Docs / Networking

TLS certificates

Available

Default service URLs

{serviceId}.isoward.com hostnames use Cloudflare Universal SSL on the operator's zone. No certificate action is required for customers using default URLs.

Custom domains (platform TLS)

When the operator configures Cloudflare for SaaS (CF_API_TOKEN + CF_ZONE_ID), Isoward provisions a custom hostname certificate for each customer domain via the Cloudflare API. The free tier includes 100 custom hostnames; additional hostnames are billed by Cloudflare at a low per-hostname rate.

Certificate status appears in Dashboard → Settings → Custom domains (pending validation / active). Customers still CNAME their hostname to {serviceId}.isoward.com and click Verify.

If Cloudflare for SaaS is not configured, terminate TLS at your own DNS/CDN (for example Cloudflare SSL mode Full) — routing still works after DNS verification.

CAA records

If your domain defines CAA records, allow Cloudflare's CAs (or your chosen TLS provider) to issue certificates for the hostname.

See Custom domains and Cloudflare tunnel setup for operators.