Permissions and diagnostics
macOS permission grants, diagnostic probes and install reports.
macOS permission grants, diagnostic probes and install reports.
| Command | Description |
|---|---|
cua-driver permissions | Inspect or raise macOS TCC permission grants (macOS only). |
cua-driver permissions status | Report Accessibility and Screen Recording status through a running daemon (read-only, no prompt). |
cua-driver permissions grant | Launch CuaDriver through LaunchServices so the permission prompts are attributed to the app. |
cua-driver doctor | Run platform-aware diagnostic probes. |
cua-driver diagnose | Print a pasteable install-layout and permission-attribution report. |
cua-driver permissions exists on macOS only; Windows and Linux have no TCC equivalent.
permissions status is read-only and never prompts. It does not run the ScreenCaptureKit probe (macOS Tahoe can show a separate dialog for it), so it reports screen_recording_capturable: null and direct_capture_status: "not_checked", plus the last successful permissions grant verification when one is recorded for the running driver identity.permissions grant launches the installed CuaDriver.app through LaunchServices so the prompts attribute to the app, then requires a successful live capture probe. It never sends a prompt-capable request over the daemon socket.CuaDriver.create() runtimes and cua-driver mcp --direct own their own prompts: there, check_permissions stays read-only even with {"prompt": true}.CuaDriver.app, or the host of a direct runtime).See Permissions for the grant flow and recovery.
Every command also accepts the global options.
cua-driver permissions#Inspect or raise macOS TCC permission grants (macOS only).
macOS only: Accessibility and Screen Recording are macOS TCC grants. See the macOS permissions reference.
cua-driver permissions [COMMAND]Without a subcommand, runs cua-driver permissions status.
Examples
# Report Accessibility and Screen Recording status
cua-driver permissionscua-driver permissions status#Report Accessibility and Screen Recording status through a running daemon (read-only, no prompt). The default subcommand.
cua-driver permissions status [OPTIONS]| Flag | Type | Default | Description |
|---|---|---|---|
--json | boolean | false | Emit machine-readable output. |
Examples
# Report the grants as JSON
cua-driver permissions status --jsoncua-driver permissions grant#Launch CuaDriver through LaunchServices so the permission prompts are attributed to the app.
cua-driver permissions grantExamples
# Request the grants for CuaDriver.app
cua-driver permissions grantcua-driver doctor#Run platform-aware diagnostic probes.
Exit code is non-zero when any probe is an error.
cua-driver doctor [OPTIONS]| Flag | Type | Default | Description |
|---|---|---|---|
--json | boolean | false | Emit the probe report as JSON. |
Examples
# Run the diagnostic probes
cua-driver doctor
# Emit the probe report as JSON
cua-driver doctor --jsoncua-driver diagnose#Print a pasteable install-layout and permission-attribution report.
cua-driver diagnoseExamples
# Print an install and permission report to paste into an issue
cua-driver diagnose| Code | Meaning |
|---|---|
0 | Success. |
1 | Failure: the daemon is not running or is incompatible, a tool call returned an error, or the operation failed. call and direct tool invocations exit with the daemon's result code (1 on a tool error); update --apply passes through the installer's status. |
2 | Invalid input: tool arguments that are not valid JSON, an unknown mcp-config client, or an update --apply refused on a local development install. |
64 | Usage error: an unknown or missing subcommand or argument, or conflicting flags (for example revoke without exactly one of --session or --all, or an authorization flag passed to mcp). |