OnlineNIC · Authentication Profile

Onlinenic Authentication

Authentication

Authentication profile for the OnlineNIC Reseller API v4 (domain + SSL), transcribed from section 2.2 "Security Token" of the provider-published API 4.0.9 Reseller Guide (PDF). There is no OpenAPI securitySchemes block to derive from — OnlineNIC publishes no machine-readable contract — so every field below is read from the provider's own reference document and from a live unauthenticated probe of the API host.

OnlineNIC declares 3 security scheme(s) across its OpenAPI definitions.

DomainsDomain RegistrationRegistrarDNSSSL CertificatesCertificatesResellerHostingSecurity
Methods: Schemes: 3 OAuth flows: API key in:

Security Schemes

apikey apiKey
· in: formData ()
token signed-request
· in: formData ()
network

Source

Authentication Profile

onlinenic-authentication.yml Raw ↑
specification: API Commons Authentication
specificationVersion: '0.1'
provider: OnlineNIC
providerId: onlinenic
generated: '2026-09-17'
method: searched
source: https://www.onlinenic.com/cp_english/template_api/download/Onlinenic_API_v4.0.9.2_Reseller_Guide.pdf
docs: https://www.onlinenic.com/cp_english/template_api/api_help.php
description: >-
  Authentication profile for the OnlineNIC Reseller API v4 (domain + SSL), transcribed from
  section 2.2 "Security Token" of the provider-published API 4.0.9 Reseller Guide (PDF). There
  is no OpenAPI securitySchemes block to derive from — OnlineNIC publishes no machine-readable
  contract — so every field below is read from the provider's own reference document and from a
  live unauthenticated probe of the API host.
styles:
  - api-key
  - signed-request
  - ip-allowlist
schemes:
  - id: apikey
    type: apiKey
    in: formData
    name: apikey
    required: true
    description: >-
      API key issued to the reseller. The guide states "This parameter is required for security
      Authentication. Partner can get this in Reseller Control panel." Sent as a POST body
      parameter, not as a header.
    issued_via: Reseller Control Panel
  - id: token
    type: signed-request
    in: formData
    name: token
    required: true
    algorithm: md5
    description: >-
      Per-request security token. Token = MD5(user + MD5(password) + timestamp + command),
      lowercase 32-character MD5. Binds the request to the reseller id, the account password,
      the request timestamp and the command name.
    components:
      - name: user
        description: Reseller ID
      - name: password
        description: Reseller account password (hashed, never sent in the clear)
      - name: timestamp
        description: Request timestamp; a request is valid for 10 minutes
      - name: command
        description: Name of the method being called
    note: >-
      MD5 is used both for the password digest and for the request signature. It is a broken
      hash for signature purposes; HMAC-SHA256 would be the modern equivalent of this design.
      Recorded as an observation about the published scheme, not a vulnerability claim.
  - id: ip-allowlist
    type: network
    required: false
    description: >-
      IP White List. "By adding IP to white list in Reseller control panel, the IP address will
      be whitelisted, and other IP address will be blocked from accessing API server. If the IP
      White list omitted, system will not set limitation with the IP address." Optional and
      off by default. Error 1021 ("Your IP does not exist in IP whitelist") is returned when it
      is configured and the caller is not on it.
    applies_to: live
    note: The OTE test environment does not require IP allowlisting.
required_parameters:
  - user
  - timestamp
  - token
  - apikey
transport:
  protocol: https
  method: POST
  note: >-
    "API interface response to HTTPS call, and the request type must be POST." Credentials
    travel in the POST body; there is no Authorization header and no bearer token.
oauth2: false
openid_connect: false
mutual_tls: false
scopes:
  supported: false
  note: >-
    The API has no scope or permission model. A reseller API key carries the full command
    surface for that reseller account, so scopes/ is deliberately not emitted.
errors:
  - code: 1006
    message: Authentication error.
    meaning: Security token or password is wrong.
  - code: 1020
    message: Invalid API key.
  - code: 1021
    message: Your IP does not exist in IP whitelist.
  - code: 1005
    message: Object does not exist(user).
    meaning: Invalid reseller ID.
evidence:
  - url: https://api.onlinenic.com/api4/ssl/index.php
    method: GET
    status: 200
    body: '{"code":1001,"msg":"Invalid request."}'
    note: Live host answers the documented JSON envelope; GET is rejected as the guide states.
  - url: https://api.onlinenic.com/api4/domain/index.php?command=checkDomain
    method: POST
    status: 200
    body: '{"code":1004,"msg":"Required parameter missing(user)."}'
    note: Unauthenticated POST confirms `user` is the first required credential parameter.
legacy:
  - api: OnlineNIC API 3.4 (deprecated)
    transport: raw TCP socket, XML request/response
    port: 30009
    auth: chksum over category + action + params + cltrid, credentials in config
    source: https://www.onlinenic.com/cp_english/template_api/download.php?f=sdk_php.zip
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/onlinenic-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.