> ## Documentation Index
> Fetch the complete documentation index at: https://docs.advinservers.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Download an ISO

> ### Overview

Starts downloading an ISO from a public URL for use by servers in the same team. Returns immediately with `status` set to `downloading`, `completed_at` set to null and `download_progress` set to 0. Poll `GET /api/v1/client/isos` until the status is `ready` or `failed`.

Downloads must be enabled (`quota.download_enabled`). Only one download per account can run at a time, and total storage cannot exceed 10 GiB. Rejected requests explain which condition failed.

Send a `name` of up to 40 characters and the file URL as `link`. The file size is checked against the account's remaining storage before downloading.

### Permissions

Requires the `iso.update` (Manage ISO images) permission for the selected team. Resources outside that team return 404.



## OpenAPI

````yaml https://console.advinservers.com/docs/openapi.json post /isos
openapi: 3.1.0
info:
  title: API reference
  version: 1.0.0
  description: >-
    Use this API to manage your team's servers, networks, backups, and other
    resources.


    ## Authentication


    Create an API key under **API Keys** and send it as a bearer token with
    every request:


    ```

    Authorization: Bearer {YOUR_API_KEY}

    Accept: application/json

    ```


    Copy the key when you create it. It cannot be shown again. Revoking a key
    takes effect immediately.


    ## Permissions


    Give each key only the permissions it needs. Every endpoint lists the
    required permission.


    Permissions cover servers and other resources in the key's team.


    ## Team scope


    A key can access resources in the team selected when it was created. This
    includes servers,

    snapshots, backups, firewall groups, images, SSH keys, scripts, networks and
    addresses.

    Resources in other teams return `404 Not Found`. Create a separate key for
    each team.


    The key determines the team for every request. Legacy keys that had no team
    are assigned

    to the account's first owned team.


    ## Actions that need the panel


    API keys cannot do the following, even with every permission. Sign in to the
    panel in a

    browser to do them:


    - Create, edit or revoke API keys

    - Edit the IP groups that restrict API keys

    - End signed-in sessions

    - Change two-factor authentication

    - Change the account's email address

    - Accept or decline team invitations

    - Switch or leave a team


    This keeps a leaked key from widening its own access or locking you out of
    your account.


    ## Source IP restrictions


    A key can be restricted to one or more IP groups. Requests from other
    addresses are rejected.


    ## Requests and responses


    Each endpoint lists its path, query, header, and body parameters. Examples
    use fictional data.


    Single records use JSON objects. Collections use JSON arrays unless the
    endpoint supports pagination. Timestamps use ISO 8601 in UTC.


    Error responses include `message`. Validation errors also include an
    `errors` object for each field. Each endpoint lists its status codes.


    ## Audit log


    Every API request, including reads, is recorded in the account audit log
    with the key that made it.
servers:
  - url: https://console.advinservers.com/api/v1/client
security:
  - http: []
tags:
  - name: Account
    description: Billing contact details and account setup progress.
  - name: Account activity
    description: Actions performed in the current team by people and API keys.
  - name: Servers
    description: >-
      Order and list servers, read their state and resource use, open a console,
      and control power.
  - name: Server settings
    description: >-
      Rename a server, rebuild it, and change its hardware, media, resolvers and
      credentials.
  - name: Backups
    description: Scheduled server copies stored separately from the server.
  - name: Snapshots
    description: >-
      Take, restore and move server snapshots. Snapshots are kept in snapshot
      storage that the team buys by the GiB.
  - name: Firewall groups
    description: Reusable sets of firewall rules, and the servers they apply to.
  - name: IP groups
    description: Reusable source address lists for firewall rules.
  - name: Server firewall
    description: >-
      Read default traffic policies and rules managed outside your firewall
      groups.
  - name: IP addresses
    description: Manage floating IPs and server address assignments.
  - name: Private networks
    description: Connect servers over a private network in the same location.
  - name: Reverse DNS
    description: Set the hostnames returned by IP address lookups.
  - name: DDoS protection
    description: Configure attack filtering for server addresses.
  - name: Bandwidth
    description: Buy extra bandwidth and share it between servers or location pools.
  - name: SSH keys
    description: Public keys the account can install on a server when it is built.
  - name: Setup scripts
    description: Scripts the account can run on a server when it is built.
  - name: ISO images
    description: ISO images you have downloaded, and the servers they are mounted on.
  - name: Server upgrades
    description: Change an existing server's plan.
  - name: Checkout
    description: Choose a payment method and pay for a purchase.
  - name: Invoices
    description: View and pay account invoices.
  - name: Billing
    description: Manage service renewals, payment methods and account credit.
  - name: Transfers
    description: Move resources between teams or transfer ownership.
  - name: Teams
    description: Manage the team assigned to your API key.
  - name: Team members
    description: Invite people and manage their team access.
  - name: Team roles
    description: Define the permissions granted to team members.
  - name: Team activity
    description: View actions performed in a team.
  - name: Support tickets
    description: >-
      Open, read, reply to and close support tickets. Tickets belong to the
      account holder and are not shared with team members.
paths:
  /isos:
    post:
      tags:
        - ISO images
      summary: Download an ISO
      description: >-
        ### Overview


        Starts downloading an ISO from a public URL for use by servers in the
        same team. Returns immediately with `status` set to `downloading`,
        `completed_at` set to null and `download_progress` set to 0. Poll `GET
        /api/v1/client/isos` until the status is `ready` or `failed`.


        Downloads must be enabled (`quota.download_enabled`). Only one download
        per account can run at a time, and total storage cannot exceed 10 GiB.
        Rejected requests explain which condition failed.


        Send a `name` of up to 40 characters and the file URL as `link`. The
        file size is checked against the account's remaining storage before
        downloading.


        ### Permissions


        Requires the `iso.update` (Manage ISO images) permission for the
        selected team. Resources outside that team return 404.
      operationId: iso.store
      requestBody:
        description: >-
          Send a JSON object containing the fields below. Required fields are
          marked in the schema.
        required: true
        content:
          application/json:
            schema:
              examples:
                - name: Debian 12.7 netinst
                  link: >-
                    https://cdimage.debian.org/debian-cd/12.7.0/amd64/iso-cd/debian-12.7.0-amd64-netinst.iso
              allOf:
                - $ref: '#/components/schemas/StoreIsoRequest'
      responses:
        '200':
          description: The record, as a JSON object. There is no envelope.
          content:
            application/json:
              schema:
                examples:
                  - uuid: a015fe1c-a2a8-44e4-b188-05736ce42b26
                    name: Debian 12.7 netinst
                    file_name: >-
                      client-67d74fbd-2dc5-4f95-a946-c504a98f59fb-zfqyW1HhtBAj.iso
                    size: 661651456
                    is_successful: null
                    status: downloading
                    is_preparing: false
                    mounted_server_count: 0
                    mounted_on_this_server: false
                    mounted_on_other_servers_count: 0
                    mounted_servers: []
                    can_delete: true
                    owned_by_server_owner: true
                    completed_at: null
                    created_at: '2026-09-14T16:42:09.000000Z'
                    download_progress: 0
                    download_started_at: null
                allOf:
                  - $ref: '#/components/schemas/IsoData'
        '401':
          description: >-
            The key was missing, malformed, revoked, or belongs to an account
            that no longer exists.
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    examples:
                      - Unauthenticated.
                required:
                  - message
        '403':
          description: >-
            Access denied. Check the key's team, permissions and allowed IP
            addresses. Some actions, such as managing API keys, require a
            browser session. The response message explains the reason.
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    examples:
                      - >-
                        This API key is not allowed to do that in this team. It
                        needs the "snapshot.delete" permission.
                required:
                  - message
        '422':
          description: >-
            A field is missing or invalid, or the resource cannot accept this
            change in its current state. Check `message` for details. Field
            validation also includes an `errors` object keyed by field name.
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    description: >-
                      A summary of the validation error or the reason the change
                      was refused.
                    examples:
                      - The name field is required.
                  errors:
                    type: object
                    description: Validation errors grouped by field name.
                    additionalProperties:
                      type: array
                      items:
                        type: string
                required:
                  - message
        '429':
          description: >-
            Too many requests. The `Retry-After` header says how many seconds to
            wait. Limits are per account, so several keys on one account share
            them.
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    examples:
                      - Too Many Attempts.
                required:
                  - message
components:
  schemas:
    StoreIsoRequest:
      type: object
      examples:
        - name: Debian 12.7 netinst
          link: >-
            https://cdimage.debian.org/debian-cd/12.7.0/amd64/iso-cd/debian-12.7.0-amd64-netinst.iso
      properties:
        name:
          type: string
          description: The name shown to customers.
          minLength: 1
          maxLength: 40
        link:
          type: string
          format: uri
          description: The value of `link`.
          maxLength: 2048
      required:
        - name
        - link
      title: StoreIsoRequest
    IsoData:
      type: object
      description: An ISO image stored for the customer.
      examples:
        - uuid: ec4fa5b5-cc7c-4fcf-b280-ee55eca8d44b
          name: Ubuntu 24.04.1 Live Server
          file_name: client-67d74fbd-2dc5-4f95-a946-c504a98f59fb-pASjFJotP7rB.iso
          size: 2774532096
          is_successful: true
          status: ready
          is_preparing: false
          mounted_server_count: 1
          mounted_on_this_server: true
          mounted_on_other_servers_count: 0
          mounted_servers:
            - uuid: ecc6f4f1-c89b-4dce-a20b-a330641c5b0b
              name: lambda-core
              windows: false
              template_name: Ubuntu 24.04
              template_icon_url: https://img.icons8.com/color/48/ubuntu.png
          can_delete: true
          owned_by_server_owner: true
          completed_at: '2026-09-10 13:27:41'
          created_at: '2026-09-10T13:25:01.000000Z'
          download_progress: 100
          download_started_at: '2026-09-10T13:25:04.000000Z'
      properties:
        uuid:
          type: string
          description: The uuid UUID.
          examples:
            - ec4fa5b5-cc7c-4fcf-b280-ee55eca8d44b
        name:
          type: string
          description: The name shown to customers.
          examples:
            - Ubuntu 24.04.1 Live Server
        file_name:
          type:
            - string
            - 'null'
          description: The value of `file_name`.
          examples:
            - client-67d74fbd-2dc5-4f95-a946-c504a98f59fb-pASjFJotP7rB.iso
        size:
          type:
            - integer
            - 'null'
          description: The value of `size`.
          examples:
            - 2774532096
        is_successful:
          type:
            - boolean
            - 'null'
          description: >-
            Null until the download finishes, which is a third state and not a
            failure: a row created the moment a fetch is queued has never been
            written to. Published as null and kept that way.
          examples:
            - true
        status:
          type: string
          description: The value of `status`.
          enum:
            - downloading
            - failed
            - ready
          examples:
            - ready
        is_preparing:
          type: boolean
          description: >-
            The download has finished and the image is being prepared for
            mounting.
          examples:
            - false
        mounted_server_count:
          type: integer
          description: >-
            The total number of servers using this image, including servers
            outside the current team. The image cannot be deleted while mounted.
          examples:
            - 1
        mounted_on_this_server:
          type: boolean
          description: The value of `mounted_on_this_server`.
          examples:
            - true
        mounted_on_other_servers_count:
          type: integer
          description: The number of mounted on other servers count.
          examples:
            - 0
        mounted_servers:
          type: array
          description: >-
            Visible servers using this image. Empty without deletion permission.
            The mount count may be higher because it includes inaccessible
            servers.
          examples:
            - - uuid: ecc6f4f1-c89b-4dce-a20b-a330641c5b0b
                name: lambda-core
                windows: false
                template_name: Ubuntu 24.04
                template_icon_url: https://img.icons8.com/color/48/ubuntu.png
          items:
            $ref: '#/components/schemas/IsoMountedServerData'
        can_delete:
          type: boolean
          description: Whether the customer can delete.
          examples:
            - true
        owned_by_server_owner:
          type: boolean
          description: >-
            False only for a member of staff's own image showing up on a
            customer's server. Account-level listings are all the viewer's own,
            so nothing there is ever flagged.
          examples:
            - true
        completed_at:
          type:
            - string
            - 'null'
          description: >-
            A string, not a date object, and deliberately so: the column carries
            no `datetime` cast, so this has always gone out as MySQL wrote it
            ("2026-08-19 18:20:41") rather than in the ISO-8601 form
            `created_at` below uses. Two formats in one payload is not a design,
            it is what is published, and changing it would move a date under
            every caller that parses it.
          examples:
            - '2026-09-10 13:27:41'
        created_at:
          type:
            - string
            - 'null'
          format: date-time
          description: The date and time for created at, in UTC.
          examples:
            - '2026-09-03T04:21:17.000000Z'
            - '2026-09-10T13:25:01.000000Z'
        download_progress:
          type: integer
          description: Percent, and zero rather than null while nothing has started.
          examples:
            - 100
        download_started_at:
          type:
            - string
            - 'null'
          format: date-time
          description: The date and time for download started at, in UTC.
          examples:
            - '2026-09-03T04:21:17.000000Z'
            - '2026-09-10T13:25:04.000000Z'
      required:
        - uuid
        - name
        - file_name
        - size
        - is_successful
        - status
        - is_preparing
        - mounted_server_count
        - mounted_on_this_server
        - mounted_on_other_servers_count
        - mounted_servers
        - can_delete
        - owned_by_server_owner
        - completed_at
        - created_at
        - download_progress
        - download_started_at
      title: IsoData
    IsoMountedServerData:
      type: object
      description: A server that currently has the ISO mounted.
      examples:
        - uuid: ecc6f4f1-c89b-4dce-a20b-a330641c5b0b
          name: lambda-core
          windows: false
          template_name: Ubuntu 24.04
          template_icon_url: https://img.icons8.com/color/48/ubuntu.png
      properties:
        uuid:
          type: string
          description: The uuid UUID.
          examples:
            - ecc6f4f1-c89b-4dce-a20b-a330641c5b0b
        name:
          type: string
          description: The name shown to customers.
          examples:
            - lambda-core
        windows:
          type: boolean
          description: The value of `windows`.
          examples:
            - false
        template_name:
          type:
            - string
            - 'null'
          description: The value of `template_name`.
          examples:
            - Ubuntu 24.04
        template_icon_url:
          type:
            - string
            - 'null'
          description: >-
            The custom icon a customer set, falling back to the template's. Read
            through the model so the places that draw a server's icon cannot
            disagree about which one wins.
          examples:
            - https://img.icons8.com/color/48/ubuntu.png
      required:
        - uuid
        - name
        - windows
        - template_name
        - template_icon_url
      title: IsoMountedServerData
  securitySchemes:
    http:
      type: http
      description: >-
        Your API key, sent as a bearer token. Create one in the control panel
        under API Keys, give it only the permissions the integration needs, and
        copy it when it is created. It cannot be shown again. Each key is
        restricted to one owned team. The key determines the team for every
        request.
      scheme: bearer

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.