# Client — Account

<a id="get-api-v1-client-accounts"></a>
#### `GET /api/v1/client/accounts`

*List reseller sub-accounts*

List hosting accounts owned by the calling reseller with pagination, sorting, status filter, and search.

**Query parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `limit` | integer | no | minimum=1; maximum=200 |
| `offset` | integer | no | minimum=0 |
| `sort` | string | no | pattern=`^(created_at\|username)$` |
| `order` | string | no | pattern=`^(asc\|desc)$` |
| `status` | string | no | — |
| `search` | string | no | — |

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_dict_str__Any__` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X GET \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/client/accounts
```

---

<a id="post-api-v1-client-accounts"></a>
#### `POST /api/v1/client/accounts`

*Create reseller sub-account*

Create a new hosting account owned by the calling reseller. Reseller-scoping fields are forced server-side.

**Body fields:**

| Field | Type | Required | Notes |
|-------|------|----------|-------|
| `auto_ssl` | boolean | no | default `True` |
| `domain` | string | yes | — |
| `email` | string | yes | — |
| `ip_address` | string | no | — |
| `is_reseller` | boolean | no | default `False` |
| `package` | PackageLimits | no | — |
| `password` | string | yes | At least 8 characters and at most 72 bytes when UTF-8 encoded. |
| `php_version` | string | no | — |
| `plan_id` | string | no | — |
| `reseller_acl_plan_id` | string | no | — |
| `reseller_limits` | ResellerLimits | no | — |
| `reseller_owner` | string | no | — |
| `setup_mail_dns` | boolean | no | default `True` |
| `shell_access` | boolean | no | default `False` |
| `username` | string | yes | — |
| `webserver` | string | no | — |

**Request body example:**

```json
{
  "auto_ssl": true,
  "domain": "example.com",
  "email": "user@example.com",
  "ip_address": "string",
  "is_reseller": false,
  "package": {
    "bandwidth_mb": 10240,
    "disk_mb": 1024,
    "email_hourly_limit": 100,
    "max_databases": 1,
    "max_domains": 1,
    "max_email_accounts": 5,
    "max_ftp_accounts": 5,
    "max_node_apps": 0,
    "max_parked_domains": 1,
    "max_python_apps": 0,
    "max_subdomains": 5,
    "node_max_memory_mb": 0,
    "node_workers_limit": 4,
    "python_workers_limit": 4,
    "resource": {
      "cpu_limit": "...",
      "io_read_mbps": "...",
      "io_write_mbps": "...",
      "iops_read": "...",
      "iops_write": "...",
      "memory_mb": "...",
      "nproc": "..."
    }
  },
  "password": "REPLACE_ME",
  "php_version": "string",
  "plan_id": "string",
  "reseller_acl_plan_id": "string",
  "reseller_limits": {
    "max_accounts": 10,
    "max_bandwidth_mb": 102400,
    "max_databases": 10,
    "max_disk_mb": 10240,
    "max_domains": 10,
    "max_email_accounts": 50,
    "max_ftp_accounts": 10,
    "overselling": false
  },
  "reseller_owner": "string",
  "setup_mail_dns": true,
  "shell_access": false,
  "username": "alice",
  "webserver": "string"
}
```

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_dict_str__Any__` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/client/accounts
```

---

<a id="delete-api-v1-client-accounts-username"></a>
#### `DELETE /api/v1/client/accounts/{username}`

*Terminate reseller sub-account*

Permanently terminate a sub-account owned by the calling reseller.

**Path parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `username` | string | yes | — |

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `MessageResponse` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "message": "string",
  "status": "success"
}
```

**cURL example:**

```bash
curl -X DELETE \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/client/accounts/{username}
```

---

<a id="get-api-v1-client-accounts-username"></a>
#### `GET /api/v1/client/accounts/{username}`

*Get reseller sub-account*

Return detailed metadata for a sub-account owned by the calling reseller.

**Path parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `username` | string | yes | — |

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_dict_str__Any__` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X GET \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/client/accounts/{username}
```

---

<a id="put-api-v1-client-accounts-username"></a>
#### `PUT /api/v1/client/accounts/{username}`

*Update reseller sub-account*

Update sub-account fields owned by the calling reseller. Admin-only fields are stripped server-side.

**Path parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `username` | string | yes | — |

**Body fields:**

| Field | Type | Required | Notes |
|-------|------|----------|-------|
| `auto_ssl` | boolean | no | — |
| `domain` | string | no | — |
| `email` | string | no | — |
| `ip_address` | string | no | — |
| `is_reseller` | boolean | no | — |
| `package` | PackageLimits | no | — |
| `php_version` | string | no | — |
| `plan_id` | string | no | — |
| `reseller_acl_plan_id` | string | no | — |
| `reseller_limits` | ResellerLimits | no | — |
| `reseller_owner` | string | no | — |
| `setup_mail_dns` | boolean | no | — |
| `shell_access` | boolean | no | — |
| `webserver` | string | no | — |

**Request body example:**

```json
{
  "auto_ssl": false,
  "domain": "string",
  "email": "string",
  "ip_address": "string",
  "is_reseller": false,
  "package": {
    "bandwidth_mb": 10240,
    "disk_mb": 1024,
    "email_hourly_limit": 100,
    "max_databases": 1,
    "max_domains": 1,
    "max_email_accounts": 5,
    "max_ftp_accounts": 5,
    "max_node_apps": 0,
    "max_parked_domains": 1,
    "max_python_apps": 0,
    "max_subdomains": 5,
    "node_max_memory_mb": 0,
    "node_workers_limit": 4,
    "python_workers_limit": 4,
    "resource": "..."
  },
  "php_version": "string",
  "plan_id": "string",
  "reseller_acl_plan_id": "string",
  "reseller_limits": {
    "max_accounts": 10,
    "max_bandwidth_mb": 102400,
    "max_databases": 10,
    "max_disk_mb": 10240,
    "max_domains": 10,
    "max_email_accounts": 50,
    "max_ftp_accounts": 10,
    "overselling": false
  },
  "reseller_owner": "string",
  "setup_mail_dns": false,
  "shell_access": false,
  "webserver": "string"
}
```

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_dict_str__Any__` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X PUT \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/client/accounts/{username}
```

---

<a id="patch-api-v1-client-accounts-username-password"></a>
#### `PATCH /api/v1/client/accounts/{username}/password`

*Change reseller sub-account password*

Reset the password of a sub-account owned by the calling reseller. Requires session cookie (HMAC forbidden).

**Path parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `username` | string | yes | — |

**Body fields:**

| Field | Type | Required | Notes |
|-------|------|----------|-------|
| `password` | string | yes | At least 8 characters and at most 72 bytes when UTF-8 encoded. |

**Request body example:**

```json
{
  "password": "REPLACE_ME"
}
```

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `MessageResponse` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "message": "string",
  "status": "success"
}
```

**cURL example:**

```bash
curl -X PATCH \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/client/accounts/{username}/password
```

---

<a id="post-api-v1-client-accounts-username-suspend"></a>
#### `POST /api/v1/client/accounts/{username}/suspend`

*Suspend reseller sub-account*

Suspend a sub-account owned by the calling reseller with an optional reason.

**Path parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `username` | string | yes | — |

**Request body example:**

```json
{
  "reason": "string"
}
```

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `MessageResponse` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "message": "string",
  "status": "success"
}
```

**cURL example:**

```bash
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/client/accounts/{username}/suspend
```

---

<a id="post-api-v1-client-accounts-username-unsuspend"></a>
#### `POST /api/v1/client/accounts/{username}/unsuspend`

*Unsuspend reseller sub-account*

Reactivate a previously suspended sub-account owned by the calling reseller.

**Path parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `username` | string | yes | — |

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `MessageResponse` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "message": "string",
  "status": "success"
}
```

**cURL example:**

```bash
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/client/accounts/{username}/unsuspend
```

---

<a id="get-api-v1-client-accounts-username-waf"></a>
#### `GET /api/v1/client/accounts/{username}/waf`

*Sub-account WAF status*

ModSecurity on/off state for a sub-account owned by the calling reseller.

**Path parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `username` | string | yes | — |

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_dict_str__Any__` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X GET \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/client/accounts/{username}/waf
```

---

<a id="put-api-v1-client-accounts-username-waf"></a>
#### `PUT /api/v1/client/accounts/{username}/waf`

*Toggle sub-account WAF*

Turn ModSecurity on or off for a sub-account owned by the calling reseller.

**Path parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `username` | string | yes | — |

**Body fields:**

| Field | Type | Required | Notes |
|-------|------|----------|-------|
| `enabled` | boolean | yes | — |

**Request body example:**

```json
{
  "enabled": false
}
```

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_dict_str__Any__` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X PUT \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/client/accounts/{username}/waf
```

---
