List VPS backups

GET /api/v2/vps/{id}/backups

Return VPS backups, quota state, and action gates.

Get {id} from GET /api/v2/vps data[].id.

Use backups[].id as {backupId} for restore or delete.

Backups are offsite, longer-term recovery images and can take longer to create or restore than snapshots.

Snapshots are short-lived local block-on-write rollback points for quick changes; use backups when the user needs durable/offsite recovery.

actions.canCreateBackup and actions.canRestore include service status, quota, permission, and in-flight job checks.

Also respect each backups[].actions.canRestore: a configuration-only snapshot with no disk images cannot restore a server.

Such snapshots remain visible and deletable.

Full-server restore actions recheck content and return backup_has_no_disk_images (409) when disk images are positively absent.

VPS Services Backups

Authentication

Required API scope: read:vm

Authenticate with an API key in the Authorization: Bearer <token> header.

Context

Path Parameters

id string required Example: vps_01hxa3b4c5d6e7f8g9h0j1k2m3

Public VPS ID from GET /api/v2/vps data[].id. Do not invent this value; use the exact ID returned by the referenced API response.

Query Parameters

includeDiskCoverage boolean · default: false

Add one live disk-configuration read. diskSelection describes current inclusion/exclusion only; backups[].diskImageInventory describes each dated archive independently. Neither current configuration nor matching slot names prove a future or replaced disk was backed up. Detached disks, backup-disabled disks, media and external/network mounts are not automatically covered. Failed reads remain unavailable, not empty. No disk or backup is created.

Headers

Authorization Bearer <token>
Accept application/json

Responses

200 VPS backups with quota and action gates.
diskSelection object

Present only with includeDiskCoverage=true. Allowlisted live configuration metadata; contains no storage paths, credentials or guest file contents.

diskSelection.status string · enum
confirmed
unavailable
diskSelection.disks array<object>
diskSelection.disks[].slot string · Example: scsi0
diskSelection.disks[].sizeGb number · nullable

Nullable: may be null when not applicable.

diskSelection.disks[].included boolean
diskSelection.disks[].reason string · enum
attached
backup_disabled
detached
cdrom
backups array<object> required
backups[].id string required · Example: bkp_01hxa3b4c5d6e7f8g9h0j1k2m3
backups[].displayId string required · Example: 2026-04-27T10:00:00.000Z (vzdump-qemu-101.vma.zst)
backups[].storageKey string required · Example: vzdump-qemu-101.vma.zst
backups[].createdAt string · nullable required · Example: 2026-04-27T10:00:00.000Z

Nullable: may be null when not applicable.

backups[].sizeGb integer required · Example: 12
backups[].backupType string required · Example: manual
backups[].note string · nullable required · Example: Before upgrade

Nullable: may be null when not applicable.

backups[].actions object

Per-backup content availability. A configuration-only snapshot has canRestore.allowed=false even if the account-level restore gate permits restores. Missing legacy metadata is not proof that disk data is absent.

backups[].actions.canRestore object
backups[].actions.canRestore.allowed boolean required · Example: true
backups[].actions.canRestore.reason string · nullable required · Example: null

Nullable: may be null when not applicable.

backups[].actions.canRestore.code string · nullable · Example: pending_order

Machine-readable reason code when an action is blocked.

backups[].diskImageInventory object

Disk images recorded by this dated backup's PBS manifest. Current VM size, entitlement and matching slot names do not prove the same current disk's contents are covered. A partial/unavailable inventory cannot establish absence or completeness.

backups[].diskImageInventory.source string · enum
pbs_manifest
partial
unavailable
backups[].diskImageInventory.disks array<object>
backups[].diskImageInventory.disks[].slot string · Example: scsi1
backups[].diskImageInventory.disks[].sizeGb number · nullable

Logical image size in GiB, when present in the manifest.

quotaInfo object required
quotaInfo.used integer required · Example: 1
quotaInfo.limit integer · nullable required · Example: 3

Nullable: may be null when not applicable.

quotaInfo.remaining integer · nullable required · Example: 2

Nullable: may be null when not applicable.

actions object required
actions.canCreateBackup object required
actions.canCreateBackup.allowed boolean required · Example: true
actions.canCreateBackup.reason string · nullable required · Example: null

Nullable: may be null when not applicable.

actions.canCreateBackup.code string · nullable · Example: pending_order

Machine-readable reason code when an action is blocked.

actions.canRestore object required
actions.canRestore.allowed boolean required · Example: true
actions.canRestore.reason string · nullable required · Example: null

Nullable: may be null when not applicable.

actions.canRestore.code string · nullable · Example: pending_order

Machine-readable reason code when an action is blocked.

400 Invalid request. The response body is an RFC 7807 Problem Details document.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
401 Unauthorized. Authentication is required.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
403 Forbidden. The caller lacks a required scope or does not own the resource.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
404 Not found. The resource does not exist or is not owned by the caller; code is vps_not_found.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
429 Rate limited. Retry after the limit resets. 429 responses include Retry-After seconds plus X-RateLimit-* headers.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
500 Internal error. Retry later or contact support if the issue persists.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
GET https://cloud.hostup.se/api/v2/vps/{id}/backups
For AI assistants
View as Markdown
cURL
curl -X GET "https://cloud.hostup.se/api/v2/vps/vps_01hxa3b4c5d6e7f8g9h0j1k2m3/backups" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Accept: application/json"
Response
{
  "backups": [
    {
      "id": "bkp_01hxa3b4c5d6e7f8g9h0j1k2m3",
      "displayId": "2026-04-27T10:00:00.000Z (vzdump-qemu-101.vma.zst)",
      "storageKey": "vzdump-qemu-101.vma.zst",
      "createdAt": "2026-04-27T10:00:00.000Z",
      "sizeGb": 12,
      "backupType": "manual",
      "note": "Before upgrade"
    }
  ],
  "quotaInfo": {
    "used": 1,
    "limit": 3,
    "remaining": 2
  },
  "actions": {
    "canCreateBackup": {
      "allowed": true,
      "reason": null
    },
    "canRestore": {
      "allowed": true,
      "reason": null
    }
  }
}