Using the reseller portal
Overview
The reseller portal is the white-label control surface for a CloudPe partner organisation. A reseller organisation sits under CloudPe and owns a set of customer organisations; the reseller sets the prices those customers pay, funds their wallets, applies its own branding and domain, and watches the resulting revenue.
The model is manual settlement. CloudPe sets the reseller's cost basis (a wholesale discount off retail); the reseller sets end-customer prices through pricing tiers and per-tariff overrides. Those prices are applied to real billing — usage records for reseller customers are rate-stamped at the reseller's prices across every billable family (instances, VDI sessions, volumes, snapshots, backups, floating IPs, routers, VPN, load balancers, object storage, Kubernetes and managed databases). Wholesale settlement between the reseller and CloudPe happens outside the system; the platform never auto-debits the reseller.
End customers on a reseller domain see the reseller's brand, their wallet balance and their usage amounts. Invoice, payment and provider-KYC surfaces are hidden for them, and the support link points at the reseller's own support URL.
Before you start
- A reseller organisation must already exist. CloudPe creates it, along with the default customer group, wholesale discount, billing currency and the owner invitation email. You cannot self-provision a reseller organisation from the portal.
- The owner invitation must be accepted. Accepting an owner invitation marks the accepting user as the organisation owner, which is what grants full portal access — no role assignment step is required.
- Staff access needs organisation-scoped roles. Reseller staff roles (
reseller_admin,reseller_support,reseller_billing_viewer,reseller_viewer) only grant permissions when the role assignment is scoped to the reseller organisation. A globally scoped reseller role contributes no per-organisation permission and the portal will refuse access. - Permissions: the portal shell requires
reseller:view(or organisation ownership). Read pages are gated by area:reseller_customers:read,reseller_billing:read,reseller_pricing:read,reseller_branding:read,reseller_email_templates:read. Every mutation control is gated byreseller:manageor ownership. SMTP configuration stays owner-or-reseller:manageonly. - The reseller organisation must be active. Suspended or deleted reseller organisations are rejected by the portal, and suspending a reseller cascades to its customer organisations.
- A custom domain must be pointed at the platform and verified before branding on that host takes effect. Google sign-in on a custom domain additionally requires a CloudPe operator to register the origin — until then the sign-in page on that host omits the Google button.
Steps
- Accept the owner invitation sent to the reseller owner email. You become the reseller organisation owner and land in the portal.
- Review the dashboard. It summarises customers, revenue, your quota pool allocation and a recent activity feed of customer lifecycle events, credit grants, tier changes and login-as-customer sessions.
- Create pricing tiers on the pricing tiers page. A tier defines the billing mode (prepaid or postpaid), a signed markup percentage applied on top of your cost price, the subset of your entitled regions customers on that tier may provision in, and optional quota caps drawn from your pool. The page shows a live preview of what a customer on the tier would pay. A postpaid tier needs a positive credit limit before it can be assigned.
- Create customers on the customers page. Supply a name, slug and owner email; the customer organisation is created under your reseller organisation, placed in a customer group so its projects can provision, and an owner invitation email is sent. Membership only exists once the invitation is accepted. If self-service signup is enabled for your verified domain, new signups can instead arrive on their own — with "require approval" on, they wait in pending status until you approve them from the customers page.
- Assign a tier from the customer detail page. The current tier, billing mode and markup are shown as badges. Switching a customer from postpaid to prepaid while usage is accrued prompts for confirmation and surfaces the outstanding amount.
- Fund the customer. Welcome credits configured at customer creation are granted to the new customer's wallet automatically when the owner accepts the invitation, debited from your wholesale wallet. Further top-ups are made with the add-credits action, which is the audited path that debits your wallet. Optionally set a monthly spend cap per customer (amount, warning threshold and auto-suspend) from the wallet tab.
- Add fine-grained price exceptions on the pricing page if a tier markup is not enough: per-tariff overrides (absolute, percentage markup or fixed markup) and per-customer overrides. An override always wins over the tier markup. Use the price preview to confirm the resulting customer price before saving.
- Apply your branding. On the branding settings page set logo, colours, favicon, support, terms and privacy URLs, and add your custom domain, which is verified with a DNS TXT token. Configure your own SMTP and customer-facing email templates so invitations and auth emails come from your brand and link to your domain.
- Support your customers. The customer detail page has tabs for resources (instances and volumes), resource usage counts across every billable family, the wallet ledger and an activity feed. As the owner you can also open a short, view-only, audited impersonation session as the customer's owner to reproduce an issue; the session dies the moment your grant is revoked.
- Watch the money. The billing pages show your wholesale wallet and its transactions, per-customer revenue for the current month, and monthly billing records with a per-customer breakdown. Each record offers a branded PDF statement download and a CSV breakdown export.
- Manage the platform surfaces. As the owner, invite staff and change or remove their roles from the team page, review your allocated, distributed, available and utilised quota per resource family and region on the read-only quota pool page, and create or revoke read-only API keys from the API keys settings page. An API key secret is shown once, at creation.
Limits & billing
- Customer prices are derived from your cost basis: retail less the wholesale discount CloudPe set for you, then your tier markup. A per-tariff or per-customer override replaces that result when one exists.
- Negative tier markups (discounts) are allowed, but the resulting customer price is clamped so it never goes below zero.
- Override validation: absolute prices must be greater than zero, markups must be zero or above, and a margin must be below one hundred percent.
- Customer revenue for a month is exact — it is summed from usage records stamped at your prices. Platform cost is indicative only; exact wholesale settlement is a commercial process outside the system, and your wallet is never debited automatically for it.
- Two wallets exist and should not be conflated: your standard organisation wallet is what you top up and what customer credit grants debit; the wholesale wallet tracks what you owe CloudPe for the month.
- Credit grants are capped at 100000 per grant.
- Deleting a pricing tier is blocked while customers are still assigned to it.
- The reseller hierarchy is one level deep — sub-resellers are not supported.
- Welcome credits are granted on invitation acceptance; if your wholesale balance is insufficient at that moment the grant is skipped and the pending amount is restored for a later manual grant.
- Spend caps are enforced by a daily sweep, not at provisioning time, so a customer can briefly exceed a cap before auto-suspension applies.
- CSV exports of customers, billing records, per-record breakdowns, wallet transactions and customer revenue are read-only, rate-limited and row-capped.
- Custom-period customer revenue is not computed live; arbitrary windows fall back to stored monthly records.
- Automatic SSL issuance for custom domains is not built — certificates are managed by CloudPe operations.
Troubleshooting
| Symptom | Cause and fix |
|---|---|
| The portal returns a permission error for a staff member | Their reseller role is assigned at global scope. Reassign the role scoped to the reseller organisation. |
| The portal rejects the reseller organisation entirely | The reseller organisation is suspended or deleted. Contact CloudPe to reactivate it. |
| Deleting a pricing tier is refused | Customers are still assigned to that tier. Move them to another tier first. |
| Assigning a customer to a postpaid tier is refused | The target tier has no positive credit limit. Set a credit limit on the tier, then reassign. |
| A customer was billed at platform prices instead of yours | The customer has no reseller-owned tier assigned. Assign one of your tiers from the customer detail page. |
| The Google sign-in button is missing on your custom domain | The origin has not been registered with CloudPe's identity client yet. Ask CloudPe operations to register it and confirm the attestation. |
| Branding does not appear on your domain | The domain is not verified. Complete DNS TXT verification and confirm the domain status. |
| Welcome credits never reached a new customer's wallet | Either the invitation has not been accepted yet, or your wholesale balance was insufficient at acceptance. Grant the credits manually. |
| A revenue tile shows a dash instead of an amount | The aggregate was unavailable for that view; refresh the page rather than summing the visible rows. |
FAQ
Do my end customers see CloudPe anywhere? No. On a verified reseller domain they see your brand on login, signup and dashboard, your support link, and only their wallet and usage amounts. Invoice, payment and provider-KYC surfaces are hidden and the corresponding endpoints are refused server-side.
Can I create resellers under my reseller? No. The hierarchy is one level deep.
Who approves customer KYC on my tenant? KYC banners and redirects are suppressed for reseller customers; approval is a manual process handled outside the customer-facing flow.
Can I take card payments for my customers inside the portal? No. Payment gateway top-ups for reseller wallets are handled by CloudPe manually, and end customers have no payment UI. Collect payment outside the system and grant credits.
Does impersonating a customer let me change their resources? No. Reseller impersonation is view-only, time-limited, audited, and pinned to that customer's organisation.
Can I clear a customer's billing email? Not currently. The billing email field is set-only — leaving it empty means "no change".
What can a reseller API key do? Read-only access to your own reseller data. Keys are bound to a single reseller organisation and the secret is shown once when created.

