Tuqo + Firebase
Firebase gives you Firestore (NoSQL), authentication and storage through a browser SDK. The web config, apiKey included, is public by design: it identifies the project and is not a secret. Tuqo serves the front end, and it works with Firebase directly.
What Tuqo + Firebase gives you
- Firestore, a realtime NoSQL database
- Authentication: Google, email, phone and more
- Cloud Storage for files
- Fully client-side, no server
Create a Firebase project
In the Firebase console, add a web app and copy the web config (apiKey, projectId and so on).
Set up Security Rules
Write access rules for Firestore and Storage. They are what protects the data.
Add the Firebase SDK
Add firebase to the site and call initializeApp(config).
Deploy to Tuqo
The site on name.tuqo.ru works with Firebase directly over HTTPS.
import { initializeApp } from 'firebase/app'
import { getFirestore, collection, getDocs } from 'firebase/firestore'
// the web config is public: it identifies the project, it is not a secret
const app = initializeApp({ apiKey: '...', projectId: '...' /* ... */ })
const db = getFirestore(app)
const snap = await getDocs(collection(db, 'posts')) Security
The web config (apiKey) is public by design: it is an identifier, not a secret. The data is protected by Firebase Security Rules. Set them up so the client can do only what is allowed.
Tuqo serves the front end over HTTPS and never touches your data or the service's secrets.
Tuqo + Firebase — frequently asked questions
Is an apiKey in the code a leak? +
No. In Firebase the apiKey is a public project identifier. The data is protected by Security Rules, not by keeping the key secret.
How is Tuqo different from Firebase Hosting? +
Servers in Russia (sites open there without a VPN), custom domains from the Start plan, deploys from an AI agent over MCP. Firebase stays your backend.
Does Firebase Auth work on a static site? +
Yes, fully client-side: Google or email sign-in and sessions work from the browser.