Domain reseller API
Webway's domain reseller API lets you register, transfer, renew and manage domains for your own customers from your WHMCS or your own code. To find out more about the domain reseller programme, see webway.host/domain-reseller.
Endpoint
https://portal.webway.host/modules/addons/DomainsReseller/api/index.php
Append the call's path to the endpoint, for example …/api/index.php/order/domains/renew.
Authentication
Every request sends two headers:
| Header | Value |
|---|---|
username |
The email address of your client account at Webway |
token |
Your API key, hashed with SHA-256 (HMAC) using your email address and the current UTC hour, then base64-encoded |
The token is built like this:
base64_encode(hash_hmac("sha256", "<api-key>", "<email>:" . gmdate("y-m-d H")))
Because the token includes the current hour (UTC), it changes every hour. Generate it for each request, and make sure your server's clock is correct.
Example (PHP)
$endpoint = "https://portal.webway.host/modules/addons/DomainsReseller/api/index.php";
$action = "/order/domains/renew";
$params = [
"domain" => "example.com",
"regperiod" => "3",
"addons" => [
"dnsmanagement" => 0,
"emailforwarding" => 1,
"idprotection" => 0,
],
];
$headers = [
"username: email@example.com",
"token: " . base64_encode(hash_hmac("sha256", "YOUR_API_KEY", "email@example.com:" . gmdate("y-m-d H"))),
];
$curl = curl_init();
curl_setopt($curl, CURLOPT_URL, "{$endpoint}{$action}");
curl_setopt($curl, CURLOPT_POST, true);
curl_setopt($curl, CURLOPT_POSTFIELDS, http_build_query($params));
curl_setopt($curl, CURLOPT_RETURNTRANSFER, true);
curl_setopt($curl, CURLOPT_SSL_VERIFYPEER, true);
curl_setopt($curl, CURLOPT_HTTPHEADER, $headers);
$response = curl_exec($curl);
curl_close($curl);
Keep your API key secret. Never put it in code that runs in a browser or in a public repository.
Calls
| Method | Path | What it does | Parameters |
|---|---|---|---|
| POST | /order/domains/register |
Register Domain | domain (required), regperiod (required), domainfields, addons, nameservers (required), contacts (required), idnLanguage |
| POST | /order/domains/transfer |
Transfer Domain | domain (required), eppcode, regperiod (required), domainfields, addons, nameservers (required), contacts (required), idnLanguage |
| POST | /order/domains/renew |
Renew Domain | domain (required), regperiod (required), addons, idnLanguage |
| POST | /domains/{domain}/release |
Release Domain | domain (required), transfertag (required) |
| GET | /domains/{domain}/eppcode |
Get EPP Code | domain (required) |
| GET | /domains/{domain}/contact |
Get Contact Details | domain (required) |
| POST | /domains/{domain}/contact |
Save Contact Details | domain (required), contactdetails (required) |
| GET | /domains/{domain}/lock |
Get Registrar Lock | domain (required) |
| POST | /domains/{domain}/lock |
Save Registrar Lock | domain (required), lockstatus (required) |
| GET | /domains/{domain}/dns |
Get DNS | domain (required) |
| POST | /domains/{domain}/dns |
Save DNS | domain (required), dnsrecords (required) |
| POST | /domains/{domain}/delete |
Request Deletion | domain (required) |
| POST | /domains/{domain}/transfersync |
Transfer Sync | domain (required) |
| POST | /domains/{domain}/sync |
Domain Sync | domain (required) |
| GET | /domains/{domain}/email |
Get Email Forwarding | domain (required) |
| POST | /domains/{domain}/email |
Save Email Forwarding | domain (required), prefix, forwardto |
| POST | /domains/{domain}/protectid |
ID Protect Toggle | domain (required), status (required) |
| POST | /domains/lookup |
Check Availability | searchTerm, punyCodeSearchTerm, tldsToInclude, isIdnDomain, premiumEnabled |
| POST | /domains/lookup/suggestions |
Get Domain Suggestions | searchTerm, punyCodeSearchTerm, tldsToInclude, isIdnDomain, premiumEnabled, suggestionSettings |
| GET | /domains/{domain}/nameservers |
Get Nameservers | domain (required) |
| POST | /domains/{domain}/nameservers |
Save Nameservers | domain (required), ns1 (required), ns2 (required), ns3, ns4, ns5 |
| POST | /domains/{domain}/nameservers/register |
Register Nameserver | domain (required), nameserver (required), ipaddress (required) |
| POST | /domains/{domain}/nameservers/modify |
Modify Nameserver | nameserver (required), currentipaddress (required), newipaddress (required) |
| POST | /domains/{domain}/nameservers/delete |
Delete Nameserver | nameserver (required) |
| GET | /order/pricing/domains/{type} |
Cart Get Pricing Register | domain (required) |
| GET | /order/pricing/domains/{type} |
Cart Get Pricing Renew | domain (required) |
| GET | /order/pricing/domains/{type} |
Cart Get Pricing Transfer | domain (required) |
| GET | /billing/credits |
Get Credits | — |
| GET | /version |
Get Version | — |
| GET | /tlds |
Get Available TLDs | — |
| GET | /tlds/pricing |
Get TLDs Pricing | — |
| GET | /domains/{domain}/information |
Get Domain Information | domain (required) |
{domain} in a path is the domain name, for example /domains/example.com/eppcode. {type} in the pricing paths is register, renew or transfer.
Models
These are the structures used by the parameters above.
Nameservers
ns1(text), requiredns2(text), requiredns3(text)ns4(text)ns5(text)
DNS Records
hostname(text), requiredtype(text), requiredaddress(text), requiredpriority(numeric), requiredrecid(text)
Contacts
registrant(contact)tech(contact)billing(contact)admin(contact)
Contact Details
Registrant(contact), requiredTechnical(contact), requiredBilling(contact), requiredAdmin(contact), required
Contact
firstname(text), requiredlastname(text), requiredfullname(text), requiredcompanyname(text), requiredemail(text), requiredaddress1(text), requiredaddress2(text)city(text), requiredstate(text), requiredpostcode(text), requiredcountry(text), requiredphonenumber(text), required
Addons
dnsmanagement(numeric)emailforwarding(numeric)idprotection(numeric)
Webway doesn't offer ID protection (WHOIS privacy), so send idprotection as 0.
Related
- Assign existing domains to your domain reseller account
- How to connect WHMCS to my Webway reseller account
- How to register a new domain
Still stuck?
Open a support ticket and include the call you're making (method and path), the parameters sent (without your API key), the full response, and the date and time (UTC) of the request.
Did this answer it?