Perl & CGI

Manually Testing the cPanel API Using a Perl Script

By the Domain India teamPublished 8 min read
Knowledge base article
Contents (8 sections)

You can manage much of a cPanel hosting account from a script instead of clicking through the control panel: list email accounts, create a mailbox, read disk usage and more. This guide shows how to test the cPanel API by hand with a short Perl script, using an API token you create in your own cPanel account. It is written for Domain India cPanel hosting customers and beginner developers.

Key takeaways

On shared cPanel hosting you call UAPI, the account-level cPanel API, over HTTPS on port 2083. Create an API token in cPanel under Security › Manage API Tokens, then send requests to https://your-server:2083/execute/Module/function with the header Authorization: cpanel USERNAME:TOKEN. A 25-line Perl script using the core HTTP::Tiny and JSON::PP modules is enough to test any call. The server-level WHM API needs WHM access, which shared hosting accounts do not have.

1. Which cPanel API you can use

cPanel has several APIs, and older guides mix them up.

APIWhat it controlsWho can use itPort
UAPIOne cPanel account: email, domains, databases, files, SSLThe account owner, with a cPanel API token2083
WHM API 1The whole server: create and suspend accounts, packagesServer administrators and resellers with WHM access2087
cPanel API 2Legacy account functionsDeprecated; use UAPI instead2083

As a Domain India shared hosting customer you own one cPanel account, so UAPI is the API for you. Scripts that send Authorization: whm … to port 2087, as many older examples do, are for WHM and will not work with a cPanel account token.

2. Create an API token

  1. Log in to cPanel.
    Use the one-click login in the client area, or see how to log in to cPanel.
  2. Open Manage API Tokens.
    It is in the Security section.
  3. Create a token.
    Give it a name you will recognise, such as perl-test, and set an expiry date if you only need it for testing.
  4. Copy the token now.
    cPanel shows the token only once. Store it in a password manager.
cPanel Manage API Tokens page with the Create API Token form: token name, expiry choice, a danger warning and the Create button
The Create API Token form in cPanel's Manage API Tokens.
A token is a key to your whole account

Anyone with your username and token can read and change your email, files and databases, without needing your password or two-factor code. Never paste a token into a ticket, a chat, a public repository or a shared document. Delete tokens you no longer use from the same page.

3. The Perl test script

This script calls one UAPI function and prints the result. It uses only modules that ship with Perl (HTTP::Tiny and JSON::PP), reads the token from an environment variable so it never sits in the file, and keeps certificate checking on.

perl
#!/usr/bin/perl
use strict;
use warnings;
use HTTP::Tiny;
use JSON::PP qw(decode_json);

my $host   = $ENV{CPANEL_HOST}  or die "Set CPANEL_HOST\n";   # server name from the client area
my $user   = $ENV{CPANEL_USER}  or die "Set CPANEL_USER\n";   # your cPanel username
my $token  = $ENV{CPANEL_TOKEN} or die "Set CPANEL_TOKEN\n";  # the API token
my $module = shift // 'DomainInfo';
my $func   = shift // 'list_domains';
my %args   = map { split /=/, $_, 2 } @ARGV;                  # extra key=value arguments

my $ua  = HTTP::Tiny->new(
    verify_SSL      => 1,
    timeout         => 30,
    default_headers => { Authorization => "cpanel $user:$token" },
);
my $url = "https://$host:2083/execute/$module/$func";
$url .= '?' . $ua->www_form_urlencode(\%args) if %args;

my $res = $ua->get($url);
die "HTTP $res->{status} $res->{reason}\n$res->{content}\n" unless $res->{success};

my $data = decode_json($res->{content});
if ($data->{status}) {
    print JSON::PP->new->pretty->canonical->encode($data->{data});
} else {
    print "API error: ", join('; ', @{ $data->{errors} || [] }), "\n";
}

Save it as uapi-test.pl. The script takes the module and function names as its first two arguments, followed by any key=value arguments the function needs.

4. Run it

The easiest place to run the script is your own computer. Perl is installed on macOS and most Linux systems; on Windows, install Strawberry Perl. HTTPS in HTTP::Tiny needs the IO::Socket::SSL module; check it with perl -MIO::Socket::SSL -e1 and install it with your package manager or cpanm IO::Socket::SSL if that command prints an error.

bash
export CPANEL_HOST="server-name-from-client-area"
export CPANEL_USER="yourcpaneluser"
export CPANEL_TOKEN="paste-the-token-here"

perl uapi-test.pl DomainInfo list_domains
perl uapi-test.pl Email list_pops
perl uapi-test.pl Quota get_quota_info

For CPANEL_HOST, use the server name shown for your hosting service in the client area (the Manage › Access tab lists your username, server and panel URL). Using the server name rather than a bare IP address lets certificate checking pass.

A successful call prints the data part of the response. Every UAPI response has the same shape: status (1 for success, 0 for failure), errors, warnings, messages, data and metadata, so your scripts can check status first.

5. Useful UAPI functions to try

TaskModule and functionExample arguments
List domains on the accountDomainInfo list_domainsnone
List email accountsEmail list_popsnone
Create an email accountEmail add_popemail=info domain=example.com password=… quota=1024
Show disk usageQuota get_quota_infonone
List MySQL databasesMysql list_databasesnone

Start with read-only functions such as list_domains and list_pops. Test anything that changes the account, like add_pop, on a test address first. The full list of modules and functions is in cPanel's official UAPI documentation.

On the command line, arguments go after the function name, for example perl uapi-test.pl Email add_pop email=test domain=example.com password='Str0ng-Pass!' quota=1024. Avoid typing real passwords into shell history on a shared computer.

6. Troubleshooting

Access denied or HTTP 401
The username or token is wrong, the token has expired or been deleted, or the header says whm instead of cpanel.
Connection timed out
Your network may block port 2083, or your IP may have been blocked after failed logins. Try from mobile data, and see the IP block guide linked below.
Certificate error
You used an IP address or the wrong host name. Use the server name from the client area. Do not switch certificate checking off.
API error in the output
The call reached cPanel but the function failed. Read the message: a missing argument, a wrong domain, or a feature your plan does not include.
Can't locate JSON/PP.pm or IO/Socket/SSL.pm
A Perl module is missing on your computer. Install it with your package manager or cpanm.
Failed logins can block your IP

Repeated wrong tokens count as failed logins, and the server's protection can block your IP address, cutting off your website and email on that connection too. If a call fails twice, stop and check the token before trying again. I can't reach my server: have I been blocked? explains how to get unblocked.

7. Running this on Domain India

  • Shared cPanel hosting: port 2083 is open on our cPanel servers, and Manage API Tokens is in every cPanel account, so the script above works from your own computer. Jailed SSH is available on every shared hosting plan; it is off by default, so ask support to enable it for your account. Tools available inside the jailed shell vary, so if you want to run scripts on the server itself, ask support what is available.
  • WHM API: shared hosting accounts have no WHM access, so WHM API 1 calls on port 2087 are not available to them. Our VPS plans do not offer cPanel, so WHM is not part of them either.
  • Scheduled scripts: if you want the script to run on a schedule, run it from your own machine or a server you control; keep the token outside the script, as above.
cPanel Starter
₹125/mo + GST
  • 25 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 10 Email Accounts
See plan details

Frequently asked questions

Which cPanel API should I use on shared hosting?

Use UAPI. It works on one cPanel account, authenticates with an API token you create in that account, and is reached at https://your-server:2083/execute/Module/function. WHM API 1 is for server administrators and is not available to shared hosting accounts.

How do I create a cPanel API token?

Log in to cPanel, open Manage API Tokens in the Security section, create a token with a name and an optional expiry date, and copy it immediately. cPanel shows the token only once.

What authorization header does the cPanel API need?

For UAPI with an account token, send the header Authorization: cpanel USERNAME:TOKEN. The whm prefix is only for WHM API tokens.

Why does my script say Access denied?

The username or token is wrong, the token has expired or been deleted, or the header uses whm instead of cpanel. Repeated failures can block your IP address, so check the details before retrying.

Is cPanel API 2 still supported?

cPanel API 2 is deprecated. New scripts should use UAPI, which covers the same account tasks with a consistent JSON response.

Is it safe to turn off SSL verification in my script?

No. Your token travels in every request, so keep certificate checking on and connect using the server name shown in the client area rather than an IP address.

Ready to try it? Log in through how to log in to cPanel, create a token under Security, and run the script against a read-only function first. If you need SSH on your account, see enabling and accessing jailed SSH.

Need help with the cPanel API?

Tell us which call you are testing and the error you see, without the token, and our team will help you find the cause.

Open a support ticket

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Test the cPanel UAPI with a Perl script