Account Provisioning
APIs: how account provisioning stops being manual
You can build the first twenty client accounts by hand; the API is what stops the next two hundred eating your evenings.
Straight answer first
An API is an agreed, machine-readable contract between two pieces of software — and in a reselling business it is the thing that lets your billing system create, suspend, upgrade and terminate cPanel accounts in WHM without a human opening either screen.
The commercial case is arithmetic rather than engineering. Five minutes to build an account by hand, two to suspend it for non-payment, two more to bring it back: across forty clients that is an evening a week you never priced into a package, and it arrives whether or not anyone paid you that month. Automation does not make the work quicker, it removes the category of work altogether — along with the quota set from memory and the password recycled from the last account.
Written by the Hosting Seller staff · Checked 4 August 2026
0
Terms left vague
100+
Entries, cross-linked
Real
Panels, named
Free
To read, no signup
Web APIs run over HTTPS. Your billing platform sends a request to an endpoint, the far side does something and returns structured data, almost always JSON. WHMCS wired into WHM is precisely that arrangement: an order is paid, a create-account call goes out, a cPanel account exists, and a welcome message reaches the client carrying credentials nobody typed.
Every call carries a credential that acts as you. A WHM API token can create and remove accounts across your entire reseller container, which makes it worth rather more than the password to your own inbox and worth handling accordingly.
What the client sees when this works
Nothing at all, which is the point. They pay, and inside a minute there is a welcome message, a cPanel login on your nameservers and an account that works. No apology for the delay, no promise to set it up in the morning, no request to wait for office hours.
When it does not work they see the gap, and the gap is the first impression your brand ever makes. Provisioning failures arrive as tickets before the client has used the product once.
Minutes per account, and where they go
Building an account by hand in WHM is a package choice, a domain, a contact address, a password and a welcome email you write yourself. Call it five minutes when nothing goes wrong. Suspension for non-payment is another two, unsuspension two more, termination two after that.
That is a figure you can multiply, which is what makes it a commercial number rather than a technical one. Twenty clients is a nuisance. A hundred is a part-time job you never priced into the packages.
Where it strains as the client list grows
Manual provisioning fails quietly first. A client gets suspended twice, a package limit is set from memory rather than from the plan, someone is issued a password recycled from the last account. None of it looks like an outage and all of it produces tickets.
An API removes the class of error rather than the instance. Accounts are built from one definition every time, which is also what makes the packages you named worth naming.
Tokens, and what they can leak upstream
Issue a WHM API token scoped to the job instead of handing your billing system something close to root, and keep it out of anything a contractor or a screenshot can reach. If a token turns up in a support paste, replace it that hour rather than that week.
One more habit worth keeping: raw error text from an upstream call often names software, hostnames and vendors you would rather your client never read. Log it, do not display it. Encryption is the natural next entry, and WordPress after that.

The file you keep behind the counter
Every term in here was defined because it turned up in a client conversation first — usually as a question a reseller had to answer for somebody else, at speed, with the client listening.
Overselling is switched on from the start, so the packages you build can reflect real usage rather than the disk you have bought.
- Written for the person holding the reseller account, not the single site
- Every term placed in WHM, cPanel or the billing system
- Admin time and ticket volume named alongside the definition
- Cross-linked, so one lookup answers the next client question
Why Hosting Seller
On every plan, as standard
Costed in minutes per account
The admin time a term adds or removes, multiplied across a client list, because that is the number you actually pay.
Token scope treated as risk
Credentials described by what they are able to destroy, not by the job they were issued for.
The failure path written first
What a client sees when provisioning fails matters more than what they see when it works.
Upstream kept out of sight
Where a raw error or an unbranded template can name your supplier, the entry says so plainly.
An order of automation given
Create, suspend, terminate first; everything else stays a human decision until volume argues otherwise.
API, closed off in one read
Defined, costed and placed in your provisioning chain, so you can answer a client without opening a manual.
First Steps
From choosing to live
- 1
Read the token scope before the documentation
Look at what the credential you are about to store is permitted to do. Most reseller incidents begin with a token allowed to do considerably more than the job required.
- 2
Automate the boring three first
Create, suspend, terminate. Those three calls remove most of the manual handling in a hosting business, and everything else can stay a human decision for now.
- 3
Write the failure path before the happy path
Decide what the client sees when provisioning fails: a holding message in your brand voice, never a raw upstream error naming somebody else's software.
In the Box
Packed with every plan
- WHM for you, and a cPanel of their own for every client account you create
- Overselling switched on from the first account, so packages reflect real usage
- Packages you build, name and price yourself
- Ready to wire into WHMCS billing when doing it by hand stops being funny
- Softaculous in every account, with one-click installs for WordPress and 400+ applications
- PHP versions picked per site from the panel, without a support ticket
- Daily backups on every client account, with restores you run yourself
- Upgrades applied to the account in place, with no move between plans
- The renewal figure matches the figure you ordered at
- Real people to escalate to at any hour, for you and for your clients
Across the Counter
Things people ask us all the time
Which API does a reseller actually need, WHM or the billing system?
Both, but in one direction. Your billing system is the caller and WHM is the thing being called: an order triggers create-account, a failed payment triggers suspend, a cancellation triggers terminate. You almost never need to write against WHM directly — you need to configure the server module in billing correctly and then leave it alone.
Can a client tell that their account was created by a machine?
Only by how fast it happened, which reflects well on you. Where automation gives itself away is in the details you forgot to brand: a welcome email carrying default templates, a cPanel theme still showing an upstream logo, or a nameserver pair that is not yours. Fix those three and the client sees an in-house platform.
What breaks when I rotate an API token?
Provisioning stops silently, which is the dangerous part. Orders keep taking payment and accounts stop appearing. Rotate the token in the billing system in the same sitting, then place one test order through checkout and watch it complete end to end before you close the laptop.
Does automation still work if I name my own packages?
Yes, and it should. You build packages in WHM with the limits you choose, name them whatever your brand calls them, and map each billing product to one of them. The client never meets the underlying container name, only the package name you invented and printed on your own price list.
Read next
Drupal Hosting
Drupal for the client who arrives with one already built — Composer, Drush and a PHP version set per site.
WordPress Hosting
Where to move a WordPress client when their site outgrows a slot inside your reseller container.
Moving your site to another host? Start with this checklist.
A step-by-step order of work for a move your visitors never spot: which files to copy first, how to carry email across without losing one message, the right moment to repoint DNS, and the two mistakes behind nearly every hour of downtime people ring us about.
Wire the billing in and stop opening WHM.
Overselling from the first account, packages you name and price yourself, and a platform ready to wire into WHMCS billing. Nothing charged at setup on any reseller tier.
See Drupal Hosting plans