- About Veeam Backup & Replication REST API
- Overview
- How To
- Changelog
- Login
- License
- postInstall License
- getGet Installed License
- postRemove License
- postCreate License Usage Report
- postRenew Installed License
- getGet Consumption of Socket Licenses
- postRevoke Socket License
- getGet Instance Licenses Consumption
- postAssign Instance License
- postRevoke Instance License
- getGet Capacity License Consumption
- postRevoke Capacity License From Unstructured Data Workload
- postUpdate License
- postEnable or Disable License Auto Update
- postEnable or Disable Instance Consumption for Unlicensed Agents
- Credentials
- getGet All Credentials
- postAdd Credentials Record
- getGet Credentials Record
- putEdit Credentials Record
- delRemove Credentials Record
- postChange Password
- postChange Linux Private Key
- postChange Linux Root Password
- getGet All Cloud Credentials
- postAdd Cloud Credentials Record
- postGet Microsoft Entra ID Verification Code
- postRegister Microsoft Entra ID Application
- postGet Google Authentication Information
- getGet Cloud Credentials Record
- putEdit Cloud Credentials Record
- delRemove Cloud Credentials Record
- postChange Secret Key
- postChange Google Service Account
- postChange Certificate
- getGet All Helper Appliances
- postAdd or Edit Helper Appliance
- getGet Helper Appliance
- delRemove Helper Appliance
- Encryption
- Service
- Services
- Connection
- Cloud Browser
- Inventory Browser
- getGet All VMware vSphere Servers
- getGet VMware vSphere Server Objects
- postGet All Servers
- postGet Inventory Objects
- postRescan Inventory Objects
- getGet All Unstructured Data Servers
- getGet Unstructured Data Servers
- getGet All Microsoft Entra ID Tenants
- postAdd Microsoft Entra ID Tenant
- getGet Microsoft Entra ID Tenant
- putEdit Microsoft Entra ID Tenant
- delRemove Microsoft Entra ID Tenant
- Traffic Rules
- General Options
- Security
- postStart Security & Compliance Analyzer
- getGet Security & Compliance Analyzer Last Run
- getGet Security & Compliance Analyzer Schedule
- putModify Security & Compliance Analyzer Schedule
- postReset All Security & Compliance Analyzer Statuses
- getGet Security & Compliance Analyzer Results
- postSuppress Security & Compliance Analyzer Best Practice Status
- postReset Security & Compliance Analyzer Status
- getGet All Authorization Events
- getGet Authorization Event
- Malware Detection
- Configuration Backup
- Managed Servers
- Repositories
- getGet All Repositories
- postAdd Repository
- getGet All Repository States
- getGet Repository
- putEdit Repository
- delRemove Repository
- getGet All Scale-Out Backup Repositories
- postAdd Scale-Out Backup Repository
- getGet Scale-Out Backup Repository
- putEdit Scale-Out Backup Repository
- delRemove Scale-Out Backup Repository
- postEnable Sealed Mode
- postDisable Sealed Mode
- postEnable Maintenance Mode
- postDisable Maintenance Mode
- Proxies
- WAN Accelerators
- Jobs
- Backups
- Backup Objects
- Restore Points
- Backup Browsers
- getGet All File Restore Mount Points
- getGet File Restore Mount Point
- postBrowse File System
- postCompare Attributes
- postCompare Files and Folders
- postSearch for Files and Folders
- postBrowse Search Results
- postRestore Files and Folders to Original Location
- postRestore Files and Folders to Another Location
- postPrepare Files and Folders for Download
- postDownload Files and Folders
- getGet All Unstructured Data Mount Points
- getGet Unstructured Data Mount Point
- postBrowse Unstructured Data File System
- postSearch for Files and Folders in Unstructured Data Source
- postBrowse Search Results
- postCopy Files and Folders to Specific Folder
- getGet Mount Points of All Entra ID Tenants
- getGet Mount Point of Microsoft Entra ID Tenant
- postGet Restore Points of Microsoft Entra ID Tenant
- postGet Microsoft Entra ID Items
- postGet Microsoft Entra ID Item
- postGet Restore Points of Microsoft Entra ID Item
- postValidate Microsoft Entra ID Items
- postCheck Microsoft Entra ID Items in Production
- postGenerate Microsoft Entra ID User Passwords
- postRestore Microsoft Entra ID Items
- postRestore Microsoft Entra ID Item Properties
- postCompare Microsoft Entra ID Item Properties
- postStart Comparing Microsoft Entra ID Item Properties
- getGet Comparison Results for Microsoft Entra ID Items
- postExport Microsoft Entra ID Items
- postUpload Microsoft Entra ID Users
- postUpload Microsoft Entra ID Groups
- postUpload Microsoft Entra ID Administrative Units
- postUpload Microsoft Entra ID Roles
- postUpload Microsoft Entra ID Applications
- getGet All Restore Sessions of Microsoft Entra ID Tenant
- getGet Restore Session of Microsoft Entra ID Tenant
- getGet Restore Session Logs of Microsoft Entra ID Tenant
- postStop Restore Session of Microsoft Entra ID Tenant
- Restore
- getGet All VM Mount Points
- postStart Instant Recovery
- getGet VM Mount Point
- postStop VM Publishing
- postStart VM Migration
- postRestore Entire VMware vSphere VM
- postRestore Entire VMware Cloud Director VM
- getGet All FCD Mounts
- postStart Instant FCD Recovery
- getGet FCD Mount Point
- postStop FCD Publishing
- postStart FCD Migration
- postStart File Restore
- postUnmount File System
- postGet User Code for Delegated Restore of Microsoft Entra ID Items
- postGet Credentials for Delegated Restore of Microsoft Entra ID Items
- postMount Microsoft Entra ID Tenant
- postUnmount Microsoft Entra ID Tenant
- postStart Microsoft Entra ID Audit Log Restore
- postUnmount Microsoft Entra ID Audit Logs
- Data Integration API
- Tasks
- Replicas
- Replica Restore Points
- Failover
- Failback
- Sessions
- Agents
- Automation
- postImport Jobs
- postExport Jobs
- postImport Credentials
- postExport Credentials
- postImport Cloud Credentials
- postExport Cloud Credentials
- postImport Proxies
- postExport Proxies
- postImport Servers
- postExport Servers
- postImport Repositories
- postExport Repositories
- postImport Encryption Passwords
- postExport Encryption Passwords
- getGet All Automation Sessions
- getGet Automation Session
- getGet Automation Session Logs
- postStop Automation Session
The Encryption section defines paths and operations for managing KMS servers and passwords that are used for data encryption.
Get All Encryption Passwords
The HTTP GET request to the /api/v1/encryptionPasswords
path allows you to get an array of all passwords that are used for data encryption.
Available to: Veeam Backup Administrator, Veeam Security Administrator.
query Parameters
skip | integer <int32> Number of passwords to skip. |
limit | integer <int32> Maximum number of passwords to return. |
orderColumn | string (EEncryptionPasswordsFiltersOrderColumn) Sorts passwords by one of the password parameters. |
orderAsc | boolean If |
header Parameters
x-api-version required | string Default: 1.2-rev0 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 500
{- "data": [
- {
- "id": "6ebbe3cc-8147-47b6-b77a-01eeb7965522",
- "hint": "Standard Password",
- "modificationTime": "2023-10-19T12:37:58.27+03:00",
- "uniqueId": "internal"
}, - {
- "id": "3261d360-1db7-4291-b1ed-360ef5b77175",
- "hint": "Created by TECH\\Administrator",
- "modificationTime": "2024-02-11T11:34:28.677+03:00",
- "uniqueId": "external"
}
], - "pagination": {
- "total": 2,
- "count": 2,
- "skip": 0,
- "limit": 200
}
}
Add Encryption Password
The HTTP POST request to the /api/v1/encryptionPasswords
path allows you to add an encryption password.
Available to: Veeam Backup Administrator, Veeam Security Administrator.
header Parameters
x-api-version required | string Default: 1.2-rev0 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
hint required | string Hint for the encryption password. Provide a meaningful hint that will help you recall the password. |
password required | string Password for data encryption. If you lose the password, you will not be able to restore it. |
uniqueId | string Unique ID for the encryption password. |
Password has been added.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "password": "passsw3wrsdf2d44",
- "hint": "Pet name",
- "uniqueId": "vcenter01"
}
- 201
- 400
- 401
- 403
- 500
{- "id": "86e99ee0-3673-48d6-bf6a-9a8058d4de96",
- "hint": "Pet name",
- "modificationTime": "2023-02-13T02:22:40.801982-08:00",
- "uniqueId": "vcenter01"
}
Get Encryption Password
The HTTP GET request to the /api/v1/encryptionPasswords/{id}
path allows you to get an encryption password that has the specified id
.
Available to: Veeam Backup Administrator, Veeam Security Administrator.
path Parameters
id required | string <uuid> ID of the encryption password. |
header Parameters
x-api-version required | string Default: 1.2-rev0 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 404
- 500
{- "id": "86e99ee0-3673-48d6-bf6a-9a8058d4de96",
- "hint": "Pet name",
- "modificationTime": "2023-02-13T02:22:40.801982-08:00",
- "uniqueId": "vcenter01"
}
Edit Encryption Password
The HTTP PUT request to the /api/v1/encryptionPasswords/{id}
path allows you to edit an encryption password that has the specified id
.
Available to: Veeam Backup Administrator, Veeam Security Administrator.
path Parameters
id required | string <uuid> ID of the encryption password. |
header Parameters
x-api-version required | string Default: 1.2-rev0 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
hint required | string Hint for the encryption password. |
id required | string <uuid> ID of the encryption password. |
modificationTime | string <date-time> Date and time when the password was last modified. |
uniqueId | string Unique ID for the encryption password. |
Password has been updated.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "id": "86e99ee0-3673-48d6-bf6a-9a8058d4de96",
- "hint": "Pet name",
- "modificationTime": "2023-02-13T02:22:40.801982-08:00",
- "uniqueId": "vcenter01"
}
- 200
- 400
- 401
- 403
- 404
- 500
{- "id": "86e99ee0-3673-48d6-bf6a-9a8058d4de96",
- "hint": "Pet name",
- "modificationTime": "2023-02-13T02:22:40.801982-08:00",
- "uniqueId": "vcenter01"
}
Remove Encryption Password
The HTTP DELETE request to the /api/v1/encryptionPasswords/{id}
path allows you to remove an encryption password that has the specified id
.
Available to: Veeam Backup Administrator, Veeam Security Administrator.
path Parameters
id required | string <uuid> ID of the encryption password. |
header Parameters
x-api-version required | string Default: 1.2-rev0 Version and revision of the client REST API. Must be in the following format: |
Password has been removed.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 204
- 401
- 403
- 404
- 500
{ }
Get All KMS Servers
The HTTP GET request to the /api/v1/kmsServers
path allows you to get an array of all KMS servers that are added to the backup infrastructure.
Available to: Veeam Backup Administrator, Veeam Security Administrator.
query Parameters
skip | integer <int32> Number of KMS servers to skip. |
limit | integer <int32> Maximum number of KMS servers to return. |
orderColumn | string (EKMSFiltersOrderColumn) Sorts KMS servers by one of the KMS server parameters. |
orderAsc | boolean If |
nameFilter | string Filters KMS servers by the |
typeFilter | string (EKeyManagementServerType) Filters KMS servers by KMS server type. |
header Parameters
x-api-version required | string Default: 1.2-rev0 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 500
{- "data": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "name": "string",
- "description": "string",
- "type": "KMS",
- "port": 0,
- "serverCertificateThumbprint": "string",
- "clientCertificateThumbprint": "string"
}
], - "pagination": {
- "total": 0,
- "count": 0,
- "skip": 0,
- "limit": 0
}
}
Add KMS Server
The HTTP POST request to the /api/v1/kmsServers
path allows you to add a KMS server to the backup infrastructure.
Available to: Veeam Backup Administrator, Veeam Security Administrator.
header Parameters
x-api-version required | string Default: 1.2-rev0 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
name required | string Full DNS name or IP address of the KMS server. |
type required | string (EKeyManagementServerType) KMS server type. |
port required | integer KMIP port on the backup server. You must open the port manually. |
required | object (CertificateUploadSpec) Certificate settings (for certificate-based authentication). |
required | object (CertificateUploadSpec) Certificate settings (for certificate-based authentication). |
description | string KMS server description. |
KMS server has been added.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "name": "string",
- "description": "string",
- "type": "KMS",
- "port": 0,
- "serverCertificate": {
- "certificate": "string",
- "formatType": "pfx",
- "password": "string"
}, - "clientCertificate": {
- "certificate": "string",
- "formatType": "pfx",
- "password": "string"
}
}
- 201
- 400
- 401
- 403
- 500
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "name": "string",
- "description": "string",
- "type": "KMS",
- "port": 0,
- "serverCertificateThumbprint": "string",
- "clientCertificateThumbprint": "string"
}
Get KMS Server
The HTTP GET request to the /api/v1/kmsServers/{id}
path allows you to get a KMS server that has the specified id
.
Available to: Veeam Backup Administrator, Veeam Security Administrator.
path Parameters
id required | string <uuid> ID of the KMS server. |
header Parameters
x-api-version required | string Default: 1.2-rev0 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 404
- 500
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "name": "string",
- "description": "string",
- "type": "KMS",
- "port": 0,
- "serverCertificateThumbprint": "string",
- "clientCertificateThumbprint": "string"
}
Edit KMS Server
The HTTP PUT request to the /api/v1/kmsServers/{id}
path allows you to edit a KMS server that has the specified id
.
Available to: Veeam Backup Administrator, Veeam Security Administrator.
path Parameters
id required | string <uuid> ID of the KMS server. |
header Parameters
x-api-version required | string Default: 1.2-rev0 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
id required | string <uuid> ID of the KMS server. |
name required | string Full DNS name or IP address of the KMS server. |
type required | string (EKeyManagementServerType) KMS server type. |
port required | integer <int32> KMIP port on the backup server. |
description | string KMS server description. |
serverCertificateThumbprint | string Thumbprint of the KMS server certificate. |
clientCertificateThumbprint | string Thumbprint of the client certificate created on the KMS server. |
KMS server has been updated.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "name": "string",
- "description": "string",
- "type": "KMS",
- "port": 0,
- "serverCertificateThumbprint": "string",
- "clientCertificateThumbprint": "string"
}
- 200
- 400
- 401
- 403
- 404
- 500
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "name": "string",
- "description": "string",
- "type": "KMS",
- "port": 0,
- "serverCertificateThumbprint": "string",
- "clientCertificateThumbprint": "string"
}
Remove KMS Server
The HTTP DELETE request to the /api/v1/kmsServers/{id}
path allows you to remove a KMS server that has the specified id
.
Available to: Veeam Backup Administrator, Veeam Security Administrator.
path Parameters
id required | string <uuid> ID of the KMS server. |
header Parameters
x-api-version required | string Default: 1.2-rev0 Version and revision of the client REST API. Must be in the following format: |
KMS server has been removed.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 204
- 400
- 401
- 403
- 404
- 500
{ }
Change KMS Server Certificate
The HTTP POST request to the /api/v1/kmsServers/{id}/changeCertificate
path allows you to change a certificate of a KMS server that has the specified id
.
Available to: Veeam Backup Administrator, Veeam Security Administrator.
path Parameters
id required | string <uuid> ID of the KMS server. |
header Parameters
x-api-version required | string Default: 1.2-rev0 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
type required | string (EKMSCertificateType) Certificate type. |
required | object (CertificateUploadSpec) Certificate settings (for certificate-based authentication). |
KMS server certificate has been changed.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "certificate": {
- "certificate": "string",
- "formatType": "pfx",
- "password": "string"
}, - "type": "Client"
}
- 204
- 400
- 401
- 403
- 500
{ }