Security
TREX OTT Panel Security Recommendations
A reseller panel is a set of credentials that can create and destroy your customer base. These are the habits that keep it yours. None of them take long.
Do these on day one
- Use a password nothing else uses
A panel password that appears in any breach corpus is a matter of time, not luck. Use a generated one and a password manager.
- Lock the panel down to people, not a shared login
If a colleague needs access, give them a sub-account. A shared login has no audit trail and cannot be revoked when someone leaves.
- Treat API credentials as production secrets
They belong in your WHMCS server configuration and nowhere else — not in a chat, not in a screenshot, not in a repository. See the WHMCS guide.
- Never send credentials in response to an unsolicited message
We will never ask you for your panel password or your API key, and we will never send you new ones out of the blue. Anything that does either is an impersonation attempt.
- Check the transactions view regularly
Unexpected credit movement is the earliest sign of a compromised account, usually earlier than a customer complaint.
Protecting customer lines
- Do not post credentials in group chats. A line shared into a public group is consumed by strangers within hours and the connection limit makes it unusable for the customer who paid.
- One line, one customer. Selling a 4-connection line to four unrelated people creates four people who can lock each other out and one account you cannot diagnose.
- Reset a suspected leak immediately. Changing the credentials on a leaked line costs nothing and takes a moment.
- Be suspicious of a line used from many countries at once. That pattern is the clearest indicator of a shared or resold credential.
If you think your panel has been accessed by someone else, change the password first, then tell us on WhatsApp so API keys can be rotated. In that order — do not wait for a reply before changing the password.
Questions
Is two-factor authentication available?
Ask support what is currently available on your account rather than assuming from this page. Until you have confirmed it, a unique generated password is your control.
Can I restrict API access by IP?
Ask sales. If it is available for your account it is worth turning on, because a stolen key becomes far less useful.
A customer is sharing their line. What can I do?
Reset the credentials and tell them why. Repeat offenders cost you support time and connection capacity you paid for.

