Providers
Resend
Uses the Ahena CLI (beta). Install it with npm install -g @ahena/cli, or prefix commands with npx @ahena/cli. See Installation. The dashboard covers projects, connections, Doctor, the Stack Graph, plans and approvals without it.
Overview
Ahena adds and verifies your sending domain, works out the DNS records it needs, sets up
webhooks, and checks deliverability (SPF, DKIM, DMARC). Your app sends through the
generated src/ahena/email code straight to Resend. Ahena isn't in the path.
Package: @ahena/provider-resend · Category: email
Capabilities: transactional-email, domains, dns-requirements, domain-verification, webhooks
Connection
One secret field: RESEND_API_KEY. It must be a full-access key, because sending-only
keys can't list or create domains and webhooks. Ahena detects a sending-only key and says
so. Your app should use a separate sending-only key.
RESEND_API_KEY=re_… ahena connect resend -e production
Permissions
| Key | Access | Used by |
|---|---|---|
| Ahena's key | Full access | domains, DNS requirements, verification, webhooks |
| Your app's key | Sending access, restricted to your domain | sending email at runtime |
Keep them separate: if the app's key leaks, it can only send from your domain.
Capabilities
| Capability | What Ahena does |
|---|---|
transactional-email |
Generates ahena.email.send(...). |
domains, domain-verification |
Adds your domain and triggers verification. |
dns-requirements |
Works out SPF/DKIM records; adds them to a Cloudflare zone after review (--records-from resend, or ahena diff). |
webhooks |
Creates the endpoint, stores its signing secret, generates a verifying route, probes it. |
Network: api.resend.com, and cloudflare-dns.com for public DMARC lookups (no
credentials). ahena lock tracks domain status and webhooks for drift.
Configure
email: {
provider: "resend",
domain: { production: "example.com" },
from: "Leo <hello@example.com>",
webhook: { endpoint: "https://example.com/api/webhooks/resend", events: ["email.bounced", "email.complained"] },
},
dns: { provider: "cloudflare", zone: "example.com" },
| Change | Classification |
|---|---|
| Add the sending domain | CONFIRMATION_REQUIRED |
| Ask Resend to re-check DNS | SAFE (changes nothing else) |
| Create the webhook | CONFIRMATION_REQUIRED. Resend returns the signing secret once; Ahena stores it encrypted as RESEND_WEBHOOK_SECRET in that environment. It's never shown in plans, outputs or logs. The only way to read it back is the secret reveal API route (POST …/secrets/RESEND_WEBHOOK_SECRET/reveal), which needs the secrets.reveal permission (secrets.reveal.production in production) and is always audited. From the CLI: ahena env reveal <environment> RESEND_WEBHOOK_SECRET (same permission, audited). You can also copy it from the Resend dashboard. |
DNS through Cloudflare (no silent changes)
ahena configure cloudflare -e production --records-from resend --with-dmarc
Ahena reads the records Resend requires and shows them as a Cloudflare diff for approval.
It then runs Cloudflare's usual safety rules (SPF stays one record, CNAMEs can't collide).
Then ahena configure resend asks Resend to verify.
Generate
ahena generate resend [--framework nextjs] writes:
src/ahena/providers/resend.ts,src/ahena/email/index.ts(email.send,email.raw).env.example.resend- with
nextjs:src/app/api/webhooks/resend/route.ts, which verifies the Svix signature headers with the official SDK, returns 401 for unsigned or tampered requests, and 204 otherwise.
Limitations
- Ahena doesn't delete domains, webhooks or API keys.
- DMARC is checked with a public DNS-over-HTTPS lookup (
cloudflare-dns.com). Ahena only suggests the record; with--with-dmarcit addsp=nonethrough the DNS provider. - Broadcasts, audiences and templates are out of scope (application features, not stack wiring).
Manual steps
| Situation | What to do |
|---|---|
| DNS not on a connected provider | Add the records Doctor lists at your DNS host, then ahena configure resend. |
| Sending-only key connected | ahena disconnect resend, then reconnect with a full-access key. |
Doctor checks
| Id | Severity | Meaning |
|---|---|---|
resend.key |
PASS / FAIL | Key works; sending-only keys are explained. |
resend.domain |
PASS / WARNING / FAIL | Domain verified, pending, failed, or missing. |
resend.domain.spf / .dkim |
PASS / WARNING / FAIL | Each record's status, with the exact record to add (FAIL in production). |
resend.domain.dmarc |
PASS / INFO / WARNING | DMARC enforced, monitoring only (p=none), or missing. |
resend.webhook |
PASS / WARNING / FAIL | Webhook exists for the configured endpoint, enabled, with the events. |
resend.webhook.endpoint |
PASS / WARNING / FAIL | One unsigned POST: rejected = good; 404/405 = route missing; 2xx = signatures not verified. Only public https endpoints are probed. |
Disconnect behavior
Removes the connection and the key Ahena stored. Resend can't revoke keys for Ahena, so Ahena links to https://resend.com/api-keys. Domains, webhooks and history are untouched.