Back to articles
Technology Insight

Designing a VPS Reseller System: Integrating Domestic Payments (VND) and KYC (Know Your Customer) Process

April 14, 2026
Designing a Reseller VPS System: VND Integration and KYC Standards 2026

Designing a Reseller VPS System: Domestic Payment Integration (VND) and KYC Compliance

Building a Reseller VPS (Virtual Private Server) system is more than just connecting APIs to major providers like DigitalOcean, Vultr, or Proxmox. To operate a professional platform in the Vietnamese market, the real challenge lies in risk management, optimizing domestic cash flow, and establishing a rigorous Know Your Customer (KYC) process. This article dives deep into the technical architecture and operational workflows for a comprehensive Reseller VPS platform.

1. System Architecture and Role-Based Access Control (RBAC)

In a reseller system, defining clear boundaries between user groups is vital for security and transparency. A multi-tier RBAC (Role-Based Access Control) model is essential.

  • Super Admin: Full system control, manages root API connections, configures exchange rates, and approves high-level KYC requests.
  • Seller: The primary stakeholder. They lease resources from the Admin or connect their own infrastructure, set pricing in VND, and manage their end-customers.
  • Standard User: The end-customer who directly uses the VPS. They perform payments via domestic gateways and manage their servers through the dashboard.

// Defining Role-Based Access Control in a NestJS system
enum UserRole {
    ADMIN = 'ADMIN',
    SELLER = 'SELLER',
    USER = 'USER'
}

interface UserProfile {
    id: string;
    email: string;
    role: UserRole;
    isKycVerified: boolean;
    walletBalanceVND: number;
}

// Middleware to verify VPS resource management permissions
function canManageVPS(user: UserProfile, targetVpsOwnerId: string): boolean {
    if (user.role === UserRole.ADMIN) return true;
    if (user.role === UserRole.SELLER && user.id === targetVpsOwnerId) return true;
    return user.id === targetVpsOwnerId;
}
    

2. KYC (Know Your Customer) Workflow for Sellers

Why is strict KYC necessary for Sellers? In this model, the Seller holds direct legal responsibility for the content running on the VPS. A system without KYC becomes a breeding ground for fraud, DDoS attacks, or mail spamming.

A standard KYC process involves these steps:

  1. Data Collection: Photos of ID/Passport (both sides) and a portrait (selfie).
  2. OCR Validation: Utilizing AI APIs to extract data from photos and match it with registered info.
  3. Risk Scoring: Checking if phone numbers or emails are blacklisted in security databases.
  4. Manual Approval: The final step by an Admin to ensure absolute authenticity before granting "Seller" status.

// Simulating the KYC approval state
type KycStatus = 'PENDING' | 'APPROVED' | 'REJECTED';

interface KycDocument {
    userId: string;
    idNumber: string;
    frontImageUrl: string;
    backImageUrl: string;
    selfieImageUrl: string;
    status: KycStatus;
}

async function processKycSubmission(doc: KycDocument): Promise {
    // Calling an AI OCR service (e.g., Google Vision or AWS Textract)
    const ocrResult = await ocrService.extractInfo(doc.frontImageUrl);
    
    if (ocrResult.idNumber !== doc.idNumber) {
        throw new Error("ID Number does not match the provided image!");
    }
    
    // Save to database pending Admin review
    return await database.saveKycStatus(doc.userId, 'PENDING');
}
    

3. Domestic Payment: VND Integration and Gateways

In the Vietnamese market, international credit card payments (Visa/Mastercard) still face barriers regarding currency conversion fees and trust. A successful Reseller VPS system must integrate: Bank Transfers (VietQR), MoMo, and ZaloPay.

Cash Flow Optimization:

The system requires an "Internal E-Wallet" mechanism. Users deposit VND into the wallet, and the system deducts funds based on hourly usage (Pay-as-you-go) or monthly subscriptions. This helps Sellers manage steady cash flow and allows users to control costs easily.

Method Advantages Disadvantages
VietQR (Banking) Low fees (~0%), instant settlement. Difficult to automate without direct Banking APIs.
E-Wallets (MoMo/ZaloPay) Great UX, stable APIs. High transaction fees (1.5% - 2.5%).
Domestic Cards (NAPAS) Widely used, trustworthy. Requires integration through intermediaries (PayOS, Alepay).

4. API Synchronization and Message Queues

When a customer clicks "Buy VPS," the system cannot ask them to wait 5-10 minutes while the server initializes. However, upstream provider APIs often have latency. We must use Message Queues (Redis/RabbitMQ) for asynchronous processing.


// Example of a Task Queue handling VPS provisioning
import { InjectQueue } from '@nestjs/bull';
import { Queue } from 'bull';

class VpsService {
    constructor(@InjectQueue('provisioning') private vpsQueue: Queue) {}

    async createVpsOrder(orderData: any) {
        // 1. Check VND wallet balance
        // 2. Deduct funds (Escrow)
        // 3. Add to processing queue
        await this.vpsQueue.add('setup-vps', {
            planId: orderData.planId,
            userId: orderData.userId,
            region: 'Hanoi-1'
        }, { attempts: 3, backoff: 5000 });
        
        return { message: "Order is being processed, please wait a moment." };
    }
}
    

5. Reseller Policies and Commissions

To grow the reseller network, you need a flexible commission engine. However, a strict rule must be applied: Sellers cannot earn commission from their own purchases.

Wallet structures should be separated:

  • Main Wallet: Used for service payments.
  • Affiliate Wallet: Stores commissions from referrals (Standard Users only).
  • Seller Credit: A credit limit granted by Admin for reselling purposes.

// Calculating commission based on Tier level
function calculateCommission(amount: number, tier: number): number {
    const rates = { 1: 0.05, 2: 0.1, 3: 0.15 }; // 5%, 10%, 15%
    const rate = rates[tier] || 0.02;
    return amount * rate;
}

const orderValue = 500000; // 500,000 VND
const commission = calculateCommission(orderValue, 2);
console.log(`Commission added to wallet: ${commission.toLocaleString()} VND`);
    

6. Security and Anti-Fraud Measures

In a VPS environment, the biggest risk is customers using servers for illegal crypto mining or launching cyberattacks, which damages IP Reputation. The system needs integrated monitoring tools:

  • Bandwidth Limiting: Automatically throttle bandwidth if abnormal traffic spikes are detected.
  • Port Monitoring: Block port 25 by default to prevent mass spam emails.
  • Behavioral Analytics: Trigger alerts if an account deposits large sums using multiple different cards in a short time.

7. Conclusion: The Optimal Implementation Roadmap

Building a Reseller VPS platform is a technical marathon. To begin, focus on three core pillars:

  1. API Connectivity Stability: Always have a failover plan if the root provider goes down.
  2. Payment Transparency: Automated reconciliation between Bank records and internal wallets must be 100% accurate.
  3. User Experience: A clean Dashboard with one-click installs for popular OS like Ubuntu, CentOS, and Windows Server.

Hopefully, this analysis provides the technical insights needed to design a robust Reseller VPS system that meets the growing demands of the 2026 market!