DirectAdmin API Guide for Developers

DirectAdmin is not only a control panel you click through — it also exposes an API that lets developers issue every command via HTTP requests, from creating domains and email to managing DNS. It is ideal for automation and for connecting DirectAdmin to your own systems. This guide covers the fundamentals you need before you start writing code that calls the API.

What the DirectAdmin API Can Do

The DirectAdmin API mirrors almost every function available in the panel as a command callable from code. The real benefit is automating repetitive work — a script that creates many mailboxes for new staff at once, a system that issues subdomains to customers automatically, or a provisioning tool that sets up an entire new site in a single command. Tasks that normally take dozens of clicks in the panel can be done in one script.

Authentication: Login Keys Are Safer Than Passwords

The DirectAdmin API supports Basic Authentication. The basic format is:

https://username:[email protected]:2222/CMD_API_ENDPOINT

But embedding your account's main password in a script is risky — if the code leaks, the password used for everything leaks with it. The safer way is to create a Login Key from Advanced Features → Login Keys, where you can define which commands the key may call and revoke it instantly without affecting your main password. Use the Login Key in place of the password when calling the API.

Common API Endpoints

cURL Example: List Domains

A basic cURL command to retrieve all domain names — the result comes back as a URL-encoded query string you can parse further:

curl -u "username:password" "https://yourdomain.com:2222/CMD_API_SHOW_DOMAINS"

PHP Example: Create an Email Account

Use cURL in PHP to send a POST request that creates a mailbox:

$ch = curl_init();

curl_setopt($ch, CURLOPT_URL, 'https://yourdomain.com:2222/CMD_API_POP');

curl_setopt($ch, CURLOPT_POST, 1);

curl_setopt($ch, CURLOPT_POSTFIELDS, 'action=create&domain=yourdomain.com&user=newuser&passwd=secret123"a=500');

curl_setopt($ch, CURLOPT_USERPWD, 'da_user:da_login_key');

$result = curl_exec($ch);

Always check the API response for error=1 to catch failed commands, rather than assuming every call succeeds.

Security Precautions

The API runs on port 2222 over HTTPS — never call it over plain HTTP, as your credentials would be sent unencrypted. Do not embed a Login Key in client-side code or JavaScript that users can see; keep it in a server-side configuration file that is not reachable from outside, and limit each Login Key to only the commands it genuinely needs.

API Documentation: The full list of endpoints, required parameters, and response formats is in the official documentation at docs.directadmin.com/api. Refer to the documentation matching the DirectAdmin version your server runs.

Frequently Asked Questions

Do I need to be a developer to use the API?

Yes — the API is for those who can write scripts. For general website management, the DirectAdmin control panel is enough.

How does a Login Key differ from a password?

A Login Key is a purpose-specific key with limited scope that can be revoked without changing your main password, making it safer for use in scripts.

What port does the API use?

Port 2222 over HTTPS — the same as the DirectAdmin control panel.

What the DirectAdmin API Can Do: Real-World Use Cases

The DirectAdmin API exposes virtually every function available in the control panel as an HTTP-callable command. This means any repetitive task you do in the panel can be scripted, scheduled, and automated. Here are the most common real-world applications:

The API uses a simple REST-like HTTP model — not GraphQL or a complex SDK — so any programming language capable of sending HTTP requests works: PHP, Python, Node.js, Go, Ruby, or even a basic shell script with cURL.

Creating API Keys via Login Keys: Scope and Expiry

Before writing a single line of API code, you should create a dedicated Login Key. Using your main account password in scripts is a significant security risk: if the script or its configuration file is ever exposed, your entire hosting account is compromised. Login Keys give you fine-grained control over what each script can do and can be revoked instantly if needed.

How to Create a Login Key

  1. Log in to DirectAdmin and navigate to Advanced Features > Login Keys.
  2. Click Create Login Key.
  3. Enter a descriptive name that identifies the script or service that will use this key, such as billing-provisioner or dns-automation.
  4. Under Allowed Commands, select only the API endpoints this key needs to call. A key used only for creating email accounts should have access to CMD_API_POP and nothing else.
  5. Set an Expiry Date. Keys that never expire are a long-term risk. Setting an expiry forces periodic rotation. One year is a reasonable default.
  6. Optionally, restrict the key to specific IP addresses if your script runs from a server with a static IP. This adds a network-level barrier even if the key is leaked.
  7. Click Save and copy the key immediately — DirectAdmin will not show it again after you leave the page.

Once created, substitute the Login Key for the password in Basic Authentication. Your API call URL format becomes: https://username:[email protected]:2222/CMD_API_ENDPOINT. The key grants access only to the endpoints you permitted, nothing more.

More cURL Examples: Check Quota, List Domains, Add DNS

Beyond the basic domain list and email creation examples, here are additional cURL commands for tasks developers commonly automate:

List all email accounts for a domain

curl -u "username:login_key" "https://yourdomain.com:2222/CMD_API_POP?action=list&domain=yourdomain.com"

List all domains in the account

curl -u "username:login_key" "https://yourdomain.com:2222/CMD_API_SHOW_DOMAINS"

Check disk usage for all users (reseller level)

curl -u "reseller_user:login_key" "https://yourdomain.com:2222/CMD_API_SHOW_USERS"

Add a DNS A record

curl -u "username:login_key" -X POST "https://yourdomain.com:2222/CMD_API_DNS_CONTROL" \
-d "action=add&domain=yourdomain.com&type=A&name=subdomain&value=1.2.3.4&ttl=300"

Delete an email account

curl -u "username:login_key" -X POST "https://yourdomain.com:2222/CMD_API_POP" \
-d "action=delete&domain=yourdomain.com&user=olduser"

API responses come back as URL-encoded key-value strings. A successful call returns something like error=0&text=Done. A failed call returns error=1&text=Description of error. Always parse the error field in your code rather than assuming success.

Security Best Practices: IP Whitelisting, Key Rotation, and Least Privilege

Using HTTPS is necessary but not sufficient for API security. Production environments require additional safeguards to minimize the impact of a compromised key or an insecure deployment.

Restrict Login Keys by IP Address

When creating a Login Key, DirectAdmin allows you to specify which IP addresses may use that key. If your API script runs on a server with a fixed IP, always set this restriction. A leaked key becomes worthless to an attacker who is not calling from the whitelisted IP range. Even for scripts that run locally during development, restricting to your office IP adds meaningful protection.

Rotate Keys Regularly

Treat API keys like passwords: rotate them periodically and immediately whenever a team member with access to the key leaves the organization. The process is straightforward — create a new key, update the configuration in all scripts that use it, verify everything still works, then revoke the old key. Setting a short expiry (three to six months) forces this discipline automatically.

Apply the Least-Privilege Principle

Each Login Key should have the minimum permissions needed for its specific purpose. A provisioning script that only creates email accounts does not need permission to delete domains or modify DNS. Restricting permissions limits the blast radius if a key is compromised. Key capabilities that would cause irreversible damage — such as deleting accounts or purging databases — should be granted only to keys used interactively, not to automated scripts.

Treating API access with the same rigor as account password security ensures that automation capabilities do not introduce new attack vectors into your hosting environment.

API Documentation page in DirectAdmin
API Documentation page in DirectAdmin

Need Hosting with Full API Access?

AsiaGB Hosting supports the full DirectAdmin API — ideal for developers and businesses.

View Hosting Plans