All integration guides
DIRECT NETLIFY INTEGRATION · MANAGED SETUP

Deploy your QWAC on Netlify

Keep your site on Netlify. Connect your issuer and manage certificate deployment, reissues, and expiration alerts in QWAC.com.

Connect your site, then your certificate provider•Reviewed October 9, 2026
Check compatibility first

This version supports one custom hostname on a site with working HTTPS. Apex/www pairs, additional aliases, wildcard certificates, and automatic deploy subdomains need a coverage review first. We block setup rather than replace a certificate that protects other names.

Before you start

This integration connects your website to verified organization identity—a foundation for your SEO and AEO strategy. See how QWAC fits into search and AI discovery.

  • A Netlify site with one exact custom hostname and working HTTPS
  • A Netlify token with access to the site and its SSL settings
  • An enabled DigiCert Europe or Sectigo account, with business verification and billing arranged
  • Access to the DNS provider for domain validation and an active QWAC.com managed service
What you’re setting up

Netlify serves your organization’s certificate directly. QWAC.com checks the certificate visitors receive, tracks its expiration, and deploys issued replacements. No Cloudflare account is needed.

Account setup time does not include provider identity checks, certificate issuance, or managed-service activation.

01

Check your custom domain

WHERE TO GONetlify → Your site → Domain management
  1. Confirm your website is working at its custom hostname over HTTPS.
  2. Review the primary domain, domain aliases, and HTTPS certificate names. This integration currently needs one hostname; contact us before connecting a site with multiple names.
  3. Keep the working certificate in place. QWAC.com checks coverage before requesting a replacement.
✓
You’re ready for the next step when…

Your site has one supported hostname and working HTTPS.

02

Connect Netlify in QWAC.com

WHERE TO GOQWAC.com → Add website → Netlify
  1. Create a Netlify personal access token with access to your site. Paste it into the secure token field and select Connect Netlify.
  2. Select the site and hostname, then choose your certificate provider.
QWAC.com Netlify connection form with hosting selection and secure token field
Select Netlify, then connect with your token. The site list loads after connection. Click image to enlarge
Before you continue

The token is encrypted on the backend and is never returned to the browser. Replace it before it expires. This connection uses a token, not OAuth.

✓
You’re ready for the next step when…

The site is linked to your Netlify account.

03

Choose your issuer and key option

WHERE TO GOWebsite setup → Certificate provider
  1. Connect your DigiCert Europe API account or your enabled Sectigo ACME account.
  2. Choose We host the key for automatic deployment, or Bring your key and CSR to install certificates yourself.
  3. Select the purchased QWAC or EV product, then review issuer terms and the request authorization. The issuer charges your own account.
Before you continue

Hosted TLS keys are envelope-encrypted with AWS KMS and decrypted in memory for upload to Netlify. With your own CSR, QWAC.com never receives the private key.

✓
You’re ready for the next step when…

Your certificate request is authorized.

04

Complete validation

WHERE TO GOWebsite setup → DNS validation and your issuer account
  1. Add each TXT record shown in the dashboard at your DNS provider, then select Check DNS.
  2. Complete the issuer’s business checks or representative approval.
  3. Watch for emails when a new DNS record or another action is needed.
Before you continue

DNS updates are manual, including when Netlify manages your DNS. Fresh validation may be required for reissues.

✓
You’re ready for the next step when…

Your issuer completes its checks and releases the certificate.

05

Deploy and keep it current

WHERE TO GOWebsite setup → Deployment status
  1. For hosted keys, we upload the issued certificate, matching key, and issuer chain to Netlify.
  2. For your own CSR, download the certificate and follow the installation section below.
  3. Select Sync to check progress. Active means the public website serves the expected certificate.
  4. Keep issuer and Netlify access current and act on renewal alerts.
Before you continue

Netlify does not renew custom certificates for you. QWAC.com requests and deploys replacements through your enabled issuer account. Do not rely on an automatic fallback after expiry.

✓
You’re ready for the next step when…

Your issued certificate is serving and its renewal is tracked.

Bring your key and CSR

Keep your private key on your own system. QWAC.com needs only the public certificate signing request (CSR). Ask your administrator to generate an RSA-3072 key and a CSR for exactly your website hostname.

Example commands for your administrator
umask 077
openssl req -new -newkey rsa:3072 -nodes   -keyout example.com.key -out example.com.csr   -subj "/CN=example.com" -addext "subjectAltName=DNS:example.com"

Replace example.com with your selected hostname. Keep the .key file private and backed up. Only select the .csr file in QWAC.com.

  1. Choose your issuer, then Bring your key and CSR.
  2. Paste or select the public CSR. Connect your issuer account for the selected QWAC or EV product and authorize the request.
  3. When notified, download the issued certificate from your workspace.
  4. Open the Netlify site → Domain management → HTTPS → Set custom certificate. Supply the issued certificate, its matching private key, and the issuer’s intermediate CA chain.
  5. Return to QWAC.com and select Verify Netlify installation. Repeat installation after every reissue.

Your key is uploaded directly to Netlify, which holds it for TLS serving. QWAC.com never receives it. This option does not use Keyless SSL.

Netlify installation instructions ↗
IF SOMETHING DOESN’T LOOK RIGHT

Troubleshooting

My site is not listed

Add a custom domain to the correct site and make sure the token can read that site.

Coverage review is required

A site certificate can protect multiple names, including apex and www. The current workflow issues one hostname at a time and will not replace shared coverage. Contact us before changing your domain configuration.

A DNS check is pending

Add the exact TXT value at the authoritative DNS provider. Select Check DNS after it is publicly visible.

Upload needs review

A failed response does not prove the upload failed. We inspect the live certificate before retrying. Contact support if the status remains uncertain.

Official references

Provider screens and requirements change. These links are the source of truth for their platform settings.

Netlify custom certificatesNetlify certificate APINetlify domain troubleshooting

Keep this guide handy.

Start with your hosting account, then choose your issuer and how to manage your key.

Register your interest