Ludus API
    • Host Management
      • Retrieve the ludus version
        GET
      • Retrieve the ludus license
        GET
      • Diagnostics
        GET
      • Retrieve the Ludus OpenAPI specification
        GET
    • Ansible Management
      • Retrieve available subscription roles
        GET
      • Install subscription roles
        POST
      • Get role variables for one or more Ansible roles
        POST
      • Install or Remove an Ansible collection
        POST
      • Retrieve available Ansible roles and collections
        GET
      • Move or copy roles between global and local scopes
        PATCH
      • Install or Remove an Ansible role
        POST
      • Install an Ansible role from local directory
        PUT
    • User Management
      • whoami
        GET
      • Get Default Range ID
        GET
      • Set Default Range ID
        POST
      • Get user group memberships
        GET
      • List user details
        GET
      • Add a user to the system
        POST
      • Remove a user from the system
        DELETE
      • Get proxmox creds for a user
        GET
      • Set the Ludus and Proxmox creds for the user
        POST
      • Reset and retrieve the Ludus API key for a user
        GET
      • List all users
        GET
      • Retrieve a WireGuard configuration file for a user
        GET
    • Range Management
      • VM Management
      • Create a new range
        POST
      • List range VMs, power state, and testing state
        GET
      • Delete a range from the database and proxmox host
        DELETE
      • Stop the range deployment ansible process
        POST
      • Stop and delete all range VMs
        DELETE
      • List all tags available to use with deploy
        GET
      • List summary information for all ranges
        GET
      • Retrieve range configuration
        GET
      • Update the range configuration
        PUT
      • Retrieve an example range configuration
        GET
      • Deploy the range
        POST
      • Retrieve the latest range logs
        GET
      • Retrieve /etc/hosts file for the range
        GET
      • Retrieve a ssh config
        GET
      • Retrieve a zip file of RDP configs
        GET
      • Retrieve an ansible inventory
        GET
      • Assign a range to a user (admin only)
        POST
      • Revoke range access from a user (admin only)
        DELETE
      • List users with access to a range (admin only)
        GET
      • List ranges accessible to the user
        GET
      • List range deploy log history
        GET
      • Retrieve a specific range log history entry
        GET
      • Retrieve auto-shutdown configuration (enterprise)
        GET
      • Update auto-shutdown (enterprise)
        PUT
    • Power State Management
      • Power on range VMs
      • Power off range VMs
    • Testing State Management
      • Snapshot and enter testing state
      • Revert and exit testing state
      • Allow a domain
      • Deny a domain
      • Update a VM or group
    • Anti-Sandbox Management
      • Enable anti-sandbox for a VM or multiple VMs (enterprise)
      • Install the custom QEMU/OMVF packages
      • Install the standard QEMU/OMVF packages
    • Template Management
      • Retrieve a list of VM templates
      • Build templates
      • Install an Ansible role from local directory
      • Delete a template
      • Kill packer processes for user
      • Retrieve the latest packer logs
      • Get the status of packer builds
      • List template build log history
      • Retrieve a specific template log history entry
    • Snapshot Management
      • Get all snapshots for a range
      • Take a snapshot of a VM or multiple VMs
      • Roll back to a snapshot of a VM or multiple VMs
      • Delete a snapshot from a VM or multiple VMs
    • KMS Management
      • Setup the KMS VM and install the KMS server
      • License Windows VMs using the KMS server
    • Group Management
      • Create a new group
      • List all groups
      • Delete a group
      • List group members
      • Add users to group
      • Remove users from group
      • List group ranges
      • Add ranges to group
      • Remove ranges from group
    • Migration
      • SDN Migration Status
      • Migrate to SDN networking
      • Migrate SQLite to PocketBase
    • Blueprint Management
      • List blueprints
      • Create blueprint
      • Create blueprint from range
      • Copy blueprint
      • Import blueprint
      • Apply blueprint to range
      • Get blueprint config
      • Update blueprint config
      • List blueprint access users
      • Share blueprint with users
      • Unshare blueprint from users
      • List blueprint access groups
      • Share blueprint with groups
      • Unshare blueprint from groups
      • Get blueprint detail
      • Install blueprint dependencies
      • Export blueprint
      • Delete blueprint
    • Quota Management
      • Get quota status for the current user
      • Set quotas for one or more users (admin only)
      • Get quota status for all users (admin only)
      • Get system-wide default quotas (admin only)
      • Get default quotas for all groups (admin only)
      • Set default quotas for one or more groups (admin only)
    • Sources
      • Create source
      • Get source catalog
      • Install items from source
      • Sync source
      • Update source
      • List sources
      • Get source metadata
      • List source blueprints
      • List source templates
      • List source roles
      • List source collections
      • Delete source
    • VM Management
      • Destroy VM
      • Get Console Websocket Ticket
      • Connect to VM Console WebSocket
    • Download range machine credentials
      GET
    • Schemas
      • userID
      • BlueprintListItem
      • BulkAddUsersToGroupRequest
      • rangeID
      • CreateBlueprintFromRangeRequest
      • BulkRemoveUsersFromGroupRequest
      • UserObject
      • CopyBlueprintRequest
      • BulkAddRangesToGroupRequest
      • ApplyBlueprintRequest
      • BulkRemoveRangesFromGroupRequest
      • UserAPIKeyObject
      • UpdateBlueprintConfigRequest
      • UserCredentialObject
      • BulkGroupOperationResponse
      • RangeObject
      • UserMembershipObject
      • BulkGroupOperationErrorItem
      • BulkShareBlueprintWithGroupsRequest
      • BlueprintAccessUserItem
      • BulkUnshareBlueprintWithGroupsRequest
      • BlueprintAccessGroupItem
      • BulkShareBlueprintWithUsersRequest
      • Domain
      • BulkUnshareBlueprintWithUsersRequest
      • IP
      • AllowPayload
      • BulkBlueprintOperationErrorItem
      • SnapshotInfo
      • BulkBlueprintOperationResponse
      • BlueprintMutationResponse
      • ErrorInfo
      • SnapshotCreatePayload
      • LicenseDataObject
      • AnsibleInstallResult
      • UndeclaredDependency
      • SyncResultResponse
      • InstallBlueprintDepsRequest
      • BlueprintDetail
      • CatalogItem
      • CatalogBlueprint
      • SourceResponse
      • SourceCatalog
      • UpdateSourceRequest
      • RegisterSourceResponse
      • SyncSourceRequest
      • SyncResult
      • InstallRequest
      • InstallSelection
      • DeleteSourceResponse
      • VMObject
      • BlueprintCreatedResponse
      • CreateBlueprintRequest
      • LogHistoryEntry
      • CopyBlueprintResponse
      • LogHistoryDetailResponse
      • UpdateBlueprintMetadataRequest
      • JobAcceptedResponse
      • TemplateStatusEntry
      • RoleStatusEntry
      • SourceCreateResponse
      • DeleteSourceRequest
      • ArtifactResult
      • RoleInstallResult
      • DryRunPlan
      • SourceBlueprintListItem
      • ListSourceTemplatesResponseItem
      • ListSourceCollectionsResponseItem
      • ListSourceRolesResponseItem
      • BlueprintCreatedResponseRoleResult
      • BlueprintCreatedResponseAnsibleResult
      • CatalogBlueprints

      Download range machine credentials

      Developing
      Cloud Mock
      https://mock.apidog.com/m1/1126461-0-default
      Cloud Mock
      https://mock.apidog.com/m1/1126461-0-default
      GET
      https://mock.apidog.com/m1/1126461-0-default
      /range/machine-credentials

      Download the existing SSH machine credentials for a range as a ZIP archive. Requires the Ludus Enterprise plugin. Use the normal Ludus API service, not the admin service.

      Authentication and range access

      Authenticate with a valid Ludus API key in X-API-KEY or a valid user JWT in Authorization. Non-admin users must have access to the selected range, including when their default range is used. Administrators may select another user's context with userID; access checks then use that user's privileges.

      Range selection

      Pass rangeID to select a range. If omitted, the endpoint uses the authenticated or impersonated user's default range. URL-encode query parameter values.

      Archive contents

      The archive contains exactly README.txt (connection instructions), ssh/ludus_ed25519 (SSH private key, Unix mode 0600), and ssh/ludus_ed25519.pub (SSH public key, Unix mode 0644). These keys authenticate to Linux, macOS, and Windows hosts configured for the range's SSH key authentication. They are SSH keys, not CA-signed SSH certificates. No passwords or WinRM certificates are included.

      This endpoint only reads existing credentials. It does not provision, regenerate, or rotate them. A missing credential set returns 404; an invalid or unreadable set returns 500.

      Sensitive download

      Treat this archive as administrative access to the range. Store it privately and do not cache or log its contents. The attachment filename is -machine-credentials.zip, with slashes in the range ID replaced by hyphens. On Unix-like systems, set mode 0600 on the private key after extraction. Verify the guest host key and use the configured SSH username when connecting.

      CLI

      Run ludus range machine-credentials -r MYRANGE -o machine-credentials.zip. Omit -r to use your default range. The CLI saves the archive with owner-only permissions on Unix-like systems.

      Request

      Authorization
      JWT Bearer
      Add the parameter
      Authorization
      to Headers
      Example:
      Authorization: ********************
      or
      API Key
      Add parameter in header
      X-API-KEY
      Example:
      X-API-KEY: ********************
      or
      Query Params

      Header Params

      Responses

      🟢200Machine credentials ZIP
      application/zip
      Binary ZIP containing README.txt and the existing SSH private/public key pair. Save to a file; do not parse as JSON.
      Headers

      🟠400Impersonated user not found
      🟠401Authentication or impersonation denied
      🟠403Range access denied
      🟠404Range or credentials not found
      🔴500Credentials unavailable
      Request Request Example
      Shell
      JavaScript
      Java
      Swift
      ludus range machine-credentials -r MYRANGE -o machine-credentials.zip
      Response Response Example
      400 - Unknown impersonated user
      {"error":"User JD from query parameter not found"}
      Modified at 2026-10-02 20:11:30
      Previous
      Connect to VM Console WebSocket
      Next
      userID
      Built with