# xCloud API Documentations

> Explore the xCloud Public API — 170 REST endpoints for servers, sites, backups, billing, and addons, with token authentication and clear rate limits.

The **xCloud Public API** is a self-service REST API for all xCloud customers. Use it to programmatically manage your servers, sites, databases, backups, cron jobs, billing, and addons — directly from your own scripts, CI/CD pipelines, or integrations.

**[📖 Open the interactive API reference →](https://app.xcloud.host/api/v1/docs)**

The reference documents every endpoint with request and response examples, and lets you try calls against your own account. All requests go to one base URL:

```
https://app.xcloud.host/api/v1
```

## Authentication

Every request (except the public health check) needs a personal access token sent as a bearer token in the Authorization header:

```
Authorization: Bearer <your-token>
Accept: application/json
```

Create a token from your dashboard and scope it to exactly what your integration needs — see [How to Access the xCloud API](/docs/how-to-access-the-xcloud-api/) for the step-by-step guide. Token scopes cover reading and writing servers (`read:servers`, `write:servers`), sites (`read:sites`, `write:sites`), billing (`read:billing`), and addons (`read:addons`, `write:addons`).

## What you can manage

The API currently exposes **170 endpoints**, grouped in the reference as:

| Area | What it covers |
| --- | --- |
| **Servers** (51) | Provisioning info, reboots, databases, cron jobs, PHP versions, monitoring, sudo users |
| **Sites** (54) | Site details, backups, SSL, domains, git deployments, cache purge, SSH/SFTP config |
| **WordPress** (9) | WordPress site creation, plugin/theme actions, magic login |
| **Security & health** (16) | Vulnerability scans, broken-link checks, PageSpeed reports, SSL certificates, health check |
| **One-click apps & blueprints** (8) | The app catalog and one-click app deployments |
| **Billing & payments** (11) | Plans, invoices, bills, packages, payment methods, subscriptions |
| **Addons** (13) | Mailbox and mail-delivery addons, DNS verification |
| **Account** (8) | User profile, API tokens, integrations, catalog |

## A first request

List your servers:

```
curl https://app.xcloud.host/api/v1/servers \
  -H "Authorization: Bearer <your-token>" \
  -H "Accept: application/json"
```

Every response uses a consistent envelope — `success`, `message`, and a `data` payload (with `meta` pagination on list endpoints). Async operations such as reboots and backups return `202 Accepted` and run in the background.

## Frequently asked questions

### Where is the xCloud API documentation?

The full interactive reference lives at app.xcloud.host/api/v1/docs. It documents all 170 endpoints with request and response examples you can try against your own account.

### How do I authenticate with the xCloud API?

Every request except the health check needs a personal access token sent as a bearer token in the Authorization header. You can create one from your xCloud dashboard and choose the scopes it should have.

### What are the xCloud API rate limits?

Authenticated requests are limited to 60 per minute and unauthenticated requests to 10 per minute. Every response carries rate limit headers, and exceeding the limit returns a 429 with a Retry-After header.

If you face any issues, please do not hesitate to contact our [**support team**](https://support.xcloud.host/).
