All integration guides
DIRECT VERCEL INTEGRATION · MANAGED SETUP

Deploy your QWAC on Vercel

Keep your website on Vercel. Connect your issuer and Enterprise team, then manage certificate deployment and renewal from QWAC.com.

Connect your team, project, and issuer•Reviewed October 9, 2026
Check compatibility first

Vercel Enterprise is required for custom certificates. Hobby and Pro cannot continue. QWAC.com checks the team plan before provisioning and again before deployment.

Before you start

This integration connects your website to verified organization identity—a foundation for your SEO and AEO strategy. See how QWAC fits into search and AI discovery.

  • A Vercel Enterprise team and a verified production custom domain attached to its project
  • A team-scoped Vercel access token with project/domain read and certificate management access
  • Your own DigiCert Europe or Sectigo account enabled for the selected QWAC or EV product
  • Access to your DNS provider to publish validation TXT records
  • An active QWAC.com managed service and completed issuer business verification
What you’re setting up

Visitors receive the certificate issued for your organization from Vercel’s network. QWAC.com verifies the public TLS certificate after upload. Vercel does not need to move behind Cloudflare.

Account setup time does not include provider identity checks, certificate issuance, or managed-service activation.

01

Check your Vercel team and domain

WHERE TO GOVercel → Team Settings and project → Settings → Domains
  1. Confirm the team is on Enterprise. If it is on Hobby or Pro, contact Vercel to upgrade before ordering a certificate.
  2. Attach your custom domain to the production project and complete Vercel’s verification. Check the website works over HTTPS.
  3. Connect each hostname you want to certify. An apex redirect still needs valid SSL before the browser follows it. Preview and vercel.app domains are excluded.
✓
You’re ready for the next step when…

The custom domain is verified and working in the Enterprise team.

02

Connect Vercel in QWAC.com

WHERE TO GOQWAC.com → Add website → Vercel
  1. Copy your team ID from Vercel Team Settings → General. Create an access token scoped to that team and paste both into QWAC.com.
  2. Select Connect Vercel. QWAC.com reads the team plan and loads its projects.
  3. Select your project and verified website hostname, then choose your certificate provider.
QWAC.com Vercel connection fields for a team ID and access token, with the Enterprise requirement
In QWAC.com, connect the team before choosing a project and domain. Enter credentials only in the secure dashboard fields. Click image to enlarge
Before you continue

Tokens are encrypted on the backend. Choose an expiry that fits your security policy and replace the token before it expires. This connection uses a token, not OAuth.

✓
You’re ready for the next step when…

Your website is linked to the correct Vercel team and project.

03

Choose your issuer and key management

WHERE TO GOWebsite setup → Certificate provider
  1. Connect DigiCert Europe using your API key and organization, or Sectigo using its enabled ACME directory and EAB credentials.
  2. Choose We host the key for managed deployment. The TLS key is envelope-encrypted with AWS KMS and decrypted in memory for Vercel upload.
  3. Or choose Bring your key and CSR. QWAC.com receives only the public CSR; you install every issued certificate directly in Vercel.
  4. Select your purchased QWAC or EV product, then review issuer terms and authorization before starting. Your issuer bills your own account.
Before you continue

Vercel does not use the Cloudflare-generated-key option. Use the product enabled on your issuer account.

✓
You’re ready for the next step when…

The request is authorized for the selected product and key option.

04

Complete domain and business validation

WHERE TO GOWebsite setup → DNS validation and your issuer account
  1. When a TXT challenge appears, add its exact name and value at the provider that manages your DNS.
  2. Select Check DNS after saving. We continue only after detecting the expected public value; your issuer makes the final validation decision.
  3. Complete any business checks or representative approval requested by your issuer. We email you when action is needed.
Before you continue

Vercel DNS changes are manual in this integration. New TXT records may be needed for every reissue; QWAC.com shows instructions and emails you each time.

✓
You’re ready for the next step when…

The issuer approves and releases your certificate.

05

Deploy, verify, and keep it current

WHERE TO GOWebsite setup → Deployment status
  1. For hosted keys, QWAC.com uploads the issued certificate, its matching key, and CA chain using Vercel’s API.
  2. For your own CSR, download the certificate and follow the manual installation steps below.
  3. Select Sync or verify installation. Active means public TLS serves the expected certificate, not just that an upload succeeded.
  4. Keep issuer access, the Vercel token, DNS access, and your managed service active. Review renewal alerts promptly.
Before you continue

Vercel serves an automatically generated certificate when a custom certificate is within five days of expiry. This may preserve HTTPS, but the QWAC identity is absent until its replacement is deployed. Uploading a certificate does not make Vercel renew it.

✓
You’re ready for the next step when…

The certificate is deployed and verified; reissues are scheduled before expiry.

Bring your key and CSR

Keep your private key on your own system. QWAC.com needs only the public certificate signing request (CSR). Ask your administrator to generate an RSA-3072 key and a CSR for exactly your website hostname.

Example commands for your administrator
umask 077
openssl req -new -newkey rsa:3072 -nodes   -keyout example.com.key -out example.com.csr   -subj "/CN=example.com" -addext "subjectAltName=DNS:example.com"

Replace example.com with your selected hostname. Keep the .key file private and backed up. Only select the .csr file in QWAC.com.

  1. Choose your issuer, then Bring your key and CSR.
  2. Paste or select the public CSR. Connect your issuer account for the selected QWAC or EV product and authorize the request.
  3. When notified, download the issued certificate from your workspace.
  4. Open your Vercel team → Domains and upload a custom SSL certificate for the domain, including its matching private key and the issuer’s CA chain.
  5. Return to QWAC.com and select Verify Vercel installation. Repeat installation after every reissue.

Your key is uploaded directly to Vercel, which holds it for TLS serving. QWAC.com never receives it. This option does not use Keyless SSL.

Vercel installation instructions ↗
IF SOMETHING DOESN’T LOOK RIGHT

Troubleshooting

My team cannot continue

Custom certificate upload requires Enterprise. Upgrade with Vercel, then select Recheck Vercel. Your QWAC.com subscription does not change the Vercel plan.

My domain is missing

Select the right team and project. The hostname must be a verified custom domain in production, not a preview, wildcard, or vercel.app domain.

The site still serves a different certificate

Allow propagation, then Sync again. A proxy in front of Vercel may terminate TLS and serve its own certificate. QWAC.com will not mark this as verified.

The upload outcome is uncertain

Contact support before retrying. We retain the upload intent to avoid a duplicate upload after an interrupted response.

Renewal needs a TXT record again

Domain validation can recur. Add the latest value at your DNS provider and select Check DNS. Keep unrelated records intact.

Official references

Provider screens and requirements change. These links are the source of truth for their platform settings.

Vercel custom SSL requirements and fallbackVercel certificate upload APIVercel Enterprise plan

Keep this guide handy.

Start with your hosting account, then choose your issuer and how to manage your key.

Register your interest