Registrar integrations
Registrar integrations can be configured through the web interface: open a system registrar that has a supported driver (currently Namecheap or Porkbun) from the Registrars view, and its connect form shows the required fields automatically. Once connected, you can sync all domains from that registrar's account or disconnect the integration from the same modal.
Integrations can also be managed directly through the authenticated integration API, which is scoped to the selected team. This is useful for automation or when a dedicated UI screen isn't convenient. Use the integration API only from a trusted client or server. Never put registrar credentials in browser code, public documentation, source control, or a support request.
The API routes and request example below document the supported create, read, update, and delete workflow.
| Method | Route | Purpose |
|---|---|---|
GET | /api/registrars/integrations | List integrations for the current team. Secrets are omitted from the response. |
POST | /api/registrars/integrations | Create an integration. |
GET | /api/registrars/integrations/:id | Read an integration. |
PATCH | /api/registrars/integrations/:id | Update an integration. |
DELETE | /api/registrars/integrations/:id | Delete an integration. |
All routes require an authenticated session. For example, an authorized API client can create an integration with a JSON body shaped like this:
{
"registrarId": "REGISTRAR_ID",
"type": "namecheap",
"secrets": {
"apiUser": "supplied-securely",
"apiKey": "supplied-securely",
"clientIp": "YOUR_ALLOWED_CLIENT_IP"
},
"settings": {}
}
The Namecheap driver requires apiUser, apiKey, and clientIp. Supply real values through a secret-safe client; the values above are illustrative, not credentials. Creation and update responses omit secrets, and list responses never return them.
The Porkbun driver requires apiKey and secretApiKey (an API key and secret key pair generated from Porkbun's account settings):
{
"registrarId": "REGISTRAR_ID",
"type": "porkbun",
"secrets": {
"apiKey": "supplied-securely",
"secretApiKey": "supplied-securely"
},
"settings": {}
}
To change credentials, send a PATCH to /api/registrars/integrations/INTEGRATION_ID with the replacement values:
{
"secrets": {
"apiUser": "supplied-securely",
"apiKey": "replacement-securely",
"clientIp": "YOUR_ALLOWED_CLIENT_IP"
}
}
The single-integration GET and DELETE endpoints currently return the stored integration, including its secrets. Call them only from a trusted backend and never log or expose those responses. The collection GET, POST, and PATCH responses omit secrets. Keep this distinction in mind when building API clients.