---
title: "How to create an API key and manage your server through the panel API"
description: "Create an API key in your panel account and use it to start, stop and restart the server, send commands and handle files from a script. Experimental feature, not supported by the team."
url: "https://redhosting.com.br/en/base-de-conhecimento/como-criar-uma-chave-de-api-e-gerenciar-seu-servidor-pela-api-do-painel"
type: "article"
language: "en"
category: "Other"
published: "2026-09-24"
translations:
  pt-BR: "https://redhosting.com.br/base-de-conhecimento/como-criar-uma-chave-de-api-e-gerenciar-seu-servidor-pela-api-do-painel.md"
  en: "https://redhosting.com.br/en/base-de-conhecimento/como-criar-uma-chave-de-api-e-gerenciar-seu-servidor-pela-api-do-painel.md"
  es: "https://redhosting.com.br/es/base-de-conhecimento/como-criar-uma-chave-de-api-e-gerenciar-seu-servidor-pela-api-do-painel.md"
  de: "https://redhosting.com.br/de/base-de-conhecimento/como-criar-uma-chave-de-api-e-gerenciar-seu-servidor-pela-api-do-painel.md"
---

# How to create an API key and manage your server through the panel API

Create an API key in your panel account and use it to start, stop and restart the server, send commands and handle files from a script. Experimental feature, not supported by the team.

- RedHosting knowledge base guide — category: Other
- HTML page: https://redhosting.com.br/en/base-de-conhecimento/como-criar-uma-chave-de-api-e-gerenciar-seu-servidor-pela-api-do-painel
- Published on: 2026-09-24 · Language: en

🧪**Experimental feature — not supported**: The panel API is available to anyone who wants to automate their own server, but **RedHosting does not provide support for it**. The team doesn't help build scripts, doesn't debug integrations and isn't responsible for what a script does on your server — including shutting it down, deleting files or sending commands by mistake. The API's behavior may change without notice. Support still covers the service itself: server down, panel, network and billing.

Everything you do by clicking in the panel — starting the server, sending a console command, editing a file — can also be done with an HTTP request. That's what lets a Discord bot restart the Minecraft server with a command, a script bring the server back up if it goes down, or a routine save a configuration file every day.

This guide shows how to create the key that grants this access and how to use it for the most common operations.

## 1. What the API key can do

The key acts **on behalf of your account**. It has no separate permissions: whatever you can do in the panel, it can too, on **every server in the account**. The most used operations are:

- **Power** — start, stop, restart and force stop.
- **Console** — send commands such as `say`, `whitelist add` or `save-all`.
- **Usage** — read the server state and CPU, memory and disk usage.
- **Files** — list folders, read and write files.
- **Backups and schedules** — the same ones shown in the server's tabs.

  ⚠️**Treat the key like your password**: Whoever has the key controls all your servers, without needing your password or two-factor verification. Never publish the key on GitHub, in a screenshot or in a Discord channel.

## 2. Creating the key

The panel may show its labels in Portuguese; the original name is in parentheses.

1. Log in to the panel at [app.redhosting.com.br](https://app.redhosting.com.br).
2. In the side menu, click **Account** (Conta) — or go straight to [app.redhosting.com.br/account](https://app.redhosting.com.br/account).
3. Scroll to the keys box at the bottom of the page and click the **API Key** tab (Chave API) — the tab next to it is SSH Key.
4. Under **Description** (Descrição), write what the key is for — for example, `discord bot`. It needs at least 4 characters, and this name is what will tell you, months later, which key to delete.
5. Under **Allowed IPs** (IPs Permitidos), enter the IP of the machine that will use the key, one per line. Leaving it blank allows use from anywhere on the internet.
6. Click **Create** (Criar).

The **Your API Key** window (Sua Chave API) shows the full key, which starts with `ptlc_`. Copy it and keep it somewhere safe: **it isn't shown again**. If you lose it, delete the key and create another.

  💡**Tip**: If the script will run on a RedHosting VPS or bot server, fill in Allowed IPs with its IP. That way, even if the key leaks, it won't work from anywhere else.

## 3. Finding the server identifier

Every call needs to say which server to act on. The identifier appears in the address bar when you open the server in the panel:

```
https://app.redhosting.com.br/server/1a2b3c4d
```

The identifier is the part after `/server/` — in the example, `1a2b3c4d`. The examples below use `YOUR_SERVER` in its place and `YOUR_KEY` in place of the key.

## 4. First test

Every request carries the key and the indication that the conversation is in JSON. This command lists the account's servers and confirms that the key works:

```
curl https://app.redhosting.com.br/api/client \
  -H "Authorization: Bearer YOUR_KEY" \
  -H "Accept: application/json"
```

The response has one item per server. The `identifier` field of each is the same identifier from the previous step.

## 5. Managing the server

### Check whether it's on and how much it uses

```
curl https://app.redhosting.com.br/api/client/servers/YOUR_SERVER/resources \
  -H "Authorization: Bearer YOUR_KEY" \
  -H "Accept: application/json"
```

The `current_state` field gives the state: `running`, `starting`, `stopping` or `offline`. Under `resources` come memory and disk in bytes and CPU as a percentage.

### Start, stop and restart

```
curl -X POST https://app.redhosting.com.br/api/client/servers/YOUR_SERVER/power \
  -H "Authorization: Bearer YOUR_KEY" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{"signal": "restart"}'
```

`signal` accepts `start`, `stop`, `restart` and `kill`. Prefer `stop`: it shuts down gracefully and lets the server save what's in memory. `kill` cuts it off immediately, like pulling the plug, and can corrupt the world or open files.

### Send a command to the console

```
curl -X POST https://app.redhosting.com.br/api/client/servers/YOUR_SERVER/command \
  -H "Authorization: Bearer YOUR_KEY" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{"command": "say Restarting in 5 minutes"}'
```

The command goes to the console exactly as if you'd typed it there. The server must be on; if it's off, the response is a 502 error.

### Read and write files

To list a folder:

```
curl "https://app.redhosting.com.br/api/client/servers/YOUR_SERVER/files/list?directory=/" \
  -H "Authorization: Bearer YOUR_KEY" \
  -H "Accept: application/json"
```

To read a file — the response is the raw content, not JSON:

```
curl "https://app.redhosting.com.br/api/client/servers/YOUR_SERVER/files/contents?file=/server.properties" \
  -H "Authorization: Bearer YOUR_KEY"
```

To write, the request body is the file's entire new content, which replaces the old one:

```
curl -X POST "https://app.redhosting.com.br/api/client/servers/YOUR_SERVER/files/write?file=/motd.txt" \
  -H "Authorization: Bearer YOUR_KEY" \
  -H "Accept: application/json" \
  --data-binary @motd.txt
```

Summary of the endpoints. All start with `https://app.redhosting.com.br/api/client/servers/YOUR_SERVER`:

    ActionMethodEndpoint

    State and usageGET`/resources`
    Start, stop, restartPOST`/power`
    Console commandPOST`/command`
    List folderGET`/files/list?directory=/`
    Read fileGET`/files/contents?file=/path`
    Write filePOST`/files/write?file=/path`
    List backupsGET`/backups`

## 6. Example: bring the server back up if it goes down

A Node.js script (version 18 or newer) that checks the state and starts the server when it finds it off. The key comes from an environment variable, not written in the code — that's how it stays out of GitHub along with everything else.

```
const PANEL = 'https://app.redhosting.com.br/api/client';
const SERVER = 'YOUR_SERVER';
const headers = {
  Authorization: `Bearer ${process.env.PANEL_API_KEY}`,
  Accept: 'application/json',
  'Content-Type': 'application/json',
};

async function check() {
  const response = await fetch(`${PANEL}/servers/${SERVER}/resources`, { headers });
  if (!response.ok) throw new Error(`API responded ${response.status}`);

  const { attributes } = await response.json();
  if (attributes.current_state === 'offline') {
    await fetch(`${PANEL}/servers/${SERVER}/power`, {
      method: 'POST',
      headers,
      body: JSON.stringify({ signal: 'start' }),
    });
    console.log('Server was off — starting it.');
  }
}

check().catch((error) => console.error(error.message));
```

Run every few minutes by a system scheduler, it brings the server back after an outage. Don't run it at too short an interval: see the request limit in the next section.

  💡**Tip**: Before automating restarts, find out why the server is going down. A server that crashes for lack of memory will crash again right after starting, and the script only hides the problem. The guide [My service is down: how to find the cause](/en/base-de-conhecimento/meu-servico-esta-fora-do-ar-como-descobrir-a-causa) helps with that.

## 7. Common errors

    ResponseWhat it meansWhat to do

    **401**The key wasn't accepted.Check that you copied the whole key, including `ptlc_`, and that the header is `Authorization: Bearer`. A key deleted in the panel stops working immediately.
    **403**The key works, but not here.The IP the request came from isn't in Allowed IPs, or your account is a subuser of the server without permission for that action.
    **404**Server or file not found.Check the 8-character identifier and the file path, which starts with `/`.
    **409**The server can't do that right now.It's installing, being transferred or suspended. Wait for it to finish.
    **429**Too many requests.The panel accepts up to 256 requests per minute per account. Space out your calls.
    **502**The server must be on.Happens when sending a command with the server off. Start it first.

## 8. Security

- **One key per use.** One for the bot, another for the backup script. If one leaks, you delete just that one and the rest keeps working.
- **Fill in Allowed IPs** whenever you know where the key will be used from.
- **Keep the key in an environment variable or a `.env` file** that's in `.gitignore`, never inside the code.
- **Check the "Last used"** of each key in the API Key tab. A key you no longer use but that keeps being used is a key that has leaked.
- **To revoke**, click the trash icon next to the key. Deletion takes effect immediately for all requests.

  Before putting the script into production

    ✓The key has a description that says what it's for.

    ✓Allowed IPs is filled in with the IP of the machine that will use the key.

    ✓The key is in an environment variable, out of the code and out of Git.

    ✓You tested the key with the server listing and got your list back.

    ✓The script uses `stop`, not `kill`, to shut down.

    ✓You know the API is experimental and that support doesn't help with the script.

## Frequently asked questions

**Does RedHosting support the panel API?**

No. The API is an experimental feature, offered as is: the team doesn't help build scripts or debug integrations, and isn't responsible for what a script does on the server. Support still covers the service itself — server down, panel, network and billing.

**Where do I create the API key?**

In the panel, under **Account** (Conta) → **API Key** tab (Chave API), in the box at the bottom of the page. Fill in the description and allowed IPs and click Create.

**I lost the key. Can I see it again?**

No. The key is only shown once, when it's created. Delete the old one with the trash icon and create another.

**Which servers does the key give access to?**

All the servers in your account, with the same permissions you have in the panel. There's no key limited to a single server — which is why it's worth filling in Allowed IPs and using one key per application.

**Where do I find the server identifier?**

In the address bar when you open the server in the panel: it's the 8-character code after `/server/`.

**Can I use the key in a Discord bot?**

Yes, keeping the key in an environment variable and never in the code. And restrict in the bot who can trigger the commands: a shutdown command open to the whole Discord server is a shutdown button open to anyone.

**Is there a request limit?**

Yes, 256 per minute. Above that the API responds 429 until the minute rolls over.

## Navigation — Other (article 9 of 9)

- Previous article: [Welcome to the RedHosting Docs](https://redhosting.com.br/en/base-de-conhecimento/bem-vindo-ao-git-da-redhosting.md) — https://redhosting.com.br/en/base-de-conhecimento/bem-vindo-ao-git-da-redhosting
- Back to the knowledge base: https://redhosting.com.br/en/base-de-conhecimento

---

Need help with these steps? RedHosting's 24/7 support: suporte@redhosting.com.br · WhatsApp +55 11 98833-3902 · https://redhosting.com.br/discord

More guides: https://redhosting.com.br/en/base-de-conhecimento.md
