Your game servers have always lived in the control panel. With the LOW.MS Public API, you can also run them from your own code: a Discord bot, a scheduled backup job, a status page or a quick script. It's included with every server at no extra cost.
What you can do
The API covers the everyday tasks you already handle in the control panel. You can:
- List your servers and check their status
- Start, stop and restart them
- Take backups and list existing ones
- Read the console and send commands
- Browse and read server files
- See who's online and manage player lists
- Read and change game settings
Long-running actions such as a restart or a backup return a job you can check until it finishes, so your script knows when it's actually done.
How it works
The process is short:
- Create a key. You make an API key in the control panel and choose exactly which permissions it has.
- Authenticate. Your code sends that key as a bearer token with each request.
- Call the endpoints. You use the endpoints to read information or take actions on your own servers.
- Follow long jobs. For actions that take time, such as a restart or a backup, you get a job back. You check that job until it finishes, so your script doesn't move on too early.
Getting started
- In the control panel, go to Account settings, API keys, and create a key.
- Tick only the permissions it needs. A status page only needs to read servers, while a backup job also needs to create backups.
- Send the key as a bearer token:
curl https://api.prod.nexus.low.ms/v1/servers \
-H "Authorization: Bearer lowms_..."
Every endpoint is documented in the API reference, with example requests and responses. There's also an OpenAPI file, so you can generate a client in your language of choice.
Built to be safe
- Each key gets only the permissions you tick. A leaked read-only key can't stop your server.
- A key only reaches your own servers. It never sees anyone else's.
- Passwords stay in the panel. Server and admin passwords are never returned by the API. You can only view them in the control panel.
- Revoking is instant. Revoke a key from the same page and anything using it stops straight away.
What people are building
Customers are already using the API to:
- watch their console live;
- take a backup every morning;
- restart their server on a schedule.
We'd love to see what you make with it. If there's an endpoint you need that isn't there yet, tell us in a ticket or on Discord.
FAQ
Does the API cost extra?
No. The Public API is included with every server at no extra cost.
Where do I create an API key?
In the control panel, go to Account settings, API keys, and create a key there. Tick only the permissions that key needs.
Can a key access other people's servers?
No. A key only reaches your own servers and never sees anyone else's.
Can I get my server or admin passwords through the API?
No. Server and admin passwords are never returned by the API. You can only view them in the control panel.
What should I do if a key leaks?
Revoke it from the same page where you created it. Revoking is instant, and anything using the key stops straight away. If the key only had read permissions, it couldn't have stopped your server in the meantime.
How do I know when a restart or backup has finished?
Long-running actions return a job. Check that job until it finishes, and your script will know when the action is actually done.
Do I have to use curl?
No. curl is just one example. There's an OpenAPI file, so you can generate a client in your language of choice. Example requests and responses for every endpoint are in the API reference.
What if the endpoint I need isn't there yet?
Tell us in a ticket or on Discord.