Automating a hosting business.
WHAT IT PROVIDES
Programmatic access to clients, orders, invoices, products, tickets and domains.
WHAT IT IS USED FOR
Provisioning from other systems Reporting Custom client interfaces Synchronising with other tools
WHAT AUTHENTICATION IT USES
Credentials issued to an administrative role, restricted by address.
WHAT TO RESTRICT
The permitted addresses The permitted actions
WHY
The credential can do a great deal, including financial actions.
WHAT TO NEVER DO
Expose the interface publicly without restriction Use an unrestricted administrative account
WHAT THE REQUEST SHAPE IS
An action name, with parameters.
WHAT TO CHECK IN EVERY RESPONSE
The result indicator, not only the status code.
WHY
Failures are reported in the body.
WHAT TO BE CAREFUL WITH
Actions that create invoices or take payment Bulk operations affecting many clients Assumptions about field names across versions
WHAT TO TEST AGAINST
A separate installation, never production.
WHY
Actions are frequently irreversible, and they affect real customers.
WHAT TO LOG
Every call and its outcome.
WHAT TO REVIEW AFTER ANY UPGRADE
Whether the actions you rely on changed.
WHAT TO PREFER FOR EXTENSIONS
A module using the internal interfaces, rather than external calls to your own system.