Getting started
- Create a client account (or log in) at Hostingsubidha.
- Open Client Area → Domain Reseller and click Apply. We approve reseller accounts quickly.
- Add funds to your wallet with bKash, Nagad or any available method.
- Click Generate API key and store it on your server (never in browser JavaScript).
https://clients.hostingsubidha.com/reseller-api.phpAll requests must use HTTPS. Responses are JSON.
Authentication
Send your API key in the Authorization header (or X-API-Key):
Authorization: Bearer hsr_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Keys are shown once when generated and stored hashed on our side. Regenerating a key disables the old one immediately. You can restrict your key to specific server IPs in the dashboard.
Requests & responses
- Choose the operation with the
actionquery parameter. Read actions useGET, write actions usePOST. POSTbodies can be JSON (Content-Type: application/json) or form-encoded.- Every response has
ok. On success the result is indata; on failure inerrorwith a machine-readablecodeand a humanmessage.
{ "ok": false, "error": { "code": "insufficient_funds", "message": "Insufficient balance: BDT 1296.00 needed, 200.00 available.", "required": 1296, "balance": 200, "currency": "BDT" } }
Wallet & pricing
- Orders are paid from your Hostingsubidha account credit in your account currency (BDT or USD). Top up via Add Funds.
- Your price = our retail price minus your reseller discount (shown in
balanceandpricing). High-volume resellers get bigger discounts — ask us. - The wallet is charged before the registrar is contacted, and each order appears as a paid invoice in your client area.
- If automatic registration or renewal does not complete, you get
pending_manual: the order is kept and our team completes it manually (or refunds it to your wallet if it cannot be completed). Do not retry the same domain. - Use a unique
referenceper order so a network retry never charges you twice.
Endpoints
GET ?action=balance — Wallet balance
Returns your prepaid balance, its currency and your discount.
curl -H "Authorization: Bearer $HSR_API_KEY" "https://clients.hostingsubidha.com/reseller-api.php?action=balance"$b = hsr('balance');
echo $b['balance'] . ' ' . $b['currency'];const r = await fetch('https://clients.hostingsubidha.com/reseller-api.php?action=balance', { headers: { Authorization: 'Bearer ' + process.env.HSR_API_KEY } });
console.log((await r.json()).data);Response
{
"ok": true,
"data": { "balance": 5000, "currency": "BDT", "discount_percent": 10 }
}GET ?action=pricing — Your price list
Reseller prices (1 year) for every extension, or one extension with tld. Also shows the retail price so you can set your own markup.
| Parameter | Type | Required | Description |
|---|---|---|---|
tld | string | No | e.g. com — omit for all 280+ extensions |
curl -H "Authorization: Bearer $HSR_API_KEY" "https://clients.hostingsubidha.com/reseller-api.php?action=pricing&tld=com"$p = hsr('pricing', 'GET', ['tld' => 'com']);await fetch('https://clients.hostingsubidha.com/reseller-api.php?action=pricing&tld=com', { headers: { Authorization: 'Bearer ' + KEY } })Response
{
"ok": true,
"data": {
"currency": "BDT", "discount_percent": 10, "years": 1,
"tlds": [ { "tld": ".com", "register": 1296, "retail_register": 1440,
"renew": 1566, "retail_renew": 1740, "transfer": 1134, "retail_transfer": 1260 } ]
}
}GET ?action=check — Check availability
Live availability check with your price.
| Parameter | Type | Required | Description |
|---|---|---|---|
domain | string | Yes | Full domain, e.g. mybrand.com |
curl -H "Authorization: Bearer $HSR_API_KEY" "https://clients.hostingsubidha.com/reseller-api.php?action=check&domain=mybrand.com"$c = hsr('check', 'GET', ['domain' => 'mybrand.com']);
if ($c['available']) echo 'Price: ' . $c['price'];const c = await (await fetch('https://clients.hostingsubidha.com/reseller-api.php?action=check&domain=mybrand.com', { headers: { Authorization: 'Bearer ' + KEY } })).json();Response
{
"ok": true,
"data": { "domain": "mybrand.com", "available": true, "currency": "BDT",
"price": 1296, "retail_price": 1440, "renew_price": 1566 }
}POST ?action=register — Register a domain
Charges your wallet, then registers the domain at the registrar. If automatic registration does not complete, the order is kept and activated manually by our team (response pending_manual). Can take up to ~2 minutes — use a timeout of 240 s.
| Parameter | Type | Required | Description |
|---|---|---|---|
domain | string | Yes | Domain to register |
years | int | No | 1–10, default 1 |
nameservers | array | No | 2–5 nameservers, e.g. ["ns1.host.com","ns2.host.com"] |
reference | string | No | Your unique order ID. Retrying with the same reference never charges twice (idempotency). |
curl -X POST -H "Authorization: Bearer $HSR_API_KEY" -H "Content-Type: application/json" \
-d '{"domain":"mybrand.com","years":1,"nameservers":["ns1.myhost.com","ns2.myhost.com"],"reference":"order-1001"}' \
"https://clients.hostingsubidha.com/reseller-api.php?action=register"$r = hsr('register', 'POST', [
'domain' => 'mybrand.com', 'years' => 1,
'nameservers' => ['ns1.myhost.com', 'ns2.myhost.com'],
'reference' => 'order-1001',
]);await fetch('https://clients.hostingsubidha.com/reseller-api.php?action=register', {
method: 'POST',
headers: { Authorization: 'Bearer ' + KEY, 'Content-Type': 'application/json' },
body: JSON.stringify({ domain: 'mybrand.com', years: 1, nameservers: ['ns1.myhost.com','ns2.myhost.com'], reference: 'order-1001' })
});Response
{
"ok": true,
"data": { "domain": "mybrand.com", "status": "registered", "years": 1, "charged": 1296,
"currency": "BDT", "order_id": 512, "invoice_id": 2045, "expiry_date": "2027-09-27", "balance": 3704 }
}POST ?action=renew — Renew a domain
Renews a domain in your account. If automatic renewal does not complete, our team renews it manually (pending_manual).
| Parameter | Type | Required | Description |
|---|---|---|---|
domain | string | Yes | Domain in your account |
years | int | No | 1–10, default 1 |
reference | string | No | Idempotency key |
curl -X POST -H "Authorization: Bearer $HSR_API_KEY" -d "domain=mybrand.com&years=1" "https://clients.hostingsubidha.com/reseller-api.php?action=renew"hsr('renew', 'POST', ['domain' => 'mybrand.com', 'years' => 1]);await fetch('https://clients.hostingsubidha.com/reseller-api.php?action=renew', { method:'POST', headers:{Authorization:'Bearer '+KEY,'Content-Type':'application/json'}, body: JSON.stringify({domain:'mybrand.com',years:1}) });Response
{ "ok": true, "data": { "domain": "mybrand.com", "status": "renewed", "charged": 1566, "expiry_date": "2028-09-27" } }POST ?action=transfer — Transfer a domain in
Starts an inbound transfer. The domain must be unlocked at the current registrar.
| Parameter | Type | Required | Description |
|---|---|---|---|
domain | string | Yes | Domain to transfer |
eppcode | string | Yes | Authorization / EPP code |
years | int | No | Default 1 |
nameservers | array | No | Optional |
reference | string | No | Idempotency key |
curl -X POST -H "Authorization: Bearer $HSR_API_KEY" -d "domain=mybrand.com&eppcode=Xy12..." "https://clients.hostingsubidha.com/reseller-api.php?action=transfer"hsr('transfer', 'POST', ['domain' => 'mybrand.com', 'eppcode' => 'Xy12...']);await fetch('https://clients.hostingsubidha.com/reseller-api.php?action=transfer', { method:'POST', headers:{Authorization:'Bearer '+KEY,'Content-Type':'application/json'}, body: JSON.stringify({domain:'mybrand.com',eppcode:'Xy12...'}) });Response
{ "ok": true, "data": { "domain": "mybrand.com", "status": "transfer_started", "charged": 1134 } }GET ?action=domains — List your domains
Paginated list of domains in your account.
| Parameter | Type | Required | Description |
|---|---|---|---|
limit | int | No | 1–250, default 100 |
offset | int | No | Default 0 |
curl -H "Authorization: Bearer $HSR_API_KEY" "https://clients.hostingsubidha.com/reseller-api.php?action=domains&limit=50"$list = hsr('domains', 'GET', ['limit' => 50]);await fetch('https://clients.hostingsubidha.com/reseller-api.php?action=domains&limit=50', { headers: { Authorization: 'Bearer ' + KEY } })Response
{ "ok": true, "data": { "total": 2, "domains": [ { "domain": "mybrand.com", "status": "Active", "registered": "2026-09-27", "expires": "2027-09-27" } ] } }GET ?action=domain — Domain details
Status, dates, nameservers and lock state.
| Parameter | Type | Required | Description |
|---|---|---|---|
domain | string | Yes | Domain in your account |
curl -H "Authorization: Bearer $HSR_API_KEY" "https://clients.hostingsubidha.com/reseller-api.php?action=domain&domain=mybrand.com"$d = hsr('domain', 'GET', ['domain' => 'mybrand.com']);await fetch('https://clients.hostingsubidha.com/reseller-api.php?action=domain&domain=mybrand.com', { headers: { Authorization: 'Bearer ' + KEY } })Response
{ "ok": true, "data": { "domain": "mybrand.com", "status": "Active", "expires": "2027-09-27",
"nameservers": ["ns1.myhost.com","ns2.myhost.com"], "locked": true, "auto_renew": true } }POST ?action=nameservers — Update nameservers
Sets 2–5 nameservers.
| Parameter | Type | Required | Description |
|---|---|---|---|
domain | string | Yes | Domain in your account |
nameservers | array|string | Yes | Array or comma-separated list |
curl -X POST -H "Authorization: Bearer $HSR_API_KEY" -d "domain=mybrand.com&nameservers=ns1.a.com,ns2.a.com" "https://clients.hostingsubidha.com/reseller-api.php?action=nameservers"hsr('nameservers', 'POST', ['domain' => 'mybrand.com', 'nameservers' => ['ns1.a.com', 'ns2.a.com']]);await fetch('https://clients.hostingsubidha.com/reseller-api.php?action=nameservers', { method:'POST', headers:{Authorization:'Bearer '+KEY,'Content-Type':'application/json'}, body: JSON.stringify({domain:'mybrand.com',nameservers:['ns1.a.com','ns2.a.com']}) });Response
{ "ok": true, "data": { "domain": "mybrand.com", "nameservers": ["ns1.a.com","ns2.a.com"] } }POST ?action=epp — Get EPP / auth code
Returns the transfer authorization code, or emails it to the registrant if the registry requires that.
| Parameter | Type | Required | Description |
|---|---|---|---|
domain | string | Yes | Domain in your account |
curl -X POST -H "Authorization: Bearer $HSR_API_KEY" -d "domain=mybrand.com" "https://clients.hostingsubidha.com/reseller-api.php?action=epp"$e = hsr('epp', 'POST', ['domain' => 'mybrand.com']);await fetch('https://clients.hostingsubidha.com/reseller-api.php?action=epp', { method:'POST', headers:{Authorization:'Bearer '+KEY,'Content-Type':'application/json'}, body: JSON.stringify({domain:'mybrand.com'}) });Response
{ "ok": true, "data": { "domain": "mybrand.com", "eppcode": "Xy12#abc" } }POST ?action=lock — Registrar lock
Locks or unlocks a domain (unlock before transferring away).
| Parameter | Type | Required | Description |
|---|---|---|---|
domain | string | Yes | Domain in your account |
locked | bool | Yes | true or false |
curl -X POST -H "Authorization: Bearer $HSR_API_KEY" -d "domain=mybrand.com&locked=false" "https://clients.hostingsubidha.com/reseller-api.php?action=lock"hsr('lock', 'POST', ['domain' => 'mybrand.com', 'locked' => false]);await fetch('https://clients.hostingsubidha.com/reseller-api.php?action=lock', { method:'POST', headers:{Authorization:'Bearer '+KEY,'Content-Type':'application/json'}, body: JSON.stringify({domain:'mybrand.com',locked:false}) });Response
{ "ok": true, "data": { "domain": "mybrand.com", "locked": false } }
Errors
| code | HTTP | Meaning |
|---|---|---|
unauthorized | 401 | Missing or wrong API key |
account_inactive | 403 | Reseller account pending/disabled |
ip_not_allowed | 403 | Request IP not in your whitelist |
rate_limited | 429 | More than 120 requests per minute |
invalid_domain | 422 | Domain format is wrong |
unsupported | 422 | Extension/term not offered |
insufficient_funds | 402 | Wallet balance too low — add funds |
domain_unavailable | 409 | Domain is already registered |
already_exists | 409 | Domain already exists in our system |
not_found | 404 | Domain not in your account |
pending_manual | 202 | Order received and paid; automatic processing did not complete, so our team activates it manually — do not retry |
order_failed | 502 | Order could not be created — amount refunded to your wallet |
registrar_error | 502 | Registrar rejected a management action (nameservers, lock, EPP) |
busy | 409 | Another order for your account is in progress — retry in a few seconds |
WHMCS registrar module
Run your own WHMCS? Install our free registrar module and sell domains fully automatically.
- Download the module (ZIP) and upload the
modulesfolder to your WHMCS root. - System Settings → Domain Registrars → Hostingsubidha Domain Reseller → Activate, paste your API key.
- Optional: Utilities → Registrar TLD Sync imports our reseller prices as your cost prices.
- System Settings → Domain Pricing: set Auto Registration to Hostingsubidha for the extensions you sell.
Supported: register, renew, transfer, transfer sync, nameservers, registrar lock, EPP code, domain sync and availability lookup.
Your own website (PHP)
A tiny PHP client and a domain-search endpoint that adds your markup and keeps your key secret:
<?php
// Minimal PHP client — works with any framework or plain PHP.
function hsr(string $action, string $method = 'GET', array $data = []): array {
$url = 'https://clients.hostingsubidha.com/reseller-api.php?action=' . $action;
if ($method === 'GET' && $data) $url .= '&' . http_build_query($data);
$ch = curl_init($url);
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true, CURLOPT_TIMEOUT => 240,
CURLOPT_HTTPHEADER => ['Authorization: Bearer ' . getenv('HSR_API_KEY'), 'Content-Type: application/json'],
]);
if ($method === 'POST') { curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode($data)); }
$res = json_decode(curl_exec($ch), true);
if (empty($res['ok'])) throw new RuntimeException($res['error']['message'] ?? 'API error');
return $res['data'];
}
<?php
// domain-search.php — put on YOUR website. Keeps your API key secret on the server
// and adds your own profit margin before showing the price to customers.
const MARKUP_PERCENT = 20;
require 'hsr-client.php'; // the hsr() function above
header('Content-Type: application/json');
$domain = strtolower(trim($_GET['domain'] ?? ''));
try {
$r = hsr('check', 'GET', ['domain' => $domain]);
$r['your_price'] = $r['price'] !== null ? round($r['price'] * (1 + MARKUP_PERCENT / 100)) : null;
unset($r['price'], $r['retail_price']); // never expose your cost
echo json_encode(['ok' => true] + $r);
} catch (Throwable $e) {
http_response_code(400);
echo json_encode(['ok' => false, 'error' => $e->getMessage()]);
}
Security
- Never put your API key in HTML or front-end JavaScript — call the API from your server.
- Use the IP whitelist when your server has a fixed IP.
- Rate limit: 120 requests per minute per account.
- Questions? Telegram @hostingsubidhaowner · WhatsApp +8801897216101
