ClientXCMS 2.17: Domains, E-Invoicing & Passkeys
ClientXCMS 2.17 marks the official launch of domain-name management, introduces electronic-invoicing support for French regulations, and adds passwordless authentication with Passkeys. This release also brings major security hardening across the entire platform.

π Domain Management: Officially Launched with OpenProviderβ
Domain management, previewed in version 2.16, is now officially available. The first supported registrar module is OpenProvider, with full automatic configuration.
Automatic TLD Configurationβ
Connect an OpenProvider production account or a separate sandbox account, then import your domain catalog in a few clicks. ClientXCMS retrieves registration, renewal, and transfer prices for each TLD. You can apply a fixed selling price or a percentage margin to several selected extensions at once.

You can filter and select exactly which extensions to import from a registrar catalog, so your storefront only shows the TLDs you want to sell. Default nameservers and DNS records can be configured once and copied to other extensions. The OpenProvider configuration guide covers credentials, sandbox mode, TLD pricing, and reusable DNS settings.
Progressive Domain Searchβ
Customers enjoy a fast, progressive search experience. Results appear in real time as each extension is checked, with availability status and pricing displayed instantly. Search results are cached to keep the interface responsive.
More Registrars Coming Soonβ
OpenProvider is the first officially supported module. Additional registrar integrations β including Netim, Domain Reseller API, and Internet.bs β are currently in development and will be available in upcoming releases.
π§Ύ Electronic Invoicing & French Complianceβ
Version 2.17 introduces electronic-invoicing support to help businesses comply with French e-invoicing regulations.
Business Lookup France and EU VAT Checkβ
The new Business Lookup France addon lets customers search for a company by name, SIREN, or SIRET during checkout. Selecting the correct establishment automatically fills the available legal and tax information.
The EU VAT Check addon complements this lookup by validating European VAT numbers through VIES. Positive checks can be cached for a configurable duration to reduce repeated requests.
Factur-X and E-reporting Providersβ
ClientXCMS now generates Factur-X documents and can route electronic invoices through a configurable provider:
- Local generates and retains the electronic document in ClientXCMS without external transmission.
- Qonto e-invoicing sends externally generated and already-numbered invoices through Qonto's regulatory API, once access has been approved by Qonto.
- Pennylane imports Factur-X invoices with a Company API token and handles their transmission through Pennylane's approved platform.
- Chorus Pro is selected separately for invoices intended for French public-sector entities and connects through PISTE.
Seller identity, SIREN/SIRET, VAT number, operation type, VAT regime, tax timezone, activation date, and the main and public-sector providers are managed from the central billing settings.

Installment Payments & Precise VATβ
Invoices can now be paid in multiple installments. Each partial payment atomically debits the customer balance and preserves the exact VAT amount due on every installment, ensuring your accounting stays accurate.
π Passwordless Authentication with Passkeysβ
ClientXCMS 2.17 introduces WebAuthn / Passkeys β a complete passwordless authentication system. Customers can register a passkey from their profile and sign in with a single tap using their fingerprint, face recognition, or security key.

Combined with the new compromised-password detection (powered by HaveIBeenPwned) and transparent password-hash migration across algorithms, authentication in ClientXCMS has never been stronger.
π₯οΈ Redesigned Administration Experienceβ
Choose Your Layoutβ
Administrators can now switch between a vertical sidebar and the classic horizontal navigation. The choice is presented on first login and can be changed at any time from the top bar or profile settings.

π Deep Security Hardeningβ
This release includes an extensive security overhaul:
- Encryption at rest β TOTP / 2FA secrets and sensitive system settings are now encrypted in the database.
- Strict API authentication β The application API now rejects web sessions as proof; API keys respect expiration dates and ability restrictions.
- Secure email templates β Blade execution in email templates has been replaced by a closed grammar with automatic migration of existing templates.
- Extension integrity β Downloaded extension archives are verified with SHA-256 checksums and signature validation; extraction is confined to the extension's own directory.
- Dynamic Brand Colors β The primary theme color can now be modified instantly from the admin panel using dynamic CSS variables, without needing to rebuild Vite.
- Audit-log filtering β Ignored attributes are now truly excluded from audit trails, and sensitive tokens are stripped from URLs before being sent to Sentry.
- Admin vs. Client isolation β A customer's password confirmation can no longer unlock administrative routes.
- GDPR improvements β Personal-data exports are now more complete, and account deletion performs a deeper cleanup of associated resources.
And Much Moreβ
Version 2.17 also brings service lifecycle controls, mass-action components, UI harmonization, button and color-palette consistency, Vite 8 compatibility, and the new Brevo newsletter addon. Brevo connects the footer subscription form to a selected contact list while supporting API-key and server-IP security.
Read the complete ClientXCMS 2.17 changelog for every technical detail.
