Registrar API keys are encrypted before storage.
API keys never leave the backend. Registrar operations happen server-side.
We only request the API permissions needed for the features you use.
When you add registrar API keys, they are encrypted before storage. Decryption happens only when our server needs to call the registrar API for a supported action.
Data moves over HTTPS. Sessions use secure, httpOnly cookies. Your domains stay with your original registrars, and you can revoke API keys from the registrar dashboard.
Connect one registrar, inspect what comes in, and decide whether this belongs in your regular domain workflow.
Free forever plan · No credit card required