20% Off for Resellers Plan — use promo code NEX2026
v1.0 REST · JSON

Reseller API Documentation

Everything you need to sell domains from your own website or WHMCS — pricing, availability, register, renew, transfer and management.

Getting started

  1. Create a client account (or log in) at Hostingsubidha.
  2. Open Client Area → Domain Reseller and click Apply. We approve reseller accounts quickly.
  3. Add funds to your wallet with bKash, Nagad or any available method.
  4. Click Generate API key and store it on your server (never in browser JavaScript).
Base URL: https://clients.hostingsubidha.com/reseller-api.php
All requests must use HTTPS. Responses are JSON.

Authentication

Send your API key in the Authorization header (or X-API-Key):

Authorization: Bearer hsr_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

Keys are shown once when generated and stored hashed on our side. Regenerating a key disables the old one immediately. You can restrict your key to specific server IPs in the dashboard.

Requests & responses

  • Choose the operation with the action query parameter. Read actions use GET, write actions use POST.
  • POST bodies can be JSON (Content-Type: application/json) or form-encoded.
  • Every response has ok. On success the result is in data; on failure in error with a machine-readable code and a human message.
{ "ok": false, "error": { "code": "insufficient_funds", "message": "Insufficient balance: BDT 1296.00 needed, 200.00 available.", "required": 1296, "balance": 200, "currency": "BDT" } }

Wallet & pricing

  • Orders are paid from your Hostingsubidha account credit in your account currency (BDT or USD). Top up via Add Funds.
  • Your price = our retail price minus your reseller discount (shown in balance and pricing). High-volume resellers get bigger discounts — ask us.
  • The wallet is charged before the registrar is contacted, and each order appears as a paid invoice in your client area.
  • If automatic registration or renewal does not complete, you get pending_manual: the order is kept and our team completes it manually (or refunds it to your wallet if it cannot be completed). Do not retry the same domain.
  • Use a unique reference per order so a network retry never charges you twice.

Endpoints

GET ?action=balance — Wallet balance

Returns your prepaid balance, its currency and your discount.

curl -H "Authorization: Bearer $HSR_API_KEY" "https://clients.hostingsubidha.com/reseller-api.php?action=balance"

Response

{
  "ok": true,
  "data": { "balance": 5000, "currency": "BDT", "discount_percent": 10 }
}

GET ?action=pricing — Your price list

Reseller prices (1 year) for every extension, or one extension with tld. Also shows the retail price so you can set your own markup.

ParameterTypeRequiredDescription
tldstringNoe.g. com — omit for all 280+ extensions
curl -H "Authorization: Bearer $HSR_API_KEY" "https://clients.hostingsubidha.com/reseller-api.php?action=pricing&tld=com"

Response

{
  "ok": true,
  "data": {
    "currency": "BDT", "discount_percent": 10, "years": 1,
    "tlds": [ { "tld": ".com", "register": 1296, "retail_register": 1440,
                "renew": 1566, "retail_renew": 1740, "transfer": 1134, "retail_transfer": 1260 } ]
  }
}

GET ?action=check — Check availability

Live availability check with your price.

ParameterTypeRequiredDescription
domainstringYesFull domain, e.g. mybrand.com
curl -H "Authorization: Bearer $HSR_API_KEY" "https://clients.hostingsubidha.com/reseller-api.php?action=check&domain=mybrand.com"

Response

{
  "ok": true,
  "data": { "domain": "mybrand.com", "available": true, "currency": "BDT",
            "price": 1296, "retail_price": 1440, "renew_price": 1566 }
}

POST ?action=register — Register a domain

Charges your wallet, then registers the domain at the registrar. If automatic registration does not complete, the order is kept and activated manually by our team (response pending_manual). Can take up to ~2 minutes — use a timeout of 240 s.

ParameterTypeRequiredDescription
domainstringYesDomain to register
yearsintNo1–10, default 1
nameserversarrayNo2–5 nameservers, e.g. ["ns1.host.com","ns2.host.com"]
referencestringNoYour unique order ID. Retrying with the same reference never charges twice (idempotency).
curl -X POST -H "Authorization: Bearer $HSR_API_KEY" -H "Content-Type: application/json" \
  -d '{"domain":"mybrand.com","years":1,"nameservers":["ns1.myhost.com","ns2.myhost.com"],"reference":"order-1001"}' \
  "https://clients.hostingsubidha.com/reseller-api.php?action=register"

Response

{
  "ok": true,
  "data": { "domain": "mybrand.com", "status": "registered", "years": 1, "charged": 1296,
            "currency": "BDT", "order_id": 512, "invoice_id": 2045, "expiry_date": "2027-09-27", "balance": 3704 }
}

POST ?action=renew — Renew a domain

Renews a domain in your account. If automatic renewal does not complete, our team renews it manually (pending_manual).

ParameterTypeRequiredDescription
domainstringYesDomain in your account
yearsintNo1–10, default 1
referencestringNoIdempotency key
curl -X POST -H "Authorization: Bearer $HSR_API_KEY" -d "domain=mybrand.com&years=1" "https://clients.hostingsubidha.com/reseller-api.php?action=renew"

Response

{ "ok": true, "data": { "domain": "mybrand.com", "status": "renewed", "charged": 1566, "expiry_date": "2028-09-27" } }

POST ?action=transfer — Transfer a domain in

Starts an inbound transfer. The domain must be unlocked at the current registrar.

ParameterTypeRequiredDescription
domainstringYesDomain to transfer
eppcodestringYesAuthorization / EPP code
yearsintNoDefault 1
nameserversarrayNoOptional
referencestringNoIdempotency key
curl -X POST -H "Authorization: Bearer $HSR_API_KEY" -d "domain=mybrand.com&eppcode=Xy12..." "https://clients.hostingsubidha.com/reseller-api.php?action=transfer"

Response

{ "ok": true, "data": { "domain": "mybrand.com", "status": "transfer_started", "charged": 1134 } }

GET ?action=domains — List your domains

Paginated list of domains in your account.

ParameterTypeRequiredDescription
limitintNo1–250, default 100
offsetintNoDefault 0
curl -H "Authorization: Bearer $HSR_API_KEY" "https://clients.hostingsubidha.com/reseller-api.php?action=domains&limit=50"

Response

{ "ok": true, "data": { "total": 2, "domains": [ { "domain": "mybrand.com", "status": "Active", "registered": "2026-09-27", "expires": "2027-09-27" } ] } }

GET ?action=domain — Domain details

Status, dates, nameservers and lock state.

ParameterTypeRequiredDescription
domainstringYesDomain in your account
curl -H "Authorization: Bearer $HSR_API_KEY" "https://clients.hostingsubidha.com/reseller-api.php?action=domain&domain=mybrand.com"

Response

{ "ok": true, "data": { "domain": "mybrand.com", "status": "Active", "expires": "2027-09-27",
  "nameservers": ["ns1.myhost.com","ns2.myhost.com"], "locked": true, "auto_renew": true } }

POST ?action=nameservers — Update nameservers

Sets 2–5 nameservers.

ParameterTypeRequiredDescription
domainstringYesDomain in your account
nameserversarray|stringYesArray or comma-separated list
curl -X POST -H "Authorization: Bearer $HSR_API_KEY" -d "domain=mybrand.com&nameservers=ns1.a.com,ns2.a.com" "https://clients.hostingsubidha.com/reseller-api.php?action=nameservers"

Response

{ "ok": true, "data": { "domain": "mybrand.com", "nameservers": ["ns1.a.com","ns2.a.com"] } }

POST ?action=epp — Get EPP / auth code

Returns the transfer authorization code, or emails it to the registrant if the registry requires that.

ParameterTypeRequiredDescription
domainstringYesDomain in your account
curl -X POST -H "Authorization: Bearer $HSR_API_KEY" -d "domain=mybrand.com" "https://clients.hostingsubidha.com/reseller-api.php?action=epp"

Response

{ "ok": true, "data": { "domain": "mybrand.com", "eppcode": "Xy12#abc" } }

POST ?action=lock — Registrar lock

Locks or unlocks a domain (unlock before transferring away).

ParameterTypeRequiredDescription
domainstringYesDomain in your account
lockedboolYestrue or false
curl -X POST -H "Authorization: Bearer $HSR_API_KEY" -d "domain=mybrand.com&locked=false" "https://clients.hostingsubidha.com/reseller-api.php?action=lock"

Response

{ "ok": true, "data": { "domain": "mybrand.com", "locked": false } }

Errors

codeHTTPMeaning
unauthorized401Missing or wrong API key
account_inactive403Reseller account pending/disabled
ip_not_allowed403Request IP not in your whitelist
rate_limited429More than 120 requests per minute
invalid_domain422Domain format is wrong
unsupported422Extension/term not offered
insufficient_funds402Wallet balance too low — add funds
domain_unavailable409Domain is already registered
already_exists409Domain already exists in our system
not_found404Domain not in your account
pending_manual202Order received and paid; automatic processing did not complete, so our team activates it manually — do not retry
order_failed502Order could not be created — amount refunded to your wallet
registrar_error502Registrar rejected a management action (nameservers, lock, EPP)
busy409Another order for your account is in progress — retry in a few seconds

WHMCS registrar module

Run your own WHMCS? Install our free registrar module and sell domains fully automatically.

  1. Download the module (ZIP) and upload the modules folder to your WHMCS root.
  2. System Settings → Domain Registrars → Hostingsubidha Domain Reseller → Activate, paste your API key.
  3. Optional: Utilities → Registrar TLD Sync imports our reseller prices as your cost prices.
  4. System Settings → Domain Pricing: set Auto Registration to Hostingsubidha for the extensions you sell.

Supported: register, renew, transfer, transfer sync, nameservers, registrar lock, EPP code, domain sync and availability lookup.

Your own website (PHP)

A tiny PHP client and a domain-search endpoint that adds your markup and keeps your key secret:

<?php
// Minimal PHP client — works with any framework or plain PHP.
function hsr(string $action, string $method = 'GET', array $data = []): array {
    $url = 'https://clients.hostingsubidha.com/reseller-api.php?action=' . $action;
    if ($method === 'GET' && $data) $url .= '&' . http_build_query($data);
    $ch = curl_init($url);
    curl_setopt_array($ch, [
        CURLOPT_RETURNTRANSFER => true, CURLOPT_TIMEOUT => 240,
        CURLOPT_HTTPHEADER => ['Authorization: Bearer ' . getenv('HSR_API_KEY'), 'Content-Type: application/json'],
    ]);
    if ($method === 'POST') { curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode($data)); }
    $res = json_decode(curl_exec($ch), true);
    if (empty($res['ok'])) throw new RuntimeException($res['error']['message'] ?? 'API error');
    return $res['data'];
}
<?php
// domain-search.php — put on YOUR website. Keeps your API key secret on the server
// and adds your own profit margin before showing the price to customers.
const MARKUP_PERCENT = 20;
require 'hsr-client.php';                    // the hsr() function above
header('Content-Type: application/json');
$domain = strtolower(trim($_GET['domain'] ?? ''));
try {
    $r = hsr('check', 'GET', ['domain' => $domain]);
    $r['your_price'] = $r['price'] !== null ? round($r['price'] * (1 + MARKUP_PERCENT / 100)) : null;
    unset($r['price'], $r['retail_price']);  // never expose your cost
    echo json_encode(['ok' => true] + $r);
} catch (Throwable $e) {
    http_response_code(400);
    echo json_encode(['ok' => false, 'error' => $e->getMessage()]);
}

Security

  • Never put your API key in HTML or front-end JavaScript — call the API from your server.
  • Use the IP whitelist when your server has a fixed IP.
  • Rate limit: 120 requests per minute per account.
  • Questions? Telegram @hostingsubidhaowner · WhatsApp +8801897216101