Cloudflare SaaS SSL

Cloudflare SaaS SSL is a plugin for Premium URL Shortener that provisions Cloudflare Custom Hostnames (SSL for SaaS) for customer branded domains. Customers point their domain with a CNAME and receive an SSL certificate automatically — with a guided DNS setup inside the dashboard.

Once configured, users who have branded domains on their plan see a Domain SSL menu and can track certificate status until it becomes active.

Features

  • Automatic SSL certificates for customer branded domains via Cloudflare for SaaS
  • Guided CNAME / DNS setup with copy-to-clipboard records
  • Ownership verification (TXT) when Cloudflare requires it
  • Live hostname and SSL status with refresh
  • Optional auto-provision when a branded domain is added
  • Admin connection settings, test connection, and hostnames overview
  • Configurable SSL validation method (HTTP or TXT) and minimum TLS version
  • Automatic cleanup when a branded domain is deleted

Requirements

Premium URL ShortenerVersion 8.0 or higher (branded domains enabled)
PHPVersion 8.2+
CloudflareZone with Cloudflare for SaaS enabled
API TokenSSL and Certificates Write on your SaaS zone

Installation

  1. Extract the zip file downloaded after purchase
  2. Go to your site Admin Plugins All Plugins
  3. Click on Upload and upload the file named cloudflaresaas.zip
  4. Click on the three dots then Activate
  5. Go to Admin Cloudflare SaaS Settings to configure it

If the uploader does not work, extract cloudflaresaas.zip into storage/plugins/. The folder must be named cloudflaresaas. Then activate it in the admin panel.

Activation creates the plugin database table and default settings automatically.

Cloudflare Setup

Before configuring the plugin, prepare your Cloudflare zone for SaaS (Custom Hostnames). Follow Cloudflare’s official getting-started guide, then complete this checklist:

  1. Enable Cloudflare for SaaS on your zone.
  2. Create a fallback origin and the DNS record for it.
  3. Note your Zone ID (Cloudflare Dashboard Overview).
  4. Create an API token with SSL and Certificates — Write on that zone.
  5. Decide your CNAME target (fallback hostname), e.g. customers.yourdomain.com — customers will CNAME their branded domains to this host.

Official reference: Cloudflare for SaaS — Getting started.

Plugin Configuration

Go to Admin Cloudflare SaaS Settings and fill in the connection details:

Enable Cloudflare SaaS SSL

When enabled (and credentials are saved), customers with branded domains can provision SSL.

API Token

Cloudflare API token with SSL and Certificates Write. Leave the field unchanged when editing other settings to keep the current token.

Zone ID

The Cloudflare zone where Custom Hostnames are managed.

CNAME Target

Hostname customers must CNAME to (your SaaS fallback / CNAME target).

SSL Validation Method

HTTP (recommended) or TXT, depending on how you configured Cloudflare for SaaS.

Minimum TLS

Choose 1.0, 1.1, 1.2, or 1.3. Default is 1.2.

Auto-provision on domain add

When enabled, a Cloudflare custom hostname is created automatically when a customer adds a branded domain.

Click Save Settings, then Test Connection to verify the API token and Zone ID. The settings page shows Configured when Enable is on and API Token, Zone ID, and CNAME Target are all set.

Customer Domain SSL

Users whose plan includes branded domains see a Domain SSL item in the dashboard menu (once the plugin is configured). A banner also appears on the branded domains page.

How customers set up SSL

  1. Add a branded domain under Branded Domains (if not already added).
  2. Open Domain SSL and choose Set up SSL for that domain.
  3. At their DNS provider, create a CNAME from their hostname to your CNAME target.
  4. If ownership verification is required, add the optional TXT record shown in the setup wizard.
  5. Use Refresh status until Hostname and SSL show as active (SSL Active).

DNS changes can take a few minutes up to 36 hours to propagate. Status badges include: Not set up, Pending, Needs attention, and SSL Active.

System domains (your main site URL and domains listed under multi-domain settings) are skipped and will not appear for SaaS SSL provisioning.

Admin Hostnames

Go to Admin Cloudflare SaaS Hostnames to review all provisioned custom hostnames. You can search by hostname or Cloudflare ID, refresh status from Cloudflare, or delete a hostname (removes it from Cloudflare and the local database).

Notes

  • Customers need the branded domains feature on their membership plan to access Domain SSL.
  • Deleting a branded domain in Premium URL Shortener also removes the related Cloudflare custom hostname.
  • Use Test Connection after changing the API token or Zone ID before enabling auto-provision.
  • If status stays pending, verify the CNAME target matches your Cloudflare for SaaS fallback and that DNS has propagated.
Need help with Cloudflare for SaaS or this plugin? Contact us.

Upgrading

To update the plugin, upload the new version via Admin Plugins All Plugins. Settings and hostname records are preserved. The plugin runs its database schema update on activate/update when needed.

© 2026 GemPixel. All Rights Reserved.