aac tenant assign-hosted-domain
Request the AAC-assigned trust domain for your tenant and save it in the bound profile; repeated calls reuse it.
Synopsis
aac tenant assign-hosted-domain
[-h]
[--profile PROFILE]
[--admin-url ADMIN_URL]
[--data-plane-url DATA_PLANE_URL]
[--field {trust-domain} | --output {json,table}]
[--tenant-id TENANT_ID]
[--bootstrap-token BOOTSTRAP_TOKEN]
Arguments
| Argument | Type | Required | Default | Description |
|---|---|---|---|---|
-h, --help |
flag | no | — | show this help message and exit |
--profile |
value | no | — | Profile to run under (selection: --profile > AAC_PROFILE > reserved baseline main). aac profile list shows what exists. |
--admin-url |
value | no | — | Admin-surface base URL (overrides profile). |
--data-plane-url |
value | no | — | Data-plane-surface base URL (overrides profile). |
--field |
trust-domain |
no | — | Print only the selected server-returned value; cannot combine with --output. |
--output |
json | table |
no | json |
Output mode: json (the default) or table. |
--tenant-id |
value | no | — | Tenant (defaults to the selected profile). |
--bootstrap-token |
value | no | — | Explicit platform ceremony; otherwise use the tenant-admin session. |
At most one of --field, --output may be given.
Output
--output json (the default) prints one JSON document to standard output; --output table prints a readable table instead. Progress notes and diagnostics go to standard error, so the JSON stays parseable.
--field prints one unquoted value followed by a newline instead. It cannot be combined with an explicit --output. A missing or invalid value fails without scalar output; diagnostics go to standard error.
Exit codes
| Code | Meaning |
|---|---|
0 |
Success. |
1 |
The control plane or the identity provider rejected the request. |
2 |
Usage error: an invalid flag, value or flag combination. |
3 |
A local configuration or state problem: profile, credential file, cached session or agent. |
4 |
Transport failure: an endpoint could not be reached. |
Notes
What this command does
Requests the AAC-assigned trust domain for your tenant. The name is your
tenant id plus a suffix the control plane selects for its environment;
no DNS record or proof of ownership is needed. The first call allocates
the name permanently and every later call returns the same one. Use the
name the command returns rather than building it yourself:
on stage <tenant_id>.tenants.stage.cascadeauth.dev
on production <tenant_id>.tenants.cascadeauth.com
Where the domain is saved
On success it is written into the selected profile as hosted_trust_domain,
if that profile is bound to this tenant; a profile bound to another tenant
is left unchanged. Signing in with `aac sso login` does not write it, so a
profile bound that way has no such line until this command or
`aac init` runs. Replace main with your profile name:
aac tenant assign-hosted-domain --profile main
aac profile show main
To use a custom domain you own instead
Prove control of it with a DNS TXT record, then bind it. A domain you
own is recorded on the server and never written to the profile:
aac tenant issue-domain-challenge --profile main --domain example.com
aac tenant verify-domain --profile main --domain example.com
aac tenant bind-trust-domain --profile main --trust-domain example.com
Related commands
aac tenantaac tenant register— Register a tenant or resume this profile's pending registration.aac tenant list— List registered tenants visible to your credential (your own tenant, with a session; registration-attribute tier).aac tenant describe— One tenant's full registration state (API-key METADATA only).aac tenant issue-domain-challenge— Issue or rotate the DNS TXT challenge for one tenant business domain.aac tenant verify-domain— Resolve and verify the current DNS TXT tenant-domain challenge.aac tenant release-domain— Voluntarily release one business-domain claim for planned transfer.aac tenant revoke-domain— Terminally revoke one business-domain claim for security or teardown.aac tenant update— Update mutable tenant attributes (sparse: only passed flags change).aac tenant api-key— Plan a zero-downtime tenant API-key rotation.aac tenant reissue-api-key— Replace a lost or suspected-compromised tenant API key.aac tenant add-workload— Add a post-registration workload identity.aac tenant list-workloads— List this tenant's workload lifecycle records.aac tenant describe-workload— Describe one workload lifecycle record by opaque id.aac tenant update-workload— Set or clear a workload's display name.aac tenant deactivate-workload— Terminally deactivate a workload.aac tenant reactivate-hosted-domain— Reactivate the tenant's AAC-assigned trust domain after a revocation; the name does not change.aac tenant bind-trust-domain— Bind a SPIFFE trust domain using current exact-name evidence or ceremony.aac tenant list-trust-domains— List this tenant's trust-domain bindings.aac tenant rotate-admin-key— Replace this tenant's admin key with a new PUBLIC key.aac tenant revoke-trust-domain— Revoke a trust-domain binding episode by binding id.