Skip to content
Leaf for platforms

Your customers build apps with AI. Inside your product.

You have the customers, their data and their agent. Leaf runs the apps that agent writes: code, versions, builds, previews, server code, databases and files, behind your API. Your customers never see Leaf.

How it fits

Your product in front. Leaf behind it.

Your backend calls Leaf for each of your customers. Their apps open in your page, on their own address, isolated from it.

Your product

1
Your customersOne Leaf organisation each
2
Your agentWrites and previews their apps
3
Your backendSigns every call
LeafRunning
  • Code and versionskept
  • Type checkslive
  • Buildssandboxed
  • Previewsin your page
  • Server code and dataper app
  • Usageper hour

Their apps

A
In your pageA frame only you may open
B
On their domainWhen an app is public
C
Calling your productThrough Leaf, signed
Who keeps what

You keep the customer. We run the code.

You
  • IdentityYour people, your roles. They never sign in to Leaf and get no mail from it.
  • Your agentIts tools and its words. It reads Leaf’s SDK reference as your projects see it.
  • Your pricesYou bill your customers your way. Leaf’s statement gives you each one’s usage, by the hour.
  • What you sellAI or real time of your own? Leaf turns its own off for your apps, so nothing bypasses yours.
Leaf
  • CodeStored with its history, checked as it is written, your own packages included.
  • BuildsIn a closed sandbox, no network but the package registry.
  • HostingPages, server code, databases and files on Cloudflare, near each visitor.
  • PreviewsEvery version at its own address, shown in your page as your product shows it.
Control

Nothing runs that you did not accept.

An app runs code your customer’s agent wrote. Here is what keeps it in its place.

Every call signed

Your backend signs each call with its own key, for one person or for itself, valid five minutes. Leaf holds no secret of yours.

You put apps online

Only your API puts a version online. Each one says what it may do (addresses, secrets, your capabilities): the version a person accepts is the one that runs.

Framed by you alone

Only your origins and your customer’s may frame an app. Your Content-Security-Policy and your script go into every page, frozen with each version.

Who calls, signed by you

Your page hands the app a token you signed. The edge checks it before the app’s code runs, and passes the caller on.

Apps call you through Leaf

An app reaches your product at one address, signed by Leaf with the org, the app and the version. A call never claims a person you did not name.

Secrets typed by a person

Your screen relays a value a person typed. An agent is refused, and nothing reads a value back.

From a request to a running app

Your customer asks. Your product delivers.

1

Their agent writes

Through your agent: code patches, type errors in return, your packages known.

2

A preview, in place

Each preview is a version at its own address, shown in your page.

3

A person accepts

In your permission screen, with what this version may do.

4

You put it online

One call. Pause, resume or delete the same way.

The API

Built like the API you would write.

Versioned by date

Your version is pinned. Leaf changes, your integration does not.

OpenAPI

One document, generated from the routes. Refusals carry a code and what to do next.

Idempotent

An Idempotency-Key on a POST: a retry never makes two.

Signed webhooks

A deployment ready or failed, in your version, signed by Leaf.

Your packages

Uploaded once per version, used by builds and type checks, never fetched from npm.

Copy an app

From one of your customers to another, files and texts included: your app store.

Billing

One invoice a month. By contract.

A subscription that grows with you

A base, plus a price per customer each month.

Usage at Leaf’s prices

Every unit your customers’ apps use, metered by the hour.

A statement you can rebill

Per customer, per item, per hour, through the API and your dashboard.

Never cut

Leaf never pauses your customers for money. You pause your own.

Questions

Do our customers see Leaf?

No. They use your product. Their apps live on Leaf’s addresses or their own domain, and a paused app shows a neutral page.

Which frameworks can an app use?

Any front end that builds to static files (Vite and React, Astro), plus an optional server part. An app is a site in a frame, so nothing of Leaf runs in your page.

How do we start?

We set up your platform with you: your keys, your webhook, your test page and your contract. Then your backend calls the API.

Where does the data live?

Leaf’s platform runs in the European Union. Apps run on Cloudflare, near their visitors.

Building a product your customers extend?

Tell us about it. Every message gets an answer.