Registrars and pricing

Registrar integrations

Manage supported registrar API credentials through the authenticated integration API.

Registrar integrations are not configured through the web interface. The current integration endpoints are authenticated and scoped to the selected team. At present, the server has a Namecheap driver; other registrar integrations are not supported by that driver.

Use the integration API only from a trusted client or server. Never put registrar credentials in browser code, public documentation, source control, or a support request.

Because integration setup is currently API-only, there is no in-app integration screen to capture. The API routes and request example below document the supported create, read, update, and delete workflow.

MethodRoutePurpose
GET/api/registrars/integrationsList integrations for the current team. Secrets are omitted from the response.
POST/api/registrars/integrationsCreate an integration.
GET/api/registrars/integrations/:idRead an integration.
PATCH/api/registrars/integrations/:idUpdate an integration.
DELETE/api/registrars/integrations/:idDelete an integration.

All routes require an authenticated session. For example, an authorized API client can create an integration with a JSON body shaped like this:

{
  "registrarId": "REGISTRAR_ID",
  "type": "generic",
  "secrets": {
    "apiUser": "supplied-securely",
    "apiKey": "supplied-securely",
    "clientIp": "YOUR_ALLOWED_CLIENT_IP"
  },
  "settings": {}
}

The Namecheap driver requires apiUser, apiKey, and clientIp. Supply real values through a secret-safe client; the values above are illustrative, not credentials. Creation and update responses omit secrets, and list responses never return them. Treat integration management as an operator workflow until the app provides a dedicated interface.

To change credentials, send a PATCH to /api/registrars/integrations/INTEGRATION_ID with the replacement values:

{
  "secrets": {
    "apiUser": "supplied-securely",
    "apiKey": "replacement-securely",
    "clientIp": "YOUR_ALLOWED_CLIENT_IP"
  }
}

The single-integration GET and DELETE endpoints currently return the stored integration, including its secrets. Call them only from a trusted backend and never log or expose those responses. The collection GET, POST, and PATCH responses omit secrets. Keep this distinction in mind when building API clients.

Copyright © 2026