Automate administration with the Web Manager API

Access every Web Manager operation from your applications and scripts through the full SFTPPlus MFT JSON-RPC administration API.

Published
2026-10-06

SFTPPlus MFT provides a JSON-RPC administration API for reading configuration, applying changes, and operating file transfer services. Your applications can use it to automate routine administration, such as creating partner accounts, updating transfer settings, or checking whether a service is running.

The Web Manager is a JavaScript client of this API, and the admin-shell CLI uses the same API for command-line administration. Every action available in the browser interface is also available through the API, so an integration can perform the same work as an administrator using Web Manager. There are no private API methods or administrative capabilities reserved for Web Manager. Your applications have access to the full administration API, subject to the permissions of the administrator account they use.

Connect administration to your workflows ​

An account provisioning system can create a file transfer user when a partner joins and remove that account when the relationship ends. A deployment pipeline can apply configuration changes, while an operations tool can inspect service status or start and stop components. These workflows can call the API directly without automating browser interactions.

Requests use JSON over HTTP through the Web Manager service. Use HTTPS to protect credentials and administrative traffic. The API uses the same administrator accounts and role permissions as the browser interface, so you can limit an integration to the operations it needs.

Delete a user with curl ​

The following example removes a user account configured in SFTPPlus MFT. Replace the example host and port with your Web Manager address and use administrator credentials with permission to remove that account.

WARNING

This curl example is for demonstration only. Use an API client that handles credentials securely instead. Entering a real password in the command can leave it in your shell history and expose it to other users through the process list.

First, log in to obtain a session ID:

shell
curl 'https://sftpplus.example.com:10020/json' \
  --header 'Content-Type: application/json' \
  --data '{
    "jsonrpc": "2.0",
    "id": 1,
    "method": "login",
    "params": {"username": "admin", "password": "YOUR_PASSWORD"}
  }'

Copy result.session_id from the response into YOUR_SESSION_ID below. Replace USER_UUID with the account's UUID, which identifies the account independently of its username. You can find it by calling get_property with the path /configuration/accounts/ and locating the intended account in the returned configuration.

Send an apply request to delete that account and save the configuration:

shell
curl 'https://sftpplus.example.com:10020/json' \
  --header 'Content-Type: application/json' \
  --data '{
    "jsonrpc": "2.0",
    "id": 2,
    "session_id": "YOUR_SESSION_ID",
    "method": "apply",
    "params": {
      "changes": {
        "remove-user": {
          "operation": "delete",
          "path": "accounts/USER_UUID",
          "value": null
        }
      }
    }
  }'

Check the response's top-level error and the errors in result.results, including any configuration save error, before treating the deletion as successful. An HTTP success status alone does not confirm that the change succeeded. Call logout with the session ID when finished.

The Web Manager JSON-RPC API documentation covers authentication, available methods, permissions, and response handling in detail.

Choose an interface for your integration ​

Use the JSON-RPC API when your application needs to configure or operate SFTPPlus MFT. The admin-shell command-line tool uses the same management interface and is another option for scripts. For uploading and downloading file contents, see the REST API integrations page.