Stable

Private apps that open on the customer domain

Publish a private app on a verified customer-owned domain with app-domain sign-in, domain-scoped passkeys and strict launch modes.

Steps

Follow these in order.

  1. 01The link looks like the customer environmentFor partners, MSPs and customer-facing private apps, the public address matters. A verified customer domain is easier to approve, send in onboarding material and recognize in the browser.
  2. 02Choose how the app may be openedEach app domain can use branded portal, BusinessProxy portal or extension-required launch depending on the customer rollout and risk boundary.
  3. 03Not full white-label platform identityBranded app access does not replace the BusinessProxy dashboard, legal publisher identity, email sender or billing relationship. It brands the selected app entry point while preserving BusinessProxy product and legal boundaries.

Reference

Implementation details for setup and review.

Customer-owned app domainsA user opens crm.apps.customer.com instead of a technical BusinessProxy link. The app domain is verified through DNS, the sign-in surface belongs to that app address and the internal upstream remains hidden behind the connector.
  • Verified customer-owned domain
  • App-domain sign-in
  • Domain-scoped passkeys
  • Extension-required launch mode
The link looks like the customer environmentFor partners, MSPs and customer-facing private apps, the public address matters. A verified customer domain is easier to approve, send in onboarding material and recognize in the browser.
  • DNS verification: The app domain is created only after the customer proves domain ownership through the required DNS record.
  • Certificate and domain state: The app domain has explicit status, certificate lifecycle and launch-mode configuration.
  • Passkey RP per host: Passkeys are scoped to the app domain; they do not silently move between unrelated domains.
Choose how the app may be openedEach app domain can use branded portal, BusinessProxy portal or extension-required launch depending on the customer rollout and risk boundary.
  • Branded portal keeps sign-in on the app domain.
  • Extension-required mode is explicit for extension-only applications.
  • Disabled private apps do not issue new app sessions.
  • The internal app host and private IP stay outside the user-facing URL.
Not full white-label platform identityBranded app access does not replace the BusinessProxy dashboard, legal publisher identity, email sender or billing relationship. It brands the selected app entry point while preserving BusinessProxy product and legal boundaries.
  • Full platform white-label is not included.
  • Passkeys do not move across unrelated domains.
  • This is not a device-wide VPN or endpoint-control product.