CLI & API

Script anything.

Nearly every UI action is also a documented REST endpoint, with per-account keys and the same access rules as the panel. The CLI sits alongside it for whoever owns the panel, as root on the box. No premium tier gates any of it.

Fleet-wide CLI

One unicorn binary on every host

The same binary sits on every host, and its subcommands mirror what the panel manages: websites, databases, backups, emails, dns, host, proxy. It is there for whoever owns the panel, run as root on the box, so fleet jobs can go in a script instead of a browser tab. Builds ship for amd64 and arm64.

  • Subcommands mirror every panel resource
  • Drive it from a shell script, a cron job, or your own tooling
  • For the panel owner, on the box, as root. Tenants never see it
  • Upgrades are a single command, on one host or scripted across the fleet
$ unicorn version
2026.09.27.21.38

$ unicorn host version
Alpine Linux (3.22.4)

$ unicorn websites list-local
yd2n
me09
...

Open REST API

The same API the panel runs on

This is not a second-class API bolted on for integrators. It is the surface the panel itself is built on, so anything the UI can do, your script can do. Keys are checked at the gateway before a handler ever runs, and cross-server calls carry their own per-server keys rather than sharing one master credential.

$ curl -H "X-API-KEY: $KEY" https://panel.acme.com/api/websites
[
  {"uid":"a7f3","domain":"shop.acme.com","server_id":1,"php_version":"8.3"},
  {"uid":"b2k9","domain":"blog.acme.com","server_id":1,"php_version":"8.4"}
]

$ curl -H "X-API-KEY: $KEY" -X PUT https://panel.acme.com/api/backups/backup-site \
       -d '{"uid":"a7f3","notes":"pre-deploy checkpoint"}'
{"success":true,"website":{"ok":true,"row_id":4821},"databases":{}}
  • Every request is authenticated before it reaches a handler
  • Per-server keys with separate scopes for cross-server calls
  • Time-limited tokens for sensitive flows
  • Documented endpoints, with no premium tier in front of them

Both calls run against a real panel with a key from Settings → API Keys.

Operate like an ops team

Automation-friendly by design

Auto-update

unicorn upgrade fetches the new panel zip, extracts, runs the per-version upgrade hook, and restarts.

Roll it out at your pace

Upgrade one host, see how it behaves, then script the rest of the fleet. You are not forced to move everything at once.

Backed up before it starts

Every upgrade snapshots state before it touches anything, so a bad one is a restore rather than a rebuild.

Build on an API that isn’t paywalled.

Fleet-wide CLI and a documented REST API: the same surface the panel uses.