CustomDomain™ docs
Connect flow

Where domains point

Send customer domains through the CustomDomain™ edge with automatic SSL, or point them straight at your own infrastructure.

Every connection's records point somewhere, and an application chooses where once. The default record set, the pre-flight check, verification and the live DNS diagnosis all follow that choice, so the records your customers see are always the ones that will work.

Through the edge (default)Your own infrastructure
Subdomain recordCNAME to edge.customdomain.aiCNAME to your hostname
Root recordALIAS/ANAME/flattened CNAME to the edge, or A records to the edge's addressesALIAS-style record to your hostname, or A records to the addresses you list
TLS certificatesIssued and renewed by the edge on first requestYours to issue (your load balancer, TLS proxy or CDN)
Root to www redirectServed by the edgeYours to serve
PlansPower (Growth and up)Every plan, including Free

In the console both live under Domain routing.

Through the edge

The edge terminates TLS and proxies each request to your origin, passing the customer's hostname in X-Forwarded-Host so one origin can serve every customer. Set that origin once for the whole application:

curl -X PUT https://api.customdomain.ai/v1/applications/<APP_ID>/power:default \
  -H "Authorization: Bearer cd_live_..." \
  -H "Content-Type: application/json" \
  -d '{ "default_origin": "https://app.example.com" }'

A connection can override it with its own origin (POST /v1/connections/{id}/power). The edge uses the connection's origin first, then the application default; with neither it answers 421, so set the default before your first customer connects.

Your own infrastructure

Name your own destination with a connection target. Customer subdomains get a CNAME to cname_target; roots get an ALIAS-style record to it where the DNS provider has one, and otherwise A records to each address in apex_ipv4 (up to four public IPv4 addresses):

curl -X PUT https://api.customdomain.ai/v1/applications/<APP_ID>/connect-target \
  -H "Authorization: Bearer cd_live_..." \
  -H "Content-Type: application/json" \
  -d '{ "cname_target": "customers.example.com", "apex_ipv4": ["203.0.113.10"] }'
  • cname_target must be a hostname, not an IP address and not the edge itself. Send "" to point the application back at the edge.
  • Without apex_ipv4, a root domain at a provider with no ALIAS-style record cannot be pointed at you. The pre-flight says so up front (apex_strategy: "unsupported") and the widget steers that customer to www or a subdomain.
  • Traffic never passes through the edge in this mode, so certificates and the root to www redirect are yours to serve. www_redirect: true still adds the www record.
  • Pick the target before customers connect. Changing it changes the records new connections get and are checked against; records already written to a provider stay as written until you reapply the connection (POST /v1/connections/{id}:reapply), and customers who added records by hand need to update them.

GET /v1/applications/{id}/connect-target returns the current mode (edge or custom), the target, and what the edge mode would point at, so a settings screen can show both.

See also Root domains and Verify and go live.

On this page