Developer API

Automate your ISP over HTTPS

A REST API that runs on your ISPCore server. Predictable resource URLs, JSON in and out, standard HTTP verbs and status codes — and because it is your installation, your subscriber data never leaves your infrastructure.

Base URL

Every endpoint lives under the /api/v1 prefix on your own domain:

https://your-server/api/v1

All traffic is HTTPS, all bodies are application/json, and collection endpoints support pagination and search.

Authentication

ISPCore uses the same credentials as the panel. You exchange them once for a pair of tokens, then send the access token as a bearer token on every request.

POST/api/v1/auth/login

Three fields are required. tenant_id is the short slug of the operator you are signing in to — easy to miss, and the most common reason a first request fails.

curl -X POST https://your-server/api/v1/auth/login \
  -H 'Content-Type: application/json' \
  -d '{
        "email": "you@example.com",
        "password": "••••••••",
        "tenant_id": "your_slug"
      }'

The response carries both tokens, the lifetime of the access token in seconds, and the signed-in user:

{
  "access_token":  "eyJhbGciOi…",
  "refresh_token": "eyJhbGciOi…",
  "token_type":    "bearer",
  "expires_in":    3600,
  "user":          { "id": "…", "email": "you@example.com", … }
}

GET/api/v1/auth/tenants

Not sure of your slug? This endpoint is public and lists the active operators on the installation, so you can pick the right tenant_id.

Using the token

curl https://your-server/api/v1/clients \
  -H 'Authorization: Bearer <access_token>'

When the access token expires, exchange the refresh token at POST /api/v1/auth/refresh. POST /api/v1/auth/logout invalidates both.

Permissions apply. The API is not a back door: a token carries the same roles and permissions as the user it belongs to, and every write is recorded in the audit log with the account that made it.

Core resources

The surface is broad — around 330 endpoints across 40 groups. These are the ones most integrations start with.

Subscribers & billing

EndpointWhat it does
GET/api/v1/clientsList and search subscribers
GET/api/v1/clients/{id}One subscriber with contacts and status
GET/api/v1/subscriptionsServices, plans and their state
GET/api/v1/plansTariff plans and speeds
GET/api/v1/invoicesInvoices, with totals and payment state
POST/api/v1/paymentsRecord a payment against an invoice
POST/api/v1/fiscal/invoices/{id}/fiscalizeFile an invoice with the tax authority

Fibre & network

EndpointWhat it does
GET/api/v1/olt/The OLTs on the installation
GET/api/v1/olt/all-onusEvery ONU with status and optical readings
GET/api/v1/olt/all-unregisteredONUs seen on the fibre but not yet provisioned
GET/api/v1/olt/onu-searchFind an ONU by serial, MAC, name or interface
GET/api/v1/olt/statsTotals per OLT — online, offline, signal
GET/api/v1/nasNAS devices for RADIUS
GET/api/v1/ip-poolsAddress pools
POST/api/v1/cpe/{id}/rebootReboot a CPE through TR-069

Live state & support

EndpointWhat it does
GET/api/v1/dashboard/online-clientsWho is online right now
GET/api/v1/dashboard/online-statsSession counts over time
GET/api/v1/dashboard/kpisHeadline numbers for the period
GET/api/v1/dashboard/unpaid-clientsWho owes money
GET/api/v1/ticketsSupport tickets
GET/api/v1/stockWarehouse items and movements

Conventions & errors

{ "detail": "Porti 1/2/8 s'ka indeks te lire." }

Interactive reference

Every installation can serve a live OpenAPI reference generated from the running code — always matching the version you have, never a stale document:

https://your-server/docs        Swagger UI
https://your-server/redoc       ReDoc
https://your-server/openapi.json  machine-readable spec
Off by default. The interactive docs are disabled unless the operator enables them, so a public installation does not expose its API surface unintentionally. Turn them on when you need them, and off again afterwards.

Need a hand?

Building something against ISPCore and stuck on a detail? Write to info@isp-core.com or message us on WhatsApp — a person answers.