TuCloudDocsv1.0
GuidesStatus Dashboard
Docs/Reference
Reference

Model Context Protocol

Connect compatible agents to TuCloud projects, deployments, logs, and domains with OAuth or personal tokens.

TuCloud MCP

TuCloud publishes a remote MCP server over Streamable HTTP. Compatible clients can inspect real account state and start platform operations without dashboard cookies.

The account endpoint exposes every project in the account. A project-scoped URL automatically provides that context and cannot access other projects.

Modern clients discover OAuth 2.1, open TuCloud in the browser, and request consent. Clients without remote OAuth support can use a personal Bearer token.

Endpoints
Account: https://dash.tucloud.app/api/mcp
Project: https://dash.tucloud.app/api/mcp/PROJECT_ID

Authentication

  • OAuth 2.1 with PKCE S256, RFC 9728 discovery, and dynamic registration for interactive clients.
  • One-hour access tokens and rotating refresh tokens bound to the exact authorized MCP endpoint.
  • Explicit consent showing the client, account, return host, and requested scope.
  • Revocable personal tokens for clients that support Bearer headers but not remote OAuth.

Claude Code

Add the HTTP server and run /mcp in Claude Code. Your browser opens to authorize the account.

Terminal
claude mcp add --transport http tucloud https://dash.tucloud.app/api/mcp
claude
/mcp

Claude.ai and Claude Desktop

  1. 1
    Open Connectors

    In Settings, open Connectors and choose Add custom connector.

  2. 2
    Register TuCloud

    Use TuCloud as the name and https://dash.tucloud.app/api/mcp as the URL.

  3. 3
    Connect the account

    Select Connect, sign in to TuCloud, and review consent before authorizing.

ChatGPT

  1. 1
    Enable Developer mode

    In Settings → Connectors → Advanced settings, enable Developer mode if your account offers it.

  2. 2
    Create the connector

    In Connectors, select Create and name it TuCloud.

  3. 3
    Configure OAuth

    Use https://dash.tucloud.app/api/mcp as the MCP server URL and select OAuth.

  4. 4
    Authorize

    Save the connector, sign in to TuCloud, and approve the requested access.

Codex CLI

Codex discovers the OAuth server and opens a browser for authorization. The desktop app and extension use the same host configuration.

Terminal
codex mcp add tucloud --url https://dash.tucloud.app/api/mcp
codex

Codex with a personal token

For browserless automation, keep the token in the environment and reference only the variable name in Codex configuration.

~/.codex/config.toml
[mcp_servers.tucloud]
url = "https://dash.tucloud.app/api/mcp"
bearer_token_env_var = "TUCLOUD_MCP_TOKEN"
default_tools_approval_mode = "writes"

Cursor

Add the configuration to the project or global ~/.cursor/mcp.json. Cursor shows Needs login; select it to complete OAuth.

.cursor/mcp.json
{
  "mcpServers": {
    "tucloud": {
      "url": "https://dash.tucloud.app/api/mcp"
    }
  }
}

VS Code with Copilot

  1. 1
    Add a server

    Open the Command Palette and run MCP: Add Server.

  2. 2
    Choose HTTP

    Enter https://dash.tucloud.app/api/mcp and name it TuCloud.

  3. 3
    Select scope

    Save it to your profile or workspace based on who should use it.

  4. 4
    Start and authorize

    Run MCP: List Servers, start TuCloud, and allow VS Code to open OAuth.

.vscode/mcp.json
{
  "servers": {
    "tucloud": {
      "type": "http",
      "url": "https://dash.tucloud.app/api/mcp"
    }
  }
}

Devin

  1. 1
    Open MCP Marketplace

    In Settings, open MCP Marketplace and add a custom server.

  2. 2
    Add the endpoint

    Use TuCloud as the name and https://dash.tucloud.app/api/mcp as the remote server.

  3. 3
    Authorize the account

    Complete OAuth when Devin asks you to sign in.

Raycast

  1. 1
    Run Install Server

    Open the MCP Install Server command in Raycast.

  2. 2
    Configure HTTP

    Name: TuCloud. Transport: HTTP. URL: https://dash.tucloud.app/api/mcp.

  3. 3
    Complete OAuth

    Install the server and authorize the account in your browser.

Goose

In Goose Desktop, open Extensions, add a remote MCP extension, and use the TuCloud endpoint. If your version requires a local command, use mcp-remote as an OAuth bridge.

Remote MCP
Name: TuCloud
Type: Streamable HTTP
URL:  https://dash.tucloud.app/api/mcp

Windsurf

Add TuCloud in Windsurf Settings → Cascade → MCP Servers or edit the configuration file. Cascade supports Streamable HTTP and OAuth.

~/.codeium/windsurf/mcp_config.json
{
  "mcpServers": {
    "tucloud": {
      "serverUrl": "https://dash.tucloud.app/api/mcp"
    }
  }
}

Gemini Code Assist

Gemini Code Assist uses Gemini configuration. mcp-remote adapts the remote endpoint and completes OAuth in the browser.

~/.gemini/settings.json
{
  "mcpServers": {
    "tucloud": {
      "command": "npx",
      "args": ["-y", "mcp-remote", "https://dash.tucloud.app/api/mcp"]
    }
  }
}

Gemini CLI

Gemini CLI shares ~/.gemini/settings.json with Gemini Code Assist. Start Gemini after saving and verify the server.

Terminal
gemini
/mcp list

Personal token

Use this fallback only when the client cannot complete OAuth but supports HTTP headers. Create the token in Settings → Model Context Protocol and store it in an environment variable.

Generic configuration
{
  "mcpServers": {
    "tucloud": {
      "type": "http",
      "url": "https://dash.tucloud.app/api/mcp",
      "headers": {
        "Authorization": "Bearer ${env:TUCLOUD_MCP_TOKEN}"
      }
    }
  }
}

Available tools

  • list_projects and get_project: project inventory, configuration, and status.
  • list_repositories: importable GitHub repositories with a suggested TuCloud domain for each.
  • list_deployments and get_deployment: deployment history and details.
  • get_deployment_build_logs: jobs and real GitHub Actions output.
  • get_runtime_logs: access, runtime, or Host Agent error logs.
  • list_domains: primary domain, aliases, and redirects.
  • list_environment_variables: names and metadata without secret values.
  • create_project: imports a GitHub repository as a new project and reserves its permanent domain. It is the only way to create a project.
  • create_deployment: starts a deployment for a compatible branch.
  • rollback_deployment: restores an available production release.

Security and scope

  • Every authorization belongs to one account and can be revoked.
  • OAuth tokens are audience-bound and rejected by other endpoints.
  • Authorization codes last five minutes, are single-use, and require PKCE S256.
  • Project URLs reject deployments and resources from any other project.
  • Variable values, secrets, credentials, and encrypted data are never returned through MCP.
  • Each call records tool, result, credential, account, and scope for audit.
  • Write tools declare risk so the client can request approval before execution.

Troubleshooting

  • 401 Unauthorized: complete OAuth, renew authorization, or verify the Bearer token.
  • invalid_redirect_uri: the return URL does not exactly match the client registration.
  • invalid_grant: the code expired, was already used, or PKCE verification failed.
  • Project not found: the ID is outside the account or the URL is scoped to another project.
  • Runtime logs are unavailable: the active provider does not use Host Agent or the account is suspended.
  • Direct-upload projects cannot start a GitHub deployment: replace static projects with a new upload.