Stable
Private apps that open on the customer domain
Publish a private app on a verified customer-owned domain with app-domain sign-in, domain-scoped passkeys and strict launch modes.
Steps
Follow these in order.
- 01The link looks like the customer environmentFor partners, MSPs and customer-facing private apps, the public address matters. A verified customer domain is easier to approve, send in onboarding material and recognize in the browser.
- 02Choose how the app may be openedEach app domain can use branded portal, BusinessProxy portal or extension-required launch depending on the customer rollout and risk boundary.
- 03Not full white-label platform identityBranded app access does not replace the BusinessProxy dashboard, legal publisher identity, email sender or billing relationship. It brands the selected app entry point while preserving BusinessProxy product and legal boundaries.
Reference
Implementation details for setup and review.
- Verified customer-owned domain
- App-domain sign-in
- Domain-scoped passkeys
- Extension-required launch mode
- DNS verification: The app domain is created only after the customer proves domain ownership through the required DNS record.
- Certificate and domain state: The app domain has explicit status, certificate lifecycle and launch-mode configuration.
- Passkey RP per host: Passkeys are scoped to the app domain; they do not silently move between unrelated domains.
- Branded portal keeps sign-in on the app domain.
- Extension-required mode is explicit for extension-only applications.
- Disabled private apps do not issue new app sessions.
- The internal app host and private IP stay outside the user-facing URL.
- Full platform white-label is not included.
- Passkeys do not move across unrelated domains.
- This is not a device-wide VPN or endpoint-control product.