> ## Documentation Index
> Fetch the complete documentation index at: https://www.wirebase.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Custom domain

> Serve your Wirebase workspace on your own domain, with your branding and access rules.

## Overview

Map a domain you own, such as `ai.yourcompany.com`, to your organization. Members use Wirebase at that address, with a sign-in page in your brand, and you control who can sign in there.

Custom domain and white-label are part of the **Enterprise** plan. Configure them in **Admin → Settings → Custom Domain**.

## Connect your domain

<Steps>
  <Step title="Enter the domain">
    Enter the domain or subdomain you want to use, for example `ai.yourcompany.com`.
  </Step>

  <Step title="Add a CNAME record">
    At your DNS provider, add the **CNAME** record shown on the page. It routes traffic to Wirebase, and an SSL certificate is issued automatically.
  </Step>

  <Step title="Add a TXT record">
    Add the **TXT** record shown on the page at `_wirebase-verify.<your-domain>`. It proves you own the domain.
  </Step>

  <Step title="Verify">
    Once both records are in place, click **Verify**. DNS changes can take up to 48 hours to propagate. When verification succeeds, the status changes from **Pending Verification** to **Active**.
  </Step>
</Steps>

<Warning>
  If your domain has a CAA DNS record, it must allow the certificate authority used for custom domains (`ssl.com`), or the SSL certificate can't be issued. If you have no CAA record, there's nothing to do.
</Warning>

## Access rules

The **Access** tab controls sign-in on your domain only. Sign-in on [www.wirebase.com](http://www.wirebase.com) is unaffected, and every rule is enforced server-side.

| Rule | Effect |
| - | - |
| **Members of this organization only** | Anyone signed in with an account outside your organization is blocked on this domain. |
| **Email and password** | Turn off to require single sign-on. This also disables password reset on the domain. |
| **Single sign-on (SAML / OIDC)** | Sign in through your configured [identity provider](/docs/admin-guide/security/sso). |
| **Open sign-up** | Off by default: new accounts can only be created by invitation or through your IdP. |
| **Allowed sign-up email domains** | Restrict sign-ups to specific email domains, such as `yourcompany.com`. |

<Note>
  Google, GitHub and Microsoft sign-in aren't available on a custom domain. Use SSO or invitations instead.
</Note>

## White-label branding

The **White-label** tab customizes the sign-in page on your domain: **Brand Color**, **Favicon URL**, **Login Page Title**, **Login Page Copy** and **Custom CSS**, with a live **Login Page Preview**. Your organization's name and logo come from [Branding](/docs/admin-guide/settings/branding).

## Remove the domain

Click **Remove Domain**. The domain stops routing to your organization immediately, its SSL certificate is revoked, and its white-label settings are deleted.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.