How to back up a Hostinger VPS
Every Hostinger VPS plan gets a free automatic backup once a week, a paid upgrade adds daily ones, and Hostinger keeps the two newest of each. You can also take one manual snapshot, which is deleted after a day. Both restore the whole VPS in place and neither can be downloaded, so use them for rollbacks and add your own nightly backup of files and database dumps to storage at another provider.
What Hostinger gives you
| Automatic backups | Snapshot | |
|---|---|---|
| Plans | Every VPS plan (KVM 1, 2, 4 and 8): weekly, included. Daily is a paid upgrade. | Every VPS plan |
| When | Weekly by default, or daily with the upgrade. Hostinger fixes the time; you cannot change it. | When you create one, in hPanel or through the API |
| Kept | The two newest weekly and the two newest daily backups. Each new one replaces the oldest of its kind. | One. A new snapshot overwrites it. It is deleted after 1 day, and reinstalling the OS or restoring a backup deletes it too. |
| Where | Stored separately from the VPS; not counted against its disk | Not stated |
| Restore | The whole VPS, overwriting it. Cannot be stopped once started. | The whole VPS, back to that moment |
| Download | Not supported | Not supported |
Hostinger's VPS page lists free weekly backups and snapshots on every plan and gives no price for daily backups, which you buy in hPanel (as of October 2026). A backup takes from 10 minutes to a few hours, and the VPS is locked while it runs: you cannot manage it in hPanel, and Hostinger warns that availability and performance may vary.
What the retention means in days: with weekly backups only, the newest backup is up to 7 days old and the oldest up to 14. If the backup runs on a Sunday and the disk fails the next Saturday, six days of orders, posts and uploads are gone. Damage you notice 15 days after it happened is inside both backups. The daily upgrade cuts the first loss to under a day, but the two daily backups reach back only two days; the weekly ones still set the 14-day limit.
Take a snapshot before risky changes
A snapshot suits a planned change, such as a release upgrade: take it, make the change, and roll back if it goes wrong. It lasts one day, so take it right before you start. In hPanel:
- In the Hostinger dashboard, go to VPS and click Manage next to the server.
- In the sidebar, choose Backups & Monitoring > Snapshots & Backups.
- Click Create Snapshot. It appears above the backups list, where you can restore or delete it.
Restoring a snapshot or backup overwrites the whole VPS: everything written since is lost, and the restore cannot be stopped once it starts. Copy out anything you need first, over SFTP or with rsync.
From a script, use Hostinger's API. Create a token on the API page in hPanel with Generate new token; it is shown once and can be set to expire. A token has the permissions of the user who created it, which means your whole account, so keep it on your own computer, not on the VPS. Load it without echoing it:
read -rsp 'Hostinger API token: ' HOSTINGER_API_TOKEN && export HOSTINGER_API_TOKENList your servers with their ID, hostname, plan and state (needs curl 7.76 or newer for --fail-with-body, and jq):
curl -sS --fail-with-body -H "Authorization: Bearer $HOSTINGER_API_TOKEN" https://developers.hostinger.com/api/vps/v1/virtual-machines | jq -r '.[] | [.id, .hostname, .plan, .state] | @tsv'Take the snapshot. The reply is an action with an id and a state:
curl -sS --fail-with-body -X POST -H "Authorization: Bearer $HOSTINGER_API_TOKEN" -H "Content-Type: application/json" https://developers.hostinger.com/api/vps/v1/virtual-machines/<vm-id>/snapshotCheck the action until its state is success (or error), then read the snapshot's creation and expiry times:
curl -sS --fail-with-body -H "Authorization: Bearer $HOSTINGER_API_TOKEN" https://developers.hostinger.com/api/vps/v1/virtual-machines/<vm-id>/actions/<action-id> | jq -r .statecurl -sS --fail-with-body -H "Authorization: Bearer $HOSTINGER_API_TOKEN" https://developers.hostinger.com/api/vps/v1/virtual-machines/<vm-id>/snapshot | jq '{created_at, expires_at}'Hostinger's official hostinger CLI wraps the same calls (hostinger vps snapshots create <vm-id>, plus get, restore and delete) and reads the token from HOSTINGER_API_TOKEN. The API allows 90 requests a minute per user. A 401 with "message": "Unauthenticated." means the token is missing, malformed, expired or revoked; Hostinger answers 404, not 403, when the token is valid but cannot see that VPS.
Restore a Hostinger backup
- Go to VPS > Manage > Backups & Monitoring > Snapshots & Backups.
- Find the date in the backups list and click Restore. Note the estimated time.
- Wait. The VPS is locked until it finishes; Backups & Monitoring > Latest actions shows a
backup_restoreentry with its status. - Restart the VPS so every service starts cleanly.
If a date is missing, there is no backup for it. Through the API, list the backups with their ID, creation time, size in kilobytes and estimated restore time in seconds, then restore one:
curl -sS --fail-with-body -H "Authorization: Bearer $HOSTINGER_API_TOKEN" https://developers.hostinger.com/api/vps/v1/virtual-machines/<vm-id>/backups | jq -r '.data[] | [.id, .created_at, .size, .restore_time] | @tsv'curl -sS --fail-with-body -X POST -H "Authorization: Bearer $HOSTINGER_API_TOKEN" -H "Content-Type: application/json" https://developers.hostinger.com/api/vps/v1/virtual-machines/<vm-id>/backups/<backup-id>/restoreIf hPanel still shows the VPS as locked after the restore has finished, Hostinger suggests clearing the browser cache or opening the dashboard in a private window.
When a VPS will not boot and you only need data off it, use Emergency mode instead (Manage > Settings > Emergency mode). It stays on for up to 24 hours with your disk under /mnt, where you can copy files and database data off. The API's recovery endpoint does the same with a temporary root password.
Why Hostinger's copies are not enough
- Same company, same account. Hostinger's cancellation guide says that ending a service, by expiry or refund, "will permanently delete all its associated data", and its emergency mode guide says emergency mode cannot retrieve backups from an expired VPS plan. A lost login, a missed payment or a leaked API token reaches the server and its backups together.
- Short windows. The oldest copy is about two weeks old. Damage found later is in every backup.
- Tied to the VPS. Backups and snapshots cannot be downloaded, and Hostinger documents restoring them only onto the VPS they came from. Neither can start a server elsewhere.
- All or nothing. Getting one deleted file back means rolling back the whole VPS and losing everything written since.
The 3-2-1 rule asks for one copy off-site. For a VPS that means storage at another company, in an account that a Hostinger problem cannot touch.
Back up nightly to another provider
Back up the data, not the disk: /etc, site and app files (/var/www, /home, /root, and /opt or /srv if your apps live there), crontabs, and each database as a dump. The server backup checklist covers the rest. If the VPS runs Docker apps from Hostinger's catalog, such as n8n, add their volumes as in Docker volume backups.
restic fits well: it encrypts on the server, uploads only changed data and writes straight to an S3-compatible bucket. Install it and create the root-only /etc/restic/env and password file as in the restic guide, pointing at a bucket at another company, for example Backblaze B2. Then run restic init once.
RESTIC_REPOSITORY=s3:https://s3.us-west-004.backblazeb2.com/my-backups/hostinger-web1
RESTIC_PASSWORD_FILE=/etc/restic/password
RESTIC_CACHE_DIR=/var/cache/restic
AWS_ACCESS_KEY_ID=your-key-id
AWS_SECRET_ACCESS_KEY=your-application-key#!/usr/bin/env bash
# Nightly backup of a Hostinger VPS to a bucket at another provider.
set -euo pipefail
set -a; . /etc/restic/env; set +a
# 1. The database, streamed into restic. A failed dump creates no snapshot.
restic backup --tag db --stdin-filename app.sql --stdin-from-command -- mysqldump --single-transaction --routines --events app
# 2. Files. --one-file-system stays on the filesystem of each directory listed.
restic backup --tag files --one-file-system --exclude-caches /etc /var/www /home /root /var/spool/cron
# 3. Keep 7 daily, 4 weekly and 6 monthly snapshots of each; delete the rest.
restic forget --keep-daily 7 --keep-weekly 4 --keep-monthly 6 --prune--stdin-from-commandrunsmysqldumpand stores its output in the snapshot as/app.sql, with nothing written to disk. restic's docs: a non-zero exit from the command cancels the backup, and no snapshot is created.--single-transactiondumps InnoDB tables consistently without locking them. On Ubuntu and Debian, root usually reaches MySQL or MariaDB through the socket with no password; otherwise use root's option file as in the mysqldump guide. For PostgreSQL, putsudo -u postgres pg_dump appafter the--instead.forgetapplies the policy to the database and the files separately, because restic groups snapshots by host and paths.
sudo chmod 700 /usr/local/bin/offsite-backup.sh30 2 * * * root /usr/local/bin/offsite-backup.sh >> /var/log/offsite-backup.log 2>&1Keep the restic password and the bucket keys in a password manager as well. A copy that lives only on the VPS is lost with it.
Restore onto a new VPS, at Hostinger or anywhere
- Create a server with the same OS release as the old one.
- Install restic and put
/etc/restic/envand the password file back. - Restore the newest files snapshot to a staging directory and copy what you need into place.
- Create the database and its user, then load the dump.
- Point DNS at the new IP and test the site before anyone else does.
In a root shell, with the env file loaded (set -a; . /etc/restic/env; set +a):
restic restore latest --tag files --target /srv/restoremysql -e 'CREATE DATABASE app'restic dump --path /app.sql latest app.sql | mysql app--tag files and --path /app.sql pick the newest snapshot of each kind; plain latest would take whichever ran last. A single-database dump holds no users or grants, so recreate the app's user with CREATE USER and GRANT, using the password in its config. From /srv/restore/etc, copy directories such as /etc/nginx and /etc/letsencrypt, never all of /etc: fstab, the network config and the SSH host keys belong to the old machine. The full sequence, with checks, is in restoring a server from backup.
If you move to a provider whose whole-server snapshots can be scheduled, DigitalOcean is one of the eight clouds VPS Snaps supports, on every plan.
Create a DigitalOcean accountAffiliate link — we earn a commission if you sign up.
Check that it works
- Read the log every morning for the first week, then add an alert as in backup failure alerts. A backup that silently stopped protects nothing.
- Run
restic checkweekly to verify the repository's structure. - Once a month, restore onto a throwaway server and open the site, as in testing a restore. Hostinger plans are paid upfront for 1, 12 or 24 months, so an hourly-billed server elsewhere is the cheaper place for the test. Time it: that is your real recovery time.
Frequently asked questions
- Does Hostinger back up my VPS automatically?
- Yes. Every VPS plan gets a free weekly backup, and Hostinger keeps the two newest. A paid upgrade adds daily backups, of which it keeps the two newest as well.
- How long does Hostinger keep VPS snapshots?
- One day. You can have one snapshot at a time; a new one overwrites it, and reinstalling the OS or restoring a backup deletes it.
- Can I download a Hostinger VPS backup?
- No. Hostinger does not support downloading VPS backups or snapshots. Copy files over SFTP, or keep your own backup in storage you control.
- Can I change the time of Hostinger's VPS backup?
- No. Hostinger fixes the backup time; you can only choose weekly, daily (paid) or off.
- Can I restore one file from a Hostinger VPS backup?
- No. A restore overwrites the whole VPS. For single files, use your own file-level backup, or copy the file out of emergency mode.
How this was checked
Commands, limits and prices were checked against these official pages, on October 4, 2026:
- Hostinger Help: How to back up or restore a Hostinger VPS
- Hostinger Help: How to activate Daily Backups
- Hostinger Help: How to use emergency mode on your VPS
- Hostinger Help: How to cancel a Hostinger service
- Hostinger: VPS hosting plans
- Hostinger API Reference: authentication, requests and rate limits
- Hostinger API Reference: Errors
- Hostinger API Reference: VPS snapshots
- Hostinger API Reference: VPS backups
- Hostinger API OpenAPI specification
- Hostinger Docs: Security & Access (API tokens)
- Hostinger CLI: documentation
- Hostinger CLI: vps snapshots create
- restic documentation: Backing up (reading data from a command)
- restic documentation: Restoring from backup
- restic documentation: Removing backup snapshots