Docs
Connect your agent
Tofu’s client runs beside your coding agent and reaches the same authenticated control plane as the dashboard. You approve it once in your browser; it asks again before anything that spends, writes to a live service or destroys.
Agent tools
loginfinishLoginconnectionStatus
The local client
Tofu's client is a local stdio MCP bridge: your agent runs it, and it reaches the same authenticated control plane as the dashboard. Node.js 22 or newer is required.
Start on the setup page, choose Codex, Claude Code, Cursor, Kimi Code or another MCP coding agent, and paste the prompt into your agent; the client and skill are pinned by SHA-256, and a mismatch stops the install.
# Private install (0700/0600), then the registration it emits for this client:
TOFU_URL=https://app.trytofu.ai node tofu-agent.mjs setup codex
codex mcp add tofu --env TOFU_URL=https://app.trytofu.ai --env TOFU_CLIENT=codex -- <absolute-node> <absolute-client> mcpTOFU_URL selects the exact trusted origin (HTTPS, or loopback in development) and TOFU_CLIENT names the connection and grants nothing; setup emits argv and configuration without touching your agent settings, and installs the client and skill privately.
A saved credential alone is not proof of connection: the client checks with Tofu. When a host has not picked up a new MCP server in the session it is already in, the installed client’s own command line does the same work without one — see the skill’s Installation and CLI fallback — and the connection is there the next time that host starts.
Signing in
A device flow: the agent starts it, you finish it in a browser where you are already signed in to Tofu.
The agent asks for a code
loginreturns a code and a same-origin approval URL.You approve the request you started
In the browser, on Tofu, for the code your own agent printed.
The agent finishes
finishLogin(at most once every five seconds) completes it.
The connection lasts seven days and is revoked in the dashboard's Agent connections; only a hash of the credential is stored.
How to recognise a real approval. A real Tofu approval happens only at /dashboard/agent?code=, on the same Tofu address you signed in to, and only when a code arrives as XXXX-XXXX-XXXX printed by a coding agent you started yourself. Refuse anything else. Nobody from Tofu, and no other site, needs an approval code, a password, a provider key or a token — and Tofu never asks for one.
Every tool
The same capabilities as the dashboard, grouped the way the dashboard is.
The bridge exposes 45 tools:
| Group | Tools |
|---|---|
| Connection | connectionStatus, login, finishLogin |
| Source | projects, ingest, detect, setFramework, scan |
| Deploy | deploy, status, listDeployments, getBuildLogs, getRuntimeLogs, repairContext, rollback, projectDelete |
| Settings | listEnv, manageEnvironment |
| Database | databaseStatus, databaseCreate, databaseReconcile, databaseDelete, databaseRestore, databaseArchiveDownload, databaseKeep |
| Sign-in | appAuthStatus, appAuthConfigure |
| Sign-in email | appAuthEmailStatus, appAuthEmailConnect, appAuthEmailDisconnect |
| Domains | domainConnect, domainVerify, domainAuthorize, domainAuthorizationStatus, domainRelease, domainAuthorizationRevoke, domains, domainGuidance, domainShop |
| Traffic | siteAnalytics, setSiteAutoInject |
| GitHub | githubStatus, githubSyncDisable |
| Hosting & project | renameProject, hostingStatus |
listEnv returns names and scopes and no values; environment values are entered in the dashboard. Nothing here can change billing, buy or transfer a domain, or run SQL, and DNS is written only through an approval the owner gave on the provider's own screen: domainAuthorize hands the owner that link, after which Tofu writes the records the connection asked for, and appAuthEmailConnect writes the six sending records into a zone only when that approval exists, reporting them to publish by hand otherwise.
What it asks first
Your agent acts on your instructions and asks for your agreement before any call that spends money, writes to a live service or destroys something — and it makes that call on your instructions, never on its own initiative.
These tools need a literal confirmed: true for the exact project or connection they act on — an earlier deploy, scan or upload is not that agreement, and without the literal nothing is sent:
| Tool | Why it asks |
|---|---|
databaseCreate | It spends Tofu's money. |
rollback | It changes which version answers the app's address. |
projectDelete | It removes that one app and takes its address offline for good, refusing an app whose managed database still exists and naming the step that removes it — databaseDelete, or a transfer to your own Supabase organization. |
appAuthConfigure | It writes into that one app's own auth service and changes how its users sign in. |
appAuthEmailConnect, appAuthEmailDisconnect | They write that app's mail settings, its DNS zone and the provider's sending identity. |
domainRelease, domainAuthorizationRevoke | The user sees that connection change. |
setSiteAutoInject | It decides what the next published site hands its visitors. |
deploy with database: true creates a database in the same call; the flag itself is that agreement, so it is sent only after you agreed to a database for that exact app.
databaseDelete and databaseRestore ask for the app's own name instead of a literal. The first removes one managed database this account owns — the data, the schema and the Supabase project behind it, permanently and with no copy kept by Tofu (for an archived database, its stored archive with it); the second puts an archived database back into a new one Tofu runs and pays for, which needs paid hosting. Both refuse a name that is not that app's own. databaseArchiveDownload hands the owner two links to an archived database's stored copy that work for about ten minutes, and changes nothing. databaseKeep is the Database panel's Keep this database: it counts as use of that app's database, so an inactivity warning (databaseStatus's inactivity) ends — for a paying account only; an unpaid account keeps its database by paying.
Limits
What your agent cannot do
Stays with you. It cannot buy or transfer a domain, submit a payment, read an environment value or a database password or connection string, change your plan or billing, or import a repository from GitHub. Those stay with you.
Secrets are typed in the dashboard.
manageEnvironmenthands you the dashboard address for the app; no tool takes or returns an environment value.GitHub needs your browser. Importing a repository or turning automatic updates on uses your own GitHub session in the dashboard; an agent can read the state and turn updates off.
Local only. The client runs over stdio on your machine; this release has no public remote-MCP address to register in a client.
Built-in repair stays in the dashboard.
repairContexthands your agent the same read-only repair brief; starting, reviewing and applying a repair happen in the dashboard.
The ship-it layer for vibe-coded apps. Your agent wrote it — Tofu ships it.
Works in all coding agents
© 2026 Tofu
trytofu.ai