Back to articles

How to create an API key and manage your server through the panel API

September 24, 2026
Other Trending
πŸ§ͺExperimental feature β€” not supported: The panel API is available to anyone who wants to automate their own server, but RedHosting does not provide support for it. The team doesn't help build scripts, doesn't debug integrations and isn't responsible for what a script does on your server β€” including shutting it down, deleting files or sending commands by mistake. The API's behavior may change without notice. Support still covers the service itself: server down, panel, network and billing.

Everything you do by clicking in the panel β€” starting the server, sending a console command, editing a file β€” can also be done with an HTTP request. That's what lets a Discord bot restart the Minecraft server with a command, a script bring the server back up if it goes down, or a routine save a configuration file every day.

This guide shows how to create the key that grants this access and how to use it for the most common operations.

1. What the API key can do

The key acts on behalf of your account. It has no separate permissions: whatever you can do in the panel, it can too, on every server in the account. The most used operations are:

  • Power β€” start, stop, restart and force stop.
  • Console β€” send commands such as say, whitelist add or save-all.
  • Usage β€” read the server state and CPU, memory and disk usage.
  • Files β€” list folders, read and write files.
  • Backups and schedules β€” the same ones shown in the server's tabs.
⚠️Treat the key like your password: Whoever has the key controls all your servers, without needing your password or two-factor verification. Never publish the key on GitHub, in a screenshot or in a Discord channel.

2. Creating the key

The panel may show its labels in Portuguese; the original name is in parentheses.

  1. Log in to the panel at app.redhosting.com.br.
  2. In the side menu, click Account (Conta) β€” or go straight to app.redhosting.com.br/account.
  3. Scroll to the keys box at the bottom of the page and click the API Key tab (Chave API) β€” the tab next to it is SSH Key.
  4. Under Description (DescriΓ§Γ£o), write what the key is for β€” for example, discord bot. It needs at least 4 characters, and this name is what will tell you, months later, which key to delete.
  5. Under Allowed IPs (IPs Permitidos), enter the IP of the machine that will use the key, one per line. Leaving it blank allows use from anywhere on the internet.
  6. Click Create (Criar).

The Your API Key window (Sua Chave API) shows the full key, which starts with ptlc_. Copy it and keep it somewhere safe: it isn't shown again. If you lose it, delete the key and create another.

πŸ’‘Tip: If the script will run on a RedHosting VPS or bot server, fill in Allowed IPs with its IP. That way, even if the key leaks, it won't work from anywhere else.

3. Finding the server identifier

Every call needs to say which server to act on. The identifier appears in the address bar when you open the server in the panel:

https://app.redhosting.com.br/server/1a2b3c4d

The identifier is the part after /server/ β€” in the example, 1a2b3c4d. The examples below use YOUR_SERVER in its place and YOUR_KEY in place of the key.

4. First test

Every request carries the key and the indication that the conversation is in JSON. This command lists the account's servers and confirms that the key works:

curl https://app.redhosting.com.br/api/client \
  -H "Authorization: Bearer YOUR_KEY" \
  -H "Accept: application/json"

The response has one item per server. The identifier field of each is the same identifier from the previous step.

5. Managing the server

Check whether it's on and how much it uses

curl https://app.redhosting.com.br/api/client/servers/YOUR_SERVER/resources \
  -H "Authorization: Bearer YOUR_KEY" \
  -H "Accept: application/json"

The current_state field gives the state: running, starting, stopping or offline. Under resources come memory and disk in bytes and CPU as a percentage.

Start, stop and restart

curl -X POST https://app.redhosting.com.br/api/client/servers/YOUR_SERVER/power \
  -H "Authorization: Bearer YOUR_KEY" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{"signal": "restart"}'

signal accepts start, stop, restart and kill. Prefer stop: it shuts down gracefully and lets the server save what's in memory. kill cuts it off immediately, like pulling the plug, and can corrupt the world or open files.

Send a command to the console

curl -X POST https://app.redhosting.com.br/api/client/servers/YOUR_SERVER/command \
  -H "Authorization: Bearer YOUR_KEY" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{"command": "say Restarting in 5 minutes"}'

The command goes to the console exactly as if you'd typed it there. The server must be on; if it's off, the response is a 502 error.

Read and write files

To list a folder:

curl "https://app.redhosting.com.br/api/client/servers/YOUR_SERVER/files/list?directory=/" \
  -H "Authorization: Bearer YOUR_KEY" \
  -H "Accept: application/json"

To read a file β€” the response is the raw content, not JSON:

curl "https://app.redhosting.com.br/api/client/servers/YOUR_SERVER/files/contents?file=/server.properties" \
  -H "Authorization: Bearer YOUR_KEY"

To write, the request body is the file's entire new content, which replaces the old one:

curl -X POST "https://app.redhosting.com.br/api/client/servers/YOUR_SERVER/files/write?file=/motd.txt" \
  -H "Authorization: Bearer YOUR_KEY" \
  -H "Accept: application/json" \
  --data-binary @motd.txt

Summary of the endpoints. All start with https://app.redhosting.com.br/api/client/servers/YOUR_SERVER:

ActionMethodEndpoint
State and usageGET/resources
Start, stop, restartPOST/power
Console commandPOST/command
List folderGET/files/list?directory=/
Read fileGET/files/contents?file=/path
Write filePOST/files/write?file=/path
List backupsGET/backups

6. Example: bring the server back up if it goes down

A Node.js script (version 18 or newer) that checks the state and starts the server when it finds it off. The key comes from an environment variable, not written in the code β€” that's how it stays out of GitHub along with everything else.

const PANEL = 'https://app.redhosting.com.br/api/client';
const SERVER = 'YOUR_SERVER';
const headers = {
  Authorization: `Bearer ${process.env.PANEL_API_KEY}`,
  Accept: 'application/json',
  'Content-Type': 'application/json',
};

async function check() {
  const response = await fetch(`${PANEL}/servers/${SERVER}/resources`, { headers });
  if (!response.ok) throw new Error(`API responded ${response.status}`);

  const { attributes } = await response.json();
  if (attributes.current_state === 'offline') {
    await fetch(`${PANEL}/servers/${SERVER}/power`, {
      method: 'POST',
      headers,
      body: JSON.stringify({ signal: 'start' }),
    });
    console.log('Server was off β€” starting it.');
  }
}

check().catch((error) => console.error(error.message));

Run every few minutes by a system scheduler, it brings the server back after an outage. Don't run it at too short an interval: see the request limit in the next section.

πŸ’‘Tip: Before automating restarts, find out why the server is going down. A server that crashes for lack of memory will crash again right after starting, and the script only hides the problem. The guide My service is down: how to find the cause helps with that.

7. Common errors

ResponseWhat it meansWhat to do
401The key wasn't accepted.Check that you copied the whole key, including ptlc_, and that the header is Authorization: Bearer. A key deleted in the panel stops working immediately.
403The key works, but not here.The IP the request came from isn't in Allowed IPs, or your account is a subuser of the server without permission for that action.
404Server or file not found.Check the 8-character identifier and the file path, which starts with /.
409The server can't do that right now.It's installing, being transferred or suspended. Wait for it to finish.
429Too many requests.The panel accepts up to 256 requests per minute per account. Space out your calls.
502The server must be on.Happens when sending a command with the server off. Start it first.

8. Security

  • One key per use. One for the bot, another for the backup script. If one leaks, you delete just that one and the rest keeps working.
  • Fill in Allowed IPs whenever you know where the key will be used from.
  • Keep the key in an environment variable or a .env file that's in .gitignore, never inside the code.
  • Check the "Last used" of each key in the API Key tab. A key you no longer use but that keeps being used is a key that has leaked.
  • To revoke, click the trash icon next to the key. Deletion takes effect immediately for all requests.

Before putting the script into production

βœ“The key has a description that says what it's for.
βœ“Allowed IPs is filled in with the IP of the machine that will use the key.
βœ“The key is in an environment variable, out of the code and out of Git.
βœ“You tested the key with the server listing and got your list back.
βœ“The script uses stop, not kill, to shut down.
βœ“You know the API is experimental and that support doesn't help with the script.

Frequently asked questions

Does RedHosting support the panel API? +
No. The API is an experimental feature, offered as is: the team doesn't help build scripts or debug integrations, and isn't responsible for what a script does on the server. Support still covers the service itself β€” server down, panel, network and billing.
Where do I create the API key? +
In the panel, under Account (Conta) β†’ API Key tab (Chave API), in the box at the bottom of the page. Fill in the description and allowed IPs and click Create.
I lost the key. Can I see it again? +
No. The key is only shown once, when it's created. Delete the old one with the trash icon and create another.
Which servers does the key give access to? +
All the servers in your account, with the same permissions you have in the panel. There's no key limited to a single server β€” which is why it's worth filling in Allowed IPs and using one key per application.
Where do I find the server identifier? +
In the address bar when you open the server in the panel: it's the 8-character code after /server/.
Can I use the key in a Discord bot? +
Yes, keeping the key in an environment variable and never in the code. And restrict in the bot who can trigger the commands: a shutdown command open to the whole Discord server is a shutdown button open to anyone.
Is there a request limit? +
Yes, 256 per minute. Above that the API responds 429 until the minute rolls over.