Custom domains.
SSL managed at the edge.

How SSLforSaaS manages SSL at the edge for registered custom domains, with DNS validation and visible lifecycle status.

Less work, more productivity

From adding a domain and configuring DNS to tracking certificate status in the app.

1
Register the domain
Add each domain in the dashboard or via the project API. DNS alone does not register a domain.
2
Configure and validate DNS
The customer configures DNS using the project-specific target. SSLforSaaS shows DNS and certificate status in the app.
3
Certificate issued
Cloudflare manages certificate issuance while SSLforSaaS shows the current status in the app.
4
HTTPS active
Traffic is seamlessly routed to your application endpoint, now fully encrypted over HTTPS.
01 — On-demand SSL

Managed SSL for every connected domain

SSLforSaaS uses Cloudflare's edge network to provision and serve certificates for customer domains connected to your project. Your customers add the DNS record shown in the app; SSLforSaaS tracks validation, certificate, and routing status from there.

For example, a customer can point www.customerdomain.com to the project-specific target shown by SSLforSaaS while requests are forwarded to your application at app.saas.com. Keep existing traffic in place until the app reports the new hostname as active.

Use the assigned target: Every project receives its own DNS target and status instructions. Do not use a shared sample hostname or IP address for production setup.
Domain status in the app
Managed TLS lifecycle
Customer DNS handoff
Project-specific target
! www.customerdomain.com HTTP — Not Secure http traffic SSLforSaaS Edge Proxy Network Managed edge Checking registered domain... Cloudflare SSL Provisioning time: Varies www.customerdomain.com HTTPS ✓ TLS 1.3 Active Your Application app.saas.com proxied CERTIFICATE STATUS domain: app.example.com status: active ✓ provider: Cloudflare tls: TLSv1.3 timing: Varies expires: 2026-07-09
02 — Setup

A guided path from endpoint to DNS target

After creating your account, enter the application endpoint that should receive customer requests, choose a plan, and complete hosted checkout. Setup then creates a project-specific CNAME target.

Project Settings shows the exact target to share with customers. Subdomains point to it with CNAME; apex domains require a DNS provider that supports ALIAS, ANAME, or CNAME flattening.

Customer-facing experience: Customers browse their own domain while its DNS record points to the project-specific target shown in the app.
Endpoint validation
Hosted checkout
Project CNAME target
Visible provisioning status
SSLforSaaS — Setup Wizard 1 APPLICATION ENDPOINT Where should we send your customer traffic? app.saas.com Verify → 2 PROJECT DNS TARGET Customers will point their domain here ssl.saas.com ✓ CONFIGURATION COMPLETE — Share with your customers: DNS Type: CNAME → ssl.saas.com DNS Type: A Record → project.sslforsaas.io SETUP PROGRESS 90%
03 — Management

Full control from a single dashboard

Once your setup is live, the app shows the state of every connected domain. You can update the application endpoint and configure project request forwarding without selecting or uploading certificate authorities.

Need to route specific traffic differently? Attach multiple custom headers with dynamic values, or configure URL rewrites to match your application's routing logic.

Project webhooks: Subscribe to supported lifecycle events so your application can react to domain and certificate state changes.
Lifecycle status
Project webhooks
Custom headers + rewrites
Scoped API keys
Auto-renewal lifecycle
Dashboard Domains Settings Logs Webhooks API Keys Domains — 3 active + Add domain app.acmecorp.com Cloudflare · TLSv1.3 · Expires 2026-07-12 Active portal.nexuscorp.io SSL · TLSv1.3 · Expires 2026-08-03 Active dash.vertexhq.com Provisioning certificate... Issuing... MINIMUM TLS TLS 1.3 TLS 1.2 App endpoint: app.saas.com Cloudflare proxy: RENEWAL MODE MANAGED domain setup status Renewal state remains visible Next renewal: 2026-06-12 RECENT ACTIVITY app.acmecorp.com — cert renewed successfully 2m ago dash.vertexhq.com — cert issuance in progress now

Performance and reliability as a standard

See DNS validation, certificate setup, and domain activation in the app before you switch customer traffic.

Managed edge routing
Cloudflare handles traffic for connected customer domains while SSLforSaaS shows each domain's setup status.
Managed certificate lifecycle
Cloudflare manages certificate issuance and renewal. Wait for the app to show an active hostname before directing customer traffic.
TLS 1.3 by default
New hostnames default to TLS 1.3. Project settings can select a minimum of TLS 1.2 or 1.3; the setting does not rewrite existing hostnames.
Cloudflare-backed edge
Each project shows its assigned DNS target and validation steps. Some DNS providers need a different setup for apex domains.
Real-time webhooks
Subscribe to project events, verify their signatures, and handle retries using the event ID.
Operational status visibility
See each project's domains, DNS validation, certificate status, and setup progress in the app.
4 plans
Plans for different needs
Included domains and plan features
Tracked
Certificate status
From DNS validation to active
Scoped
Project API access
Explicit key permissions

Common questions

Have a question not covered here? Reach out to our team.

Timing depends on DNS propagation and certificate validation. The app shows progress until the hostname and certificate are active.
Subdomains can use the CNAME target shown in the app. Apex domains require a DNS provider that supports ALIAS, ANAME, or CNAME flattening. In every case, the domain owner must add the required DNS record.
Certificate upload is not available. The project API supports domain setup, status, metrics, and webhook events.
Use the project-specific target shown in Project Settings. Customers point their own subdomain to that value; do not substitute a shared sample target.
Keep the existing route in place until the app reports the new hostname and certificate as active. Cutting DNS over before that state can interrupt traffic.
Cloudflare manages certificate renewal. SSLforSaaS surfaces lifecycle state and supported webhook events without promising a fixed renewal day.
Use SSLforSaaS with an application that accepts traffic for the registered hostname at its configured endpoint. Make sure DNS and certificate checks pass and your endpoint is reachable before directing customer traffic to the domain.
Ready to start?

SSL lifecycle control for
every customer domain.

Set your application endpoint, use the project-specific CNAME target, and wait for the app to show the domain as active.