Cloudflare: scoped OAuth
Your user approves the change on Cloudflare's own page. DoDomain writes only the requested records, verifies them, and never stores the grant.
Custom domains for SaaS
Give every user a clear path from “connect my domain” to verified DNS. DoDomain handles provider detection, one-click Cloudflare, guided setup everywhere else, signed webhooks, and the checks that come after launch.
Setting up
app.customer.com
Detecting DNS provider…Your product sends a domain and the records it needs.
DoDomain returns proof when authoritative DNS is live.
DNS is fragmented; your product should not feel that way. DoDomain adapts the setup without changing the contract your backend integrates against.
Your user approves the change on Cloudflare's own page. DoDomain writes only the requested records, verifies them, and never stores the grant.
Provider detection opens the right dashboard and explains its host-field quirks. Every record has an exact value, a copy action, and its own live status.
OAuth consent and redirect callbacks are not proof. Success is declared only after the expected values are confirmed at the authoritative source — the domain's nameservers, or the provider's own API on one-click.
Cloudflare is automated today. These providers have dedicated manual guidance and a universal fallback catches the rest.
The supported integration is plain HTTPS plus a hosted link. The same contract sits underneath the published SDKs and the MCP server agents call.
Your server sends the domain and the DNS records your product needs. The secret key stays server-side; the browser only receives a short-lived session token.
POST /api/v1/sessionsdomain + records + returnUrlOpen the hosted link. DoDomain detects the DNS provider, offers scoped Cloudflare OAuth when available, and falls back to provider-specific instructions everywhere else.
connectUrlone clear path, no dead endA callback is never treated as proof. DoDomain verifies the records at the authoritative source first, records the connection, and then signs the webhook sent to your server.
connection.verifiedHMAC-SHA256 signedCreate an app, keep the dd_sk_… key on your server, and mint a 24-hour session. Send the returned connectUrl to your user. No framework or browser package is required.
Available now: REST API + hosted flow
SDKs: @dodomain/node · @dodomain/connect · @dodomain/react on npm · dodomain-sdk on PyPI
For agents: a remote MCP server, OAuth 2.1, at app.dodomain.io/api/mcp
// Your server
const response = await fetch(
"https://app.dodomain.io/api/v1/sessions",
{
method: "POST",
headers: {
authorization: `Bearer ${DODOMAIN_KEY}`,
"content-type": "application/json"
},
body: JSON.stringify({
domain: "app.customer.com",
records: [{
type: "CNAME", host: "app",
value: "edge.yourproduct.com"
}]}
})
})
});
const { connectUrl } = await response.json();https://app.dodomain.io/connect/dd_sess_…Domains move, records get deleted, and certificates stop renewing. DoDomain keeps rechecking every verified connection against authoritative DNS — every 10 minutes for its first day, hourly for a week, then every 6 hours — and emits an event only when the state actually changes.
connection.verifiedconnection.failed · dns_driftconnection.verified · recoveredEvery tier includes the hosted connect flow and ongoing monitoring. Paid plans add one-click setup and a white-label connect flow; beyond that, choose by monthly connections, applications, and API throughput.
US$0forever
US$24per month, billed annually
US$29US$288/yr2 months free
US$82per month, billed annually
US$99US$984/yr2 months free
Monthly verified-connection allowances come from the same plan definitions the application itself uses. No sales call is required for these self-serve tiers; the enterprise row above is for volume beyond them. See how the quotas work.
DoDomain gives SaaS products a hosted custom-domain setup flow. Your server creates a session with the domain and required DNS records; DoDomain guides or applies those records, verifies them against authoritative DNS, and notifies your server with a signed webhook.
Cloudflare supports the live one-click OAuth path. Detected providers get a provider-specific guided setup with exact records, direct dashboard links, and live verification; unrecognized hosts get the universal guided fallback. DoDomain's Domain Connect templates are merged into the public registry, so a signed one-click apply is available wherever the user's DNS provider has enabled them.
No. DoDomain writes and verifies DNS; traffic goes directly to your infrastructure. TLS terminates at your host, such as Vercel, Cloudflare for SaaS, Render, Fly.io, Caddy, or nginx, so DoDomain is never in the request path.
Both, and the SDKs are published. @dodomain/node is a typed server client (sessions.create, verifyWebhook); dodomain-sdk on PyPI is the Python equivalent, sync and async. On the browser side, @dodomain/connect embeds the hosted flow as a theme-matched sheet inside your own UI, and @dodomain/react wraps it in a useDoDomainConnect hook. The plain REST API and the hosted connect link stay fully supported — the SDKs are a convenience over the same shapes, not a requirement.
Yes. DoDomain runs a remote MCP server at app.dodomain.io/api/mcp, so Claude and any other MCP client can check a domain's DNS provider, mint a connect session, and trigger verification. Clients sign in with OAuth 2.1 rather than a pasted key, you approve the scopes on a consent screen, and every tool calls the same /api/v1 endpoints your integration uses, so permissions and limits apply identically.
DoDomain re-checks every established connection automatically — every 10 minutes for a connection's first day, then hourly for a week, then every 6 hours. Suspected drift is re-checked within minutes and confirmed before you're alerted: the connection is marked broken and connection.failed is sent; when the records return, connection.verified fires with a recovery signal. Monitoring is included on every plan.
Yes. The Free plan is free forever and includes the hosted connect flow with guided DNS setup, authoritative verification, and DNS drift monitoring — no card required. One-click setup and the white-label connect flow are part of Pro and Scale. Pro and Scale are billed monthly or annually; choosing annual billing gives you 2 months free. You can cancel a paid plan at any time from the subscription-management email.
Create the session. Let the user connect. Wait for the signed proof.