xCloud API Documentations

Updated September 18, 2026 · 3 min read

The xCloud Public API is a self-service REST API for all xCloud customers. Use it to programmatically manage your servers, sites, databases, backups, cron jobs, billing, and addons — directly from your own scripts, CI/CD pipelines, or integrations.

📖 Open the interactive API reference →

The reference documents every endpoint with request and response examples, and lets you try calls against your own account. All requests go to one base URL:

https://app.xcloud.host/api/v1

Authentication

Every request (except the public health check) needs a personal access token sent as a bearer token in the Authorization header:

Authorization: Bearer <your-token>
Accept: application/json

Create a token from your dashboard and scope it to exactly what your integration needs — see How to Access the xCloud API for the step-by-step guide. Token scopes cover reading and writing servers (read:servers, write:servers), sites (read:sites, write:sites), billing (read:billing), and addons (read:addons, write:addons).

What you can manage

The API currently exposes 170 endpoints, grouped in the reference as:

Area What it covers
Servers (51) Provisioning info, reboots, databases, cron jobs, PHP versions, monitoring, sudo users
Sites (54) Site details, backups, SSL, domains, git deployments, cache purge, SSH/SFTP config
WordPress (9) WordPress site creation, plugin/theme actions, magic login
Security & health (16) Vulnerability scans, broken-link checks, PageSpeed reports, SSL certificates, health check
One-click apps & blueprints (8) The app catalog and one-click app deployments
Billing & payments (11) Plans, invoices, bills, packages, payment methods, subscriptions
Addons (13) Mailbox and mail-delivery addons, DNS verification
Account (8) User profile, API tokens, integrations, catalog

A first request

List your servers:

curl https://app.xcloud.host/api/v1/servers \
  -H "Authorization: Bearer <your-token>" \
  -H "Accept: application/json"

Every response uses a consistent envelope — success, message, and a data payload (with meta pagination on list endpoints). Async operations such as reboots and backups return 202 Accepted and run in the background.

Frequently asked questions

Where is the xCloud API documentation?

The full interactive reference lives at app.xcloud.host/api/v1/docs. It documents all 170 endpoints with request and response examples you can try against your own account.

How do I authenticate with the xCloud API?

Every request except the health check needs a personal access token sent as a bearer token in the Authorization header. You can create one from your xCloud dashboard and choose the scopes it should have.

What are the xCloud API rate limits?

Authenticated requests are limited to 60 per minute and unauthenticated requests to 10 per minute. Every response carries rate limit headers, and exceeding the limit returns a 429 with a Retry-After header.

If you face any issues, please do not hesitate to contact our support team.