# Storiza Docs > Guides and API reference for Storiza: VPS servers, game servers, databases and bots. - [What is Storiza?](https://docs.storiza.store/index.md): Cloud servers, game servers, databases and bots — run from one dashboard, one API and one balance. - [Quickstart](https://docs.storiza.store/quickstart.md): From a new account to your first API call in five minutes. - [API keys](https://docs.storiza.store/authentication.md): Create a key, give it only the permissions it needs, and keep it safe. - [Responses and errors](https://docs.storiza.store/concepts/responses-and-errors.md): One envelope for every answer, and a stable code on every error. - [Pagination and filtering](https://docs.storiza.store/concepts/pagination-and-filtering.md): Page through lists, search them, sort them and filter them. - [Billing and payments](https://docs.storiza.store/concepts/billing-and-payments.md): Balance, subscriptions, orders and checkouts — how money moves when you use the API. - [Deploy a VPS](https://docs.storiza.store/guides/deploy-a-vps.md): Choose a plan, a region and an operating system, create the server, and manage it. - [Deploy an app](https://docs.storiza.store/guides/deploy-an-app.md): Run a game server, a database or a bot from a template — no machine to manage. - [App files, logs and commands](https://docs.storiza.store/guides/app-files-and-console.md): Read and write an app's files, read its output, and run commands inside it. - [Consoles and live streams](https://docs.storiza.store/guides/realtime.md): Terminals, live app output, live metrics and collaborative editing over WebSockets and server-sent events. - [Connect an AI agent](https://docs.storiza.store/guides/ai-agents.md): Let Claude, ChatGPT, Cursor or any MCP client look after your servers — with your approval for every change. - [Getting help](https://docs.storiza.store/guides/support.md): Open a ticket from the dashboard, by email or through the API. - [API overview](https://docs.storiza.store/api-reference/introduction.md): Base URL, authentication and conventions shared by every endpoint. - [Get a list of all VPS instances](https://docs.storiza.store/api-reference/servers/get-a-list-of-all-vps-instances.md): Lists the VPS instances visible to the current actor: a user sees the VPS they own, a reseller sub-account sees only the VPS assigned to it. Supports pagination, search (name, hostname, and IP address) and sorting. - [Create a new VPS instance](https://docs.storiza.store/api-reference/servers/create-a-new-vps-instance.md): Creates a VPS for the authenticated user: validates the datacenter/plan/template, enforces trial-account limits, charges the user's balance for the requested duration, creates the VPS record and queues the provisioning job. - [Renew a VPS for another period now](https://docs.storiza.store/api-reference/servers/renew-a-vps-for-another-period-now.md): Pays for the next period of this server's subscription — or its backup add-on, with `target: "backup"` — without waiting for the automatic renewal. - [Move a VPS to a larger plan, charging the prorated difference](https://docs.storiza.store/api-reference/servers/move-a-vps-to-a-larger-plan-charging-the-prorated-difference.md): Charges the difference between the current plan and the new one for the days remaining in the current period, then resizes the machine and re-prices future renewals. - [Get VPS instance information by ID](https://docs.storiza.store/api-reference/servers/get-vps-instance-information-by-id.md): Returns the VPS record (including its plan, template, datacenter, IP and owner). If the VPS is not yet active, ensures a creation job exists and is progressing (recreating or retrying it when stuck). Supports session auth and shareToken auth. - [Update VPS instance by ID](https://docs.storiza.store/api-reference/servers/update-vps-instance-by-id.md): Updates the name and/or description of an active VPS owned by the authenticated user (admins may update any VPS). The change is recorded in the audit log. - [Delete a VPS instance](https://docs.storiza.store/api-reference/servers/delete-a-vps-instance.md): Marks the VPS for deletion (deallocating resources) and queues the deletion job. Owners can delete their own VPS; admins can delete any. - [Order a VPS and pay for it externally](https://docs.storiza.store/api-reference/servers/order-a-vps-and-pay-for-it-externally.md): Raises a transaction for a new VPS and returns where to pay it. **No server is created here** — the whole request is stored on the transaction and built only once the payment settles, so an abandoned checkout leaves nothing behind. - [Run a shell command inside a VPS via the QEMU guest agent](https://docs.storiza.store/api-reference/server-power-&-commands/run-a-shell-command-inside-a-vps-via-the-qemu-guest-agent.md): Runs one command inside the guest as root and waits for it to finish, returning stdout and the exit code. Goes through the QEMU guest agent, not SSH, so it works without network access to the VPS — but it needs the agent to be installed and answering, which it will not be while the machine is still… - [Force stop (kill) a VPS instance by ID. Use only when normal stop doesn't work](https://docs.storiza.store/api-reference/server-power-&-commands/force-stop-kill-a-vps-instance-by-id-use-only-when-normal-stop-doesnt-work.md): Force-stops (kills) an active, non-suspended VPS. Supports session auth and shareToken auth; the action is audit-logged for session actors. - [Reboot VPS instance by ID](https://docs.storiza.store/api-reference/server-power-&-commands/reboot-vps-instance-by-id.md): Reboots an active, non-suspended VPS. Supports session auth and shareToken auth; the action is audit-logged for session actors. - [Start a VPS instance by ID](https://docs.storiza.store/api-reference/server-power-&-commands/start-a-vps-instance-by-id.md): Starts an active, non-suspended, non-expired VPS. Supports session auth and shareToken auth; the action is audit-logged for session actors. - [Get real-time VPS status from Proxmox](https://docs.storiza.store/api-reference/server-power-&-commands/get-real-time-vps-status-from-proxmox.md): Returns the live resource usage (CPU, memory, disk, network) of an active VPS from the hypervisor. For inactive VPS, or when the hypervisor is unreachable, `resources` is null and `isActive` is false. Supports session auth and shareToken auth. - [Stop a VPS instance by ID](https://docs.storiza.store/api-reference/server-power-&-commands/stop-a-vps-instance-by-id.md): Gracefully stops an active, non-suspended VPS. Supports session auth and shareToken auth; the action is audit-logged for session actors. - [Rename a VPS or edit its description](https://docs.storiza.store/api-reference/server-settings/rename-a-vps-or-edit-its-description.md): Updates the display name and/or description. These are labels stored by us -- nothing on the machine changes, so no restart or reinstall is involved. The hostname is not editable here: it is written into the image at build time, so changing it means a reinstall. - [Get the progress of the template's install script](https://docs.storiza.store/api-reference/server-settings/get-the-progress-of-the-templates-install-script.md): Reports how far the template's provisioning script has got inside the guest. `provision` is null when the template installs nothing, which is what tells a client not to show progress at all. - [Reinstall VPS instance by ID](https://docs.storiza.store/api-reference/server-settings/reinstall-vps-instance-by-id.md): Reinstalls the VPS operating system, optionally switching template, image version, template inputs and login credentials. This is the only way to change them: they are applied while the image is being built, so an existing server cannot adopt a new set without being rebuilt. - [Get the firewall configuration for a VPS instance](https://docs.storiza.store/api-reference/server-firewall/get-the-firewall-configuration-for-a-vps-instance.md): Reads the VPS firewall state live from the hypervisor: whether the firewall is enabled, the default inbound/outbound policies, and the list of rules. Accessible to the VPS owner, an admin, or a reseller sub-account the VPS is assigned to. - [Update firewall options for a VPS instance](https://docs.storiza.store/api-reference/server-firewall/update-firewall-options-for-a-vps-instance.md): Toggles the firewall on/off and/or updates the default inbound and outbound policies. Any policy left out of the body keeps its current value. Returns the options that were submitted. - [Add a new firewall rule to a VPS instance](https://docs.storiza.store/api-reference/server-firewall/add-a-new-firewall-rule-to-a-vps-instance.md): Validates and appends a firewall rule to the VPS. Inbound rules may not carry a destination and outbound rules may not carry a source; ports must be a number, a range, or `all`, and source/destination must be an IPv4 address, a CIDR, or `all`. Returns the rule as it was stored. - [Update an existing firewall rule for a VPS instance](https://docs.storiza.store/api-reference/server-firewall/update-an-existing-firewall-rule-for-a-vps-instance.md): Applies a partial update to the firewall rule at the given position; omitted fields keep their current value. Inbound rules may not carry a destination and outbound rules may not carry a source; ports must be a number, a range, or `all`, and source/destination must be an IPv4 address, a CIDR, or `al… - [Delete a firewall rule from a VPS instance](https://docs.storiza.store/api-reference/server-firewall/delete-a-firewall-rule-from-a-vps-instance.md): Removes the firewall rule at the given position from the VPS. Rule positions shift after a delete, so re-read the configuration before deleting another rule. - [Apply a predefined firewall template to a VPS instance](https://docs.storiza.store/api-reference/server-firewall/apply-a-predefined-firewall-template-to-a-vps-instance.md): Replaces the VPS firewall rules with a predefined set. All existing rules are removed first, then the template's rules are added. Returns the applied template, its description, and the rules it installed. - [Enable or disable the firewall for a VPS instance](https://docs.storiza.store/api-reference/server-firewall/enable-or-disable-the-firewall-for-a-vps-instance.md): Turns the VPS firewall on or off without touching its rules. Returns the resulting state along with a warning describing the risk of the new state. - [Get available firewall service presets (SSH, HTTP, HTTPS, etc.)](https://docs.storiza.store/api-reference/server-firewall/get-available-firewall-service-presets-ssh-http-https-etc.md): Returns the static catalogue of common service presets (name, protocol, port, description) that clients can use to pre-fill a firewall rule form. The data is the same for every VPS; any authenticated actor (user or reseller sub-account) may read it. - [Get current resource usage alerts for a VPS](https://docs.storiza.store/api-reference/server-metrics/get-current-resource-usage-alerts-for-a-vps.md): Evaluates the VPS's live CPU, memory and disk usage against warning/critical thresholds and returns only the alerts that are currently firing, plus a meta block with the alert count and whether any warnings or critical alerts are present. - [Get real-time metrics for a VPS](https://docs.storiza.store/api-reference/server-metrics/get-real-time-metrics-for-a-vps.md): Reads the VPS's live CPU, memory, disk and network usage from the hypervisor (VM status, config and the latest RRD sample) and returns it together with the VM's power status and uptime. - [Get historical metrics data for a VPS over a specified timeframe](https://docs.storiza.store/api-reference/server-metrics/get-historical-metrics-data-for-a-vps-over-a-specified-timeframe.md): Returns the VPS's RRD time series (CPU, memory, disk and network counters) for the requested timeframe. When `points` is supplied the series is down-sampled to at most that many samples. The meta block echoes the timeframe, the number of samples returned and the number requested. - [Get comprehensive metrics overview including current metrics, alerts, and quick summary](https://docs.storiza.store/api-reference/server-metrics/get-comprehensive-metrics-overview-including-current-metrics-alerts-and-quick-summary.md): Fetches the VPS's current metrics, its firing resource alerts and a one-day aggregate summary in parallel, and returns them under a single `overview` object plus a meta block with the response timestamp and alert counters. - [Get aggregated metrics summary for a VPS over a specified period](https://docs.storiza.store/api-reference/server-metrics/get-aggregated-metrics-summary-for-a-vps-over-a-specified-period.md): Aggregates the VPS's historical metrics over the requested number of days into averages, peaks, total network transfer and uptime percentage, alongside a meta block echoing the period. All values are zero when no data points are available. - [Order a backup plan for a VPS](https://docs.storiza.store/api-reference/server-backups/order-a-backup-plan-for-a-vps.md): Raises a transaction that attaches a backup plan to this VPS once paid. Through the `balance` method the plan activates immediately; through an external method the response carries a `checkoutUrl` to pay at, and the plan activates when the payment settles. - [List all backups for a VPS](https://docs.storiza.store/api-reference/server-backups/list-all-backups-for-a-vps.md): Lists the backups of a VPS with pagination, search (name, description) and sorting. While listing, backups stuck in `creating` for over 30 minutes are reconciled against the hypervisor and missing backup sizes are fetched from the hypervisor storage. - [Create a backup of a VPS](https://docs.storiza.store/api-reference/server-backups/create-a-backup-of-a-vps.md): Queues the backup job for the VPS and returns the newly created backup record in `creating` state. Admins may back up any VPS; other users only their own. - [Get details of a specific backup](https://docs.storiza.store/api-reference/server-backups/get-details-of-a-specific-backup.md): Returns a single backup belonging to the given VPS. Admins may read any VPS's backups; other users only their own. - [Delete a backup](https://docs.storiza.store/api-reference/server-backups/delete-a-backup.md): Queues a deletion job that removes the backup from storage. Backups still being created (pending/creating) cannot be deleted. - [Check and update backup status from Proxmox](https://docs.storiza.store/api-reference/server-backups/check-and-update-backup-status-from-proxmox.md): Reads the task status of a pending/creating backup and reconciles the stored backup record (completed, failed, or still running), pulling the backup size from storage when it completed. Backups already in a final status are returned unchanged. - [List all snapshots for a VPS](https://docs.storiza.store/api-reference/server-snapshots/list-all-snapshots-for-a-vps.md): Lists the snapshots of a VPS owned by the current user (admins may list any VPS's snapshots). Supports pagination, search (name, description) and sorting. - [Create a snapshot of a VPS](https://docs.storiza.store/api-reference/server-snapshots/create-a-snapshot-of-a-vps.md): Starts an asynchronous snapshot of a VPS owned by the current user (admins may snapshot any VPS) and returns the newly created snapshot record with status `creating`. - [Get details of a specific snapshot](https://docs.storiza.store/api-reference/server-snapshots/get-details-of-a-specific-snapshot.md): Returns a single snapshot belonging to a VPS owned by the current user (admins may read any VPS's snapshots). - [Delete a snapshot](https://docs.storiza.store/api-reference/server-snapshots/delete-a-snapshot.md): Deletes a snapshot record of a VPS owned by the current user (admins may delete any). Snapshots that are still pending or being created cannot be deleted. - [Get the current share token for a VPS](https://docs.storiza.store/api-reference/server-sharing/get-the-current-share-token-for-a-vps.md): Returns the share token currently set on a VPS the caller owns (admins may target any VPS), or null when no token has been generated. - [Generate or regenerate a share token for VPS access](https://docs.storiza.store/api-reference/server-sharing/generate-or-regenerate-a-share-token-for-vps-access.md): Generates a fresh share token for a VPS the caller owns (admins may target any VPS), replacing any previous token. The VPS must have an IP address assigned. - [Get VPS members](https://docs.storiza.store/api-reference/server-sharing/get-vps-members.md): Get list of all managed users who are members of a VPS. Supports pagination, search (username, email, first and last name) and sorting. - [Add a managed user to VPS](https://docs.storiza.store/api-reference/server-sharing/add-a-managed-user-to-vps.md): Add a managed user to a VPS instance as a member - [Remove a managed user from VPS](https://docs.storiza.store/api-reference/server-sharing/remove-a-managed-user-from-vps.md): Remove a managed user from a VPS instance - [Validate a share token and get the associated VPS ID](https://docs.storiza.store/api-reference/server-sharing/validate-a-share-token-and-get-the-associated-vps-id.md): Public endpoint: exchanges a share token for the basic public details of the VPS it points at (id, name, hostname, status, datacenter, plan and template names). No session is required. - [List available VPS backup plan configurations](https://docs.storiza.store/api-reference/server-catalog/list-available-vps-backup-plan-configurations.md): Lists VPS backup plans, cheapest first, together with a per-frequency grouping and summary statistics for the returned page. Pass `frequency`, `isActive`, `minPrice` and/or `maxPrice` to narrow the result, plus the standard filtering query parameters (`_page`, `_limit`, `_search`, `_sort_by`). - [Get VPS backup plan configuration details](https://docs.storiza.store/api-reference/server-catalog/get-vps-backup-plan-configuration-details.md): Returns the schedule, retention limits and pricing of a single VPS backup plan. - [List the VPS plan categories with their hardware and datacenters](https://docs.storiza.store/api-reference/server-catalog/list-the-vps-plan-categories-with-their-hardware-and-datacenters.md): Lists the visible VPS plan categories, highest priority first. Each carries its hardware `specifications`, the datacenter names its plans can be built in (`supportedDatacenters`) and whether it still takes new orders (`allowNewOrders` — a category that does not only renews existing servers). Plans l… - [List VPS active datacenters](https://docs.storiza.store/api-reference/server-catalog/list-vps-active-datacenters.md): Lists the active VPS datacenters, highest priority first. Pass `includeInactive=true` to include disabled ones, plus the standard filtering query parameters (`_page`, `_limit`, `_search`, `_sort_by`). - [Get a specific VPS datacenter](https://docs.storiza.store/api-reference/server-catalog/get-a-specific-vps-datacenter.md): Returns the public details of a single VPS datacenter (name, region, location, features and availability flags). - [Get VPS plan configuration](https://docs.storiza.store/api-reference/server-catalog/get-vps-plan-configuration.md): Returns the resources, pricing and feature list of a single VPS plan. - [List VPS plans available for public viewing (no authentication required)](https://docs.storiza.store/api-reference/server-catalog/list-vps-plans-available-for-public-viewing-no-authentication-required.md): Lists the enabled, non-hidden VPS plans, cheapest first. Pass `categoryId` or `category` (a category slug, see `GET /vps-categories`; `all` means no filter) to narrow to one category. Supports the standard filtering query parameters (`_page`, `_limit`, `_search`, `_sort_by`). - [List VPS creation templates configurations](https://docs.storiza.store/api-reference/server-catalog/list-vps-creation-templates-configurations.md): Returns every VPS OS template in one response, ordered by `sortOrder`. There is no pagination and no filtering: the catalogue is small and the creation wizard needs all of it at once, so it is fetched once and narrowed in the client. - [List apps](https://docs.storiza.store/api-reference/apps/list-apps.md): List apps. You see the ones you own; admins see every app. - [Create an app, paid from balance](https://docs.storiza.store/api-reference/apps/create-an-app-paid-from-balance.md): Provision an app on a node and charge the account balance for it: reserve its ports, create its ZFS volume with the plan's storage quota, create its private network and register its managed domain. This is the counterpart to `POST /apps/order`, which raises a transaction to be paid externally and bu… - [Get an app](https://docs.storiza.store/api-reference/apps/get-an-app.md): Get one app, including its live container status as reported by the node. If the node is unreachable the desired state is still returned — an outage must not look like a missing app. - [Rename an app](https://docs.storiza.store/api-reference/apps/rename-an-app.md): Rename an app or change its description. Nothing here touches the running container. - [Delete an app](https://docs.storiza.store/api-reference/apps/delete-an-app.md): Delete an app and everything it owns: its container, its private network, its ZFS volume AND ALL THE DATA IN IT, its reserved ports and its domains. Irreversible — take a backup first if the volume matters. - [Set the start command](https://docs.storiza.store/api-reference/apps/set-the-start-command.md): Replace the command the container starts with, or send `null` to go back to the template's. - [Preview a start command](https://docs.storiza.store/api-reference/apps/preview-a-start-command.md): Resolve a draft start command against the app's real environment, without saving or restarting anything. - [Set environment variables](https://docs.storiza.store/api-reference/apps/set-environment-variables.md): Replace the app's environment variables. The body is the complete set — a key you leave out is removed. - [Reinstall onto another template or version](https://docs.storiza.store/api-reference/apps/reinstall-onto-another-template-or-version.md): Move the app onto a different template or version. - [Buy the next period for an app](https://docs.storiza.store/api-reference/apps/buy-the-next-period-for-an-app.md): Extends the app's subscription by one more period, priced from its plan by the same duration rules the original order used. Paying from balance settles immediately; any other method returns a checkout to complete. - [Order an app and pay for it externally](https://docs.storiza.store/api-reference/apps/order-an-app-and-pay-for-it-externally.md): Raises a transaction for a new app and returns where to pay it. **No app is created here** — the whole request is stored on the transaction and built only once the payment settles, so an abandoned checkout leaves nothing behind. - [Run a command in the container](https://docs.storiza.store/api-reference/app-lifecycle-&-console/run-a-command-in-the-container.md): Run a command inside the running container and wait for it to finish. - [Kill an app's process](https://docs.storiza.store/api-reference/app-lifecycle-&-console/kill-an-apps-process.md): Sends a signal to the container and **leaves it in place** so it can be inspected afterwards. This is not a state change: the app is still RUNNING as far as its desired state is concerned, and the container still exists. Use stop to remove it. - [Restart an app](https://docs.storiza.store/api-reference/app-lifecycle-&-console/restart-an-app.md): Stop then start, going through exactly the same path as any other start — there is no separate restart route through the agent. It therefore re-resolves the image tag and rebuilds the container from stored rows, which is the point: a restart can never produce a container that a fresh start would not… - [Start an app](https://docs.storiza.store/api-reference/app-lifecycle-&-console/start-an-app.md): Creates the container and runs it. The image tag is resolved fresh here, so a start can pick up a newer image than the last one did — pinning a version is the defence against that, not a substitute for it. - [Stop an app](https://docs.storiza.store/api-reference/app-lifecycle-&-console/stop-an-app.md): **Deletes the container.** Only the volume survives — anything written outside the mount point is gone, because start recreates the container from stored rows rather than resuming the old one. Deliberate (R21): it is what makes a start reproducible. - [Read the container's logs](https://docs.storiza.store/api-reference/app-lifecycle-&-console/read-the-containers-logs.md): The container's recent output, as text. - [Get an app's metrics](https://docs.storiza.store/api-reference/app-lifecycle-&-console/get-an-apps-metrics.md): CPU, memory, network and disk over one window, in one response. The four windows are the retention tiers: hour (1-minute points), day (5-minute), week (1-hour) and month (6-hour). Nothing is aggregated here — the node's Netdata already stores each resolution, and the window picks which tier answers. - [Send a line to the console](https://docs.storiza.store/api-reference/app-lifecycle-&-console/send-a-line-to-the-console.md): Write one line to the container's stdin — the app's own console. - [List files](https://docs.storiza.store/api-reference/app-files/list-files.md): List a directory in the app's volume. Paths are relative to the volume root; the node's agent confines every path to this app's dataset, so `..` cannot reach another app. - [Delete a file](https://docs.storiza.store/api-reference/app-files/delete-a-file.md): Delete a file, or a directory with `recursive`. There is no undo and no trash: the volume is the only copy unless a backup was taken. - [Read a file](https://docs.storiza.store/api-reference/app-files/read-a-file.md): Download a file from the app's volume. `offset` and `length` request a byte range, so a client can seek into a large file instead of transferring the whole thing — this is the fast channel SFTP was rejected for. - [Write a file](https://docs.storiza.store/api-reference/app-files/write-a-file.md): Replace a file in the app's volume, creating it if it does not exist. Send `base64` for anything that is not text — a binary body through a JSON string is not round-trippable as utf8. - [Copy a file](https://docs.storiza.store/api-reference/app-files/copy-a-file.md): Copy a file or directory within the app's volume. The copy counts against the same dataset quota, so a copy can fail on space where the original fit. - [Create a directory](https://docs.storiza.store/api-reference/app-files/create-a-directory.md): Create a directory in the app's volume, including any missing parents. - [Move or rename a file](https://docs.storiza.store/api-reference/app-files/move-or-rename-a-file.md): Move or rename a file or directory within the app's volume. Both paths are confined to this app's dataset by the node's agent, so neither side can reach another app. - [Read a file as text](https://docs.storiza.store/api-reference/app-files/read-a-file-as-text.md): A file's contents as text, inside the normal response envelope. - [Get SFTP credentials](https://docs.storiza.store/api-reference/app-files/get-sftp-credentials.md): The app's SFTP username, password, host and port. Returns `password: null` when SFTP is disabled for the app — enable it to mint one. - [Disable SFTP for an app](https://docs.storiza.store/api-reference/app-files/disable-sftp-for-an-app.md): Turn SFTP off for this app. The password is cleared, not merely deactivated, so an operator with a copy of the database cannot reactivate an old credential — enabling again mints a fresh one. - [Enable SFTP for an app](https://docs.storiza.store/api-reference/app-files/enable-sftp-for-an-app.md): Turn SFTP on for this app, generating a password if it does not already have one. Re-enabling an app that was disabled gives it a **new** password — the old one was revoked when it was disabled, and handing the same credential back would make disabling meaningless. - [Regenerate the SFTP password](https://docs.storiza.store/api-reference/app-files/regenerate-the-sftp-password.md): Replace the app's SFTP password with a new one, revoking the old immediately. The username never changes — it is fixed for the app's life, so anything referencing it keeps working with the new password. - [List backups](https://docs.storiza.store/api-reference/app-backups/list-backups.md): List an app's backups, newest first. - [Back up an app](https://docs.storiza.store/api-reference/app-backups/back-up-an-app.md): Archive the app's volume and upload it to a backup center. A center is chosen by capacity and round-robin so backups spread across centers instead of filling the first. The archive streams from the node straight to the center — it is never staged on the control plane. Returns immediately; poll the b… - [Delete a backup](https://docs.storiza.store/api-reference/app-backups/delete-a-backup.md): Delete a backup and its stored archive. The object goes first: a row without its archive is a backup that cannot be restored, while an archive without a row is only wasted space a later sweep can find. - [Download a backup](https://docs.storiza.store/api-reference/app-backups/download-a-backup.md): Get a short-lived presigned URL for the backup archive. The client downloads straight from the backup center's object store, so the archive never passes through the control plane. The URL expires in 15 minutes. - [List restores](https://docs.storiza.store/api-reference/app-backups/list-restores.md): List this app's restores, newest first. - [Restore an app from a backup](https://docs.storiza.store/api-reference/app-backups/restore-an-app-from-a-backup.md): Restore the app's volume from one of its backups. THE VOLUME'S CURRENT CONTENTS ARE REPLACED. The app is stopped first — extracting under a running container would hand it a filesystem changing beneath it — and started again afterwards. Extraction stages on the node and swaps in only on success, so… - [List exposures](https://docs.storiza.store/api-reference/app-domains-&-ports/list-exposures.md): Every way into the app — the hostnames it answers on and the ports published on its node. - [Add a custom domain](https://docs.storiza.store/api-reference/app-domains-&-ports/add-a-custom-domain.md): Point a domain you own at this app. - [Enable or disable an exposure](https://docs.storiza.store/api-reference/app-domains-&-ports/enable-or-disable-an-exposure.md): Turn one way into the app on or off. - [Delete an exposure](https://docs.storiza.store/api-reference/app-domains-&-ports/delete-an-exposure.md): Remove a domain you added. - [Verify a domain](https://docs.storiza.store/api-reference/app-domains-&-ports/verify-a-domain.md): Check a domain's DNS now, rather than waiting for the five-minute pass. - [List groups](https://docs.storiza.store/api-reference/app-groups/list-groups.md): List groups, filterable by node. You see the ones you own; admins see every group. - [Create a group](https://docs.storiza.store/api-reference/app-groups/create-a-group.md): Create a group. Apps in a group reach each other by hostname over a shared Docker network, which is why a group belongs to ONE node — a bridge network exists on one machine, so apps on different nodes cannot be grouped. TENANT keys create within their own tenant; ADMIN keys must pass ownerId. - [Get a group](https://docs.storiza.store/api-reference/app-groups/get-a-group.md): Get a group by id. TENANT keys only reach their own tenant's groups; a foreign id is reported as 404. - [Update a group](https://docs.storiza.store/api-reference/app-groups/update-a-group.md): Update a group's name. Tenant and cluster are immutable (changing them would strand the group's NetworkPolicy). - [Delete a group](https://docs.storiza.store/api-reference/app-groups/delete-a-group.md): Delete a group. - [List a group's apps](https://docs.storiza.store/api-reference/app-groups/list-a-groups-apps.md): The apps joined to this group. Members of a group share a Docker bridge network and can reach each other by hostname, which is why they must all sit on the same node. - [Get the app's group and its peers](https://docs.storiza.store/api-reference/app-groups/get-the-apps-group-and-its-peers.md): The group this app belongs to, and every other app in it. - [Join or leave a group](https://docs.storiza.store/api-reference/app-groups/join-or-leave-a-group.md): Join a group, move between groups, or leave one by sending `groupId: null`. - [List nodes](https://docs.storiza.store/api-reference/app-catalog/list-nodes.md): The nodes an app can be placed on, with their location and measured capacity. - [Get a node](https://docs.storiza.store/api-reference/app-catalog/get-a-node.md): One node: its location, measured capacity and whether it is accepting apps. Any signed-in user may read this — picking a node is part of creating an app. Connection details are never included for them; customers reach a node at its `fqdn`. Admins additionally get the address, SSH details and install… - [Get a node's capacity](https://docs.storiza.store/api-reference/app-catalog/get-a-nodes-capacity.md): What the node has, what it keeps for itself, and what is already promised to apps. - [Check a node's health](https://docs.storiza.store/api-reference/app-catalog/check-a-nodes-health.md): Asks the node itself, live — nothing here is read from the database. Each of the seven units is checked independently and reports what it found, so a node with a dead files API still tells you its Docker and ZFS state. - [List app plans](https://docs.storiza.store/api-reference/app-catalog/list-app-plans.md): The plans an app can be created on. Public and unauthenticated, so a pricing page renders before sign-in, and returned in full rather than paged — the catalog is small and meant to be narrowed in the client. Pass `?type=` to get only the plans valid for one kind of app; a plan and the template besid… - [List app templates](https://docs.storiza.store/api-reference/app-catalog/list-app-templates.md): Every deployable application shape. Public and unauthenticated, and returned in full rather than paged — the catalog is small and meant to be narrowed in the client. Pass `?type=` to get only the templates valid for one kind of app; a template and the plan beside it must always agree on type. Each t… - [List the caller's subscriptions](https://docs.storiza.store/api-reference/subscriptions/list-the-callers-subscriptions.md): Every recurring commitment on the account. Read straight from the database — use `GET /payments/subscriptions/:id` to pull the provider's current view of one. - [Get one subscription, synced with the provider](https://docs.storiza.store/api-reference/subscriptions/get-one-subscription-synced-with-the-provider.md): Fetches the subscription and pulls the provider's current view onto it. Status, period end, price and whether it is set to cancel all come from the provider, which is the source of truth. - [Undo a cancellation before the subscription expires](https://docs.storiza.store/api-reference/subscriptions/undo-a-cancellation-before-the-subscription-expires.md): Reactivates a subscription that was cancelled while its paid period is still running. Once the period has passed there is nothing to resume — subscribe again instead. - [Cancel a subscription at the end of its paid period](https://docs.storiza.store/api-reference/subscriptions/cancel-a-subscription-at-the-end-of-its-paid-period.md): Stops the subscription renewing. The row is kept and access runs to the end of the period already paid for, so this stays reversible with `POST /payments/subscriptions/:id` until it expires. There is no immediate revocation — the paid period always runs out. - [Get the provider's management URL for a subscription](https://docs.storiza.store/api-reference/subscriptions/get-the-providers-management-url-for-a-subscription.md): Returns a short-lived URL into the payment provider's own portal, where the customer changes their payment method, switches plan or cancels. Changes come back as webhooks. - [Start a checkout that replaces a subscription's saved card](https://docs.storiza.store/api-reference/subscriptions/start-a-checkout-that-replaces-a-subscriptions-saved-card.md): Raises a checkout whose only purpose is to put a new card on file for this subscription. Send the customer to `checkoutUrl`, or embed `iframeUrl` when `supportsIframes` is true. - [Change how long each renewal of a subscription lasts](https://docs.storiza.store/api-reference/subscriptions/change-how-long-each-renewal-of-a-subscription-lasts.md): Sets the billing period the subscription renews for from its next renewal on — one of 7, 14, 30, 90 days — and re-prices it from the plan's current price for that period (short periods carry the usual short-term fee). The current period is untouched: it ends when it was going to, nothing is charged… - [List the caller's transactions](https://docs.storiza.store/api-reference/transactions-&-invoices/list-the-callers-transactions.md): Every movement of money on the account, newest first. Read straight from the database — nothing is synced with the provider here, so this stays fast. Use `GET /payments/transactions/:id` when you need the provider's current view of one. - [Get one transaction, synced with the provider](https://docs.storiza.store/api-reference/transactions-&-invoices/get-one-transaction-synced-with-the-provider.md): Fetches the transaction and pulls the provider's current view onto it — status, checkout link and iframe all come from the provider, which is the source of truth. Anything the payment unlocked is provisioned as part of the sync, so a missed webhook is repaired just by opening the transaction. - [Get the payment link and iframe for an unpaid transaction again](https://docs.storiza.store/api-reference/transactions-&-invoices/get-the-payment-link-and-iframe-for-an-unpaid-transaction-again.md): Syncs with the provider first, so a transaction that was already paid settles here instead of being offered for payment twice. Returns the checkout link and, when the provider supports embedding, an iframe URL. - [Cancel an unpaid transaction](https://docs.storiza.store/api-reference/transactions-&-invoices/cancel-an-unpaid-transaction.md): Marks the transaction cancelled and withdraws its payment link. The row is kept — a cancelled payment is still part of the account's history. - [Download the invoice for a transaction](https://docs.storiza.store/api-reference/transactions-&-invoices/download-the-invoice-for-a-transaction.md): Streams the invoice file itself, not a link to it. When the provider issued its own invoice — Polar's PDF, for instance — that file is streamed straight through. Otherwise one is generated from the transaction and streamed instead, so balance and gift card payments still produce a document. - [Cheap status check, safe to poll](https://docs.storiza.store/api-reference/transactions-&-invoices/cheap-status-check-safe-to-poll.md): Returns just enough to know whether a payment has landed. Built for polling while a customer is at the provider's checkout — poll this, not the detail endpoint. - [Check a coupon and preview the discount it gives](https://docs.storiza.store/api-reference/billing/check-a-coupon-and-preview-the-discount-it-gives.md): Validates the code against every limit — overall uses, uses per account, uses per IP, validity dates — and returns what it would take off the order. - [Get supported currencies information](https://docs.storiza.store/api-reference/billing/get-supported-currencies-information.md): Lists the supported currencies with their symbols, formatting rules and conversion rates. Supports the standard filtering query parameters. - [List the payment methods a customer can pay with](https://docs.storiza.store/api-reference/billing/list-the-payment-methods-a-customer-can-pay-with.md): Returns the instruments available at checkout — cards, cryptocurrency, the account balance — each with the provider behind it and the currencies it settles in. - [Create a transaction that adds credit to the account balance](https://docs.storiza.store/api-reference/billing/create-a-transaction-that-adds-credit-to-the-account-balance.md): Creates the transaction and returns it already synced with the provider, so `checkoutUrl` (and `iframeUrl` where the provider supports embedding) are ready to pay immediately. - [List the caller's gift cards](https://docs.storiza.store/api-reference/gift-cards/list-the-callers-gift-cards.md): Returns a list of gift cards owned by the caller, including their status and associated users. - [Look up a gift card by its code](https://docs.storiza.store/api-reference/gift-cards/look-up-a-gift-card-by-its-code.md): Returns a gift card's value and whether it is still unspent, so a customer can check a code before redeeming it. - [Issue a new code for a gift card you own](https://docs.storiza.store/api-reference/gift-cards/issue-a-new-code-for-a-gift-card-you-own.md): Replaces the code on an unredeemed card you bought. Use it when a code has been seen by somebody it should not have been — sent to the wrong address, screenshotted, pasted into a chat. The old code stops working immediately. - [Buy a gift card](https://docs.storiza.store/api-reference/gift-cards/buy-a-gift-card.md): Purchases a gift card for one of the denominations returned by `GET /payments/giftcards/values`. Any other amount is rejected — that constraint applies here and nowhere else, so a card issued by hand for a different value still redeems normally. - [Redeem a gift card for account balance](https://docs.storiza.store/api-reference/gift-cards/redeem-a-gift-card-for-account-balance.md): Exchanges a gift card code for credit on the account. The card's own value is what gets credited — never a figure supplied by the caller, and never restricted to the denominations currently on sale. A card issued by hand for any amount redeems for exactly what it says. - [List the gift card denominations available to buy](https://docs.storiza.store/api-reference/gift-cards/list-the-gift-card-denominations-available-to-buy.md): The fixed set of values a gift card can be bought for. Render these as the options on a purchase screen — `POST /payments/giftcards/buy` rejects anything else. - [Get current logged In profile information](https://docs.storiza.store/api-reference/account/get-current-logged-in-profile-information.md): Get the currently logged in user's profile information. - [Search across all user resources with similarity-based ordering](https://docs.storiza.store/api-reference/account/search-across-all-user-resources-with-similarity-based-ordering.md): Search across all user resources including VPS, invoices, backups, and snapshots with intelligent similarity scoring. Results are ordered by relevance across all resource types. - [Get detailed resource usage summary for the user](https://docs.storiza.store/api-reference/account/get-detailed-resource-usage-summary-for-the-user.md): Retrieve comprehensive information about user's resources including VPS, invoices, backups, snapshots, and account balance - [Get the most recent user resources](https://docs.storiza.store/api-reference/account/get-the-most-recent-user-resources.md): Retrieve the most recently created VPS for the user, sorted by creation date - [List the signed-in user's SSH keys](https://docs.storiza.store/api-reference/ssh-keys/list-the-signed-in-users-ssh-keys.md): Returns the caller's own SSH keys, newest first. Supports the standard filtering query parameters (`_page`, `_limit`, `_search`, `_sort_by`) plus exact-match filters on the enabled fields (e.g. `algorithm`). - [Add an SSH public key to the signed-in user's account](https://docs.storiza.store/api-reference/ssh-keys/add-an-ssh-public-key-to-the-signed-in-users-account.md): Stores an SSH **public** key that can then be attached to any number of servers by passing `sshKeyId` when ordering a VPS. The key is parsed the way `ssh-keygen -l` parses it: the algorithm must be one OpenSSH still accepts, and the blob's own header must agree with the prefix. A mismatch is rejecte… - [Fetch one of the signed-in user's SSH keys](https://docs.storiza.store/api-reference/ssh-keys/fetch-one-of-the-signed-in-users-ssh-keys.md): Returns a single SSH key owned by the caller, including its full public key and fingerprint. A key belonging to another account is reported as `404 SSH_KEY_NOT_FOUND`, not `403`. - [Rename one of the signed-in user's SSH keys](https://docs.storiza.store/api-reference/ssh-keys/rename-one-of-the-signed-in-users-ssh-keys.md): Only the label changes. The key material itself is immutable: servers already booted with this key have it written to disk, so swapping the body here would leave the record describing something other than what is actually authorised on those machines. To use a different key, add it and reinstall the… - [Remove an SSH key from the signed-in user's account](https://docs.storiza.store/api-reference/ssh-keys/remove-an-ssh-key-from-the-signed-in-users-account.md): Removes the key from the account so it can no longer be attached to new servers. - [Get all managed users](https://docs.storiza.store/api-reference/managed-users/get-all-managed-users.md): Get list of all managed users created by the current user - [Create a new managed user](https://docs.storiza.store/api-reference/managed-users/create-a-new-managed-user.md): Create a new managed user with auto-generated email and assign to specified VPS instances - [Remove a managed user](https://docs.storiza.store/api-reference/managed-users/remove-a-managed-user.md): Remove a managed user and remove them from all VPS instances - [Change password for a managed user](https://docs.storiza.store/api-reference/managed-users/change-password-for-a-managed-user.md): Change the password for a managed user - [Update VPS access for a managed user](https://docs.storiza.store/api-reference/managed-users/update-vps-access-for-a-managed-user.md): Update which VPS instances a managed user can access - [Add a managed user to VPS](https://docs.storiza.store/api-reference/managed-users/add-a-managed-user-to-vps.md): Add a managed user to a VPS instance as a member - [Remove a managed user from VPS](https://docs.storiza.store/api-reference/managed-users/remove-a-managed-user-from-vps.md): Remove a managed user from a VPS instance - [List support tickets visible to the caller](https://docs.storiza.store/api-reference/support/list-support-tickets-visible-to-the-caller.md): Returns the caller's own tickets, most recently active first. Support staff and admins see every ticket instead — the queue and a customer's list are the same endpoint, scoped by who is asking. - [Open a support ticket with a first message](https://docs.storiza.store/api-reference/support/open-a-support-ticket-with-a-first-message.md): Creates a ticket and records its opening message. The response carries the ticket's `ref` (`TKT-XXXXXX`), which is also pinned to the subject line of every email the ticket sends — a customer replying to one of those emails has their reply appended to this same thread. - [Fetch one support ticket](https://docs.storiza.store/api-reference/support/fetch-one-support-ticket.md): Returns a single ticket the caller can see — their own, or any ticket when the caller is support staff or an admin. A ticket belonging to someone else is reported as `404 SUPPORT_TICKET_NOT_FOUND`, not `403`. - [Mark a support ticket as resolved](https://docs.storiza.store/api-reference/support/mark-a-support-ticket-as-resolved.md): Closes the ticket and leaves a note in the thread recording who closed it. Closing is idempotent — a ticket that is already closed is returned unchanged. - [Read the thread on a support ticket](https://docs.storiza.store/api-reference/support/read-the-thread-on-a-support-ticket.md): Returns the ticket's messages oldest first — both channels in one list, so a reply typed into the dashboard and one sent by email appear in the order they were written, distinguished only by `channel`. - [Append a message to a support ticket](https://docs.storiza.store/api-reference/support/append-a-message-to-a-support-ticket.md): Adds a message to the thread. Who the message is *from* is decided by the caller's role, never by the request body: support staff and admins post as `support`, everyone else posts as `customer` on their own ticket. - [Tickets with activity the caller has not seen](https://docs.storiza.store/api-reference/support/tickets-with-activity-the-caller-has-not-seen.md): The badge. Returns how many tickets have a message newer than the last time the caller read them, and which ones — so the dashboard shell can show a count on any page and link straight to the thread. - [List the reseller's sub-accounts](https://docs.storiza.store/api-reference/reseller/list-the-resellers-sub-accounts.md): List the sub-accounts owned by the current reseller, with pagination and username search. - [Create a reseller sub-account (username + password)](https://docs.storiza.store/api-reference/reseller/create-a-reseller-sub-account-username-+-password.md): Create a login-scoped sub-account owned by the accepted reseller, optionally assigning one or more of the reseller's VPS to it. Usernames are unique per reseller: another reseller may already have a customer by the same name, and that is fine. - [Delete a reseller sub-account](https://docs.storiza.store/api-reference/reseller/delete-a-reseller-sub-account.md): Permanently delete one of the current reseller's sub-accounts. - [Change a reseller sub-account's password](https://docs.storiza.store/api-reference/reseller/change-a-reseller-sub-accounts-password.md): Set a new password for one of the current reseller's sub-accounts. - [Set the VPS a reseller sub-account can control](https://docs.storiza.store/api-reference/reseller/set-the-vps-a-reseller-sub-account-can-control.md): Replace the set of the reseller's VPS assigned to the sub-account. Pass one or more VPS IDs (empty array clears them). - [Submit a reseller program application](https://docs.storiza.store/api-reference/reseller/submit-a-reseller-program-application.md): Submit a reseller program application for the current user. Fails when the user already has a pending or accepted application. - [Get the current user's reseller program status](https://docs.storiza.store/api-reference/reseller/get-the-current-users-reseller-program-status.md): Returns the high-level reseller state used by the UI to choose which screen to render: `none` (never applied), `pending`, `accepted`, or `rejected` (with the rejection reason on the application). - [Get the accepted reseller's storefront configuration](https://docs.storiza.store/api-reference/reseller/get-the-accepted-resellers-storefront-configuration.md): Return the storefront configuration of the current accepted reseller. Fails when the user is not an accepted reseller. - [Set up the accepted reseller's storefront (name + brand color)](https://docs.storiza.store/api-reference/reseller/set-up-the-accepted-resellers-storefront-name-+-brand-color.md): Create the storefront for an accepted reseller. Fails when the user is not an accepted reseller or the store already exists. - [Update the accepted reseller's storefront UI (name + brand color)](https://docs.storiza.store/api-reference/reseller/update-the-accepted-resellers-storefront-ui-name-+-brand-color.md): Partially update the storefront of the current accepted reseller. At least one field must be provided. - [Check whether the store's custom domain is serving traffic yet](https://docs.storiza.store/api-reference/reseller/check-whether-the-stores-custom-domain-is-serving-traffic-yet.md): Return the live status of the accepted reseller's custom domain, refreshed from Cloudflare and written back to the store. Poll while `status` is `pending`; a domain becomes `active` once its certificate has been issued, which requires the CNAME record in `cnameTarget` to be resolving. - [Upload/replace the reseller's store logo (base64 image)](https://docs.storiza.store/api-reference/reseller/uploadreplace-the-resellers-store-logo-base64-image.md): Upload or replace the storefront logo of the current accepted reseller. The image is sent base64-encoded (optionally as a data-URL). ## OpenAPI Specs - [openapi](/openapi.json) This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.