Frequently asked questions

Everything Venduex does — and, just as important, everything it never does.

Basics

What is Venduex?

A read-only desk for your domain-auction bids. Connect the auction sites you bid on, and Venduex shows every active bid in one place — whether you're leading or outbid, live countdowns, budget caps with headroom — plus your full win/loss history and spending stats.

Is it really read-only?

Yes, structurally. Venduex only ever calls each site's read endpoints — it has no code path that places, raises, or cancels a bid. Bidding stays where it belongs: on the auction site, done by you.

Which auction sites are supported?

DropCatch, Namecheap Market and Dynadot connect directly with a read-only API key. Park.io works by importing the orders CSV they export, since they don't offer a bid API.

The market board — live auctions you can browse whether or not you bid there — covers DropCatch, Dynadot, NameSilo, park.io and catches.io.

GoDaddy and NameJet keep their auction APIs closed to new accounts, and some marketplaces (Sedo, for one) have no bidder API at all. We add sites as access allows, and say plainly which ones work rather than listing logos we can't deliver.

What does it cost?

$39 a year, after a 14-day free trial with full access and no card required. One plan, everything included — every auction site, alerts, history, stats, the market board and API access.

How do I sign in?

Two ways, both passwordless: continue with Google, or have a one-time sign-in link emailed to you. There's no password to remember, reuse, or leak.

Connecting sites

What do I need to connect a site?

An API credential from that site — each one issues its own (Dynadot: an API key; DropCatch: a Client ID and Secret; Namecheap: an Auctions API key from the Market Dashboard). The connect page walks you through each site's exact steps, including where to find the credential.

What's the IP allowlist step about?

Some sites (notably Dynadot) only accept API calls from server addresses you've pre-approved. Venduex reads your data from a fixed set of static IPs, shown on the connect page — adding them to the site's allowlist is a security feature: even a stolen key would be useless from anywhere else.

Is my API key safe?

Your key is encrypted the moment it arrives (AES-256-GCM) and stored only in encrypted form. It's decrypted exclusively by the sync worker that reads your bids — never sent to browsers, never logged. And since it's a credential you issued, you can revoke it on the auction site at any time, independently of Venduex.

I connected Dynadot but my bids don't appear.

Dynadot restricts auction API commands on some accounts, separately from the API key itself. If your connection shows Active but stays empty, contact Dynadot support and ask them to enable auction API access for your account — the moment they do, your bids sync automatically.

How do I disconnect a site?

Settings → Disconnect (it asks you to confirm). That deletes your encrypted key from Venduex and stops syncing that site. Positions already recorded stay in your history. For belt-and-suspenders, also revoke the key on the auction site itself.

The desk

How fresh is the data?

The sync worker re-reads every connected site about once a minute, and the desk refreshes itself every 60 seconds — the footer tells you exactly how long ago. A new bid you place on a site typically appears within a couple of minutes.

What is a budget cap? Does it bid for me?

No — it's a private tracking number, not a bid. Set a cap on any live auction and the desk shows your headroom (cap minus current high bid), flags the row when bidding passes it, and can alert you. The auction site never sees your cap.

What alerts can I get?

Four kinds, each a toggle in Settings:

  • Outbid — a bid you were leading gets topped
  • Over budget — the high bid passes your cap (fires once per breach, and re-arms if you change the cap)
  • Price rises — every increase on your auctions (chatty; off by default)
  • New bids — the bid count on your auctions goes up (off by default)

Alerts land in the desk's Alerts feed within a minute or two of the event.

What's the Market tab?

A live board of public auctions across sites — currently park.io, DropCatch, and Namecheap — filterable by site and sortable by closing time, high bid, or bid count. It's public data for browsing; your own positions stay in the Live tab.

How are the Stats calculated?

Spent = the winning bid on auctions you won and paid, before auction fees. Win rate counts decided auctions (won + lost). Figures reflect what each site's API returns plus what Venduex has recorded since you connected — where a site supports it, your past history is imported automatically (and Settings has an Import history button to re-run it).

Why do some lost auctions show “—” instead of a price?

Because the site's API genuinely doesn't reveal what the domain sold for. DropCatch, for example, reports no amount on historical losses. Where the final price is knowable — auctions Venduex watched live, Namecheap history — it's shown; where it isn't, we show a dash rather than a made-up number.

read-only by design · app.venduex.com