Nameservers, contacts, EPP code, transfer lock, WHOIS privacy and auto-renew.
These calls belong to the client API and are addressed by the numeric domain id returned by GET /reseller/domains/{name} (field data.id), not by the name. Success bodies are wrapped as {"success": true, "data": …}; refusals use the client envelope {"success": false, "message": …} (ClientError), validation failures the standard {"message", "errors"} shape.
List your domains #
GET
/client/domains
Every domain of the account, paginated, nearest expiration first, with
cancelled, transferred-away and pending-delete domains last. Filter by search (part of the name), status or
expiring_within_days.
Each item carries the numeric id the other Domain management calls are
addressed by. Read-only.
- Authentication: bearer Token
- Rate limit: 120 req/min per user
Parameters
Query
-
searchstringPart of a domain name, e.g.example. -
statusstringOnly domains in this status, e.g.active. -
expiring_within_daysintegerOnly domains expiring within this many days (already expired ones included). -
per_pageintegerDomains per page, 1–100. Defaults to this server’s page size. -
pageintegerPage number, from 1.
Responses
-
200A page of your domains.
Response body
application/json-
successboolean -
dataarray of object15 properties
-
idinteger -
client_idinteger -
sldstring -
tld_extensionstring | null -
namestring -
display_namestring -
statusstring -
auto_renewboolean -
registration_datestring | null -
expiration_datestring | null -
registration_period_yearsinteger -
currency_codestring | null -
last_synced_atstring | null -
tldobject2 properties
-
idinteger | null -
extensionstring | null
-
-
supported_actionsarray of string | null
-
-
linksobject4 properties
-
firststring | null -
laststring | null -
prevstring | null -
nextstring | null
-
-
metaobject8 properties
-
current_pageinteger -
frominteger | null -
last_pageinteger -
linksarray of object3 properties
-
urlstring | null -
labelstring -
activeboolean
-
-
pathstring -
per_pageinteger -
tointeger | null -
totalinteger
-
-
-
401Missing, invalid or expired token. MessageError -
403The token is not valid for this account, or its user lacks the required permission. When the token has an IP whitelist, a caller outside it is refused with{"success": false, "message": "IP not allowed"}, and a whitelist that cannot be read with{"success": false, "message": "IP whitelist misconfigured"}(ClientError). ClientError -
429Rate limit exceeded. Retry after the number of seconds inRetry-After. MessageError
cURL
curl 'https://portal.supporthost.com/api/v1/client/domains' \
-H "Authorization: Bearer $API_TOKEN" \
-H 'Accept: application/json'
PHP
Install Guzzle once: composer require guzzlehttp/guzzle
<?php
require 'vendor/autoload.php';
$client = new GuzzleHttp\Client();
$response = $client->request('GET', 'https://portal.supporthost.com/api/v1/client/domains', [
'headers' => [
'Authorization' => 'Bearer ' . getenv('API_TOKEN'),
'Accept' => 'application/json',
],
]);
echo $response->getBody();
Node.js
// Save as a .mjs file (ES module, Node 18+): it uses top-level await.
const response = await fetch('https://portal.supporthost.com/api/v1/client/domains', {
headers: {
Authorization: `Bearer ${process.env.API_TOKEN}`,
Accept: 'application/json',
},
});
console.log(await response.json());
200
{
"success": true,
"data": [
{
"id": 1042,
"client_id": 318,
"sld": "example",
"tld_extension": ".com",
"name": "example.com",
"display_name": "example.com",
"status": "active",
"auto_renew": false,
"registration_date": "2026-09-15T00:00:00+02:00",
"expiration_date": "2027-09-15T00:00:00+02:00",
"registration_period_years": 1,
"currency_code": "EUR",
"last_synced_at": "2026-09-27T06:00:12+02:00",
"tld": {
"id": 3,
"extension": ".com"
},
"supported_actions": [
"renew",
"get_epp",
"lock",
"unlock",
"update_nameservers",
"update_contact",
"enable_whois_privacy",
"disable_whois_privacy"
]
}
],
"links": {
"first": "https://billing.example.com/api/v1/client/domains?page=1",
"last": "https://billing.example.com/api/v1/client/domains?page=2",
"prev": null,
"next": "https://billing.example.com/api/v1/client/domains?page=2"
},
"meta": {
"current_page": 1,
"from": 1,
"last_page": 2,
"links": [
{
"url": "https://billing.example.com/api/v1/client/domains?page=1",
"label": "1",
"active": true
}
],
"path": "https://billing.example.com/api/v1/client/domains",
"per_page": 25,
"to": 25,
"total": 38
}
}
Error responses share one format: see Errors.
Get a domain #
GET
/client/domains/{domain}
One of your domains with its dates, status, auto-renew flag and, in
supported_actions, the management operations its registry supports
in the domain’s current status.
By default the data may be refreshed from the registry when it is
stale; pass fresh=1 to force a live refresh first (slower).
- Authentication: bearer Token
- Rate limit: 120 req/min per user
Parameters
Path
-
domaininteger requiredThe domain ID
Query
-
freshbooleanSet to1to refresh the domain from the registry before answering.
Responses
-
200Response body
application/json-
successboolean -
dataobject15 properties
-
idinteger -
client_idinteger -
sldstring -
tld_extensionstring | null -
namestring -
display_namestring -
statusstring -
auto_renewboolean -
registration_datestring | null -
expiration_datestring | null -
registration_period_yearsinteger -
currency_codestring | null -
last_synced_atstring | null -
tldobject2 properties
-
idinteger | null -
extensionstring | null
-
-
supported_actionsarray of string | null
-
-
-
401Missing, invalid or expired token. MessageError -
403The token is not valid for this account, or its user lacks the required permission. When the token has an IP whitelist, a caller outside it is refused with{"success": false, "message": "IP not allowed"}, and a whitelist that cannot be read with{"success": false, "message": "IP whitelist misconfigured"}(ClientError). ClientError -
404The domain does not exist or belongs to another account. ClientError -
429Rate limit exceeded. Retry after the number of seconds inRetry-After. MessageError
cURL
curl 'https://portal.supporthost.com/api/v1/client/domains/{domain}' \
-H "Authorization: Bearer $API_TOKEN" \
-H 'Accept: application/json'
PHP
<?php
require 'vendor/autoload.php';
$client = new GuzzleHttp\Client();
$response = $client->request('GET', 'https://portal.supporthost.com/api/v1/client/domains/{domain}', [
'headers' => [
'Authorization' => 'Bearer ' . getenv('API_TOKEN'),
'Accept' => 'application/json',
],
]);
echo $response->getBody();
Node.js
const response = await fetch('https://portal.supporthost.com/api/v1/client/domains/{domain}', {
headers: {
Authorization: `Bearer ${process.env.API_TOKEN}`,
Accept: 'application/json',
},
});
console.log(await response.json());
200
{
"success": true,
"data": {
"id": 1042,
"client_id": 318,
"sld": "example",
"tld_extension": ".com",
"name": "example.com",
"display_name": "example.com",
"status": "active",
"auto_renew": false,
"registration_date": "2026-09-15T00:00:00+02:00",
"expiration_date": "2027-09-15T00:00:00+02:00",
"registration_period_years": 1,
"currency_code": "EUR",
"last_synced_at": "2026-09-27T06:00:12+02:00",
"tld": {
"id": 3,
"extension": ".com"
},
"supported_actions": [
"renew",
"get_epp",
"lock",
"unlock",
"update_nameservers",
"update_contact",
"enable_whois_privacy",
"disable_whois_privacy"
]
}
}
Error responses share one format: see Errors.
Get the nameservers #
GET
/client/domains/{domain}/nameservers
The nameservers currently set at the registry, read live. Read-only.
- Authentication: bearer Token
- Rate limit: 120 req/min per user
Parameters
Path
-
domaininteger requiredThe domain ID
Responses
-
200Response body
application/json-
successboolean -
dataobject1 property
-
nameserversarray of string
-
-
-
401Missing, invalid or expired token. MessageError -
403The token is not valid for this account, or its user lacks the required permission. When the token has an IP whitelist, a caller outside it is refused with{"success": false, "message": "IP not allowed"}, and a whitelist that cannot be read with{"success": false, "message": "IP whitelist misconfigured"}(ClientError). ClientError -
404The domain does not exist or belongs to another account. ClientError -
422Validation failed (ValidationError), or the registrar refused the operation or could not be reached (ClientError). ValidationError or ClientError -
429Rate limit exceeded. Retry after the number of seconds inRetry-After. MessageError
cURL
curl 'https://portal.supporthost.com/api/v1/client/domains/{domain}/nameservers' \
-H "Authorization: Bearer $API_TOKEN" \
-H 'Accept: application/json'
PHP
<?php
require 'vendor/autoload.php';
$client = new GuzzleHttp\Client();
$response = $client->request('GET', 'https://portal.supporthost.com/api/v1/client/domains/{domain}/nameservers', [
'headers' => [
'Authorization' => 'Bearer ' . getenv('API_TOKEN'),
'Accept' => 'application/json',
],
]);
echo $response->getBody();
Node.js
const response = await fetch('https://portal.supporthost.com/api/v1/client/domains/{domain}/nameservers', {
headers: {
Authorization: `Bearer ${process.env.API_TOKEN}`,
Accept: 'application/json',
},
});
console.log(await response.json());
200
{
"success": true,
"data": {
"nameservers": [
"ns1.example.net",
"ns2.example.net"
]
}
}
Error responses share one format: see Errors.
Change the nameservers #
PUT
/client/domains/{domain}/nameservers
Replaces the domain’s nameservers at the registry with the list you
send (2 to 13 host names). completed: false means the registry
accepted the change but applies it later; message explains.
Free of charge. Refused with 403 when the domain’s status does not
allow it (e.g. expired).
- Authentication: bearer Token
- Rate limit: 120 req/min per user
Parameters
Path
-
domaininteger requiredThe domain ID
Body application/json
required
-
nameserversarray of string required2 to 13 nameserver host names, all different. The list replaces the current one.-
Min items
2 -
Max items
13 - Unique items
-
Pattern
^(?=.{1,253}$)([a-z0-9](?:[a-z0-9\-]{0,61}[a-z0-9])?)(\.[a-z0-9](?:[a-z0-9\-]{0,61}[a-z0-9])?)+$ -
Max length
253
-
Min items
Responses
-
200Response body
application/json-
successboolean -
dataobject2 properties
-
completedboolean -
messagestring
-
-
-
401Missing, invalid or expired token. MessageError -
403The token is not valid for this account, or its user lacks the required permission. When the token has an IP whitelist, a caller outside it is refused with{"success": false, "message": "IP not allowed"}, and a whitelist that cannot be read with{"success": false, "message": "IP whitelist misconfigured"}(ClientError). ClientError -
404The domain does not exist or belongs to another account. ClientError -
422Validation failed (ValidationError), or the registrar refused the operation or could not be reached (ClientError). ValidationError or ClientError -
429Rate limit exceeded. Retry after the number of seconds inRetry-After. MessageError
cURL
curl -X PUT 'https://portal.supporthost.com/api/v1/client/domains/{domain}/nameservers' \
-H "Authorization: Bearer $API_TOKEN" \
-H 'Accept: application/json' \
-H 'Content-Type: application/json' \
-d '{
"nameservers": [
"ns1.example.net",
"ns2.example.net",
"ns3.example.net"
]
}'
PHP
<?php
require 'vendor/autoload.php';
$client = new GuzzleHttp\Client();
$response = $client->request('PUT', 'https://portal.supporthost.com/api/v1/client/domains/{domain}/nameservers', [
'headers' => [
'Authorization' => 'Bearer ' . getenv('API_TOKEN'),
'Accept' => 'application/json',
],
'json' => [
'nameservers' => [
'ns1.example.net',
'ns2.example.net',
'ns3.example.net',
],
],
]);
echo $response->getBody();
Node.js
const response = await fetch('https://portal.supporthost.com/api/v1/client/domains/{domain}/nameservers', {
method: 'PUT',
headers: {
Authorization: `Bearer ${process.env.API_TOKEN}`,
Accept: 'application/json',
'Content-Type': 'application/json',
},
body: JSON.stringify({
"nameservers": [
"ns1.example.net",
"ns2.example.net",
"ns3.example.net"
]
}),
});
console.log(await response.json());
200
{
"success": true,
"data": {
"completed": true,
"message": "Nameservers updated."
}
}
Error responses share one format: see Errors.
Get a contact #
GET
/client/domains/{domain}/contacts
One contact of the domain, read live from the registry: the registrant
by default, or the role named by type. The response is keyed by that
role and also lists, in required_types, the roles this domain uses.
- Authentication: bearer Token
- Rate limit: 120 req/min per user
Parameters
Path
-
domaininteger requiredThe domain ID
Query
-
typestringThe contact role:registrant(default),admin,techorbilling. Must be one of the roles this domain uses.
Responses
-
200Response body
application/json-
successboolean -
dataobject1 property
-
required_typesarray
-
-
-
401Missing, invalid or expired token. MessageError -
403The token is not valid for this account, or its user lacks the required permission. When the token has an IP whitelist, a caller outside it is refused with{"success": false, "message": "IP not allowed"}, and a whitelist that cannot be read with{"success": false, "message": "IP whitelist misconfigured"}(ClientError). ClientError -
404The domain does not exist or belongs to another account. ClientError -
422Validation failed (ValidationError), or the registrar refused the operation or could not be reached (ClientError). ValidationError or ClientError -
429Rate limit exceeded. Retry after the number of seconds inRetry-After. MessageError
cURL
curl 'https://portal.supporthost.com/api/v1/client/domains/{domain}/contacts' \
-H "Authorization: Bearer $API_TOKEN" \
-H 'Accept: application/json'
PHP
<?php
require 'vendor/autoload.php';
$client = new GuzzleHttp\Client();
$response = $client->request('GET', 'https://portal.supporthost.com/api/v1/client/domains/{domain}/contacts', [
'headers' => [
'Authorization' => 'Bearer ' . getenv('API_TOKEN'),
'Accept' => 'application/json',
],
]);
echo $response->getBody();
Node.js
const response = await fetch('https://portal.supporthost.com/api/v1/client/domains/{domain}/contacts', {
headers: {
Authorization: `Bearer ${process.env.API_TOKEN}`,
Accept: 'application/json',
},
});
console.log(await response.json());
200
{
"success": true,
"data": {
"required_types": [
"registrant",
"admin",
"tech"
]
}
}
Error responses share one format: see Errors.
Update a contact #
PUT
/client/domains/{domain}/contacts
Updates one contact of the domain at the registry: the registrant by
default, or the role named by type. Send the full contact, not only
the fields that change.
For the registrant, the registry-specific fields some TLDs require are
sent at the top level, next to first_name; which keys are required
depends on the TLD and on this server’s configuration, and a missing
one answers 422 naming it.
Free of charge. completed: false means the registry accepted the
change but applies it later; message explains.
- Authentication: bearer Token
- Rate limit: 120 req/min per user
Parameters
Path
-
domaininteger requiredThe domain ID
Body application/json
required
-
typestringThe contact to update:registrant(the default),admin,techorbilling. Only the roles this domain’s registry uses are accepted;GET /client/domains/{domain}/contactslists them inrequired_types.Allowed valuesregistrantadmintechbilling -
first_namestring required-
Max length
100
-
Max length
-
last_namestring required-
Max length
100
-
Max length
-
organizationstring | nullCompany name. For the registrant, some TLDs require it and some refuse it.-
Max length
200
-
Max length
-
emailstring required-
Format
email -
Max length
200
-
Format
-
phonestring requiredInternational format+CC.NUMBER, e.g.+39.0212345678. You may instead send a local number here together withphone_country_code(ISO country, e.g.IT).-
Pattern
^\+[0-9]{1,3}\.[0-9]{1,14}$ -
Max length
30
-
Pattern
-
street1string required-
Max length
200
-
Max length
-
street2string | null-
Max length
200
-
Max length
-
citystring required-
Max length
100
-
Max length
-
state_provincestring | null-
Max length
100
-
Max length
-
postal_codestring required-
Max length
20
-
Max length
-
country_codestring requiredISO 3166-1 alpha-2 country code, e.g.IT.-
Min length
2 -
Max length
2
-
Min length
Responses
-
200Response body
application/json-
successboolean -
dataobject2 properties
-
completedboolean -
messagestring
-
-
-
401Missing, invalid or expired token. MessageError -
403The token is not valid for this account, or its user lacks the required permission. When the token has an IP whitelist, a caller outside it is refused with{"success": false, "message": "IP not allowed"}, and a whitelist that cannot be read with{"success": false, "message": "IP whitelist misconfigured"}(ClientError). ClientError -
404The domain does not exist or belongs to another account. ClientError -
422Validation failed (ValidationError), or the registrar refused the operation or could not be reached (ClientError). ValidationError or ClientError -
429Rate limit exceeded. Retry after the number of seconds inRetry-After. MessageError
cURL
curl -X PUT 'https://portal.supporthost.com/api/v1/client/domains/{domain}/contacts' \
-H "Authorization: Bearer $API_TOKEN" \
-H 'Accept: application/json' \
-H 'Content-Type: application/json' \
-d '{
"type": "registrant",
"first_name": "Mario",
"last_name": "Rossi",
"organization": "Example Srl",
"email": "mario.rossi@example.com",
"phone": "+39.0212345678",
"street1": "Via Roma 1",
"city": "Milano",
"state_province": "MI",
"postal_code": "20121",
"country_code": "IT"
}'
PHP
<?php
require 'vendor/autoload.php';
$client = new GuzzleHttp\Client();
$response = $client->request('PUT', 'https://portal.supporthost.com/api/v1/client/domains/{domain}/contacts', [
'headers' => [
'Authorization' => 'Bearer ' . getenv('API_TOKEN'),
'Accept' => 'application/json',
],
'json' => [
'type' => 'registrant',
'first_name' => 'Mario',
'last_name' => 'Rossi',
'organization' => 'Example Srl',
'email' => 'mario.rossi@example.com',
'phone' => '+39.0212345678',
'street1' => 'Via Roma 1',
'city' => 'Milano',
'state_province' => 'MI',
'postal_code' => '20121',
'country_code' => 'IT',
],
]);
echo $response->getBody();
Node.js
const response = await fetch('https://portal.supporthost.com/api/v1/client/domains/{domain}/contacts', {
method: 'PUT',
headers: {
Authorization: `Bearer ${process.env.API_TOKEN}`,
Accept: 'application/json',
'Content-Type': 'application/json',
},
body: JSON.stringify({
"type": "registrant",
"first_name": "Mario",
"last_name": "Rossi",
"organization": "Example Srl",
"email": "mario.rossi@example.com",
"phone": "+39.0212345678",
"street1": "Via Roma 1",
"city": "Milano",
"state_province": "MI",
"postal_code": "20121",
"country_code": "IT"
}),
});
console.log(await response.json());
200
{
"success": true,
"data": {
"completed": true,
"message": "Contact updated."
}
}
Error responses share one format: see Errors.
Get the transfer lock state #
GET
/client/domains/{domain}/lock-state
Whether the registry transfer lock is on, read live, and in supported
which of lock / unlock this domain’s registry allows. Read-only.
- Authentication: bearer Token
- Rate limit: 120 req/min per user
Parameters
Path
-
domaininteger requiredThe domain ID
Responses
-
200Response body
application/json-
successboolean -
dataobject2 properties
-
lockedboolean -
supportedarray of string
-
-
-
401Missing, invalid or expired token. MessageError -
403The token is not valid for this account, or its user lacks the required permission. When the token has an IP whitelist, a caller outside it is refused with{"success": false, "message": "IP not allowed"}, and a whitelist that cannot be read with{"success": false, "message": "IP whitelist misconfigured"}(ClientError). ClientError -
404The domain does not exist or belongs to another account. ClientError -
422Validation failed (ValidationError), or the registrar refused the operation or could not be reached (ClientError). ValidationError or ClientError -
429Rate limit exceeded. Retry after the number of seconds inRetry-After. MessageError
cURL
curl 'https://portal.supporthost.com/api/v1/client/domains/{domain}/lock-state' \
-H "Authorization: Bearer $API_TOKEN" \
-H 'Accept: application/json'
PHP
<?php
require 'vendor/autoload.php';
$client = new GuzzleHttp\Client();
$response = $client->request('GET', 'https://portal.supporthost.com/api/v1/client/domains/{domain}/lock-state', [
'headers' => [
'Authorization' => 'Bearer ' . getenv('API_TOKEN'),
'Accept' => 'application/json',
],
]);
echo $response->getBody();
Node.js
const response = await fetch('https://portal.supporthost.com/api/v1/client/domains/{domain}/lock-state', {
headers: {
Authorization: `Bearer ${process.env.API_TOKEN}`,
Accept: 'application/json',
},
});
console.log(await response.json());
200
{
"success": true,
"data": {
"locked": true,
"supported": [
"lock",
"unlock"
]
}
}
Error responses share one format: see Errors.
Get the WHOIS privacy state #
GET
/client/domains/{domain}/whois-privacy-state
Whether WHOIS privacy is subscribed on the domain (subscribed),
whether the registry reports it active (registrarEnabled, read live),
whether enabling it is free or paid (optionPricing) and which of
enable / disable the registry supports (supported). Read-only.
- Authentication: bearer Token
- Rate limit: 120 req/min per user
Parameters
Path
-
domaininteger requiredThe domain ID
Responses
-
200Response body
application/json-
successboolean -
dataobject4 properties
-
subscribedboolean -
registrarEnabledboolean -
optionPricingstringAllowed valuesunknownfreepaid -
supportedarray of string
-
-
-
401Missing, invalid or expired token. MessageError -
403The token is not valid for this account, or its user lacks the required permission. When the token has an IP whitelist, a caller outside it is refused with{"success": false, "message": "IP not allowed"}, and a whitelist that cannot be read with{"success": false, "message": "IP whitelist misconfigured"}(ClientError). ClientError -
404The domain does not exist or belongs to another account. ClientError -
422Validation failed (ValidationError), or the registrar refused the operation or could not be reached (ClientError). ValidationError or ClientError -
429Rate limit exceeded. Retry after the number of seconds inRetry-After. MessageError
cURL
curl 'https://portal.supporthost.com/api/v1/client/domains/{domain}/whois-privacy-state' \
-H "Authorization: Bearer $API_TOKEN" \
-H 'Accept: application/json'
PHP
<?php
require 'vendor/autoload.php';
$client = new GuzzleHttp\Client();
$response = $client->request('GET', 'https://portal.supporthost.com/api/v1/client/domains/{domain}/whois-privacy-state', [
'headers' => [
'Authorization' => 'Bearer ' . getenv('API_TOKEN'),
'Accept' => 'application/json',
],
]);
echo $response->getBody();
Node.js
const response = await fetch('https://portal.supporthost.com/api/v1/client/domains/{domain}/whois-privacy-state', {
headers: {
Authorization: `Bearer ${process.env.API_TOKEN}`,
Accept: 'application/json',
},
});
console.log(await response.json());
200
{
"success": true,
"data": {
"subscribed": true,
"registrarEnabled": true,
"optionPricing": "free",
"supported": [
"enable_whois_privacy",
"disable_whois_privacy"
]
}
}
Error responses share one format: see Errors.
Turn auto-renew on or off #
POST
/client/domains/{domain}/auto-renew
With auto-renew on, the domain is renewed automatically before it expires. Turning it off also removes the domain from an open renewal invoice, if it had one. It cannot be turned off on a domain included with a hosting service: that domain renews with the service.
- Authentication: bearer Token
- Rate limit: 120 req/min per user
Parameters
Path
-
domaininteger requiredThe domain ID
Body application/json
required
-
valuestring required1to turn auto-renew on,0to turn it off.Allowed values01
Responses
-
200Response body
application/json-
successboolean -
dataobject1 property
-
auto_renewboolean
-
-
-
401Missing, invalid or expired token. MessageError -
403The token is not valid for this account, or its user lacks the required permission. When the token has an IP whitelist, a caller outside it is refused with{"success": false, "message": "IP not allowed"}, and a whitelist that cannot be read with{"success": false, "message": "IP whitelist misconfigured"}(ClientError). ClientError -
404The domain does not exist or belongs to another account. ClientError -
422Validation failed (ValidationError), or the registrar refused the operation or could not be reached (ClientError). ValidationError or ClientError -
429Rate limit exceeded. Retry after the number of seconds inRetry-After. MessageError
cURL
curl -X POST 'https://portal.supporthost.com/api/v1/client/domains/{domain}/auto-renew' \
-H "Authorization: Bearer $API_TOKEN" \
-H 'Accept: application/json' \
-H 'Content-Type: application/json' \
-d '{
"value": "0"
}'
PHP
<?php
require 'vendor/autoload.php';
$client = new GuzzleHttp\Client();
$response = $client->request('POST', 'https://portal.supporthost.com/api/v1/client/domains/{domain}/auto-renew', [
'headers' => [
'Authorization' => 'Bearer ' . getenv('API_TOKEN'),
'Accept' => 'application/json',
],
'json' => [
'value' => '0',
],
]);
echo $response->getBody();
Node.js
const response = await fetch('https://portal.supporthost.com/api/v1/client/domains/{domain}/auto-renew', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.API_TOKEN}`,
Accept: 'application/json',
'Content-Type': 'application/json',
},
body: JSON.stringify({
"value": "0"
}),
});
console.log(await response.json());
200
{
"success": true,
"data": {
"auto_renew": false
}
}
Error responses share one format: see Errors.
Enable the transfer lock #
POST
/client/domains/{domain}/lock
Turns on the registry transfer lock, which blocks transfers of the
domain to another registrar. Free of charge. completed: false means
the registry applies it later.
- Authentication: bearer Token
- Rate limit: 120 req/min per user
Parameters
Path
-
domaininteger requiredThe domain ID
Responses
-
200Response body
application/json-
successboolean -
dataobject2 properties
-
completedboolean -
messagestring
-
-
-
401Missing, invalid or expired token. MessageError -
403The token is not valid for this account, or its user lacks the required permission. When the token has an IP whitelist, a caller outside it is refused with{"success": false, "message": "IP not allowed"}, and a whitelist that cannot be read with{"success": false, "message": "IP whitelist misconfigured"}(ClientError). ClientError -
404The domain does not exist or belongs to another account. ClientError -
422Validation failed (ValidationError), or the registrar refused the operation or could not be reached (ClientError). ValidationError or ClientError -
429Rate limit exceeded. Retry after the number of seconds inRetry-After. MessageError
cURL
curl -X POST 'https://portal.supporthost.com/api/v1/client/domains/{domain}/lock' \
-H "Authorization: Bearer $API_TOKEN" \
-H 'Accept: application/json'
PHP
<?php
require 'vendor/autoload.php';
$client = new GuzzleHttp\Client();
$response = $client->request('POST', 'https://portal.supporthost.com/api/v1/client/domains/{domain}/lock', [
'headers' => [
'Authorization' => 'Bearer ' . getenv('API_TOKEN'),
'Accept' => 'application/json',
],
]);
echo $response->getBody();
Node.js
const response = await fetch('https://portal.supporthost.com/api/v1/client/domains/{domain}/lock', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.API_TOKEN}`,
Accept: 'application/json',
},
});
console.log(await response.json());
200
{
"success": true,
"data": {
"completed": true,
"message": "Transfer lock enabled."
}
}
Error responses share one format: see Errors.
Disable the transfer lock #
POST
/client/domains/{domain}/unlock
Turns off the registry transfer lock so the domain can be transferred
away. Free of charge. completed: false means the registry applies it
later.
- Authentication: bearer Token
- Rate limit: 120 req/min per user
Parameters
Path
-
domaininteger requiredThe domain ID
Responses
-
200Response body
application/json-
successboolean -
dataobject2 properties
-
completedboolean -
messagestring
-
-
-
401Missing, invalid or expired token. MessageError -
403The token is not valid for this account, or its user lacks the required permission. When the token has an IP whitelist, a caller outside it is refused with{"success": false, "message": "IP not allowed"}, and a whitelist that cannot be read with{"success": false, "message": "IP whitelist misconfigured"}(ClientError). ClientError -
404The domain does not exist or belongs to another account. ClientError -
422Validation failed (ValidationError), or the registrar refused the operation or could not be reached (ClientError). ValidationError or ClientError -
429Rate limit exceeded. Retry after the number of seconds inRetry-After. MessageError
cURL
curl -X POST 'https://portal.supporthost.com/api/v1/client/domains/{domain}/unlock' \
-H "Authorization: Bearer $API_TOKEN" \
-H 'Accept: application/json'
PHP
<?php
require 'vendor/autoload.php';
$client = new GuzzleHttp\Client();
$response = $client->request('POST', 'https://portal.supporthost.com/api/v1/client/domains/{domain}/unlock', [
'headers' => [
'Authorization' => 'Bearer ' . getenv('API_TOKEN'),
'Accept' => 'application/json',
],
]);
echo $response->getBody();
Node.js
const response = await fetch('https://portal.supporthost.com/api/v1/client/domains/{domain}/unlock', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.API_TOKEN}`,
Accept: 'application/json',
},
});
console.log(await response.json());
200
{
"success": true,
"data": {
"completed": true,
"message": "Transfer lock disabled."
}
}
Error responses share one format: see Errors.
Get the EPP code #
POST
/client/domains/{domain}/epp
Retrieves the transfer authorisation (EPP) code. Depending on the
registry the code is returned in code (delivered_via: screen) or
emailed to the registrant (delivered_via: email, code: null).
A POST because it has side effects: some registries generate a new code on every request.
- Authentication: bearer Token
- Rate limit: 120 req/min per user
Parameters
Path
-
domaininteger requiredThe domain ID
Responses
-
200Response body
application/json-
successboolean -
dataobject3 properties
-
delivered_viastring -
codestring | null -
messagestring | null
-
-
-
401Missing, invalid or expired token. MessageError -
403The token is not valid for this account, or its user lacks the required permission. When the token has an IP whitelist, a caller outside it is refused with{"success": false, "message": "IP not allowed"}, and a whitelist that cannot be read with{"success": false, "message": "IP whitelist misconfigured"}(ClientError). ClientError -
404The domain does not exist or belongs to another account. ClientError -
422Validation failed (ValidationError), or the registrar refused the operation or could not be reached (ClientError). ValidationError or ClientError -
429Rate limit exceeded. Retry after the number of seconds inRetry-After. MessageError
cURL
curl -X POST 'https://portal.supporthost.com/api/v1/client/domains/{domain}/epp' \
-H "Authorization: Bearer $API_TOKEN" \
-H 'Accept: application/json'
PHP
<?php
require 'vendor/autoload.php';
$client = new GuzzleHttp\Client();
$response = $client->request('POST', 'https://portal.supporthost.com/api/v1/client/domains/{domain}/epp', [
'headers' => [
'Authorization' => 'Bearer ' . getenv('API_TOKEN'),
'Accept' => 'application/json',
],
]);
echo $response->getBody();
Node.js
const response = await fetch('https://portal.supporthost.com/api/v1/client/domains/{domain}/epp', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.API_TOKEN}`,
Accept: 'application/json',
},
});
console.log(await response.json());
200
{
"success": true,
"data": {
"delivered_via": "screen",
"code": "EXAMPLE-EPP-7Hq2",
"message": "Give this code to the new registrar to authorise the transfer."
}
}
Error responses share one format: see Errors.
Enable WHOIS privacy #
POST
/client/domains/{domain}/whois-privacy/enable
Hides the owner’s details from public WHOIS. When the service is free
it is enabled at once (enabled: true). When it is paid, an invoice is
issued and returned (enabled: false, invoice_id, invoice):
privacy is enabled once that invoice is paid.
- Authentication: bearer Token
- Rate limit: 120 req/min per user
Parameters
Path
-
domaininteger requiredThe domain ID
Responses
-
200Response body
application/json-
successboolean -
dataobject3 properties
-
enabledboolean -
invoice_idinteger | null -
invoiceobject | null44 properties
-
idinteger -
client_idinteger -
clientobject4 properties
-
idinteger -
firstnamestring -
lastnamestring -
companystring | null
-
-
typestring -
related_invoice_idinteger | null -
related_invoiceobject3 properties
-
idinteger | null -
invoice_numberstring | null -
display_numberstring | null
-
-
invoice_numberstring | null -
display_numberstring -
statusstring -
currency_codestring -
exchange_ratestring -
gateway_idinteger | null -
client_namestring | null -
client_companystring | null -
client_emailstring | null -
client_addressstring | null -
client_citystring | null -
client_statestring | null -
client_countrystring | null -
client_postcodestring | null -
client_vat_numberstring | null -
client_tax_exemptboolean -
client_custom_fieldsAny of
Option 1 object
Option 2 map of any
-
-
business_namestring | null -
business_addressstring | null -
business_vat_numberstring | null -
subtotalstring | number -
tax1_namestring | null -
tax1_ratestring | number -
tax1_amountstring | number -
tax2_namestring | null -
tax2_ratestring | number -
tax2_amountstring | number -
tax_overrideboolean -
totalstring | number -
credit_appliedstring | number -
balancestring | number -
datestring | null -
due_datestring | null -
paid_datestring | null -
itemsarray of object12 properties
-
idinteger -
invoice_idinteger -
descriptionstring -
qtystring -
unit_pricestring -
taxableboolean -
amountstring -
source_typestring | null -
source_idinteger | null -
sort_orderinteger -
created_atstring -
updated_atstring
-
-
transactionsarray of object16 properties
-
idinteger -
client_idinteger -
clientobject4 properties
-
idinteger -
firstnamestring -
lastnamestring -
companystring | null
-
-
invoice_idinteger | null -
related_transaction_idinteger | null -
related_transactionobject4 properties
-
idinteger | null -
amountstring | null -
typestring | null -
datestring | null
-
-
amountstring -
currency_codestring -
gatewaystring | null -
transaction_idstring | null -
exchange_ratestring -
typestring -
descriptionstring | null -
datestring -
created_atstring -
updated_atstring
-
-
created_atstring -
updated_atstring
-
-
-
-
401Missing, invalid or expired token. MessageError -
403The token is not valid for this account, or its user lacks the required permission. When the token has an IP whitelist, a caller outside it is refused with{"success": false, "message": "IP not allowed"}, and a whitelist that cannot be read with{"success": false, "message": "IP whitelist misconfigured"}(ClientError). ClientError -
404The domain does not exist or belongs to another account. ClientError -
422Validation failed (ValidationError), or the registrar refused the operation or could not be reached (ClientError). ValidationError or ClientError -
429Rate limit exceeded. Retry after the number of seconds inRetry-After. MessageError
cURL
curl -X POST 'https://portal.supporthost.com/api/v1/client/domains/{domain}/whois-privacy/enable' \
-H "Authorization: Bearer $API_TOKEN" \
-H 'Accept: application/json'
PHP
<?php
require 'vendor/autoload.php';
$client = new GuzzleHttp\Client();
$response = $client->request('POST', 'https://portal.supporthost.com/api/v1/client/domains/{domain}/whois-privacy/enable', [
'headers' => [
'Authorization' => 'Bearer ' . getenv('API_TOKEN'),
'Accept' => 'application/json',
],
]);
echo $response->getBody();
Node.js
const response = await fetch('https://portal.supporthost.com/api/v1/client/domains/{domain}/whois-privacy/enable', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.API_TOKEN}`,
Accept: 'application/json',
},
});
console.log(await response.json());
200
{
"success": true,
"data": {
"enabled": false,
"invoice_id": 20871,
"invoice": {
"id": 20871,
"client_id": 318,
"client": {
"id": 318,
"firstname": "Mario",
"lastname": "Rossi",
"company": "Example Srl"
},
"type": "invoice",
"related_invoice_id": 20790,
"related_invoice": {
"id": 20790,
"invoice_number": "1498",
"display_number": "1498"
},
"invoice_number": "1532",
"display_number": "1532",
"status": "unpaid",
"currency_code": "EUR",
"exchange_rate": "1.00000",
"gateway_id": 1,
"client_name": "Mario Rossi",
"client_company": "Example Srl",
"client_email": "mario.rossi@example.com",
"client_address": "Via Roma 1",
"client_city": "Milano",
"client_state": "MI",
"client_country": "IT",
"client_postcode": "20121",
"client_vat_number": "IT01234567890",
"client_tax_exempt": false,
"client_custom_fields": {
"fiscal_code": "RSSMRA80A01F205X"
},
"business_name": "Example Hosting Srl",
"business_address": "Via Milano 10, 20121 Milano, Italy",
"business_vat_number": "IT09876543210",
"subtotal": "4.90",
"tax1_name": "VAT",
"tax1_rate": "22.000",
"tax1_amount": "1.08",
"tax2_name": null,
"tax2_rate": "0.000",
"tax2_amount": "0.00",
"tax_override": false,
"total": "5.98",
"credit_applied": "0.00",
"balance": "5.98",
"date": "2026-09-27T00:00:00+02:00",
"due_date": "2026-10-04T00:00:00+02:00",
"paid_date": null,
"items": [
{
"id": 48213,
"invoice_id": 20871,
"description": "WHOIS privacy - example.com",
"qty": "1.00",
"unit_price": "4.90",
"taxable": true,
"amount": "4.90",
"source_type": "domain_option",
"source_id": 1042,
"sort_order": 0,
"created_at": "2026-09-27T10:15:32+02:00",
"updated_at": "2026-09-27T10:15:32+02:00"
}
],
"transactions": [
{
"id": 7730,
"client_id": 318,
"client": {
"id": 318,
"firstname": "Mario",
"lastname": "Rossi",
"company": "Example Srl"
},
"invoice_id": 20871,
"related_transaction_id": 7729,
"related_transaction": {
"id": 7729,
"amount": "5.98",
"type": "payment",
"date": "2026-09-20T09:12:31+02:00"
},
"amount": "5.98",
"currency_code": "EUR",
"gateway": "bank_transfer",
"transaction_id": "TRX-20260927-0042",
"exchange_rate": "1.00000",
"type": "payment",
"description": "Payment of invoice 1532",
"date": "2026-09-27T11:02:44+02:00",
"created_at": "2026-09-27T11:02:44+02:00",
"updated_at": "2026-09-27T11:02:44+02:00"
}
],
"created_at": "2026-09-27T10:15:32+02:00",
"updated_at": "2026-09-27T10:15:32+02:00"
}
}
}
Error responses share one format: see Errors.
Disable WHOIS privacy #
POST
/client/domains/{domain}/whois-privacy/disable
Shows the owner’s details in public WHOIS again, where the registry allows it.
- Authentication: bearer Token
- Rate limit: 120 req/min per user
Parameters
Path
-
domaininteger requiredThe domain ID
Responses
-
200Response body
application/json-
successboolean -
dataobject1 property
-
enabledboolean
-
-
-
401Missing, invalid or expired token. MessageError -
403The token is not valid for this account, or its user lacks the required permission. When the token has an IP whitelist, a caller outside it is refused with{"success": false, "message": "IP not allowed"}, and a whitelist that cannot be read with{"success": false, "message": "IP whitelist misconfigured"}(ClientError). ClientError -
404The domain does not exist or belongs to another account. ClientError -
422Validation failed (ValidationError), or the registrar refused the operation or could not be reached (ClientError). ValidationError or ClientError -
429Rate limit exceeded. Retry after the number of seconds inRetry-After. MessageError
cURL
curl -X POST 'https://portal.supporthost.com/api/v1/client/domains/{domain}/whois-privacy/disable' \
-H "Authorization: Bearer $API_TOKEN" \
-H 'Accept: application/json'
PHP
<?php
require 'vendor/autoload.php';
$client = new GuzzleHttp\Client();
$response = $client->request('POST', 'https://portal.supporthost.com/api/v1/client/domains/{domain}/whois-privacy/disable', [
'headers' => [
'Authorization' => 'Bearer ' . getenv('API_TOKEN'),
'Accept' => 'application/json',
],
]);
echo $response->getBody();
Node.js
const response = await fetch('https://portal.supporthost.com/api/v1/client/domains/{domain}/whois-privacy/disable', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.API_TOKEN}`,
Accept: 'application/json',
},
});
console.log(await response.json());
200
{
"success": true,
"data": {
"enabled": false
}
}
Error responses share one format: see Errors.