Build with PalestineX
Buy Gmail, Hotmail, Outlook and Edu mailboxes in bulk, then read verification codes from them — through one small, well-documented REST API.
Overview
A small HTTPS REST API. Query strings on GET, JSON on the way back.
Every response uses the same envelope, so your client only has to learn one shape.
{
"success": true,
"code": 200,
"data": {
"balance": 5000,
"currency": "BDT"
},
"message": "Request completed successfully.",
"meta": {
"request_id": "req_9f2c41ab77d0e5b1",
"timestamp": "2026-09-26T09:00:00+06:00"
}
}
{
"success": false,
"code": 409,
"data": null,
"message": "Insufficient stock available. Requested: 5, Available: 2",
"error": {
"code": "OUT_OF_STOCK",
"message": "Insufficient stock available. Requested: 5, Available: 2",
"details": null
},
"meta": {
"request_id": "req_1b7d90ce44aa2f10",
"timestamp": "2026-09-26T09:00:01+06:00"
}
}
Quick start
Three requests, from zero to a verification code.
curl -X GET "https://palestinex.store/api/v1/balance" \
-H "Authorization: Bearer {KEY}" \
-H "Accept: application/json"
curl -X POST "https://palestinex.store/api/v1/order/buy" \
-H "Authorization: Bearer {KEY}" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: order-2026-09-26-0001" \
-d '{"product_key":"hotmails_graph_oauth2","quantity":1}'
curl -X POST "https://palestinex.store/api/v1/code/fetch" \
-H "Authorization: Bearer {KEY}" \
-H "Content-Type: application/json" \
-d '{"email":"user@outlook.com","type":"facebook"}'
What can I buy?
Mail accounts in 4 categories. The
product_key is the ID you send to the purchase endpoint —
copy it exactly as shown.
GET /api/v1/products
. Prices in BDT.
| Category | Product key (the ID) | Price | Qty | Stock |
|---|---|---|---|---|
| outlook Outlook | outlooks_imap Outlook (IMAP Protocol) Clean Outlook.com mailbox configured for automated IMAP fetching and token validation. | 1.00 BDT / unit | 1–5000 | 42 in stock |
| outlook Outlook | outlooks_graph_oauth2 Outlook (Graph API / OAuth2) Enterprise-grade Outlook mailbox with OAuth2 Refresh Token and client ID. Fully compatible with Code Box. | 1.00 BDT / unit | 1–5000 | 1 in stock |
| outlook Outlook | outlooks_fr Outlook FR (European Domain) Special France/EU domain Outlook mailbox (outlook.fr) tailored for localized verifications. | 1.20 BDT / unit | 1–5000 | 1 in stock |
| gmail Gmail | gmail Gmail (Webmail / Live Inbox URL) High quality Google webmail account with direct live web link to receive SMS & OTP codes in real time without login. | 7.00 BDT / unit | 1–5000 | Out of stock |
| edu Edu / Student | login_gmail Edu / Student Mail (Full Login) Full access educational mail with login credentials and recovery mail attached. Eligible for student developer discounts. | 15.00 BDT / unit | 1–5000 | Out of stock |
| hotmail Hotmail | hotmails_imap Hotmail (IMAP Protocol) Fresh Microsoft Hotmail account enabled with IMAP and direct app authentication capabilities. | 1.00 BDT / unit | 1–5000 | Out of stock |
| hotmail Hotmail | hotmails_graph_oauth2 Hotmail (Graph API / OAuth2) Hotmail account loaded with refresh token and client ID for instant headless code verification via OAuth2. | 1.00 BDT / unit | 1–5000 | Out of stock |
How do I…?
Four complete, runnable requests. Set $KEY to your API key and every
one of these returns a real result.
Returns your spendable BDT balance for the account the key belongs to. Read-only and safe to poll.
curl "https://palestinex.store/api/v1/balance" \
-H "Authorization: Bearer $KEY"
Response: data.balance (number, BDT) and
data.currency (always "BDT").
Send a product_key from the catalogue above and a
quantity. The response carries the delivered
credentials in data.items[].
curl -X POST "https://palestinex.store/api/v1/order/buy" \
-H "Authorization: Bearer $KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: order-$(date +%s)-1" \
-d '{"product_key":"outlooks_imap","quantity":1}'
The account arrives in data.items[].email together with
data.items[].details_line (password / refresh token /
inbox link, depending on the product you bought). Persist the
order_code — you need it to re-read the order later.
Add format and the response carries the whole
order already rendered in that shape, so you do not have to
rebuild a file out of thousands of JSON objects:
txt (one account per line),
csv (columns, with the UTF-8 mark Excel needs),
or xlsx (a real workbook, base64-encoded).
Anything else falls back to txt rather than
failing the order.
curl -X POST "https://palestinex.store/api/v1/order/buy" \
-H "Authorization: Bearer $KEY" \
-H "Content-Type: application/json" \
-d '{"product_key":"outlooks_imap","quantity":5000,"format":"xlsx"}'
data.order.delivery holds
filename, mime_type,
download_url and the payload itself: for
txt and csv that is
data as UTF-8 text, and for xlsx it is
data_base64, because a workbook's bytes are not
valid in a JSON string. Your format choice is stored
on the order, so re-reading it later returns the same shape.
GET /api/v1/order/{code}/download returns
the raw file with its real content type, so it can be piped
straight to disk. It needs only your API key — no browser
session — and it is the same
download_url that comes back with every order.
# the format it was bought in
curl "https://palestinex.store/api/v1/order/ORD-ABC123/download" \
-H "Authorization: Bearer $KEY" -o order.txt
# or a different one, if the shape you need has changed
curl "https://palestinex.store/api/v1/order/ORD-ABC123/download?format=xlsx" \
-H "Authorization: Bearer $KEY" -o order.xlsx
# as JSON, for a caller that cannot take a binary body
curl "https://palestinex.store/api/v1/order/ORD-ABC123/download?format=xlsx&as=json" \
-H "Authorization: Bearer $KEY"
Another customer's order returns 404, not
403, so the endpoint cannot be used to discover
which order codes exist.
GET /api/v1/order/{code}?format=csv re-reads
an order in a format other than the one it was bought in, and
&delivery=0 returns the order without the payload.
POST /api/v1/order/bulk takes an array of
orders, so you can buy several product types in a single
atomic call. Either every line item is charged and delivered, or
nothing is charged at all. Each line may name its own
format, so one request can deliver TXT for one
product and Excel for another.
curl -X POST "https://palestinex.store/api/v1/order/bulk" \
-H "Authorization: Bearer $KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: bulk-$(date +%s)-1" \
-d '{
"orders": [
{"product_key":"outlooks_imap","quantity":5000,"format":"txt"},
{"product_key":"outlooks_graph_oauth2","quantity":5,"format":"csv"}
]
}'
quantity may go up to each product's
max_quantity in the table above, and a single bulk
request may contain at most 25 line items. A request for more
than that is rejected whole — nothing is charged.
Pass the email of a mailbox you purchased. The response
gives you the newest code plus which service produced it.
curl -X POST "https://palestinex.store/api/v1/code/fetch" \
-H "Authorization: Bearer $KEY" \
-H "Content-Type: application/json" \
-d '{"email":"the-mailbox-you-bought@outlook.com"}'
You may only read codes for mailboxes your key's account owns; anyone
else gets 403. A mailbox with no code yet returns
404 CODE_NOT_FOUND — poll a few times.
Service health and version
Lightweight health probe for uptime monitoring and CI. Returns no credentials, paths or infrastructure detail.
curl -X GET "https://palestinex.store/api/v1/status"
# Response is JSON: { success, code, data, message, meta }
$ch = curl_init('https://palestinex.store/api/v1/status');
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
]);
$raw = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);
if (empty($json['success'])) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}
print_r($json['data']);
import json, urllib.request
req = urllib.request.Request(
"https://palestinex.store/api/v1/status",
method="GET",
)
with urllib.request.urlopen(req, timeout=30) as r:
data = json.load(r)
if not data["success"]:
raise RuntimeError(data["error"]["code"] + ": " + data["message"])
print(json.dumps(data["data"], indent=2))
const res = await fetch("https://palestinex.store/api/v1/status", {
method: "GET",
});
const json = await res.json();
if (!json.success) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
throw new Error(json.error.code + ": " + json.message);
}
console.log(json.data);
{
"success": true,
"code": 200,
"data": {
"api": "online",
"version": "v1",
"prefix": "/api/v1",
"database": "connected",
"services": {
"products": "available",
"purchases": "available",
"code_fetch": "available"
},
"active_products": 8,
"timestamp": "2026-09-26T09:00:00+06:00"
},
"message": "All PalestineX API services are operational.",
"meta": {
"request_id": "req_9f2c41ab77d0e5b1",
"timestamp": "2026-09-26T09:00:00+06:00"
}
}
List product categories
Every active category with a live product count. Category ids are the accepted values for the `category` filter on /products.
curl -X GET "https://palestinex.store/api/v1/categories"
# Response is JSON: { success, code, data, message, meta }
$ch = curl_init('https://palestinex.store/api/v1/categories');
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
]);
$raw = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);
if (empty($json['success'])) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}
print_r($json['data']);
import json, urllib.request
req = urllib.request.Request(
"https://palestinex.store/api/v1/categories",
method="GET",
)
with urllib.request.urlopen(req, timeout=30) as r:
data = json.load(r)
if not data["success"]:
raise RuntimeError(data["error"]["code"] + ": " + data["message"])
print(json.dumps(data["data"], indent=2))
const res = await fetch("https://palestinex.store/api/v1/categories", {
method: "GET",
});
const json = await res.json();
if (!json.success) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
throw new Error(json.error.code + ": " + json.message);
}
console.log(json.data);
{
"success": true,
"code": 200,
"data": {
"categories": [
{
"id": "gmail",
"name": "Gmail",
"product_count": 1
},
{
"id": "hotmail",
"name": "Hotmail",
"product_count": 2
},
{
"id": "outlook",
"name": "Outlook",
"product_count": 3
},
{
"id": "edu",
"name": "Edu / Student",
"product_count": 1
}
],
"count": 4
},
"message": "Request completed successfully."
}
List products and live availability
Every active product with its current price in BDT, live stock count and quantity limits. `available_stock` is authoritative — it is invalidated the moment a purchase consumes stock.
curl -X GET "https://palestinex.store/api/v1/products"
# Response is JSON: { success, code, data, message, meta }
$ch = curl_init('https://palestinex.store/api/v1/products');
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
]);
$raw = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);
if (empty($json['success'])) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}
print_r($json['data']);
import json, urllib.request
req = urllib.request.Request(
"https://palestinex.store/api/v1/products",
method="GET",
)
with urllib.request.urlopen(req, timeout=30) as r:
data = json.load(r)
if not data["success"]:
raise RuntimeError(data["error"]["code"] + ": " + data["message"])
print(json.dumps(data["data"], indent=2))
const res = await fetch("https://palestinex.store/api/v1/products", {
method: "GET",
});
const json = await res.json();
if (!json.success) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
throw new Error(json.error.code + ": " + json.message);
}
console.log(json.data);
{
"success": true,
"code": 200,
"data": {
"products": [
{
"id": 1,
"key": "gmail",
"title": "Gmail (Webmail / Live Inbox URL)",
"category": "gmail",
"category_name": "Gmail",
"description": "High quality Google webmail account with a direct live inbox URL.",
"price_bdt": 7,
"currency": "BDT",
"available_stock": 20,
"in_stock": true,
"min_quantity": 1,
"max_quantity": 200,
"active": true
}
],
"count": 1,
"category": "gmail"
},
"message": "Request completed successfully."
}
Fetch a single product by key
Same object shape as one entry from /products. `{key}` is the stable product_key, e.g. `hotmails_graph_oauth2`.
curl -X GET "https://palestinex.store/api/v1/products/{key}"
-H "Content-Type: application/json" \
-d '{"key":"hotmails_graph_oauth2"}'
# Response is JSON: { success, code, data, message, meta }
$ch = curl_init('https://palestinex.store/api/v1/products/{key}');
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_POSTFIELDS => json_encode(array (
'key' => 'hotmails_graph_oauth2',
)),
CURLOPT_HTTPHEADER => [
'Content-Type: application/json',
],
CURLOPT_TIMEOUT => 30,
]);
$raw = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);
if (empty($json['success'])) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}
print_r($json['data']);
import json, urllib.request
payload = json.dumps({"key":"hotmails_graph_oauth2"}).encode()
req = urllib.request.Request(
"https://palestinex.store/api/v1/products/{key}",
data=payload,
headers={
"Content-Type": "application/json",
},
method="GET",
)
with urllib.request.urlopen(req, timeout=30) as r:
data = json.load(r)
if not data["success"]:
raise RuntimeError(data["error"]["code"] + ": " + data["message"])
print(json.dumps(data["data"], indent=2))
const res = await fetch("https://palestinex.store/api/v1/products/{key}", {
method: "GET",
headers: {
"Content-Type": "application/json",
},
body: JSON.stringify({"key":"hotmails_graph_oauth2"}),
});
const json = await res.json();
if (!json.success) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
throw new Error(json.error.code + ": " + json.message);
}
console.log(json.data);
{
"success": true,
"code": 200,
"data": {
"product": {
"id": 4,
"key": "hotmails_graph_oauth2",
"title": "Hotmail (Graph API / OAuth2)",
"category": "hotmail",
"category_name": "Hotmail",
"price_bdt": 1,
"currency": "BDT",
"available_stock": 20,
"in_stock": true,
"min_quantity": 1,
"max_quantity": 500,
"active": true
}
},
"message": "Request completed successfully."
}
Balance and account status
Current spendable balance for the key owner, plus role and account state. Also available at /api/v1/user/balance.
curl -X GET "https://palestinex.store/api/v1/balance"
-H "Authorization: Bearer YOUR_API_KEY" \
# Response is JSON: { success, code, data, message, meta }
$ch = curl_init('https://palestinex.store/api/v1/balance');
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
'Authorization: Bearer YOUR_API_KEY',
],
CURLOPT_TIMEOUT => 30,
]);
$raw = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);
if (empty($json['success'])) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}
print_r($json['data']);
import json, urllib.request
req = urllib.request.Request(
"https://palestinex.store/api/v1/balance",
headers={
"Authorization": "Bearer YOUR_API_KEY",
},
method="GET",
)
with urllib.request.urlopen(req, timeout=30) as r:
data = json.load(r)
if not data["success"]:
raise RuntimeError(data["error"]["code"] + ": " + data["message"])
print(json.dumps(data["data"], indent=2))
const res = await fetch("https://palestinex.store/api/v1/balance", {
method: "GET",
headers: {
Authorization: "Bearer YOUR_API_KEY",
},
});
const json = await res.json();
if (!json.success) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
throw new Error(json.error.code + ": " + json.message);
}
console.log(json.data);
{
"success": true,
"code": 200,
"data": {
"user_id": 11,
"username": "apitester",
"fullname": "API Tester",
"email": "apitest@palestinex.local",
"balance": 5000,
"currency": "BDT",
"role": "user",
"status": "active"
},
"message": "Request completed successfully."
}
Inspect the active key (masked)
Never returns the secret. Shows only a masked fingerprint and last-used timestamp so an integration can confirm which key is live.
curl -X GET "https://palestinex.store/api/v1/user/key"
-H "Authorization: Bearer YOUR_API_KEY" \
# Response is JSON: { success, code, data, message, meta }
$ch = curl_init('https://palestinex.store/api/v1/user/key');
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
'Authorization: Bearer YOUR_API_KEY',
],
CURLOPT_TIMEOUT => 30,
]);
$raw = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);
if (empty($json['success'])) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}
print_r($json['data']);
import json, urllib.request
req = urllib.request.Request(
"https://palestinex.store/api/v1/user/key",
headers={
"Authorization": "Bearer YOUR_API_KEY",
},
method="GET",
)
with urllib.request.urlopen(req, timeout=30) as r:
data = json.load(r)
if not data["success"]:
raise RuntimeError(data["error"]["code"] + ": " + data["message"])
print(json.dumps(data["data"], indent=2))
const res = await fetch("https://palestinex.store/api/v1/user/key", {
method: "GET",
headers: {
Authorization: "Bearer YOUR_API_KEY",
},
});
const json = await res.json();
if (!json.success) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
throw new Error(json.error.code + ": " + json.message);
}
console.log(json.data);
{
"success": true,
"code": 200,
"data": {
"has_api_key": true,
"masked_key": "************************************************************3a85",
"last_used_at": "2026-09-26 09:06:09",
"rotate_endpoint": "/api/v1/user/api-key/rotate",
"note": "The full secret is only ever returned once, at rotation time."
},
"message": "Request completed successfully."
}
Rotate the API key
Generates a new key and immediately invalidates the previous one. This is the ONLY response that ever contains the plaintext secret — store it before leaving the response. The previous key stops working at once.
curl -X POST "https://palestinex.store/api/v1/user/api-key/rotate"
-H "Authorization: Bearer YOUR_API_KEY" \
# Response is JSON: { success, code, data, message, meta }
$ch = curl_init('https://palestinex.store/api/v1/user/api-key/rotate');
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_HTTPHEADER => [
'Authorization: Bearer YOUR_API_KEY',
],
CURLOPT_TIMEOUT => 30,
]);
$raw = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);
if (empty($json['success'])) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}
print_r($json['data']);
import json, urllib.request
req = urllib.request.Request(
"https://palestinex.store/api/v1/user/api-key/rotate",
headers={
"Authorization": "Bearer YOUR_API_KEY",
},
method="POST",
)
with urllib.request.urlopen(req, timeout=30) as r:
data = json.load(r)
if not data["success"]:
raise RuntimeError(data["error"]["code"] + ": " + data["message"])
print(json.dumps(data["data"], indent=2))
const res = await fetch("https://palestinex.store/api/v1/user/api-key/rotate", {
method: "POST",
headers: {
Authorization: "Bearer YOUR_API_KEY",
},
});
const json = await res.json();
if (!json.success) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
throw new Error(json.error.code + ": " + json.message);
}
console.log(json.data);
{
"success": true,
"code": 200,
"data": {
"api_key": "1689fd55…3a85",
"last4": "3a85",
"note": "Store this key now. For security it is never displayed again — only the last 4 characters are retained."
},
"message": "API key rotated successfully."
}
Purchase mail accounts
Atomically reserves stock, debits the balance and creates the order inside a single row-locked transaction. Concurrent calls can never oversell or double-charge. Also accepted at POST /api/v1/order. Returns 201 on success.
curl -X POST "https://palestinex.store/api/v1/order/buy"
-H "Idempotency-Key: order-2026-09-26-0001" \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"product_key":"hotmails_graph_oauth2","quantity":1}'
# Response is JSON: { success, code, data, message, meta }
$ch = curl_init('https://palestinex.store/api/v1/order/buy');
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_POSTFIELDS => json_encode(array (
'product_key' => 'hotmails_graph_oauth2',
'quantity' => 1,
)),
CURLOPT_HTTPHEADER => [
'Idempotency-Key: order-2026-09-26-0001',
'Authorization: Bearer YOUR_API_KEY',
'Content-Type: application/json',
],
CURLOPT_TIMEOUT => 30,
]);
$raw = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);
if (empty($json['success'])) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}
print_r($json['data']);
import json, urllib.request
payload = json.dumps({"product_key":"hotmails_graph_oauth2","quantity":1}).encode()
req = urllib.request.Request(
"https://palestinex.store/api/v1/order/buy",
data=payload,
headers={
"Idempotency-Key": "order-2026-09-26-0001",
"Authorization": "Bearer YOUR_API_KEY",
"Content-Type": "application/json",
},
method="POST",
)
with urllib.request.urlopen(req, timeout=30) as r:
data = json.load(r)
if not data["success"]:
raise RuntimeError(data["error"]["code"] + ": " + data["message"])
print(json.dumps(data["data"], indent=2))
const res = await fetch("https://palestinex.store/api/v1/order/buy", {
method: "POST",
headers: {
"Idempotency-Key": "order-2026-09-26-0001",
Authorization: "Bearer YOUR_API_KEY",
"Content-Type": "application/json",
},
body: JSON.stringify({"product_key":"hotmails_graph_oauth2","quantity":1}),
});
const json = await res.json();
if (!json.success) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
throw new Error(json.error.code + ": " + json.message);
}
console.log(json.data);
{
"success": true,
"code": 201,
"data": {
"order": {
"order_code": "ORD-2DA7DC421657",
"product_id": 4,
"product_key": "hotmails_graph_oauth2",
"product_title": "Hotmail (Graph API / OAuth2)",
"quantity": 1,
"unit_price": 1,
"total_cost": 1,
"currency": "BDT",
"status": "completed",
"items": [
{
"email": "apitest123+1@hotmail.com",
"details_line": "apitest123+1@hotmail.com|ApiTest!1|rt-…|cid-…"
}
]
}
},
"message": "Order ORD-2DA7DC421657 completed successfully."
}
Multi-product purchase (all-or-nothing)
Executes up to 25 line items inside one transaction. If any line fails — unknown product, insufficient stock or balance — the entire batch is rolled back and no charge is applied. Returns 201 on success.
curl -X POST "https://palestinex.store/api/v1/order/bulk"
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"orders":[{"product_key":"gmail","quantity":1},{"product_key":"outlooks_imap","quantity":1}]}'
# Response is JSON: { success, code, data, message, meta }
$ch = curl_init('https://palestinex.store/api/v1/order/bulk');
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_POSTFIELDS => json_encode(array (
'orders' =>
array (
0 =>
array (
'product_key' => 'gmail',
'quantity' => 1,
),
1 =>
array (
'product_key' => 'outlooks_imap',
'quantity' => 1,
),
),
)),
CURLOPT_HTTPHEADER => [
'Authorization: Bearer YOUR_API_KEY',
'Content-Type: application/json',
],
CURLOPT_TIMEOUT => 30,
]);
$raw = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);
if (empty($json['success'])) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}
print_r($json['data']);
import json, urllib.request
payload = json.dumps({"orders":[{"product_key":"gmail","quantity":1},{"product_key":"outlooks_imap","quantity":1}]}).encode()
req = urllib.request.Request(
"https://palestinex.store/api/v1/order/bulk",
data=payload,
headers={
"Authorization": "Bearer YOUR_API_KEY",
"Content-Type": "application/json",
},
method="POST",
)
with urllib.request.urlopen(req, timeout=30) as r:
data = json.load(r)
if not data["success"]:
raise RuntimeError(data["error"]["code"] + ": " + data["message"])
print(json.dumps(data["data"], indent=2))
const res = await fetch("https://palestinex.store/api/v1/order/bulk", {
method: "POST",
headers: {
Authorization: "Bearer YOUR_API_KEY",
"Content-Type": "application/json",
},
body: JSON.stringify({"orders":[{"product_key":"gmail","quantity":1},{"product_key":"outlooks_imap","quantity":1}]}),
});
const json = await res.json();
if (!json.success) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
throw new Error(json.error.code + ": " + json.message);
}
console.log(json.data);
{
"success": true,
"code": 201,
"data": {
"orders": [
{
"order_code": "ORD-1C0669A818BF",
"product_key": "gmail",
"quantity": 1,
"unit_price": 7,
"total_cost": 7,
"items": [
{
"email": "apitest123+1@gmail.com",
"details_line": "…"
}
]
}
],
"order_count": 2,
"total_cost": 8,
"currency": "BDT"
},
"message": "Bulk purchase completed successfully."
}
Paginated order history
Your own orders, newest first. Only documented fields are returned — internal columns such as user_id are never exposed. Also available at /api/v1/orders/recent.
curl -X GET "https://palestinex.store/api/v1/order/history"
-H "Authorization: Bearer YOUR_API_KEY" \
# Response is JSON: { success, code, data, message, meta }
$ch = curl_init('https://palestinex.store/api/v1/order/history');
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
'Authorization: Bearer YOUR_API_KEY',
],
CURLOPT_TIMEOUT => 30,
]);
$raw = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);
if (empty($json['success'])) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}
print_r($json['data']);
import json, urllib.request
req = urllib.request.Request(
"https://palestinex.store/api/v1/order/history",
headers={
"Authorization": "Bearer YOUR_API_KEY",
},
method="GET",
)
with urllib.request.urlopen(req, timeout=30) as r:
data = json.load(r)
if not data["success"]:
raise RuntimeError(data["error"]["code"] + ": " + data["message"])
print(json.dumps(data["data"], indent=2))
const res = await fetch("https://palestinex.store/api/v1/order/history", {
method: "GET",
headers: {
Authorization: "Bearer YOUR_API_KEY",
},
});
const json = await res.json();
if (!json.success) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
throw new Error(json.error.code + ": " + json.message);
}
console.log(json.data);
{
"success": true,
"code": 200,
"data": {
"orders": [
{
"order_code": "ORD-2DA7DC421657",
"product_id": 4,
"quantity": 1,
"unit_price": 1,
"total_cost": 1,
"status": "completed",
"created_at": "2026-09-26 09:05:53"
}
],
"pagination": {
"current_page": 1,
"per_page": 20,
"total_records": 1,
"total_pages": 1
}
},
"message": "Request completed successfully."
}
Fetch one order and its delivered accounts
Returns the order plus the delivered credentials. Scoped to the key owner: another user's order code returns 404, never its contents.
curl -X GET "https://palestinex.store/api/v1/order/{code}"
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"code":"ORD-2DA7DC421657"}'
# Response is JSON: { success, code, data, message, meta }
$ch = curl_init('https://palestinex.store/api/v1/order/{code}');
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_POSTFIELDS => json_encode(array (
'code' => 'ORD-2DA7DC421657',
)),
CURLOPT_HTTPHEADER => [
'Authorization: Bearer YOUR_API_KEY',
'Content-Type: application/json',
],
CURLOPT_TIMEOUT => 30,
]);
$raw = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);
if (empty($json['success'])) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}
print_r($json['data']);
import json, urllib.request
payload = json.dumps({"code":"ORD-2DA7DC421657"}).encode()
req = urllib.request.Request(
"https://palestinex.store/api/v1/order/{code}",
data=payload,
headers={
"Authorization": "Bearer YOUR_API_KEY",
"Content-Type": "application/json",
},
method="GET",
)
with urllib.request.urlopen(req, timeout=30) as r:
data = json.load(r)
if not data["success"]:
raise RuntimeError(data["error"]["code"] + ": " + data["message"])
print(json.dumps(data["data"], indent=2))
const res = await fetch("https://palestinex.store/api/v1/order/{code}", {
method: "GET",
headers: {
Authorization: "Bearer YOUR_API_KEY",
"Content-Type": "application/json",
},
body: JSON.stringify({"code":"ORD-2DA7DC421657"}),
});
const json = await res.json();
if (!json.success) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
throw new Error(json.error.code + ": " + json.message);
}
console.log(json.data);
{
"success": true,
"code": 200,
"data": {
"order": {
"order_code": "ORD-2DA7DC421657",
"product_id": 4,
"quantity": 1,
"unit_price": 1,
"total_cost": 1,
"status": "completed",
"created_at": "2026-09-26 09:05:53",
"product_key": "hotmails_graph_oauth2",
"product_title": "Hotmail (Graph API / OAuth2)",
"currency": "BDT"
},
"items": [
{
"email": "apitest123+1@hotmail.com",
"provider": "hotmail",
"details_line": "apitest123+1@hotmail.com|ApiTest!1|rt-…|cid-…"
}
]
},
"message": "Request completed successfully."
}
Fetch the latest verification code for a mailbox
Reads a mailbox you have already purchased and returns the newest code. If you omit refresh_token / inbox_url, PalestineX resolves the credentials from your own purchase history, so you never have to re-send secrets you already bought. Gmail uses the stored inbox URL; Hotmail and Outlook use OAuth2. Also accepted as GET or POST /api/v1/code.
curl -X POST "https://palestinex.store/api/v1/code/fetch"
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"email":"user@outlook.com","type":"facebook"}'
# Response is JSON: { success, code, data, message, meta }
$ch = curl_init('https://palestinex.store/api/v1/code/fetch');
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_POSTFIELDS => json_encode(array (
'email' => 'user@outlook.com',
'type' => 'facebook',
)),
CURLOPT_HTTPHEADER => [
'Authorization: Bearer YOUR_API_KEY',
'Content-Type: application/json',
],
CURLOPT_TIMEOUT => 30,
]);
$raw = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);
if (empty($json['success'])) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}
print_r($json['data']);
import json, urllib.request
payload = json.dumps({"email":"user@outlook.com","type":"facebook"}).encode()
req = urllib.request.Request(
"https://palestinex.store/api/v1/code/fetch",
data=payload,
headers={
"Authorization": "Bearer YOUR_API_KEY",
"Content-Type": "application/json",
},
method="POST",
)
with urllib.request.urlopen(req, timeout=30) as r:
data = json.load(r)
if not data["success"]:
raise RuntimeError(data["error"]["code"] + ": " + data["message"])
print(json.dumps(data["data"], indent=2))
const res = await fetch("https://palestinex.store/api/v1/code/fetch", {
method: "POST",
headers: {
Authorization: "Bearer YOUR_API_KEY",
"Content-Type": "application/json",
},
body: JSON.stringify({"email":"user@outlook.com","type":"facebook"}),
});
const json = await res.json();
if (!json.success) {
// error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
throw new Error(json.error.code + ": " + json.message);
}
console.log(json.data);
{
"success": true,
"code": 200,
"data": {
"email": "user@outlook.com",
"provider": "outlook",
"type": "facebook",
"code": "849210",
"message": "Code retrieved from the mailbox.",
"fetched_at": "2026-09-26T09:07:00+06:00"
},
"message": "Request completed successfully."
}
Errors & status codes
Branch on error.code, not on the message text. Every code below is stable.
const res = await fetch('https://palestinex.store/api/v1/order/buy', {
method: 'POST',
headers: {
Authorization: 'Bearer YOUR_API_KEY',
'Content-Type': 'application/json',
// Retrying with the same key returns the ORIGINAL order instead of
// charging you twice.
'Idempotency-Key': 'order-2026-09-26-0001',
},
body: JSON.stringify({ product_key: 'hotmails_graph_oauth2', quantity: 1 }),
});
const json = await res.json();
if (!json.success) {
switch (json.error.code) {
case 'OUT_OF_STOCK':
// Nothing was charged. Back off and try a smaller quantity.
break;
case 'INSUFFICIENT_BALANCE':
// Top up at /deposit, then retry with the same Idempotency-Key.
break;
case 'RATE_LIMITED':
// error.details.window_seconds tells you how long to wait.
await new Promise(r => setTimeout(r, json.error.details.window_seconds * 1000));
break;
default:
// meta.request_id is safe to quote in a support request.
console.error(json.error.code, json.message, json.meta.request_id);
}
}
-
Stored hashed
Only a SHA-256 hash of your key is kept server-side. PalestineX cannot show it back to you.
-
Shown once
The plaintext appears exactly once, at rotation. After that only the last 4 characters remain.
-
Rotate any time
POST /api/v1/user/api-key/rotateissues a new key and immediately invalidates the old one. -
Suspended accounts
A blocked account gets
403 ACCOUNT_NOT_ACTIVEon every call.
Examples
The same four languages, end to end.
curl -X GET "https://palestinex.store/api/v1/products?category=hotmail" \
-H "Accept: application/json"
curl -X POST "https://palestinex.store/api/v1/order/buy" \
-H "Authorization: Bearer {KEY}" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: order-2026-09-26-0001" \
-d '{"product_key":"hotmails_graph_oauth2","quantity":1}'
$ch = curl_init('https://palestinex.store/api/v1/order/buy');
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_POST => true,
CURLOPT_POSTFIELDS => json_encode([
'product_key' => 'hotmails_graph_oauth2',
'quantity' => 1,
]),
CURLOPT_HTTPHEADER => [
'Authorization: Bearer {KEY}',
'Content-Type: application/json',
'Idempotency-Key: order-2026-09-26-0001',
],
]);
$res = curl_exec($ch);
$json = json_decode($res, true);
curl_close($ch);
if (!empty($json['success'])) {
echo "Order: " . $json['data']['order']['order_code'] . PHP_EOL;
foreach ($json['data']['order']['items'] as $item) {
echo $item['email'] . PHP_EOL;
}
} else {
echo "Error [" . ($json['error']['code'] ?? '?') . "]: " . $json['message'] . PHP_EOL;
}
const res = await fetch('https://palestinex.store/api/v1/order/buy', {
method: 'POST',
headers: {
'Authorization': 'Bearer {KEY}',
'Content-Type': 'application/json',
'Idempotency-Key': 'order-2026-09-26-0001',
},
body: JSON.stringify({
product_key: 'hotmails_graph_oauth2',
quantity: 1,
}),
});
const json = await res.json();
if (!json.success) {
console.error(json.error.code, json.message);
} else {
const order = json.data.order;
console.log('Order', order.order_code, order.items);
}
import json, urllib.request
req = urllib.request.Request(
"https://palestinex.store/api/v1/order/buy",
data=json.dumps({
"product_key": "hotmails_graph_oauth2",
"quantity": 1,
}).encode(),
headers={
"Authorization": "Bearer {KEY}",
"Content-Type": "application/json",
"Idempotency-Key": "order-2026-09-26-0001",
},
method="POST",
)
with urllib.request.urlopen(req) as r:
payload = json.load(r)
if not payload["success"]:
raise RuntimeError(payload["error"]["code"] + ": " + payload["message"])
order = payload["data"]["order"]
print("Order", order["order_code"])
for item in order["items"]:
print(item["email"])
curl -X POST "https://palestinex.store/api/v1/order/bulk" \
-H "Authorization: Bearer {KEY}" \
-H "Content-Type: application/json" \
-d '{"orders":[{"product_key":"gmail","quantity":1},
{"product_key":"outlooks_imap","quantity":1}]}'
curl -X POST "https://palestinex.store/api/v1/code/fetch" \
-H "Authorization: Bearer {KEY}" \
-H "Content-Type: application/json" \
-d '{"email":"user@outlook.com","type":"facebook"}'