WHMCS automation
WHMCS API Integration and Automation
I connect WHMCS to the tools around it, such as a CRM, Slack or Telegram alerts, SMS, accounting, fraud checks, control panels and DNS. I pick the external API, localAPI() or a hook for each job, use least-privilege credentials, and test in a staging copy before live billing is touched.
By Shahid Malla, WHMCS developer and hosting infrastructure engineer · Updated
Which WHMCS automation mechanism fits which job?
Use a hook to react to an event inside WHMCS, localAPI() to act on WHMCS data from code that already runs inside it, and the external API when another system must drive WHMCS from outside. Most projects use two of the three. This table is how I choose.
| Automation goal | Mechanism | Example |
|---|---|---|
| New clients into a CRM | Hook: ClientAdd | Create or update the CRM contact with a five-second timeout, and queue a retry if the CRM is down. |
| Slack or Telegram alerts | Hooks: InvoicePaid, TicketOpen | Post "Invoice #1042 paid" to a private channel using a bot token stored outside the code. |
| SMS for late payments | Hook: DailyCronJob plus localAPI GetInvoices | Text clients whose invoice is three days overdue, once, then record that it was sent. |
| Accounting sync | Hook: InvoicePaid, or a nightly external job using GetTransactions | Post each payment to the accounting package and store its external ID so a repeat never double-books. |
| Fraud checks | A fraud module, or hook AfterShoppingCartCheckout | Send IP, email and country to a risk service and hold high scores for manual review instead of cancelling. |
| Panel or DNS provisioning | Server module for the account, hook AfterModuleCreate for follow-up steps | After the hosting account exists, add DNS records or a monitoring check through the provider's API. |
| Signups from another site | External API: AddClient, AddOrder | A marketing-site form creates the client and order, and WHMCS sends its normal signup email. |
| Custom reports | External API with paging, or an admin addon | A nightly CSV of recurring revenue, churn and failed payments, built from GetInvoices. |
| Renewal and dunning recovery | Hook: DailyCronJob plus localAPI SendEmail | Extra reminders before and after the due date with a pay link, stopping as soon as the invoice is paid. |
| Usage billing | Hook: DailyCronJob plus localAPI AddBillableItem | Read usage from the provider and add a billable item that the next invoice run collects. |
How does the external WHMCS API work?
The external API is a single HTTPS endpoint, includes/api.php, that takes a POST with an action name and returns the result. Access is controlled by API credentials: an identifier and secret pair tied to an API role that lists exactly which actions the holder may call.
- Every request carries the identifier, the secret, the action and
responsetype=json. - The reply has a
resultof success or error. Business problems such as "client not found" also come back as errors, so the caller must handle both kinds. - List calls such as
GetInvoicestakelimitstartandlimitnum. I page through results instead of pulling thousands of rows in one request. - The credential can be limited to the calling server's IP address, so a leaked secret is useless from anywhere else.
Older username and password authentication still exists in some versions. I do not use it, because it ties an integration to a real admin login.
When should I use localAPI() instead?
Use localAPI() whenever the code already runs inside WHMCS, because it runs the same commands in-process, with no HTTP request and no secret to store. A hook that adds a billable item calls localAPI('AddBillableItem', $values) and gets an array back. API roles exist to limit external credentials, and code inside WHMCS is trusted by design. That is why I keep in-process code small and review it as carefully as an admin account.
How do WHMCS hooks work, and what goes wrong with them?
A hook is a function that WHMCS runs at a defined moment. You register it with add_hook() in a PHP file inside includes/hooks/, and WHMCS loads that file on every request. Events include InvoicePaid, ClientAdd, AfterModuleCreate and DailyCronJob, and each passes a $vars array with the relevant IDs. Hooks survive upgrades because they live outside the core files. These are the failures I design against.
- Slow calls. An unresponsive CRM inside
ClientAddcan freeze signup. I set short timeouts and, for anything non-urgent, write to a queue table and send it from the cron. - Uncaught errors. I wrap outbound work in try/catch and record failures with
logActivity(), so a broken third party cannot break checkout or the cron run. - Duplicates. Events can repeat. I store a marker for each action so a client never gets two SMS messages or two accounting entries.
- Loops. A hook that updates an invoice through localAPI can trigger itself. I guard against it.
How do I keep a WHMCS API integration secure?
Give every integration its own API credential and a narrow API role, and never reuse an admin login. A signup form needs the ability to add a client and an order. It does not need to read every client or delete anything.
- One credential per integration, so revoking one breaks nothing else.
- HTTPS only, with an IP allow-list wherever the caller has a fixed address.
- Secrets in environment variables or a config file outside the web root, never in hook code or a repository.
- Signature checks on inbound webhooks before any action is taken.
- Logs through
logActivity()andlogModuleCall(), with secrets and card data stripped, plus a periodic look at the API log for unknown callers. - Credentials deleted when the integration is retired.
If you are unsure what your existing credentials can do, the WHMCS security audit reviews every one of them.
How do you test a WHMCS integration before it touches live billing?
I test in a staging copy of your WHMCS with its own database, outgoing email redirected to a test address, gateways in test mode and the other service in sandbox mode where one exists. Then I work through four checks.
- Trigger each event with test clients and orders, and confirm the hook fires exactly once.
- Cause failures on purpose, such as a wrong secret, a timeout and a 500 response, and confirm WHMCS keeps working.
- Run the daily cron through a full cycle, so
DailyCronJobcode is exercised. - Go live in a quiet hour and read the logs after the first real invoice and payment.
Which integration shortcuts do I refuse?
I do not edit WHMCS core files, because those edits vanish on upgrade. I do not copy card numbers out of WHMCS into another system, since card data stays with the gateway. I do not scrape the admin screens when an API command or hook exists, and I do not work on unlicensed or nulled WHMCS copies. Not every action is exposed by the API. When one is missing I say so, and the answer is usually a small addon module rather than writing straight into WHMCS tables.
How much does a WHMCS API integration cost?
I quote a fixed price within one business day of the scoping call, or work hourly at $55 to $65 per hour. The cost depends on how many systems are connected, how clean the other side's API is, how much error handling the volume needs, and whether an admin screen is required. For a full admin feature see custom module development, for payment flows see payment gateway integration, and for keeping integrations working after upgrades see support and maintenance. The official WHMCS developer documentation lists every API command and hook point.
Who this is for
- Hosting companies that want orders, payments and provisioning to reach other systems without manual copying
- Owners who want billing events to trigger CRM, accounting, chat or SMS actions
- Teams whose marketing site or app must create WHMCS clients and orders
- Businesses running a pile of scripts and edited core files that should become supported hooks
What is included
- A written plan listing the events, the data fields and what happens when the other system is down
- Hooks, an addon module or a small external connector built on supported WHMCS interfaces
- One API credential per integration, with a narrow API role and an IP allow-list
- Short timeouts, duplicate protection and error handling that never blocks checkout
- Logging to the activity and module logs, with secrets and card data left out
- Staging test results and a watched go-live
- Written handover notes and two weeks of post-delivery support
How the work runs
-
1
Scope
On a free call of about 30 minutes we list what should happen automatically, which systems are involved and what must never happen, such as a duplicate SMS or an unpaid order being provisioned.
-
2
Design
I choose the mechanism for each job, define the data mapping and agree the failure behavior before writing code. You get a short written plan and a quote within one business day.
-
3
Build in staging
I build against a staging copy of your WHMCS, with gateways in test mode and email redirected, so no real client is contacted.
-
4
Break it on purpose
I test wrong credentials, timeouts and error responses from the other system, and confirm WHMCS carries on and the failure is logged.
-
5
Go live and watch
I deploy in a quiet hour, watch the logs through the first real invoice and payment, then hand over the notes.
Frequently asked questions
What is the difference between the WHMCS API and localAPI()?
The external API is an HTTPS endpoint, includes/api.php, used by systems outside WHMCS and protected by API credentials and roles. localAPI() runs the same commands from PHP code already inside WHMCS, such as a hook or module, with no network request. I use the external API for other servers and localAPI() for code that runs inside WHMCS, such as hooks and modules.
Can WHMCS send notifications to Slack, Telegram or SMS?
Yes. A hook on an event such as InvoicePaid, TicketOpen or a daily cron run calls the chat or SMS provider's API with a short timeout. The message text, the recipients and the retry behavior are agreed up front. Tokens are kept outside the code, and a failed send is logged instead of blocking the invoice.
Is it safe to give an integration access to my WHMCS API?
It is safe when the access is narrow. I create a separate API credential for each integration, attach an API role that allows only the actions it needs, and restrict the credential to the calling server's IP address. An integration never uses a staff member's password, and unused credentials should be deleted when a project ends.
Will an integration break when I upgrade WHMCS?
Hooks and API commands are the supported interface, so they survive upgrades far better than edited core files. They are not immune. A release can deprecate a command or change a field, so I read the release notes and run the integration against a staging copy of the new version before you upgrade production.
How long does a WHMCS integration take?
A single event-to-service job, like pushing new clients to a CRM, typically takes three to five working days including testing. Several systems, two-way sync or an admin screen can take ten days or more. You get a firm date once the scoping call has shown what is involved.
What access do you need to build an integration?
An admin login with permission to create API credentials, SSH or SFTP access to a staging copy, and a sandbox or test account on the other service. I ask for production access only at go-live.
Can you connect WHMCS to a system that has no API?
Sometimes. If the other system can import a CSV, accept email, read a database view or call a webhook, I can build a scheduled export or a small middleware service. I tell you early when this makes the result fragile, because a missing API usually means more manual checking later.
Related services
-
WHMCS Custom Module Development
I build custom WHMCS modules for provisioning, addon, gateway and registrar jobs. Specced in writing, tested i...
-
WHMCS Payment Gateway Integration
I build and fix WHMCS payment gateway modules for Stripe, PayPal, Razorpay, crypto and regional gateways, with...
-
WHMCS Security Audit and Hack Recovery
I review WHMCS for exposed admin areas, weak access, file and PHP settings, missed security releases and leake...
-
WHMCS Support and Maintenance
Ongoing WHMCS care, hourly or monthly: staged upgrades, PHP changes, cron and backup checks, module updates an...
Ready to talk about your project?
Send the details and I reply within one business day with questions, an estimate and a plan.