*.example.com is on, acme.example.com, beta.example.com and any other subdomain reach your app without adding each one separately. Your app reads the Host header to tell them apart.
Useful for:
- Multi-tenant apps where each customer gets their own subdomain.
- Per-branch or per-feature URLs you create on the fly.
- Catch-all landing pages.
Prerequisites
- A plan that includes wildcard domains. See Plans.
- An apex domain (
example.com, notapp.example.com) added to Brimble and attached to a project. See Custom domains.
*.brimble.app subdomains.
Turn on the wildcard
Turn on the wildcard for the apex domain in the dashboard, or call the API:DNS records to add
Forexample.com:
The
_acme-challenge value is your domain with dots replaced by dashes, followed by .acme.brimble.io. For my-shop.co.uk it’s my-shop-co-uk.acme.brimble.io. Very long domains use a different value. Always copy it from the dashboard or from the API (see below) rather than typing it by hand.
On Cloudflare, set all three records to DNS only (grey cloud). A proxied
* record answers with Cloudflare’s own IPs, so Brimble can’t confirm it points here. That’s why Cloudflare needs the extra brimble-wc record. At other providers, the * record already covers brimble-wc.example.com, so you don’t need to add it.example.com itself, as set up in Custom domains. The wildcard only covers subdomains.
Get the exact records from the API
GET /v1/domains/{domain} returns the records to create for the domain in settings.records, including the wildcard ones once the wildcard is on:
Check that it’s active
Brimble re-checks pending wildcards every 2 minutes. The wildcard is active when the domain showswildcard_verified: true (from GET /v1/domains/{domain}). The *.example.com certificate is issued right after that, which can take a few more minutes.
To check your records yourself:
How routing works
- One level deep.
*.example.comcoversacme.example.combut noteu.acme.example.com. This is how wildcard DNS and certificates work. - Specific subdomains win. If you add
api.example.comas its own domain on another project, requests toapi.example.comgo to that project. Every other subdomain goes to the project that ownsexample.com. - The apex is separate.
example.comkeeps its own record and settings. The wildcard doesn’t change it.
Turn off the wildcard
Send{ "enabled": false } to the same endpoint. For domains bought on Brimble, the * and _acme-challenge records are removed for you. For other domains, delete them where your DNS is hosted.
Troubleshooting
wildcard_verified stays false. Both checks must pass:
_acme-challenge.example.comis a CNAME (not a TXT record) to the exact value above.brimble-wc.example.comresolves to Brimble. At most providers the*record handles this. On Cloudflare, addbrimble-wcas its own record and make sure it isn’t proxied.
example.com, not for a subdomain such as app.example.com.
“Domain must be attached to a project to enable wildcard.” Attach the apex domain to a project first.
Certificate error on a subdomain. Check that _acme-challenge is still in place. Brimble needs it every time it renews the certificate, so don’t delete it while the wildcard is on.
Next steps
- Custom domains: connect the apex domain first.
- DNS troubleshooting: when DNS itself is the problem.