See the privileges first
Before you paste anything, we show exactly which permissions the credential needs — least privilege, nothing more — so you grant a scoped key rather than a master one.
Bring your own accounts
Already pay for a CDN, DNS provider, Cloudflare or GitHub account? Connect it and we drive it for your sites. Enter the key, we show the privileges required and validate them on entry, then store the credential in Vault. The account joins the pool and is usable across both product lines — under the same origin-record protection as our own accounts, controlled from the dashboard and the MCP.
Connecting an account should be quick and safe at the same time. The flow is the same for every provider.
Before you paste anything, we show exactly which permissions the credential needs — least privilege, nothing more — so you grant a scoped key rather than a master one.
The moment you enter a key we call the provider's API to confirm it is live and correctly scoped, and show a green or red check. An invalid or over-scoped key is refused, not quietly stored.
A validated credential is written to Vault through the same connection seam every account uses. It is never committed to code, printed to a log, or left in an environment file.
The account becomes available for your deploys across both product lines, and can be revoked by you at the provider and removed on our side whenever you like.
You are not limited to the providers we run. There are two tiers, so the long tail is covered without a driver per vendor.
The external accounts that power your sites: CDN providers, DNS providers, your Cloudflare account and your GitHub account. Connect one you already pay for and we drive it for your sites, alongside — or instead of — our own accounts.
We show you the privileges the credential needs, validate it against the provider's API on entry — confirming it is live and correctly scoped, with a green or red check — and only then store it in Vault. We never save an unvalidated or over-scoped key, and the credential never touches code, a log or an environment file.
Yes. A brought account joins the pool and is usable across the Footprint-Free and Mainstream lines under the same product-line and IP-protection policy as our own accounts — including the rule that origin records can never be changed.
Yes, two ways. For popular providers we drive your account through a provider driver bound to your credentials, so purge, SSL and zone management work from our dashboard and MCP — Cloudflare, BunnyCDN, CDN77, KeyCDN, Fastly, Amazon CloudFront, Akamai and more. For anything else, passthrough delegates DNS to the edge you give us, so any CDN works immediately even if we have never integrated it — we just cannot purge or manage its SSL from our side.
Yes. You stay in control of the account and can revoke our access from the provider at any time, and remove the stored connection on our side. Every action taken through a connected account is audit-logged.
Start a card-free 7-day trial and bring your own CDN, DNS, Cloudflare or GitHub account — validated on entry, stored in Vault, and usable across both product lines from the dashboard and the MCP.
Start free