Media

Add an ISO to the library

Since 7.1.0
POST/media/iso

Add an ISO. name is enough to create it; url and filename must be set before it can be enabled. Any field the update accepts can be sent.

Request

Authorization
Provide your bearer token in the Authorization header when making requests to protected resources.
Example: Authorization: Bearer ********************
Body Paramsapplication/json#

The ISO, in the shape the ISO GET returns.

namestring#
Length: 3 to 150 characters
descriptionstring#nullable
Length: at most 500 characters
urlstring#

Where the hypervisor downloads the image from the first time it is needed. http or https.

Length: at most 2000 characters
filenamestring#

Letters, digits, dashes and underscores, unique in the library; the hypervisor stores it as <filename>.iso.

Length: at most 300 characters
archinteger#

0 any, 1 x86_64, 2 aarch64. A server can mount an ISO whose arch is 0 or its hypervisor's.

Allowed values:012
enabledboolean#

Needs url and filename set.

globalboolean#
downloadboolean#
Example
{
    "name": "Debian 13 netinst",
    "url": "https://cdn.example.net/debian-13-netinst.iso",
    "filename": "debian-13-netinst",
    "arch": 1,
    "enabled": true
}

Request Code Samples

curl --location --request POST 'https://cp.domain.com/api/v1/media/iso' \
--header 'Authorization: Bearer <token>' \
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data-raw '{
    "name": "Debian 13 netinst",
    "url": "https://cdn.example.net/debian-13-netinst.iso",
    "filename": "debian-13-netinst",
    "arch": 1,
    "enabled": true
}'
wget --quiet --output-document=- \
  --method=POST \
  --header='Authorization: Bearer <token>' \
  --header='Accept: application/json' \
  --header='Content-Type: application/json' \
  --body-data='{
    "name": "Debian 13 netinst",
    "url": "https://cdn.example.net/debian-13-netinst.iso",
    "filename": "debian-13-netinst",
    "arch": 1,
    "enabled": true
}' \
  'https://cp.domain.com/api/v1/media/iso'
http POST 'https://cp.domain.com/api/v1/media/iso' \
  'Authorization: Bearer <token>' \
  'Accept: application/json' \
  'Content-Type: application/json' <<< '{
    "name": "Debian 13 netinst",
    "url": "https://cdn.example.net/debian-13-netinst.iso",
    "filename": "debian-13-netinst",
    "arch": 1,
    "enabled": true
}'
const response = await fetch("https://cp.domain.com/api/v1/media/iso", {
    method: "POST",
    headers: {
        "Authorization": "Bearer <token>",
        "Accept": "application/json",
        "Content-Type": "application/json",
    },
    body: JSON.stringify({
        "name": "Debian 13 netinst",
        "url": "https://cdn.example.net/debian-13-netinst.iso",
        "filename": "debian-13-netinst",
        "arch": 1,
        "enabled": true
    }),
});

const data = await response.json();
console.log(response.status, data);
import axios from "axios";

const response = await axios({
    method: "post",
    url: "https://cp.domain.com/api/v1/media/iso",
    headers: {
        "Authorization": "Bearer <token>",
        "Accept": "application/json",
        "Content-Type": "application/json",
    },
    data: {
        "name": "Debian 13 netinst",
        "url": "https://cdn.example.net/debian-13-netinst.iso",
        "filename": "debian-13-netinst",
        "arch": 1,
        "enabled": true
    },
});

console.log(response.status, response.data);
const https = require("https");

const payload = JSON.stringify({
    "name": "Debian 13 netinst",
    "url": "https://cdn.example.net/debian-13-netinst.iso",
    "filename": "debian-13-netinst",
    "arch": 1,
    "enabled": true
});

const req = https.request({
    hostname: "cp.domain.com",
    path: "/api/v1/media/iso",
    method: "POST",
    headers: {
        "Authorization": "Bearer <token>",
        "Accept": "application/json",
        "Content-Type": "application/json",
        "Content-Length": Buffer.byteLength(payload),
    },
}, (res) => {
    let data = "";
    res.on("data", (chunk) => (data += chunk));
    res.on("end", () => console.log(res.statusCode, JSON.parse(data)));
});

req.on("error", (err) => console.error(err));
req.write(payload);
req.end();
import requests

url = "https://cp.domain.com/api/v1/media/iso"
headers = {
    "Authorization": "Bearer <token>",
    "Accept": "application/json",
    "Content-Type": "application/json",
}
payload = {
    "name": "Debian 13 netinst",
    "url": "https://cdn.example.net/debian-13-netinst.iso",
    "filename": "debian-13-netinst",
    "arch": 1,
    "enabled": True,
}

response = requests.request("POST", url, headers=headers, json=payload)

print(response.status_code)
print(response.json())
import http.client
import json

conn = http.client.HTTPSConnection("cp.domain.com")
headers = {
    "Authorization": "Bearer <token>",
    "Accept": "application/json",
    "Content-Type": "application/json",
}
payload = json.dumps({
    "name": "Debian 13 netinst",
    "url": "https://cdn.example.net/debian-13-netinst.iso",
    "filename": "debian-13-netinst",
    "arch": 1,
    "enabled": True,
})

conn.request("POST", "/api/v1/media/iso", payload, headers)
response = conn.getresponse()

print(response.status)
print(json.loads(response.read()))
<?php

$curl = curl_init();

curl_setopt_array($curl, array(
    CURLOPT_URL => 'https://cp.domain.com/api/v1/media/iso',
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_ENCODING => '',
    CURLOPT_MAXREDIRS => 10,
    CURLOPT_TIMEOUT => 0,
    CURLOPT_FOLLOWLOCATION => true,
    CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
    CURLOPT_CUSTOMREQUEST => 'POST',
    CURLOPT_POSTFIELDS => json_encode([
        'name' => 'Debian 13 netinst',
        'url' => 'https://cdn.example.net/debian-13-netinst.iso',
        'filename' => 'debian-13-netinst',
        'arch' => 1,
        'enabled' => true,
    ]),
    CURLOPT_HTTPHEADER => array(
        'Authorization: Bearer <token>',
        'Accept: application/json',
        'Content-Type: application/json'
    ),
));

$response = curl_exec($curl);
curl_close($curl);

echo $response;
<?php

require 'vendor/autoload.php';

use GuzzleHttp\Client;

$client = new Client();

$response = $client->request('POST', 'https://cp.domain.com/api/v1/media/iso', [
    'headers' => [
        'Authorization' => 'Bearer <token>',
        'Accept' => 'application/json',
    ],
    'json' => [
        'name' => 'Debian 13 netinst',
        'url' => 'https://cdn.example.net/debian-13-netinst.iso',
        'filename' => 'debian-13-netinst',
        'arch' => 1,
        'enabled' => true,
    ],
]);

echo $response->getStatusCode() . "\n";
echo $response->getBody();
package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    url := "https://cp.domain.com/api/v1/media/iso"
    payload := strings.NewReader(`{
    "name": "Debian 13 netinst",
    "url": "https://cdn.example.net/debian-13-netinst.iso",
    "filename": "debian-13-netinst",
    "arch": 1,
    "enabled": true
}`)
    req, _ := http.NewRequest("POST", url, payload)
    req.Header.Add("Authorization", "Bearer <token>")
    req.Header.Add("Accept", "application/json")
    req.Header.Add("Content-Type", "application/json")

    res, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer res.Body.Close()

    body, _ := io.ReadAll(res.Body)
    fmt.Println(res.StatusCode, string(body))
}
import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;

public class Main {
    public static void main(String[] args) throws Exception {
        HttpClient client = HttpClient.newHttpClient();

        HttpRequest request = HttpRequest.newBuilder()
            .uri(URI.create("https://cp.domain.com/api/v1/media/iso"))
            .header("Authorization", "Bearer <token>")
            .header("Accept", "application/json")
            .header("Content-Type", "application/json")
            .method("POST", HttpRequest.BodyPublishers.ofString("{\"name\":\"Debian 13 netinst\",\"url\":\"https://cdn.example.net/debian-13-netinst.iso\",\"filename\":\"debian-13-netinst\",\"arch\":1,\"enabled\":true}"))
            .build();

        HttpResponse<String> response = client.send(request, HttpResponse.BodyHandlers.ofString());
        System.out.println(response.statusCode());
        System.out.println(response.body());
    }
}
import okhttp3.*;

public class Main {
    public static void main(String[] args) throws Exception {
        OkHttpClient client = new OkHttpClient();

        MediaType json = MediaType.get("application/json");
        RequestBody body = RequestBody.create("{\"name\":\"Debian 13 netinst\",\"url\":\"https://cdn.example.net/debian-13-netinst.iso\",\"filename\":\"debian-13-netinst\",\"arch\":1,\"enabled\":true}", json);

        Request request = new Request.Builder()
            .url("https://cp.domain.com/api/v1/media/iso")
            .method("POST", body)
            .addHeader("Authorization", "Bearer <token>")
            .addHeader("Accept", "application/json")
            .build();

        try (Response response = client.newCall(request).execute()) {
            System.out.println(response.code());
            System.out.println(response.body().string());
        }
    }
}
using System.Net.Http;
using System.Net.Http.Headers;
using System.Text;

var client = new HttpClient();
var request = new HttpRequestMessage(new HttpMethod("POST"), "https://cp.domain.com/api/v1/media/iso");
request.Headers.Authorization = new AuthenticationHeaderValue("Bearer", "<token>");
request.Headers.Accept.Add(new MediaTypeWithQualityHeaderValue("application/json"));
request.Content = new StringContent("{\"name\":\"Debian 13 netinst\",\"url\":\"https://cdn.example.net/debian-13-netinst.iso\",\"filename\":\"debian-13-netinst\",\"arch\":1,\"enabled\":true}", Encoding.UTF8, "application/json");

var response = await client.SendAsync(request);
Console.WriteLine((int)response.StatusCode);
Console.WriteLine(await response.Content.ReadAsStringAsync());
require "net/http"
require "json"

uri = URI("https://cp.domain.com/api/v1/media/iso")
request = Net::HTTP::Post.new(uri)
request["Authorization"] = "Bearer <token>"
request["Accept"] = "application/json"
request["Content-Type"] = "application/json"
request.body = "{\"name\":\"Debian 13 netinst\",\"url\":\"https://cdn.example.net/debian-13-netinst.iso\",\"filename\":\"debian-13-netinst\",\"arch\":1,\"enabled\":true}"

response = Net::HTTP.start(uri.host, uri.port, use_ssl: true) do |http|
  http.request(request)
end

puts response.code
puts JSON.pretty_generate(JSON.parse(response.body))
import Foundation

var request = URLRequest(url: URL(string: "https://cp.domain.com/api/v1/media/iso")!)
request.httpMethod = "POST"
request.setValue("Bearer <token>", forHTTPHeaderField: "Authorization")
request.setValue("application/json", forHTTPHeaderField: "Accept")
request.setValue("application/json", forHTTPHeaderField: "Content-Type")
request.httpBody = "{\"name\":\"Debian 13 netinst\",\"url\":\"https://cdn.example.net/debian-13-netinst.iso\",\"filename\":\"debian-13-netinst\",\"arch\":1,\"enabled\":true}".data(using: .utf8)

let task = URLSession.shared.dataTask(with: request) { data, response, error in
    guard let data = data, error == nil else { print(error ?? "request failed"); return }
    print((response as! HTTPURLResponse).statusCode)
    print(String(data: data, encoding: .utf8) ?? "")
}
task.resume()
// Cargo.toml: reqwest = { version = "0.12", features = ["blocking", "json"] }, serde_json = "1"
use reqwest::blocking::Client;

fn main() -> Result<(), Box<dyn std::error::Error>> {
    let client = Client::new();
    let response = client
        .request(reqwest::Method::POST, "https://cp.domain.com/api/v1/media/iso")
        .bearer_auth("<token>")
        .header("Accept", "application/json")
        .header("Content-Type", "application/json")
        .body(r#"{
    "name": "Debian 13 netinst",
    "url": "https://cdn.example.net/debian-13-netinst.iso",
    "filename": "debian-13-netinst",
    "arch": 1,
    "enabled": true
}"#)
        .send()?;

    println!("{}", response.status());
    let json: serde_json::Value = response.json()?;
    println!("{}", serde_json::to_string_pretty(&json)?);
    Ok(())
}
// Cargo.toml: reqwest = { version = "0.12", features = ["json"] }, tokio = { version = "1", features = ["full"] }, serde_json = "1"
use reqwest::Client;

#[tokio::main]
async fn main() -> Result<(), Box<dyn std::error::Error>> {
    let client = Client::new();
    let response = client
        .request(reqwest::Method::POST, "https://cp.domain.com/api/v1/media/iso")
        .bearer_auth("<token>")
        .header("Accept", "application/json")
        .header("Content-Type", "application/json")
        .body(r#"{
    "name": "Debian 13 netinst",
    "url": "https://cdn.example.net/debian-13-netinst.iso",
    "filename": "debian-13-netinst",
    "arch": 1,
    "enabled": true
}"#)
        .send()
        .await?;

    println!("{}", response.status());
    let json: serde_json::Value = response.json().await?;
    println!("{}", serde_json::to_string_pretty(&json)?);
    Ok(())
}
import okhttp3.MediaType.Companion.toMediaType
import okhttp3.OkHttpClient
import okhttp3.Request
import okhttp3.RequestBody.Companion.toRequestBody

fun main() {
    val client = OkHttpClient()
    val body = """{
    "name": "Debian 13 netinst",
    "url": "https://cdn.example.net/debian-13-netinst.iso",
    "filename": "debian-13-netinst",
    "arch": 1,
    "enabled": true
}""".toRequestBody("application/json".toMediaType())
    val request = Request.Builder()
        .url("https://cp.domain.com/api/v1/media/iso")
        .method("POST", body)
        .addHeader("Authorization", "Bearer <token>")
        .addHeader("Accept", "application/json")
        .build()

    client.newCall(request).execute().use { response ->
        println(response.code)
        println(response.body?.string())
    }
}
// pubspec.yaml: http: ^1.2.0
import 'dart:convert';
import 'package:http/http.dart' as http;

Future<void> main() async {
  final request = http.Request('POST', Uri.parse('https://cp.domain.com/api/v1/media/iso'));
  request.headers['Authorization'] = 'Bearer <token>';
  request.headers['Accept'] = 'application/json';
  request.headers['Content-Type'] = 'application/json';
  request.body = r'''{
    "name": "Debian 13 netinst",
    "url": "https://cdn.example.net/debian-13-netinst.iso",
    "filename": "debian-13-netinst",
    "arch": 1,
    "enabled": true
}''';

  final response = await http.Response.fromStream(await request.send());
  print(response.statusCode);
  print(const JsonEncoder.withIndent('  ').convert(jsonDecode(response.body)));
}
#include <stdio.h>
#include <curl/curl.h>

int main(void) {
    CURL *curl = curl_easy_init();
    if (!curl) return 1;

    struct curl_slist *headers = NULL;
    headers = curl_slist_append(headers, "Authorization: Bearer <token>");
    headers = curl_slist_append(headers, "Accept: application/json");
    headers = curl_slist_append(headers, "Content-Type: application/json");

    curl_easy_setopt(curl, CURLOPT_URL, "https://cp.domain.com/api/v1/media/iso");
    curl_easy_setopt(curl, CURLOPT_CUSTOMREQUEST, "POST");
    curl_easy_setopt(curl, CURLOPT_HTTPHEADER, headers);
    curl_easy_setopt(curl, CURLOPT_POSTFIELDS, "{\"name\":\"Debian 13 netinst\",\"url\":\"https://cdn.example.net/debian-13-netinst.iso\",\"filename\":\"debian-13-netinst\",\"arch\":1,\"enabled\":true}");

    CURLcode result = curl_easy_perform(curl);
    if (result != CURLE_OK) fprintf(stderr, "%s\n", curl_easy_strerror(result));

    curl_slist_free_all(headers);
    curl_easy_cleanup(curl);
    return result == CURLE_OK ? 0 : 1;
}
$headers = @{
    Authorization = "Bearer <token>"
    Accept        = "application/json"
}

$body = @'
{
    "name": "Debian 13 netinst",
    "url": "https://cdn.example.net/debian-13-netinst.iso",
    "filename": "debian-13-netinst",
    "arch": 1,
    "enabled": true
}
'@

$response = Invoke-RestMethod -Uri "https://cp.domain.com/api/v1/media/iso" -Method POST -Headers $headers -ContentType "application/json" -Body $body
$response | ConvertTo-Json -Depth 10
POST /api/v1/media/iso HTTP/1.1
Host: cp.domain.com
Authorization: Bearer <token>
Accept: application/json
Content-Type: application/json
Content-Length: 168

{
    "name": "Debian 13 netinst",
    "url": "https://cdn.example.net/debian-13-netinst.iso",
    "filename": "debian-13-netinst",
    "arch": 1,
    "enabled": true
}

Responses

201

Created.

#
application/json
object
dataISO#

An ISO in the media library, as GET /media/iso/{isoId} returns it.

ISO fields
idinteger#
namestring#
descriptionstring#nullable
archinteger#
urlstring#
filenamestring#
enabledboolean#
configstring#

Stored as given by the installer; nothing writes it through the API.

globalboolean#

Available to every user. When false, only the users under users can mount it.

downloadboolean#

Stored and shown; nothing reads it today.

usersarray[object]#

The users a non-global ISO is assigned to.

item fields
idinteger#
emailstring#
namestring#
enabledboolean#
addedstring <date-time>#
createdstring <date-time>#
updatedstring <date-time>#
Example
{
    "data": {
        "id": 12,
        "name": "Debian 13 netinst",
        "description": "Net installer",
        "arch": 1,
        "url": "https://cdn.example.net/debian-13-netinst.iso",
        "filename": "debian-13-netinst",
        "enabled": true,
        "config": "[]",
        "global": false,
        "download": true,
        "users": [
            {
                "id": 9,
                "email": "owner@example.net",
                "name": "Owner",
                "enabled": true,
                "added": "2026-10-07T09:14:02.000000Z"
            }
        ],
        "created": "2026-10-07T09:14:02+00:00",
        "updated": "2026-10-07T09:20:11+00:00"
    }
}
401

The bearer token is missing, invalid, or expired. The response has no body.

#
No response body.
422

Validation failed, or a read-only or unknown field was sent. Nothing was written.

#
application/json
errorsobject#
Example
{
    "errors": {
        "filename": [
            "another ISO already uses this filename"
        ]
    }
}
429

Too many requests. Either the token's requests per minute are used up (see the `X-RateL…

#
application/json

Too many requests. Either the token's requests per minute are used up (see the X-RateLimit-* headers) or the calling address has failed authentication 10 times in a minute (the body then includes retry_after_seconds). Retry-After gives the seconds to wait.

object
errorsarray[string]#
retry_after_secondsinteger#

Seconds to wait before retrying. Present on the failed-authentication limit only.

Response headers
Retry-Afterinteger

Seconds to wait before retrying.

X-RateLimit-Limitinteger

The token's requests per minute (token limit only).

X-RateLimit-Remaininginteger

Requests left in the current minute (token limit only).

X-RateLimit-Resetinteger

Unix timestamp at which the minute resets (token limit only).

Examples
{
    "errors": [
        "Too Many Requests"
    ]
}
{
    "errors": [
        "Too many authentication attempts. Try again later."
    ],
    "retry_after_seconds": 42
}