Bring your own accounts

Connect your own CDN, DNS, Cloudflare and GitHub accounts

Already pay for a CDN, DNS provider, Cloudflare or GitHub account? Connect it and we drive it for your sites. Enter the key, we show the privileges required and validate them on entry, then store the credential in Vault. The account joins the pool and is usable across both product lines — under the same origin-record protection as our own accounts, controlled from the dashboard and the MCP.

  • CDN, DNS, CF, GitHubconnect what you have
  • Validated on entryprivileges shown first
  • Vault-storednever in code or logs
  • Across both linesone shared policy

Enter a key, we do the rest safely

Connecting an account should be quick and safe at the same time. The flow is the same for every provider.

See the privileges first

Before you paste anything, we show exactly which permissions the credential needs — least privilege, nothing more — so you grant a scoped key rather than a master one.

Validated on entry

The moment you enter a key we call the provider's API to confirm it is live and correctly scoped, and show a green or red check. An invalid or over-scoped key is refused, not quietly stored.

Straight into Vault

A validated credential is written to Vault through the same connection seam every account uses. It is never committed to code, printed to a log, or left in an environment file.

Added to the pool

The account becomes available for your deploys across both product lines, and can be revoked by you at the provider and removed on our side whenever you like.

Even a CDN we don't operate

You are not limited to the providers we run. There are two tiers, so the long tail is covered without a driver per vendor.

  • Full integration for popular providers: we drive your account through a provider driver bound to your credentials, so purge, SSL and zone management all work from our dashboard and MCP.
  • The tier-1 set includes the ones we also operate — Cloudflare, BunnyCDN, CDN77, KeyCDN, Fastly — plus common brought accounts like Amazon CloudFront and Akamai.
  • Passthrough for anything else: we delegate DNS to the CNAME or edge you provide, so any CDN works immediately, even one we have never integrated.
  • The passthrough trade-off is that you manage purge and SSL in your own CDN panel — we handle the DNS delegation, you handle the edge.
  • Every brought account flows through the same credential-to-Vault seam and the same product-line and IP-protection policy as our own.

FAQ

Which accounts can I connect?

The external accounts that power your sites: CDN providers, DNS providers, your Cloudflare account and your GitHub account. Connect one you already pay for and we drive it for your sites, alongside — or instead of — our own accounts.

What happens when I enter a key?

We show you the privileges the credential needs, validate it against the provider's API on entry — confirming it is live and correctly scoped, with a green or red check — and only then store it in Vault. We never save an unvalidated or over-scoped key, and the credential never touches code, a log or an environment file.

Can a connected account be used on both product lines?

Yes. A brought account joins the pool and is usable across the Footprint-Free and Mainstream lines under the same product-line and IP-protection policy as our own accounts — including the rule that origin records can never be changed.

Can I connect a CDN you don't operate?

Yes, two ways. For popular providers we drive your account through a provider driver bound to your credentials, so purge, SSL and zone management work from our dashboard and MCP — Cloudflare, BunnyCDN, CDN77, KeyCDN, Fastly, Amazon CloudFront, Akamai and more. For anything else, passthrough delegates DNS to the edge you give us, so any CDN works immediately even if we have never integrated it — we just cannot purge or manage its SSL from our side.

Can I revoke access later?

Yes. You stay in control of the account and can revoke our access from the provider at any time, and remove the stored connection on our side. Every action taken through a connected account is audit-logged.

Connect your accounts

Start a card-free 7-day trial and bring your own CDN, DNS, Cloudflare or GitHub account — validated on entry, stored in Vault, and usable across both product lines from the dashboard and the MCP.

Start free