Update an ISO
Since 7.1.0Change an ISO's settings. Send only the fields to change; a GET can be sent back once its read-only members are removed.
Try it
Sent from this browser to your panel with your token. Changes live data.
⌘↵Request
Authorization
Authorization header when making requests to protected resources.Example:
Authorization: Bearer ********************Body Paramsapplication/json#
The fields to change.
Where the hypervisor downloads the image from the first time it is needed. http or https.
Letters, digits, dashes and underscores, unique in the library; the hypervisor stores it as <filename>.iso.
0 any, 1 x86_64, 2 aarch64. A server can mount an ISO whose arch is 0 or its hypervisor's.
Needs url and filename set.
{
"enabled": false,
"description": "Superseded by the 13.1 image"
}Request Code Samples
curl --location --request PUT 'https://cp.domain.com/api/v1/media/iso/12' \
--header 'Authorization: Bearer <token>' \
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data-raw '{
"enabled": false,
"description": "Superseded by the 13.1 image"
}'wget --quiet --output-document=- \
--method=PUT \
--header='Authorization: Bearer <token>' \
--header='Accept: application/json' \
--header='Content-Type: application/json' \
--body-data='{
"enabled": false,
"description": "Superseded by the 13.1 image"
}' \
'https://cp.domain.com/api/v1/media/iso/12'http PUT 'https://cp.domain.com/api/v1/media/iso/12' \
'Authorization: Bearer <token>' \
'Accept: application/json' \
'Content-Type: application/json' <<< '{
"enabled": false,
"description": "Superseded by the 13.1 image"
}'const response = await fetch("https://cp.domain.com/api/v1/media/iso/12", {
method: "PUT",
headers: {
"Authorization": "Bearer <token>",
"Accept": "application/json",
"Content-Type": "application/json",
},
body: JSON.stringify({
"enabled": false,
"description": "Superseded by the 13.1 image"
}),
});
const data = await response.json();
console.log(response.status, data);import axios from "axios";
const response = await axios({
method: "put",
url: "https://cp.domain.com/api/v1/media/iso/12",
headers: {
"Authorization": "Bearer <token>",
"Accept": "application/json",
"Content-Type": "application/json",
},
data: {
"enabled": false,
"description": "Superseded by the 13.1 image"
},
});
console.log(response.status, response.data);const https = require("https");
const payload = JSON.stringify({
"enabled": false,
"description": "Superseded by the 13.1 image"
});
const req = https.request({
hostname: "cp.domain.com",
path: "/api/v1/media/iso/12",
method: "PUT",
headers: {
"Authorization": "Bearer <token>",
"Accept": "application/json",
"Content-Type": "application/json",
"Content-Length": Buffer.byteLength(payload),
},
}, (res) => {
let data = "";
res.on("data", (chunk) => (data += chunk));
res.on("end", () => console.log(res.statusCode, JSON.parse(data)));
});
req.on("error", (err) => console.error(err));
req.write(payload);
req.end();import requests
url = "https://cp.domain.com/api/v1/media/iso/12"
headers = {
"Authorization": "Bearer <token>",
"Accept": "application/json",
"Content-Type": "application/json",
}
payload = {
"enabled": False,
"description": "Superseded by the 13.1 image",
}
response = requests.request("PUT", url, headers=headers, json=payload)
print(response.status_code)
print(response.json())import http.client
import json
conn = http.client.HTTPSConnection("cp.domain.com")
headers = {
"Authorization": "Bearer <token>",
"Accept": "application/json",
"Content-Type": "application/json",
}
payload = json.dumps({
"enabled": False,
"description": "Superseded by the 13.1 image",
})
conn.request("PUT", "/api/v1/media/iso/12", payload, headers)
response = conn.getresponse()
print(response.status)
print(json.loads(response.read()))<?php
$curl = curl_init();
curl_setopt_array($curl, array(
CURLOPT_URL => 'https://cp.domain.com/api/v1/media/iso/12',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => '',
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 0,
CURLOPT_FOLLOWLOCATION => true,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => 'PUT',
CURLOPT_POSTFIELDS => json_encode([
'enabled' => false,
'description' => 'Superseded by the 13.1 image',
]),
CURLOPT_HTTPHEADER => array(
'Authorization: Bearer <token>',
'Accept: application/json',
'Content-Type: application/json'
),
));
$response = curl_exec($curl);
curl_close($curl);
echo $response;<?php
require 'vendor/autoload.php';
use GuzzleHttp\Client;
$client = new Client();
$response = $client->request('PUT', 'https://cp.domain.com/api/v1/media/iso/12', [
'headers' => [
'Authorization' => 'Bearer <token>',
'Accept' => 'application/json',
],
'json' => [
'enabled' => false,
'description' => 'Superseded by the 13.1 image',
],
]);
echo $response->getStatusCode() . "\n";
echo $response->getBody();package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
url := "https://cp.domain.com/api/v1/media/iso/12"
payload := strings.NewReader(`{
"enabled": false,
"description": "Superseded by the 13.1 image"
}`)
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Accept", "application/json")
req.Header.Add("Content-Type", "application/json")
res, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(res.StatusCode, string(body))
}import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Main {
public static void main(String[] args) throws Exception {
HttpClient client = HttpClient.newHttpClient();
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://cp.domain.com/api/v1/media/iso/12"))
.header("Authorization", "Bearer <token>")
.header("Accept", "application/json")
.header("Content-Type", "application/json")
.method("PUT", HttpRequest.BodyPublishers.ofString("{\"enabled\":false,\"description\":\"Superseded by the 13.1 image\"}"))
.build();
HttpResponse<String> response = client.send(request, HttpResponse.BodyHandlers.ofString());
System.out.println(response.statusCode());
System.out.println(response.body());
}
}import okhttp3.*;
public class Main {
public static void main(String[] args) throws Exception {
OkHttpClient client = new OkHttpClient();
MediaType json = MediaType.get("application/json");
RequestBody body = RequestBody.create("{\"enabled\":false,\"description\":\"Superseded by the 13.1 image\"}", json);
Request request = new Request.Builder()
.url("https://cp.domain.com/api/v1/media/iso/12")
.method("PUT", body)
.addHeader("Authorization", "Bearer <token>")
.addHeader("Accept", "application/json")
.build();
try (Response response = client.newCall(request).execute()) {
System.out.println(response.code());
System.out.println(response.body().string());
}
}
}using System.Net.Http;
using System.Net.Http.Headers;
using System.Text;
var client = new HttpClient();
var request = new HttpRequestMessage(new HttpMethod("PUT"), "https://cp.domain.com/api/v1/media/iso/12");
request.Headers.Authorization = new AuthenticationHeaderValue("Bearer", "<token>");
request.Headers.Accept.Add(new MediaTypeWithQualityHeaderValue("application/json"));
request.Content = new StringContent("{\"enabled\":false,\"description\":\"Superseded by the 13.1 image\"}", Encoding.UTF8, "application/json");
var response = await client.SendAsync(request);
Console.WriteLine((int)response.StatusCode);
Console.WriteLine(await response.Content.ReadAsStringAsync());require "net/http"
require "json"
uri = URI("https://cp.domain.com/api/v1/media/iso/12")
request = Net::HTTP::Put.new(uri)
request["Authorization"] = "Bearer <token>"
request["Accept"] = "application/json"
request["Content-Type"] = "application/json"
request.body = "{\"enabled\":false,\"description\":\"Superseded by the 13.1 image\"}"
response = Net::HTTP.start(uri.host, uri.port, use_ssl: true) do |http|
http.request(request)
end
puts response.code
puts JSON.pretty_generate(JSON.parse(response.body))import Foundation
var request = URLRequest(url: URL(string: "https://cp.domain.com/api/v1/media/iso/12")!)
request.httpMethod = "PUT"
request.setValue("Bearer <token>", forHTTPHeaderField: "Authorization")
request.setValue("application/json", forHTTPHeaderField: "Accept")
request.setValue("application/json", forHTTPHeaderField: "Content-Type")
request.httpBody = "{\"enabled\":false,\"description\":\"Superseded by the 13.1 image\"}".data(using: .utf8)
let task = URLSession.shared.dataTask(with: request) { data, response, error in
guard let data = data, error == nil else { print(error ?? "request failed"); return }
print((response as! HTTPURLResponse).statusCode)
print(String(data: data, encoding: .utf8) ?? "")
}
task.resume()// Cargo.toml: reqwest = { version = "0.12", features = ["blocking", "json"] }, serde_json = "1"
use reqwest::blocking::Client;
fn main() -> Result<(), Box<dyn std::error::Error>> {
let client = Client::new();
let response = client
.request(reqwest::Method::PUT, "https://cp.domain.com/api/v1/media/iso/12")
.bearer_auth("<token>")
.header("Accept", "application/json")
.header("Content-Type", "application/json")
.body(r#"{
"enabled": false,
"description": "Superseded by the 13.1 image"
}"#)
.send()?;
println!("{}", response.status());
let json: serde_json::Value = response.json()?;
println!("{}", serde_json::to_string_pretty(&json)?);
Ok(())
}// Cargo.toml: reqwest = { version = "0.12", features = ["json"] }, tokio = { version = "1", features = ["full"] }, serde_json = "1"
use reqwest::Client;
#[tokio::main]
async fn main() -> Result<(), Box<dyn std::error::Error>> {
let client = Client::new();
let response = client
.request(reqwest::Method::PUT, "https://cp.domain.com/api/v1/media/iso/12")
.bearer_auth("<token>")
.header("Accept", "application/json")
.header("Content-Type", "application/json")
.body(r#"{
"enabled": false,
"description": "Superseded by the 13.1 image"
}"#)
.send()
.await?;
println!("{}", response.status());
let json: serde_json::Value = response.json().await?;
println!("{}", serde_json::to_string_pretty(&json)?);
Ok(())
}import okhttp3.MediaType.Companion.toMediaType
import okhttp3.OkHttpClient
import okhttp3.Request
import okhttp3.RequestBody.Companion.toRequestBody
fun main() {
val client = OkHttpClient()
val body = """{
"enabled": false,
"description": "Superseded by the 13.1 image"
}""".toRequestBody("application/json".toMediaType())
val request = Request.Builder()
.url("https://cp.domain.com/api/v1/media/iso/12")
.method("PUT", body)
.addHeader("Authorization", "Bearer <token>")
.addHeader("Accept", "application/json")
.build()
client.newCall(request).execute().use { response ->
println(response.code)
println(response.body?.string())
}
}// pubspec.yaml: http: ^1.2.0
import 'dart:convert';
import 'package:http/http.dart' as http;
Future<void> main() async {
final request = http.Request('PUT', Uri.parse('https://cp.domain.com/api/v1/media/iso/12'));
request.headers['Authorization'] = 'Bearer <token>';
request.headers['Accept'] = 'application/json';
request.headers['Content-Type'] = 'application/json';
request.body = r'''{
"enabled": false,
"description": "Superseded by the 13.1 image"
}''';
final response = await http.Response.fromStream(await request.send());
print(response.statusCode);
print(const JsonEncoder.withIndent(' ').convert(jsonDecode(response.body)));
}#include <stdio.h>
#include <curl/curl.h>
int main(void) {
CURL *curl = curl_easy_init();
if (!curl) return 1;
struct curl_slist *headers = NULL;
headers = curl_slist_append(headers, "Authorization: Bearer <token>");
headers = curl_slist_append(headers, "Accept: application/json");
headers = curl_slist_append(headers, "Content-Type: application/json");
curl_easy_setopt(curl, CURLOPT_URL, "https://cp.domain.com/api/v1/media/iso/12");
curl_easy_setopt(curl, CURLOPT_CUSTOMREQUEST, "PUT");
curl_easy_setopt(curl, CURLOPT_HTTPHEADER, headers);
curl_easy_setopt(curl, CURLOPT_POSTFIELDS, "{\"enabled\":false,\"description\":\"Superseded by the 13.1 image\"}");
CURLcode result = curl_easy_perform(curl);
if (result != CURLE_OK) fprintf(stderr, "%s\n", curl_easy_strerror(result));
curl_slist_free_all(headers);
curl_easy_cleanup(curl);
return result == CURLE_OK ? 0 : 1;
}$headers = @{
Authorization = "Bearer <token>"
Accept = "application/json"
}
$body = @'
{
"enabled": false,
"description": "Superseded by the 13.1 image"
}
'@
$response = Invoke-RestMethod -Uri "https://cp.domain.com/api/v1/media/iso/12" -Method PUT -Headers $headers -ContentType "application/json" -Body $body
$response | ConvertTo-Json -Depth 10PUT /api/v1/media/iso/12 HTTP/1.1
Host: cp.domain.com
Authorization: Bearer <token>
Accept: application/json
Content-Type: application/json
Content-Length: 75
{
"enabled": false,
"description": "Superseded by the 13.1 image"
}Responses
200The ISO as GET returns it.
#
An ISO in the media library, as GET /media/iso/{isoId} returns it.
ISO fields
Stored as given by the installer; nothing writes it through the API.
Available to every user. When false, only the users under users can mount it.
Stored and shown; nothing reads it today.
The users a non-global ISO is assigned to.
{
"data": {
"id": 12,
"name": "Debian 13 netinst",
"description": "Net installer",
"arch": 1,
"url": "https://cdn.example.net/debian-13-netinst.iso",
"filename": "debian-13-netinst",
"enabled": true,
"config": "[]",
"global": false,
"download": true,
"users": [
{
"id": 9,
"email": "owner@example.net",
"name": "Owner",
"enabled": true,
"added": "2026-10-07T09:14:02.000000Z"
}
],
"created": "2026-10-07T09:14:02+00:00",
"updated": "2026-10-07T09:20:11+00:00"
}
}401The bearer token is missing, invalid, or expired. The response has no body.
#
404The ISO was not found.
#
{
"msg": "iso not found"
}422Validation failed, the body had no fields, a read-only or unknown field was sent, or `e…
#
Validation failed, the body had no fields, a read-only or unknown field was sent, or enabled was set before url and filename. Nothing was written.
{
"errors": {
"enabled": [
"set url and filename before enabling the ISO"
]
}
}429Too many requests. Either the token's requests per minute are used up (see the `X-RateL…
#
Too many requests. Either the token's requests per minute are used up (see the X-RateLimit-* headers) or the calling address has failed authentication 10 times in a minute (the body then includes retry_after_seconds). Retry-After gives the seconds to wait.
Seconds to wait before retrying. Present on the failed-authentication limit only.
Seconds to wait before retrying.
The token's requests per minute (token limit only).
Requests left in the current minute (token limit only).
Unix timestamp at which the minute resets (token limit only).
{
"errors": [
"Too Many Requests"
]
}{
"errors": [
"Too many authentication attempts. Try again later."
],
"retry_after_seconds": 42
}