Space Access and Domains
Choose who can open a Space, what visitors see when they're denied, and how to change its URL or serve it on your own domain.
Every Space has two separate controls. Access decides who can reach the app's URL at all. The app's own sign-in decides whether people have accounts inside the app. This page covers both, plus the app's URL and custom domains.
Choose who can open a Space
Access is set separately for the production app and the preview app.
- Open Spaces and select the Space.
- Open the Access tab.
- Under Production app or Preview app, pick one option:
- - Public: "Anyone with the URL can open this space."
- - Workspace members: "Only members of your workspace can open this space."
- - Specific people and groups: "Only the space's creator and the people or groups picked below can open this space." Search for people or groups to add, then select Save changes. The creator always has access.
The change applies right away with no redeploy. The status line reads "Enforced at the edge · policy vN" once it is live. When a custom domain goes live, it takes the production access setting, and later changes to production access also apply to live custom domains.
You can also ask Viktor: "make the demo tracker open to the whole workspace" or "only let Priya and me open it."
Access for a new Space
Viktor sets the first access when the Space is first deployed:
- An internal app starts as Workspace members.
- An app that uses a personal or restricted integration starts with only its creator allowed. If the creator can't be determined, it falls back to Workspace members.
- Public is used only when you confirm that anyone on the internet may open the app.
After that, redeploys never change access. Only the Access tab, or asking Viktor to change it, does.
Search engines
Under Access, the switch Allow search engines to index this site is off by default. Off means "Anyone with the link can still open it; search engines are asked not to list it." The switch only matters while production access is Public; otherwise the page adds "Takes effect once production access is set to Public."
What visitors see
Signing in to the app
An app that has accounts can offer Sign in with Viktor, a one-click sign-in for members of the workspace that owns the app. It can also offer email and password. Someone outside the workspace who tries Sign in with Viktor sees "Viktor sign-in didn't complete. You may not be a member of this app's workspace", and is pointed to email and password when the app offers it.
The access-denied page
A visitor who isn't allowed in lands on a page titled "You don't have access to this content", which names the app's address. The explanation depends on why:
- "This content belongs to a different workspace." The visitor is signed in to another workspace.
- "Your account is in the right workspace, but doesn't have access yet." The Space is limited to specific people. The page suggests asking the person who shared the link, or a workspace admin, for access.
If another account signed in on the same browser does have access, the page lists it under Open with another account so the visitor can switch in one click. The page also offers Try again and Use a different account.
Change a Space's URL
- Open the Space and go to Settings.
- Edit App URL and select Change URL.
- Confirm in Change this space's URL?.
The old address redirects to the new one, so shared links keep working. Everyone signs in again on the new address. No redeploy is needed.
If the URL can't be changed yet, the field shows the reason instead:
- "Set a workspace slug in Team settings first." The workspace needs a slug, the name added to Space addresses. It is 2 to 24 characters of lowercase letters, digits and hyphens, starts with a letter and ends with a letter or digit. It only affects URLs created or changed afterwards. A workspace admin can also ask Viktor to set it; Viktor asks for an admin's approval before he applies it.
- "This space runs an older template whose sign-in is bound to its current URL. Update it to the latest template first."
- "This space's URL is not served through the edge gate, so it cannot be changed here."
- "Custom hostnames are not available on this deployment."
If the Space isn't deployed yet, the field says "Not deployed yet. Your app will be published at this address once it is deployed."
If the redirect from the old address fails, Settings shows "The old address is still serving your app". Select Finish cleanup to retry.
Serve a Space on your own domain
A Space's production app can also be served on a domain you own, such as app.yourcompany.com. This works with any DNS provider: you add a TXT record (ownership) and a CNAME record (routing). No nameserver change is needed.
- Make sure the Space is deployed to production. Until it is, the panel says "Deploy this space to production before adding a custom domain."
- Open the Space, go to Settings, and find Custom domains.
- Enter the domain and select Add domain.
- Copy the TXT and CNAME records shown and add both at your DNS provider.
- Select Check. The status moves from Waiting for DNS to Issuing certificate to Live. DNS changes can take a few minutes, so check again if it isn't live yet.
To stop using a domain, select Remove. You can also ask Viktor to add, check or remove a domain.
Use a subdomain where you can. A bare domain like yourcompany.com only works if your DNS provider supports ALIAS or ANAME records.
Limits
- Only the Space's creator and workspace admins can change access, the URL and custom domains. Other members can view the Access tab read-only: "Only {name} and workspace admins can change access. Everyone on the team can view these settings." The Custom domains section is hidden from them.
- Setting the workspace's Space address name needs a workspace admin's approval.
- A workspace can hold up to 20 custom domains, counting domains used for hosted pages. Support can raise the limit. When it's reached, adding fails with "This workspace has reached its custom domain limit".
- If you add a domain and don't verify it, another workspace can claim the same domain after 2 hours.
- The Access tab needs you to be in a workspace.
Common problems
- "This space has no production deployment yet." Ask Viktor to deploy it, then set access.
- "Access controls aren't active on this deployment yet." Ask Viktor to redeploy the Space, then set access.
- "Saved · takes effect when this domain moves behind Viktor's edge gate." The setting is saved, but until then the app stays publicly reachable.
- A teammate lands on the access-denied page. Add them under Specific people and groups, or switch to Workspace members. If they're signed in to a different workspace, they can use Use a different account. See wrong workspace.
- A custom domain stays on Waiting for DNS. Check that both records match exactly, wait a few minutes, then select Check again.
- "Domain is already registered". Another workspace holds that domain.