The Ultimate, Database-Free KeyHelp Registration Portal
📦 Product Page: KH-Register | 🧪 Live Demo: Demo | 🌐 Project: PanelLayer
KH-Register is an incredibly robust, secure, and fully-featured self-service registration portal built specifically for KeyHelp by Keyweb AG. Designed from the ground up for maximum security, beautiful UI/UX, and GDPR compliance, it requires zero database setup (100% flat-file logic) and handles user creation flawlessly through the native KeyHelp REST API.
DISCLAIMER: This software is provided "as is" without any warranty of any kind. KH-Register is an independent software solution and is not affiliated with, endorsed by, or sponsored by Keyweb AG (KeyHelp) or its affiliates.
- k-Anonymity Password Checks: Integrates the Have I Been Pwned API directly in the client's browser using the Web Crypto API. Only the first 5 characters of a SHA-1 hash are transmitted—your plaintext password never leaves your browser.
- Advanced Rate-Limiting (Token Bucket): Fully protects the KeyHelp API against brute-force and DDoS spam attacks using a highly efficient, session-independent Token Bucket algorithm based on cryptographically hashed IPs.
- No Database Required: Works strictly with local flat files (JSON/PHP). All sensitive log files (
audit.log.php,used_codes.php) are completely locked down and unreadable from the web, regardless of whether your webserver is Apache, LiteSpeed, or NGINX. - Strict Content Security Policy (CSP): Ships with hardened HTTP response headers (CSP, HSTS, X-Frame-Options) out of the box, mitigating XSS and iframe-injection attacks.
- 20+ Supported Languages: Comes fully translated into 20 languages (English, German, French, Spanish, Russian, Chinese, Thai, and more).
- Responsive Dark/Light Mode: Automatically adjusts its premium UI to the system preferences of your users.
- Live Password Checklist: A real-time, side-by-side interactive UI element that instantly visually validates password complexity requirements.
- Fail-open DNS MX Checks: Automatically verifies the existence of mail servers (MX records) for the email domains entered during registration to prevent bot signups, featuring built-in caching.
Forget spam. We support natively integrated setups for:
- hCaptcha
- reCAPTCHA (Google)
- Cloudflare Turnstile
- Altcha (Proof-of-Work, 100% GDPR compliant)
- MTCaptcha
- Invite-Only Mode: Optionally lock your registration portal so only users with pre-generated, single-use, or multi-use invitation codes can join your platform.
KH-Register communicates with KeyHelp via the official REST API (/api/v2/):
| Action | Endpoint | Method |
|---|---|---|
| Create user (client) | /api/v2/clients |
POST |
| Add domain to client | /api/v2/domains |
POST |
| Delete user (demo mode) | /api/v2/clients/{id} |
DELETE |
| Look up user by name | /api/v2/clients/name/{name} |
GET |
Authentication uses the X-API-Key header. No direct database access or server-side shell commands are required.
- Upload & Extract: Upload the contents to any PHP 8.x web directory on your server.
- Generate API Key: In your KeyHelp panel, go to Settings → Configuration → API and generate an API key.
- Find Template ID: In KeyHelp, go to Templates → Account Templates and note the integer ID of the template to use for new registrations.
- Configure: Open
config.phpand enter your:- KeyHelp Host URL (e.g.
https://panel.yourdomain.com) KH_API_KEY(from step 2)KH_ACCOUNT_TEMPLATE_ID(from step 3, must be an integer)- Desired CAPTCHA Provider Keys
- Security toggles (HIBP, Invite-Mode, Audit Logging)
- KeyHelp Host URL (e.g.
- Generate a Salt: Replace the default
LOG_IP_SALTinconfig.phpwith a random string for IP pseudonymization:openssl rand -hex 16
- Done: The system automatically creates and protects the necessary
data/andlogs/folders upon the first registration.
If DEMO_MODE is enabled, add this to crontab to auto-delete expired accounts:
*/30 * * * * php /path/to/your/webroot/cron_cleanup.php >> /dev/null 2>&1This project is licensed under the MIT License.
Developer: Andy Goldau
Copyright: © 2026 KH-Register by PanelLayer, a brand of Subdomain LTD and managed on behalf of GoMaKe UG. All rights reserved.
Product Page: https://kh-register.panellayer.com/
Live Demo: https://demo.kh-register.panellayer.com/
Project: https://panellayer.com/
The above copyright notice, the developer attribution, and the permission notice must be included in all copies or substantial portions of the Software.