# Connect Openprovider

> Connect Openprovider to manage your domains, your DNS and your SSL certificates from InfraNest — one connection covers all three.

Source: https://infranest.io/docs/connect-openprovider
Last updated: 2026-09-18

---

Connect your Openprovider account to InfraNest to manage your domains, DNS, and SSL certificates from one place — this article is for anyone who registers or manages domains through Openprovider.

## Overview

- One connection covers **Domains**, **DNS**, and **Certificates** — you don't need to connect each separately.
- Openprovider is a wholesale registrar built for managing a large portfolio, not just a handful of domains. If you manage domains for clients, InfraNest imports your whole portfolio — even thousands of domains — a page at a time.
- Because Openprovider accounts are prepaid, keeping an eye on your balance matters more here than with other registrars.

> [!NOTE]
> Before you connect, you need a dedicated Openprovider user set up for API access, with two-factor authentication turned off for that user and InfraNest's IP address allowed. See **Set up Openprovider API access** first — it only takes a few minutes, and it determines whether the connection will work at all.

## Connect Openprovider

1. Go to **Integrations** and open **Openprovider**.
2. Give the connection an **Account label** so you can recognise it later. This is **Optional**, but worth doing if you have more than one Openprovider account.
3. Enter the **API username** and password of the user you created for InfraNest — not your own personal login.
4. Select **Connect**.



InfraNest checks the credentials and starts importing your domains. If you have a large portfolio, this can take a few minutes.

<!-- docs-screenshots:start -->

![Connect Openprovider](/media/9c10d8ea-71ba-475a-b6ef-5a845b7f5e68)

<!-- docs-screenshots:end -->

## What you can do once it's connected

**Domains**
- See your whole portfolio with renewal dates, and get told before anything expires
- Check availability and pricing across every extension Openprovider sells
- Register, transfer in, renew, and restore a domain from quarantine
- Change nameservers, DNSSEC, transfer lock, WHOIS privacy and auto-renew
- Fetch the EPP (auth) code when you're moving a domain away

**DNS**
- Manage zones and records for any domain, wherever you registered it
- Create and delete zones from InfraNest

**Certificates**
- The SSL certificates on your Openprovider account appear in your certificate inventory, with their expiry dates, alongside certificates from everywhere else

## Check your account balance

Openprovider is prepaid — registrations and renewals are paid for out of your account balance. InfraNest shows that balance on the connection's page and warns you when it's running low.

> [!WARNING]
> An empty balance doesn't just fail one registration — it stops auto-renew across every domain you manage, including your clients'. Keep enough balance topped up to cover upcoming renewals.

## Tips

- **Renewal dates.** Openprovider tracks a renewal date that can differ from the expiry date shown at the registry. InfraNest uses the renewal date, because that's the one you actually need to act on.
- **Changing a domain's owner** is a paid "trade" at Openprovider with its own confirmation process, so InfraNest doesn't offer it as a normal contact edit. Do this directly in the Openprovider panel.
- **Certificate files can't be downloaded** from InfraNest. Openprovider never holds the private key — you created the CSR, so you have it — and we don't store keys we didn't generate.
- **DNS records without IDs.** Openprovider identifies a record by its name, type, and value. Two records that differ only in TTL look identical to InfraNest, so they'll appear as a single row.

## Troubleshooting

If InfraNest reports **"Authentication/Authorization Failed"**, the password is the least likely cause. Check the troubleshooting list at the end of **Set up Openprovider API access** — the problem is almost always API access being switched off, two-factor authentication still enabled on the user, or the IP whitelist not including InfraNest's address.
