DevelopersREST API

REST API reference

Base URL: https://panel.hostwolf.net/api/client

Auth: send Authorization: Bearer ptlc_... and Accept: application/json. Create keys at Account → API keys.

The API is compatible with the Pterodactyl client API, so existing Pterodactyl tools and libraries work against it. Hostwolf-only endpoints are marked HW.

Conventions#

Responses. Single objects come wrapped as {"object": "server", "attributes": {...}}. Lists come as {"object": "list", "data": [...], "meta": {...}}. Hostwolf-only endpoints return plain JSON.

Pagination. Paginated lists accept ?page= and ?per_page= (max 100 for servers, 50 for backups), and return meta.pagination with total, count, per_page, current_page and total_pages.

Errors.

{
  "errors": [
    { "code": "ValidationException", "status": "422", "detail": "The name field is required." }
  ]
}

Some Hostwolf endpoints return {"error": "...", "code": "..."} instead, e.g. 409 downgrade_requires_reset when switching a game to an older version.

Status codes:

  • 204: success with no body.
  • 401: bad key.
  • 403: missing permission (subusers) or a suspended server.
  • 404: not found.
  • 409: the server is busy (installing, restoring or transferring).
  • 422: validation error.
  • 429: rate limited (check Retry-After).
  • 502: the server's node is unreachable, or the server must be running.

Server ids. {server} is the server's identifier, the 8 characters in its panel URL. The full uuid also works.

Account#

MethodPathBody / queryNotes
GET/page, per_page, filter[*], typeYour servers (paginated)
GET/permissionsEvery subuser permission key
GET/accountYour account
PUT/account/emailemail, password
PUT/account/passwordcurrent_password, password, password_confirmation
PUT/account/profile HWfirst_name, last_nameDisplay name
PUT/account/language HWlanguage: en-GB en-US de fr es fi
POST DELETE/account/avatar HWimage: data URL (PNG/JPEG/WebP, max 512 KB)
GET/account/activitypage, filter[event], sortPaginated
GET PUT/account/notifications HWemail_enabled, email_address, discord_enabled, discord_webhook, notify_deployAccount-wide alerts
GET PUT/account/curseforge HWkey (null clears)Your own CurseForge API key
GET PUT/account/factorio HWusername, tokenFactorio mod portal credentials
GET/account/api-keys
POST/account/api-keysdescription, allowed_ips[]The full key is in meta.secret_token, shown once
DELETE/account/api-keys/{identifier}
GET/account/ssh-keysFor SFTP
POST/account/ssh-keysname, public_key
POST/account/ssh-keys/removefingerprint

Servers#

MethodPathBody / queryNotes
GET/servers/{server}include=egg,subusersDetails, allocations, startup variables, region HW
GET/servers/{server}/resourcescurrent_state, CPU, memory, disk, network, uptime
GET/servers/{server}/activitypage, filter[event]Paginated
POST/servers/{server}/powersignal: start stop restart kill204
POST/servers/{server}/commandcommandServer must be running
GET/servers/{server}/websocketConsole token, see Console
POST/servers/{server}/settings/renamename, description
POST/servers/{server}/settings/reinstallRe-runs the install script
PUT/servers/{server}/settings/docker-imagedocker_imageOne of the egg's images
GET/servers/{server}/startupVariables, plus meta.startup_command and meta.docker_images
PUT/servers/{server}/startup/variablekey, valuekey is the env name, e.g. MINECRAFT_VERSION

Files#

All paths are relative to the server root. root is the directory that the files entries live in.

MethodPathBody / queryNotes
GET/servers/{server}/files/listdirectory
GET/servers/{server}/files/contentsfileRaw text body
POST/servers/{server}/files/write?file=; raw text bodyCreates or overwrites
GET/servers/{server}/files/downloadfileattributes.url: signed one-time URL
GET/servers/{server}/files/uploadSigned URL: POST multipart files to url&directory=/path
PUT/servers/{server}/files/renameroot, files[]: {from, to}Also moves
POST/servers/{server}/files/copylocation
POST/servers/{server}/files/deleteroot, files[]
POST/servers/{server}/files/create-folderroot, name
POST/servers/{server}/files/compressroot, files[]Returns the archive
POST/servers/{server}/files/decompressroot, file
POST/servers/{server}/files/chmodroot, files[]: {file, mode}
POST/servers/{server}/files/pullurl, directory, filename, use_header, foregroundServer downloads a URL

Backups#

SDK: hw.backups · MCP: create_backup, restore_backup, list_backups · Limit: 2 backups per 10 minutes.

MethodPathBody / queryNotes
GET/servers/{server}/backupspage, per_pagePaginated
POST/servers/{server}/backupsname, ignored, is_lockedRuns in the background
GET/servers/{server}/backups/{uuid}completed_at is set when done
GET/servers/{server}/backups/{uuid}/downloadSigned URL
POST/servers/{server}/backups/{uuid}/lockToggle lock
POST/servers/{server}/backups/{uuid}/restoretruncatetruncate: true deletes all files first
DELETE/servers/{server}/backups/{uuid}
GET PUT/servers/{server}/hostwolf/smart-backups HWenabledAutomatic backups before risky changes

Game, players and diagnostics HW#

MethodPathBody / queryNotes
GET/servers/{server}/game/versionssupported, current, versions
POST/servers/{server}/game/versionversion, reset_world, forceSwitches and reinstalls. 409 downgrade_requires_reset for older versions
GET/servers/{server}/hostwolf/game-settingsFriendly settings grouped by config file
PUT/servers/{server}/hostwolf/game-settingsvalues: {id: "value"}, restartBool values are "true" / "false"
GET/servers/{server}/hostwolf/diagnostics"Fix my server" checks with severity
GET/servers/{server}/playersOnline count, max, names (Minecraft)
GET/servers/{server}/hostwolf/playersLive player list via RCON/query, and supported actions
POST/servers/{server}/hostwolf/players/{action}player: {name, steamid, id}, messageaction: kick ban unban broadcast

Mods, plugins and modpacks HW#

MethodPathBody / queryNotes
GET/servers/{server}/addonsSupported sources, install directory, frameworks, workshop mode
GET/servers/{server}/addons/searchsource, q, pageSources depend on the game: modrinth, curseforge, hangar, spigot, umod, thunderstore…
GET/servers/{server}/addons/versionssource, projectMarks compatible versions
POST/servers/{server}/addons/installsource, project, versionOmit version for the newest compatible one
GET/servers/{server}/addons/installedupdates=1Installed addons with available updates, plus manual files
DELETE/servers/{server}/addons/installed/{id}
POST/servers/{server}/addons/manual/deletefileRemove a manually added file
POST/servers/{server}/addons/uploadmultipart filee.g. a plugin .jar
POST/servers/{server}/addons/featuredprojectOne-click featured addons
PUT/servers/{server}/addons/frameworkframeworke.g. Oxide/Carbon, BepInEx
POST/servers/{server}/addons/cs2repairCS2: Metamod + CounterStrikeSharp
GET PUT/servers/{server}/addons/workshopitems[]Steam Workshop items or collection
GET/servers/{server}/addons/modpacksCurrent modpack and its last start result
GET/servers/{server}/addons/modpacks/searchq, page, category, sourcesource: modrinth or curseforge
GET/servers/{server}/addons/modpacks/versionsproject, source
POST/servers/{server}/addons/modpacksproject, version, fresh_world, sourceReplaces mods and loader
DELETE/servers/{server}/addons/modpacks

Schedules#

MethodPathBody / queryNotes
GET/servers/{server}/schedulesIncludes tasks
POST/servers/{server}/schedulesname, minute, hour, day_of_month, month, day_of_week, is_active, only_when_onlineCron fields, UTC
GET POST DELETE/servers/{server}/schedules/{id}same as createPOST updates
POST/servers/{server}/schedules/{id}/executeRun now
POST/servers/{server}/schedules/{id}/tasksaction (command power backup), payload, time_offset, continue_on_failure
POST DELETE/servers/{server}/schedules/{id}/tasks/{task}same as createPOST updates

Network, databases and subusers#

MethodPathBody / queryNotes
GET/servers/{server}/network/allocationsPorts
POST/servers/{server}/network/allocationsAuto-assign another port (plan permitting)
POST/servers/{server}/network/allocations/{id}notes
POST/servers/{server}/network/allocations/{id}/primary
DELETE/servers/{server}/network/allocations/{id}
GET/servers/{server}/databasesinclude=password
POST/servers/{server}/databasesdatabase, remote
POST/servers/{server}/databases/{id}/rotate-password
DELETE/servers/{server}/databases/{id}
GET/servers/{server}/usersSubusers
POST/servers/{server}/usersemail, permissions[]Invite
GET POST DELETE/servers/{server}/users/{uuid}permissions[]POST updates

Server extras HW#

MethodPathBody / queryNotes
GET PUT/servers/{server}/hostwolf/notificationswebhook_url, clear_webhook, eventsDiscord alerts: started, stopped, crashed, backups, players
POST/servers/{server}/hostwolf/notifications/test
GET/servers/{server}/hostwolf/domainCustom domain and the records it needs
POST/servers/{server}/hostwolf/domain/checkhostnameChecks the live DNS
PUT DELETE/servers/{server}/hostwolf/domainhostname
GET/servers/{server}/hostwolf/networkOn a Velocity/BungeeCord proxy: its entries and the servers you can link
POST/servers/{server}/hostwolf/network/linkservers[]: {id, key}, lobby, restart
POST/servers/{server}/hostwolf/network/unlinkid, restart
POST/servers/{server}/hostwolf/network/fabric-proxyidInstalls FabricProxy-Lite on a Fabric backend

Plans and orders HW#

SDK: hw.store · MCP: get_plans_and_prices, list_orders · Human-friendly prices: pricing

Read-only. Ordering, cancelling and payment happen in the panel.

MethodPathNotes
GET/store/catalogGames, plan sizes, regions and live per-region prices
GET/store/ordersPending, active and recently failed orders
GET/store/billingEvery order with price, renewal, cancellation and refund state

Console#

The live console is a websocket on the node that runs your server.

  1. GET /servers/{server}/websocket returns {"data": {"token": "...", "socket": "wss://..."}}.
  2. Connect to socket with an Origin: https://panel.hostwolf.net header.
  3. Send {"event": "auth", "args": ["<token>"]} and wait for auth success.
  4. Send {"event": "send logs", "args": [null]} to replay recent output.

Messages are JSON in the form {"event": "...", "args": [...]}.

Events you receive:

  • console output
  • status
  • stats (a JSON string)
  • install output
  • daemon message and daemon error
  • token expiring: fetch a new token and send auth again.
  • token expired

Events you can send:

  • send command with the command text.
  • set state with start, stop, restart or kill.
  • send logs
  • send stats

The SDK handles all of this: hw.console(id) or hw.tail(id).

SFTP#

Files are also reachable over SFTP. Use the address in sftp_details from GET /servers/{server}, with username <your username>.<server identifier>. Log in with your panel password or an SSH key added at /account/ssh-keys.

Stuck, or missing an endpoint? Tell us at game.hostwolf.net/contact or hostwolfsupport@gmail.com.