PalestineX API v1 Back to home
API v1 · live documentation

Build with PalestineX

Buy Gmail, Hotmail, Outlook and Edu mailboxes in bulk, then read verification codes from them — through one small, well-documented REST API.

# any order can be fetched as a real file
curl "https://palestinex.store/api/v1/order/<code>/download?format=xlsx" \
  -H "Authorization: Bearer $KEY" -o "order.xlsx"
01
Introduction

Overview

A small HTTPS REST API. Query strings on GET, JSON on the way back. Every response uses the same envelope, so your client only has to learn one shape.

https://palestinex.store /api/v1
A success response
200 OK Success
{
    "success": true,
    "code": 200,
    "data": {
        "balance": 5000,
        "currency": "BDT"
    },
    "message": "Request completed successfully.",
    "meta": {
        "request_id": "req_9f2c41ab77d0e5b1",
        "timestamp": "2026-09-26T09:00:00+06:00"
    }
}
An error response
409 Conflict Out of stock
{
    "success": false,
    "code": 409,
    "data": null,
    "message": "Insufficient stock available. Requested: 5, Available: 2",
    "error": {
        "code": "OUT_OF_STOCK",
        "message": "Insufficient stock available. Requested: 5, Available: 2",
        "details": null
    },
    "meta": {
        "request_id": "req_1b7d90ce44aa2f10",
        "timestamp": "2026-09-26T09:00:01+06:00"
    }
}
02
Get going

Quick start

Three requests, from zero to a verification code.

All three steps in cURL
cURL
curl -X GET "https://palestinex.store/api/v1/balance" \
  -H "Authorization: Bearer {KEY}" \
  -H "Accept: application/json"
curl -X POST "https://palestinex.store/api/v1/order/buy" \
  -H "Authorization: Bearer {KEY}" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: order-2026-09-26-0001" \
  -d '{"product_key":"hotmails_graph_oauth2","quantity":1}'
curl -X POST "https://palestinex.store/api/v1/code/fetch" \
  -H "Authorization: Bearer {KEY}" \
  -H "Content-Type: application/json" \
  -d '{"email":"user@outlook.com","type":"facebook"}'
03
Catalogue

What can I buy?

Mail accounts in 4 categories. The product_key is the ID you send to the purchase endpoint — copy it exactly as shown.

https://palestinex.store /api/v1/products
All products
Live from the database — also readable without a key at GET /api/v1/products . Prices in BDT.
Category Product key (the ID) Price Qty Stock
outlook Outlook outlooks_imap Outlook (IMAP Protocol) Clean Outlook.com mailbox configured for automated IMAP fetching and token validation. 1.00 BDT / unit 1–5000 42 in stock
outlook Outlook outlooks_graph_oauth2 Outlook (Graph API / OAuth2) Enterprise-grade Outlook mailbox with OAuth2 Refresh Token and client ID. Fully compatible with Code Box. 1.00 BDT / unit 1–5000 1 in stock
outlook Outlook outlooks_fr Outlook FR (European Domain) Special France/EU domain Outlook mailbox (outlook.fr) tailored for localized verifications. 1.20 BDT / unit 1–5000 1 in stock
gmail Gmail gmail Gmail (Webmail / Live Inbox URL) High quality Google webmail account with direct live web link to receive SMS & OTP codes in real time without login. 7.00 BDT / unit 1–5000 Out of stock
edu Edu / Student login_gmail Edu / Student Mail (Full Login) Full access educational mail with login credentials and recovery mail attached. Eligible for student developer discounts. 15.00 BDT / unit 1–5000 Out of stock
hotmail Hotmail hotmails_imap Hotmail (IMAP Protocol) Fresh Microsoft Hotmail account enabled with IMAP and direct app authentication capabilities. 1.00 BDT / unit 1–5000 Out of stock
hotmail Hotmail hotmails_graph_oauth2 Hotmail (Graph API / OAuth2) Hotmail account loaded with refresh token and client ID for instant headless code verification via OAuth2. 1.00 BDT / unit 1–5000 Out of stock
04
Copy & paste

How do I…?

Four complete, runnable requests. Set $KEY to your API key and every one of these returns a real result.

1 Check my balance

Returns your spendable BDT balance for the account the key belongs to. Read-only and safe to poll.

cURL
curl "https://palestinex.store/api/v1/balance" \
  -H "Authorization: Bearer $KEY"

Response: data.balance (number, BDT) and data.currency (always "BDT").

2 Buy one mailbox

Send a product_key from the catalogue above and a quantity. The response carries the delivered credentials in data.items[].

cURL
curl -X POST "https://palestinex.store/api/v1/order/buy" \
  -H "Authorization: Bearer $KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: order-$(date +%s)-1" \
  -d '{"product_key":"outlooks_imap","quantity":1}'

The account arrives in data.items[].email together with data.items[].details_line (password / refresh token / inbox link, depending on the product you bought). Persist the order_code — you need it to re-read the order later.

2b Choose a delivery format

Add format and the response carries the whole order already rendered in that shape, so you do not have to rebuild a file out of thousands of JSON objects: txt (one account per line), csv (columns, with the UTF-8 mark Excel needs), or xlsx (a real workbook, base64-encoded). Anything else falls back to txt rather than failing the order.

cURL
curl -X POST "https://palestinex.store/api/v1/order/buy" \
  -H "Authorization: Bearer $KEY" \
  -H "Content-Type: application/json" \
  -d '{"product_key":"outlooks_imap","quantity":5000,"format":"xlsx"}'

data.order.delivery holds filename, mime_type, download_url and the payload itself: for txt and csv that is data as UTF-8 text, and for xlsx it is data_base64, because a workbook's bytes are not valid in a JSON string. Your format choice is stored on the order, so re-reading it later returns the same shape.

2c Re-download a file

GET /api/v1/order/{code}/download returns the raw file with its real content type, so it can be piped straight to disk. It needs only your API key — no browser session — and it is the same download_url that comes back with every order.

cURL
# the format it was bought in
curl "https://palestinex.store/api/v1/order/ORD-ABC123/download" \
  -H "Authorization: Bearer $KEY" -o order.txt

# or a different one, if the shape you need has changed
curl "https://palestinex.store/api/v1/order/ORD-ABC123/download?format=xlsx" \
  -H "Authorization: Bearer $KEY" -o order.xlsx

# as JSON, for a caller that cannot take a binary body
curl "https://palestinex.store/api/v1/order/ORD-ABC123/download?format=xlsx&as=json" \
  -H "Authorization: Bearer $KEY"

Another customer's order returns 404, not 403, so the endpoint cannot be used to discover which order codes exist. GET /api/v1/order/{code}?format=csv re-reads an order in a format other than the one it was bought in, and &delivery=0 returns the order without the payload.

3 Buy in bulk

POST /api/v1/order/bulk takes an array of orders, so you can buy several product types in a single atomic call. Either every line item is charged and delivered, or nothing is charged at all. Each line may name its own format, so one request can deliver TXT for one product and Excel for another.

cURL
curl -X POST "https://palestinex.store/api/v1/order/bulk" \
  -H "Authorization: Bearer $KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: bulk-$(date +%s)-1" \
  -d '{
    "orders": [
      {"product_key":"outlooks_imap","quantity":5000,"format":"txt"},
      {"product_key":"outlooks_graph_oauth2","quantity":5,"format":"csv"}
    ]
  }'

quantity may go up to each product's max_quantity in the table above, and a single bulk request may contain at most 25 line items. A request for more than that is rejected whole — nothing is charged.

4 Read a verification code

Pass the email of a mailbox you purchased. The response gives you the newest code plus which service produced it.

cURL
curl -X POST "https://palestinex.store/api/v1/code/fetch" \
  -H "Authorization: Bearer $KEY" \
  -H "Content-Type: application/json" \
  -d '{"email":"the-mailbox-you-bought@outlook.com"}'

You may only read codes for mailboxes your key's account owns; anyone else gets 403. A mailbox with no code yet returns 404 CODE_NOT_FOUND — poll a few times.

05
GET Overview Public

Service health and version

Lightweight health probe for uptime monitoring and CI. Returns no credentials, paths or infrastructure detail.

https://palestinex.store /api/v1/status
Request
cURL
curl -X GET "https://palestinex.store/api/v1/status"

# Response is JSON: { success, code, data, message, meta }
PHP
$ch = curl_init('https://palestinex.store/api/v1/status');
curl_setopt_array($ch, [
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_TIMEOUT        => 30,
]);

$raw  = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);

if (empty($json['success'])) {
    // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
    exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}

print_r($json['data']);
Python
import json, urllib.request

req = urllib.request.Request(
    "https://palestinex.store/api/v1/status",
    method="GET",
)

with urllib.request.urlopen(req, timeout=30) as r:
    data = json.load(r)

if not data["success"]:
    raise RuntimeError(data["error"]["code"] + ": " + data["message"])

print(json.dumps(data["data"], indent=2))
JavaScript
const res = await fetch("https://palestinex.store/api/v1/status", {
  method: "GET",
});

const json = await res.json();

if (!json.success) {
  // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
  throw new Error(json.error.code + ": " + json.message);
}

console.log(json.data);
Response (200)
200 OK All PalestineX API services are operational.
{
    "success": true,
    "code": 200,
    "data": {
        "api": "online",
        "version": "v1",
        "prefix": "/api/v1",
        "database": "connected",
        "services": {
            "products": "available",
            "purchases": "available",
            "code_fetch": "available"
        },
        "active_products": 8,
        "timestamp": "2026-09-26T09:00:00+06:00"
    },
    "message": "All PalestineX API services are operational.",
    "meta": {
        "request_id": "req_9f2c41ab77d0e5b1",
        "timestamp": "2026-09-26T09:00:00+06:00"
    }
}
06
GET Products Public

List product categories

Every active category with a live product count. Category ids are the accepted values for the `category` filter on /products.

https://palestinex.store /api/v1/categories
Request
cURL
curl -X GET "https://palestinex.store/api/v1/categories"

# Response is JSON: { success, code, data, message, meta }
PHP
$ch = curl_init('https://palestinex.store/api/v1/categories');
curl_setopt_array($ch, [
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_TIMEOUT        => 30,
]);

$raw  = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);

if (empty($json['success'])) {
    // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
    exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}

print_r($json['data']);
Python
import json, urllib.request

req = urllib.request.Request(
    "https://palestinex.store/api/v1/categories",
    method="GET",
)

with urllib.request.urlopen(req, timeout=30) as r:
    data = json.load(r)

if not data["success"]:
    raise RuntimeError(data["error"]["code"] + ": " + data["message"])

print(json.dumps(data["data"], indent=2))
JavaScript
const res = await fetch("https://palestinex.store/api/v1/categories", {
  method: "GET",
});

const json = await res.json();

if (!json.success) {
  // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
  throw new Error(json.error.code + ": " + json.message);
}

console.log(json.data);
Response (200)
200 OK Request completed successfully.
{
    "success": true,
    "code": 200,
    "data": {
        "categories": [
            {
                "id": "gmail",
                "name": "Gmail",
                "product_count": 1
            },
            {
                "id": "hotmail",
                "name": "Hotmail",
                "product_count": 2
            },
            {
                "id": "outlook",
                "name": "Outlook",
                "product_count": 3
            },
            {
                "id": "edu",
                "name": "Edu / Student",
                "product_count": 1
            }
        ],
        "count": 4
    },
    "message": "Request completed successfully."
}
07
GET Products Public

List products and live availability

Every active product with its current price in BDT, live stock count and quantity limits. `available_stock` is authoritative — it is invalidated the moment a purchase consumes stock.

https://palestinex.store /api/v1/products
Request
cURL
curl -X GET "https://palestinex.store/api/v1/products"

# Response is JSON: { success, code, data, message, meta }
PHP
$ch = curl_init('https://palestinex.store/api/v1/products');
curl_setopt_array($ch, [
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_TIMEOUT        => 30,
]);

$raw  = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);

if (empty($json['success'])) {
    // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
    exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}

print_r($json['data']);
Python
import json, urllib.request

req = urllib.request.Request(
    "https://palestinex.store/api/v1/products",
    method="GET",
)

with urllib.request.urlopen(req, timeout=30) as r:
    data = json.load(r)

if not data["success"]:
    raise RuntimeError(data["error"]["code"] + ": " + data["message"])

print(json.dumps(data["data"], indent=2))
JavaScript
const res = await fetch("https://palestinex.store/api/v1/products", {
  method: "GET",
});

const json = await res.json();

if (!json.success) {
  // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
  throw new Error(json.error.code + ": " + json.message);
}

console.log(json.data);
Response (200)
200 OK Request completed successfully.
{
    "success": true,
    "code": 200,
    "data": {
        "products": [
            {
                "id": 1,
                "key": "gmail",
                "title": "Gmail (Webmail / Live Inbox URL)",
                "category": "gmail",
                "category_name": "Gmail",
                "description": "High quality Google webmail account with a direct live inbox URL.",
                "price_bdt": 7,
                "currency": "BDT",
                "available_stock": 20,
                "in_stock": true,
                "min_quantity": 1,
                "max_quantity": 200,
                "active": true
            }
        ],
        "count": 1,
        "category": "gmail"
    },
    "message": "Request completed successfully."
}
08
GET Products Public

Fetch a single product by key

Same object shape as one entry from /products. `{key}` is the stable product_key, e.g. `hotmails_graph_oauth2`.

https://palestinex.store /api/v1/products/{key}
Request
cURL
curl -X GET "https://palestinex.store/api/v1/products/{key}"
  -H "Content-Type: application/json" \
  -d '{"key":"hotmails_graph_oauth2"}'

# Response is JSON: { success, code, data, message, meta }
PHP
$ch = curl_init('https://palestinex.store/api/v1/products/{key}');
curl_setopt_array($ch, [
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_POSTFIELDS     => json_encode(array (
      'key' => 'hotmails_graph_oauth2',
    )),
    CURLOPT_HTTPHEADER     => [
        'Content-Type: application/json',
    ],
    CURLOPT_TIMEOUT        => 30,
]);

$raw  = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);

if (empty($json['success'])) {
    // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
    exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}

print_r($json['data']);
Python
import json, urllib.request

payload = json.dumps({"key":"hotmails_graph_oauth2"}).encode()

req = urllib.request.Request(
    "https://palestinex.store/api/v1/products/{key}",
    data=payload,
    headers={
        "Content-Type": "application/json",
    },
    method="GET",
)

with urllib.request.urlopen(req, timeout=30) as r:
    data = json.load(r)

if not data["success"]:
    raise RuntimeError(data["error"]["code"] + ": " + data["message"])

print(json.dumps(data["data"], indent=2))
JavaScript
const res = await fetch("https://palestinex.store/api/v1/products/{key}", {
  method: "GET",
  headers: {
    "Content-Type": "application/json",
  },
  body: JSON.stringify({"key":"hotmails_graph_oauth2"}),
});

const json = await res.json();

if (!json.success) {
  // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
  throw new Error(json.error.code + ": " + json.message);
}

console.log(json.data);
Response (200)
200 OK Request completed successfully.
{
    "success": true,
    "code": 200,
    "data": {
        "product": {
            "id": 4,
            "key": "hotmails_graph_oauth2",
            "title": "Hotmail (Graph API / OAuth2)",
            "category": "hotmail",
            "category_name": "Hotmail",
            "price_bdt": 1,
            "currency": "BDT",
            "available_stock": 20,
            "in_stock": true,
            "min_quantity": 1,
            "max_quantity": 500,
            "active": true
        }
    },
    "message": "Request completed successfully."
}
09
GET Account API key

Balance and account status

Current spendable balance for the key owner, plus role and account state. Also available at /api/v1/user/balance.

https://palestinex.store /api/v1/balance
Request
cURL
curl -X GET "https://palestinex.store/api/v1/balance"
  -H "Authorization: Bearer YOUR_API_KEY" \

# Response is JSON: { success, code, data, message, meta }
PHP
$ch = curl_init('https://palestinex.store/api/v1/balance');
curl_setopt_array($ch, [
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_HTTPHEADER     => [
        'Authorization: Bearer YOUR_API_KEY',
    ],
    CURLOPT_TIMEOUT        => 30,
]);

$raw  = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);

if (empty($json['success'])) {
    // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
    exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}

print_r($json['data']);
Python
import json, urllib.request

req = urllib.request.Request(
    "https://palestinex.store/api/v1/balance",
    headers={
        "Authorization": "Bearer YOUR_API_KEY",
    },
    method="GET",
)

with urllib.request.urlopen(req, timeout=30) as r:
    data = json.load(r)

if not data["success"]:
    raise RuntimeError(data["error"]["code"] + ": " + data["message"])

print(json.dumps(data["data"], indent=2))
JavaScript
const res = await fetch("https://palestinex.store/api/v1/balance", {
  method: "GET",
  headers: {
    Authorization: "Bearer YOUR_API_KEY",
  },
});

const json = await res.json();

if (!json.success) {
  // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
  throw new Error(json.error.code + ": " + json.message);
}

console.log(json.data);
Response (200)
200 OK Request completed successfully.
{
    "success": true,
    "code": 200,
    "data": {
        "user_id": 11,
        "username": "apitester",
        "fullname": "API Tester",
        "email": "apitest@palestinex.local",
        "balance": 5000,
        "currency": "BDT",
        "role": "user",
        "status": "active"
    },
    "message": "Request completed successfully."
}
10
GET Account API key

Inspect the active key (masked)

Never returns the secret. Shows only a masked fingerprint and last-used timestamp so an integration can confirm which key is live.

https://palestinex.store /api/v1/user/key
Request
cURL
curl -X GET "https://palestinex.store/api/v1/user/key"
  -H "Authorization: Bearer YOUR_API_KEY" \

# Response is JSON: { success, code, data, message, meta }
PHP
$ch = curl_init('https://palestinex.store/api/v1/user/key');
curl_setopt_array($ch, [
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_HTTPHEADER     => [
        'Authorization: Bearer YOUR_API_KEY',
    ],
    CURLOPT_TIMEOUT        => 30,
]);

$raw  = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);

if (empty($json['success'])) {
    // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
    exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}

print_r($json['data']);
Python
import json, urllib.request

req = urllib.request.Request(
    "https://palestinex.store/api/v1/user/key",
    headers={
        "Authorization": "Bearer YOUR_API_KEY",
    },
    method="GET",
)

with urllib.request.urlopen(req, timeout=30) as r:
    data = json.load(r)

if not data["success"]:
    raise RuntimeError(data["error"]["code"] + ": " + data["message"])

print(json.dumps(data["data"], indent=2))
JavaScript
const res = await fetch("https://palestinex.store/api/v1/user/key", {
  method: "GET",
  headers: {
    Authorization: "Bearer YOUR_API_KEY",
  },
});

const json = await res.json();

if (!json.success) {
  // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
  throw new Error(json.error.code + ": " + json.message);
}

console.log(json.data);
Response (200)
200 OK Request completed successfully.
{
    "success": true,
    "code": 200,
    "data": {
        "has_api_key": true,
        "masked_key": "************************************************************3a85",
        "last_used_at": "2026-09-26 09:06:09",
        "rotate_endpoint": "/api/v1/user/api-key/rotate",
        "note": "The full secret is only ever returned once, at rotation time."
    },
    "message": "Request completed successfully."
}
11
POST Account API key

Rotate the API key

Generates a new key and immediately invalidates the previous one. This is the ONLY response that ever contains the plaintext secret — store it before leaving the response. The previous key stops working at once.

https://palestinex.store /api/v1/user/api-key/rotate
Request
cURL
curl -X POST "https://palestinex.store/api/v1/user/api-key/rotate"
  -H "Authorization: Bearer YOUR_API_KEY" \

# Response is JSON: { success, code, data, message, meta }
PHP
$ch = curl_init('https://palestinex.store/api/v1/user/api-key/rotate');
curl_setopt_array($ch, [
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_CUSTOMREQUEST  => 'POST',
    CURLOPT_HTTPHEADER     => [
        'Authorization: Bearer YOUR_API_KEY',
    ],
    CURLOPT_TIMEOUT        => 30,
]);

$raw  = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);

if (empty($json['success'])) {
    // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
    exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}

print_r($json['data']);
Python
import json, urllib.request

req = urllib.request.Request(
    "https://palestinex.store/api/v1/user/api-key/rotate",
    headers={
        "Authorization": "Bearer YOUR_API_KEY",
    },
    method="POST",
)

with urllib.request.urlopen(req, timeout=30) as r:
    data = json.load(r)

if not data["success"]:
    raise RuntimeError(data["error"]["code"] + ": " + data["message"])

print(json.dumps(data["data"], indent=2))
JavaScript
const res = await fetch("https://palestinex.store/api/v1/user/api-key/rotate", {
  method: "POST",
  headers: {
    Authorization: "Bearer YOUR_API_KEY",
  },
});

const json = await res.json();

if (!json.success) {
  // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
  throw new Error(json.error.code + ": " + json.message);
}

console.log(json.data);
Response (200)
200 OK API key rotated successfully.
{
    "success": true,
    "code": 200,
    "data": {
        "api_key": "1689fd55…3a85",
        "last4": "3a85",
        "note": "Store this key now. For security it is never displayed again — only the last 4 characters are retained."
    },
    "message": "API key rotated successfully."
}
12
POST Orders API key

Purchase mail accounts

Atomically reserves stock, debits the balance and creates the order inside a single row-locked transaction. Concurrent calls can never oversell or double-charge. Also accepted at POST /api/v1/order. Returns 201 on success.

https://palestinex.store /api/v1/order/buy
Request
cURL
curl -X POST "https://palestinex.store/api/v1/order/buy"
  -H "Idempotency-Key: order-2026-09-26-0001" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"product_key":"hotmails_graph_oauth2","quantity":1}'

# Response is JSON: { success, code, data, message, meta }
PHP
$ch = curl_init('https://palestinex.store/api/v1/order/buy');
curl_setopt_array($ch, [
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_CUSTOMREQUEST  => 'POST',
    CURLOPT_POSTFIELDS     => json_encode(array (
      'product_key' => 'hotmails_graph_oauth2',
      'quantity' => 1,
    )),
    CURLOPT_HTTPHEADER     => [
        'Idempotency-Key: order-2026-09-26-0001',
        'Authorization: Bearer YOUR_API_KEY',
        'Content-Type: application/json',
    ],
    CURLOPT_TIMEOUT        => 30,
]);

$raw  = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);

if (empty($json['success'])) {
    // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
    exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}

print_r($json['data']);
Python
import json, urllib.request

payload = json.dumps({"product_key":"hotmails_graph_oauth2","quantity":1}).encode()

req = urllib.request.Request(
    "https://palestinex.store/api/v1/order/buy",
    data=payload,
    headers={
        "Idempotency-Key": "order-2026-09-26-0001",
        "Authorization": "Bearer YOUR_API_KEY",
        "Content-Type": "application/json",
    },
    method="POST",
)

with urllib.request.urlopen(req, timeout=30) as r:
    data = json.load(r)

if not data["success"]:
    raise RuntimeError(data["error"]["code"] + ": " + data["message"])

print(json.dumps(data["data"], indent=2))
JavaScript
const res = await fetch("https://palestinex.store/api/v1/order/buy", {
  method: "POST",
  headers: {
    "Idempotency-Key": "order-2026-09-26-0001",
    Authorization: "Bearer YOUR_API_KEY",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({"product_key":"hotmails_graph_oauth2","quantity":1}),
});

const json = await res.json();

if (!json.success) {
  // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
  throw new Error(json.error.code + ": " + json.message);
}

console.log(json.data);
Response (201)
201 OK Order ORD-2DA7DC421657 completed successfully.
{
    "success": true,
    "code": 201,
    "data": {
        "order": {
            "order_code": "ORD-2DA7DC421657",
            "product_id": 4,
            "product_key": "hotmails_graph_oauth2",
            "product_title": "Hotmail (Graph API / OAuth2)",
            "quantity": 1,
            "unit_price": 1,
            "total_cost": 1,
            "currency": "BDT",
            "status": "completed",
            "items": [
                {
                    "email": "apitest123+1@hotmail.com",
                    "details_line": "apitest123+1@hotmail.com|ApiTest!1|rt-…|cid-…"
                }
            ]
        }
    },
    "message": "Order ORD-2DA7DC421657 completed successfully."
}
13
POST Orders API key

Multi-product purchase (all-or-nothing)

Executes up to 25 line items inside one transaction. If any line fails — unknown product, insufficient stock or balance — the entire batch is rolled back and no charge is applied. Returns 201 on success.

https://palestinex.store /api/v1/order/bulk
Request
cURL
curl -X POST "https://palestinex.store/api/v1/order/bulk"
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"orders":[{"product_key":"gmail","quantity":1},{"product_key":"outlooks_imap","quantity":1}]}'

# Response is JSON: { success, code, data, message, meta }
PHP
$ch = curl_init('https://palestinex.store/api/v1/order/bulk');
curl_setopt_array($ch, [
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_CUSTOMREQUEST  => 'POST',
    CURLOPT_POSTFIELDS     => json_encode(array (
      'orders' => 
      array (
        0 => 
        array (
          'product_key' => 'gmail',
          'quantity' => 1,
        ),
        1 => 
        array (
          'product_key' => 'outlooks_imap',
          'quantity' => 1,
        ),
      ),
    )),
    CURLOPT_HTTPHEADER     => [
        'Authorization: Bearer YOUR_API_KEY',
        'Content-Type: application/json',
    ],
    CURLOPT_TIMEOUT        => 30,
]);

$raw  = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);

if (empty($json['success'])) {
    // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
    exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}

print_r($json['data']);
Python
import json, urllib.request

payload = json.dumps({"orders":[{"product_key":"gmail","quantity":1},{"product_key":"outlooks_imap","quantity":1}]}).encode()

req = urllib.request.Request(
    "https://palestinex.store/api/v1/order/bulk",
    data=payload,
    headers={
        "Authorization": "Bearer YOUR_API_KEY",
        "Content-Type": "application/json",
    },
    method="POST",
)

with urllib.request.urlopen(req, timeout=30) as r:
    data = json.load(r)

if not data["success"]:
    raise RuntimeError(data["error"]["code"] + ": " + data["message"])

print(json.dumps(data["data"], indent=2))
JavaScript
const res = await fetch("https://palestinex.store/api/v1/order/bulk", {
  method: "POST",
  headers: {
    Authorization: "Bearer YOUR_API_KEY",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({"orders":[{"product_key":"gmail","quantity":1},{"product_key":"outlooks_imap","quantity":1}]}),
});

const json = await res.json();

if (!json.success) {
  // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
  throw new Error(json.error.code + ": " + json.message);
}

console.log(json.data);
Response (201)
201 OK Bulk purchase completed successfully.
{
    "success": true,
    "code": 201,
    "data": {
        "orders": [
            {
                "order_code": "ORD-1C0669A818BF",
                "product_key": "gmail",
                "quantity": 1,
                "unit_price": 7,
                "total_cost": 7,
                "items": [
                    {
                        "email": "apitest123+1@gmail.com",
                        "details_line": "…"
                    }
                ]
            }
        ],
        "order_count": 2,
        "total_cost": 8,
        "currency": "BDT"
    },
    "message": "Bulk purchase completed successfully."
}
14
GET Orders API key

Paginated order history

Your own orders, newest first. Only documented fields are returned — internal columns such as user_id are never exposed. Also available at /api/v1/orders/recent.

https://palestinex.store /api/v1/order/history
Request
cURL
curl -X GET "https://palestinex.store/api/v1/order/history"
  -H "Authorization: Bearer YOUR_API_KEY" \

# Response is JSON: { success, code, data, message, meta }
PHP
$ch = curl_init('https://palestinex.store/api/v1/order/history');
curl_setopt_array($ch, [
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_HTTPHEADER     => [
        'Authorization: Bearer YOUR_API_KEY',
    ],
    CURLOPT_TIMEOUT        => 30,
]);

$raw  = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);

if (empty($json['success'])) {
    // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
    exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}

print_r($json['data']);
Python
import json, urllib.request

req = urllib.request.Request(
    "https://palestinex.store/api/v1/order/history",
    headers={
        "Authorization": "Bearer YOUR_API_KEY",
    },
    method="GET",
)

with urllib.request.urlopen(req, timeout=30) as r:
    data = json.load(r)

if not data["success"]:
    raise RuntimeError(data["error"]["code"] + ": " + data["message"])

print(json.dumps(data["data"], indent=2))
JavaScript
const res = await fetch("https://palestinex.store/api/v1/order/history", {
  method: "GET",
  headers: {
    Authorization: "Bearer YOUR_API_KEY",
  },
});

const json = await res.json();

if (!json.success) {
  // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
  throw new Error(json.error.code + ": " + json.message);
}

console.log(json.data);
Response (200)
200 OK Request completed successfully.
{
    "success": true,
    "code": 200,
    "data": {
        "orders": [
            {
                "order_code": "ORD-2DA7DC421657",
                "product_id": 4,
                "quantity": 1,
                "unit_price": 1,
                "total_cost": 1,
                "status": "completed",
                "created_at": "2026-09-26 09:05:53"
            }
        ],
        "pagination": {
            "current_page": 1,
            "per_page": 20,
            "total_records": 1,
            "total_pages": 1
        }
    },
    "message": "Request completed successfully."
}
15
GET Orders API key

Fetch one order and its delivered accounts

Returns the order plus the delivered credentials. Scoped to the key owner: another user's order code returns 404, never its contents.

https://palestinex.store /api/v1/order/{code}
Request
cURL
curl -X GET "https://palestinex.store/api/v1/order/{code}"
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"code":"ORD-2DA7DC421657"}'

# Response is JSON: { success, code, data, message, meta }
PHP
$ch = curl_init('https://palestinex.store/api/v1/order/{code}');
curl_setopt_array($ch, [
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_POSTFIELDS     => json_encode(array (
      'code' => 'ORD-2DA7DC421657',
    )),
    CURLOPT_HTTPHEADER     => [
        'Authorization: Bearer YOUR_API_KEY',
        'Content-Type: application/json',
    ],
    CURLOPT_TIMEOUT        => 30,
]);

$raw  = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);

if (empty($json['success'])) {
    // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
    exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}

print_r($json['data']);
Python
import json, urllib.request

payload = json.dumps({"code":"ORD-2DA7DC421657"}).encode()

req = urllib.request.Request(
    "https://palestinex.store/api/v1/order/{code}",
    data=payload,
    headers={
        "Authorization": "Bearer YOUR_API_KEY",
        "Content-Type": "application/json",
    },
    method="GET",
)

with urllib.request.urlopen(req, timeout=30) as r:
    data = json.load(r)

if not data["success"]:
    raise RuntimeError(data["error"]["code"] + ": " + data["message"])

print(json.dumps(data["data"], indent=2))
JavaScript
const res = await fetch("https://palestinex.store/api/v1/order/{code}", {
  method: "GET",
  headers: {
    Authorization: "Bearer YOUR_API_KEY",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({"code":"ORD-2DA7DC421657"}),
});

const json = await res.json();

if (!json.success) {
  // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
  throw new Error(json.error.code + ": " + json.message);
}

console.log(json.data);
Response (200)
200 OK Request completed successfully.
{
    "success": true,
    "code": 200,
    "data": {
        "order": {
            "order_code": "ORD-2DA7DC421657",
            "product_id": 4,
            "quantity": 1,
            "unit_price": 1,
            "total_cost": 1,
            "status": "completed",
            "created_at": "2026-09-26 09:05:53",
            "product_key": "hotmails_graph_oauth2",
            "product_title": "Hotmail (Graph API / OAuth2)",
            "currency": "BDT"
        },
        "items": [
            {
                "email": "apitest123+1@hotmail.com",
                "provider": "hotmail",
                "details_line": "apitest123+1@hotmail.com|ApiTest!1|rt-…|cid-…"
            }
        ]
    },
    "message": "Request completed successfully."
}
16
POST Code retrieval API key

Fetch the latest verification code for a mailbox

Reads a mailbox you have already purchased and returns the newest code. If you omit refresh_token / inbox_url, PalestineX resolves the credentials from your own purchase history, so you never have to re-send secrets you already bought. Gmail uses the stored inbox URL; Hotmail and Outlook use OAuth2. Also accepted as GET or POST /api/v1/code.

https://palestinex.store /api/v1/code/fetch
Request
cURL
curl -X POST "https://palestinex.store/api/v1/code/fetch"
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"email":"user@outlook.com","type":"facebook"}'

# Response is JSON: { success, code, data, message, meta }
PHP
$ch = curl_init('https://palestinex.store/api/v1/code/fetch');
curl_setopt_array($ch, [
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_CUSTOMREQUEST  => 'POST',
    CURLOPT_POSTFIELDS     => json_encode(array (
      'email' => 'user@outlook.com',
      'type' => 'facebook',
    )),
    CURLOPT_HTTPHEADER     => [
        'Authorization: Bearer YOUR_API_KEY',
        'Content-Type: application/json',
    ],
    CURLOPT_TIMEOUT        => 30,
]);

$raw  = curl_exec($ch);
$json = json_decode((string)$raw, true);
curl_close($ch);

if (empty($json['success'])) {
    // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
    exit('Error: ' . ($json['error']['code'] ?? 'UNKNOWN'));
}

print_r($json['data']);
Python
import json, urllib.request

payload = json.dumps({"email":"user@outlook.com","type":"facebook"}).encode()

req = urllib.request.Request(
    "https://palestinex.store/api/v1/code/fetch",
    data=payload,
    headers={
        "Authorization": "Bearer YOUR_API_KEY",
        "Content-Type": "application/json",
    },
    method="POST",
)

with urllib.request.urlopen(req, timeout=30) as r:
    data = json.load(r)

if not data["success"]:
    raise RuntimeError(data["error"]["code"] + ": " + data["message"])

print(json.dumps(data["data"], indent=2))
JavaScript
const res = await fetch("https://palestinex.store/api/v1/code/fetch", {
  method: "POST",
  headers: {
    Authorization: "Bearer YOUR_API_KEY",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({"email":"user@outlook.com","type":"facebook"}),
});

const json = await res.json();

if (!json.success) {
  // error.code is a stable machine-readable string, e.g. OUT_OF_STOCK
  throw new Error(json.error.code + ": " + json.message);
}

console.log(json.data);
Response (200)
200 OK Request completed successfully.
{
    "success": true,
    "code": 200,
    "data": {
        "email": "user@outlook.com",
        "provider": "outlook",
        "type": "facebook",
        "code": "849210",
        "message": "Code retrieved from the mailbox.",
        "fetched_at": "2026-09-26T09:07:00+06:00"
    },
    "message": "Request completed successfully."
}
17
Reference

Errors & status codes

Branch on error.code, not on the message text. Every code below is stable.

Handling errors safely
JavaScript
const res = await fetch('https://palestinex.store/api/v1/order/buy', {
  method: 'POST',
  headers: {
    Authorization: 'Bearer YOUR_API_KEY',
    'Content-Type': 'application/json',
    // Retrying with the same key returns the ORIGINAL order instead of
    // charging you twice.
    'Idempotency-Key': 'order-2026-09-26-0001',
  },
  body: JSON.stringify({ product_key: 'hotmails_graph_oauth2', quantity: 1 }),
});

const json = await res.json();

if (!json.success) {
  switch (json.error.code) {
    case 'OUT_OF_STOCK':
      // Nothing was charged. Back off and try a smaller quantity.
      break;
    case 'INSUFFICIENT_BALANCE':
      // Top up at /deposit, then retry with the same Idempotency-Key.
      break;
    case 'RATE_LIMITED':
      // error.details.window_seconds tells you how long to wait.
      await new Promise(r => setTimeout(r, json.error.details.window_seconds * 1000));
      break;
    default:
      // meta.request_id is safe to quote in a support request.
      console.error(json.error.code, json.message, json.meta.request_id);
  }
}
Key handling
  • Stored hashed

    Only a SHA-256 hash of your key is kept server-side. PalestineX cannot show it back to you.

  • Shown once

    The plaintext appears exactly once, at rotation. After that only the last 4 characters remain.

  • Rotate any time

    POST /api/v1/user/api-key/rotate issues a new key and immediately invalidates the old one.

  • Suspended accounts

    A blocked account gets 403 ACCOUNT_NOT_ACTIVE on every call.

18
Copy & paste

Examples

The same four languages, end to end.

Products
cURL
curl -X GET "https://palestinex.store/api/v1/products?category=hotmail" \
  -H "Accept: application/json"
Purchase
cURL
curl -X POST "https://palestinex.store/api/v1/order/buy" \
  -H "Authorization: Bearer {KEY}" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: order-2026-09-26-0001" \
  -d '{"product_key":"hotmails_graph_oauth2","quantity":1}'
PHP
$ch = curl_init('https://palestinex.store/api/v1/order/buy');
curl_setopt_array($ch, [
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_POST           => true,
    CURLOPT_POSTFIELDS     => json_encode([
        'product_key' => 'hotmails_graph_oauth2',
        'quantity'    => 1,
    ]),
    CURLOPT_HTTPHEADER => [
        'Authorization: Bearer {KEY}',
        'Content-Type: application/json',
        'Idempotency-Key: order-2026-09-26-0001',
    ],
]);
$res  = curl_exec($ch);
$json = json_decode($res, true);
curl_close($ch);

if (!empty($json['success'])) {
    echo "Order: " . $json['data']['order']['order_code'] . PHP_EOL;
    foreach ($json['data']['order']['items'] as $item) {
        echo $item['email'] . PHP_EOL;
    }
} else {
    echo "Error [" . ($json['error']['code'] ?? '?') . "]: " . $json['message'] . PHP_EOL;
}
Buy (JS)
JavaScript
const res = await fetch('https://palestinex.store/api/v1/order/buy', {
  method: 'POST',
  headers: {
    'Authorization': 'Bearer {KEY}',
    'Content-Type': 'application/json',
    'Idempotency-Key': 'order-2026-09-26-0001',
  },
  body: JSON.stringify({
    product_key: 'hotmails_graph_oauth2',
    quantity: 1,
  }),
});

const json = await res.json();

if (!json.success) {
  console.error(json.error.code, json.message);
} else {
  const order = json.data.order;
  console.log('Order', order.order_code, order.items);
}
Buy (Py)
Python
import json, urllib.request

req = urllib.request.Request(
    "https://palestinex.store/api/v1/order/buy",
    data=json.dumps({
        "product_key": "hotmails_graph_oauth2",
        "quantity": 1,
    }).encode(),
    headers={
        "Authorization": "Bearer {KEY}",
        "Content-Type": "application/json",
        "Idempotency-Key": "order-2026-09-26-0001",
    },
    method="POST",
)

with urllib.request.urlopen(req) as r:
    payload = json.load(r)

if not payload["success"]:
    raise RuntimeError(payload["error"]["code"] + ": " + payload["message"])

order = payload["data"]["order"]
print("Order", order["order_code"])
for item in order["items"]:
    print(item["email"])
Bulk
cURL
curl -X POST "https://palestinex.store/api/v1/order/bulk" \
  -H "Authorization: Bearer {KEY}" \
  -H "Content-Type: application/json" \
  -d '{"orders":[{"product_key":"gmail","quantity":1},
                 {"product_key":"outlooks_imap","quantity":1}]}'
Code fetch
cURL
curl -X POST "https://palestinex.store/api/v1/code/fetch" \
  -H "Authorization: Bearer {KEY}" \
  -H "Content-Type: application/json" \
  -d '{"email":"user@outlook.com","type":"facebook"}'