What it is
Register your application to personalize it: name, slug, description, and icon. Your users click the Deploy to Tucloud button, sign in (or create a free Tucloud account), and their content is saved into their account as a native repository in Tucloud's git. They continue straight into the deploy configuration wizard.
There are no developer keys: security comes from the user's own session, and everything lands inside their account under their plan's quota.
How it works
- 1Register your app
From developers.tucloud.app create an app with a unique slug, a short description, and, if you want, a template repository. Choose the default branch.
- 2Bring your user's content
Build the button URL with ?source pointing at the Git repository with your user's content and an optional branch. Without a source we clone your template instead.
- 3Your user deploys
The person clicks the button, signs in, and the content is imported into their native Tucloud repository. The dashboard opens the new-project wizard with that repository preselected to configure runtime and build, then deploy.
The button
Every app has a snippet ready to copy. It points at your slug and accepts an optional source, branch, and variables.
<a href="https://developers.tucloud.app/deploy/my-awesome-app?source=https://github.com/user/export.git&branch=main">
<img src="https://developers.tucloud.app/deploy-button.svg"
alt="Deploy to Tucloud" width="160" height="36" />
</a>Environment variables
Declare the variables users must complete, such as an API_KEY or project identifier. They are requested before installing and arrive prefilled in the deploy wizard.
Mark only the essentials as required, and never put secrets in default values: anyone opening the install page can read them.
Source requirements
- Public Git repository over http or https; SSH, file paths, and private repositories are not supported.
- The template repository is optional: leave it empty when your buttons always carry ?source= with the user's content.
- Without a template or ?source= the install is rejected with a clear error before creating anything.
- The given branch must exist in the source; a missing branch fails the install with a clear error before creating anything.
- The user needs a session and an active plan; installs respect their storage quota.
Security
- Installing requires a session; anonymous routes only see the app's public page.
- Every source URL is validated against private addresses (SSRF) on the server and again on the agent.
- Everything lands in the clicker's account. A malicious source can only affect its own account, like a personal git push.
- If the import fails, the reserved repository is deleted and no partial state remains.
Troubleshooting
- App not found: check that the URL slug matches your app.
- Invalid source: the URL must be http or https and resolve to a public address.
- Empty repository or missing branch: confirm the default branch in your app or pass branch explicitly.
- No active plan: the user must activate a plan before installing applications.