fb-pixel
SupportHost italian

Authentication

On this page

Every call is authenticated with a personal API token, sent as a Bearer token.

Bearer token

Authorization: Bearer <your-token>

Create tokens in the client area under API Tokens. A token is a secret: keep it on your servers, never in a browser, a mobile app or a public repository. If one leaks, delete it in the client area and create a new one.

One account per token

A token is bound to one account and acts with the permissions its user has on that account. There is no separate scope list: a token cannot be narrowed to fewer permissions than its user. To limit what an integration can do, give it a user with fewer permissions.

Permissions

Permission
Allows
domains
Reading: price list, availability checks, domain state, charges, and the read-only Domain management calls.
managedomains
Changes and anything that moves money: register, transfer, renew, restore, and the Domain management changes (nameservers, contacts, EPP code, lock, WHOIS privacy, auto-renew).

Each operation in the reference shows the permission it needs. The account must also be enabled for the reseller programme, with credit enabled.

IP whitelist

When you create a token you can restrict it to a list of IP addresses. Use it for production tokens: your servers call from known addresses. The whitelist is checked on every token route and answers 403. On reseller calls the body is a ResellerError; on Domain management calls it is a ClientError:

  • ip_not_allowed (reseller calls) or "IP not allowed" (Domain management calls): the call comes from an address outside the whitelist.
  • ip_whitelist_misconfigured (reseller calls) or "IP whitelist misconfigured" (Domain management calls): the whitelist cannot be read, so every call is refused (fail-closed). Fix the whitelist in the client area.

On reseller calls, read error.code as for any other refusal; on Domain management calls, read message.

401 and 403

Answer
Meaning
What to do
401
The token is missing, invalid or expired. The body is {"message": "…"} (MessageError).
Check the header and the token; do not retry blindly.
403 ip_not_allowed / "IP not allowed"
The call comes from an address outside the token’s IP whitelist. Reseller calls: ResellerError; Domain management calls: ClientError.
Call from a whitelisted server, or update the whitelist.
403 ip_whitelist_misconfigured / "IP whitelist misconfigured"
The token’s IP whitelist cannot be read, so every call is refused. Reseller calls: ResellerError; Domain management calls: ClientError.
Fix the whitelist in the client area.
403 not_reseller
The account is not enabled for the reseller API.
Contact SupportHost.
403 credit_disabled
Credit is disabled for the account.
Contact SupportHost.
403 forbidden
The token’s user lacks the permission the call needs.
Use a user with managedomains for changes.
403 on Domain management
The token is not valid for this account, the user lacks the permission, or the domain’s status does not allow the change. The body is {"success": false, "message": "…"} (ClientError).
Read message.