WHMCS and billing modules
Automate hosting sales with the ZoPanel modules for WHMCS, Blesta, HostBill and Paymenter: install, connect with an API token, set up products and SSO.
ZoPanel includes ready-made modules for WHMCS, Blesta, HostBill and Paymenter. When a customer pays, the billing system creates the hosting account and its first website. Suspension, termination, upgrades, password changes and single sign-on into the panel then happen automatically. All of the modules use the provisioning API.
Before you start
Every integration needs:
- a ZoPanel Pro license, because API tokens are part of Pro,
- a valid certificate on the panel. Set a panel domain under Settings → General → Panel domain & SSL,
- at least one package in Packages (or one pushed through the API),
- an API token with the permission Provisioning only.
Create the API token
- In ZoPanel, open My account → API tokens and click Create token.
- Give it a name, for example
whmcs. - Set Permissions to Provisioning only (WHMCS, CMS).
- In Allowed from IPs, enter the billing server's IP address.
- Choose an expiry, confirm with your password (and 2FA code), and copy the
zpat_…token. It is shown only once.
A provisioning token can only call /api/v1: packages, accounts, single sign-on and usage. It cannot reach server settings, files or the terminal. If you also restrict panel access under Settings → General → Restrict panel access, add the billing server's IP there as well.
WHMCS
The module supports WHMCS 8.x and 9.x on PHP 8.1 or newer.
| Event in WHMCS | What happens in ZoPanel |
|---|---|
| Order paid | The account and its first website are created |
| Overdue | The account is suspended, and later terminated |
| Upgrade or downgrade | The package is changed |
| Password reset | The password is changed |
| Client area | Login to ZoPanel (single sign-on) and usage |
| Daily cron | Disk and bandwidth usage are updated |
| Server sync | Existing accounts are imported |
Install the module
Copy the modules/servers/zopanel folder into your WHMCS installation at modules/servers/zopanel. Use the release archive zopanel-whmcs-module.zip, or the integrations/whmcs folder of the source.
Add the server
In WHMCS, go to System Settings → Servers → Add New Server:
| Field | Value |
|---|---|
| Module | ZoPanel |
| Hostname | The panel's host name, for example panel.example.com |
| Port | 8888, with Secure checked |
| Access Hash | The zpat_… token |
| Username | Leave empty |
Click Test Connection. The username field accepts skip-tls-verify to turn off certificate checks, but use it only to test a panel that has no valid certificate yet.
Configure the product
Create a product under System Settings → Products/Services. In the Module Settings tab, choose the server group and set:
- Package: a ZoPanel package. The list is loaded from the server.
- PHP version: for the first website (8.4, 8.3, 8.2, 8.1, 7.4 or the server default).
- Create website: create the order's domain as the account's first website.
Choose Automatically setup the product as soon as the first payment is received.
Usernames
ZoPanel usernames are 3–16 characters, lowercase letters and digits, starting with a letter. Names starting with zp are reserved. The module adapts the name WHMCS proposes and saves the final name back on the service. For example, shop-demo.vn becomes shopdemovn.
Single sign-on
The Login to ZoPanel button asks ZoPanel for a one-time sign-in link and redirects the customer to it. The link works once, for 60 seconds. Single sign-on is for customer accounts only. Resellers sign in with their own password and second factor.
Safe retries (idempotency)
Billing systems retry calls that time out. To make retries safe, the module sends an Idempotency-Key header with each account creation, built from the WHMCS service ID and the username (whmcs-create-<service id>-<username>). If WHMCS repeats the call within 24 hours, ZoPanel returns the first answer instead of creating the account again or failing with "username already exists".
Troubleshooting
Every API call is written to System Logs → Module Log, with passwords and tokens masked.
| Error | Cause |
|---|---|
this API token is not allowed from your address |
Add the WHMCS IP to the token |
this token can only use the provisioning API |
Expected for other paths: the module only uses /api/v1 |
unknown package |
The product points to a package that was renamed or deleted |
API tokens require a Pro license |
The ZoPanel server needs a Pro license |
If the account was created but the website was not (for example, the domain is already hosted elsewhere), the order still succeeds. WHMCS logs the reason in its activity log, and the customer can add the website in the panel.
Blesta
The module supports Blesta 5.x (PHP 7.2+) and lives in integrations/blesta.
- Copy
components/modules/zopanelinto Blesta atcomponents/modules/zopanel. - Install it under Settings → Modules → Available → ZoPanel.
- Add a server with the Panel URL (
https://panel.example.com:8888) and the API token. Blesta checks the connection when you save, and stores the token encrypted. - Create a package with the module ZoPanel, then choose the ZoPanel package and the PHP version.
The Control Panel tab shows usage and a Login to ZoPanel button. The welcome email can use {service.zopanel_username}, {service.zopanel_password} and {service.zopanel_domain}.
HostBill
The module lives in integrations/hostbill (PHP 7.2+).
- Copy
includes/modules/Hosting/zopanelinto HostBill atincludes/modules/Hosting/zopanel. - Go to Settings → Apps → Add new App → ZoPanel. Enter the Hostname, the token as Password, and Port
8888, then click Test Connection. - Create a product with that app and choose the Package and the PHP version.
For single sign-on, link to the module's login action (user/class.zopanel_controller.php) from your client area template.
Paymenter
The extension supports Paymenter 1.x (PHP 8.3+) and lives in integrations/paymenter.
- Copy
extensions/Servers/ZoPanelinto Paymenter atextensions/Servers/ZoPanel. If Paymenter does not list it, runcomposer dump-autoload. - Go to Admin → Servers → New and choose ZoPanel. Enter the Panel URL and the API token. Paymenter stores the token encrypted.
- Create a product with that server and pick the ZoPanel package and the PHP version. Customers enter their domain at checkout.
Customers sign in through Open ZoPanel. The welcome email includes the username, password and panel URL.
Resellers with their own billing
A reseller can connect its own WHMCS, Blesta, HostBill or Paymenter with a provisioning token created on the reseller account. The billing system then sees only the reseller's packages and sells only to the reseller's customers, within the reseller's plan limits.