---
title: Custom domains
description: Serve your app’s main version at a domain you own.
url: https://agentlab.cresclab.com/docs/en/deploy/custom-domains
language: en
updated: 2026-10-08
---

# Custom domains

Serve your app’s main version at a domain you own.

## Add and verify

Open **App → Settings → Domains** and add a hostname, without a scheme or path. Custom domains are available on paid plans. Your organization’s allowance is its effective static-app limit plus container-app limit; each App accepts at most 50 domains. A downgrade keeps existing domains but can prevent new additions.

Copy both DNS records exactly as shown in the console:

| Record                               | Purpose                                                |
| ------------------------------------ | ------------------------------------------------------ |
| CNAME for a subdomain                | Points to `cname.agentlab.run`                         |
| A for an apex                        | Points to the IPv4 address shown in the console        |
| TXT at `_agentlab-verify.<hostname>` | Proves ownership with your organization’s stable token |

Do not put a CNAME at your zone’s apex. Remove conflicting records; IPv6 is not supported. On staging the CNAME target is `cname.staging.cresclab.site`.

Click **Verify** after DNS has propagated. Both pointing and TXT records are required, even when a CNAME already exists. Pending claims expire after 14 days. Another organization cannot take the domain using the pointing record alone. A hostname can belong to only one App in an organization; remove it before adding it to another App.

## HTTPS and the main version

Ownership verification starts certificate issuance. **Issuing** means HTTPS is being prepared; **Active** means the origin certificate has been checked successfully. The domain follows main, including promotions, rollbacks, password protection and usage limits. It does not serve staging.

You may remove the TXT after successful verification; keep the pointing record. Seven consecutive days of an observed pointing mismatch changes ownership to **Lost**. Restore both records and verify again. Removing the domain stops serving it and stops certificate renewal.

## Cloudflare and CAA

With Cloudflare, choose **DNS only** (gray cloud) while verifying and preparing HTTPS. If your DNS has CAA records, permit `letsencrypt.org` or `pki.goog`; these are the two supported certificate authorities. An existing CAA policy that permits neither prevents issuance.

## Troubleshooting

- **Pending:** check both records at the authoritative DNS provider and wait for propagation.
- **Pointing mismatch / Lost:** restore the displayed pointing record; reverify Lost domains with the TXT as well.
- **CAA refuses:** update the CAA policy to permit one of the supported authorities.
- **Origin TLS unavailable:** the direct origin handshake has not succeeded. Check DNS and CAA diagnostics separately; this message does not identify a CA rate limit or a Cloudflare certificate failure.
- **Domain taken:** another App has verified the hostname. Remove the existing binding before moving it.

The MCP tools are `sites_domains_add`, `sites_domains_list`, `sites_domains_verify` and `sites_domains_remove`. They take an App, without an environment.
