One server entry holds one brand's credential
Add your storage account under Configuration → System Settings → Servers → Add New Server, with the module set to this product. Each field has exactly one correct destination:
- Password — your reseller API token. WHMCS encrypts this column.
- Username — your white-label domain, as a bare hostname. This field is required and there is no fallback.
- Hostname — leave blank unless your reseller account uses a non-default API base. Blank means the vendor default.
- Access Hash — leave blank, or use it only for a small JSON object of non-secret overrides. This column is stored in plain text.
- Secure — leave ticked. Port — leave blank.
Never put the token in Access Hash
Your reseller API token is the master credential for every customer under that account. The Access Hash column is plain text, so a credential placed there is readable in every database backup ever taken of your install. This module refuses to use a credential-shaped value found in Access Hash and reports it by name rather than silently using it.
Type your Hostname as a bare hostname too — no scheme and no path. WHMCS passes that field to the module exactly as typed, so a pasted https://… value is rejected rather than silently corrected.
One server group per brand, with exactly one entry in it
Create one server group per brand, put exactly one server entry in each, and point every product and every product's server group setting at exactly that group. Do not leave a storage product on server group zero: WHMCS's own server selector falls back to any active server of this module's type when a product has no group, which is how one brand's customer can end up silently provisioned against a different brand's reseller account. The failure is invisible from the outside — everything still returns success — so this is the one check worth making before you take a real order.
The DNS records, and why they must never be proxied
For each region you intend to offer, create one DNS record per brand in the form s3.<region-code>.<your-white-label-domain>, pointing at that region's endpoint address. Every one of these records must be DNS-only — never proxied. A proxied record answers with the proxy's own certificate for a host it does not actually serve: it looks healthy from the outside, and storage requests never reach the real endpoint. This module verifies each endpoint by the certificate it presents, rather than by whether the name merely resolves, specifically to catch this.
Read the whole Test Connection report before moving on
Press Test Connection on your server entry once your credential and DNS records are in place. The report runs ten checks and shows the outcome of every one of them, not just the first failure, so several problems are visible on a single pass. A line marked WARN does not fail the connection. Do not continue to the next article until the report is clean, or every remaining line is a warning you have read and accepted.