API and reseller readiness for service panels
API and reseller readiness for service panels
An API can help resellers automate service requests and status checks, but it should only be opened after the catalog, payment workflow, and fulfillment process are verified.
API key safety
API keys should be treated like passwords. Keep them out of URLs, screenshots, public repositories, and customer support messages. If a key may have been exposed, regenerate it from the account settings.
Idempotency matters
Order creation should use an idempotency key so a network retry does not create a duplicate order or second wallet debit. Reusing the same key for a different request should be rejected.
Child-panel review
Child-panel domains require administrator review, DNS configuration, TLS setup, and clear customer support responsibility. A reseller should not advertise platform affiliation or delivery guarantees that the underlying service does not provide.