Zipper
ServicesPlansDocsSupport
Sign inCreate account

Start

  • Getting started
  • Quickstart in ten minutes
  • What to use Zipper for
  • Plans and quotas
  • Migrate from Cloudflare
  • Auth, tokens, and SSO
  • Control plane API

Delivery

  • The Crown
  • The Drawbridge
  • The Gallery
  • The Archives
  • Video Delivery

Security

  • The Keep
  • Portcullis
  • The Moat
  • The Scepter
  • Visitor Queue

Compute

  • Edge Functions
  • Site Hosting
  • Job Queues
  • Edge AI

Identity & access

  • The Herald
  • The Vault
  • The Throne Room
  • Origin Connect
  • Emails

Observe

  • The Watchtower

Start

  • Getting started
  • Quickstart in ten minutes
  • What to use Zipper for
  • Plans and quotas
  • Migrate from Cloudflare
  • Auth, tokens, and SSO
  • Control plane API

Delivery

  • The Crown
  • The Drawbridge
  • The Gallery
  • The Archives
  • Video Delivery

Security

  • The Keep
  • Portcullis
  • The Moat
  • The Scepter
  • Visitor Queue

Compute

  • Edge Functions
  • Site Hosting
  • Job Queues
  • Edge AI

Identity & access

  • The Herald
  • The Vault
  • The Throne Room
  • Origin Connect
  • Emails

Observe

  • The Watchtower

TLS certificates

The Vault

The Vault issues and renews certificates for each zone, enforces modern cipher suites, and stores private keys outside the tenant control plane. This is a Cloudflare Cloudflare SSL/TLS alternative included on every Zipper plan.

Cloudflare analogue: Cloudflare SSL/TLS

What it is

The Vault issues and renews certificates for each zone, enforces modern cipher suites, and stores private keys outside the tenant control plane.

Cloudflare analogue: Cloudflare SSL/TLS. SLA 99.99% · p99 20ms. Admins set cipher policy. Private keys stay in The Vault.

  • ▸Auto-renewal
  • ▸Custom certificates
  • ▸HSTS helpers
  • ▸Key isolation

How it works

The Vault issues and renews certificates for each hostname. Private keys never leave the vault.

Minimum TLS, HSTS, OCSP stapling, and custom certificates are Policy toggles.

Use cases

Concrete ways teams use this service on day one.

Force HTTPS

Search consoles still report mixed content.

  1. Enable HSTS with includeSubDomains. Wait until every hostname answers HTTPS before preload.

Set it up in the dashboard

Dashboard → Services → The Vault. Automatic HTTPS is on. Upload a custom cert only if you must bring your own.

API

Control-plane: PATCH /api/v1/services/vault. Send Authorization: Bearer tz_live_YOUR_TOKEN.

Creates count against the plan quota. A 402 plan_limit means you are at the cap — upgrade or delete an unused resource.

Read Vault policy

curl -sS https://tinyzipper.com/api/v1/services/vault \
  -H "Authorization: Bearer tz_live_YOUR_TOKEN"

List the same resource in JavaScript

const res = await fetch("https://tinyzipper.com/api/v1/services/vault", {
  method: "GET",
  headers: {
    Authorization: `Bearer ${process.env.ZIPPER_TOKEN}`,
    "Content-Type": "application/json"
  }
});
const json = await res.json();
if (!res.ok) throw new Error(json.error ?? res.statusText);
console.log(json);

Tips

TLS 1.3 only is fine for modern apps. Keep 1.2 if you still have old POS terminals.

  • ▸SOC 2
  • ▸PCI-ready
  • ▸TLS 1.2+

Runbook

Automatic HTTPS is the default. A custom certificate replaces the issued leaf.

Next: The Scepter · All docs · Create a free account

Zipper

An affordable Cloudflare alternative: CDN, WAF, edge compute, and bot checks. A Spatial Regal Technology platform by Spatial Regal Digital Ltd.

Product

  • Services
  • Pricing
  • Docs
  • vs Cloudflare
  • Cloudflare alternative
  • Workers alternative
  • Turnstile alternative
  • Create account
  • Support

Services

  • The Crown
  • The Keep
  • Portcullis
  • The Moat
  • The Herald
  • The Vault
  • The Scepter
  • The Watchtower

Legal

  • Terms
  • Privacy
  • Cookies
  • AUP
  • DPA
  • Security
  • Subprocessors
  • Billing
  • DMCA

© 2026 Spatial Regal Digital Ltd. Zipper is part of Spatial Regal Technology.

Powered by Spatial Regal · tinyzipper.com