Customer API
Read server status, connection details, resources, incidents, and activity from your MaximusHost account.
The MaximusHost Customer API lets you build personal dashboards, monitoring tools, reports, bots, and automation that read information about servers your account owns or can access through Server Team sharing.
It is currently read-only. A bearer token can read server information, resource history, incidents, and activity; it cannot start, stop, or restart a server, change its configuration or resources, manage files, create or restore backups, change schedules, or delete a server.
In this section
Get started
- Sign in to MaximusHost.
- Open My Account in the site menu, then choose API Access.
- Enter an optional label, such as
Home dashboard, so you can recognize where the token is used. - Select Create token.
- Copy the token and place it in your integration's secret store before closing the message.
Important: MaximusHost displays a new token only once. It stores a salted hash instead of the token value, so it cannot be recovered later. If you lose a token, revoke it from API Access and create a replacement.
The API Access page lists each token's label, when it was created, when it was last used, and whether it has been revoked. Revoked tokens stay in the list for reference but cannot authenticate requests.
Base URL and authentication
The Customer API base URL is:
https://maximushost.com/api/v1
For every server-data request, send the token in the Authorization header:
Authorization: Bearer mhca_example_token_replace_me
The token begins with mhca_. The example token above is fake; replace it with a token created in API Access. Do not send your MaximusHost password or a game-server credential.
Your first request
This request lists servers available to the account that created the token:
curl --request GET \
--url 'https://maximushost.com/api/v1/servers' \
--header 'Accept: application/json' \
--header 'Authorization: Bearer mhca_example_token_replace_me'
$headers = @{
Accept = 'application/json'
Authorization = 'Bearer mhca_example_token_replace_me'
}
Invoke-RestMethod -Method Get `
-Uri 'https://maximushost.com/api/v1/servers' `
-Headers $headers
import os
import requests
response = requests.get(
'https://maximushost.com/api/v1/servers',
headers={
'Accept': 'application/json',
'Authorization': f"Bearer {os.environ['MAXIMUSHOST_API_TOKEN']}",
},
timeout=30,
)
response.raise_for_status()
print(response.json())
Owners and Server Team access
A token acts as the MaximusHost account that created it. It does not grant extra access or bypass Server Team permissions.
- A server owner can read that server's summary, resource history, incidents, and activity.
- An active Server Team member can see a shared server in the server list, read its summary, and read its activity.
- A shared member needs
viewresources,manageresources, orview_consoleto read resource history and see resource allocation in a server summary. - A shared member needs
view_consoleto read incidents. - If the share is removed or is no longer active, subsequent requests no longer have access. The server will not appear in the list, and individual requests are denied or treated as inaccessible according to the endpoint.
Every server summary includes an access object. Its role is owner or team_member; for a team member, permissions contains the active Server Team permission keys.
Pagination and rate limits
The server list, resource history, incidents, and activity use the same pagination parameters:
pagedefaults to1and is limited to1through10000.per_pagedefaults to20and is limited to1through50.- Each response includes
page,perpage, andhasmore.has_moreistrueonly when another record is available; increasepagewhile it istrue.
For example:
GET /servers/12345/resources?page=2&per_page=50
Bearer-token requests are limited to 120 authenticated requests per token in each fixed 60-second window. A request over the limit receives HTTP 429 with the rate_limited error code. Make only the requests you need and wait before retrying after a limit response.
Token security and revocation
- Treat a token like a password.
- Store it in a secret manager or environment variable, not in source code.
- Never put it in a public repository, public client-side application, screenshot, ticket, chat, or game mod.
- Use separate labeled tokens for separate integrations, so one can be revoked without interrupting the others.
- If a token may be exposed, revoke it immediately in My Account → API Access, create a replacement, and update the affected integration.
Token creation, listing, and revocation are performed from the signed-in API Access page. Those website operations require your WordPress session and REST nonce; they are not bearer-token operations for external scripts.
Useful projects
The current read-only API is a good fit for:
- A personal dashboard showing server state, connection details, and allocated resources.
- A Discord bot that reports the current server state or a recent incident.
- A monitoring or status integration that records resource samples.
- A home-automation or scheduled script that reports status without changing a server.
- A reporting tool that summarizes safe activity history.
See the API reference for all available data routes, responses, examples, and troubleshooting.