DevelopersREST API
REST API reference
Base URL: https://panel.hostwolf.net/api/client
Auth: send Authorization: Bearer ptlc_... and Accept: application/json. Create keys at Account → API keys.
The API is compatible with the Pterodactyl client API, so existing Pterodactyl tools and libraries work against it. Hostwolf-only endpoints are marked HW.
Conventions#
Responses. Single objects come wrapped as {"object": "server", "attributes": {...}}. Lists come as {"object": "list", "data": [...], "meta": {...}}. Hostwolf-only endpoints return plain JSON.
Pagination. Paginated lists accept ?page= and ?per_page= (max 100 for servers, 50 for backups), and return meta.pagination with total, count, per_page, current_page and total_pages.
Errors.
{
"errors": [
{ "code": "ValidationException", "status": "422", "detail": "The name field is required." }
]
}
Some Hostwolf endpoints return {"error": "...", "code": "..."} instead, e.g. 409 downgrade_requires_reset when switching a game to an older version.
Status codes:
204: success with no body.401: bad key.403: missing permission (subusers) or a suspended server.404: not found.409: the server is busy (installing, restoring or transferring).422: validation error.429: rate limited (checkRetry-After).502: the server's node is unreachable, or the server must be running.
Server ids. {server} is the server's identifier, the 8 characters in its panel URL. The full uuid also works.
Account#
SDK: hw.account · hw.servers.list · Panel: Account settings
| Method | Path | Body / query | Notes |
|---|---|---|---|
| GET | / | page, per_page, filter[*], type | Your servers (paginated) |
| GET | /permissions | Every subuser permission key | |
| GET | /account | Your account | |
| PUT | /account/email | email, password | |
| PUT | /account/password | current_password, password, password_confirmation | |
| PUT | /account/profile HW | first_name, last_name | Display name |
| PUT | /account/language HW | language: en-GB en-US de fr es fi | |
| POST DELETE | /account/avatar HW | image: data URL (PNG/JPEG/WebP, max 512 KB) | |
| GET | /account/activity | page, filter[event], sort | Paginated |
| GET PUT | /account/notifications HW | email_enabled, email_address, discord_enabled, discord_webhook, notify_deploy | Account-wide alerts |
| GET PUT | /account/curseforge HW | key (null clears) | Your own CurseForge API key |
| GET PUT | /account/factorio HW | username, token | Factorio mod portal credentials |
| GET | /account/api-keys | ||
| POST | /account/api-keys | description, allowed_ips[] | The full key is in meta.secret_token, shown once |
| DELETE | /account/api-keys/{identifier} | ||
| GET | /account/ssh-keys | For SFTP | |
| POST | /account/ssh-keys | name, public_key | |
| POST | /account/ssh-keys/remove | fingerprint |
Servers#
| Method | Path | Body / query | Notes |
|---|---|---|---|
| GET | /servers/{server} | include=egg,subusers | Details, allocations, startup variables, region HW |
| GET | /servers/{server}/resources | current_state, CPU, memory, disk, network, uptime | |
| GET | /servers/{server}/activity | page, filter[event] | Paginated |
| POST | /servers/{server}/power | signal: start stop restart kill | 204 |
| POST | /servers/{server}/command | command | Server must be running |
| GET | /servers/{server}/websocket | Console token, see Console | |
| POST | /servers/{server}/settings/rename | name, description | |
| POST | /servers/{server}/settings/reinstall | Re-runs the install script | |
| PUT | /servers/{server}/settings/docker-image | docker_image | One of the egg's images |
| GET | /servers/{server}/startup | Variables, plus meta.startup_command and meta.docker_images | |
| PUT | /servers/{server}/startup/variable | key, value | key is the env name, e.g. MINECRAFT_VERSION |
Files#
All paths are relative to the server root. root is the directory that the files entries live in.
| Method | Path | Body / query | Notes |
|---|---|---|---|
| GET | /servers/{server}/files/list | directory | |
| GET | /servers/{server}/files/contents | file | Raw text body |
| POST | /servers/{server}/files/write | ?file=; raw text body | Creates or overwrites |
| GET | /servers/{server}/files/download | file | attributes.url: signed one-time URL |
| GET | /servers/{server}/files/upload | Signed URL: POST multipart files to url&directory=/path | |
| PUT | /servers/{server}/files/rename | root, files[]: {from, to} | Also moves |
| POST | /servers/{server}/files/copy | location | |
| POST | /servers/{server}/files/delete | root, files[] | |
| POST | /servers/{server}/files/create-folder | root, name | |
| POST | /servers/{server}/files/compress | root, files[] | Returns the archive |
| POST | /servers/{server}/files/decompress | root, file | |
| POST | /servers/{server}/files/chmod | root, files[]: {file, mode} | |
| POST | /servers/{server}/files/pull | url, directory, filename, use_header, foreground | Server downloads a URL |
Backups#
SDK: hw.backups · MCP: create_backup, restore_backup, list_backups · Limit: 2 backups per 10 minutes.
| Method | Path | Body / query | Notes |
|---|---|---|---|
| GET | /servers/{server}/backups | page, per_page | Paginated |
| POST | /servers/{server}/backups | name, ignored, is_locked | Runs in the background |
| GET | /servers/{server}/backups/{uuid} | completed_at is set when done | |
| GET | /servers/{server}/backups/{uuid}/download | Signed URL | |
| POST | /servers/{server}/backups/{uuid}/lock | Toggle lock | |
| POST | /servers/{server}/backups/{uuid}/restore | truncate | truncate: true deletes all files first |
| DELETE | /servers/{server}/backups/{uuid} | ||
| GET PUT | /servers/{server}/hostwolf/smart-backups HW | enabled | Automatic backups before risky changes |
Game, players and diagnostics HW#
| Method | Path | Body / query | Notes |
|---|---|---|---|
| GET | /servers/{server}/game/versions | supported, current, versions | |
| POST | /servers/{server}/game/version | version, reset_world, force | Switches and reinstalls. 409 downgrade_requires_reset for older versions |
| GET | /servers/{server}/hostwolf/game-settings | Friendly settings grouped by config file | |
| PUT | /servers/{server}/hostwolf/game-settings | values: {id: "value"}, restart | Bool values are "true" / "false" |
| GET | /servers/{server}/hostwolf/diagnostics | "Fix my server" checks with severity | |
| GET | /servers/{server}/players | Online count, max, names (Minecraft) | |
| GET | /servers/{server}/hostwolf/players | Live player list via RCON/query, and supported actions | |
| POST | /servers/{server}/hostwolf/players/{action} | player: {name, steamid, id}, message | action: kick ban unban broadcast |
Mods, plugins and modpacks HW#
SDK: hw.addons, hw.modpacks · MCP: search_addons, install_addon, install_modpack · Supported games: games
| Method | Path | Body / query | Notes |
|---|---|---|---|
| GET | /servers/{server}/addons | Supported sources, install directory, frameworks, workshop mode | |
| GET | /servers/{server}/addons/search | source, q, page | Sources depend on the game: modrinth, curseforge, hangar, spigot, umod, thunderstore… |
| GET | /servers/{server}/addons/versions | source, project | Marks compatible versions |
| POST | /servers/{server}/addons/install | source, project, version | Omit version for the newest compatible one |
| GET | /servers/{server}/addons/installed | updates=1 | Installed addons with available updates, plus manual files |
| DELETE | /servers/{server}/addons/installed/{id} | ||
| POST | /servers/{server}/addons/manual/delete | file | Remove a manually added file |
| POST | /servers/{server}/addons/upload | multipart file | e.g. a plugin .jar |
| POST | /servers/{server}/addons/featured | project | One-click featured addons |
| PUT | /servers/{server}/addons/framework | framework | e.g. Oxide/Carbon, BepInEx |
| POST | /servers/{server}/addons/cs2 | repair | CS2: Metamod + CounterStrikeSharp |
| GET PUT | /servers/{server}/addons/workshop | items[] | Steam Workshop items or collection |
| GET | /servers/{server}/addons/modpacks | Current modpack and its last start result | |
| GET | /servers/{server}/addons/modpacks/search | q, page, category, source | source: modrinth or curseforge |
| GET | /servers/{server}/addons/modpacks/versions | project, source | |
| POST | /servers/{server}/addons/modpacks | project, version, fresh_world, source | Replaces mods and loader |
| DELETE | /servers/{server}/addons/modpacks |
Schedules#
SDK: hw.schedules · MCP: create_schedule, list_schedules
| Method | Path | Body / query | Notes |
|---|---|---|---|
| GET | /servers/{server}/schedules | Includes tasks | |
| POST | /servers/{server}/schedules | name, minute, hour, day_of_month, month, day_of_week, is_active, only_when_online | Cron fields, UTC |
| GET POST DELETE | /servers/{server}/schedules/{id} | same as create | POST updates |
| POST | /servers/{server}/schedules/{id}/execute | Run now | |
| POST | /servers/{server}/schedules/{id}/tasks | action (command power backup), payload, time_offset, continue_on_failure | |
| POST DELETE | /servers/{server}/schedules/{id}/tasks/{task} | same as create | POST updates |
Network, databases and subusers#
| Method | Path | Body / query | Notes |
|---|---|---|---|
| GET | /servers/{server}/network/allocations | Ports | |
| POST | /servers/{server}/network/allocations | Auto-assign another port (plan permitting) | |
| POST | /servers/{server}/network/allocations/{id} | notes | |
| POST | /servers/{server}/network/allocations/{id}/primary | ||
| DELETE | /servers/{server}/network/allocations/{id} | ||
| GET | /servers/{server}/databases | include=password | |
| POST | /servers/{server}/databases | database, remote | |
| POST | /servers/{server}/databases/{id}/rotate-password | ||
| DELETE | /servers/{server}/databases/{id} | ||
| GET | /servers/{server}/users | Subusers | |
| POST | /servers/{server}/users | email, permissions[] | Invite |
| GET POST DELETE | /servers/{server}/users/{uuid} | permissions[] | POST updates |
Server extras HW#
| Method | Path | Body / query | Notes |
|---|---|---|---|
| GET PUT | /servers/{server}/hostwolf/notifications | webhook_url, clear_webhook, events | Discord alerts: started, stopped, crashed, backups, players |
| POST | /servers/{server}/hostwolf/notifications/test | ||
| GET | /servers/{server}/hostwolf/domain | Custom domain and the records it needs | |
| POST | /servers/{server}/hostwolf/domain/check | hostname | Checks the live DNS |
| PUT DELETE | /servers/{server}/hostwolf/domain | hostname | |
| GET | /servers/{server}/hostwolf/network | On a Velocity/BungeeCord proxy: its entries and the servers you can link | |
| POST | /servers/{server}/hostwolf/network/link | servers[]: {id, key}, lobby, restart | |
| POST | /servers/{server}/hostwolf/network/unlink | id, restart | |
| POST | /servers/{server}/hostwolf/network/fabric-proxy | id | Installs FabricProxy-Lite on a Fabric backend |
Plans and orders HW#
SDK: hw.store · MCP: get_plans_and_prices, list_orders · Human-friendly prices: pricing
Read-only. Ordering, cancelling and payment happen in the panel.
| Method | Path | Notes |
|---|---|---|
| GET | /store/catalog | Games, plan sizes, regions and live per-region prices |
| GET | /store/orders | Pending, active and recently failed orders |
| GET | /store/billing | Every order with price, renewal, cancellation and refund state |
Console#
SDK: hw.console(), hw.tail() · MCP: get_console
The live console is a websocket on the node that runs your server.
GET /servers/{server}/websocketreturns{"data": {"token": "...", "socket": "wss://..."}}.- Connect to
socketwith anOrigin: https://panel.hostwolf.netheader. - Send
{"event": "auth", "args": ["<token>"]}and wait forauth success. - Send
{"event": "send logs", "args": [null]}to replay recent output.
Messages are JSON in the form {"event": "...", "args": [...]}.
Events you receive:
console outputstatusstats(a JSON string)install outputdaemon messageanddaemon errortoken expiring: fetch a new token and sendauthagain.token expired
Events you can send:
send commandwith the command text.set statewithstart,stop,restartorkill.send logssend stats
The SDK handles all of this: hw.console(id) or hw.tail(id).
SFTP#
Files are also reachable over SFTP. Use the address in sftp_details from GET /servers/{server}, with username <your username>.<server identifier>. Log in with your panel password or an SSH key added at /account/ssh-keys.