST /domains/{domain}/aliases Add alias

Path parameters

NameDescription
domainWeb domain, e.g. `example.com`.

Request body AliasCreate

FieldTypeDescription
alias (required)string

Response 201 data: AliasCreated

FieldTypeDescription
domainstring
aliasstring

DELETE /domains/{domain}/aliases/{alias} Remove alias

Path parameters

NameDescription
domainWeb domain, e.g. `example.com`.
aliasAlias hostname.

Response 204

GET /domains/{domain}/redirect Get redirect

Returns `null` when no redirect is set.

Path parameters

NameDescription
domainWeb domain, e.g. `example.com`.

Response 200 data: Redirect | null

FieldTypeDescription
targetstring
codeinteger301 or 302.

PUT /domains/{domain}/redirect Set redirect

Path parameters

NameDescription
domainWeb domain, e.g. `example.com`.

Request body RedirectSet

FieldTypeDescription
target (required)stringHostname or URL.
codeinteger301 (default) or 302.

Response 200 data: Redirect

FieldTypeDescription
targetstring
codeinteger301 or 302.

DELETE /domains/{domain}/redirect Remove redirect

Path parameters

NameDescription
domainWeb domain, e.g. `example.com`.

Response 204

SSL

GET /domains/{domain}/ssl SSL status

Includes the last issuance job, if any.

Path parameters

NameDescription
domainWeb domain, e.g. `example.com`.

Response 200 data: SslStatus

FieldTypeDescription
domainstring
sslboolean
letsencryptboolean
jobobject | null

POST /domains/{domain}/ssl Issue Let's Encrypt certificate

Asynchronous. Returns `202` with a job handle; poll `GET /jobs/ssl/{domain}`. Rate-limited to one attempt per domain every 5 minutes.

Path parameters

NameDescription
domainWeb domain, e.g. `example.com`.

Response 202 data: Job

FieldTypeDescription
jobstringHandle `kind:key`.
statusnone | pending | started | ok | error
messagestring
updated_atstring | nullISO 8601 or null.

DELETE /domains/{domain}/ssl Remove certificate

Path parameters

NameDescription
domainWeb domain, e.g. `example.com`.

Response 204

DNS

GET /dns/zones List DNS zones

Response 200 data: DnsZone[]

FieldTypeDescription
zonestring
recordsinteger
dnssecboolean

GET /dns/zones/{zone}/records List records

Path parameters

NameDescription
zoneDNS zone, e.g. `example.com`.

Response 200 data: DnsRecord[]

FieldTypeDescription
idstring
namestring`@` for the apex.
typestring
valuestring
priorityinteger | null
ttlinteger | null

POST /dns/zones/{zone}/records Create record

Path parameters

NameDescription
zoneDNS zone, e.g. `example.com`.

Request body DnsRecordInput

FieldTypeDescription
name (required)string`@`, `www`, `mail`, …
type (required)A | AAAA | CNAME | MX | TXT | NS | SRV | CAA | PTR | TLSA | DNSKEY | DS
value (required)string
priorityintegerRequired for MX and SRV.
ttlinteger60 – 2592000 seconds.

Response 201 data: DnsRecord

FieldTypeDescription
idstring
namestring`@` for the apex.
typestring
valuestring
priorityinteger | null
ttlinteger | null

PATCH /dns/zones/{zone}/records/{id} Update record

Partial update — omitted fields keep their value.

Path parameters

NameDescription
zoneDNS zone, e.g. `example.com`.
idRecord id from the list.

Request body DnsRecordInput

FieldTypeDescription
name (required)string`@`, `www`, `mail`, …
type (required)A | AAAA | CNAME | MX | TXT | NS | SRV | CAA | PTR | TLSA | DNSKEY | DS
value (required)string
priorityintegerRequired for MX and SRV.
ttlinteger60 – 2592000 seconds.

Response 200 data: DnsRecord

FieldTypeDescription
idstring
namestring`@` for the apex.
typestring
valuestring
priorityinteger | null
ttlinteger | null

DELETE /dns/zones/{zone}/records/{id} Delete record

Path parameters

NameDescription
zoneDNS zone, e.g. `example.com`.
idRecord id from the list.

Response 204

FTP

GET /ftp List FTP accounts

Response 200 data: FtpAccount[]

FieldTypeDescription
usernamestring
domainstring
pathstring
primaryboolean

POST /ftp Create FTP account

The full login becomes `<panel-user>_<username>`. If `password` is omitted a random one is generated and returned **once**.

Request body FtpAccountCreate

FieldTypeDescription
domain (required)string
username (required)stringSuffix only; lowercase, digits, underscore.
pathstringRelative to the domain root, e.g. public_html/app.
passwordstringMin. 8 chars. Omit to generate.

Response 201 data: FtpAccountCreated

FieldTypeDescription
usernamestring
domainstring
pathstring
primaryboolean
passwordstringOnly when generated. Shown once.

PATCH /ftp/{username} Change FTP password

Omit `password` to generate one.

Path parameters

NameDescription
usernameFull FTP login.

Request body PasswordInput

FieldTypeDescription
passwordstringOmit to generate a random one.

Response 200 data: PasswordChanged

FieldTypeDescription
updatedboolean
passwordstringOnly when generated. Shown once.

DELETE /ftp/{username} Delete FTP account

The primary account cannot be deleted.

Path parameters

NameDescription
usernameFull FTP login.

Response 204

Databases

GET /databases List databases

Response 200 data: Database[]

FieldTypeDescription
namestring
userstring
typestring
hoststring
charsetstring
disk_mbnumber
suspendedboolean

POST /databases Create database

Name and user are prefixed with `<panel-user>_`. Omit `password` to generate one (returned once).

Request body DatabaseCreate

FieldTypeDescription
name (required)stringSuffix; lowercase, digits, underscore, max. 32.
userstringDefaults to name.
typemysql | pgsqlDefault `mysql`.
passwordstringMin. 8 chars. Omit to generate.

Response 201 data: DatabaseCreated

FieldTypeDescription
namestring
userstring
typestring
passwordstringOnly when generated. Shown once.

PATCH /databases/{name} Change database password

Path parameters

NameDescription
nameFull database name.

Request body PasswordInput

FieldTypeDescription
passwordstringOmit to generate a random one.

Response 200 data: PasswordChanged

FieldTypeDescription
updatedboolean
passwordstringOnly when generated. Shown once.

DELETE /databases/{name} Delete database

Irreversible.

Path parameters

NameDescription
nameFull database name.

Response 204

Cron

GET /cron List cron jobs

Response 200 data: CronJob[]

FieldTypeDescription
idstring
minutestring
hourstring
daystring
monthstring
weekdaystring
commandstring
suspendedboolean

POST /cron Create cron job

Request body CronJobCreate

FieldTypeDescription
minutestringDefault `*`.
hourstringDefault `*`.
daystringDefault `*`.
monthstringDefault `*`.
weekdaystringDefault `*`.
command (required)stringSingle line, max. 1024 chars.

Response 201 data: CronJob

FieldTypeDescription
idstring
minutestring
hourstring
daystring
monthstring
weekdaystring
commandstring
suspendedboolean

DELETE /cron/{id} Delete cron job

Path parameters

NameDescription
idJob id from the list.

Response 204

Mail

GET /mail/domains List mail domains

Response 200 data: MailDomain[]

FieldTypeDescription
domainstring
accountsinteger
disk_mbnumber
antispamboolean
antivirusboolean
reject_spamboolean
dkimboolean
sslboolean
catchallstring | null
webmailstring
suspendedboolean
ssl_jobobject | nullOnly on 202 after enabling SSL.

POST /mail/domains Create mail domain

Asynchronous (mail setup takes a while). Returns `202` with a job handle; poll `GET /jobs/mail_create/{domain}`.

Request body MailDomainCreate

FieldTypeDescription
domain (required)string
antispambooleanDefault true.
antivirusbooleanDefault true.
dkimbooleanDefault true.
reject_spambooleanDefault false.

Response 202 data: Job

FieldTypeDescription
jobstringHandle `kind:key`.
statusnone | pending | started | ok | error
messagestring
updated_atstring | nullISO 8601 or null.

GET /mail/domains/{domain} Get mail domain

Path parameters

NameDescription
domainMail domain.

Response 200 data: MailDomain

FieldTypeDescription
domainstring
accountsinteger
disk_mbnumber
antispamboolean
antivirusboolean
reject_spamboolean
dkimboolean
sslboolean
catchallstring | null
webmailstring
suspendedboolean
ssl_jobobject | nullOnly on 202 after enabling SSL.

PATCH /mail/domains/{domain} Update mail domain

Toggle features, set or clear the catch-all, enable/disable SSL. Enabling SSL is asynchronous: the response is `202` with an `ssl_job` handle — poll `GET /jobs/mail_ssl/{domain}`.

Path parameters

NameDescription
domainMail domain.

Request body MailDomainUpdate

FieldTypeDescription
antispamboolean
antivirusboolean
dkimboolean
reject_spamboolean
catchallstringEmail address, or empty string to remove.
sslboolean

Response 200 data: MailDomain

FieldTypeDescription
domainstring
accountsinteger
disk_mbnumber
antispamboolean
antivirusboolean
reject_spamboolean
dkimboolean
sslboolean
catchallstring | null
webmailstring
suspendedboolean
ssl_jobobject | nullOnly on 202 after enabling SSL.

DELETE /mail/domains/{domain} Delete mail domain

Deletes all mailboxes. Irreversible. Asynchronous: returns `202` with a job handle — poll `GET /jobs/mail_delete/{domain}`.

Path parameters

NameDescription
domainMail domain.

Response 202 data: Job

FieldTypeDescription
jobstringHandle `kind:key`.
statusnone | pending | started | ok | error
messagestring
updated_atstring | nullISO 8601 or null.

GET /mail/domains/{domain}/accounts List mailboxes

Path parameters

NameDescription
domainMail domain.

Response 200 data: MailAccount[]

FieldTypeDescription
accountstring
domainstring
emailstring
disk_mbnumber
suspendedboolean

POST /mail/domains/{domain}/accounts Create mailbox

Omit `password` to generate one (returned once).

Path parameters

NameDescription
domainMail domain.

Request body MailAccountCreate

FieldTypeDescription
account (required)stringLocal part.
passwordstringMin. 10 chars. Omit to generate.
quota_mbinteger0 or omitted = unlimited.

Response 201 data: MailAccountCreated

FieldTypeDescription
accountstring
domainstring
emailstring
quota_mbinteger | null
passwordstringOnly when generated. Shown once.

GET /mail/domains/{domain}/accounts/{account} Get mailbox

Includes quota, aliases and forwards.

Path parameters

NameDescription
domainMail domain.
accountLocal part, e.g. `info`.

Response 200 data: MailAccountDetail

FieldTypeDescription
accountstring
domainstring
emailstring
disk_mbnumber
suspendedboolean
quota_mbinteger | nullnull = unlimited.
aliasesarray<string>
forwardsarray<string>
forward_onlyboolean

PATCH /mail/domains/{domain}/accounts/{account} Update mailbox

Change password, forward-only mode, add/remove forwards and aliases.

Path parameters

NameDescription
domainMail domain.
accountLocal part, e.g. `info`.

Request body MailAccountUpdate

FieldTypeDescription
passwordstringEmpty string generates one.
forward_onlyboolean
add_forwardstringEmail address.
remove_forwardstring
add_aliasstringLocal part.
remove_aliasstring

Response 200 data: MailAccountDetail

FieldTypeDescription
accountstring
domainstring
emailstring
disk_mbnumber
suspendedboolean
quota_mbinteger | nullnull = unlimited.
aliasesarray<string>
forwardsarray<string>
forward_onlyboolean

DELETE /mail/domains/{domain}/accounts/{account} Delete mailbox

Irreversible.

Path parameters

NameDescription
domainMail domain.
accountLocal part, e.g. `info`.

Response 204

Backups

GET /backups List backups

Response 200 data: Backup[]

FieldTypeDescription
namestring
typestring
size_mbnumber
created_atstring | nullISO 8601.
contentsobject

POST /backups Schedule backup

Asynchronous; the backup appears in the list once completed. One request per 10 minutes.

Response 202 data: Scheduled

FieldTypeDescription
scheduledboolean
messagestring
namestring

DELETE /backups/{name} Delete backup

Path parameters

NameDescription
nameBackup file name from the list.

Response 204

POST /backups/{name}/restore Schedule restore

Restores the full backup in the background. Existing data is overwritten.

Path parameters

NameDescription
nameBackup file name.

Response 202 data: Scheduled

FieldTypeDescription
scheduledboolean
messagestring
namestring

Jobs

GET /jobs/{kind}/{key} Job status

Poll asynchronous operations. `kind` is one of `ssl`, `mail_ssl`, `mail_create`, `mail_delete`, `dns_records_save`; `key` is the domain.

Path parameters

NameDescription
kindJob kind.
keyDomain the job belongs to.

Response 200 data: Job

FieldTypeDescription
jobstringHandle `kind:key`.
statusnone | pending | started | ok | error
messagestring
updated_atstring | nullISO 8601 or null.

Fields marked * are required. Questions? Open a ticket in the dashboard and include the request_id.