API Overview¶
Appliku exposes a REST API that powers the web dashboard, the CLI, and the Python SDK. You can use the same API to build your own integrations and automation.
Base URL¶
All API endpoints are served over HTTPS.
Authentication¶
API requests are authenticated using API tokens. Include your token in the Authorization header with the Token prefix:
Note
The Token prefix is what an API token needs. Bearer is for JWT access tokens issued to the dashboard, not for API tokens.
Generating an API Token¶
- Log into the Appliku dashboard
- Go to Account Settings
- Navigate to the API Tokens section
- Click Generate New Token
- Choose an access level: Full access (read and write), Read-only (read requests only; any write returns a
403), or Custom (pick exactly which resources and actions the token can perform) - Copy the token and store it securely
Warning
A full-access token can read and change everything in your account. Treat tokens like passwords: do not commit them to version control or share them in public channels. If a token only needs a subset of access, create it as Read-only or Custom and grant only what it needs.
Token Permission Levels¶
Every token carries a set of (resource, action) grants where the actions are Read, Create, Update, and Delete. When creating a token, you choose one of three permission levels:
- Full access: grants every action on every resource. This is the default.
- Read-only: grants Read on every resource. The token can list resources, view details, and fetch logs, but cannot create, update, or delete anything.
- Custom: grants only the resource/action combinations you select in a per-resource permission matrix.
Custom permissions¶
The custom option lets you grant or deny access for each combination of resource type and action (Read, Create, Update, Delete). For example, you can create a token that can read and deploy applications but cannot delete servers or manage team members.
The available resource types are: Applications, Deployments, Servers, Clusters, Datastores, Domains, Environment Variables, Cron Jobs, Backups, Volumes, Team Members, Projects, SSH Keys, Git Credentials, Registry Credentials, Monitors, API Tokens, Teams, and User.
Each resource is App-scoped, Team-scoped, or Account-scoped — this decides how the optional team/app scope below limits it:
- App-scoped (an action on one application): Applications, Deployments, Domains, Environment Variables, Cron Jobs, Volumes, Datastores, Backups, Monitors, and application logs/processes.
- Team-scoped (an action on a team as a whole): Servers, Clusters, Registry Credentials, Projects, Team Members, Teams, and database migrations.
- Account-scoped (tied to your user, not a team or app): API Tokens, User, SSH Keys, and Git Credentials.
If a token attempts an operation it does not have permission for, the API returns a 403 Forbidden response with a body that names the missing permission:
Token permission checks run before the usual team-membership and ownership checks, and they do not apply to dashboard sessions or JWT-authenticated requests. Tokens created before fine-grained permissions were introduced keep behaving according to their Full access or Read-only level.
Tip
For AI agents and CI/CD integrations, consider using custom permissions to follow the principle of least privilege. For example, grant Read + Create + Update on Applications and Deployments, but not Delete, so the agent can deploy but cannot accidentally remove resources.
Token Scoping (Teams and Apps)¶
The permission matrix says what a token can do; scoping says where. When you create a token you may optionally limit it to a chosen set of teams and apps. This is separate from, and stacks on top of, the permission level above.
- No scope selected = full account reach. This is the default, and every token created before scoping was introduced keeps full reach — nothing changes for it.
- A team in scope grants access to all of that team's apps (current and future) and to team-level actions on that team.
- An app in scope grants access to that one app only. An app-scoped token can act on the app but cannot perform team-level actions (for example, it cannot create servers) and cannot create new apps.
Three checks must all pass for a scoped token: (1) the (resource, action) grant, (2) the scope, and (3) your own team membership. Scope can only narrow your reach, never widen it.
For a scoped token, an out-of-scope app or team is invisible: lists omit it, a direct fetch returns 404, and a write returns 403:
A common use is a token that manages custom domains for a single app: give it the Domains resource (Read/Create/Update/Delete) and scope it to that one app. It can then manage that app's domains and nothing else.
Note
Deleting a scoped app or team removes it from the token's scope. A token that had only that one target then denies everything (it never falls back to full reach). Create a fresh token if you need a new scope.
OpenAPI Schema¶
The complete API specification is available as an OpenAPI (Swagger) schema:
You can use this schema to: - Explore all available endpoints and their parameters - Generate API clients in any language using tools like openapi-generator - Import into API tools like Postman or Insomnia for interactive testing
API Structure¶
The API is organized around resources that map to the main concepts in Appliku:
| Resource | Endpoint Prefix | Description |
|---|---|---|
| Teams | /api/team |
Team management |
| Applications | /api/team/{team_path}/applications/ |
Application CRUD and configuration |
| Servers | /api/team/{team_path}/server_list |
Server management |
| Datastores | /api/team/{team_path}/applications/{application_id}/datastores |
Database provisioning |
| Deployments | /api/team/{team_path}/deployments |
Deployment management |
Note
Most API endpoints are scoped to a team via the {team_path} URL parameter. You need to know your team's path to make requests.
Warning
The trailing slash is part of the route. Only /applications/ takes one; the other prefixes above must be called without it. A wrong slash returns 404 {"result": "incorrect url"}, the same answer as an unknown path.
Rate Limiting¶
The API applies no general rate limit. A few individual features limit themselves — Telegram account linking, password-reset email, notification email volume, and the UptimeFor.me monitor endpoints, which pass an upstream 429 through and add Retry-After when the upstream service supplies a numeric value. Treat a 429 as retryable, but do not expect one to carry Retry-After.
Using the CLI and SDK¶
The Appliku CLI and Python SDK are the easiest ways to interact with the API programmatically. They handle authentication and API error responses for you.
# Install the CLI/SDK
pip install appliku
# Authenticate
appliku login
# List applications
appliku apps list --team <team_path>
See CLI & SDK for more details.