Registrar integrations
Registrar integrations are not configured through the web interface. The current integration endpoints are authenticated and scoped to the selected team. At present, the server has a Namecheap driver; other registrar integrations are not supported by that driver.
Use the integration API only from a trusted client or server. Never put registrar credentials in browser code, public documentation, source control, or a support request.
Because integration setup is currently API-only, there is no in-app integration screen to capture. The API routes and request example below document the supported create, read, update, and delete workflow.
| Method | Route | Purpose |
|---|---|---|
GET | /api/registrars/integrations | List integrations for the current team. Secrets are omitted from the response. |
POST | /api/registrars/integrations | Create an integration. |
GET | /api/registrars/integrations/:id | Read an integration. |
PATCH | /api/registrars/integrations/:id | Update an integration. |
DELETE | /api/registrars/integrations/:id | Delete an integration. |
All routes require an authenticated session. For example, an authorized API client can create an integration with a JSON body shaped like this:
{
"registrarId": "REGISTRAR_ID",
"type": "generic",
"secrets": {
"apiUser": "supplied-securely",
"apiKey": "supplied-securely",
"clientIp": "YOUR_ALLOWED_CLIENT_IP"
},
"settings": {}
}
The Namecheap driver requires apiUser, apiKey, and clientIp. Supply real values through a secret-safe client; the values above are illustrative, not credentials. Creation and update responses omit secrets, and list responses never return them. Treat integration management as an operator workflow until the app provides a dedicated interface.
To change credentials, send a PATCH to /api/registrars/integrations/INTEGRATION_ID with the replacement values:
{
"secrets": {
"apiUser": "supplied-securely",
"apiKey": "replacement-securely",
"clientIp": "YOUR_ALLOWED_CLIENT_IP"
}
}
The single-integration GET and DELETE endpoints currently return the stored integration, including its secrets. Call them only from a trusted backend and never log or expose those responses. The collection GET, POST, and PATCH responses omit secrets. Keep this distinction in mind when building API clients.