curl --request POST \
--url https://console.advinservers.com/api/v1/client/isos \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "Debian 12.7 netinst",
"link": "https://cdimage.debian.org/debian-cd/12.7.0/amd64/iso-cd/debian-12.7.0-amd64-netinst.iso"
}
'import requests
url = "https://console.advinservers.com/api/v1/client/isos"
payload = {
"name": "Debian 12.7 netinst",
"link": "https://cdimage.debian.org/debian-cd/12.7.0/amd64/iso-cd/debian-12.7.0-amd64-netinst.iso"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'Debian 12.7 netinst',
link: 'https://cdimage.debian.org/debian-cd/12.7.0/amd64/iso-cd/debian-12.7.0-amd64-netinst.iso'
})
};
fetch('https://console.advinservers.com/api/v1/client/isos', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://console.advinservers.com/api/v1/client/isos",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'Debian 12.7 netinst',
'link' => 'https://cdimage.debian.org/debian-cd/12.7.0/amd64/iso-cd/debian-12.7.0-amd64-netinst.iso'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://console.advinservers.com/api/v1/client/isos"
payload := strings.NewReader("{\n \"name\": \"Debian 12.7 netinst\",\n \"link\": \"https://cdimage.debian.org/debian-cd/12.7.0/amd64/iso-cd/debian-12.7.0-amd64-netinst.iso\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://console.advinservers.com/api/v1/client/isos")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"Debian 12.7 netinst\",\n \"link\": \"https://cdimage.debian.org/debian-cd/12.7.0/amd64/iso-cd/debian-12.7.0-amd64-netinst.iso\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://console.advinservers.com/api/v1/client/isos")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"Debian 12.7 netinst\",\n \"link\": \"https://cdimage.debian.org/debian-cd/12.7.0/amd64/iso-cd/debian-12.7.0-amd64-netinst.iso\"\n}"
response = http.request(request)
puts response.read_body{
"uuid": "a015fe1c-a2a8-44e4-b188-05736ce42b26",
"name": "Debian 12.7 netinst",
"file_name": "client-67d74fbd-2dc5-4f95-a946-c504a98f59fb-zfqyW1HhtBAj.iso",
"size": 661651456,
"is_successful": null,
"status": "downloading",
"is_preparing": false,
"mounted_server_count": 0,
"mounted_on_this_server": false,
"mounted_on_other_servers_count": 0,
"mounted_servers": [],
"can_delete": true,
"owned_by_server_owner": true,
"completed_at": null,
"created_at": "2026-09-14T16:42:09.000000Z",
"download_progress": 0,
"download_started_at": null
}{
"message": "Unauthenticated."
}{
"message": "This API key is not allowed to do that in this team. It needs the \"snapshot.delete\" permission."
}{
"message": "The name field is required.",
"errors": {}
}{
"message": "Too Many Attempts."
}Download an ISO
Overview
Starts downloading an ISO from a public URL for use by servers in the same team. Returns immediately with status set to downloading, completed_at set to null and download_progress set to 0. Poll GET /api/v1/client/isos until the status is ready or failed.
Downloads must be enabled (quota.download_enabled). Only one download per account can run at a time, and total storage cannot exceed 10 GiB. Rejected requests explain which condition failed.
Send a name of up to 40 characters and the file URL as link. The file size is checked against the account’s remaining storage before downloading.
Permissions
Requires the iso.update (Manage ISO images) permission for the selected team. Resources outside that team return 404.
curl --request POST \
--url https://console.advinservers.com/api/v1/client/isos \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "Debian 12.7 netinst",
"link": "https://cdimage.debian.org/debian-cd/12.7.0/amd64/iso-cd/debian-12.7.0-amd64-netinst.iso"
}
'import requests
url = "https://console.advinservers.com/api/v1/client/isos"
payload = {
"name": "Debian 12.7 netinst",
"link": "https://cdimage.debian.org/debian-cd/12.7.0/amd64/iso-cd/debian-12.7.0-amd64-netinst.iso"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'Debian 12.7 netinst',
link: 'https://cdimage.debian.org/debian-cd/12.7.0/amd64/iso-cd/debian-12.7.0-amd64-netinst.iso'
})
};
fetch('https://console.advinservers.com/api/v1/client/isos', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://console.advinservers.com/api/v1/client/isos",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'Debian 12.7 netinst',
'link' => 'https://cdimage.debian.org/debian-cd/12.7.0/amd64/iso-cd/debian-12.7.0-amd64-netinst.iso'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://console.advinservers.com/api/v1/client/isos"
payload := strings.NewReader("{\n \"name\": \"Debian 12.7 netinst\",\n \"link\": \"https://cdimage.debian.org/debian-cd/12.7.0/amd64/iso-cd/debian-12.7.0-amd64-netinst.iso\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://console.advinservers.com/api/v1/client/isos")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"Debian 12.7 netinst\",\n \"link\": \"https://cdimage.debian.org/debian-cd/12.7.0/amd64/iso-cd/debian-12.7.0-amd64-netinst.iso\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://console.advinservers.com/api/v1/client/isos")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"Debian 12.7 netinst\",\n \"link\": \"https://cdimage.debian.org/debian-cd/12.7.0/amd64/iso-cd/debian-12.7.0-amd64-netinst.iso\"\n}"
response = http.request(request)
puts response.read_body{
"uuid": "a015fe1c-a2a8-44e4-b188-05736ce42b26",
"name": "Debian 12.7 netinst",
"file_name": "client-67d74fbd-2dc5-4f95-a946-c504a98f59fb-zfqyW1HhtBAj.iso",
"size": 661651456,
"is_successful": null,
"status": "downloading",
"is_preparing": false,
"mounted_server_count": 0,
"mounted_on_this_server": false,
"mounted_on_other_servers_count": 0,
"mounted_servers": [],
"can_delete": true,
"owned_by_server_owner": true,
"completed_at": null,
"created_at": "2026-09-14T16:42:09.000000Z",
"download_progress": 0,
"download_started_at": null
}{
"message": "Unauthenticated."
}{
"message": "This API key is not allowed to do that in this team. It needs the \"snapshot.delete\" permission."
}{
"message": "The name field is required.",
"errors": {}
}{
"message": "Too Many Attempts."
}Authorizations
Your API key, sent as a bearer token. Create one in the control panel under API Keys, give it only the permissions the integration needs, and copy it when it is created. It cannot be shown again. Each key is restricted to one owned team. The key determines the team for every request.
Body
Send a JSON object containing the fields below. Required fields are marked in the schema.
Response
The record, as a JSON object. There is no envelope.
An ISO image stored for the customer.
The uuid UUID.
"ec4fa5b5-cc7c-4fcf-b280-ee55eca8d44b"
The name shown to customers.
"Ubuntu 24.04.1 Live Server"
The value of file_name.
"client-67d74fbd-2dc5-4f95-a946-c504a98f59fb-pASjFJotP7rB.iso"
The value of size.
2774532096
Null until the download finishes, which is a third state and not a failure: a row created the moment a fetch is queued has never been written to. Published as null and kept that way.
true
The value of status.
downloading, failed, ready "ready"
The download has finished and the image is being prepared for mounting.
false
The total number of servers using this image, including servers outside the current team. The image cannot be deleted while mounted.
1
The value of mounted_on_this_server.
true
The number of mounted on other servers count.
0
Visible servers using this image. Empty without deletion permission. The mount count may be higher because it includes inaccessible servers.
Show child attributes
Show child attributes
[
{
"uuid": "ecc6f4f1-c89b-4dce-a20b-a330641c5b0b",
"name": "lambda-core",
"windows": false,
"template_name": "Ubuntu 24.04",
"template_icon_url": "https://img.icons8.com/color/48/ubuntu.png"
}
]
Whether the customer can delete.
true
False only for a member of staff's own image showing up on a customer's server. Account-level listings are all the viewer's own, so nothing there is ever flagged.
true
A string, not a date object, and deliberately so: the column carries no datetime cast, so this has always gone out as MySQL wrote it ("2026-08-19 18:20:41") rather than in the ISO-8601 form created_at below uses. Two formats in one payload is not a design, it is what is published, and changing it would move a date under every caller that parses it.
"2026-09-10 13:27:41"
The date and time for created at, in UTC.
"2026-09-03T04:21:17.000000Z"
"2026-09-10T13:25:01.000000Z"
Percent, and zero rather than null while nothing has started.
100
The date and time for download started at, in UTC.
"2026-09-03T04:21:17.000000Z"
"2026-09-10T13:25:04.000000Z"