Features · Hosting & deploys
Live, and reversible.
Every app gets its own hosting project and trytofu.app address. A new version is checked before it builds, published only after it answers a real request, and kept in a history you can restore from — in the dashboard, or by asking your agent.
What your agent calls
deploystatuslistDeploymentsgetBuildLogsgetRuntimeLogsrollback
Start from the agent. Or from a folder.
Each path goes through the same check and the same publication, and an update replaces the same project’s source — its settings, address and history stay.
Your coding agent
Paste one line into Claude Code, Codex or Cursor. The agent installs Tofu’s client, you approve one sign-in in your browser, and it uploads, checks and deploys from the conversation.
Agent & CLI❯ I want to take my product live with Tofu.A folder or a ZIP
Drop the project folder or a .zip of it in the dashboard. Dependencies and build output are left out, and an update replaces the same project’s source while its settings, address and history stay.
franks-kitchen.zip · node_modules left outA GitHub branch
Import one branch with a read-only grant, pinned to a commit. On the paid plan, turn on automatic updates and a push deploys the branch’s latest commit through the same check.
main · push → deployThe command line
The standalone client runs the same operations from a terminal or a cloud sandbox: Node.js 22 or newer, one approval in your browser, no key pasted anywhere.
$ node tofu-agent.mjs login
Checked before it builds. A refusal submits nothing.
The files about to be uploaded go through the safety check first, and the same check runs again on the exact bytes right before the build. A finding rated critical or high stops it there: nothing reaches the provider, and the version already live keeps serving.
A build that says ready is not yet a live app.
Tofu moves your app’s address only after the new version has answered a request of its own.
Checked
The snapshot is checked; a blocking finding stops here and submits nothing.Built
The provider builds it in the app’s own hosting project while the live version keeps serving.Answered
Tofu requests the new build’s own address. Only an answer counts; a sign-in wall reads as protected, not broken.Published
Only then does your trytofu.app address move. Anything that failed leaves the previous version serving.
What your agent reads back
deploy waits a bounded time for a settled answer, and status continues from there. The answer is machine-readable, so an agent never has to open the address to guess.
publiclyReachable- True only when an anonymous request was served — the answer to “can a visitor open it now?”
verification.accesspublic(served),protection(refused anonymously: an access wall, not a failed build) orunreachable(retried once).serving- Whether this deployment answers the app’s address; a ready build that is not serving was not published.
{
"status": "ready",
"managedUrl": "https://franks-kitchen-3f9a1c07b2e4.trytofu.app/",
"serving": true,
"publiclyReachable": true,
"verification": {
"access": "public",
"httpStatus": 200
}
}Every attempt, on the record. Any healthy one, back in a step.
listDeployments
History
Every attempt with its status, and which one is current: the version last actually published, not simply the newest.
getBuildLogs · getRuntimeLogs
Logs
The build and runtime logs the platform produced, with lines that look like credentials filtered out on a best-effort basis.
rollback
Rollback
Points the address at an earlier deployment that is ready, without a new build. Your data does not move back, and your agent asks you first.
A failed build gets a proposal. You decide what ships.
On the paid plan, Tofu diagnoses a failed deployment and proposes a small, checked change. Nothing reaches your code or your live app until you say so.
It starts on a failure
Open a project whose latest attempt failed and the diagnosis begins — once per failure, while you are there to see it.A bounded proposal
At most eight files, built and checked in an isolated sandbox with no public ports and none of your environment values.Apply, then deploy
Review the before and after. Applying never deploys; the deploy is its own click, through the same check and health check.Undo
Undo restores the exact source the repair replaced. A newer upload is never overwritten.
Built-in repair has a daily allowance and never writes to a GitHub repository. When it is unavailable or past its allowance, repairContext hands your own coding agent a repair brief instead: the failure, its logs and the next steps.
Names in Tofu. Values write-only.
Names and scopes live in the dashboard; values go straight to the hosting provider. A secret is stored there write-only and never read back — not by the dashboard, not by Tofu, not by your agent.
A pasted .env file treats every value as a secret, VERCEL_* names are reserved, and the values Tofu writes for a managed database are managed and read-only. Saving a change does not redeploy; the next deployment picks it up.
Push, and it deploys. Through the same check.
Import a branch, confirm the framework, and turn on automatic updates. Each push deploys the branch’s latest commit through the same check and the same publication; if an update fails, your previous healthy version stays live.
Tofu reads the repository with a short-lived, read-only token and never writes to it. A manual upload pauses automatic updates instead of being overwritten, and your agent can turn them off; turning them on takes your own GitHub approval in the browser.
Request-driven web apps. In the stack you already chose.
Every one of these answers a request and scales to zero between requests. The Free plan publishes a prebuilt static site; server apps need the paid plan.
- Sites and web frameworks
- Next.js
- Vite
- Astro
- SvelteKit
- Nuxt
- Remix
- Gatsby
- Static HTML
Built by the provider from the framework’s own build — or, for a prebuilt static site, published as it is.
- Python
- FastAPI
- Flask
- Django
- Python
Built from the app’s own manifest and started as an HTTP process that answers the address.
- Go
- Go
Built from the app’s own go.mod and started as an HTTP process that reads PORT.
- JavaScript servers
- Express
- Hono
- NestJS
- Node.js server
One entrypoint file the provider finds by name, started as an HTTP process — the server answers /.
- Containers
- Dockerfile (container)
The image your own container file describes, built by the provider and run as a service.
Limits
What is not here yet
What hosting on Tofu does not do, on any plan unless the line says otherwise.
Anything that has to stay running. A background worker, a queue consumer, an always-on scheduler or a non-HTTP service has no path through Tofu, and no plan changes that.
Your own cron schedule. An app’s own
vercel.jsoncrons do not register here; the schedule belongs to whatever calls the app.Preview deployments. Updates follow one branch and one app root per project — no pull-request previews, no tags, and the latest head rather than every commit.
Runtime logs for container apps. They have not been readable so far, and the read says it is unavailable rather than showing an empty log.
Server code on the Free plan. Free takes a prebuilt static site — an
index.htmland its assets, up to 500 files and 10 MB, no build step.An uptime guarantee. Tofu is in alpha: paid plans are rolling out to invited users, and there is no SLA.
Paste one line. Go live.
Your app, its database, your domain and your sign-in — from the agent you already use, in about 10 minutes.
The ship-it layer for vibe-coded apps. Your agent wrote it — Tofu ships it.
Works in all coding agents
© 2026 Tofu
trytofu.ai