Features · Domains

Your domain, HTTPS included.

Connect a hostname you already own to a paid app. Tofu proves it is yours, prepares the certificate, and calls it connected only once the live address reads back — on Cloudflare, after a single approval.

Read the docsAgent setup

What your agent calls

  • domainConnect
  • domainAuthorize
  • domainAuthorizationStatus
  • domainVerify
  • domainGuidance
claude · ~/franks-kitchenexample

Connect frankskitchen.com

tofu · domainConnect frankskitchen.com

ownership_pending · _tofu TXT record

tofu · domainAuthorize

DNS approval is waiting · approve in your browser

tofu · domainVerify

Connected to your current healthy live version. HTTPS is configured.

How a hostname connects

Proven, then served. Never the other way round.

Every step is read back before the next one starts, so the dashboard and your agent only ever report what Tofu could see.

  1. Claim the hostname

    From the Domains page or domainConnect: Tofu hands back a fresh _tofu TXT challenge for exactly that name.

  2. Prove it is yours

    Tofu reads the challenge back over DNS-over-HTTPS on every check. A parent domain does not prove a child, and an old challenge does not prove a new claim.
  3. Route it, and prepare HTTPS

    The hosting provider verifies the name, the routing record points it at your app, and a certificate is prepared for it.
  4. Connected, after a read-back

    Only once the name answers from your healthy live version — the one its health check accepted. Until then, your app keeps serving at its own address.
Verify ownershipownership_pendingDNS pendingdns_pendingHTTPS pendingcertificate_pendingConnectedconnected
One click on Cloudflare

Approve once. Tofu writes the records.

If Cloudflare serves your domain, skip the copying. Open the link Tofu gives you while signed in to Tofu, and approve Tofu on Cloudflare’s own screen. Tofu then writes the records the connection asked for, in that one zone, and checks straight away instead of on the next minute.

There is no field for an API key anywhere. The approval is the credential: stored encrypted, and yours to withdraw from Tofu or from Cloudflare’s own dashboard.

A record that already holds a different value is never overwritten — Tofu tells you which one to resolve. And the button is not offered for a zone another provider serves, where the approval could write nothing.

DNS accessauthorized
Zone
frankskitchen.com one zone
Scopes
zone.read dns.write
Writes
_tofu and the routing record
Proxy
off, on every record
Keys pasted
none

Access approved. Tofu may write DNS records in this one zone.

Anywhere else

The exact records, checked for you.

The Domains page first reads the zone you are about to change — who serves it, what is already at the name, what would conflict — and writes nothing. Then it lists the records to add, and checks them the moment you say they are saved.

TypeNameValue
TXT_tofu.frankskitchen.comtofu-verification=… — keep it while connected
TXT_vercel.frankskitchen.comThe hosting provider’s own check, when it asks for one — shown as it gives it
A or CNAMEfrankskitchen.comThe routing record the hosting provider recommends — shown as it gives it

Each row also shows the short name a DNS host that appends the zone expects (_tofu, @), so a pasted name never doubles the domain.

Your agent can add them with your own DNS tooling, on your machine — Tofu never asks for a DNS password or key. A record saved after a resolver already asked can stay hidden for the zone’s negative-cache window; the card names how long, and whose limit it is.

The rules

One name, one app. Your address stays.

  • Per app

    Up to 10 hostnames

    Each one claimed, and proven, on its own.

  • Per hostname

    One app across all of Tofu

    A proven name cannot be claimed by another app until its owner disconnects it.

  • Apex and www

    Two names, two claims

    A connection covers exactly the name you claimed; the card offers frankskitchen.com’s www sibling so you can connect it too.

  • Your address

    trytofu.app stays

    A domain is added beside your app’s own trytofu.app address, never in place of it — and that address keeps working.

Limits

What is not here yet

What a domain connection on Tofu does not do.

  • No buying, renewing or transferring a domain. Search and quotes exist, but buying inside Tofu is switched off: you buy at a registrar, then connect the name here.

  • One-click setup is Cloudflare only. On any other DNS host, you — or your agent, with your own DNS tooling — add the records Tofu lists.

  • Records stay when you disconnect. Disconnecting withdraws the approval first, then the connection; the records Tofu wrote stay in your zone, listed so you can delete them where they live.

  • A paid plan, and a deployed app. A custom domain points at a live version, so the app has to be deployed first.

  • One exact hostname per claim. No wildcards, URLs or IP addresses.

  • No mail or nameserver changes. Connecting a domain moves no nameservers and writes no mail records. Sign-up email from your domain is its own step, under send. — see Sign-in & email.

Paste one line. Go live.

Your app, its database, your domain and your sign-in — from the agent you already use, in about 10 minutes.

I want to take my product live with Tofu. Fetch https://app.trytofu.ai/agent/prompt.txt and follow the setup instructions in it, then help me ship this app.
Join Waitlist
Early access · every preview is labelled in your dashboard.