All manual sections

DocumentationWHMCS and API keys

WHMCS and API keys

Koapanel connects to WHMCS (8.x and 9.x) with the official module: when a customer orders hosting, WHMCS creates the account on the panel, suspends it when an invoice is unpaid, upgrades and deletes it, and the customer logs into the panel with one click from the WHMCS client area.

API keys

WHMCS and other billing systems use a personal API key. Create it in API keys (administrators and resellers):

  • the key (kpk_…) is shown once: copy it right away;
  • it acts as you: a reseller's key reaches only the reseller's clients and packages, within its quota; creating resellers from WHMCS needs an administrator key;
  • keys are created and deleted only while logged into the panel (a key cannot create keys);
  • at most 300 requests per minute and 10 keys per account;
  • if the account is suspended or deleted, its keys stop working;
  • in the Activity log everything done with a key shows "via API key …" and the system that used it.

Delete at once a key you no longer use or that may have been seen by others.

Connecting WHMCS

  1. Download the module from https://console.koapanel.app/updates/integrations/ and extract it in the WHMCS folder (modules/servers/koapanel).
  2. In WHMCS add a server: Hostname = this panel's name, Module Koapanel, Password = the API key, Secure yes, port 8443. Press Test Connection.
  3. Create products with the Koapanel module: pick a panel package or set the limits (sites, disk, databases, mailboxes); for a reseller product choose "Reseller" and the number of clients.

The full WHMCS guide is README.en.md in the module zip.

What WHMCS does on the panel

  • Creates the account with the service username and password (a strong password is generated when WHMCS's is too weak); creating again does not make duplicates.
  • Suspends and unsuspends the account, with the reason written in WHMCS.
  • Changes the package or the reseller quota.
  • Deletes the account and its sites when the service is terminated.
  • One-click login: WHMCS asks the panel for a one-time login link valid 60 seconds; the client area also has direct links to Files, WordPress, Email and Databases. A suspended account gets no link.
  • Once a day it reads the disk used by each account.

Reselling Koapanel licences

Partner providers can also sell Koapanel licences from WHMCS with the koapanel_license module and the partner key issued by Koapanel.