Docs
Domains
Put an app on a hostname you already own, with HTTPS. Tofu proves you own it by a record it reads back, and on Cloudflare one approval replaces copying records by hand.
Agent tools
domainsdomainConnectdomainAuthorizedomainVerifydomainGuidancedomainRelease
Connecting a hostname
Both steps need paid hosting, and they are the same in the dashboard’s Domains page and in your agent.
Claim it
Claim a hostname you already own in Domains, or with
domainConnect: Tofu returns a_tofu.<hostname>TXT challenge and, later, the routing records.Create the records
On a domain Cloudflare serves, approve Tofu once on Cloudflare's own screen (
domainAuthorize) and Tofu writes those records itself; anywhere else, you create them at your DNS provider.Verify
Tofu re-reads the challenge over DNS-over-HTTPS, verifies the hostname with the hosting provider and prepares the certificate (
domainVerify).Connected
The hostname is advertised as connected only after Tofu reads it back and sees the deployment that passed its health check.
One approval on Cloudflare
Copying DNS records by hand is the step owners actually fail. On a domain Cloudflare serves, you open one link — signed in to Tofu as the account that owns the app — and approve Tofu on Cloudflare's own screen; Tofu then writes the records it had already asked for. The proof of ownership does not move: the _tofu challenge is still read back, so the approval replaces the copy-paste, not the verification.
The approval is offered only for a zone Cloudflare actually serves: Tofu reads the zone's nameservers first, and a zone served by somebody else gets that provider's name and the record instructions instead of a button.
There is no field for an API key or a token anywhere: an approval is a link you open on the provider's own screen, and Tofu can withdraw it (domainAuthorizationRevoke, the dashboard's Withdraw authorization).
Anywhere else
You create the records at your DNS provider, and Tofu shows exactly which. The Domains page — and domainGuidance for your agent — also reads the DNS you are about to change: who serves the zone, the steps for that provider, and any existing record that would fight the one Tofu asks for. That read writes nothing.
Propagation takes minutes. Verifying again later reports the state as it is, rather than a connection that has not happened.
What each state means
| State | What it means |
|---|---|
ownership_pending | The _tofu TXT record is missing or has not propagated yet. |
dns_pending | Ownership is proven; the routing records are still pending. |
certificate_pending | HTTPS is being prepared. |
connected | Read back, and serving the deployment that passed its health check. |
disconnecting | The connection is being removed. |
error | The row carries the explanation. |
Rules
- Each proven hostname is unique across all Tofu projects, and a project may claim at most ten. A hostname connects only to the app that published it.
- A connected domain does not replace the app's managed address.
domainRelease, the dashboard's Disconnect, withdraws any approval Tofu holds and removes the connection. Your registration and the records you created stay with your provider.- Sending sign-up email from your domain uses its own records, all under
send.— see Sign-in & email.
Limits
What Tofu does not do with domains
Sell them. Tofu connects a hostname; it does not sell registrations. Buying a domain inside Tofu is deliberately not enabled: the path exists in code with no enable flag and no merchant integration, so no card data is accepted. You buy, renew and transfer at your registrar.
Write DNS without your approval. Records are written only through the approval you gave on Cloudflare’s own screen; everywhere else they are yours to create.
Take a credential. No form, tool or message accepts a DNS API key, token or password.
The ship-it layer for vibe-coded apps. Your agent wrote it — Tofu ships it.
Works in all coding agents
© 2026 Tofu
trytofu.ai