Cloudexa API

API v1 gives you access to account, repository, hosting, deployment and database data using JSON and bearer tokens.

Basics

The API is versioned under /api/v1 and returns JSON responses.

Base URL https://cloudexa.dev/api/v1
Authentication Bearer token
Format JSON

Endpoints

Routes currently exposed by API v1.

GET /api/v1 Public
GET /api/v1/health Public
GET /api/v1/me Token
GET /api/v1/repositories Token
GET /api/v1/hosting/projects Token
GET /api/v1/hosting/projects/:id Token
GET /api/v1/deployments Token
GET /api/v1/databases Token
GET /api/v1/tokens Session
POST /api/v1/tokens Session
DELETE /api/v1/tokens/:id Session

Authentication

Send your API token in the Authorization header.

cURL
curl https://cloudexa.dev/api/v1/me \
  -H "Authorization: Bearer clx_api_YOUR_TOKEN"
Response
{
    "id": 1,
    "username": "example",
    "plan": "normal",
    "authentication": "token"
}
Tokens are only shown when created API tokens start with clx_api_. Cloudexa stores the token hash, not the raw token.

Example request

Fetch the hosting projects available to the token owner.

cURL
curl https://cloudexa.dev/api/v1/hosting/projects \
  -H "Authorization: Bearer clx_api_YOUR_TOKEN"
JavaScript
const response =
    await fetch(
        "https://cloudexa.dev/api/v1/hosting/projects",
        {
            headers: {
                Authorization:
                    "Bearer " +
                    process.env.CLOUDEXA_TOKEN
            }
        }
    );

const data =
    await response.json();

console.log(
    data.projects
);

Health

The health endpoint is public and can be used for simple monitoring.

GET /api/v1/health
{
    "status": "operational",
    "database": "operational",
    "version": "v1",
    "latency_ms": 3
}

Security

API v1 is deliberately limited to application-level resources and token management.

No shell execution There is no endpoint for arbitrary host or application shell commands.
No Docker exec The API does not provide direct container exec access.
Secrets excluded Database passwords and encrypted credential values are not returned in normal API responses.
Rate limiting API requests are subject to Cloudexa request limits.
Revocable tokens Tokens can be removed from account settings when they are no longer needed.

Use API v1

Create a token, then send it as a bearer token with your requests.

Copied