Media

Update an ISO

Since 7.1.0
PUT/media/iso/{isoId}

Change an ISO's settings. Send only the fields to change; a GET can be sent back once its read-only members are removed.

Request

Authorization
Provide your bearer token in the Authorization header when making requests to protected resources.
Example: Authorization: Bearer ********************
Path Params#
isoIdinteger#required

A valid ISO ID as shown in VirtFusion.

Example: 12
Body Paramsapplication/json#

The fields to change.

namestring#
Length: 3 to 150 characters
descriptionstring#nullable
Length: at most 500 characters
urlstring#

Where the hypervisor downloads the image from the first time it is needed. http or https.

Length: at most 2000 characters
filenamestring#

Letters, digits, dashes and underscores, unique in the library; the hypervisor stores it as <filename>.iso.

Length: at most 300 characters
archinteger#

0 any, 1 x86_64, 2 aarch64. A server can mount an ISO whose arch is 0 or its hypervisor's.

Allowed values:012
enabledboolean#

Needs url and filename set.

globalboolean#
downloadboolean#
Example
{
    "enabled": false,
    "description": "Superseded by the 13.1 image"
}

Request Code Samples

curl --location --request PUT 'https://cp.domain.com/api/v1/media/iso/12' \
--header 'Authorization: Bearer <token>' \
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data-raw '{
    "enabled": false,
    "description": "Superseded by the 13.1 image"
}'
wget --quiet --output-document=- \
  --method=PUT \
  --header='Authorization: Bearer <token>' \
  --header='Accept: application/json' \
  --header='Content-Type: application/json' \
  --body-data='{
    "enabled": false,
    "description": "Superseded by the 13.1 image"
}' \
  'https://cp.domain.com/api/v1/media/iso/12'
http PUT 'https://cp.domain.com/api/v1/media/iso/12' \
  'Authorization: Bearer <token>' \
  'Accept: application/json' \
  'Content-Type: application/json' <<< '{
    "enabled": false,
    "description": "Superseded by the 13.1 image"
}'
const response = await fetch("https://cp.domain.com/api/v1/media/iso/12", {
    method: "PUT",
    headers: {
        "Authorization": "Bearer <token>",
        "Accept": "application/json",
        "Content-Type": "application/json",
    },
    body: JSON.stringify({
        "enabled": false,
        "description": "Superseded by the 13.1 image"
    }),
});

const data = await response.json();
console.log(response.status, data);
import axios from "axios";

const response = await axios({
    method: "put",
    url: "https://cp.domain.com/api/v1/media/iso/12",
    headers: {
        "Authorization": "Bearer <token>",
        "Accept": "application/json",
        "Content-Type": "application/json",
    },
    data: {
        "enabled": false,
        "description": "Superseded by the 13.1 image"
    },
});

console.log(response.status, response.data);
const https = require("https");

const payload = JSON.stringify({
    "enabled": false,
    "description": "Superseded by the 13.1 image"
});

const req = https.request({
    hostname: "cp.domain.com",
    path: "/api/v1/media/iso/12",
    method: "PUT",
    headers: {
        "Authorization": "Bearer <token>",
        "Accept": "application/json",
        "Content-Type": "application/json",
        "Content-Length": Buffer.byteLength(payload),
    },
}, (res) => {
    let data = "";
    res.on("data", (chunk) => (data += chunk));
    res.on("end", () => console.log(res.statusCode, JSON.parse(data)));
});

req.on("error", (err) => console.error(err));
req.write(payload);
req.end();
import requests

url = "https://cp.domain.com/api/v1/media/iso/12"
headers = {
    "Authorization": "Bearer <token>",
    "Accept": "application/json",
    "Content-Type": "application/json",
}
payload = {
    "enabled": False,
    "description": "Superseded by the 13.1 image",
}

response = requests.request("PUT", url, headers=headers, json=payload)

print(response.status_code)
print(response.json())
import http.client
import json

conn = http.client.HTTPSConnection("cp.domain.com")
headers = {
    "Authorization": "Bearer <token>",
    "Accept": "application/json",
    "Content-Type": "application/json",
}
payload = json.dumps({
    "enabled": False,
    "description": "Superseded by the 13.1 image",
})

conn.request("PUT", "/api/v1/media/iso/12", payload, headers)
response = conn.getresponse()

print(response.status)
print(json.loads(response.read()))
<?php

$curl = curl_init();

curl_setopt_array($curl, array(
    CURLOPT_URL => 'https://cp.domain.com/api/v1/media/iso/12',
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_ENCODING => '',
    CURLOPT_MAXREDIRS => 10,
    CURLOPT_TIMEOUT => 0,
    CURLOPT_FOLLOWLOCATION => true,
    CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
    CURLOPT_CUSTOMREQUEST => 'PUT',
    CURLOPT_POSTFIELDS => json_encode([
        'enabled' => false,
        'description' => 'Superseded by the 13.1 image',
    ]),
    CURLOPT_HTTPHEADER => array(
        'Authorization: Bearer <token>',
        'Accept: application/json',
        'Content-Type: application/json'
    ),
));

$response = curl_exec($curl);
curl_close($curl);

echo $response;
<?php

require 'vendor/autoload.php';

use GuzzleHttp\Client;

$client = new Client();

$response = $client->request('PUT', 'https://cp.domain.com/api/v1/media/iso/12', [
    'headers' => [
        'Authorization' => 'Bearer <token>',
        'Accept' => 'application/json',
    ],
    'json' => [
        'enabled' => false,
        'description' => 'Superseded by the 13.1 image',
    ],
]);

echo $response->getStatusCode() . "\n";
echo $response->getBody();
package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    url := "https://cp.domain.com/api/v1/media/iso/12"
    payload := strings.NewReader(`{
    "enabled": false,
    "description": "Superseded by the 13.1 image"
}`)
    req, _ := http.NewRequest("PUT", url, payload)
    req.Header.Add("Authorization", "Bearer <token>")
    req.Header.Add("Accept", "application/json")
    req.Header.Add("Content-Type", "application/json")

    res, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer res.Body.Close()

    body, _ := io.ReadAll(res.Body)
    fmt.Println(res.StatusCode, string(body))
}
import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;

public class Main {
    public static void main(String[] args) throws Exception {
        HttpClient client = HttpClient.newHttpClient();

        HttpRequest request = HttpRequest.newBuilder()
            .uri(URI.create("https://cp.domain.com/api/v1/media/iso/12"))
            .header("Authorization", "Bearer <token>")
            .header("Accept", "application/json")
            .header("Content-Type", "application/json")
            .method("PUT", HttpRequest.BodyPublishers.ofString("{\"enabled\":false,\"description\":\"Superseded by the 13.1 image\"}"))
            .build();

        HttpResponse<String> response = client.send(request, HttpResponse.BodyHandlers.ofString());
        System.out.println(response.statusCode());
        System.out.println(response.body());
    }
}
import okhttp3.*;

public class Main {
    public static void main(String[] args) throws Exception {
        OkHttpClient client = new OkHttpClient();

        MediaType json = MediaType.get("application/json");
        RequestBody body = RequestBody.create("{\"enabled\":false,\"description\":\"Superseded by the 13.1 image\"}", json);

        Request request = new Request.Builder()
            .url("https://cp.domain.com/api/v1/media/iso/12")
            .method("PUT", body)
            .addHeader("Authorization", "Bearer <token>")
            .addHeader("Accept", "application/json")
            .build();

        try (Response response = client.newCall(request).execute()) {
            System.out.println(response.code());
            System.out.println(response.body().string());
        }
    }
}
using System.Net.Http;
using System.Net.Http.Headers;
using System.Text;

var client = new HttpClient();
var request = new HttpRequestMessage(new HttpMethod("PUT"), "https://cp.domain.com/api/v1/media/iso/12");
request.Headers.Authorization = new AuthenticationHeaderValue("Bearer", "<token>");
request.Headers.Accept.Add(new MediaTypeWithQualityHeaderValue("application/json"));
request.Content = new StringContent("{\"enabled\":false,\"description\":\"Superseded by the 13.1 image\"}", Encoding.UTF8, "application/json");

var response = await client.SendAsync(request);
Console.WriteLine((int)response.StatusCode);
Console.WriteLine(await response.Content.ReadAsStringAsync());
require "net/http"
require "json"

uri = URI("https://cp.domain.com/api/v1/media/iso/12")
request = Net::HTTP::Put.new(uri)
request["Authorization"] = "Bearer <token>"
request["Accept"] = "application/json"
request["Content-Type"] = "application/json"
request.body = "{\"enabled\":false,\"description\":\"Superseded by the 13.1 image\"}"

response = Net::HTTP.start(uri.host, uri.port, use_ssl: true) do |http|
  http.request(request)
end

puts response.code
puts JSON.pretty_generate(JSON.parse(response.body))
import Foundation

var request = URLRequest(url: URL(string: "https://cp.domain.com/api/v1/media/iso/12")!)
request.httpMethod = "PUT"
request.setValue("Bearer <token>", forHTTPHeaderField: "Authorization")
request.setValue("application/json", forHTTPHeaderField: "Accept")
request.setValue("application/json", forHTTPHeaderField: "Content-Type")
request.httpBody = "{\"enabled\":false,\"description\":\"Superseded by the 13.1 image\"}".data(using: .utf8)

let task = URLSession.shared.dataTask(with: request) { data, response, error in
    guard let data = data, error == nil else { print(error ?? "request failed"); return }
    print((response as! HTTPURLResponse).statusCode)
    print(String(data: data, encoding: .utf8) ?? "")
}
task.resume()
// Cargo.toml: reqwest = { version = "0.12", features = ["blocking", "json"] }, serde_json = "1"
use reqwest::blocking::Client;

fn main() -> Result<(), Box<dyn std::error::Error>> {
    let client = Client::new();
    let response = client
        .request(reqwest::Method::PUT, "https://cp.domain.com/api/v1/media/iso/12")
        .bearer_auth("<token>")
        .header("Accept", "application/json")
        .header("Content-Type", "application/json")
        .body(r#"{
    "enabled": false,
    "description": "Superseded by the 13.1 image"
}"#)
        .send()?;

    println!("{}", response.status());
    let json: serde_json::Value = response.json()?;
    println!("{}", serde_json::to_string_pretty(&json)?);
    Ok(())
}
// Cargo.toml: reqwest = { version = "0.12", features = ["json"] }, tokio = { version = "1", features = ["full"] }, serde_json = "1"
use reqwest::Client;

#[tokio::main]
async fn main() -> Result<(), Box<dyn std::error::Error>> {
    let client = Client::new();
    let response = client
        .request(reqwest::Method::PUT, "https://cp.domain.com/api/v1/media/iso/12")
        .bearer_auth("<token>")
        .header("Accept", "application/json")
        .header("Content-Type", "application/json")
        .body(r#"{
    "enabled": false,
    "description": "Superseded by the 13.1 image"
}"#)
        .send()
        .await?;

    println!("{}", response.status());
    let json: serde_json::Value = response.json().await?;
    println!("{}", serde_json::to_string_pretty(&json)?);
    Ok(())
}
import okhttp3.MediaType.Companion.toMediaType
import okhttp3.OkHttpClient
import okhttp3.Request
import okhttp3.RequestBody.Companion.toRequestBody

fun main() {
    val client = OkHttpClient()
    val body = """{
    "enabled": false,
    "description": "Superseded by the 13.1 image"
}""".toRequestBody("application/json".toMediaType())
    val request = Request.Builder()
        .url("https://cp.domain.com/api/v1/media/iso/12")
        .method("PUT", body)
        .addHeader("Authorization", "Bearer <token>")
        .addHeader("Accept", "application/json")
        .build()

    client.newCall(request).execute().use { response ->
        println(response.code)
        println(response.body?.string())
    }
}
// pubspec.yaml: http: ^1.2.0
import 'dart:convert';
import 'package:http/http.dart' as http;

Future<void> main() async {
  final request = http.Request('PUT', Uri.parse('https://cp.domain.com/api/v1/media/iso/12'));
  request.headers['Authorization'] = 'Bearer <token>';
  request.headers['Accept'] = 'application/json';
  request.headers['Content-Type'] = 'application/json';
  request.body = r'''{
    "enabled": false,
    "description": "Superseded by the 13.1 image"
}''';

  final response = await http.Response.fromStream(await request.send());
  print(response.statusCode);
  print(const JsonEncoder.withIndent('  ').convert(jsonDecode(response.body)));
}
#include <stdio.h>
#include <curl/curl.h>

int main(void) {
    CURL *curl = curl_easy_init();
    if (!curl) return 1;

    struct curl_slist *headers = NULL;
    headers = curl_slist_append(headers, "Authorization: Bearer <token>");
    headers = curl_slist_append(headers, "Accept: application/json");
    headers = curl_slist_append(headers, "Content-Type: application/json");

    curl_easy_setopt(curl, CURLOPT_URL, "https://cp.domain.com/api/v1/media/iso/12");
    curl_easy_setopt(curl, CURLOPT_CUSTOMREQUEST, "PUT");
    curl_easy_setopt(curl, CURLOPT_HTTPHEADER, headers);
    curl_easy_setopt(curl, CURLOPT_POSTFIELDS, "{\"enabled\":false,\"description\":\"Superseded by the 13.1 image\"}");

    CURLcode result = curl_easy_perform(curl);
    if (result != CURLE_OK) fprintf(stderr, "%s\n", curl_easy_strerror(result));

    curl_slist_free_all(headers);
    curl_easy_cleanup(curl);
    return result == CURLE_OK ? 0 : 1;
}
$headers = @{
    Authorization = "Bearer <token>"
    Accept        = "application/json"
}

$body = @'
{
    "enabled": false,
    "description": "Superseded by the 13.1 image"
}
'@

$response = Invoke-RestMethod -Uri "https://cp.domain.com/api/v1/media/iso/12" -Method PUT -Headers $headers -ContentType "application/json" -Body $body
$response | ConvertTo-Json -Depth 10
PUT /api/v1/media/iso/12 HTTP/1.1
Host: cp.domain.com
Authorization: Bearer <token>
Accept: application/json
Content-Type: application/json
Content-Length: 75

{
    "enabled": false,
    "description": "Superseded by the 13.1 image"
}

Responses

200

The ISO as GET returns it.

#
application/json
object
dataISO#

An ISO in the media library, as GET /media/iso/{isoId} returns it.

ISO fields
idinteger#
namestring#
descriptionstring#nullable
archinteger#
urlstring#
filenamestring#
enabledboolean#
configstring#

Stored as given by the installer; nothing writes it through the API.

globalboolean#

Available to every user. When false, only the users under users can mount it.

downloadboolean#

Stored and shown; nothing reads it today.

usersarray[object]#

The users a non-global ISO is assigned to.

item fields
idinteger#
emailstring#
namestring#
enabledboolean#
addedstring <date-time>#
createdstring <date-time>#
updatedstring <date-time>#
Example
{
    "data": {
        "id": 12,
        "name": "Debian 13 netinst",
        "description": "Net installer",
        "arch": 1,
        "url": "https://cdn.example.net/debian-13-netinst.iso",
        "filename": "debian-13-netinst",
        "enabled": true,
        "config": "[]",
        "global": false,
        "download": true,
        "users": [
            {
                "id": 9,
                "email": "owner@example.net",
                "name": "Owner",
                "enabled": true,
                "added": "2026-10-07T09:14:02.000000Z"
            }
        ],
        "created": "2026-10-07T09:14:02+00:00",
        "updated": "2026-10-07T09:20:11+00:00"
    }
}
401

The bearer token is missing, invalid, or expired. The response has no body.

#
No response body.
404

The ISO was not found.

#
application/json
msgstring#
Example
{
    "msg": "iso not found"
}
422

Validation failed, the body had no fields, a read-only or unknown field was sent, or `e…

#
application/json

Validation failed, the body had no fields, a read-only or unknown field was sent, or enabled was set before url and filename. Nothing was written.

errorsobject#
Example
{
    "errors": {
        "enabled": [
            "set url and filename before enabling the ISO"
        ]
    }
}
429

Too many requests. Either the token's requests per minute are used up (see the `X-RateL…

#
application/json

Too many requests. Either the token's requests per minute are used up (see the X-RateLimit-* headers) or the calling address has failed authentication 10 times in a minute (the body then includes retry_after_seconds). Retry-After gives the seconds to wait.

object
errorsarray[string]#
retry_after_secondsinteger#

Seconds to wait before retrying. Present on the failed-authentication limit only.

Response headers
Retry-Afterinteger

Seconds to wait before retrying.

X-RateLimit-Limitinteger

The token's requests per minute (token limit only).

X-RateLimit-Remaininginteger

Requests left in the current minute (token limit only).

X-RateLimit-Resetinteger

Unix timestamp at which the minute resets (token limit only).

Examples
{
    "errors": [
        "Too Many Requests"
    ]
}
{
    "errors": [
        "Too many authentication attempts. Try again later."
    ],
    "retry_after_seconds": 42
}