subdy docs
Guides

Wildcard TLS

One certificate for myapp.subdy.io and every name under it.

At the end you will have HTTPS on myapp.subdy.io and any *.myapp.subdy.io — either with Subdy's managed certificate or with your own ACME client.

Toggle issue wildcard certificate when creating the subdomain, or press Renew now on Certificates. Subdy completes the DNS-01 challenge on its own nameservers — nothing to configure. When the status is valid, press Download to get the full chain and private key, then point your server at them:

Caddyfile (Caddy v2.8+)
myapp.subdy.io, *.myapp.subdy.io {
    tls /etc/ssl/subdy/cert.pem /etc/ssl/subdy/key.pem
    reverse_proxy 127.0.0.1:3000
}

Renewal is automatic ~30 days before expiry — re-download and reload (or script it via GET /v1/certificates).

Option B — your own ACME client

Wildcard certificates require DNS-01: the CA checks a TXT record at _acme-challenge.myapp.subdy.io. Publish it via the Subdy API.

certbot (4.x) manual mode:

certbot certonly --manual --preferred-challenges dns \
  -d "myapp.subdy.io" -d "*.myapp.subdy.io"

When certbot prints the validation string, set the record (see set_record):

curl -sS -X PUT "https://api.subdy.io/v1/subdomains/$SUBDOMAIN_ID/records" \
  -H "Authorization: Bearer $SUBDY_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"type":"TXT","name":"_acme-challenge","value":"<validation-string>","ttl":60}'

Traefik (v3.x) and Caddy with a DNS plugin need a provider integration; until a native Subdy plugin ships, use Option A or the exec provider pattern with the same API call.