← บทความทั้งหมด

บทความนี้มีเฉพาะภาษาอังกฤษในตอนนี้

Connecting your registrar accounts safely

เผยแพร่ 28 กันยายน 2569

drop/expired never holds your money or your domains. When you order, the order is placed with the registrar, auction house or drop-catcher in your own account there. To do that, you connect those accounts with API keys.

What a key allows

An API key lets us act for you at that provider: check prices, place backorders and bids, buy or register names. The key is sent once, stored encrypted, and never shown again, not even to you. You see only its masked end (for example ••••1234).

Good habits

  • Create a key for drop/expired only. Most providers allow several keys; a dedicated key can be revoked without breaking anything else.
  • Use the provider’s restrictions where they exist: IP allow-lists, read / write scopes, spending caps.
  • Set your spending limits in drop/expired too: per order and per day. Every order, including the ones the agent prepares and the ones placed through the API or MCP, is checked against them before you confirm.
  • Test the connection after connecting. If a key stops working, the account shows “Key rejected” and the orders through it fail safely until you update the key.

Teams

In a team, only the owner and admins connect team accounts. Members order through them within their own limits and never see the keys. Viewers can look but cannot order.

Disconnecting

Disconnect an account at any time from Connected accounts. Orders already placed stay with the provider; nothing new goes through that account. Revoke the key at the provider as well if you no longer need it.

Every provider publishes where to create keys; our docs have a short page per provider.