Your customers build apps with AI. Inside your product.
You have the customers, their data and their agent. Leaf runs the apps that agent writes: code, versions, builds, previews, server code, databases and files, behind your API. Your customers never see Leaf.
Your product in front. Leaf behind it.
Your backend calls Leaf for each of your customers. Their apps open in your page, on their own address, isolated from it.
Your product
- Code and versionskept
- Type checkslive
- Buildssandboxed
- Previewsin your page
- Server code and dataper app
- Usageper hour
Their apps
You keep the customer. We run the code.
- IdentityYour people, your roles. They never sign in to Leaf and get no mail from it.
- Your agentIts tools and its words. It reads Leaf’s SDK reference as your projects see it.
- Your pricesYou bill your customers your way. Leaf’s statement gives you each one’s usage, by the hour.
- What you sellAI or real time of your own? Leaf turns its own off for your apps, so nothing bypasses yours.
- CodeStored with its history, checked as it is written, your own packages included.
- BuildsIn a closed sandbox, no network but the package registry.
- HostingPages, server code, databases and files on Cloudflare, near each visitor.
- PreviewsEvery version at its own address, shown in your page as your product shows it.
Nothing runs that you did not accept.
An app runs code your customer’s agent wrote. Here is what keeps it in its place.
Every call signed
Your backend signs each call with its own key, for one person or for itself, valid five minutes. Leaf holds no secret of yours.
You put apps online
Only your API puts a version online. Each one says what it may do (addresses, secrets, your capabilities): the version a person accepts is the one that runs.
Framed by you alone
Only your origins and your customer’s may frame an app. Your Content-Security-Policy and your script go into every page, frozen with each version.
Who calls, signed by you
Your page hands the app a token you signed. The edge checks it before the app’s code runs, and passes the caller on.
Apps call you through Leaf
An app reaches your product at one address, signed by Leaf with the org, the app and the version. A call never claims a person you did not name.
Secrets typed by a person
Your screen relays a value a person typed. An agent is refused, and nothing reads a value back.
Your customer asks. Your product delivers.
Their agent writes
Through your agent: code patches, type errors in return, your packages known.
A preview, in place
Each preview is a version at its own address, shown in your page.
A person accepts
In your permission screen, with what this version may do.
You put it online
One call. Pause, resume or delete the same way.
Built like the API you would write.
Versioned by date
Your version is pinned. Leaf changes, your integration does not.
OpenAPI
One document, generated from the routes. Refusals carry a code and what to do next.
Idempotent
An Idempotency-Key on a POST: a retry never makes two.
Signed webhooks
A deployment ready or failed, in your version, signed by Leaf.
Your packages
Uploaded once per version, used by builds and type checks, never fetched from npm.
Copy an app
From one of your customers to another, files and texts included: your app store.
One invoice a month. By contract.
A subscription that grows with you
A base, plus a price per customer each month.
Usage at Leaf’s prices
Every unit your customers’ apps use, metered by the hour.
A statement you can rebill
Per customer, per item, per hour, through the API and your dashboard.
Never cut
Leaf never pauses your customers for money. You pause your own.
Questions
Do our customers see Leaf?
No. They use your product. Their apps live on Leaf’s addresses or their own domain, and a paused app shows a neutral page.
Which frameworks can an app use?
Any front end that builds to static files (Vite and React, Astro), plus an optional server part. An app is a site in a frame, so nothing of Leaf runs in your page.
How do we start?
We set up your platform with you: your keys, your webhook, your test page and your contract. Then your backend calls the API.
Where does the data live?
Leaf’s platform runs in the European Union. Apps run on Cloudflare, near their visitors.
Building a product your customers extend?
Tell us about it. Every message gets an answer.