specification: API Commons Conformance specificationVersion: '0.1' provider: OnlineNIC providerId: onlinenic generated: '2026-09-17' method: searched source: >- https://www.onlinenic.com/cp_english/template_api/download/Onlinenic_API_v4.0.9.2_Reseller_Guide.pdf ; https://www.onlinenic.com/en/ ; live TLS + HTTP probes description: >- Cross-cutting and domain-standard conformance for the OnlineNIC Reseller API. Assessed against the provider's own reference guide and live probes. Most entries are honest negatives — recording that a standard is NOT implemented is the useful measurement for a buyer choosing a registrar API, and nothing here was assumed from the product category. entries: - id: openapi label: OpenAPI description available conforms: false evidence: >- /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs and /redoc all return 404 on www.onlinenic.com and api.onlinenic.com (probed 2026-09-17). The reference is a 60-page PDF. - id: asyncapi label: AsyncAPI event description conforms: false evidence: >- No event, webhook, callback or streaming surface is documented anywhere in the 4.0.9 guide; state changes are discovered by polling. - id: graphql label: GraphQL conforms: false evidence: No /graphql surface is documented or referenced. - id: soap-wsdl label: SOAP / WSDL conforms: false evidence: >- ?wsdl on api.onlinenic.com returns the ordinary JSON error envelope, not a WSDL. The legacy v3.4 protocol is bespoke XML over a raw TCP socket on port 30009, not SOAP. - id: rest label: REST (resource-oriented) conforms: false evidence: >- Marketed as "RESTful" but the surface is RPC: two PHP endpoints and a `command` query parameter carry all 43 operations; POST is the only method and HTTP status is always 200. - id: rfc9457 label: RFC 9457 Problem Details conforms: false evidence: >- Errors use a bespoke {"code":,"msg":} envelope returned with HTTP 200. No application/problem+json. - id: rfc7807 label: RFC 7807 Problem Details (superseded) conforms: false evidence: Same bespoke envelope. - id: http-semantics label: HTTP status semantics conforms: false evidence: >- Probed live — an unauthenticated request returns HTTP 200 carrying {"code":1004,"msg":"Required parameter missing(user)."}. Authentication failure (1006), missing resource (1016) and server fault (1008) are all HTTP 200. - id: oauth2 label: OAuth 2.0 conforms: false evidence: >- Authentication is an API key plus an MD5 request signature in the POST body. No /.well-known/oauth-authorization-server on any host (probed 404). - id: oidc label: OpenID Connect conforms: false evidence: /.well-known/openid-configuration returns 404 on every host probed. - id: idempotency label: Idempotent write semantics conforms: false evidence: >- No idempotency key on any of the 43 commands; duplicate submission is rejected as an error (1014/1032) rather than replayed. See conventions/onlinenic-conventions.yml. - id: pagination label: Documented pagination conforms: true evidence: >- Guide sections 3.2 and 6.7 — `page` request parameter, `page` and `pagesum` response fields, 100 records per page, added in API 4.08. Scoped to the order-list commands. - id: rfc8594-sunset label: RFC 8594 Sunset header conforms: false evidence: No Sunset or Deprecation header is documented; no deprecation policy is published. - id: rfc9116-security-txt label: RFC 9116 security.txt conforms: false evidence: /.well-known/security.txt returns 404 on onlinenic.com, www, api and helpdesk hosts. - id: tls-1-2 label: TLS 1.2 or better on the API and website hosts conforms: true evidence: >- Re-probed 2026-09-17 — www.onlinenic.com and api.onlinenic.com both negotiate TLSv1.2 with a certificate valid to 2026-10-10. See security/onlinenic-domain-security.yml. - id: tls-1-3 label: TLS 1.3 conforms: false evidence: >- Neither www.onlinenic.com nor api.onlinenic.com offered TLS 1.3 when probed on 2026-09-17; both topped out at TLSv1.2. - id: hsts label: HTTP Strict Transport Security conforms: false evidence: No Strict-Transport-Security header on www.onlinenic.com (probed 2026-09-17). - id: caa label: CAA records conforms: false evidence: >- onlinenic.com publishes no CAA record. Worth naming because the company resells certificates from five CAs. - id: vulnerability-disclosure label: Published vulnerability disclosure programme conforms: false evidence: >- probe-security-programs.py found no security.txt Policy or Contact, no bug-bounty listing (HackerOne / Bugcrowd / Intigriti) and no disclosure page. No Security pointer is wired. - id: trust-center label: Trust centre conforms: false evidence: No trust.onlinenic.com and no trust/compliance page on the main site. - id: dnssec label: DNSSEC on the registrable domain conforms: false evidence: >- onlinenic.com publishes no DNSSEC. Recorded as a finding rather than a neutral fact because the company is an ICANN-accredited registrar selling DNS services. domain_standards: - id: epp label: EPP (RFC 5730-5734) — the registry provisioning protocol conforms: false partial: true evidence: >- The command vocabulary is EPP-derived and reads as a REST façade over an EPP back end — checkDomain, infoDomain, createContact, infoContact, updateContact, transferDomain, checkHost/createHost/updateHost/deleteHost, getAuthCode/updateAuthCode all map one-to-one onto EPP //// on the domain, contact and host objects, and the WHMCS module advertises "Get EPP Code". But the wire format is neither EPP XML nor EPP-over-TCP: it is form-encoded POST with a JSON reply. A client that already speaks EPP cannot talk to this API without a bespoke connector, which is exactly the distinction this check exists to draw. signature_location: >- Command names in sections 4.1-4.4 of the API 4.0.9 Reseller Guide. - id: rdap label: RDAP (RFC 7480-7484) — registration data access conforms: false evidence: >- OnlineNIC publishes a human Whois lookup page (/en/Domains/whois.html) and a Whois verification command pair in the API (checkWhoisVF / resendWhoisVF), but no RDAP endpoint and no RDAP bootstrap reference. The API's Whois surface is registrant-verification workflow, not registration-data access. - id: icann-raa label: ICANN Registrar Accreditation conforms: true kind: accreditation evidence: >- "1999-2026 OnlineNIC is an ICANN-accredited registrar" — published in the footer of every page on www.onlinenic.com (probed 200, 2026-09-17). IANA registrar ID 82. Recorded as an accreditation the company publishes about itself, not as a security or compliance certification; no Compliance pointer is wired from it. certifications: published: [] note: >- No SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP attestation is published on any OnlineNIC surface, and there is no trust centre. No Compliance or TrustCenter pointer is wired. maintainers: - FN: Kin Lane email: kin@apievangelist.com