Connect TPP Wholesale
TPP Wholesale is an Australian wholesaler of domains, DNS and hosting. Resellers use it to register and transfer domains, run their customers' DNS, order hosting, SSL and Microsoft 365, and keep track…
Written By Christopher Scaminaci
Last updated About 2 hours ago
TPP Wholesale is an Australian wholesaler of domains, DNS and hosting. Resellers use it to register and transfer domains, run their customers' DNS, order hosting, SSL and Microsoft 365, and keep track of what each service costs and who pays for it at renewal. It is one of the main registrar back ends for Australian MSPs, and a reseller account normally holds many customers, each with their own domains.
Connecting TPP Wholesale to StackJack gives your AI assistant a large family of tpp_ MCP tools. MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Find and inspect domains: list every domain with its expiry date and auto-renew setting, check whether a name is available, read the registry contacts and nameservers, and see what is locked
- Run DNS: read, add, change and remove records, read a domain's DNS history, and point many domains' A records at a new address in one request
- Work across your customers: list and search the customer accounts under your reseller, see each one's saved registrants and billing accounts, and create new ones
- Price and place orders: price a basket before ordering it, place an order, follow its status, and resend a transfer authorisation email
- Control renewals and pricing: see every service line, switch auto-renew, choose who pays at renewal, and set or remove a price lock
- Move domains in and out: check whether a domain can be transferred in, validate a bulk transfer CSV, and approve or cancel transfers away
- Open a customer's hosting: get a single sign-on link into a customer's cPanel
How StackJack authenticates to TPP Wholesale
TPP Wholesale uses an API key and a secret key, a pair you create in The Console. StackJack exchanges the pair for a token that lasts one hour, uses that token for every call, and gets a fresh one on its own when it runs out, so there is nothing to renew by hand. TPP runs one shared service at one address for every reseller, so there is no web address to enter.
Three things about the key are worth knowing before you create it:
- The key belongs to your reseller account, not to a person. Everything StackJack does through it is done as the reseller, and TPP records no individual behind it. One key reaches every customer account under you, and your AI names the customer on each call.
- TPP only accepts the key from addresses registered against it. It answers a wrong key and an unregistered address in exactly the same way, so a refused token request is usually the allow-list rather than a mistyped key.
- StackJack does not publish its outbound addresses. Open a support ticket from the StackJack Portal to get the current addresses for your region, and add every one of them to the key's IP allow-list in The Console. If your organization later moves to a different StackJack region, the addresses change and the list needs updating.
Steps
- Sign in to The Console with your reseller login. API access is available to every reseller account, with no approval and no fee.
- Open Reseller, then API, and generate an API key and a secret key. Copy both before you leave the page and treat the secret like a password.
- Open a support ticket from the StackJack Portal and ask for StackJack's outbound addresses for your region.
- Add every address you were given to the IP allow-list of the key you just created.
- Check the Zone Manager option if you want the DNS tools. See the DNS section below.
- Open TPP Wholesale in StackJack, paste the API key and the secret key, and save. There is no URL to enter. Enter both on every save.
- Run a Test Connection. StackJack asks TPP for one customer record. That proves the key, the secret and the allow-list entry in a single step, and it proves the key is a reseller key: a customer-level key is refused.
Allow-list StackJack on the key before you save. If you save first, the first Test Connection fails with a refusal that looks exactly like a bad key.
What you get
Domains and transfers
The domain tools cover the everyday questions: which domains does this customer hold, when do they expire, are they set to renew, and who is the registrant. You can read a domain's registry contacts and nameservers, check whether a name is free to register, and check whether a domain you do not hold can be transferred in. Changes include locking and unlocking a domain, changing its nameservers, updating its registry contacts, and switching auto-renew for many domains at once.
Transfers away work in two steps: list the pending requests, then approve or cancel them. Approving releases the domain to another registrar and cannot be undone.
DNS records
You can list a domain's records, read its DNS history, add a record, change one, delete one, restore the registrar's default zone, and change an A record's address across many domains at once. Supported record types are A, AAAA, CNAME, MX, NS, TXT, SPF and SRV.
The DNS tools need the Zone Manager option on your TPP Wholesale reseller account. TPP does not publish how it is switched on, so if a DNS call comes back as a refusal about the domain, ask TPP Wholesale to enable it.
Customers and registrants
The customer list, the customer search and customer creation all work from the reseller account. Each customer is identified by a greencode, TPP's account identifier, which the customer tools return. TPP spells it three different ways on different routes; StackJack takes it as one argument and maps it, so you only ever say "greencode".
A registrant is a saved contact profile that a domain order refers to. You can list, create and update them for your own account and for any customer. A reference tool returns TPP's lists of countries and states, which is what the address part of those profiles uses.
Orders and pricing
Your AI can price a basket first, with itemised prices, setup fees and a total, and then place the order. It can list orders by type and status, read the live price list, and resend a transfer authorisation email for a transfer-in order. TPP lists orders one type at a time (registration, renewal, transfer or registrant name change), so a view of everything is several calls.
StackJack never sends card details. Orders are charged to a billing account you already have in TPP, which the billing tools list. TPP's read tool only says whether your reseller account must supply a card security code when it submits orders. TPP does not say whether that also applies to an order charged to a billing account you already hold, so a "required" answer may mean the order has to be placed in TPP's own console, not that it will. If TPP does refuse an order over a card or security code, place that order in TPP's own console.
Service lines, price locks and billing
A service line is one product a customer holds. You can list them, switch a line's auto-renew, and choose whether the reseller or the customer pays at renewal. A price lock fixes a service line's renewal price: you can read it, set it and remove it. The pricing dashboard shows every service line across your customers with its live price, so a review of renewals is one read.
Hosting and files
A cPanel tool returns a single sign-on link into a customer's hosting control panel. Treat the link like a password. Two further tools work with files: one exports orders as a CSV and hands back a temporary download link, and one uploads a CSV of domains to validate before a bulk transfer.
Things to know before you rely on it
Many changes spend money or change a customer's bill
Placing an order charges your billing account straight away, and TPP has no sandbox and no refund through its API. Switching a service line's payer to the customer bills a real customer at retail prices at the next renewal. Setting or removing a price lock changes what a customer is billed. Turning auto-renew off lets a domain or service lapse. Unlocking a domain exposes it to transfer, changing nameservers can take a website and email offline, and approving a transfer away releases the domain to another registrar. Changing a DNS record, or editing a saved registrant profile for yourself or a customer, is marked destructive too: TPP does not say whether the fields you leave out of such an update are kept or cleared, so an update that names only one field may blank the rest.
All of these are marked destructive, along with the other changes that are hard to take back. Whether your AI application asks you to confirm before running one depends on that application's own settings; see Destructive tools and confirmation. Review that setting before you let an assistant place orders.
Two order routes are older, and TPP itself says new work should use the current one. They are available because TPP still serves them; use them only if you know you need them.
Results that are secrets
A domain's EPP transfer code, a cPanel single sign-on link and the payment tokenization key are secrets. Treat them like passwords and do not paste them into tickets or documents. StackJack does not record them. The EPP code is only returned when your AI asks for it by name.
Dates, paging and a few quirks
- Dates are day/month/year. Where a tool takes a date it is
dd/MM/yyyy, for example 31/12/2026, not an ISO date. - Paging differs by tool. The customer list and the pricing dashboard take a page size up to 100. Orders are fixed at 25 per page and cannot be changed. The domain list documents no page size. Service lines and DNS history use a start position and an offset. Transfers away take a page size that StackJack caps at 100.
- The order list's page count is not a page count. It is the number of rows on that page. Work out the number of pages from the total.
- A DNS update gives the record a new ID. After you change a record, use the ID in the answer. The old one no longer exists. TPP does not say whether a field you leave out is kept, so your AI sends every field you want the record to end up with.
- A bulk A-record change is accepted, not finished. TPP answers that it took the request and offers no way to ask how it went. Read a few of the domains' records afterwards to confirm.
- Restoring default DNS discards every custom record on the domain.
One key, every customer
Because one reseller key reaches every customer account, a tool that acts for a customer needs the greencode, and a wrong one acts on the wrong customer. Start from the customer list or search and use the greencode it returns rather than one typed from memory.
Pacing
TPP publishes no rate limit. StackJack paces itself at a conservative number of requests a minute for your organization and waits when TPP asks it to, which usually makes a wide sweep slower rather than failed. The periodic connection check shares that allowance with your AI's own calls. Pacing smooths a burst; it does not guarantee that every call arrives. Retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it; see Retrying a failed or timed-out write.
What StackJack could not confirm with TPP
TPP's published description leaves a few details open, and StackJack has been built from that description without being able to try it against a live reseller account. If any of these turns out differently for you, tell support and it will be corrected:
- The exact address of the token request. StackJack uses the form TPP's integration guide gives, with a trailing slash.
- That a token only works from the address that asked for it. TPP says it is tied to the requesting address, and StackJack treats it that way.
- How the Zone Manager option is switched on for the DNS tools.
- Whether a card security code is still needed when an order is charged to a billing account you already hold in TPP. TPP's read only says whether your reseller account must supply one when it submits orders.
- Whether TPP keeps or clears the fields you leave out of a DNS record update or a saved registrant update. TPP does not say, so StackJack marks both destructive and tells your AI to send every field.
- Whether TPP is happy with the identifier StackJack sends on every request. TPP does not document one either way, so StackJack identifies itself as StackJack/1.0 in case its edge refuses a request that carries none.
Plans and limits
Every read is available on the Free tier, and every change, including placing an order, is on the Pro tier. Business reaches the same tools as Pro and differs by monthly call quota only, because a TPP key is one reseller identity and gives StackJack nothing to attribute a single user's call to.
See the generated TPP Wholesale tool reference for the current inventory, plan assignment, input schemas and destructive-action labels.
Troubleshooting
"TPP Wholesale refused the token request": this is almost always the allow-list, and TPP answers it exactly as it answers a wrong key or secret. Check that every address StackJack gave you is on the key's allow-list, then check the key and secret for a typo or a stray space. If you have not yet asked for the addresses, open a support ticket. StackJack reports this on the connection and does not by itself switch the connection off, so it keeps showing until it is fixed.
"TPP Wholesale accepted the API key and secret key, but then refused the access token it had just issued": the key and the secret are fine, because TPP handed StackJack a token for them, and TPP then refused that token on the very next call. TPP does not say why. The usual cause is the key's IP allow-list, which TPP checks on every call, so confirm every address StackJack gave you is still on the key's allow-list and open a support ticket if you need the current addresses. There is nothing to re-enter, and StackJack does not count this toward switching the connection off.
A call is refused with a message about the domain or the account: TPP gives this answer, a 401 with a body, when the domain is not in your reseller account, or the customer is not yours, or you are using a DNS tool and the Zone Manager option is not enabled on your account. The key was accepted, so do not re-enter it. Check the domain against the domain list, and for DNS ask TPP Wholesale whether Zone Manager is on.
"Only resellers can access this endpoint": the key in StackJack is a customer-level key. The tools here need a reseller key. Generate one under Reseller, then API in The Console.
A customer-payment tool is refused: the payment configuration read is built for a customer's own order page and TPP refuses it for a reseller key. That is the usual answer and not a fault; there is almost never a reason to call it.
"TPP Wholesale is rate-limiting requests": you asked for too much too quickly. It is temporary and StackJack recovers on its own. If it keeps happening, narrow the read or ask for a page at a time.
An order did not go through and mentions a card or security code: TPP may require a card security code for your reseller account, and StackJack never sends one. Ask your AI to check TPP's CVV read, and place that order in TPP's own console.
The old DNS record ID stops working: a DNS update gives the record a new ID. Use the one in the answer, or list the records again.
A bulk A-record change says it was accepted but nothing has changed yet: that answer means TPP took the request, not that it finished. Read the records on a couple of the domains after a few minutes. If they have not changed, repeat the change for those domains.
The default billing account read says it was not found: TPP answers that when no default billing account is set. Set one in The Console, or name a billing account when you place an order.
TPP Wholesale tools
tpp_ · 55 tools · Free 29 · Pro 26
Domains
Transfers
DNS
Customers
Account
Registrants
Billing
Orders
Service lines
Pricing
Hosting
Files
Was this helpful?
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team