Developers

SNG Hosting API · v1

Control your servers from your own code

Power, metrics, IP addresses, reverse DNS, traffic, firewall and DDoS protection for every SNG VPS and dedicated server, behind one token and one consistent API.

Request
curl -X POST https://api.snghosting.com/api/v1/servers/ded_6a4b…/actions \
  -H "Authorization: Bearer $SNG_API_TOKEN" \
  -H "Idempotency-Key: 5f0c…" \
  -d '{"action":"reboot"}'
202 Accepted
{
  "data": {
    "operation": {
      "id": "6a4b2a40-6d0e-4c1b-9c1d-1c7c8f3f0a11",
      "action": "reboot",
      "status": "running",
      "requestedAt": "2026-10-07T12:00:00.000Z"
    }
  }
}

Introduction

The SNG API is a JSON over HTTPS API. Every endpoint lives under the base URL below and returns either a data object or an error object, never both.

Everything you can do in the control panel for a server, its network and its DDoS protection is available here, with the same ownership checks: a token only ever sees the servers of the account that created it.

Base URLhttps://api.snghosting.com/api/v1

Quick start

  1. Open API & MCP in the SNG control panel and create a personal access token. Choose only the scopes your integration needs.
  2. Copy the token. SNG shows it once and stores only a hash.
  3. Call GET /connect to confirm the token works, then GET /servers to list your servers.
curl "https://api.snghosting.com/api/v1/servers" \
  -H "Authorization: Bearer $SNG_API_TOKEN"

Authentication

Send the token in the Authorization header on every request: Authorization: Bearer sng_pat_v1_….

Tokens expire (30 days by default, 90 at most) and can be revoked at any time. You can restrict a token to up to ten source IP addresses. Reseller tokens always require an IP allowlist.

Never put a token in front-end code or a public repository. If one leaks, revoke it in the control panel; the next request with it is refused.

Scopes

Each token carries explicit scopes. A request outside them is refused with insufficient_scope, and no scope grants everything.

ScopeAllows
servers:readList servers and read details, resource usage and operation status.
servers:powerStart and reboot servers.
servers:controlShut down, force off and hard-reset servers. Use together with servers:power.
network:readRead IP addresses, reverse DNS, traffic, DDoS protection, attacks, filter rules and the VPS firewall.
network:writeChange reverse DNS, IP descriptions, the DDoS protection mode and the VPS firewall.

Requests and responses

Send JSON with Content-Type: application/json. Bodies are limited to 10 KB.

Server ids look like vps_1_4021 or ded_<uuid>. Take them from GET /servers; do not build them yourself.

Every response carries an X-Request-Id header. Include it when you contact support.

Idempotent actions

Every request that changes something needs an Idempotency-Key header: a unique value of 8–128 characters per intended action, such as a UUID.

If the connection drops and you retry with the same key, SNG returns the first result (with Idempotent-Replayed: true) instead of rebooting the server twice. Reusing a key with a different body is refused with idempotency_key_reused.

Actions run asynchronously. A 202 response contains an operation; poll GET /servers/{serverId}/operations/{operationId} until its status is succeeded, failed, timed_out or outcome_unknown. The API never reports success before the server confirms it.

Rate limits

Each token can make 120 requests and 10 actions per minute, and an account 300 requests per minute across all its tokens. Every response reports the tightest budget that applies:

RateLimit-LimitRequests allowed in the window.
RateLimit-RemainingRequests left in the window.
RateLimit-ResetSeconds until the window resets.
Retry-AfterOn 429 only: seconds to wait before retrying.

Fresh and stale data

Network and infrastructure readings are cached for a few seconds and shared between callers, so polling stays fast and never slows anyone down.

When live data is briefly unavailable, the API returns the last good value with meta.stale: true and meta.observedAt, instead of failing. A refusal, such as a server that no longer belongs to you, is never answered from cache.

Errors

Errors use stable codes you can rely on in code. The message is for people and may change.

Error
{
  "error": {
    "code": "insufficient_scope",
    "message": "This API token does not have the network:read scope.",
    "requestId": "req_8f2kQ1mZx0aLr3Ts"
  }
}
HTTPCodeMeaning
400validation_failedThe body or a parameter is invalid. fields lists each problem.
400idempotency_key_requiredA change request was sent without an Idempotency-Key.
401unauthorizedThe token is missing, invalid, expired or revoked.
403insufficient_scopeThe token lacks the scope this request needs.
403ip_not_allowedThe request came from an address the token does not allow.
403primary_owner_requiredThe server was shared with you; only its owner can change it.
404not_foundThe server, address or operation does not exist on this account.
409action_unsupportedThis server type does not support the request.
409idempotency_request_in_progressA request with this key is still running.
422idempotency_key_reusedThe key was already used for a different request.
423service_lockedThe service is suspended or locked.
429rate_limitedToo many requests. Wait for Retry-After.
502action_failedThe server reported that the action failed.
503outcome_unknownThe action was sent but its result could not be confirmed. Check the server before retrying.
503temporarily_unavailableTry again shortly.
504action_timeoutThe server did not confirm the action in time.

API reference

Account

Test the API token

GET/connect

Scope Any valid token

Confirms the token works and shows its scopes. Needs no scope.

Response 200

accountId
integer
token
object
token.name
string
token.type
string

personal_token reseller_token

token.scopes
string[]
sourceIp
string
apiVersion
string

v1

Errors

400 401 403 404 429

curl -X GET "https://api.snghosting.com/api/v1/connect" \
  -H "Authorization: Bearer $SNG_API_TOKEN"
Example response
{
  "data": {
    "accountId": 0,
    "token": {
      "name": "game-01",
      "type": "personal_token",
      "scopes": [
        "string"
      ]
    },
    "sourceIp": "198.51.100.7",
    "apiVersion": "v1"
  }
}

Servers

List servers

GET/servers

Scope servers:read

Every VPS, VDS, and dedicated server on the account, including shared ones.

Response 200

id
string

Server id from GET /servers, e.g. vps_1_4021 or ded_<uuid>.

type
string

vps vds dedicated

name
string
hostname
string or null
status
string

Service state. Actions are only accepted while active.

active provisioning building suspended failed terminated

power
string

running stopped unknown

ipv4
string[]
ipv6
string[]
os
string or null
resources
object
resources.cpuCores
number or null
resources.memoryMb
number or null
resources.storageGb
number or null
resources.trafficGb
number or null

Monthly traffic allowance; null when unmetered.

accessRole
string

secondary means the server was shared with this account: read-only.

primary secondary

serviceId
integer or null

SNG billing service id.

createdAt
string or null

ISO 8601 timestamp.

Errors

400 401 403 404 429

curl -X GET "https://api.snghosting.com/api/v1/servers" \
  -H "Authorization: Bearer $SNG_API_TOKEN"
Example response
{
  "data": [
    {
      "id": "vps_1_4021",
      "type": "vps",
      "name": "game-01",
      "hostname": "game-01.example.com",
      "status": "active",
      "power": "running",
      "ipv4": [
        "string"
      ],
      "ipv6": [
        "string"
      ],
      "os": "Ubuntu 24.04",
      "resources": {
        "cpuCores": 0,
        "memoryMb": 0,
        "storageGb": 0,
        "trafficGb": 0
      },
      "accessRole": "primary",
      "serviceId": null,
      "createdAt": "2026-10-07T12:00:00.000Z"
    }
  ]
}

Get a server

GET/servers/{serverId}

Scope servers:read

Includes the power actions this token can run now and any action in progress.

Parameters

serverId path · required
string

Server id from GET /servers, e.g. vps_1_4021 or ded_<uuid>.

Response 200

id
string

Server id from GET /servers, e.g. vps_1_4021 or ded_<uuid>.

type
string

vps vds dedicated

name
string
hostname
string or null
status
string

Service state. Actions are only accepted while active.

active provisioning building suspended failed terminated

power
string

running stopped unknown

ipv4
string[]
ipv6
string[]
os
string or null
resources
object
resources.cpuCores
number or null
resources.memoryMb
number or null
resources.storageGb
number or null
resources.trafficGb
number or null

Monthly traffic allowance; null when unmetered.

accessRole
string

secondary means the server was shared with this account: read-only.

primary secondary

serviceId
integer or null

SNG billing service id.

createdAt
string or null

ISO 8601 timestamp.

actions
string[]

Power actions this token can run on the server right now.

start shutdown power_off reboot reset

currentOperation
object or null
currentOperation.id
string
currentOperation.serverId
string

Server id from GET /servers, e.g. vps_1_4021 or ded_<uuid>.

currentOperation.action
string
currentOperation.status
string

outcome_unknown means the request was sent but its result could not be confirmed: check the server state before retrying.

queued running succeeded failed timed_out outcome_unknown

currentOperation.message
string or null
currentOperation.requestedAt
string or null

ISO 8601 timestamp.

currentOperation.completedAt
string or null

ISO 8601 timestamp.

Errors

400 401 403 404 429

curl -X GET "https://api.snghosting.com/api/v1/servers/vps_1_4021" \
  -H "Authorization: Bearer $SNG_API_TOKEN"
Example response
{
  "data": {
    "id": "vps_1_4021",
    "type": "vps",
    "name": "game-01",
    "hostname": "game-01.example.com",
    "status": "active",
    "power": "running",
    "ipv4": [
      "string"
    ],
    "ipv6": [
      "string"
    ],
    "os": "Ubuntu 24.04",
    "resources": {
      "cpuCores": 0,
      "memoryMb": 0,
      "storageGb": 0,
      "trafficGb": 0
    },
    "accessRole": "primary",
    "serviceId": null,
    "createdAt": "2026-10-07T12:00:00.000Z",
    "actions": [
      "start"
    ],
    "currentOperation": {
      "id": "q48211",
      "serverId": "vps_1_4021",
      "action": "reboot",
      "status": "queued",
      "message": null,
      "requestedAt": "2026-10-07T12:00:00.000Z",
      "completedAt": null
    }
  }
}

Get resource usage

GET/servers/{serverId}/metrics

Scope servers:read

CPU, memory, disk, and monthly bandwidth. Dedicated servers report usage through the SNG agent.

Parameters

serverId path · required
string

Server id from GET /servers, e.g. vps_1_4021 or ded_<uuid>.

Response 200

sampledAt
string or null

ISO 8601 timestamp.

cpuPercent
number or null
memory
object or null
memory.totalBytes
number
memory.usedBytes
number
memory.usagePercent
number or null
storage
object[]
storage.mount
string
storage.totalBytes
number
storage.usedBytes
number
storage.usagePercent
number or null
bandwidth
object or null

Traffic used in the current billing month, when the server reports it.

bandwidth.usedBytes
number
bandwidth.limitBytes
number or null

Errors

400 401 403 404 429

curl -X GET "https://api.snghosting.com/api/v1/servers/vps_1_4021/metrics" \
  -H "Authorization: Bearer $SNG_API_TOKEN"
Example response
{
  "data": {
    "sampledAt": "2026-10-07T12:00:00.000Z",
    "cpuPercent": 0,
    "memory": {
      "totalBytes": 0,
      "usedBytes": 0,
      "usagePercent": 0
    },
    "storage": [
      {
        "mount": "/",
        "totalBytes": 0,
        "usedBytes": 0,
        "usagePercent": 0
      }
    ],
    "bandwidth": {
      "usedBytes": 0,
      "limitBytes": 0
    }
  }
}

Run a power action

POST/servers/{serverId}/actions

Scope servers:power

start and reboot need servers:power; shutdown, power_off, and reset also need servers:control. Starts the action and returns an operation. A 202 means it is still running: poll GET /servers/{serverId}/operations/{operationId} until it reaches a final status. The API never reports success before the server confirms it.

Parameters

serverId path · required
string

Server id from GET /servers, e.g. vps_1_4021 or ded_<uuid>.

Idempotency-Key header · required
string

A unique value per intended action (8–128 characters). Repeating a request with the same key returns the first result instead of running the action again.

Request body

action
string

shutdown and reboot ask the operating system; power_off and reset act on the hardware immediately.

start shutdown power_off reboot reset

Response 202

operation
object
operation.id
string
operation.serverId
string

Server id from GET /servers, e.g. vps_1_4021 or ded_<uuid>.

operation.action
string
operation.status
string

outcome_unknown means the request was sent but its result could not be confirmed: check the server state before retrying.

queued running succeeded failed timed_out outcome_unknown

operation.message
string or null
operation.requestedAt
string or null

ISO 8601 timestamp.

operation.completedAt
string or null

ISO 8601 timestamp.

Errors

400 401 403 404 409 422 423 429 502 503 504

curl -X POST "https://api.snghosting.com/api/v1/servers/vps_1_4021/actions" \
  -H "Authorization: Bearer $SNG_API_TOKEN" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{"action":"reboot"}'
Example response
{
  "data": {
    "operation": {
      "id": "q48211",
      "serverId": "vps_1_4021",
      "action": "reboot",
      "status": "queued",
      "message": null,
      "requestedAt": "2026-10-07T12:00:00.000Z",
      "completedAt": null
    }
  }
}

Get an operation

GET/servers/{serverId}/operations/{operationId}

Scope servers:read

Parameters

serverId path · required
string

Server id from GET /servers, e.g. vps_1_4021 or ded_<uuid>.

operationId path · required
string

Operation id returned by an action.

Response 200

id
string
serverId
string

Server id from GET /servers, e.g. vps_1_4021 or ded_<uuid>.

action
string
status
string

outcome_unknown means the request was sent but its result could not be confirmed: check the server state before retrying.

queued running succeeded failed timed_out outcome_unknown

message
string or null
requestedAt
string or null

ISO 8601 timestamp.

completedAt
string or null

ISO 8601 timestamp.

Errors

400 401 403 404 429

curl -X GET "https://api.snghosting.com/api/v1/servers/vps_1_4021/operations/q48211" \
  -H "Authorization: Bearer $SNG_API_TOKEN"
Example response
{
  "data": {
    "id": "q48211",
    "serverId": "vps_1_4021",
    "action": "reboot",
    "status": "queued",
    "message": null,
    "requestedAt": "2026-10-07T12:00:00.000Z",
    "completedAt": null
  }
}

Network

List IP addresses

GET/servers/{serverId}/ips

Scope network:read

Parameters

serverId path · required
string

Server id from GET /servers, e.g. vps_1_4021 or ded_<uuid>.

Response 200

address
string
version
string

ipv4 ipv6

primary
boolean

Errors

400 401 403 404 429

curl -X GET "https://api.snghosting.com/api/v1/servers/vps_1_4021/ips" \
  -H "Authorization: Bearer $SNG_API_TOKEN"
Example response
{
  "data": [
    {
      "address": "203.0.113.20",
      "version": "ipv4",
      "primary": true
    }
  ]
}

Get IP settings

GET/servers/{serverId}/ips/{ip}

Scope network:read

Reverse DNS, description, and DDoS protection mode of one address.

Parameters

serverId path · required
string

Server id from GET /servers, e.g. vps_1_4021 or ded_<uuid>.

ip path · required
string · ipv4

An IPv4 address assigned to the server.

Response 200

address
string
rdns
string or null
description
string or null
protection
object or null

DDoS protection mode. dynamic filters only during an attack; permanent filters all the time. Layer 7 only filters web traffic only.

protection.layer4
string

dynamic permanent

protection.layer7
string

off permanent only

editable
object
editable.rdns
boolean
editable.description
boolean
editable.protection
boolean

Errors

400 401 403 404 429 503

curl -X GET "https://api.snghosting.com/api/v1/servers/ded_6a4b2a40-6d0e-4c1b-9c1d-1c7c8f3f0a11/ips/203.0.113.20" \
  -H "Authorization: Bearer $SNG_API_TOKEN"
Example response
{
  "data": {
    "address": "203.0.113.20",
    "rdns": "mail.example.com",
    "description": "Game server",
    "protection": {
      "layer4": "dynamic",
      "layer7": "off"
    },
    "editable": {
      "rdns": true,
      "description": true,
      "protection": true
    }
  }
}

Change IP settings

PATCH/servers/{serverId}/ips/{ip}

Scope network:write

Change reverse DNS, the description, or the DDoS protection mode of a dedicated server address. Send one change per request.

Parameters

serverId path · required
string

Server id from GET /servers, e.g. vps_1_4021 or ded_<uuid>.

ip path · required
string · ipv4

An IPv4 address assigned to the server.

Idempotency-Key header · required
string

A unique value per intended action (8–128 characters). Repeating a request with the same key returns the first result instead of running the action again.

Request body

Exactly one change per request: rdns, description, or protection.

One of · 1
rdns
string
One of · 2
description
string
One of · 3
protection
object
protection.layer4
string

dynamic permanent

protection.layer7
string

off permanent only

Response 200

address
string
rdns
string or null
description
string or null
protection
object or null

DDoS protection mode. dynamic filters only during an attack; permanent filters all the time. Layer 7 only filters web traffic only.

protection.layer4
string

dynamic permanent

protection.layer7
string

off permanent only

editable
object
editable.rdns
boolean
editable.description
boolean
editable.protection
boolean

Errors

400 401 403 404 409 422 423 429 503

curl -X PATCH "https://api.snghosting.com/api/v1/servers/ded_6a4b2a40-6d0e-4c1b-9c1d-1c7c8f3f0a11/ips/203.0.113.20" \
  -H "Authorization: Bearer $SNG_API_TOKEN" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{"rdns":"mail.example.com"}'
Example response
{
  "data": {
    "address": "203.0.113.20",
    "rdns": "mail.example.com",
    "description": "Game server",
    "protection": {
      "layer4": "dynamic",
      "layer7": "off"
    },
    "editable": {
      "rdns": true,
      "description": true,
      "protection": true
    }
  }
}

Get traffic

GET/servers/{serverId}/traffic

Scope network:read

Dedicated servers return the last 24 hours of port rates in Mbps (kind: rates). VPS servers return transfer per billing month (kind: monthly).

Parameters

serverId path · required
string

Server id from GET /servers, e.g. vps_1_4021 or ded_<uuid>.

Response 200

One of · 1
kind
string

rates

from
string

ISO 8601 timestamp.

to
string

ISO 8601 timestamp.

totals
object or null

Transfer volume over the window.

totals.incomingGb
number
totals.outgoingGb
number
interfaces
object[]
interfaces.incoming
object[]
interfaces.incoming.time
string

ISO 8601 timestamp.

interfaces.incoming.mbps
number
interfaces.outgoing
object[]
interfaces.outgoing.time
string

ISO 8601 timestamp.

interfaces.outgoing.mbps
number
One of · 2
kind
string

monthly

months
object[]
months.start
string

ISO 8601 timestamp.

months.end
string

ISO 8601 timestamp.

months.rxBytes
number
months.txBytes
number
months.totalBytes
number
months.limitGb
number or null

Errors

400 401 403 404 429 503

curl -X GET "https://api.snghosting.com/api/v1/servers/vps_1_4021/traffic" \
  -H "Authorization: Bearer $SNG_API_TOKEN"
Example response
{
  "data": {
    "kind": "rates",
    "from": "string",
    "to": "string",
    "totals": {
      "incomingGb": 0,
      "outgoingGb": 0
    },
    "interfaces": [
      {
        "incoming": [
          {
            "time": "string",
            "mbps": 0
          }
        ],
        "outgoing": [
          {
            "time": "string",
            "mbps": 0
          }
        ]
      }
    ]
  }
}

DDoS protection

Get DDoS protection and attacks

GET/servers/{serverId}/ddos

Scope network:read

Protection status and recent attacks for one address of the server (the primary address by default).

Parameters

serverId path · required
string

Server id from GET /servers, e.g. vps_1_4021 or ded_<uuid>.

ip query
string · ipv4

Address to inspect.

Response 200

address
string or null
status
string

protected unavailable

incidents
object[]
incidents.id
string
incidents.startedAt
string

ISO 8601 timestamp.

incidents.endedAt
string or null

ISO 8601 timestamp.

incidents.durationSeconds
number or null
incidents.peak
string or null

Peak attack rate, e.g. 12.4 Gbps.

incidents.attackTypes
string[]
totalIncidents
integer
addresses
string[]

Every address of the server you can query with ip.

Errors

400 401 403 404 429 503

curl -X GET "https://api.snghosting.com/api/v1/servers/vps_1_4021/ddos" \
  -H "Authorization: Bearer $SNG_API_TOKEN"
Example response
{
  "data": {
    "address": "203.0.113.20",
    "status": "protected",
    "incidents": [
      {
        "id": "vps_1_4021",
        "startedAt": "2026-10-07T12:00:00.000Z",
        "endedAt": null,
        "durationSeconds": null,
        "peak": "12.4 Gbps",
        "attackTypes": [
          "string"
        ]
      }
    ],
    "totalIncidents": 0,
    "addresses": [
      "string"
    ]
  }
}

List DDoS filter rules

GET/servers/{serverId}/ips/{ip}/ddos/rules

Scope network:read

Filter rules applied to one address of a dedicated server.

Parameters

serverId path · required
string

Server id from GET /servers, e.g. vps_1_4021 or ded_<uuid>.

ip path · required
string · ipv4

An IPv4 address assigned to the server.

Response 200

address
string
available
boolean
rules
object[]
rules.protocol
string
rules.port
number
rules.state
string

Errors

400 401 403 404 429 503

curl -X GET "https://api.snghosting.com/api/v1/servers/ded_6a4b2a40-6d0e-4c1b-9c1d-1c7c8f3f0a11/ips/203.0.113.20/ddos/rules" \
  -H "Authorization: Bearer $SNG_API_TOKEN"
Example response
{
  "data": {
    "address": "203.0.113.20",
    "available": true,
    "rules": [
      {
        "protocol": "tcp",
        "port": 30120,
        "state": "string"
      }
    ]
  }
}

Firewall

List firewall rule sets

GET/firewall/rulesets

Scope network:read

Rule sets that can be applied to a VPS firewall.

Response 200

id
integer
name
string

Errors

400 401 403 404 429

curl -X GET "https://api.snghosting.com/api/v1/firewall/rulesets" \
  -H "Authorization: Bearer $SNG_API_TOKEN"
Example response
{
  "data": [
    {
      "id": 0,
      "name": "game-01"
    }
  ]
}

Get the VPS firewall

GET/servers/{serverId}/firewall

Scope network:read

Parameters

serverId path · required
string

Server id from GET /servers, e.g. vps_1_4021 or ded_<uuid>.

Response 200

enabled
boolean
rulesets
integer[]

Ids of the applied rule sets.

Errors

400 401 403 404 429

curl -X GET "https://api.snghosting.com/api/v1/servers/vps_1_4021/firewall" \
  -H "Authorization: Bearer $SNG_API_TOKEN"
Example response
{
  "data": {
    "enabled": true,
    "rulesets": [
      0
    ]
  }
}

Change the VPS firewall

PUT/servers/{serverId}/firewall

Scope network:write

Turn the firewall on or off and choose which rule sets apply.

Parameters

serverId path · required
string

Server id from GET /servers, e.g. vps_1_4021 or ded_<uuid>.

Idempotency-Key header · required
string

A unique value per intended action (8–128 characters). Repeating a request with the same key returns the first result instead of running the action again.

Request body

enabled optional
boolean
rulesets optional
integer[]

Response 200

enabled
boolean
rulesets
integer[]

Ids of the applied rule sets.

Errors

400 401 403 404 409 422 429

curl -X PUT "https://api.snghosting.com/api/v1/servers/vps_1_4021/firewall" \
  -H "Authorization: Bearer $SNG_API_TOKEN" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{"enabled":true,"rulesets":[3]}'
Example response
{
  "data": {
    "enabled": true,
    "rulesets": [
      0
    ]
  }
}

Try it with your token