Connect a Cloudflare domain
Put a custom domain from Cloudflare on your app with automatic HTTPS. One-click (OAuth) setup, the exact DNS records, and how to verify it went live.
Connect a Cloudflare domain
Setup type: One-click (OAuth). You sign in to Cloudflare in a popup and approve the change. No records to copy; no password is shared with the app.
Cloudflare is the smoothest case: it supports native OAuth, so your users click, sign in to Cloudflare, approve, and the records are written for them, no copy-paste. Cloudflare also speaks the Domain Connect standard, but it serves none of our one-click templates, so sign-in is the way in.
What you'll need
- A domain whose DNS is managed at Cloudflare.
- Access to your app's CustomDomain™ dashboard (it shows the exact target for your account).
The records
CustomDomain™ gives you the authoritative records for your account in the dashboard, typically a CNAME (or apex A/ALIAS) pointing your domain at the edge. Use the values shown there; the shape is always the same, the target is per-account. There is no separate ownership TXT to add on this path: control is proven by the rail itself, or by the records appearing in your own authoritative DNS. See Setup types.
Setting it up on Cloudflare
- Enter the domain in the connect flow (the console, or the widget inside the product you're connecting to). It detects Cloudflare and offers to sign in with Cloudflare.
- A Cloudflare sign-in window opens. Approve the requested DNS change.
- The records apply automatically; you're returned to the app, which usually verifies them within seconds and goes live.
Cloudflare specifics
- The OAuth token requests only
dns.writeandzone.read, the minimum to add the records, nothing more. Cloudflare's API requires the dottedresource.actionscope form; the colon form (dns_records:write) is rejected as an invalid scope. - Cloudflare hand-curates its Domain Connect templates and serves none of our 18 (checked 2026-09-28), so one-click setup is not offered. If you would rather not sign in, a scoped API token or adding the records by hand works too.
- A root CNAME is fine: Cloudflare flattens it at the apex.
How you know it worked
CustomDomain™ polls public DNS and issues the TLS certificate automatically. When the dashboard shows the domain live, HTTPS is serving. Drift monitoring then watches the records so a later change at the provider doesn't silently break the domain.
FAQ
Do I have to hand over my Cloudflare API key?
No. The OAuth flow signs you in to Cloudflare directly and asks only for permission to add DNS records. CustomDomain™ never sees your Cloudflare password or a global API key.
Will this touch my other Cloudflare DNS records?
No. The token is scoped to write DNS records for the zone you're connecting; it can't read or change anything outside that.
Related
- All DNS providers, the full connection catalog.
- How custom domains work
Connect a domain by DNS provider
Step by step guides to connect a custom domain from each supported DNS provider, with the exact records and how each provider's setup works.
Connect a DigitalOcean domain
Put a custom domain from DigitalOcean on your app with automatic HTTPS. One-click (OAuth) setup, the exact DNS records, and how to verify it went live.