Custom domains
Serve your app’s main version at a domain you own.
Add and verify#
Open App → Settings → Domains and add a hostname, without a scheme or path. Custom domains are available on paid plans. Your organization’s allowance is its effective static-app limit plus container-app limit; each App accepts at most 50 domains. A downgrade keeps existing domains but can prevent new additions.
Copy both DNS records exactly as shown in the console:
| Record | Purpose |
|---|---|
| CNAME for a subdomain | Points to cname.agentlab.run |
| A for an apex | Points to the IPv4 address shown in the console |
TXT at _agentlab-verify.<hostname> | Proves ownership with your organization’s stable token |
Do not put a CNAME at your zone’s apex. Remove conflicting records; IPv6 is not supported. On staging the CNAME target is cname.staging.cresclab.site.
Click Verify after DNS has propagated. Both pointing and TXT records are required, even when a CNAME already exists. Pending claims expire after 14 days. Another organization cannot take the domain using the pointing record alone. A hostname can belong to only one App in an organization; remove it before adding it to another App.
HTTPS and the main version#
Ownership verification starts certificate issuance. Issuing means HTTPS is being prepared; Active means the origin certificate has been checked successfully. The domain follows main, including promotions, rollbacks, password protection and usage limits. It does not serve staging.
You may remove the TXT after successful verification; keep the pointing record. Seven consecutive days of an observed pointing mismatch changes ownership to Lost. Restore both records and verify again. Removing the domain stops serving it and stops certificate renewal.
Cloudflare and CAA#
With Cloudflare, choose DNS only (gray cloud) while verifying and preparing HTTPS. If your DNS has CAA records, permit letsencrypt.org or pki.goog; these are the two supported certificate authorities. An existing CAA policy that permits neither prevents issuance.
Troubleshooting#
- Pending: check both records at the authoritative DNS provider and wait for propagation.
- Pointing mismatch / Lost: restore the displayed pointing record; reverify Lost domains with the TXT as well.
- CAA refuses: update the CAA policy to permit one of the supported authorities.
- Origin TLS unavailable: the direct origin handshake has not succeeded. Check DNS and CAA diagnostics separately; this message does not identify a CA rate limit or a Cloudflare certificate failure.
- Domain taken: another App has verified the hostname. Remove the existing binding before moving it.
The MCP tools are sites_domains_add, sites_domains_list, sites_domains_verify and sites_domains_remove. They take an App, without an environment.