Pterodactyldocs

API Overview

The Pterodactyl 2.0 APIs and how to authenticate with them.

Introduction

The Panel has three APIs. Choose the one that matches what you want to do:

APIPathUse it to
Client/api/clientManage your account and the servers you have access to.
Application/api/applicationManage users, nodes, and servers, for example from a billing system.
Admin/api/adminManage the whole Panel, including eggs, tags, settings, and extensions.

The Panel's own login pages use the browser authentication endpoints under /auth.

The paths above are the same in every version. The v2 in this documentation's address is not part of the API path.

In the examples, replace https://panel.example.com with the address of your Panel.

Authentication

Send your API key in the Authorization header of every request:

Authorization: Bearer YOUR_API_KEY

Each API accepts different keys:

APIAccepted keys
ClientA Client API key. It can only do what its user can do.
ApplicationAn Application API key, or a root administrator's Client API key.
AdminA root administrator's Client API key.

Application API keys only work with the Application API, where each key is limited to the permissions it was created with. The Client API and the Admin API reject them.

API keys created on 1.x keep working after you upgrade.

Browser Sessions

The Panel's frontend signs in with a session cookie instead of an API key. First request /sanctum/csrf-cookie, then keep the cookies it returns, and send the CSRF token with every request that changes data.

The examples use a session cookie named pterodactyl_session. Your Panel may use a different name if you have set APP_NAME or SESSION_COOKIE.

Where to Start

If you are moving an integration from 1.x, read Changes From 1.x first. The nest endpoints have been removed.

On this page