Packages

Create a package

Since 7.1.0
POST/packages

Create a package from its name alone, or with any field the update endpoint accepts. It starts disabled with the admin page's defaults.

Request

Authorization
Provide your bearer token in the Authorization header when making requests to protected resources.
Example: Authorization: Bearer ********************
Body Paramsapplication/json#

The package, in the shape the package GET returns.

PackageCreate
namestring#
Length: 3 to 150 characters
descriptionstring#nullable
Length: at most 500 characters
selfServiceDescriptionstring#nullable
enabledboolean#
memoryinteger#

MB.

Range: 64 to 2097152
primaryStorageinteger#

GB.

Range: 1 to 102400
trafficinteger#

GB per period; 0 is unlimited.

Range: at least 0
trafficPolicyobject#

The same six fields the GET returns; null inherits.

cpuCoresinteger#
Range: 1 to 600
primaryNetworkSpeedIninteger#
Range: at least 0
primaryNetworkSpeedOutinteger#
Range: at least 0
primaryDiskTypestring#
Allowed values:inheritqcow2raw
backupPlanIdinteger#nullable

A backup plan id, or null for none.

backupTypestring#
Allowed values:inheritdisabledscheduledviewAndRestorefullmanual
tokenValueinteger#
Range: at least 0
primaryStorageReadBytesSecinteger#nullable
primaryStorageWriteBytesSecinteger#nullable
primaryStorageReadIopsSecinteger#nullable
primaryStorageWriteIopsSecinteger#nullable
primaryStorageProfileinteger#
Range: 0 to 20
primaryNetworkProfileinteger#
Range: 0 to 20
PackageVirtualization fields
cpuModelstring#

inherit, or a CPU model name the Control Server offers.

machineTypestring#
Allowed values:inheritpcq35
pciPortsinteger#
Range: 10 to 32
cpuSharesinteger#
Range: 2 to 262144
cpuTopologyobject#
fields
enabledboolean#
socketsinteger#
Range: 1 to 36
coresinteger#
Range: 1 to 128
threadsinteger#
Range: 1 to 36
forceIpv6boolean#
additionalDisksarray[PackageAdditionalDisk]#
PackageAdditionalDisk fields
slotinteger#

Which of the two extra disks. Required on write; a slot not sent is unchanged.

Allowed values:12
enabledboolean#
sizeGbinteger#
Range: 1 to 102400
formatstring#
Allowed values:inheritqcow2raw
storageProfileinteger#
Range: 0 to 20
qosobject#

Limits for the disk; null means unlimited.

fields
readIopsinteger#nullable
writeIopsinteger#nullable
readBytesinteger#nullable
writeBytesinteger#nullable
PackageSelfService fields
ipv4Addressesinteger#

IPv4 addresses a self-service server gets.

Range: 0 to 5
displayobject#

Text shown in self service instead of the raw figures; null shows the figure.

fields
namestring#nullable
memorystring#nullable
storagestring#nullable
coresstring#nullable
trafficstring#nullable
variableobject#

Sizes a self-service user may pick from, as real values. An empty list with a null default means the resource is not variable.

fields
PackageVariableChoice fields
optionsarray[integer]#

The offered sizes, ascending. A size the Control Server does not offer is refused, naming the nearest it does.

defaultinteger#nullable

One of the options, or null.

PackageVariableChoice fields
optionsarray[integer]#

The offered sizes, ascending. A size the Control Server does not offer is refused, naming the nearest it does.

defaultinteger#nullable

One of the options, or null.

PackageVariableChoice fields
optionsarray[integer]#

The offered sizes, ascending. A size the Control Server does not offer is refused, naming the nearest it does.

defaultinteger#nullable

One of the options, or null.

templateCollectionsarray[any]#
firewallRulesetsarray[any]#
hypervisorAssetGroupsarray[any]#
Examples
{
    "name": "Starter"
}
{
    "name": "Medium",
    "enabled": true,
    "memory": 4096,
    "cpuCores": 2,
    "primaryStorage": 80,
    "traffic": 2000,
    "virtualization": {
        "cpuModel": "host-passthrough"
    },
    "templateCollections": [
        2
    ],
    "firewallRulesets": [
        7
    ]
}

Request Code Samples

Showing the Name only example from Body Params.
curl --location --request POST 'https://cp.domain.com/api/v1/packages' \
--header 'Authorization: Bearer <token>' \
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data-raw '{
    "name": "Starter"
}'
wget --quiet --output-document=- \
  --method=POST \
  --header='Authorization: Bearer <token>' \
  --header='Accept: application/json' \
  --header='Content-Type: application/json' \
  --body-data='{
    "name": "Starter"
}' \
  'https://cp.domain.com/api/v1/packages'
http POST 'https://cp.domain.com/api/v1/packages' \
  'Authorization: Bearer <token>' \
  'Accept: application/json' \
  'Content-Type: application/json' <<< '{
    "name": "Starter"
}'
const response = await fetch("https://cp.domain.com/api/v1/packages", {
    method: "POST",
    headers: {
        "Authorization": "Bearer <token>",
        "Accept": "application/json",
        "Content-Type": "application/json",
    },
    body: JSON.stringify({
        "name": "Starter"
    }),
});

const data = await response.json();
console.log(response.status, data);
import axios from "axios";

const response = await axios({
    method: "post",
    url: "https://cp.domain.com/api/v1/packages",
    headers: {
        "Authorization": "Bearer <token>",
        "Accept": "application/json",
        "Content-Type": "application/json",
    },
    data: {
        "name": "Starter"
    },
});

console.log(response.status, response.data);
const https = require("https");

const payload = JSON.stringify({
    "name": "Starter"
});

const req = https.request({
    hostname: "cp.domain.com",
    path: "/api/v1/packages",
    method: "POST",
    headers: {
        "Authorization": "Bearer <token>",
        "Accept": "application/json",
        "Content-Type": "application/json",
        "Content-Length": Buffer.byteLength(payload),
    },
}, (res) => {
    let data = "";
    res.on("data", (chunk) => (data += chunk));
    res.on("end", () => console.log(res.statusCode, JSON.parse(data)));
});

req.on("error", (err) => console.error(err));
req.write(payload);
req.end();
import requests

url = "https://cp.domain.com/api/v1/packages"
headers = {
    "Authorization": "Bearer <token>",
    "Accept": "application/json",
    "Content-Type": "application/json",
}
payload = {
    "name": "Starter",
}

response = requests.request("POST", url, headers=headers, json=payload)

print(response.status_code)
print(response.json())
import http.client
import json

conn = http.client.HTTPSConnection("cp.domain.com")
headers = {
    "Authorization": "Bearer <token>",
    "Accept": "application/json",
    "Content-Type": "application/json",
}
payload = json.dumps({
    "name": "Starter",
})

conn.request("POST", "/api/v1/packages", payload, headers)
response = conn.getresponse()

print(response.status)
print(json.loads(response.read()))
<?php

$curl = curl_init();

curl_setopt_array($curl, array(
    CURLOPT_URL => 'https://cp.domain.com/api/v1/packages',
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_ENCODING => '',
    CURLOPT_MAXREDIRS => 10,
    CURLOPT_TIMEOUT => 0,
    CURLOPT_FOLLOWLOCATION => true,
    CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
    CURLOPT_CUSTOMREQUEST => 'POST',
    CURLOPT_POSTFIELDS => json_encode([
        'name' => 'Starter',
    ]),
    CURLOPT_HTTPHEADER => array(
        'Authorization: Bearer <token>',
        'Accept: application/json',
        'Content-Type: application/json'
    ),
));

$response = curl_exec($curl);
curl_close($curl);

echo $response;
<?php

require 'vendor/autoload.php';

use GuzzleHttp\Client;

$client = new Client();

$response = $client->request('POST', 'https://cp.domain.com/api/v1/packages', [
    'headers' => [
        'Authorization' => 'Bearer <token>',
        'Accept' => 'application/json',
    ],
    'json' => [
        'name' => 'Starter',
    ],
]);

echo $response->getStatusCode() . "\n";
echo $response->getBody();
package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    url := "https://cp.domain.com/api/v1/packages"
    payload := strings.NewReader(`{
    "name": "Starter"
}`)
    req, _ := http.NewRequest("POST", url, payload)
    req.Header.Add("Authorization", "Bearer <token>")
    req.Header.Add("Accept", "application/json")
    req.Header.Add("Content-Type", "application/json")

    res, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer res.Body.Close()

    body, _ := io.ReadAll(res.Body)
    fmt.Println(res.StatusCode, string(body))
}
import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;

public class Main {
    public static void main(String[] args) throws Exception {
        HttpClient client = HttpClient.newHttpClient();

        HttpRequest request = HttpRequest.newBuilder()
            .uri(URI.create("https://cp.domain.com/api/v1/packages"))
            .header("Authorization", "Bearer <token>")
            .header("Accept", "application/json")
            .header("Content-Type", "application/json")
            .method("POST", HttpRequest.BodyPublishers.ofString("{\"name\":\"Starter\"}"))
            .build();

        HttpResponse<String> response = client.send(request, HttpResponse.BodyHandlers.ofString());
        System.out.println(response.statusCode());
        System.out.println(response.body());
    }
}
import okhttp3.*;

public class Main {
    public static void main(String[] args) throws Exception {
        OkHttpClient client = new OkHttpClient();

        MediaType json = MediaType.get("application/json");
        RequestBody body = RequestBody.create("{\"name\":\"Starter\"}", json);

        Request request = new Request.Builder()
            .url("https://cp.domain.com/api/v1/packages")
            .method("POST", body)
            .addHeader("Authorization", "Bearer <token>")
            .addHeader("Accept", "application/json")
            .build();

        try (Response response = client.newCall(request).execute()) {
            System.out.println(response.code());
            System.out.println(response.body().string());
        }
    }
}
using System.Net.Http;
using System.Net.Http.Headers;
using System.Text;

var client = new HttpClient();
var request = new HttpRequestMessage(new HttpMethod("POST"), "https://cp.domain.com/api/v1/packages");
request.Headers.Authorization = new AuthenticationHeaderValue("Bearer", "<token>");
request.Headers.Accept.Add(new MediaTypeWithQualityHeaderValue("application/json"));
request.Content = new StringContent("{\"name\":\"Starter\"}", Encoding.UTF8, "application/json");

var response = await client.SendAsync(request);
Console.WriteLine((int)response.StatusCode);
Console.WriteLine(await response.Content.ReadAsStringAsync());
require "net/http"
require "json"

uri = URI("https://cp.domain.com/api/v1/packages")
request = Net::HTTP::Post.new(uri)
request["Authorization"] = "Bearer <token>"
request["Accept"] = "application/json"
request["Content-Type"] = "application/json"
request.body = "{\"name\":\"Starter\"}"

response = Net::HTTP.start(uri.host, uri.port, use_ssl: true) do |http|
  http.request(request)
end

puts response.code
puts JSON.pretty_generate(JSON.parse(response.body))
import Foundation

var request = URLRequest(url: URL(string: "https://cp.domain.com/api/v1/packages")!)
request.httpMethod = "POST"
request.setValue("Bearer <token>", forHTTPHeaderField: "Authorization")
request.setValue("application/json", forHTTPHeaderField: "Accept")
request.setValue("application/json", forHTTPHeaderField: "Content-Type")
request.httpBody = "{\"name\":\"Starter\"}".data(using: .utf8)

let task = URLSession.shared.dataTask(with: request) { data, response, error in
    guard let data = data, error == nil else { print(error ?? "request failed"); return }
    print((response as! HTTPURLResponse).statusCode)
    print(String(data: data, encoding: .utf8) ?? "")
}
task.resume()
// Cargo.toml: reqwest = { version = "0.12", features = ["blocking", "json"] }, serde_json = "1"
use reqwest::blocking::Client;

fn main() -> Result<(), Box<dyn std::error::Error>> {
    let client = Client::new();
    let response = client
        .request(reqwest::Method::POST, "https://cp.domain.com/api/v1/packages")
        .bearer_auth("<token>")
        .header("Accept", "application/json")
        .header("Content-Type", "application/json")
        .body(r#"{
    "name": "Starter"
}"#)
        .send()?;

    println!("{}", response.status());
    let json: serde_json::Value = response.json()?;
    println!("{}", serde_json::to_string_pretty(&json)?);
    Ok(())
}
// Cargo.toml: reqwest = { version = "0.12", features = ["json"] }, tokio = { version = "1", features = ["full"] }, serde_json = "1"
use reqwest::Client;

#[tokio::main]
async fn main() -> Result<(), Box<dyn std::error::Error>> {
    let client = Client::new();
    let response = client
        .request(reqwest::Method::POST, "https://cp.domain.com/api/v1/packages")
        .bearer_auth("<token>")
        .header("Accept", "application/json")
        .header("Content-Type", "application/json")
        .body(r#"{
    "name": "Starter"
}"#)
        .send()
        .await?;

    println!("{}", response.status());
    let json: serde_json::Value = response.json().await?;
    println!("{}", serde_json::to_string_pretty(&json)?);
    Ok(())
}
import okhttp3.MediaType.Companion.toMediaType
import okhttp3.OkHttpClient
import okhttp3.Request
import okhttp3.RequestBody.Companion.toRequestBody

fun main() {
    val client = OkHttpClient()
    val body = """{
    "name": "Starter"
}""".toRequestBody("application/json".toMediaType())
    val request = Request.Builder()
        .url("https://cp.domain.com/api/v1/packages")
        .method("POST", body)
        .addHeader("Authorization", "Bearer <token>")
        .addHeader("Accept", "application/json")
        .build()

    client.newCall(request).execute().use { response ->
        println(response.code)
        println(response.body?.string())
    }
}
// pubspec.yaml: http: ^1.2.0
import 'dart:convert';
import 'package:http/http.dart' as http;

Future<void> main() async {
  final request = http.Request('POST', Uri.parse('https://cp.domain.com/api/v1/packages'));
  request.headers['Authorization'] = 'Bearer <token>';
  request.headers['Accept'] = 'application/json';
  request.headers['Content-Type'] = 'application/json';
  request.body = r'''{
    "name": "Starter"
}''';

  final response = await http.Response.fromStream(await request.send());
  print(response.statusCode);
  print(const JsonEncoder.withIndent('  ').convert(jsonDecode(response.body)));
}
#include <stdio.h>
#include <curl/curl.h>

int main(void) {
    CURL *curl = curl_easy_init();
    if (!curl) return 1;

    struct curl_slist *headers = NULL;
    headers = curl_slist_append(headers, "Authorization: Bearer <token>");
    headers = curl_slist_append(headers, "Accept: application/json");
    headers = curl_slist_append(headers, "Content-Type: application/json");

    curl_easy_setopt(curl, CURLOPT_URL, "https://cp.domain.com/api/v1/packages");
    curl_easy_setopt(curl, CURLOPT_CUSTOMREQUEST, "POST");
    curl_easy_setopt(curl, CURLOPT_HTTPHEADER, headers);
    curl_easy_setopt(curl, CURLOPT_POSTFIELDS, "{\"name\":\"Starter\"}");

    CURLcode result = curl_easy_perform(curl);
    if (result != CURLE_OK) fprintf(stderr, "%s\n", curl_easy_strerror(result));

    curl_slist_free_all(headers);
    curl_easy_cleanup(curl);
    return result == CURLE_OK ? 0 : 1;
}
$headers = @{
    Authorization = "Bearer <token>"
    Accept        = "application/json"
}

$body = @'
{
    "name": "Starter"
}
'@

$response = Invoke-RestMethod -Uri "https://cp.domain.com/api/v1/packages" -Method POST -Headers $headers -ContentType "application/json" -Body $body
$response | ConvertTo-Json -Depth 10
POST /api/v1/packages HTTP/1.1
Host: cp.domain.com
Authorization: Bearer <token>
Accept: application/json
Content-Type: application/json
Content-Length: 25

{
    "name": "Starter"
}
curl --location --request POST 'https://cp.domain.com/api/v1/packages' \
--header 'Authorization: Bearer <token>' \
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data-raw '{
    "name": "Medium",
    "enabled": true,
    "memory": 4096,
    "cpuCores": 2,
    "primaryStorage": 80,
    "traffic": 2000,
    "virtualization": {
        "cpuModel": "host-passthrough"
    },
    "templateCollections": [
        2
    ],
    "firewallRulesets": [
        7
    ]
}'
wget --quiet --output-document=- \
  --method=POST \
  --header='Authorization: Bearer <token>' \
  --header='Accept: application/json' \
  --header='Content-Type: application/json' \
  --body-data='{
    "name": "Medium",
    "enabled": true,
    "memory": 4096,
    "cpuCores": 2,
    "primaryStorage": 80,
    "traffic": 2000,
    "virtualization": {
        "cpuModel": "host-passthrough"
    },
    "templateCollections": [
        2
    ],
    "firewallRulesets": [
        7
    ]
}' \
  'https://cp.domain.com/api/v1/packages'
http POST 'https://cp.domain.com/api/v1/packages' \
  'Authorization: Bearer <token>' \
  'Accept: application/json' \
  'Content-Type: application/json' <<< '{
    "name": "Medium",
    "enabled": true,
    "memory": 4096,
    "cpuCores": 2,
    "primaryStorage": 80,
    "traffic": 2000,
    "virtualization": {
        "cpuModel": "host-passthrough"
    },
    "templateCollections": [
        2
    ],
    "firewallRulesets": [
        7
    ]
}'
const response = await fetch("https://cp.domain.com/api/v1/packages", {
    method: "POST",
    headers: {
        "Authorization": "Bearer <token>",
        "Accept": "application/json",
        "Content-Type": "application/json",
    },
    body: JSON.stringify({
        "name": "Medium",
        "enabled": true,
        "memory": 4096,
        "cpuCores": 2,
        "primaryStorage": 80,
        "traffic": 2000,
        "virtualization": {
            "cpuModel": "host-passthrough"
        },
        "templateCollections": [
            2
        ],
        "firewallRulesets": [
            7
        ]
    }),
});

const data = await response.json();
console.log(response.status, data);
import axios from "axios";

const response = await axios({
    method: "post",
    url: "https://cp.domain.com/api/v1/packages",
    headers: {
        "Authorization": "Bearer <token>",
        "Accept": "application/json",
        "Content-Type": "application/json",
    },
    data: {
        "name": "Medium",
        "enabled": true,
        "memory": 4096,
        "cpuCores": 2,
        "primaryStorage": 80,
        "traffic": 2000,
        "virtualization": {
            "cpuModel": "host-passthrough"
        },
        "templateCollections": [
            2
        ],
        "firewallRulesets": [
            7
        ]
    },
});

console.log(response.status, response.data);
const https = require("https");

const payload = JSON.stringify({
    "name": "Medium",
    "enabled": true,
    "memory": 4096,
    "cpuCores": 2,
    "primaryStorage": 80,
    "traffic": 2000,
    "virtualization": {
        "cpuModel": "host-passthrough"
    },
    "templateCollections": [
        2
    ],
    "firewallRulesets": [
        7
    ]
});

const req = https.request({
    hostname: "cp.domain.com",
    path: "/api/v1/packages",
    method: "POST",
    headers: {
        "Authorization": "Bearer <token>",
        "Accept": "application/json",
        "Content-Type": "application/json",
        "Content-Length": Buffer.byteLength(payload),
    },
}, (res) => {
    let data = "";
    res.on("data", (chunk) => (data += chunk));
    res.on("end", () => console.log(res.statusCode, JSON.parse(data)));
});

req.on("error", (err) => console.error(err));
req.write(payload);
req.end();
import requests

url = "https://cp.domain.com/api/v1/packages"
headers = {
    "Authorization": "Bearer <token>",
    "Accept": "application/json",
    "Content-Type": "application/json",
}
payload = {
    "name": "Medium",
    "enabled": True,
    "memory": 4096,
    "cpuCores": 2,
    "primaryStorage": 80,
    "traffic": 2000,
    "virtualization": {
        "cpuModel": "host-passthrough",
    },
    "templateCollections": [
        2,
    ],
    "firewallRulesets": [
        7,
    ],
}

response = requests.request("POST", url, headers=headers, json=payload)

print(response.status_code)
print(response.json())
import http.client
import json

conn = http.client.HTTPSConnection("cp.domain.com")
headers = {
    "Authorization": "Bearer <token>",
    "Accept": "application/json",
    "Content-Type": "application/json",
}
payload = json.dumps({
    "name": "Medium",
    "enabled": True,
    "memory": 4096,
    "cpuCores": 2,
    "primaryStorage": 80,
    "traffic": 2000,
    "virtualization": {
        "cpuModel": "host-passthrough",
    },
    "templateCollections": [
        2,
    ],
    "firewallRulesets": [
        7,
    ],
})

conn.request("POST", "/api/v1/packages", payload, headers)
response = conn.getresponse()

print(response.status)
print(json.loads(response.read()))
<?php

$curl = curl_init();

curl_setopt_array($curl, array(
    CURLOPT_URL => 'https://cp.domain.com/api/v1/packages',
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_ENCODING => '',
    CURLOPT_MAXREDIRS => 10,
    CURLOPT_TIMEOUT => 0,
    CURLOPT_FOLLOWLOCATION => true,
    CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
    CURLOPT_CUSTOMREQUEST => 'POST',
    CURLOPT_POSTFIELDS => json_encode([
        'name' => 'Medium',
        'enabled' => true,
        'memory' => 4096,
        'cpuCores' => 2,
        'primaryStorage' => 80,
        'traffic' => 2000,
        'virtualization' => [
            'cpuModel' => 'host-passthrough',
        ],
        'templateCollections' => [
            2,
        ],
        'firewallRulesets' => [
            7,
        ],
    ]),
    CURLOPT_HTTPHEADER => array(
        'Authorization: Bearer <token>',
        'Accept: application/json',
        'Content-Type: application/json'
    ),
));

$response = curl_exec($curl);
curl_close($curl);

echo $response;
<?php

require 'vendor/autoload.php';

use GuzzleHttp\Client;

$client = new Client();

$response = $client->request('POST', 'https://cp.domain.com/api/v1/packages', [
    'headers' => [
        'Authorization' => 'Bearer <token>',
        'Accept' => 'application/json',
    ],
    'json' => [
        'name' => 'Medium',
        'enabled' => true,
        'memory' => 4096,
        'cpuCores' => 2,
        'primaryStorage' => 80,
        'traffic' => 2000,
        'virtualization' => [
            'cpuModel' => 'host-passthrough',
        ],
        'templateCollections' => [
            2,
        ],
        'firewallRulesets' => [
            7,
        ],
    ],
]);

echo $response->getStatusCode() . "\n";
echo $response->getBody();
package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    url := "https://cp.domain.com/api/v1/packages"
    payload := strings.NewReader(`{
    "name": "Medium",
    "enabled": true,
    "memory": 4096,
    "cpuCores": 2,
    "primaryStorage": 80,
    "traffic": 2000,
    "virtualization": {
        "cpuModel": "host-passthrough"
    },
    "templateCollections": [
        2
    ],
    "firewallRulesets": [
        7
    ]
}`)
    req, _ := http.NewRequest("POST", url, payload)
    req.Header.Add("Authorization", "Bearer <token>")
    req.Header.Add("Accept", "application/json")
    req.Header.Add("Content-Type", "application/json")

    res, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer res.Body.Close()

    body, _ := io.ReadAll(res.Body)
    fmt.Println(res.StatusCode, string(body))
}
import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;

public class Main {
    public static void main(String[] args) throws Exception {
        HttpClient client = HttpClient.newHttpClient();

        HttpRequest request = HttpRequest.newBuilder()
            .uri(URI.create("https://cp.domain.com/api/v1/packages"))
            .header("Authorization", "Bearer <token>")
            .header("Accept", "application/json")
            .header("Content-Type", "application/json")
            .method("POST", HttpRequest.BodyPublishers.ofString("{\"name\":\"Medium\",\"enabled\":true,\"memory\":4096,\"cpuCores\":2,\"primaryStorage\":80,\"traffic\":2000,\"virtualization\":{\"cpuModel\":\"host-passthrough\"},\"templateCollections\":[2],\"firewallRulesets\":[7]}"))
            .build();

        HttpResponse<String> response = client.send(request, HttpResponse.BodyHandlers.ofString());
        System.out.println(response.statusCode());
        System.out.println(response.body());
    }
}
import okhttp3.*;

public class Main {
    public static void main(String[] args) throws Exception {
        OkHttpClient client = new OkHttpClient();

        MediaType json = MediaType.get("application/json");
        RequestBody body = RequestBody.create("{\"name\":\"Medium\",\"enabled\":true,\"memory\":4096,\"cpuCores\":2,\"primaryStorage\":80,\"traffic\":2000,\"virtualization\":{\"cpuModel\":\"host-passthrough\"},\"templateCollections\":[2],\"firewallRulesets\":[7]}", json);

        Request request = new Request.Builder()
            .url("https://cp.domain.com/api/v1/packages")
            .method("POST", body)
            .addHeader("Authorization", "Bearer <token>")
            .addHeader("Accept", "application/json")
            .build();

        try (Response response = client.newCall(request).execute()) {
            System.out.println(response.code());
            System.out.println(response.body().string());
        }
    }
}
using System.Net.Http;
using System.Net.Http.Headers;
using System.Text;

var client = new HttpClient();
var request = new HttpRequestMessage(new HttpMethod("POST"), "https://cp.domain.com/api/v1/packages");
request.Headers.Authorization = new AuthenticationHeaderValue("Bearer", "<token>");
request.Headers.Accept.Add(new MediaTypeWithQualityHeaderValue("application/json"));
request.Content = new StringContent("{\"name\":\"Medium\",\"enabled\":true,\"memory\":4096,\"cpuCores\":2,\"primaryStorage\":80,\"traffic\":2000,\"virtualization\":{\"cpuModel\":\"host-passthrough\"},\"templateCollections\":[2],\"firewallRulesets\":[7]}", Encoding.UTF8, "application/json");

var response = await client.SendAsync(request);
Console.WriteLine((int)response.StatusCode);
Console.WriteLine(await response.Content.ReadAsStringAsync());
require "net/http"
require "json"

uri = URI("https://cp.domain.com/api/v1/packages")
request = Net::HTTP::Post.new(uri)
request["Authorization"] = "Bearer <token>"
request["Accept"] = "application/json"
request["Content-Type"] = "application/json"
request.body = "{\"name\":\"Medium\",\"enabled\":true,\"memory\":4096,\"cpuCores\":2,\"primaryStorage\":80,\"traffic\":2000,\"virtualization\":{\"cpuModel\":\"host-passthrough\"},\"templateCollections\":[2],\"firewallRulesets\":[7]}"

response = Net::HTTP.start(uri.host, uri.port, use_ssl: true) do |http|
  http.request(request)
end

puts response.code
puts JSON.pretty_generate(JSON.parse(response.body))
import Foundation

var request = URLRequest(url: URL(string: "https://cp.domain.com/api/v1/packages")!)
request.httpMethod = "POST"
request.setValue("Bearer <token>", forHTTPHeaderField: "Authorization")
request.setValue("application/json", forHTTPHeaderField: "Accept")
request.setValue("application/json", forHTTPHeaderField: "Content-Type")
request.httpBody = "{\"name\":\"Medium\",\"enabled\":true,\"memory\":4096,\"cpuCores\":2,\"primaryStorage\":80,\"traffic\":2000,\"virtualization\":{\"cpuModel\":\"host-passthrough\"},\"templateCollections\":[2],\"firewallRulesets\":[7]}".data(using: .utf8)

let task = URLSession.shared.dataTask(with: request) { data, response, error in
    guard let data = data, error == nil else { print(error ?? "request failed"); return }
    print((response as! HTTPURLResponse).statusCode)
    print(String(data: data, encoding: .utf8) ?? "")
}
task.resume()
// Cargo.toml: reqwest = { version = "0.12", features = ["blocking", "json"] }, serde_json = "1"
use reqwest::blocking::Client;

fn main() -> Result<(), Box<dyn std::error::Error>> {
    let client = Client::new();
    let response = client
        .request(reqwest::Method::POST, "https://cp.domain.com/api/v1/packages")
        .bearer_auth("<token>")
        .header("Accept", "application/json")
        .header("Content-Type", "application/json")
        .body(r#"{
    "name": "Medium",
    "enabled": true,
    "memory": 4096,
    "cpuCores": 2,
    "primaryStorage": 80,
    "traffic": 2000,
    "virtualization": {
        "cpuModel": "host-passthrough"
    },
    "templateCollections": [
        2
    ],
    "firewallRulesets": [
        7
    ]
}"#)
        .send()?;

    println!("{}", response.status());
    let json: serde_json::Value = response.json()?;
    println!("{}", serde_json::to_string_pretty(&json)?);
    Ok(())
}
// Cargo.toml: reqwest = { version = "0.12", features = ["json"] }, tokio = { version = "1", features = ["full"] }, serde_json = "1"
use reqwest::Client;

#[tokio::main]
async fn main() -> Result<(), Box<dyn std::error::Error>> {
    let client = Client::new();
    let response = client
        .request(reqwest::Method::POST, "https://cp.domain.com/api/v1/packages")
        .bearer_auth("<token>")
        .header("Accept", "application/json")
        .header("Content-Type", "application/json")
        .body(r#"{
    "name": "Medium",
    "enabled": true,
    "memory": 4096,
    "cpuCores": 2,
    "primaryStorage": 80,
    "traffic": 2000,
    "virtualization": {
        "cpuModel": "host-passthrough"
    },
    "templateCollections": [
        2
    ],
    "firewallRulesets": [
        7
    ]
}"#)
        .send()
        .await?;

    println!("{}", response.status());
    let json: serde_json::Value = response.json().await?;
    println!("{}", serde_json::to_string_pretty(&json)?);
    Ok(())
}
import okhttp3.MediaType.Companion.toMediaType
import okhttp3.OkHttpClient
import okhttp3.Request
import okhttp3.RequestBody.Companion.toRequestBody

fun main() {
    val client = OkHttpClient()
    val body = """{
    "name": "Medium",
    "enabled": true,
    "memory": 4096,
    "cpuCores": 2,
    "primaryStorage": 80,
    "traffic": 2000,
    "virtualization": {
        "cpuModel": "host-passthrough"
    },
    "templateCollections": [
        2
    ],
    "firewallRulesets": [
        7
    ]
}""".toRequestBody("application/json".toMediaType())
    val request = Request.Builder()
        .url("https://cp.domain.com/api/v1/packages")
        .method("POST", body)
        .addHeader("Authorization", "Bearer <token>")
        .addHeader("Accept", "application/json")
        .build()

    client.newCall(request).execute().use { response ->
        println(response.code)
        println(response.body?.string())
    }
}
// pubspec.yaml: http: ^1.2.0
import 'dart:convert';
import 'package:http/http.dart' as http;

Future<void> main() async {
  final request = http.Request('POST', Uri.parse('https://cp.domain.com/api/v1/packages'));
  request.headers['Authorization'] = 'Bearer <token>';
  request.headers['Accept'] = 'application/json';
  request.headers['Content-Type'] = 'application/json';
  request.body = r'''{
    "name": "Medium",
    "enabled": true,
    "memory": 4096,
    "cpuCores": 2,
    "primaryStorage": 80,
    "traffic": 2000,
    "virtualization": {
        "cpuModel": "host-passthrough"
    },
    "templateCollections": [
        2
    ],
    "firewallRulesets": [
        7
    ]
}''';

  final response = await http.Response.fromStream(await request.send());
  print(response.statusCode);
  print(const JsonEncoder.withIndent('  ').convert(jsonDecode(response.body)));
}
#include <stdio.h>
#include <curl/curl.h>

int main(void) {
    CURL *curl = curl_easy_init();
    if (!curl) return 1;

    struct curl_slist *headers = NULL;
    headers = curl_slist_append(headers, "Authorization: Bearer <token>");
    headers = curl_slist_append(headers, "Accept: application/json");
    headers = curl_slist_append(headers, "Content-Type: application/json");

    curl_easy_setopt(curl, CURLOPT_URL, "https://cp.domain.com/api/v1/packages");
    curl_easy_setopt(curl, CURLOPT_CUSTOMREQUEST, "POST");
    curl_easy_setopt(curl, CURLOPT_HTTPHEADER, headers);
    curl_easy_setopt(curl, CURLOPT_POSTFIELDS, "{\"name\":\"Medium\",\"enabled\":true,\"memory\":4096,\"cpuCores\":2,\"primaryStorage\":80,\"traffic\":2000,\"virtualization\":{\"cpuModel\":\"host-passthrough\"},\"templateCollections\":[2],\"firewallRulesets\":[7]}");

    CURLcode result = curl_easy_perform(curl);
    if (result != CURLE_OK) fprintf(stderr, "%s\n", curl_easy_strerror(result));

    curl_slist_free_all(headers);
    curl_easy_cleanup(curl);
    return result == CURLE_OK ? 0 : 1;
}
$headers = @{
    Authorization = "Bearer <token>"
    Accept        = "application/json"
}

$body = @'
{
    "name": "Medium",
    "enabled": true,
    "memory": 4096,
    "cpuCores": 2,
    "primaryStorage": 80,
    "traffic": 2000,
    "virtualization": {
        "cpuModel": "host-passthrough"
    },
    "templateCollections": [
        2
    ],
    "firewallRulesets": [
        7
    ]
}
'@

$response = Invoke-RestMethod -Uri "https://cp.domain.com/api/v1/packages" -Method POST -Headers $headers -ContentType "application/json" -Body $body
$response | ConvertTo-Json -Depth 10
POST /api/v1/packages HTTP/1.1
Host: cp.domain.com
Authorization: Bearer <token>
Accept: application/json
Content-Type: application/json
Content-Length: 290

{
    "name": "Medium",
    "enabled": true,
    "memory": 4096,
    "cpuCores": 2,
    "primaryStorage": 80,
    "traffic": 2000,
    "virtualization": {
        "cpuModel": "host-passthrough"
    },
    "templateCollections": [
        2
    ],
    "firewallRulesets": [
        7
    ]
}

Responses

201

Created.

#
application/json
object

A server package. trafficPolicy carries the per-package traffic policy overrides; null values inherit.

Package fields
descriptionstring#nullable
idinteger#
namestring#
enabledboolean#
memoryinteger#
primaryStorageinteger#
trafficinteger#
trafficPolicyobject#
Since 7.1.0
fields
trafficCountDirectioninteger#

Which direction counts towards the allowance.

ValueMeaning
0Inherit from the hypervisor, then the global setting
1Inbound and outbound
2Inbound only
3Outbound only
Since 7.1.0
trafficLimitActioninteger#nullable

What happens when the allowance is reached.

ValueMeaning
1Nothing
2Throttle the network
nullInherit
Since 7.1.0
trafficLimitThrottleIninteger#nullable

Inbound throttle speed in kB/s; null inherits.

Since 7.1.0
trafficLimitThrottleOutinteger#nullable

Outbound throttle speed in kB/s; null inherits.

Since 7.1.0
trafficLimitNotification1integer#nullable

First usage alert as a percentage of the allowance; null inherits.

Since 7.1.0
trafficLimitNotification2integer#nullable

Second usage alert as a percentage of the allowance; null inherits.

Since 7.1.0
cpuCoresinteger#
primaryNetworkSpeedIninteger#
primaryNetworkSpeedOutinteger#
primaryDiskTypestring#
backupPlanIdinteger#
primaryStorageReadBytesSecinteger#nullable
primaryStorageWriteBytesSecinteger#nullable
primaryStorageReadIopsSecinteger#nullable
primaryStorageWriteIopsSecinteger#nullable
primaryStorageProfileinteger#
primaryNetworkProfileinteger#
createdstring <date-time>#
updatedstring <date-time>#nullable
primaryStorageProfileNamestring#nullable

The name of the storage profile primaryStorageProfile refers to. Read-only.

primaryNetworkProfileNamestring#nullable

The name of the network profile primaryNetworkProfile refers to. Read-only.

selfServiceDescriptionstring#nullable

The longer description shown in self service.

tokenValueinteger#
backupTypestring#

What Backup Manager access servers built from the package get.

Allowed values:inheritdisabledscheduledviewAndRestorefullmanual
PackageVirtualization fields
cpuModelstring#

inherit, or a CPU model name the Control Server offers.

machineTypestring#
Allowed values:inheritpcq35
pciPortsinteger#
Range: 10 to 32
cpuSharesinteger#
Range: 2 to 262144
cpuTopologyobject#
fields
enabledboolean#
socketsinteger#
Range: 1 to 36
coresinteger#
Range: 1 to 128
threadsinteger#
Range: 1 to 36
forceIpv6boolean#
additionalDisksarray[PackageAdditionalDisk]#

The two optional extra disks, slot 1 and slot 2, always both present.

PackageAdditionalDisk fields
slotinteger#

Which of the two extra disks. Required on write; a slot not sent is unchanged.

Allowed values:12
enabledboolean#
sizeGbinteger#
Range: 1 to 102400
formatstring#
Allowed values:inheritqcow2raw
storageProfileinteger#
Range: 0 to 20
qosobject#

Limits for the disk; null means unlimited.

fields
readIopsinteger#nullable
writeIopsinteger#nullable
readBytesinteger#nullable
writeBytesinteger#nullable
PackageSelfService fields
ipv4Addressesinteger#

IPv4 addresses a self-service server gets.

Range: 0 to 5
displayobject#

Text shown in self service instead of the raw figures; null shows the figure.

fields
namestring#nullable
memorystring#nullable
storagestring#nullable
coresstring#nullable
trafficstring#nullable
variableobject#

Sizes a self-service user may pick from, as real values. An empty list with a null default means the resource is not variable.

fields
PackageVariableChoice fields
optionsarray[integer]#

The offered sizes, ascending. A size the Control Server does not offer is refused, naming the nearest it does.

defaultinteger#nullable

One of the options, or null.

PackageVariableChoice fields
optionsarray[integer]#

The offered sizes, ascending. A size the Control Server does not offer is refused, naming the nearest it does.

defaultinteger#nullable

One of the options, or null.

PackageVariableChoice fields
optionsarray[integer]#

The offered sizes, ascending. A size the Control Server does not offer is refused, naming the nearest it does.

defaultinteger#nullable

One of the options, or null.

templateCollectionsarray[object]#

In order.

item fields
idinteger#
namestring#
firewallRulesetsarray[object]#

In order. Their rules are copied to a server built from the package.

item fields
idinteger#
namestring#
hypervisorAssetGroupsarray[object]#

In order.

item fields
idinteger#
namestring#
typestring#
Allowed values:devicecpu
Example
{
    "data": {
        "id": 7,
        "name": "Medium",
        "description": "Two cores, 4 GB",
        "enabled": true,
        "memory": 4096,
        "primaryStorage": 80,
        "traffic": 2000,
        "trafficPolicy": {
            "trafficCountDirection": 0,
            "trafficLimitAction": 2,
            "trafficLimitThrottleIn": 1000,
            "trafficLimitThrottleOut": null,
            "trafficLimitNotification1": null,
            "trafficLimitNotification2": null
        },
        "cpuCores": 2,
        "primaryNetworkSpeedIn": 100,
        "primaryNetworkSpeedOut": 100,
        "primaryDiskType": "qcow2",
        "backupPlanId": 5,
        "primaryStorageReadBytesSec": null,
        "primaryStorageWriteBytesSec": null,
        "primaryStorageReadIopsSec": 5000,
        "primaryStorageWriteIopsSec": null,
        "primaryStorageProfile": 1,
        "primaryStorageProfileName": "Fast NVMe",
        "primaryNetworkProfile": 0,
        "primaryNetworkProfileName": "Any",
        "selfServiceDescription": "Good for web",
        "tokenValue": 10,
        "backupType": "full",
        "virtualization": {
            "cpuModel": "host-passthrough",
            "machineType": "q35",
            "pciPorts": 20,
            "cpuShares": 2048,
            "cpuTopology": {
                "enabled": true,
                "sockets": 1,
                "cores": 2,
                "threads": 1
            },
            "forceIpv6": false
        },
        "additionalDisks": [
            {
                "slot": 1,
                "enabled": true,
                "sizeGb": 50,
                "format": "raw",
                "storageProfile": 1,
                "qos": {
                    "readIops": 3000,
                    "writeIops": null,
                    "readBytes": null,
                    "writeBytes": null
                }
            },
            {
                "slot": 2,
                "enabled": false,
                "sizeGb": 10,
                "format": "inherit",
                "storageProfile": 0,
                "qos": {
                    "readIops": null,
                    "writeIops": null,
                    "readBytes": null,
                    "writeBytes": null
                }
            }
        ],
        "selfService": {
            "ipv4Addresses": 2,
            "display": {
                "name": "Medium VPS",
                "memory": null,
                "storage": null,
                "cores": null,
                "traffic": null
            },
            "variable": {
                "memoryMb": {
                    "options": [
                        2048,
                        4096,
                        8192
                    ],
                    "default": 4096
                },
                "storageGb": {
                    "options": [],
                    "default": null
                },
                "cores": {
                    "options": [],
                    "default": null
                }
            }
        },
        "templateCollections": [
            {
                "id": 2,
                "name": "Windows"
            }
        ],
        "firewallRulesets": [
            {
                "id": 7,
                "name": "Web"
            }
        ],
        "hypervisorAssetGroups": [
            {
                "id": 4,
                "name": "Pinned cores",
                "type": "cpu"
            }
        ],
        "created": "2026-10-07T09:14:02.000000Z",
        "updated": "2026-10-07T09:20:11+00:00"
    }
}
401

The bearer token is missing, invalid, or expired. The response has no body.

#
No response body.
422

Validation failed, or a read-only or unknown field was sent. Nothing was written.

#
application/json
errorsobject#
Example
{
    "errors": {
        "memory": [
            "must be a whole number from 64 to 2097152"
        ]
    }
}
429

Too many requests. Either the token's requests per minute are used up (see the `X-RateL…

#
application/json

Too many requests. Either the token's requests per minute are used up (see the X-RateLimit-* headers) or the calling address has failed authentication 10 times in a minute (the body then includes retry_after_seconds). Retry-After gives the seconds to wait.

object
errorsarray[string]#
retry_after_secondsinteger#

Seconds to wait before retrying. Present on the failed-authentication limit only.

Response headers
Retry-Afterinteger

Seconds to wait before retrying.

X-RateLimit-Limitinteger

The token's requests per minute (token limit only).

X-RateLimit-Remaininginteger

Requests left in the current minute (token limit only).

X-RateLimit-Resetinteger

Unix timestamp at which the minute resets (token limit only).

Examples
{
    "errors": [
        "Too Many Requests"
    ]
}
{
    "errors": [
        "Too many authentication attempts. Try again later."
    ],
    "retry_after_seconds": 42
}