https://verify.yourcompany.com — carrying your logo, your colors, and your name in the address bar.
Only the signer-facing pages move. Your own team keeps using the Conduit dashboard at its normal address, so your admin and login surface stays separate from the pages you hand to third parties.
Setup happens in the Conduit dashboard, not through the API. There are no endpoints on this page. Budget a few minutes plus however long your DNS provider takes to publish changes.
Prerequisites
- A subdomain you control, such as
verify.yourcompany.comorpay.yourcompany.com. Root domains likeyourcompany.comare not supported. - Access to your DNS, either directly or through whoever manages it.
- An admin on your organization, because enabling the domain requires an admin approval.
Set up the domain
1
Enter the address
Go to Settings → Custom domains, type the subdomain you plan to use, and click Add.
2
Copy the two DNS records
The page shows exactly what to create, each row with a copy button. One record proves the domain is yours; the other points it at Conduit.
3
Add the records at your DNS provider
Paste both rows into Cloudflare, Route 53, GoDaddy, or wherever your DNS lives.
4
Verify
Click Verify. Conduit checks both records live and reports, per record, whether it matched and what is wrong when it did not.
5
Wait for Active
Once verification passes, Conduit obtains the HTTPS certificate automatically. The page shows an Issuing state and flips to Active when the domain is live, usually within a few minutes. No refresh needed.
If your DNS publishes CAA records
Most domains do not. A CAA record is a list of certificate authorities allowed to issue for your domain, and Conduit’s certificates come from Let’s Encrypt. If you have CAA records and Let’s Encrypt is not among them, add:
It goes on your root domain, not on the subdomain. A name holding a CNAME may hold no other record, so your DNS provider will reject a CAA record at
verify.yourcompany.com. Conduit climbs from the subdomain until it finds a CAA set, and your root is the first one it reaches.
Verify tells you explicitly when this is the blocker.
Statuses
When a check fails, the page tells you what to fix in plain language rather than showing a raw error.
Certificates are handled for you
You never generate a key, produce a certificate signing request, or upload a certificate. Conduit requests the certificate and renews it for the life of the domain. Nothing expires on your calendar, and there is no renewal fee.Keep the DNS records in place
Conduit rechecks your records daily. If they disappear, the domain moves to Failed and keeps serving for 72 hours after the last successful check, then switches off. Restoring the records and clicking Verify brings the domain back at any point, before or after it switches off.Plan for passkeys
Your customers’ signers approve payments with passkeys, and a passkey is permanently tied to the single web address where it was created. That is a browser security rule, not a Conduit choice, so a passkey created on a Conduit address cannot be used on yours.Turning the domain on first does not avoid this. A signer’s first passkey is always created on the Conduit address, because the link that enrols them can only move to your domain once they already hold a passkey there.
- When your domain goes live, Conduit emails a link to every signer who does not yet have a passkey on it. This email is sent once, on that transition.
- The link opens a page on the Conduit address where the signer signs in with their existing passkey. The email is not a credential — on its own it grants nothing.
- Once signed in, the signer is moved to your domain and creates a new passkey there.
There is no deadline. Until a signer re-enrols they keep receiving links on the Conduit address, and their original passkey is kept as a working fallback — so a half-finished migration is harmless and nobody loses access.
Turn it off
Removal is self-serve from the same settings page; admins do not need to contact support. Verification links immediately go back to the Conduit address, and your signers’ original passkeys keep working. The one case that needs work first is signers who have only ever had a passkey on your domain, meaning they joined after it went live. Conduit blocks removal and names them, so you can move them back before anything is switched off rather than discovering a lockout afterwards. To clear each named signer, give them a passkey on the Conduit address: send them to/signer-profile/migrate on your own domain, which runs the move in reverse, or run credential recovery for them. Once every named signer holds one, removal goes through.
What happens next
- A signer’s own activation link moves to your domain as soon as that signer re-enrols. Payout-approval links go to everyone who might approve, so they stay on the Conduit address until every signer has re-enrolled. The flow is unchanged either way — see Non-custodial payout lifecycle.
- Your webhook payloads carry the verification URL, which may be on your domain or on the Conduit address while signers are still re-enrolling. Treat the URL as opaque and always use the most recent one you received.
- Branding on the signer pages comes from the logo and colors you configure under Branding.