SNG Hosting API · v1
Control your servers from your own code
Power, metrics, IP addresses, reverse DNS, traffic, firewall and DDoS protection for every SNG VPS and dedicated server, behind one token and one consistent API.
curl -X POST https://api.snghosting.com/api/v1/servers/ded_6a4b…/actions \
-H "Authorization: Bearer $SNG_API_TOKEN" \
-H "Idempotency-Key: 5f0c…" \
-d '{"action":"reboot"}'{
"data": {
"operation": {
"id": "6a4b2a40-6d0e-4c1b-9c1d-1c7c8f3f0a11",
"action": "reboot",
"status": "running",
"requestedAt": "2026-10-07T12:00:00.000Z"
}
}
}
Introduction
The SNG API is a JSON over HTTPS API. Every endpoint lives under the base URL below and returns either a data object or an error object, never both.
Everything you can do in the control panel for a server, its network and its DDoS protection is available here, with the same ownership checks: a token only ever sees the servers of the account that created it.
https://api.snghosting.com/api/v1Quick start
- Open API & MCP in the SNG control panel and create a personal access token. Choose only the scopes your integration needs.
- Copy the token. SNG shows it once and stores only a hash.
- Call
GET /connectto confirm the token works, thenGET /serversto list your servers.
curl "https://api.snghosting.com/api/v1/servers" \
-H "Authorization: Bearer $SNG_API_TOKEN"const response = await fetch("https://api.snghosting.com/api/v1/servers", {
headers: { Authorization: `Bearer ${process.env.SNG_API_TOKEN}` },
});
const { data: servers } = await response.json();import os, requests
servers = requests.get(
"https://api.snghosting.com/api/v1/servers",
headers={"Authorization": f"Bearer {os.environ['SNG_API_TOKEN']}"},
timeout=30,
).json()["data"]$ch = curl_init("https://api.snghosting.com/api/v1/servers");
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => ["Authorization: Bearer " . getenv("SNG_API_TOKEN")],
]);
$servers = json_decode(curl_exec($ch), true)["data"];
Authentication
Send the token in the Authorization header on every request: Authorization: Bearer sng_pat_v1_….
Tokens expire (30 days by default, 90 at most) and can be revoked at any time. You can restrict a token to up to ten source IP addresses. Reseller tokens always require an IP allowlist.
Never put a token in front-end code or a public repository. If one leaks, revoke it in the control panel; the next request with it is refused.
Scopes
Each token carries explicit scopes. A request outside them is refused with insufficient_scope, and no scope grants everything.
| Scope | Allows |
|---|---|
servers:read | List servers and read details, resource usage and operation status. |
servers:power | Start and reboot servers. |
servers:control | Shut down, force off and hard-reset servers. Use together with servers:power. |
network:read | Read IP addresses, reverse DNS, traffic, DDoS protection, attacks, filter rules and the VPS firewall. |
network:write | Change reverse DNS, IP descriptions, the DDoS protection mode and the VPS firewall. |
Requests and responses
Send JSON with Content-Type: application/json. Bodies are limited to 10 KB.
Server ids look like vps_1_4021 or ded_<uuid>. Take them from GET /servers; do not build them yourself.
Every response carries an X-Request-Id header. Include it when you contact support.
Idempotent actions
Every request that changes something needs an Idempotency-Key header: a unique value of 8–128 characters per intended action, such as a UUID.
If the connection drops and you retry with the same key, SNG returns the first result (with Idempotent-Replayed: true) instead of rebooting the server twice. Reusing a key with a different body is refused with idempotency_key_reused.
Actions run asynchronously. A 202 response contains an operation; poll GET /servers/{serverId}/operations/{operationId} until its status is succeeded, failed, timed_out or outcome_unknown. The API never reports success before the server confirms it.
Rate limits
Each token can make 120 requests and 10 actions per minute, and an account 300 requests per minute across all its tokens. Every response reports the tightest budget that applies:
RateLimit-Limit | Requests allowed in the window. |
RateLimit-Remaining | Requests left in the window. |
RateLimit-Reset | Seconds until the window resets. |
Retry-After | On 429 only: seconds to wait before retrying. |
Fresh and stale data
Network and infrastructure readings are cached for a few seconds and shared between callers, so polling stays fast and never slows anyone down.
When live data is briefly unavailable, the API returns the last good value with meta.stale: true and meta.observedAt, instead of failing. A refusal, such as a server that no longer belongs to you, is never answered from cache.
Errors
Errors use stable codes you can rely on in code. The message is for people and may change.
{
"error": {
"code": "insufficient_scope",
"message": "This API token does not have the network:read scope.",
"requestId": "req_8f2kQ1mZx0aLr3Ts"
}
}
| HTTP | Code | Meaning |
|---|---|---|
| 400 | validation_failed | The body or a parameter is invalid. fields lists each problem. |
| 400 | idempotency_key_required | A change request was sent without an Idempotency-Key. |
| 401 | unauthorized | The token is missing, invalid, expired or revoked. |
| 403 | insufficient_scope | The token lacks the scope this request needs. |
| 403 | ip_not_allowed | The request came from an address the token does not allow. |
| 403 | primary_owner_required | The server was shared with you; only its owner can change it. |
| 404 | not_found | The server, address or operation does not exist on this account. |
| 409 | action_unsupported | This server type does not support the request. |
| 409 | idempotency_request_in_progress | A request with this key is still running. |
| 422 | idempotency_key_reused | The key was already used for a different request. |
| 423 | service_locked | The service is suspended or locked. |
| 429 | rate_limited | Too many requests. Wait for Retry-After. |
| 502 | action_failed | The server reported that the action failed. |
| 503 | outcome_unknown | The action was sent but its result could not be confirmed. Check the server before retrying. |
| 503 | temporarily_unavailable | Try again shortly. |
| 504 | action_timeout | The server did not confirm the action in time. |
API reference
Account
Test the API token
GET/connect
Scope Any valid token
Confirms the token works and shows its scopes. Needs no scope.
Response 200
accountIdinteger |
|
tokenobject |
|
token.namestring |
|
token.typestring |
|
token.scopesstring[] |
|
sourceIpstring |
|
apiVersionstring |
|
Errors
curl -X GET "https://api.snghosting.com/api/v1/connect" \
-H "Authorization: Bearer $SNG_API_TOKEN"const response = await fetch("https://api.snghosting.com/api/v1/connect", {
method: "GET",
headers: {
Authorization: `Bearer ${process.env.SNG_API_TOKEN}`,
},
});
const { data, error } = await response.json();import os, uuid, requests
response = requests.get(
"https://api.snghosting.com/api/v1/connect",
headers={
"Authorization": f"Bearer {os.environ['SNG_API_TOKEN']}",
},
timeout=30,
)
data = response.json()$ch = curl_init("https://api.snghosting.com/api/v1/connect");
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer " . getenv("SNG_API_TOKEN"),
],
]);
$data = json_decode(curl_exec($ch), true);
{
"data": {
"accountId": 0,
"token": {
"name": "game-01",
"type": "personal_token",
"scopes": [
"string"
]
},
"sourceIp": "198.51.100.7",
"apiVersion": "v1"
}
}
Servers
List servers
GET/servers
Scope servers:read
Every VPS, VDS, and dedicated server on the account, including shared ones.
Response 200
idstring |
Server id from GET /servers, e.g. |
typestring |
|
namestring |
|
hostnamestring or null |
|
statusstring |
Service state. Actions are only accepted while
|
powerstring |
|
ipv4string[] |
|
ipv6string[] |
|
osstring or null |
|
resourcesobject |
|
resources.cpuCoresnumber or null |
|
resources.memoryMbnumber or null |
|
resources.storageGbnumber or null |
|
resources.trafficGbnumber or null |
Monthly traffic allowance; null when unmetered. |
accessRolestring |
|
serviceIdinteger or null |
SNG billing service id. |
createdAtstring or null |
ISO 8601 timestamp. |
Errors
curl -X GET "https://api.snghosting.com/api/v1/servers" \
-H "Authorization: Bearer $SNG_API_TOKEN"const response = await fetch("https://api.snghosting.com/api/v1/servers", {
method: "GET",
headers: {
Authorization: `Bearer ${process.env.SNG_API_TOKEN}`,
},
});
const { data, error } = await response.json();import os, uuid, requests
response = requests.get(
"https://api.snghosting.com/api/v1/servers",
headers={
"Authorization": f"Bearer {os.environ['SNG_API_TOKEN']}",
},
timeout=30,
)
data = response.json()$ch = curl_init("https://api.snghosting.com/api/v1/servers");
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer " . getenv("SNG_API_TOKEN"),
],
]);
$data = json_decode(curl_exec($ch), true);
{
"data": [
{
"id": "vps_1_4021",
"type": "vps",
"name": "game-01",
"hostname": "game-01.example.com",
"status": "active",
"power": "running",
"ipv4": [
"string"
],
"ipv6": [
"string"
],
"os": "Ubuntu 24.04",
"resources": {
"cpuCores": 0,
"memoryMb": 0,
"storageGb": 0,
"trafficGb": 0
},
"accessRole": "primary",
"serviceId": null,
"createdAt": "2026-10-07T12:00:00.000Z"
}
]
}
Get a server
GET/servers/{serverId}
Scope servers:read
Includes the power actions this token can run now and any action in progress.
Parameters
serverId path · requiredstring |
Server id from GET /servers, e.g. |
Response 200
idstring |
Server id from GET /servers, e.g. |
typestring |
|
namestring |
|
hostnamestring or null |
|
statusstring |
Service state. Actions are only accepted while
|
powerstring |
|
ipv4string[] |
|
ipv6string[] |
|
osstring or null |
|
resourcesobject |
|
resources.cpuCoresnumber or null |
|
resources.memoryMbnumber or null |
|
resources.storageGbnumber or null |
|
resources.trafficGbnumber or null |
Monthly traffic allowance; null when unmetered. |
accessRolestring |
|
serviceIdinteger or null |
SNG billing service id. |
createdAtstring or null |
ISO 8601 timestamp. |
actionsstring[] |
Power actions this token can run on the server right now.
|
currentOperationobject or null |
|
currentOperation.idstring |
|
currentOperation.serverIdstring |
Server id from GET /servers, e.g. |
currentOperation.actionstring |
|
currentOperation.statusstring |
|
currentOperation.messagestring or null |
|
currentOperation.requestedAtstring or null |
ISO 8601 timestamp. |
currentOperation.completedAtstring or null |
ISO 8601 timestamp. |
Errors
curl -X GET "https://api.snghosting.com/api/v1/servers/vps_1_4021" \
-H "Authorization: Bearer $SNG_API_TOKEN"const response = await fetch("https://api.snghosting.com/api/v1/servers/vps_1_4021", {
method: "GET",
headers: {
Authorization: `Bearer ${process.env.SNG_API_TOKEN}`,
},
});
const { data, error } = await response.json();import os, uuid, requests
response = requests.get(
"https://api.snghosting.com/api/v1/servers/vps_1_4021",
headers={
"Authorization": f"Bearer {os.environ['SNG_API_TOKEN']}",
},
timeout=30,
)
data = response.json()$ch = curl_init("https://api.snghosting.com/api/v1/servers/vps_1_4021");
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer " . getenv("SNG_API_TOKEN"),
],
]);
$data = json_decode(curl_exec($ch), true);
{
"data": {
"id": "vps_1_4021",
"type": "vps",
"name": "game-01",
"hostname": "game-01.example.com",
"status": "active",
"power": "running",
"ipv4": [
"string"
],
"ipv6": [
"string"
],
"os": "Ubuntu 24.04",
"resources": {
"cpuCores": 0,
"memoryMb": 0,
"storageGb": 0,
"trafficGb": 0
},
"accessRole": "primary",
"serviceId": null,
"createdAt": "2026-10-07T12:00:00.000Z",
"actions": [
"start"
],
"currentOperation": {
"id": "q48211",
"serverId": "vps_1_4021",
"action": "reboot",
"status": "queued",
"message": null,
"requestedAt": "2026-10-07T12:00:00.000Z",
"completedAt": null
}
}
}
Get resource usage
GET/servers/{serverId}/metrics
Scope servers:read
CPU, memory, disk, and monthly bandwidth. Dedicated servers report usage through the SNG agent.
Parameters
serverId path · requiredstring |
Server id from GET /servers, e.g. |
Response 200
sampledAtstring or null |
ISO 8601 timestamp. |
cpuPercentnumber or null |
|
memoryobject or null |
|
memory.totalBytesnumber |
|
memory.usedBytesnumber |
|
memory.usagePercentnumber or null |
|
storageobject[] |
|
storage.mountstring |
|
storage.totalBytesnumber |
|
storage.usedBytesnumber |
|
storage.usagePercentnumber or null |
|
bandwidthobject or null |
Traffic used in the current billing month, when the server reports it. |
bandwidth.usedBytesnumber |
|
bandwidth.limitBytesnumber or null |
Errors
curl -X GET "https://api.snghosting.com/api/v1/servers/vps_1_4021/metrics" \
-H "Authorization: Bearer $SNG_API_TOKEN"const response = await fetch("https://api.snghosting.com/api/v1/servers/vps_1_4021/metrics", {
method: "GET",
headers: {
Authorization: `Bearer ${process.env.SNG_API_TOKEN}`,
},
});
const { data, error } = await response.json();import os, uuid, requests
response = requests.get(
"https://api.snghosting.com/api/v1/servers/vps_1_4021/metrics",
headers={
"Authorization": f"Bearer {os.environ['SNG_API_TOKEN']}",
},
timeout=30,
)
data = response.json()$ch = curl_init("https://api.snghosting.com/api/v1/servers/vps_1_4021/metrics");
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer " . getenv("SNG_API_TOKEN"),
],
]);
$data = json_decode(curl_exec($ch), true);
{
"data": {
"sampledAt": "2026-10-07T12:00:00.000Z",
"cpuPercent": 0,
"memory": {
"totalBytes": 0,
"usedBytes": 0,
"usagePercent": 0
},
"storage": [
{
"mount": "/",
"totalBytes": 0,
"usedBytes": 0,
"usagePercent": 0
}
],
"bandwidth": {
"usedBytes": 0,
"limitBytes": 0
}
}
}
Run a power action
POST/servers/{serverId}/actions
Scope servers:power
start and reboot need servers:power; shutdown, power_off, and reset also need servers:control. Starts the action and returns an operation. A 202 means it is still running: poll GET /servers/{serverId}/operations/{operationId} until it reaches a final status. The API never reports success before the server confirms it.
Parameters
serverId path · requiredstring |
Server id from GET /servers, e.g. |
Idempotency-Key header · requiredstring |
A unique value per intended action (8–128 characters). Repeating a request with the same key returns the first result instead of running the action again. |
Request body
actionstring |
|
Response 202
operationobject |
|
operation.idstring |
|
operation.serverIdstring |
Server id from GET /servers, e.g. |
operation.actionstring |
|
operation.statusstring |
|
operation.messagestring or null |
|
operation.requestedAtstring or null |
ISO 8601 timestamp. |
operation.completedAtstring or null |
ISO 8601 timestamp. |
Errors
curl -X POST "https://api.snghosting.com/api/v1/servers/vps_1_4021/actions" \
-H "Authorization: Bearer $SNG_API_TOKEN" \
-H "Idempotency-Key: $(uuidgen)" \
-H "Content-Type: application/json" \
-d '{"action":"reboot"}'const response = await fetch("https://api.snghosting.com/api/v1/servers/vps_1_4021/actions", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.SNG_API_TOKEN}`,
"Idempotency-Key": crypto.randomUUID(),
"Content-Type": "application/json",
},
body: JSON.stringify({
"action": "reboot"
}),
});
const { data, error } = await response.json();import os, uuid, requests
response = requests.post(
"https://api.snghosting.com/api/v1/servers/vps_1_4021/actions",
headers={
"Authorization": f"Bearer {os.environ['SNG_API_TOKEN']}",
"Idempotency-Key": str(uuid.uuid4()),
},
json={
"action": "reboot"
},
timeout=30,
)
data = response.json()$ch = curl_init("https://api.snghosting.com/api/v1/servers/vps_1_4021/actions");
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer " . getenv("SNG_API_TOKEN"),
"Idempotency-Key: " . bin2hex(random_bytes(16)),
"Content-Type: application/json",
],
CURLOPT_POSTFIELDS => '{"action":"reboot"}',
]);
$data = json_decode(curl_exec($ch), true);
{
"data": {
"operation": {
"id": "q48211",
"serverId": "vps_1_4021",
"action": "reboot",
"status": "queued",
"message": null,
"requestedAt": "2026-10-07T12:00:00.000Z",
"completedAt": null
}
}
}
Get an operation
GET/servers/{serverId}/operations/{operationId}
Scope servers:read
Parameters
serverId path · requiredstring |
Server id from GET /servers, e.g. |
operationId path · requiredstring |
Operation id returned by an action. |
Response 200
idstring |
|
serverIdstring |
Server id from GET /servers, e.g. |
actionstring |
|
statusstring |
|
messagestring or null |
|
requestedAtstring or null |
ISO 8601 timestamp. |
completedAtstring or null |
ISO 8601 timestamp. |
Errors
curl -X GET "https://api.snghosting.com/api/v1/servers/vps_1_4021/operations/q48211" \
-H "Authorization: Bearer $SNG_API_TOKEN"const response = await fetch("https://api.snghosting.com/api/v1/servers/vps_1_4021/operations/q48211", {
method: "GET",
headers: {
Authorization: `Bearer ${process.env.SNG_API_TOKEN}`,
},
});
const { data, error } = await response.json();import os, uuid, requests
response = requests.get(
"https://api.snghosting.com/api/v1/servers/vps_1_4021/operations/q48211",
headers={
"Authorization": f"Bearer {os.environ['SNG_API_TOKEN']}",
},
timeout=30,
)
data = response.json()$ch = curl_init("https://api.snghosting.com/api/v1/servers/vps_1_4021/operations/q48211");
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer " . getenv("SNG_API_TOKEN"),
],
]);
$data = json_decode(curl_exec($ch), true);
{
"data": {
"id": "q48211",
"serverId": "vps_1_4021",
"action": "reboot",
"status": "queued",
"message": null,
"requestedAt": "2026-10-07T12:00:00.000Z",
"completedAt": null
}
}
Network
List IP addresses
GET/servers/{serverId}/ips
Scope network:read
Parameters
serverId path · requiredstring |
Server id from GET /servers, e.g. |
Response 200
addressstring |
|
versionstring |
|
primaryboolean |
Errors
curl -X GET "https://api.snghosting.com/api/v1/servers/vps_1_4021/ips" \
-H "Authorization: Bearer $SNG_API_TOKEN"const response = await fetch("https://api.snghosting.com/api/v1/servers/vps_1_4021/ips", {
method: "GET",
headers: {
Authorization: `Bearer ${process.env.SNG_API_TOKEN}`,
},
});
const { data, error } = await response.json();import os, uuid, requests
response = requests.get(
"https://api.snghosting.com/api/v1/servers/vps_1_4021/ips",
headers={
"Authorization": f"Bearer {os.environ['SNG_API_TOKEN']}",
},
timeout=30,
)
data = response.json()$ch = curl_init("https://api.snghosting.com/api/v1/servers/vps_1_4021/ips");
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer " . getenv("SNG_API_TOKEN"),
],
]);
$data = json_decode(curl_exec($ch), true);
{
"data": [
{
"address": "203.0.113.20",
"version": "ipv4",
"primary": true
}
]
}
Get IP settings
GET/servers/{serverId}/ips/{ip}
Scope network:read
Reverse DNS, description, and DDoS protection mode of one address.
Parameters
serverId path · requiredstring |
Server id from GET /servers, e.g. |
ip path · requiredstring · ipv4 |
An IPv4 address assigned to the server. |
Response 200
addressstring |
|
rdnsstring or null |
|
descriptionstring or null |
|
protectionobject or null |
DDoS protection mode. |
protection.layer4string |
|
protection.layer7string |
|
editableobject |
|
editable.rdnsboolean |
|
editable.descriptionboolean |
|
editable.protectionboolean |
Errors
curl -X GET "https://api.snghosting.com/api/v1/servers/ded_6a4b2a40-6d0e-4c1b-9c1d-1c7c8f3f0a11/ips/203.0.113.20" \
-H "Authorization: Bearer $SNG_API_TOKEN"const response = await fetch("https://api.snghosting.com/api/v1/servers/ded_6a4b2a40-6d0e-4c1b-9c1d-1c7c8f3f0a11/ips/203.0.113.20", {
method: "GET",
headers: {
Authorization: `Bearer ${process.env.SNG_API_TOKEN}`,
},
});
const { data, error } = await response.json();import os, uuid, requests
response = requests.get(
"https://api.snghosting.com/api/v1/servers/ded_6a4b2a40-6d0e-4c1b-9c1d-1c7c8f3f0a11/ips/203.0.113.20",
headers={
"Authorization": f"Bearer {os.environ['SNG_API_TOKEN']}",
},
timeout=30,
)
data = response.json()$ch = curl_init("https://api.snghosting.com/api/v1/servers/ded_6a4b2a40-6d0e-4c1b-9c1d-1c7c8f3f0a11/ips/203.0.113.20");
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer " . getenv("SNG_API_TOKEN"),
],
]);
$data = json_decode(curl_exec($ch), true);
{
"data": {
"address": "203.0.113.20",
"rdns": "mail.example.com",
"description": "Game server",
"protection": {
"layer4": "dynamic",
"layer7": "off"
},
"editable": {
"rdns": true,
"description": true,
"protection": true
}
}
}
Change IP settings
PATCH/servers/{serverId}/ips/{ip}
Scope network:write
Change reverse DNS, the description, or the DDoS protection mode of a dedicated server address. Send one change per request.
Parameters
serverId path · requiredstring |
Server id from GET /servers, e.g. |
ip path · requiredstring · ipv4 |
An IPv4 address assigned to the server. |
Idempotency-Key header · requiredstring |
A unique value per intended action (8–128 characters). Repeating a request with the same key returns the first result instead of running the action again. |
Request body
Exactly one change per request: rdns, description, or protection.
| One of · 1 | |
rdnsstring |
|
| One of · 2 | |
descriptionstring |
|
| One of · 3 | |
protectionobject |
|
protection.layer4string |
|
protection.layer7string |
|
Response 200
addressstring |
|
rdnsstring or null |
|
descriptionstring or null |
|
protectionobject or null |
DDoS protection mode. |
protection.layer4string |
|
protection.layer7string |
|
editableobject |
|
editable.rdnsboolean |
|
editable.descriptionboolean |
|
editable.protectionboolean |
Errors
curl -X PATCH "https://api.snghosting.com/api/v1/servers/ded_6a4b2a40-6d0e-4c1b-9c1d-1c7c8f3f0a11/ips/203.0.113.20" \
-H "Authorization: Bearer $SNG_API_TOKEN" \
-H "Idempotency-Key: $(uuidgen)" \
-H "Content-Type: application/json" \
-d '{"rdns":"mail.example.com"}'const response = await fetch("https://api.snghosting.com/api/v1/servers/ded_6a4b2a40-6d0e-4c1b-9c1d-1c7c8f3f0a11/ips/203.0.113.20", {
method: "PATCH",
headers: {
Authorization: `Bearer ${process.env.SNG_API_TOKEN}`,
"Idempotency-Key": crypto.randomUUID(),
"Content-Type": "application/json",
},
body: JSON.stringify({
"rdns": "mail.example.com"
}),
});
const { data, error } = await response.json();import os, uuid, requests
response = requests.patch(
"https://api.snghosting.com/api/v1/servers/ded_6a4b2a40-6d0e-4c1b-9c1d-1c7c8f3f0a11/ips/203.0.113.20",
headers={
"Authorization": f"Bearer {os.environ['SNG_API_TOKEN']}",
"Idempotency-Key": str(uuid.uuid4()),
},
json={
"rdns": "mail.example.com"
},
timeout=30,
)
data = response.json()$ch = curl_init("https://api.snghosting.com/api/v1/servers/ded_6a4b2a40-6d0e-4c1b-9c1d-1c7c8f3f0a11/ips/203.0.113.20");
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer " . getenv("SNG_API_TOKEN"),
"Idempotency-Key: " . bin2hex(random_bytes(16)),
"Content-Type: application/json",
],
CURLOPT_POSTFIELDS => '{"rdns":"mail.example.com"}',
]);
$data = json_decode(curl_exec($ch), true);
{
"data": {
"address": "203.0.113.20",
"rdns": "mail.example.com",
"description": "Game server",
"protection": {
"layer4": "dynamic",
"layer7": "off"
},
"editable": {
"rdns": true,
"description": true,
"protection": true
}
}
}
Get traffic
GET/servers/{serverId}/traffic
Scope network:read
Dedicated servers return the last 24 hours of port rates in Mbps (kind: rates). VPS servers return transfer per billing month (kind: monthly).
Parameters
serverId path · requiredstring |
Server id from GET /servers, e.g. |
Response 200
| One of · 1 | |
kindstring |
|
fromstring |
ISO 8601 timestamp. |
tostring |
ISO 8601 timestamp. |
totalsobject or null |
Transfer volume over the window. |
totals.incomingGbnumber |
|
totals.outgoingGbnumber |
|
interfacesobject[] |
|
interfaces.incomingobject[] |
|
interfaces.incoming.timestring |
ISO 8601 timestamp. |
interfaces.incoming.mbpsnumber |
|
interfaces.outgoingobject[] |
|
interfaces.outgoing.timestring |
ISO 8601 timestamp. |
interfaces.outgoing.mbpsnumber |
|
| One of · 2 | |
kindstring |
|
monthsobject[] |
|
months.startstring |
ISO 8601 timestamp. |
months.endstring |
ISO 8601 timestamp. |
months.rxBytesnumber |
|
months.txBytesnumber |
|
months.totalBytesnumber |
|
months.limitGbnumber or null |
|
Errors
curl -X GET "https://api.snghosting.com/api/v1/servers/vps_1_4021/traffic" \
-H "Authorization: Bearer $SNG_API_TOKEN"const response = await fetch("https://api.snghosting.com/api/v1/servers/vps_1_4021/traffic", {
method: "GET",
headers: {
Authorization: `Bearer ${process.env.SNG_API_TOKEN}`,
},
});
const { data, error } = await response.json();import os, uuid, requests
response = requests.get(
"https://api.snghosting.com/api/v1/servers/vps_1_4021/traffic",
headers={
"Authorization": f"Bearer {os.environ['SNG_API_TOKEN']}",
},
timeout=30,
)
data = response.json()$ch = curl_init("https://api.snghosting.com/api/v1/servers/vps_1_4021/traffic");
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer " . getenv("SNG_API_TOKEN"),
],
]);
$data = json_decode(curl_exec($ch), true);
{
"data": {
"kind": "rates",
"from": "string",
"to": "string",
"totals": {
"incomingGb": 0,
"outgoingGb": 0
},
"interfaces": [
{
"incoming": [
{
"time": "string",
"mbps": 0
}
],
"outgoing": [
{
"time": "string",
"mbps": 0
}
]
}
]
}
}
DDoS protection
Get DDoS protection and attacks
GET/servers/{serverId}/ddos
Scope network:read
Protection status and recent attacks for one address of the server (the primary address by default).
Parameters
serverId path · requiredstring |
Server id from GET /servers, e.g. |
ip querystring · ipv4 |
Address to inspect. |
Response 200
addressstring or null |
|
statusstring |
|
incidentsobject[] |
|
incidents.idstring |
|
incidents.startedAtstring |
ISO 8601 timestamp. |
incidents.endedAtstring or null |
ISO 8601 timestamp. |
incidents.durationSecondsnumber or null |
|
incidents.peakstring or null |
Peak attack rate, e.g. |
incidents.attackTypesstring[] |
|
totalIncidentsinteger |
|
addressesstring[] |
Every address of the server you can query with |
Errors
curl -X GET "https://api.snghosting.com/api/v1/servers/vps_1_4021/ddos" \
-H "Authorization: Bearer $SNG_API_TOKEN"const response = await fetch("https://api.snghosting.com/api/v1/servers/vps_1_4021/ddos", {
method: "GET",
headers: {
Authorization: `Bearer ${process.env.SNG_API_TOKEN}`,
},
});
const { data, error } = await response.json();import os, uuid, requests
response = requests.get(
"https://api.snghosting.com/api/v1/servers/vps_1_4021/ddos",
headers={
"Authorization": f"Bearer {os.environ['SNG_API_TOKEN']}",
},
timeout=30,
)
data = response.json()$ch = curl_init("https://api.snghosting.com/api/v1/servers/vps_1_4021/ddos");
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer " . getenv("SNG_API_TOKEN"),
],
]);
$data = json_decode(curl_exec($ch), true);
{
"data": {
"address": "203.0.113.20",
"status": "protected",
"incidents": [
{
"id": "vps_1_4021",
"startedAt": "2026-10-07T12:00:00.000Z",
"endedAt": null,
"durationSeconds": null,
"peak": "12.4 Gbps",
"attackTypes": [
"string"
]
}
],
"totalIncidents": 0,
"addresses": [
"string"
]
}
}
List DDoS filter rules
GET/servers/{serverId}/ips/{ip}/ddos/rules
Scope network:read
Filter rules applied to one address of a dedicated server.
Parameters
serverId path · requiredstring |
Server id from GET /servers, e.g. |
ip path · requiredstring · ipv4 |
An IPv4 address assigned to the server. |
Response 200
addressstring |
|
availableboolean |
|
rulesobject[] |
|
rules.protocolstring |
|
rules.portnumber |
|
rules.statestring |
Errors
curl -X GET "https://api.snghosting.com/api/v1/servers/ded_6a4b2a40-6d0e-4c1b-9c1d-1c7c8f3f0a11/ips/203.0.113.20/ddos/rules" \
-H "Authorization: Bearer $SNG_API_TOKEN"const response = await fetch("https://api.snghosting.com/api/v1/servers/ded_6a4b2a40-6d0e-4c1b-9c1d-1c7c8f3f0a11/ips/203.0.113.20/ddos/rules", {
method: "GET",
headers: {
Authorization: `Bearer ${process.env.SNG_API_TOKEN}`,
},
});
const { data, error } = await response.json();import os, uuid, requests
response = requests.get(
"https://api.snghosting.com/api/v1/servers/ded_6a4b2a40-6d0e-4c1b-9c1d-1c7c8f3f0a11/ips/203.0.113.20/ddos/rules",
headers={
"Authorization": f"Bearer {os.environ['SNG_API_TOKEN']}",
},
timeout=30,
)
data = response.json()$ch = curl_init("https://api.snghosting.com/api/v1/servers/ded_6a4b2a40-6d0e-4c1b-9c1d-1c7c8f3f0a11/ips/203.0.113.20/ddos/rules");
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer " . getenv("SNG_API_TOKEN"),
],
]);
$data = json_decode(curl_exec($ch), true);
{
"data": {
"address": "203.0.113.20",
"available": true,
"rules": [
{
"protocol": "tcp",
"port": 30120,
"state": "string"
}
]
}
}
Firewall
List firewall rule sets
GET/firewall/rulesets
Scope network:read
Rule sets that can be applied to a VPS firewall.
Response 200
idinteger |
|
namestring |
Errors
curl -X GET "https://api.snghosting.com/api/v1/firewall/rulesets" \
-H "Authorization: Bearer $SNG_API_TOKEN"const response = await fetch("https://api.snghosting.com/api/v1/firewall/rulesets", {
method: "GET",
headers: {
Authorization: `Bearer ${process.env.SNG_API_TOKEN}`,
},
});
const { data, error } = await response.json();import os, uuid, requests
response = requests.get(
"https://api.snghosting.com/api/v1/firewall/rulesets",
headers={
"Authorization": f"Bearer {os.environ['SNG_API_TOKEN']}",
},
timeout=30,
)
data = response.json()$ch = curl_init("https://api.snghosting.com/api/v1/firewall/rulesets");
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer " . getenv("SNG_API_TOKEN"),
],
]);
$data = json_decode(curl_exec($ch), true);
{
"data": [
{
"id": 0,
"name": "game-01"
}
]
}
Get the VPS firewall
GET/servers/{serverId}/firewall
Scope network:read
Parameters
serverId path · requiredstring |
Server id from GET /servers, e.g. |
Response 200
enabledboolean |
|
rulesetsinteger[] |
Ids of the applied rule sets. |
Errors
curl -X GET "https://api.snghosting.com/api/v1/servers/vps_1_4021/firewall" \
-H "Authorization: Bearer $SNG_API_TOKEN"const response = await fetch("https://api.snghosting.com/api/v1/servers/vps_1_4021/firewall", {
method: "GET",
headers: {
Authorization: `Bearer ${process.env.SNG_API_TOKEN}`,
},
});
const { data, error } = await response.json();import os, uuid, requests
response = requests.get(
"https://api.snghosting.com/api/v1/servers/vps_1_4021/firewall",
headers={
"Authorization": f"Bearer {os.environ['SNG_API_TOKEN']}",
},
timeout=30,
)
data = response.json()$ch = curl_init("https://api.snghosting.com/api/v1/servers/vps_1_4021/firewall");
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer " . getenv("SNG_API_TOKEN"),
],
]);
$data = json_decode(curl_exec($ch), true);
{
"data": {
"enabled": true,
"rulesets": [
0
]
}
}
Change the VPS firewall
PUT/servers/{serverId}/firewall
Scope network:write
Turn the firewall on or off and choose which rule sets apply.
Parameters
serverId path · requiredstring |
Server id from GET /servers, e.g. |
Idempotency-Key header · requiredstring |
A unique value per intended action (8–128 characters). Repeating a request with the same key returns the first result instead of running the action again. |
Request body
enabled optionalboolean |
|
rulesets optionalinteger[] |
Response 200
enabledboolean |
|
rulesetsinteger[] |
Ids of the applied rule sets. |
Errors
curl -X PUT "https://api.snghosting.com/api/v1/servers/vps_1_4021/firewall" \
-H "Authorization: Bearer $SNG_API_TOKEN" \
-H "Idempotency-Key: $(uuidgen)" \
-H "Content-Type: application/json" \
-d '{"enabled":true,"rulesets":[3]}'const response = await fetch("https://api.snghosting.com/api/v1/servers/vps_1_4021/firewall", {
method: "PUT",
headers: {
Authorization: `Bearer ${process.env.SNG_API_TOKEN}`,
"Idempotency-Key": crypto.randomUUID(),
"Content-Type": "application/json",
},
body: JSON.stringify({
"enabled": true,
"rulesets": [
3
]
}),
});
const { data, error } = await response.json();import os, uuid, requests
response = requests.put(
"https://api.snghosting.com/api/v1/servers/vps_1_4021/firewall",
headers={
"Authorization": f"Bearer {os.environ['SNG_API_TOKEN']}",
"Idempotency-Key": str(uuid.uuid4()),
},
json={
"enabled": True,
"rulesets": [
3
]
},
timeout=30,
)
data = response.json()$ch = curl_init("https://api.snghosting.com/api/v1/servers/vps_1_4021/firewall");
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer " . getenv("SNG_API_TOKEN"),
"Idempotency-Key: " . bin2hex(random_bytes(16)),
"Content-Type: application/json",
],
CURLOPT_POSTFIELDS => '{"enabled":true,"rulesets":[3]}',
]);
$data = json_decode(curl_exec($ch), true);
{
"data": {
"enabled": true,
"rulesets": [
0
]
}
}