API Credits for Continuous Website Security Monitoring
A practical model for selling domain-scoped scans, API access, reports, and integrations without exposing internal crawler secrets to customers.
A security monitoring product needs a billing model that is easy to understand. ExploitShield uses a domain-scoped API-credit model: one accepted scan consumes a defined number of credits, and the customer can see their balance before launching new scans.
The public API is intentionally separated from internal service secrets. Customers receive bearer API keys with an es_live_ prefix, scoped to their verified domain and allowed actions. The hosted portal, WordPress plugin, WHMCS add-on, and other integrations can all use the same entitlement and credit ledger without giving customers backend HMAC secrets.
This makes the workflow predictable. A customer verifies a domain, buys credits, launches a scan, watches progress, downloads a report, and can call the FastAPI/OpenAPI endpoints from their own systems. The credit ledger records scan usage, report access, and plan state in a way that support and administration panels can audit.
For operators and resellers, the model also makes packaging simpler. WordPress, WHMCS, cPanel, Plesk, and custom SDK integrations can present the same credit balance, scan controls, and report downloads while relying on the central ExploitShield API for enforcement.