cua keyvault
Set up, unlock and lock the Cua Keyvault, with the OS key store or a passphrase.
Set up, unlock and lock the Cua Keyvault, with the OS key store or a passphrase.
| Command | Description |
|---|---|
cua keyvault status | Whether the Keyvault exists and is unlocked, and which protectors (Touch ID with the OS key store, a passphrase) the daemon can use. |
cua keyvault init | Create the Keyvault and print its recovery key once. |
cua keyvault unlock | Unlock the Keyvault with the OS key store, or with its passphrase. |
cua keyvault lock | Lock the Keyvault (unlocking needs the OS key store or the passphrase again). |
cua keyvault import-passwords | Import a browser's saved passwords into the Keyvault, one item per site. |
cua keyvault import-session | Import a signed-in session (cookies, or a single-app session like Slack's) into the Keyvault, without delivering it anywhere. |
cua keyvault requests | Requests waiting for your approval (site logins, teleports). |
cua keyvault approve | Approve a waiting request (the daemon asks for Touch ID or your login password). |
cua keyvault deny | Decline a waiting request. |
Every command also accepts the global options.
The Cua Keyvault the daemon hosts: status, init, unlock, lock, saved passwords and approvals. Passphrases are prompted for (or read from stdin), never arguments.
cua keyvault [OPTIONS] <COMMAND>Examples
cua keyvault status
cua keyvault init --passphrase
cua keyvault unlock --passphrase
cua keyvault import-passwords --browser chrome
cua keyvault requests
cua keyvault approve <request-id>
cua keyvault lockcua keyvault status#Whether the Keyvault exists and is unlocked, and which protectors (Touch ID with the OS key store, a passphrase) the daemon can use.
cua keyvault status [OPTIONS]Examples
cua keyvault status
cua keyvault status --jsoncua keyvault init#Create the Keyvault and print its recovery key once. Uses the OS key store (Touch ID confirms) unless --passphrase or --passphrase-stdin.
cua keyvault init [OPTIONS]| Flag | Type | Default | Description |
|---|---|---|---|
--passphrase | boolean | false | Use a passphrase, typed at a terminal prompt with echo off. |
--passphrase-stdin | boolean | false | Use a passphrase read from the first line of stdin (scripts). |
Examples
# The OS key store (the signed Cua daemon only)
cua keyvault init
# A passphrase, typed twice at a prompt
cua keyvault init --passphrase
# Scripts: the passphrase is the first line of stdin
cua keyvault init --passphrase-stdincua keyvault unlock#Unlock the Keyvault with the OS key store, or with its passphrase.
cua keyvault unlock [OPTIONS]| Flag | Type | Default | Description |
|---|---|---|---|
--passphrase | boolean | false | Use a passphrase, typed at a terminal prompt with echo off. |
--passphrase-stdin | boolean | false | Use a passphrase read from the first line of stdin (scripts). |
Examples
cua keyvault unlock
cua keyvault unlock --passphrasecua keyvault lock#Lock the Keyvault (unlocking needs the OS key store or the passphrase again).
cua keyvault lock [OPTIONS]Examples
cua keyvault lockcua keyvault import-passwords#Import a browser's saved passwords into the Keyvault, one item per site. They stay sealed: agents sign in with them through request_site_login after you approve, and never see them. The daemon asks for Touch ID or your login password.
cua keyvault import-passwords [OPTIONS]| Flag | Type | Default | Description |
|---|---|---|---|
--browser | chrome | chrome | The browser to import from. |
--profile | string | The browser profile (name or path); default: the default profile. | |
--site | string | Only this site (a registrable domain such as github.com). Repeatable; default: every saved site. |
Examples
cua keyvault import-passwords --browser chrome
cua keyvault import-passwords --browser chrome --site github.com --site example.com
cua keyvault import-passwords --browser chrome --profile "Profile 1"cua keyvault import-session#Import a signed-in session (cookies, or a single-app session like Slack's) into the Keyvault, without delivering it anywhere. A later cua teleport push --sandbox NAME (or the review sheet's "Save to Keyvault") can deliver it; it stays sealed until then. The daemon asks for Touch ID or your login password.
cua keyvault import-session [OPTIONS] --app <APP>| Flag | Type | Default | Description |
|---|---|---|---|
--app | string | required | The app to import from (a teleport provider id: chrome, firefox, slack, ...; cua teleport providers lists every one on this machine). |
--profile | string | The browser profile (name or path); default: the default profile. Ignored for a single-app provider (Slack, Discord, ...). | |
--site | string | Only this site's cookies (a registrable domain such as github.com). Repeatable; a browser with none named imports every site's cookies. Ignored (the whole session is one item) for a single-app provider. | |
--include-storage | boolean | false | Also carry each named site's localStorage / IndexedDB origins. |
--include-passwords | boolean | false | Also carry each named site's saved passwords, as part of this same session item (cua keyvault import-passwords keeps them as their own items instead, one per site). |
--session-only | boolean | false | Only session cookies: drop every persistent cookie. |
--drop-long-lived | boolean | false | Drop persistent cookies that expire more than 30 days out (long-lived refresh tokens), keeping short sessions. |
Examples
cua keyvault import-session --app chrome
cua keyvault import-session --app chrome --site github.com --site example.com
cua keyvault import-session --app firefox --profile "Profile 1"
cua keyvault import-session --app slackcua keyvault requests#Requests waiting for your approval (site logins, teleports).
cua keyvault requests [OPTIONS]Examples
cua keyvault requests
cua keyvault requests --jsoncua keyvault approve#Approve a waiting request (the daemon asks for Touch ID or your login password). A site login is approved for one sign-in.
cua keyvault approve [OPTIONS] <ID>| Argument | Type | Default | Description |
|---|---|---|---|
<ID> | string | required | The request id (cua keyvault requests). |
Examples
cua keyvault approve 5f2c9a0ecua keyvault deny#Decline a waiting request.
cua keyvault deny [OPTIONS] <ID>| Argument | Type | Default | Description |
|---|---|---|---|
<ID> | string | required | The request id. |
Examples
cua keyvault deny 5f2c9a0e| Code | Meaning |
|---|---|
0 | Success. |
1 | Failure, or cua do reported an error. |
2 | Invalid argument, or an ambiguous sandbox name (qualify it: local:NAME, cloud:NAME). |
3 | Not found: sandbox, window, skill or image (or an image not published yet). |
4 | Not supported, or not configured (for example no Fleet credentials). |
5 | No cua-spacesd answered, or a transport failure. |
6 | Unauthenticated or permission denied (by Cua, Fleet or your cloud account). |
7 | Not enough free disk space (see cua cache). |
130 | Cancelled (Ctrl-C during a create): what it made was removed. |