Documentation menu

Providers

Resend

Uses the Ahena CLI (beta). Install it with npm install -g @ahena/cli, or prefix commands with npx @ahena/cli. See Installation. The dashboard covers projects, connections, Doctor, the Stack Graph, plans and approvals without it.

Overview

Ahena adds and verifies your sending domain, works out the DNS records it needs, sets up webhooks, and checks deliverability (SPF, DKIM, DMARC). Your app sends through the generated src/ahena/email code straight to Resend. Ahena isn't in the path.

Package: @ahena/provider-resend · Category: email Capabilities: transactional-email, domains, dns-requirements, domain-verification, webhooks

Connection

One secret field: RESEND_API_KEY. It must be a full-access key, because sending-only keys can't list or create domains and webhooks. Ahena detects a sending-only key and says so. Your app should use a separate sending-only key.

RESEND_API_KEY=re_… ahena connect resend -e production

Permissions

Key Access Used by
Ahena's key Full access domains, DNS requirements, verification, webhooks
Your app's key Sending access, restricted to your domain sending email at runtime

Keep them separate: if the app's key leaks, it can only send from your domain.

Capabilities

Capability What Ahena does
transactional-email Generates ahena.email.send(...).
domains, domain-verification Adds your domain and triggers verification.
dns-requirements Works out SPF/DKIM records; adds them to a Cloudflare zone after review (--records-from resend, or ahena diff).
webhooks Creates the endpoint, stores its signing secret, generates a verifying route, probes it.

Network: api.resend.com, and cloudflare-dns.com for public DMARC lookups (no credentials). ahena lock tracks domain status and webhooks for drift.

Configure

email: {
  provider: "resend",
  domain: { production: "example.com" },
  from: "Leo <hello@example.com>",
  webhook: { endpoint: "https://example.com/api/webhooks/resend", events: ["email.bounced", "email.complained"] },
},
dns: { provider: "cloudflare", zone: "example.com" },
Change Classification
Add the sending domain CONFIRMATION_REQUIRED
Ask Resend to re-check DNS SAFE (changes nothing else)
Create the webhook CONFIRMATION_REQUIRED. Resend returns the signing secret once; Ahena stores it encrypted as RESEND_WEBHOOK_SECRET in that environment. It's never shown in plans, outputs or logs. The only way to read it back is the secret reveal API route (POST …/secrets/RESEND_WEBHOOK_SECRET/reveal), which needs the secrets.reveal permission (secrets.reveal.production in production) and is always audited. From the CLI: ahena env reveal <environment> RESEND_WEBHOOK_SECRET (same permission, audited). You can also copy it from the Resend dashboard.

DNS through Cloudflare (no silent changes)

ahena configure cloudflare -e production --records-from resend --with-dmarc

Ahena reads the records Resend requires and shows them as a Cloudflare diff for approval. It then runs Cloudflare's usual safety rules (SPF stays one record, CNAMEs can't collide). Then ahena configure resend asks Resend to verify.

Generate

ahena generate resend [--framework nextjs] writes:

  • src/ahena/providers/resend.ts, src/ahena/email/index.ts (email.send, email.raw)
  • .env.example.resend
  • with nextjs: src/app/api/webhooks/resend/route.ts, which verifies the Svix signature headers with the official SDK, returns 401 for unsigned or tampered requests, and 204 otherwise.

Limitations

  • Ahena doesn't delete domains, webhooks or API keys.
  • DMARC is checked with a public DNS-over-HTTPS lookup (cloudflare-dns.com). Ahena only suggests the record; with --with-dmarc it adds p=none through the DNS provider.
  • Broadcasts, audiences and templates are out of scope (application features, not stack wiring).

Manual steps

Situation What to do
DNS not on a connected provider Add the records Doctor lists at your DNS host, then ahena configure resend.
Sending-only key connected ahena disconnect resend, then reconnect with a full-access key.

Doctor checks

Id Severity Meaning
resend.key PASS / FAIL Key works; sending-only keys are explained.
resend.domain PASS / WARNING / FAIL Domain verified, pending, failed, or missing.
resend.domain.spf / .dkim PASS / WARNING / FAIL Each record's status, with the exact record to add (FAIL in production).
resend.domain.dmarc PASS / INFO / WARNING DMARC enforced, monitoring only (p=none), or missing.
resend.webhook PASS / WARNING / FAIL Webhook exists for the configured endpoint, enabled, with the events.
resend.webhook.endpoint PASS / WARNING / FAIL One unsigned POST: rejected = good; 404/405 = route missing; 2xx = signatures not verified. Only public https endpoints are probed.

Disconnect behavior

Removes the connection and the key Ahena stored. Resend can't revoke keys for Ahena, so Ahena links to https://resend.com/api-keys. Domains, webhooks and history are untouched.