# OnlineNIC > OnlineNIC, Inc. is an ICANN-accredited domain registrar (IANA ID 82) and wholesale reseller > platform for domain names, SSL/TLS certificates, business email, reseller hosting and cloud > services. It publishes a partner API — the OnlineNIC Reseller API v4 — that lets resellers > register and manage domains, manage contacts and nameservers, run registrar transfers, apply > registrant privacy (ID Shield), and order, reissue, cancel and revoke SSL certificates. Generated by API Evangelist on 2026-09-17 from the provider's own public documentation and from live probes of its hosts. This file is NOT published by OnlineNIC; /llms.txt returns 404 on every OnlineNIC host. See https://apievangelist.com/about/where-our-data-comes-from ## What an agent needs to know first - There is **no machine-readable contract**. No OpenAPI, no AsyncAPI, no GraphQL SDL, no WSDL, no Postman collection, no JSON Schema. The reference ships as a 60-page PDF. Probed 2026-09-17: /openapi.json, /swagger.json and /api-docs all return 404 on www.onlinenic.com and api.onlinenic.com. - The API is live and answering. GET https://api.onlinenic.com/api4/ssl/index.php returns {"code":1001,"msg":"Invalid request."}; an unauthenticated POST returns {"code":1004,"msg":"Required parameter missing(user)."}. - It is **RPC, not REST**, despite the marketing label. Two PHP endpoints carry all 43 operations and the verb travels in a `command` query parameter. POST only. - **Every response is HTTP 200**, including authentication failures. The outcome is an integer `code` in the JSON body. Branching on HTTP status will read every error as a success. - **No idempotency key exists.** A retry after a timeout cannot be made safe. Duplicate SSL orders are rejected as errors (1014/1032); domain register/renew/transfer have no duplicate protection documented at all. - **registerDomain has no reversal.** There is no delete-domain command in API v4 and no documented grace-period refund. Treat it as irreversible. - **No webhooks, no events.** Asynchronous outcomes (registrant change, transfer, Whois verification) must be polled. - Access requires a reseller account; there is no self-serve API key. ## API - [API / Integration page](https://www.onlinenic.com/cp_english/template_api/api_help.php): the provider's reference hub — download links for each API version and the PHP SDK. - [API 4.0.9 Reseller Guide (PDF)](https://www.onlinenic.com/cp_english/template_api/download/Onlinenic_API_v4.0.9.2_Reseller_Guide.pdf): the actual contract. Overview, security token, all 43 commands with parameter tables, the full error-code registry, product catalogue and change log. - [API 3.4 Usage Guide (PDF)](https://onlinenic.com/cp_english/template_api/download/API_EN_Version_3.4.pdf): the DEPRECATED predecessor — domain functions only, XML over a raw TCP socket on port 30009. - [PHP SDK (ZIP)](https://www.onlinenic.com/cp_english/template_api/download.php?f=sdk_php.zip): first-party, but implements the deprecated 3.4 socket protocol, last released 2015-10-08. - Live base: https://api.onlinenic.com/api4/ — SSL surface at /api4/ssl/index.php, domain surface at /api4/domain/index.php - Test base (OTE): https://ote.onlinenic.com/api4/ — documented for all 43 commands; did not answer when probed on 2026-09-17. ## Authentication Four POST body parameters on every call: `user` (reseller id), `timestamp`, `apikey`, and `token`, where token = MD5(user + MD5(password) + timestamp + command), lowercase 32-char MD5. A request is valid for 10 minutes. An optional IP allowlist is configured in the reseller control panel. No OAuth, no OpenID Connect, no scopes. ## Operations Domain (https://api.onlinenic.com/api4/domain/index.php?command=...): checkDomain, registerDomain, renewDomain, infoDomain, updateDomainStatus, updateDomainDns, setDomainPassword, createContact, infoContact, updateContact, domainChangeContact, transferDomain, queryTransferStatus, cancelDomainTransfer, getAuthCode, updateAuthCode, checkHost, createHost, infoHost, updateHost, deleteHost, checkWhoisVF, resendWhoisVF, applyIDShield, infoIDShield, suspendIDShield, resumeIDShield, changeDCVmethod SSL (https://api.onlinenic.com/api4/ssl/index.php?command=...): parseCsr, getApprovalEmailList, orderSSL, renewSSL, getSSLProductDetails, getSSLprice, getSSLOrderId, getSSLOrderInfo, getSSLOrderList, checkDomainDcv, resendApprovalEmail, reissueSSL, cancelSSL, changeValidationEmail, getSSLCert, revokeSSL ## Reversibility - orderSSL -> cancelSSL, **within 30 days of issuance** (stated in the guide). This is the only write in the API with a reversal path AND a stated window. - orderSSL -> revokeSSL (no window; for key compromise, not refund). - transferDomain -> cancelDomainTransfer (no window stated). - applyIDShield -> suspendIDShield / resumeIDShield. - createHost -> deleteHost. - registerDomain, renewDomain -> **no reversal**. ## Errors 79 documented codes, flat integers in the response body. 1000 = success. Highlights: 1004 required parameter missing, 1006 authentication error, 1020 invalid API key, 1021 IP not in whitelist, 1023 insufficient balance, 1024 timeout, 1029 order cannot be cancelled in current status, 1074 server too busy. Full registry: Addendum 6.1 of the 4.0.9 guide. ## Limits No rate limit is published, no RateLimit-*/X-RateLimit-* headers are documented, and no 429 appears in the error registry. Pagination on order lists only: `page` in, `page` + `pagesum` out, 100 records per page. ## Company - [Website](https://www.onlinenic.com/) - [Reseller programme](https://www.onlinenic.com/en/Reseller/index/18.html) - [Domain pricing (Platinum/Gold/Silver/Bronze tiers)](https://www.onlinenic.com/en/Domains/index/19.html) - [WHMCS module](https://www.onlinenic.com/en/Module/index/17.html) - [News Center](https://www.onlinenic.com/en/News/index.html) — announcements, last dated 2020-08-04 - [Help desk](https://helpdesk.onlinenic.com/portal/en/home) - [Sign up](https://www.onlinenic.com/en/Home/register.html) | [Login](https://www.onlinenic.com/en/Home/login.html) - [Service terms](https://www.onlinenic.com/en/Content/content/118.html) | [Privacy Statement (PDF)](https://onlinenic.com/OnlineNIC_PRIVACY_Statement.pdf) ## Not available No MCP server. No A2A agent card. No /.well-known/ documents of any kind (security.txt, openid-configuration, oauth-authorization-server, api-catalog, ai-plugin.json, agent-card.json all 404 on every host). No status page. No GitHub organisation. No SDK for the current API version.