compute

POST /v1/compute/servers/{serverId}/console/allow

Let one address reach an IP-gated console.

All compute endpoints

Authentication

Send an API key as a bearer token. The key must carry the sites.restart permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/compute/servers/{serverId}/console/allow \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "ip": <string> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

⭐⭐ **Without this, the console on an IP-gated range is a password for a bolted door.** Such a range starts with an empty allow-list, meaning *nobody* may connect — the credential is real and useless until an address is added. ⛔ The response is the console session **re-read from the provider**, never an echo of the request: a `200` is not evidence on every provider, and the allow-list coming back containing the address is the only proof it landed. Requires `sites.restart` — granting an address console access **is** granting console access. Audited with the address, unlike opening a console, because an allow-list entry is a lasting change to who may reach the machine rather than a credential. `503` on a range whose console is not restricted by address.

Parameters

NameTypeRequiredWhat it is
serverId (path)UuidYesThe server's id, as `listComputeServers` reports it. **Ours** (UUIDv7), minted when the order row was written — never the provider's own identifier for the machine.

Request body

NameTypeRequiredWhat it is
ipstringYesThe public address that should be allowed to connect.

Response

NameTypeRequiredWhat it is
urlstringYesThe console address, for `kind: url` (a page a browser opens) and `kind: wss` (a WebSocket endpoint a VNC client connects to). ⛔ **Blank on a `vnc` console, and that is not a fa…
passwordstringYesThe password the console asks for, when the provider issues one alongside the URL. `""` when the URL alone authenticates.
expires_atstringYesWhen it stops working, ISO-8601, or `""` when the provider does not say. ⛔ Blank does **not** mean "never" — these last minutes by design. A `url` and a `wss` console are both o…
kindstring<url, wss, vnc>Yes⛔⛔ **THREE genuinely different consoles, not three spellings of one, and `wss` was missing** (W22-B, D10906). `url` is a page a browser opens. `wss` is a one-shot WebSocket endp…
hoststringYesThe VNC host, for `kind: vnc`. ⛔ **May be blank, and that is a refusal rather than a gap**: where the only hostname a supplier states is its own branded one, we do not pass it on.
portintegerYesThe VNC port, `0` when the provider does not state one.
allowed_ipsstring[]YesThe addresses currently permitted to reach the console. ⛔⛔ **An empty list on an IP-restricted console means NOBODY may connect** — the exact opposite of the "no restriction" an…
ip_restrictedbooleanYesWhether the caller's address must be allow-listed before anything can connect. `false` means the credential alone is enough.

Errors this endpoint can return

401 · 403 · 404 · 422 · 429 · 503