Migração 100% grátis na contratação semestral · nossa equipe migra tudo de qualquer provedor · novos clientes Migrar agora
Agente de IA no WhatsApp na API Oficial da Meta · somos Tech Provider aprovado · orçamento sob consulta Pedir orçamento
VPS com OpenClaw pré-instalado · a partir de R$ 56,90/mês · gerenciada pela Rollin Quero a VPS
VPS com Hermes Agent pré-instalado · a partir de R$ 56,90/mês · gerenciada pela Rollin Quero a VPS
Hospedagem com 30 dias de garantia · Não gostou? Devolvemos 100%, sem perguntas. Ver hospedagem

API · Authentication

How to authenticate requests to the Rollin Host API with Bearer tokens, which scopes are available and security best practices for production.

The Rollin Host API uses Bearer tokens with scopes. Each token has granular permissions: you should never use a “root” token in production.

Generate a token

  1. Go to https://painel.rollinhost.com.br and open Account → API tokens.

  2. Click Create token, give it a name (e.g. provisionamento-prod) and select the scopes:

    • vps:read: list VPS and view details
    • vps:write: create / suspend / delete VPS
    • domains:read: list domains
    • domains:write: register / transfer domains
    • invoices:read: list invoices
    • services:read: list subscribed services
  3. Copy the token right away. It is shown only once. If you lose it, generate another one.

Use the token

curl https://api.rollinhost.com.br/v1/services \
  -H "Authorization: Bearer rh_live_abc123..." \
  -H "Accept: application/json"

Expected response

{
  "data": [
    {
      "id": "srv_01HX3AB7DEF",
      "type": "vps",
      "plan": "vps-pro",
      "status": "active",
      "created_at": "2026-01-15T10:00:00Z"
    }
  ]
}

Authentication errors

StatusMeaning
401 UnauthorizedInvalid, expired or missing token
403 ForbiddenValid token but without the required scope
429 Too Many RequestsRate limit exceeded (60 req/min per token)

Token rotation

Best practice: rotate tokens every 90 days.

  1. Generate a new token with the same scopes
  2. Update the application’s environment variable
  3. Confirm that requests work with the new token
  4. Revoke the old token in the panel

Webhooks (coming soon)

Instead of polling, you will be able to receive event webhooks:

  • service.created / service.suspended / service.terminated
  • invoice.paid / invoice.overdue
  • domain.transferred

Next steps

Last updated: