TuCloud MCP
TuCloud publishes a remote MCP server over Streamable HTTP. Compatible clients can inspect real account state and start platform operations without dashboard cookies.
The account endpoint exposes every project in the account. A project-scoped URL automatically provides that context and cannot access other projects.
Modern clients discover OAuth 2.1, open TuCloud in the browser, and request consent. Clients without remote OAuth support can use a personal Bearer token.
Account: https://dash.tucloud.app/api/mcp
Project: https://dash.tucloud.app/api/mcp/PROJECT_IDAuthentication
- OAuth 2.1 with PKCE S256, RFC 9728 discovery, and dynamic registration for interactive clients.
- One-hour access tokens and rotating refresh tokens bound to the exact authorized MCP endpoint.
- Explicit consent showing the client, account, return host, and requested scope.
- Revocable personal tokens for clients that support Bearer headers but not remote OAuth.
Claude Code
Add the HTTP server and run /mcp in Claude Code. Your browser opens to authorize the account.
claude mcp add --transport http tucloud https://dash.tucloud.app/api/mcp
claude
/mcpClaude.ai and Claude Desktop
- 1Open Connectors
In Settings, open Connectors and choose Add custom connector.
- 2Register TuCloud
Use TuCloud as the name and https://dash.tucloud.app/api/mcp as the URL.
- 3Connect the account
Select Connect, sign in to TuCloud, and review consent before authorizing.
ChatGPT
- 1Enable Developer mode
In Settings → Connectors → Advanced settings, enable Developer mode if your account offers it.
- 2Create the connector
In Connectors, select Create and name it TuCloud.
- 3Configure OAuth
Use https://dash.tucloud.app/api/mcp as the MCP server URL and select OAuth.
- 4Authorize
Save the connector, sign in to TuCloud, and approve the requested access.
Codex CLI
Codex discovers the OAuth server and opens a browser for authorization. The desktop app and extension use the same host configuration.
codex mcp add tucloud --url https://dash.tucloud.app/api/mcp
codexCodex with a personal token
For browserless automation, keep the token in the environment and reference only the variable name in Codex configuration.
[mcp_servers.tucloud]
url = "https://dash.tucloud.app/api/mcp"
bearer_token_env_var = "TUCLOUD_MCP_TOKEN"
default_tools_approval_mode = "writes"Cursor
Add the configuration to the project or global ~/.cursor/mcp.json. Cursor shows Needs login; select it to complete OAuth.
{
"mcpServers": {
"tucloud": {
"url": "https://dash.tucloud.app/api/mcp"
}
}
}VS Code with Copilot
- 1Add a server
Open the Command Palette and run MCP: Add Server.
- 2Choose HTTP
Enter https://dash.tucloud.app/api/mcp and name it TuCloud.
- 3Select scope
Save it to your profile or workspace based on who should use it.
- 4Start and authorize
Run MCP: List Servers, start TuCloud, and allow VS Code to open OAuth.
{
"servers": {
"tucloud": {
"type": "http",
"url": "https://dash.tucloud.app/api/mcp"
}
}
}Devin
- 1Open MCP Marketplace
In Settings, open MCP Marketplace and add a custom server.
- 2Add the endpoint
Use TuCloud as the name and https://dash.tucloud.app/api/mcp as the remote server.
- 3Authorize the account
Complete OAuth when Devin asks you to sign in.
Raycast
- 1Run Install Server
Open the MCP Install Server command in Raycast.
- 2Configure HTTP
Name: TuCloud. Transport: HTTP. URL: https://dash.tucloud.app/api/mcp.
- 3Complete OAuth
Install the server and authorize the account in your browser.
Goose
In Goose Desktop, open Extensions, add a remote MCP extension, and use the TuCloud endpoint. If your version requires a local command, use mcp-remote as an OAuth bridge.
Name: TuCloud
Type: Streamable HTTP
URL: https://dash.tucloud.app/api/mcpWindsurf
Add TuCloud in Windsurf Settings → Cascade → MCP Servers or edit the configuration file. Cascade supports Streamable HTTP and OAuth.
{
"mcpServers": {
"tucloud": {
"serverUrl": "https://dash.tucloud.app/api/mcp"
}
}
}Gemini Code Assist
Gemini Code Assist uses Gemini configuration. mcp-remote adapts the remote endpoint and completes OAuth in the browser.
{
"mcpServers": {
"tucloud": {
"command": "npx",
"args": ["-y", "mcp-remote", "https://dash.tucloud.app/api/mcp"]
}
}
}Gemini CLI
Gemini CLI shares ~/.gemini/settings.json with Gemini Code Assist. Start Gemini after saving and verify the server.
gemini
/mcp listPersonal token
Use this fallback only when the client cannot complete OAuth but supports HTTP headers. Create the token in Settings → Model Context Protocol and store it in an environment variable.
{
"mcpServers": {
"tucloud": {
"type": "http",
"url": "https://dash.tucloud.app/api/mcp",
"headers": {
"Authorization": "Bearer ${env:TUCLOUD_MCP_TOKEN}"
}
}
}
}Available tools
- list_projects and get_project: project inventory, configuration, and status.
- list_repositories: importable GitHub repositories with a suggested TuCloud domain for each.
- list_deployments and get_deployment: deployment history and details.
- get_deployment_build_logs: jobs and real GitHub Actions output.
- get_runtime_logs: access, runtime, or Host Agent error logs.
- list_domains: primary domain, aliases, and redirects.
- list_environment_variables: names and metadata without secret values.
- create_project: imports a GitHub repository as a new project and reserves its permanent domain. It is the only way to create a project.
- create_deployment: starts a deployment for a compatible branch.
- rollback_deployment: restores an available production release.
Security and scope
- Every authorization belongs to one account and can be revoked.
- OAuth tokens are audience-bound and rejected by other endpoints.
- Authorization codes last five minutes, are single-use, and require PKCE S256.
- Project URLs reject deployments and resources from any other project.
- Variable values, secrets, credentials, and encrypted data are never returned through MCP.
- Each call records tool, result, credential, account, and scope for audit.
- Write tools declare risk so the client can request approval before execution.
Troubleshooting
- 401 Unauthorized: complete OAuth, renew authorization, or verify the Bearer token.
- invalid_redirect_uri: the return URL does not exactly match the client registration.
- invalid_grant: the code expired, was already used, or PKCE verification failed.
- Project not found: the ID is outside the account or the URL is scoped to another project.
- Runtime logs are unavailable: the active provider does not use Host Agent or the account is suspended.
- Direct-upload projects cannot start a GitHub deployment: replace static projects with a new upload.