tuqo
DB + Auth

Tuqo + Firebase

Firebase gives you Firestore (NoSQL), authentication and storage through a browser SDK. The web config, apiKey included, is public by design: it identifies the project and is not a secret. Tuqo serves the front end, and it works with Firebase directly.

Static front end on Tuqo + Firebase straight from the browser · free SSL

What Tuqo + Firebase gives you

  • Firestore, a realtime NoSQL database
  • Authentication: Google, email, phone and more
  • Cloud Storage for files
  • Fully client-side, no server
1

Create a Firebase project

In the Firebase console, add a web app and copy the web config (apiKey, projectId and so on).

2

Set up Security Rules

Write access rules for Firestore and Storage. They are what protects the data.

3

Add the Firebase SDK

Add firebase to the site and call initializeApp(config).

4

Deploy to Tuqo

The site on name.tuqo.ru works with Firebase directly over HTTPS.

import { initializeApp } from 'firebase/app'
import { getFirestore, collection, getDocs } from 'firebase/firestore'

// the web config is public: it identifies the project, it is not a secret
const app = initializeApp({ apiKey: '...', projectId: '...' /* ... */ })
const db = getFirestore(app)
const snap = await getDocs(collection(db, 'posts'))

Security

The web config (apiKey) is public by design: it is an identifier, not a secret. The data is protected by Firebase Security Rules. Set them up so the client can do only what is allowed.

Tuqo serves the front end over HTTPS and never touches your data or the service's secrets.

Tuqo + Firebase — frequently asked questions

Is an apiKey in the code a leak? +

No. In Firebase the apiKey is a public project identifier. The data is protected by Security Rules, not by keeping the key secret.

How is Tuqo different from Firebase Hosting? +

Servers in Russia (sites open there without a VPN), custom domains from the Start plan, deploys from an AI agent over MCP. Firebase stays your backend.

Does Firebase Auth work on a static site? +

Yes, fully client-side: Google or email sign-in and sessions work from the browser.

Other integrations