DirectAdmin has run two API surfaces for several years: the original CMD_API_* and CMD_* form endpoints on port 2222 that return URL-encoded or JSON data, and the newer REST-style /api/ endpoints introduced with the Go rewrite. Since 1.688 the project has been removing legacy endpoints one release at a time, and by 1.712 several that billing platforms, monitoring tools and in-house scripts relied on have gone. The removals are announced in the changelog, but scripts do not read changelogs. This guide lists the removals to date and shows how to find and replace them.
Applies to DirectAdmin 1.688 to 1.712
Table of Contents
Short answer: Between 1.688 and 1.712 DirectAdmin removed CMD_MODSECURITY?action=log, swagger.json, CMD_AJAX_GET_COUNTS, the CMD_*_LIMITS endpoints, the File Manager tree endpoint and CMD_AJAX_SEARCH, each replaced by a JSON /api/ path documented live by the panel. Grep /var/log/directadmin/access.log* for CMD_ requests to find the scripts, plugins and billing modules still calling them, then move those calls to /api/ with a scoped login key.
The removals so far
The endpoints below are gone as of the versions shown. Each had been superseded by an /api/ equivalent for at least a few releases before removal.
CMD_MODSECURITY?action=log(1.688): the ModSecurity log view. Replaced by the Web application firewall page and its/api/log endpoints, which return structured JSON rather than a rendered page.swagger.json(1.703): the static OpenAPI description. The live API documentation is served by the panel itself under the/apidocumentation path on Evolution builds; check the changelog for your build for the exact URL.CMD_AJAX_GET_COUNTS(1.704): the counts of users, domains and messages shown in the skin header. Replaced by the session and dashboard/api/endpoints.CMD_*_LIMITS(1.706): the per-user limit endpoints used to read package quotas. Replaced by the user and package resources under/api/.- The File Manager tree endpoint (1.711): used by the Enhanced skin’s file browser. The reworked File Manager in Evolution uses
/api/filemanager/paths. CMD_AJAX_SEARCH(1.712): the skin search box. Replaced by the search/api/endpoint.
Two related deprecations belong on the same list even though they are scripts rather than endpoints: move_user_to_reseller.sh (1.703) in favour of the API action, and the automatic private_html creation removed in 1.711, which changes what CMD_API_DOMAIN and its replacement return for new domains.
Find what still calls them
Every request to the panel is logged. Search the access log for the retired names and for any CMD_ request coming from an automated client, identifiable by a fixed user agent or an API key login:
grep -hoE 'CMD_[A-Z_]+' /var/log/directadmin/access.log* | sort | uniq -c | sort -rn
grep -E 'CMD_AJAX_SEARCH|CMD_AJAX_GET_COUNTS|CMD_MODSECURITY|_LIMITS' /var/log/directadmin/access.log* | awk '{print $1}' | sort | uniq -c
The second command lists the client IPs still calling removed endpoints. Typical callers are a WHMCS or Blesta module pinned to an old version, a custom provisioning script, an uptime checker that hit CMD_AJAX_GET_COUNTS because it was cheap, and skins or plugins that were never updated. Plugins are worth a separate search because they run on the server:
grep -rl 'CMD_AJAX_\|CMD_MODSECURITY\|_LIMITS' /usr/local/directadmin/plugins/ 2>/dev/null
Move to /api/
The /api/ surface uses the same login keys and session cookies as the legacy endpoints, plus bearer tokens for scripts. Create a login key with only the permissions the script needs, at Admin Level → Login Keys or through the API, and call the JSON endpoints with it:
curl -s -u 'admin:LOGINKEY' https://server.example.net:2222/api/users | jq '.[].username'
curl -s -u 'admin:LOGINKEY' https://server.example.net:2222/api/users/USER/usage | jq .
Responses are JSON with stable field names, which removes the URL-decoding step that made the legacy API awkward to script. The documentation served by the panel lists every path with its parameters; since swagger.json was removed, use that live documentation rather than a cached copy, because paths added in 1.71x for the new TLS system and the system backup are only described there.
For billing modules, update to the vendor’s current release before rewriting anything. The maintained DirectAdmin modules for the major billing platforms switched to /api/ during 2025 and 2026, and a module that still uses CMD_API_SHOW_USER_USAGE or CMD_API_LIMITS is simply out of date.
Common pitfall: assuming CMD_API_ endpoints are next
Not everything under CMD_API_ is scheduled for removal. The core provisioning endpoints such as CMD_API_ACCOUNT_USER and CMD_API_SHOW_USERS remain in place, and the changelog names each removal explicitly. Rewriting every integration pre-emptively is wasted effort; auditing the access log after each upgrade is not. The practical rule is to migrate a call when its replacement appears in the /api/ documentation, and to treat a deprecation notice in the changelog as the deadline.
Keep it running
Add a check to the post-upgrade routine that runs the access-log search above and flags any hit on the removed endpoints, and read the changelog section on removed endpoints for every release before it is applied on production. With the channel set to stable and updates every two to three weeks, that is a short task each month. Test integrations against a server on the current channel, which receives releases first, so a removal surfaces there before it reaches production. The commands for channel selection are in The da CLI: update, build and config-set.
DirectAdmin removed API endpoints at a glance

Official documentation: DirectAdmin documentation, Linux man pages.
Related guides: Using the da CLI: da update, da build, da config-set, da user and update channels · Broken custom Apache/nginx templates after the DOCROOT token change in DirectAdmin 1.710 · Installing DirectAdmin on AlmaLinux 9/10 and Debian 13 (modern license, web installer vs CLI).
Frequently asked questions
Does the removal of legacy endpoints also affect WHMCS and Blesta DirectAdmin modules?
Only outdated ones. The maintained modules for the major billing platforms moved to /api/ during 2025 and 2026, so updating the module to its current release is usually enough; a module that still calls CMD_API_LIMITS or CMD_AJAX_GET_COUNTS needs updating before the next panel release.
How long does migrating a script from CMD_ endpoints to /api/ take?
For most provisioning scripts a few hours: the login key and authentication are unchanged, and the work is mapping each call to its /api/ path in the panel’s live documentation and switching from URL-encoded parsing to JSON.
Can I undo this?
Not on the server side, because removed endpoints are gone from the binary and the only way to get them back is to run an older DirectAdmin release, which is not advisable given the security fixes in 1.711. Script changes can be reverted, but the legacy calls they restore will keep failing.
Maintenance record
This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.
- Maintained by
- srvScripts editorial team
- Supported versions
- DirectAdmin 1.688 to 1.712
- Last full review
- Next review
- Sources
- docs.directadmin.com