Guide

Automating Web Hosting with a REST API and CLI: One Call, Any Server

Updated

On this page
  1. The same API the panel runs on
  2. Your first API calls
  3. Automation ideas for hosting operators
  4. The unicorn CLI: one binary on every host
  5. Upgrades you can script safely
  6. Security for automation
  7. Frequently asked questions
  8. Script anything

Clicking through a control panel is fine for one site. It is not fine for fifty sites, a nightly report, a pre-deploy backup in a CI pipeline, or provisioning that runs the moment a customer pays. At that point, hosting operators need an API they can trust and a command line they can script.

Too many panels treat automation as an afterthought: a limited API bolted on for integrators, or one hidden behind a higher-priced tier. Unicorn Panel takes the opposite approach. Its REST API is the same surface the panel itself is built on, and none of it is paywalled.

The same API the panel runs on

Nearly every action in the Unicorn Panel interface is also a documented REST endpoint, and the developers page lists them. This is not a second-class integration layer. The panel's own UI calls the same API, so anything the UI can do, your script can do.

Key properties:

  • Per-account API keys. Each key carries exactly the access its account has in the panel. An integration built by a reseller cannot reach further than that reseller could by clicking.
  • Authenticated at the gateway. Every request is checked before it reaches a handler.
  • Fleet-wide reach. One API call can reach a resource on any server in the fleet. You call the Primary; it routes the request to the right Secondary.
  • Per-server keys behind the scenes. Cross-server calls carry their own per-server keys with separate scopes, rather than every host sharing one master credential.
  • Time-limited tokens for sensitive flows such as file downloads and single sign-on into admin tools.
  • No premium tier. The API is available on every plan, including free.

Your first API calls

Create a key under Settings → API Keys, then pass it in the X-API-KEY header. Both examples run against a real panel.

List websites across the fleet:

curl -H "X-API-KEY: $KEY" https://panel.acme.com/api/websites

The response includes each site's short ID (uid), domain, the server it lives on and its PHP version:

[
  {"uid":"a7f3","domain":"shop.acme.com","server_id":1,"php_version":"8.3"},
  {"uid":"b2k9","domain":"blog.acme.com","server_id":1,"php_version":"8.4"}
]

Take a backup before a deploy:

curl -H "X-API-KEY: $KEY" -X PUT https://panel.acme.com/api/backups/backup-site \
     -d '{"uid":"a7f3","notes":"pre-deploy checkpoint"}'

Every site keeps its short ID even if its domain is renamed, which makes it a stable key for scripts. The full endpoint list is in the documentation.

Automation ideas for hosting operators

Once the API is in reach, a lot of repetitive work disappears:

WorkflowHow it works
Pre-deploy checkpointsYour CI pipeline triggers a site backup before every release, so rollback is one restore
Nightly inventoryA script lists every site, its server and PHP version, and flags anything on an old PHP release
Automated provisioningYour billing or signup system creates accounts and sites when a customer pays
Suspensions and upgradesBilling events suspend, restore or change packages without manual steps
ReportingPull site and server data into your own dashboards
Reseller integrationsResellers wire their own tools to the panel with their own scoped keys

For resellers especially, automation is what turns a side business into a scalable one; see how to start a white-label hosting reseller business.

The unicorn CLI: one binary on every host

Alongside the API, every server in a Unicorn fleet has the same unicorn binary, built for amd64 and arm64. Its subcommands mirror what the panel manages: websites, databases, backups, emails, dns, host and proxy. It is for the panel owner, run as root on the box, so fleet jobs can live in shell scripts and cron instead of browser tabs. Tenants never see it.

$ unicorn version
2026.09.27.21.38

$ unicorn host version
Alpine Linux (3.22.4)

$ unicorn websites list-local
yd2n
me09

The documentation lists every command. The ones you will use most:

CommandUse it to
unicorn upgradeUpgrade the panel on this host
unicorn cron check-common-server-issuesScan logs for the most common problems
unicorn podman list-containersSee every tenant container and its status
unicorn podman restart-containersCycle every tenant container without rebuilding
unicorn websites fix-permissions <uid>Reset file ownership in one site
unicorn tools recalculate-diskRefresh cached disk usage figures
unicorn tools update-cdn-ipsRefresh Cloudflare and BunnyCDN trusted IPs
unicorn proxy test / reloadTest and reload the reverse proxy
unicorn shield ban <IP> / unban <IP>Manage the firewall ban list
unicorn root reset-admin-passwordRecover the first admin account

Upgrades you can script safely

unicorn upgrade fetches the new release, verifies the license, extracts it, runs any per-version upgrade hooks and restarts services. Every upgrade snapshots state before it touches anything, so a bad upgrade is a restore rather than a rebuild, and a failed download leaves the server on its previous working version.

You also control the pace. Upgrade one host, watch how it behaves, then script the rest of the fleet, or use the panel's bulk update screen to bring every server up to date at once. Our multi-server pillar guide explains how bulk updates fit into fleet management.

Security for automation

API keys are credentials, so treat them that way:

  • Use the least-privileged account that can do the job, since keys inherit their account's access.
  • Store keys in a secrets manager or CI secret store, never in a repository.
  • Rotate keys when people leave or integrations change.
  • Prefer the API over SSH for routine automation; it is scoped, logged and needs no shell access.

Our hosting control panel security checklist covers how Unicorn Panel protects keys and sessions.

Frequently asked questions

Is the API available on the free plan? Yes. There is no premium tier in front of the API.

Can one API call manage a site on a different server? Yes. You call the Primary, and it reaches the resource on whichever server it lives.

Can resellers use the API? Yes, with their own per-account keys, limited to what their account can access.

Can tenants use the CLI? No. The CLI is for the panel owner as root. Customers can use the browser terminal inside their own site container.

Where is the endpoint documentation? In the Unicorn Panel documentation and on the CLI & API page.

Script anything

A control panel should make automation easier, not ration it. Unicorn Panel gives you the same API its own interface uses, a CLI on every server, and safe upgrades you can roll out at your own pace, on every plan.

wget -qO- https://unicornpanel.com/install | sh

Or try the live demo and explore the panel the API is built on.

Try it on your own servers.

Free for 2 servers and 2 accounts, with unlimited websites, databases, mailboxes and DNS zones.