GET
/
Health check
No authentication required.
Response 200 data: Health
| Field | Type | Description |
|---|---|---|
| name | string | |
| version | string | |
| status | string |
Developer documentation
Manage domains, DNS, SSL, FTP, databases, cron jobs, mail and backups from your own scripts, CI pipelines or control panel. Same isolation as the dashboard: every token acts strictly within your own account.
curl -H "Authorization: Bearer wr_…" https://www.webrock.online/api/v1/account
# create a domain with a DNS zone
curl -X POST -H "Authorization: Bearer wr_…" -H "Content-Type: application/json" \
-d '{"domain":"example.com","dns":true}' https://www.webrock.online/api/v1/domains
# issue a certificate, then poll the job
curl -X POST -H "Authorization: Bearer wr_…" https://www.webrock.online/api/v1/domains/example.com/ssl
curl -H "Authorization: Bearer wr_…" https://www.webrock.online/api/v1/jobs/ssl/example.com
Every request except GET / and GET /openapi.json needs Authorization: Bearer wr_…. Tokens are 43 characters, prefixed wr_; we store only a hash.
Up to 10 active tokens per account, optional expiry, instant revocation in the dashboard. A revoked or expired token returns 401.
Subscription gate. Without an active API subscription every hosting endpoint returns 402 SUBSCRIPTION_REQUIRED. GET /account still works and tells you api_subscription.active, so scripts can fail early with a clear message. Tokens survive a lapse — after re-booking they simply work again.
{"data": …, "request_id": "…"}. Error: {"error": {"code", "message", …}, "request_id"}. 204 has no body.X-Request-Id. Quote it in support tickets — we can trace the exact request.Content-Type: application/json). Invalid JSON returns 400 INVALID_JSON.X-RateLimit-Limit, -Remaining, -Reset; on 429 honour Retry-After.202 with a job handle. Poll GET /jobs/{kind}/{key} until status is ok or error.password when creating FTP, database or mail accounts and we generate one. It is returned once in that response and never again.Match on error.code, not on the message — messages may be reworded.
| Code | HTTP | Meaning |
|---|---|---|
| UNAUTHORIZED | 401 | Missing or invalid bearer token. |
| TOKEN_EXPIRED | 401 | The token has passed its expiry date. |
| SUBSCRIPTION_REQUIRED | 402 | No active API subscription. Book it in the dashboard. |
| ACCOUNT_SUSPENDED | 403 | The account is suspended. |
| FORBIDDEN | 403 | The operation is not allowed (e.g. deleting the primary FTP account). |
| NOT_FOUND | 404 | Endpoint or resource does not exist / does not belong to you. |
| METHOD_NOT_ALLOWED | 405 | Wrong HTTP method; see the `Allow` header. |
| NO_HOSTING | 409 | The account has no active hosting product. |
| ALREADY_EXISTS | 409 | A resource with that name already exists. |
| RESOURCE_LOCKED | 409 | The resource is locked (e.g. suspended). |
| RESOURCE_IN_USE | 409 | The resource is still referenced elsewhere. |
| INVALID_JSON | 400 | Request body is not valid JSON. |
| VALIDATION_ERROR | 422 | One or more fields are invalid; see `fields`. |
| QUOTA_EXCEEDED | 422 | The plan limit for this resource type is reached. |
| FEATURE_DISABLED | 422 | The feature is not enabled for this account. |
| RATE_LIMITED | 429 | Too many requests; wait `retry_after` seconds. |
| BACKEND_ERROR | 502 | The hosting service reported an error. Retry later. |
| BACKEND_UNAVAILABLE | 503 | The hosting service is temporarily unreachable. Retry with backoff. |
| MAINTENANCE | 503 | Planned maintenance. Wait for `Retry-After` and try again. |
| INTERNAL_ERROR | 500 | Unexpected error. Quote the `request_id` to support. |
/
Health check
No authentication required.
Response 200 data: Health
| Field | Type | Description |
|---|---|---|
| name | string | |
| version | string | |
| status | string |
/account
Account and subscription status
Works without an active API subscription — use it to check `api_subscription.active` before making other calls.
Response 200 data: Account
| Field | Type | Description |
|---|---|---|
| id | integer | |
| string | ||
| hosting_active | boolean | |
| plan | string | null | Hosting plan key or null. |
| term_ends_at | string | null | Hosting term end (ISO 8601) or null. |
| suspended | boolean | |
| api_subscription | object | |
| token | object |
/account/usage
Storage and traffic usage
Response 200 data: Usage
| Field | Type | Description |
|---|---|---|
| storage | object | |
| traffic | object |
/domains
List web domains
Response 200 data: Domain[]
| Field | Type | Description |
|---|---|---|
| domain | string | |
| ssl | boolean | |
| disk_mb | number | |
| bandwidth_mb | number |
/domains
Create web domain
Optionally creates a DNS zone pointing at the server IP.
Request body DomainCreate
| Field | Type | Description |
|---|---|---|
| domain (required) | string | Hostname, e.g. example.com. |
| dns | boolean | Also create a DNS zone. Default false. |
Response 201 data: DomainCreated
| Field | Type | Description |
|---|---|---|
| domain | string | |
| ssl | boolean | |
| dns | boolean | Whether the DNS zone was created. |
| warnings | array<string> | Non-fatal problems, e.g. DNS zone not created. |
/domains/{domain}
Get web domain
Path parameters
| Name | Description |
|---|---|
| domain | Web domain, e.g. `example.com`. |
Response 200 data: Domain
| Field | Type | Description |
|---|---|---|
| domain | string | |
| ssl | boolean | |
| disk_mb | number | |
| bandwidth_mb | number |
/domains/{domain}
Delete web domain
Removes the web domain including its files. Irreversible.
Path parameters
| Name | Description |
|---|---|
| domain | Web domain, e.g. `example.com`. |
Response 204
/domains/{domain}/aliases
List aliases
Path parameters
| Name | Description |
|---|---|
| domain | Web domain, e.g. `example.com`. |
Response 200 data: Alias[]
| Field | Type | Description |
|---|---|---|
| alias | string |
/domains/{domain}/aliases
Add alias
Path parameters
| Name | Description |
|---|---|
| domain | Web domain, e.g. `example.com`. |
Request body AliasCreate
| Field | Type | Description |
|---|---|---|
| alias (required) | string |
Response 201 data: AliasCreated
| Field | Type | Description |
|---|---|---|
| domain | string | |
| alias | string |
/domains/{domain}/aliases/{alias}
Remove alias
Path parameters
| Name | Description |
|---|---|
| domain | Web domain, e.g. `example.com`. |
| alias | Alias hostname. |
Response 204
/domains/{domain}/redirect
Get redirect
Returns `null` when no redirect is set.
Path parameters
| Name | Description |
|---|---|
| domain | Web domain, e.g. `example.com`. |
Response 200 data: Redirect | null
| Field | Type | Description |
|---|---|---|
| target | string | |
| code | integer | 301 or 302. |
/domains/{domain}/redirect
Set redirect
Path parameters
| Name | Description |
|---|---|
| domain | Web domain, e.g. `example.com`. |
Request body RedirectSet
| Field | Type | Description |
|---|---|---|
| target (required) | string | Hostname or URL. |
| code | integer | 301 (default) or 302. |
Response 200 data: Redirect
| Field | Type | Description |
|---|---|---|
| target | string | |
| code | integer | 301 or 302. |
/domains/{domain}/redirect
Remove redirect
Path parameters
| Name | Description |
|---|---|
| domain | Web domain, e.g. `example.com`. |
Response 204
/domains/{domain}/ssl
SSL status
Includes the last issuance job, if any.
Path parameters
| Name | Description |
|---|---|
| domain | Web domain, e.g. `example.com`. |
Response 200 data: SslStatus
| Field | Type | Description |
|---|---|---|
| domain | string | |
| ssl | boolean | |
| letsencrypt | boolean | |
| job | object | null |
/domains/{domain}/ssl
Issue Let's Encrypt certificate
Asynchronous. Returns `202` with a job handle; poll `GET /jobs/ssl/{domain}`. Rate-limited to one attempt per domain every 5 minutes.
Path parameters
| Name | Description |
|---|---|
| domain | Web domain, e.g. `example.com`. |
Response 202 data: Job
| Field | Type | Description |
|---|---|---|
| job | string | Handle `kind:key`. |
| status | none | pending | started | ok | error | |
| message | string | |
| updated_at | string | null | ISO 8601 or null. |
/domains/{domain}/ssl
Remove certificate
Path parameters
| Name | Description |
|---|---|
| domain | Web domain, e.g. `example.com`. |
Response 204
/dns/zones
List DNS zones
Response 200 data: DnsZone[]
| Field | Type | Description |
|---|---|---|
| zone | string | |
| records | integer | |
| dnssec | boolean |
/dns/zones/{zone}/records
List records
Path parameters
| Name | Description |
|---|---|
| zone | DNS zone, e.g. `example.com`. |
Response 200 data: DnsRecord[]
| Field | Type | Description |
|---|---|---|
| id | string | |
| name | string | `@` for the apex. |
| type | string | |
| value | string | |
| priority | integer | null | |
| ttl | integer | null |
/dns/zones/{zone}/records
Create record
Path parameters
| Name | Description |
|---|---|
| zone | DNS zone, e.g. `example.com`. |
Request body DnsRecordInput
| Field | Type | Description |
|---|---|---|
| name (required) | string | `@`, `www`, `mail`, … |
| type (required) | A | AAAA | CNAME | MX | TXT | NS | SRV | CAA | PTR | TLSA | DNSKEY | DS | |
| value (required) | string | |
| priority | integer | Required for MX and SRV. |
| ttl | integer | 60 – 2592000 seconds. |
Response 201 data: DnsRecord
| Field | Type | Description |
|---|---|---|
| id | string | |
| name | string | `@` for the apex. |
| type | string | |
| value | string | |
| priority | integer | null | |
| ttl | integer | null |
/dns/zones/{zone}/records/{id}
Update record
Partial update — omitted fields keep their value.
Path parameters
| Name | Description |
|---|---|
| zone | DNS zone, e.g. `example.com`. |
| id | Record id from the list. |
Request body DnsRecordInput
| Field | Type | Description |
|---|---|---|
| name (required) | string | `@`, `www`, `mail`, … |
| type (required) | A | AAAA | CNAME | MX | TXT | NS | SRV | CAA | PTR | TLSA | DNSKEY | DS | |
| value (required) | string | |
| priority | integer | Required for MX and SRV. |
| ttl | integer | 60 – 2592000 seconds. |
Response 200 data: DnsRecord
| Field | Type | Description |
|---|---|---|
| id | string | |
| name | string | `@` for the apex. |
| type | string | |
| value | string | |
| priority | integer | null | |
| ttl | integer | null |
/dns/zones/{zone}/records/{id}
Delete record
Path parameters
| Name | Description |
|---|---|
| zone | DNS zone, e.g. `example.com`. |
| id | Record id from the list. |
Response 204
/ftp
List FTP accounts
Response 200 data: FtpAccount[]
| Field | Type | Description |
|---|---|---|
| username | string | |
| domain | string | |
| path | string | |
| primary | boolean |
/ftp
Create FTP account
The full login becomes `<panel-user>_<username>`. If `password` is omitted a random one is generated and returned **once**.
Request body FtpAccountCreate
| Field | Type | Description |
|---|---|---|
| domain (required) | string | |
| username (required) | string | Suffix only; lowercase, digits, underscore. |
| path | string | Relative to the domain root, e.g. public_html/app. |
| password | string | Min. 8 chars. Omit to generate. |
Response 201 data: FtpAccountCreated
| Field | Type | Description |
|---|---|---|
| username | string | |
| domain | string | |
| path | string | |
| primary | boolean | |
| password | string | Only when generated. Shown once. |
/ftp/{username}
Change FTP password
Omit `password` to generate one.
Path parameters
| Name | Description |
|---|---|
| username | Full FTP login. |
Request body PasswordInput
| Field | Type | Description |
|---|---|---|
| password | string | Omit to generate a random one. |
Response 200 data: PasswordChanged
| Field | Type | Description |
|---|---|---|
| updated | boolean | |
| password | string | Only when generated. Shown once. |
/ftp/{username}
Delete FTP account
The primary account cannot be deleted.
Path parameters
| Name | Description |
|---|---|
| username | Full FTP login. |
Response 204
/databases
List databases
Response 200 data: Database[]
| Field | Type | Description |
|---|---|---|
| name | string | |
| user | string | |
| type | string | |
| host | string | |
| charset | string | |
| disk_mb | number | |
| suspended | boolean |
/databases
Create database
Name and user are prefixed with `<panel-user>_`. Omit `password` to generate one (returned once).
Request body DatabaseCreate
| Field | Type | Description |
|---|---|---|
| name (required) | string | Suffix; lowercase, digits, underscore, max. 32. |
| user | string | Defaults to name. |
| type | mysql | pgsql | Default `mysql`. |
| password | string | Min. 8 chars. Omit to generate. |
Response 201 data: DatabaseCreated
| Field | Type | Description |
|---|---|---|
| name | string | |
| user | string | |
| type | string | |
| password | string | Only when generated. Shown once. |
/databases/{name}
Change database password
Path parameters
| Name | Description |
|---|---|
| name | Full database name. |
Request body PasswordInput
| Field | Type | Description |
|---|---|---|
| password | string | Omit to generate a random one. |
Response 200 data: PasswordChanged
| Field | Type | Description |
|---|---|---|
| updated | boolean | |
| password | string | Only when generated. Shown once. |
/databases/{name}
Delete database
Irreversible.
Path parameters
| Name | Description |
|---|---|
| name | Full database name. |
Response 204
/cron
List cron jobs
Response 200 data: CronJob[]
| Field | Type | Description |
|---|---|---|
| id | string | |
| minute | string | |
| hour | string | |
| day | string | |
| month | string | |
| weekday | string | |
| command | string | |
| suspended | boolean |
/cron
Create cron job
Request body CronJobCreate
| Field | Type | Description |
|---|---|---|
| minute | string | Default `*`. |
| hour | string | Default `*`. |
| day | string | Default `*`. |
| month | string | Default `*`. |
| weekday | string | Default `*`. |
| command (required) | string | Single line, max. 1024 chars. |
Response 201 data: CronJob
| Field | Type | Description |
|---|---|---|
| id | string | |
| minute | string | |
| hour | string | |
| day | string | |
| month | string | |
| weekday | string | |
| command | string | |
| suspended | boolean |
/cron/{id}
Delete cron job
Path parameters
| Name | Description |
|---|---|
| id | Job id from the list. |
Response 204
/mail/domains
List mail domains
Response 200 data: MailDomain[]
| Field | Type | Description |
|---|---|---|
| domain | string | |
| accounts | integer | |
| disk_mb | number | |
| antispam | boolean | |
| antivirus | boolean | |
| reject_spam | boolean | |
| dkim | boolean | |
| ssl | boolean | |
| catchall | string | null | |
| webmail | string | |
| suspended | boolean | |
| ssl_job | object | null | Only on 202 after enabling SSL. |
/mail/domains
Create mail domain
Asynchronous (mail setup takes a while). Returns `202` with a job handle; poll `GET /jobs/mail_create/{domain}`.
Request body MailDomainCreate
| Field | Type | Description |
|---|---|---|
| domain (required) | string | |
| antispam | boolean | Default true. |
| antivirus | boolean | Default true. |
| dkim | boolean | Default true. |
| reject_spam | boolean | Default false. |
Response 202 data: Job
| Field | Type | Description |
|---|---|---|
| job | string | Handle `kind:key`. |
| status | none | pending | started | ok | error | |
| message | string | |
| updated_at | string | null | ISO 8601 or null. |
/mail/domains/{domain}
Get mail domain
Path parameters
| Name | Description |
|---|---|
| domain | Mail domain. |
Response 200 data: MailDomain
| Field | Type | Description |
|---|---|---|
| domain | string | |
| accounts | integer | |
| disk_mb | number | |
| antispam | boolean | |
| antivirus | boolean | |
| reject_spam | boolean | |
| dkim | boolean | |
| ssl | boolean | |
| catchall | string | null | |
| webmail | string | |
| suspended | boolean | |
| ssl_job | object | null | Only on 202 after enabling SSL. |
/mail/domains/{domain}
Update mail domain
Toggle features, set or clear the catch-all, enable/disable SSL. Enabling SSL is asynchronous: the response is `202` with an `ssl_job` handle — poll `GET /jobs/mail_ssl/{domain}`.
Path parameters
| Name | Description |
|---|---|
| domain | Mail domain. |
Request body MailDomainUpdate
| Field | Type | Description |
|---|---|---|
| antispam | boolean | |
| antivirus | boolean | |
| dkim | boolean | |
| reject_spam | boolean | |
| catchall | string | Email address, or empty string to remove. |
| ssl | boolean |
Response 200 data: MailDomain
| Field | Type | Description |
|---|---|---|
| domain | string | |
| accounts | integer | |
| disk_mb | number | |
| antispam | boolean | |
| antivirus | boolean | |
| reject_spam | boolean | |
| dkim | boolean | |
| ssl | boolean | |
| catchall | string | null | |
| webmail | string | |
| suspended | boolean | |
| ssl_job | object | null | Only on 202 after enabling SSL. |
/mail/domains/{domain}
Delete mail domain
Deletes all mailboxes. Irreversible. Asynchronous: returns `202` with a job handle — poll `GET /jobs/mail_delete/{domain}`.
Path parameters
| Name | Description |
|---|---|
| domain | Mail domain. |
Response 202 data: Job
| Field | Type | Description |
|---|---|---|
| job | string | Handle `kind:key`. |
| status | none | pending | started | ok | error | |
| message | string | |
| updated_at | string | null | ISO 8601 or null. |
/mail/domains/{domain}/accounts
List mailboxes
Path parameters
| Name | Description |
|---|---|
| domain | Mail domain. |
Response 200 data: MailAccount[]
| Field | Type | Description |
|---|---|---|
| account | string | |
| domain | string | |
| string | ||
| disk_mb | number | |
| suspended | boolean |
/mail/domains/{domain}/accounts
Create mailbox
Omit `password` to generate one (returned once).
Path parameters
| Name | Description |
|---|---|
| domain | Mail domain. |
Request body MailAccountCreate
| Field | Type | Description |
|---|---|---|
| account (required) | string | Local part. |
| password | string | Min. 10 chars. Omit to generate. |
| quota_mb | integer | 0 or omitted = unlimited. |
Response 201 data: MailAccountCreated
| Field | Type | Description |
|---|---|---|
| account | string | |
| domain | string | |
| string | ||
| quota_mb | integer | null | |
| password | string | Only when generated. Shown once. |
/mail/domains/{domain}/accounts/{account}
Get mailbox
Includes quota, aliases and forwards.
Path parameters
| Name | Description |
|---|---|
| domain | Mail domain. |
| account | Local part, e.g. `info`. |
Response 200 data: MailAccountDetail
| Field | Type | Description |
|---|---|---|
| account | string | |
| domain | string | |
| string | ||
| disk_mb | number | |
| suspended | boolean | |
| quota_mb | integer | null | null = unlimited. |
| aliases | array<string> | |
| forwards | array<string> | |
| forward_only | boolean |
/mail/domains/{domain}/accounts/{account}
Update mailbox
Change password, forward-only mode, add/remove forwards and aliases.
Path parameters
| Name | Description |
|---|---|
| domain | Mail domain. |
| account | Local part, e.g. `info`. |
Request body MailAccountUpdate
| Field | Type | Description |
|---|---|---|
| password | string | Empty string generates one. |
| forward_only | boolean | |
| add_forward | string | Email address. |
| remove_forward | string | |
| add_alias | string | Local part. |
| remove_alias | string |
Response 200 data: MailAccountDetail
| Field | Type | Description |
|---|---|---|
| account | string | |
| domain | string | |
| string | ||
| disk_mb | number | |
| suspended | boolean | |
| quota_mb | integer | null | null = unlimited. |
| aliases | array<string> | |
| forwards | array<string> | |
| forward_only | boolean |
/mail/domains/{domain}/accounts/{account}
Delete mailbox
Irreversible.
Path parameters
| Name | Description |
|---|---|
| domain | Mail domain. |
| account | Local part, e.g. `info`. |
Response 204
/backups
List backups
Response 200 data: Backup[]
| Field | Type | Description |
|---|---|---|
| name | string | |
| type | string | |
| size_mb | number | |
| created_at | string | null | ISO 8601. |
| contents | object |
/backups
Schedule backup
Asynchronous; the backup appears in the list once completed. One request per 10 minutes.
Response 202 data: Scheduled
| Field | Type | Description |
|---|---|---|
| scheduled | boolean | |
| message | string | |
| name | string |
/backups/{name}
Delete backup
Path parameters
| Name | Description |
|---|---|
| name | Backup file name from the list. |
Response 204
/backups/{name}/restore
Schedule restore
Restores the full backup in the background. Existing data is overwritten.
Path parameters
| Name | Description |
|---|---|
| name | Backup file name. |
Response 202 data: Scheduled
| Field | Type | Description |
|---|---|---|
| scheduled | boolean | |
| message | string | |
| name | string |
/jobs/{kind}/{key}
Job status
Poll asynchronous operations. `kind` is one of `ssl`, `mail_ssl`, `mail_create`, `mail_delete`, `dns_records_save`; `key` is the domain.
Path parameters
| Name | Description |
|---|---|
| kind | Job kind. |
| key | Domain the job belongs to. |
Response 200 data: Job
| Field | Type | Description |
|---|---|---|
| job | string | Handle `kind:key`. |
| status | none | pending | started | ok | error | |
| message | string | |
| updated_at | string | null | ISO 8601 or null. |
Fields marked * are required. Questions? Open a ticket in the dashboard and include the request_id.