Clicking through a control panel is fine for one site. It is not fine for fifty sites, a nightly report, a pre-deploy backup in a CI pipeline, or provisioning that runs the moment a customer pays. At that point, hosting operators need an API they can trust and a command line they can script.
Too many panels treat automation as an afterthought: a limited API bolted on for integrators, or one hidden behind a higher-priced tier. Unicorn Panel takes the opposite approach. Its REST API is the same surface the panel itself is built on, and none of it is paywalled.
The same API the panel runs on
Nearly every action in the Unicorn Panel interface is also a documented REST endpoint, and the developers page lists them. This is not a second-class integration layer. The panel's own UI calls the same API, so anything the UI can do, your script can do.
Key properties:
- Per-account API keys. Each key carries exactly the access its account has in the panel. An integration built by a reseller cannot reach further than that reseller could by clicking.
- Authenticated at the gateway. Every request is checked before it reaches a handler.
- Fleet-wide reach. One API call can reach a resource on any server in the fleet. You call the Primary; it routes the request to the right Secondary.
- Per-server keys behind the scenes. Cross-server calls carry their own per-server keys with separate scopes, rather than every host sharing one master credential.
- Time-limited tokens for sensitive flows such as file downloads and single sign-on into admin tools.
- No premium tier. The API is available on every plan, including free.
Your first API calls
Create a key under Settings → API Keys, then pass it in the X-API-KEY header. Both examples run against a real panel.
List websites across the fleet:
curl -H "X-API-KEY: $KEY" https://panel.acme.com/api/websites
The response includes each site's short ID (uid), domain, the server it lives on and its PHP version:
[
{"uid":"a7f3","domain":"shop.acme.com","server_id":1,"php_version":"8.3"},
{"uid":"b2k9","domain":"blog.acme.com","server_id":1,"php_version":"8.4"}
]
Take a backup before a deploy:
curl -H "X-API-KEY: $KEY" -X PUT https://panel.acme.com/api/backups/backup-site \
-d '{"uid":"a7f3","notes":"pre-deploy checkpoint"}'
Every site keeps its short ID even if its domain is renamed, which makes it a stable key for scripts. The full endpoint list is in the documentation.
Automation ideas for hosting operators
Once the API is in reach, a lot of repetitive work disappears:
| Workflow | How it works |
|---|---|
| Pre-deploy checkpoints | Your CI pipeline triggers a site backup before every release, so rollback is one restore |
| Nightly inventory | A script lists every site, its server and PHP version, and flags anything on an old PHP release |
| Automated provisioning | Your billing or signup system creates accounts and sites when a customer pays |
| Suspensions and upgrades | Billing events suspend, restore or change packages without manual steps |
| Reporting | Pull site and server data into your own dashboards |
| Reseller integrations | Resellers wire their own tools to the panel with their own scoped keys |
For resellers especially, automation is what turns a side business into a scalable one; see how to start a white-label hosting reseller business.
The unicorn CLI: one binary on every host
Alongside the API, every server in a Unicorn fleet has the same unicorn binary, built for amd64 and arm64. Its subcommands mirror what the panel manages: websites, databases, backups, emails, dns, host and proxy. It is for the panel owner, run as root on the box, so fleet jobs can live in shell scripts and cron instead of browser tabs. Tenants never see it.
$ unicorn version
2026.09.27.21.38
$ unicorn host version
Alpine Linux (3.22.4)
$ unicorn websites list-local
yd2n
me09
The documentation lists every command. The ones you will use most:
| Command | Use it to |
|---|---|
unicorn upgrade | Upgrade the panel on this host |
unicorn cron check-common-server-issues | Scan logs for the most common problems |
unicorn podman list-containers | See every tenant container and its status |
unicorn podman restart-containers | Cycle every tenant container without rebuilding |
unicorn websites fix-permissions <uid> | Reset file ownership in one site |
unicorn tools recalculate-disk | Refresh cached disk usage figures |
unicorn tools update-cdn-ips | Refresh Cloudflare and BunnyCDN trusted IPs |
unicorn proxy test / reload | Test and reload the reverse proxy |
unicorn shield ban <IP> / unban <IP> | Manage the firewall ban list |
unicorn root reset-admin-password | Recover the first admin account |
Upgrades you can script safely
unicorn upgrade fetches the new release, verifies the license, extracts it, runs any per-version upgrade hooks and restarts services. Every upgrade snapshots state before it touches anything, so a bad upgrade is a restore rather than a rebuild, and a failed download leaves the server on its previous working version.
You also control the pace. Upgrade one host, watch how it behaves, then script the rest of the fleet, or use the panel's bulk update screen to bring every server up to date at once. Our multi-server pillar guide explains how bulk updates fit into fleet management.
Security for automation
API keys are credentials, so treat them that way:
- Use the least-privileged account that can do the job, since keys inherit their account's access.
- Store keys in a secrets manager or CI secret store, never in a repository.
- Rotate keys when people leave or integrations change.
- Prefer the API over SSH for routine automation; it is scoped, logged and needs no shell access.
Our hosting control panel security checklist covers how Unicorn Panel protects keys and sessions.
Frequently asked questions
Is the API available on the free plan? Yes. There is no premium tier in front of the API.
Can one API call manage a site on a different server? Yes. You call the Primary, and it reaches the resource on whichever server it lives.
Can resellers use the API? Yes, with their own per-account keys, limited to what their account can access.
Can tenants use the CLI? No. The CLI is for the panel owner as root. Customers can use the browser terminal inside their own site container.
Where is the endpoint documentation? In the Unicorn Panel documentation and on the CLI & API page.
Script anything
A control panel should make automation easier, not ration it. Unicorn Panel gives you the same API its own interface uses, a CLI on every server, and safe upgrades you can roll out at your own pace, on every plan.
wget -qO- https://unicornpanel.com/install | sh
Or try the live demo and explore the panel the API is built on.