API · Authentication
How to authenticate requests to the Rollin Host API with Bearer tokens, which scopes are available and security best practices for production.
The Rollin Host API uses Bearer tokens with scopes. Each token has granular permissions: you should never use a “root” token in production.
Generate a token
-
Go to https://painel.rollinhost.com.br and open Account → API tokens.
-
Click Create token, give it a name (e.g.
provisionamento-prod) and select the scopes:vps:read: list VPS and view detailsvps:write: create / suspend / delete VPSdomains:read: list domainsdomains:write: register / transfer domainsinvoices:read: list invoicesservices:read: list subscribed services
-
Copy the token right away. It is shown only once. If you lose it, generate another one.
Use the token
curl https://api.rollinhost.com.br/v1/services \
-H "Authorization: Bearer rh_live_abc123..." \
-H "Accept: application/json"
Expected response
{
"data": [
{
"id": "srv_01HX3AB7DEF",
"type": "vps",
"plan": "vps-pro",
"status": "active",
"created_at": "2026-01-15T10:00:00Z"
}
]
}
Authentication errors
| Status | Meaning |
|---|---|
401 Unauthorized | Invalid, expired or missing token |
403 Forbidden | Valid token but without the required scope |
429 Too Many Requests | Rate limit exceeded (60 req/min per token) |
Token rotation
Best practice: rotate tokens every 90 days.
- Generate a new token with the same scopes
- Update the application’s environment variable
- Confirm that requests work with the new token
- Revoke the old token in the panel
Webhooks (coming soon)
Instead of polling, you will be able to receive event webhooks:
service.created/service.suspended/service.terminatedinvoice.paid/invoice.overduedomain.transferred
Next steps
Last updated: