Features · Domains
Your domain, HTTPS included.
Connect a hostname you already own to a paid app. Tofu proves it is yours, prepares the certificate, and calls it connected only once the live address reads back — on Cloudflare, after a single approval.
What your agent calls
domainConnectdomainAuthorizedomainAuthorizationStatusdomainVerifydomainGuidance
Connect frankskitchen.com
tofu · domainConnect frankskitchen.com
ownership_pending · _tofu TXT record
tofu · domainAuthorize
DNS approval is waiting · approve in your browser
tofu · domainVerify
Connected to your current healthy live version. HTTPS is configured.
How a hostname connects
Proven, then served. Never the other way round.
Every step is read back before the next one starts, so the dashboard and your agent only ever report what Tofu could see.
Claim the hostname
From the Domains page or
domainConnect: Tofu hands back a fresh_tofuTXT challenge for exactly that name.Prove it is yours
Tofu reads the challenge back over DNS-over-HTTPS on every check. A parent domain does not prove a child, and an old challenge does not prove a new claim.Route it, and prepare HTTPS
The hosting provider verifies the name, the routing record points it at your app, and a certificate is prepared for it.Connected, after a read-back
Only once the name answers from your healthy live version — the one its health check accepted. Until then, your app keeps serving at its own address.
ownership_pendingDNS pendingdns_pendingHTTPS pendingcertificate_pendingConnectedconnectedApprove once. Tofu writes the records.
If Cloudflare serves your domain, skip the copying. Open the link Tofu gives you while signed in to Tofu, and approve Tofu on Cloudflare’s own screen. Tofu then writes the records the connection asked for, in that one zone, and checks straight away instead of on the next minute.
There is no field for an API key anywhere. The approval is the credential: stored encrypted, and yours to withdraw from Tofu or from Cloudflare’s own dashboard.
A record that already holds a different value is never overwritten — Tofu tells you which one to resolve. And the button is not offered for a zone another provider serves, where the approval could write nothing.
- Zone
- frankskitchen.com one zone
- Scopes
zone.readdns.write- Writes
_tofuand the routing record- Proxy
- off, on every record
- Keys pasted
- none
Access approved. Tofu may write DNS records in this one zone.
Anywhere else
The exact records, checked for you.
The Domains page first reads the zone you are about to change — who serves it, what is already at the name, what would conflict — and writes nothing. Then it lists the records to add, and checks them the moment you say they are saved.
| Type | Name | Value |
|---|---|---|
| TXT | _tofu.frankskitchen.com | tofu-verification=… — keep it while connected |
| TXT | _vercel.frankskitchen.com | The hosting provider’s own check, when it asks for one — shown as it gives it |
| A or CNAME | frankskitchen.com | The routing record the hosting provider recommends — shown as it gives it |
Each row also shows the short name a DNS host that appends the zone expects (_tofu, @), so a pasted name never doubles the domain.
Your agent can add them with your own DNS tooling, on your machine — Tofu never asks for a DNS password or key. A record saved after a resolver already asked can stay hidden for the zone’s negative-cache window; the card names how long, and whose limit it is.
The rules
One name, one app. Your address stays.
Per app
Up to 10 hostnames
Each one claimed, and proven, on its own.
Per hostname
One app across all of Tofu
A proven name cannot be claimed by another app until its owner disconnects it.
Apex and www
Two names, two claims
A connection covers exactly the name you claimed; the card offers frankskitchen.com’s www sibling so you can connect it too.
Your address
trytofu.app stays
A domain is added beside your app’s own trytofu.app address, never in place of it — and that address keeps working.
Limits
What is not here yet
What a domain connection on Tofu does not do.
No buying, renewing or transferring a domain. Search and quotes exist, but buying inside Tofu is switched off: you buy at a registrar, then connect the name here.
One-click setup is Cloudflare only. On any other DNS host, you — or your agent, with your own DNS tooling — add the records Tofu lists.
Records stay when you disconnect. Disconnecting withdraws the approval first, then the connection; the records Tofu wrote stay in your zone, listed so you can delete them where they live.
A paid plan, and a deployed app. A custom domain points at a live version, so the app has to be deployed first.
One exact hostname per claim. No wildcards, URLs or IP addresses.
No mail or nameserver changes. Connecting a domain moves no nameservers and writes no mail records. Sign-up email from your domain is its own step, under
send.— see Sign-in & email.
Paste one line. Go live.
Your app, its database, your domain and your sign-in — from the agent you already use, in about 10 minutes.
The ship-it layer for vibe-coded apps. Your agent wrote it — Tofu ships it.
Works in all coding agents
© 2026 Tofu
trytofu.ai