Cua Spaces app export
These APIs are part of the Cua Spaces app export for building Spaces UIs. They are source-available under FSL-1.1-MIT and ship for Swift only (import CuaSpacesFFI); the Rust tab shows the cua-spaces-ffi crate they come from. The open source SDK packages for Python, TypeScript and Kotlin do not include them.
KeyvaultClient talks to the Keyvault broker and returns a KeyvaultOverview. The screens derived from it are on Keyvault screens .
AppSensitiveOption record#
Returned by app_picker_sensitive_options .
Field Type Default Description groupAppSensitiveGroupThe group. labelStringLabel. detailStringThe line under the label. checkedboolChecked.
AppSensitiveGroup enum#
Swift Rust
.signIns
.passwords
.history
Variant Description SignInsThe session cookies: what keeps the app signed in. PasswordsSaved passwords. HistoryBrowsing history.
app_sensitive_group_sdk#
The SDK's plan-option group for a picker group.
Swift Rust
func appSensitiveGroupSdk ( group : AppSensitiveGroup) -> TeleportSensitiveGroup
Returns TeleportSensitiveGroup
KeyvaultClient#
The Keyvault broker client: the verified connection to the broker
cua daemon hosts on $CUA_HOME/keyvault.sock. The broker checks this
process's code signature; approvals, re-enabling and unattended-on make
the daemon ask for Touch ID. No call returns a secret value.
Method Description newThe broker in cua_home (None: $CUA_HOME, else ~/.cua). executeRuns one page action (a broker request). lockLocks the vault. overviewEverything the page shows. setup_with_passphraseCreates the vault with a passphrase (and a recovery key, returned once). unlock_with_passphraseUnlocks with the passphrase (sent only to the broker; zeroized here).
KeyvaultClient.new#
The broker in cua_home (None: $CUA_HOME, else ~/.cua).
Parameter Type Default cua_homeOption<String>required
Returns KeyvaultClient
KeyvaultClient.execute#
Runs one page action (a broker request).
Swift Rust
func execute ( command : KvCommand) async throws -> KvOutcome
Returns KvOutcome ยท Async ยท Raises CuaError
KeyvaultClient.lock#
Locks the vault.
Async ยท Raises CuaError
KeyvaultClient.overview#
Everything the page shows. Never fails: an unavailable Keyvault is a
state (availability).
Swift Rust
func overview () async -> KeyvaultOverview
Returns KeyvaultOverview ยท Async
KeyvaultClient.setup_with_passphrase#
Creates the vault with a passphrase (and a recovery key, returned
once). The passphrase goes only to the broker over the verified
Keyvault socket; it is never logged or kept, and zeroized here.
Swift Rust
func setupWithPassphrase ( passphrase : String ) async throws -> String ?
Parameter Type Default passphraseStringrequired
Returns Option<String> ยท Async ยท Raises CuaError
KeyvaultClient.unlock_with_passphrase#
Unlocks with the passphrase (sent only to the broker; zeroized here).
Swift Rust
func unlockWithPassphrase ( passphrase : String ) async throws
Parameter Type Default passphraseStringrequired
Async ยท Raises CuaError
KeyvaultOverview record#
Returned by KeyvaultClient.overview , kv_overview_from_json .
Field Type Default Description availabilityStringready, or why not: not_running, impostor, connect, no_vault, locked, not_first_party, unsupported, error.messageOption<String>A sentence when not ready. statusOption<KvStatus>The broker's status. server_verified / serverVerifiedboolThe daemon was checked against Cua's signature. itemsVec<KvItem>Items. pendingVec<KvPending>Pending requests. grantsVec<KvGrant>Grants. rulesVec<KvRule>Rules. deliveriesVec<KvDelivery>Deliveries. auditVec<KvAuditEntry>Audit tail, oldest first. audit_verification / auditVerificationOption<KvVerification>Chain check. partial_errors / partialErrorsVec<String>Sections that failed while the rest loaded.
KvAccessRequest record#
Field Type Default Description selectorsVec<KvSelector>What. targetsVec<String>Where. actionsVec<String>Actions. duration_secs / durationSecsOption<u64>For how long. usesOption<u32>Uses. reasonStringThe caller's reason (unverified). claimed_name / claimedNameOption<String>The caller's name for itself (unverified). agentOption<String>The named agent the request is for (unverified).
KvAuditEntry record#
Field Type Default Description sequ64Sequence. ts_ms / tsMsu64Time. kindStringKind (consent.allow, ...). actorStringActor. caller_fp / callerFpStringCaller fingerprint. itemOption<String>Item. targetOption<String>Target. decisionStringok, allow, deny, error.detailOption<String>Detail. authlessOption<bool>Written without the MAC key.
KvCaller record#
Field Type Default Description pidi32Pid. uidu32Uid. pathOption<String>Executable. signingKvSigningSigning. first_party / firstPartyboolSatisfied the Cua requirement. os_verified / osVerifiedboolThe OS verified the signature. launched_by / launchedByOption<String>Launched by. verified_name / verifiedNameOption<String>OS-verified leaf name.
KvCookieInfo record#
Field Type Default Description nameStringName. domainStringDomain. sessionboolSession cookie. expires_ms / expiresMsOption<i64>Expiry.
Returned by kv_credential_form .
Field Type Default Description modeKvFormModeSetup or unlock. methodKvMethodTouch ID or a passphrase. helpStringOne line under the form. passphrase_label / passphraseLabelOption<String>The passphrase field's label (passphrase only). confirm_label / confirmLabelOption<String>The second field's label (passphrase setup only). submit_label / submitLabelStringThe button.
KvDelivery record#
Field Type Default Description import_id / importIdStringImport id. targetStringTarget. provider_id / providerIdStringProvider. itemsVec<String>Items. caller_fp / callerFpStringCaller fingerprint. delivered_ms / deliveredMsu64Delivered. expires_ms / expiresMsu64Wiped at. wipedboolAlready wiped.
KvGrant record#
Field Type Default Description idStringId. request_id / requestIdStringRequest. caller_fp / callerFpStringCaller fingerprint. caller_display / callerDisplayStringCaller. itemsVec<String>Items. targetsVec<String>Targets. actionsVec<String>Actions. created_ms / createdMsu64Created. not_after_ms / notAfterMsu64Expires. uses_left / usesLeftOption<u32>Uses left (none: unlimited until expiry). revokedboolRevoked. agentOption<String>The named agent it was approved for.
KvItem record#
Field Type Default Description idStringId. kindStringbrowser_site, site_passwords, app_session.labelStringLabel. provider_id / providerIdStringProvider. app_display / appDisplayStringApp. siteOption<String>Site. accountOption<String>Account. sourceStringProfile. summaryKvItemSummarySummary. warningsVec<String>Warnings. identity_provider / identityProviderboolIdentity providers always ask. policyKvItemPolicyPolicy. created_ms / createdMsu64Created. updated_ms / updatedMsu64Updated. revu64Revision. record_digest / recordDigestStringDigest.
KvItemPolicy record#
Field Type Default Description allowed_targets / allowedTargetsVec<String>Allowed targets (empty: any). ttl_secs / ttlSecsu64Delivery lifetime. unattendedboolUnattended rules may use it.
KvItemSummary record#
Field Type Default Description cookiesVec<KvCookieInfo>Cookies. storage_origins / storageOriginsVec<String>Storage origins. passwordsu32Saved passwords. filesVec<String>Files. keychain_services / keychainServicesVec<String>Keychain services. bytesu64Bytes.
KvLabels record#
Returned by kv_labels .
Field Type Default Description denyString"Deny". reviewString"Reviewโฆ" (opens the approval sheet). cancelString"Cancel". set_up / setUpString"Set up Keyvault". unlockString"Unlock". revoke_all / revokeAllString"Revoke all". confirm_note / confirmNoteStringUnder the approval sheet. protection_title / protectionTitleString"Protection". accounts_title / accountsTitleStringA site's accounts section. app_label / appLabelStringA site's app fact. every_account / everyAccountStringA site's switch.
KvPassphraseCheck record#
Returned by kv_passphrase_check .
Field Type Default Description can_submit / canSubmitboolThe button is enabled. strengthOption<KvStrength>Setup only, once something is typed. hintOption<String>One short line under the fields.
KvPending record#
Field Type Default Description idStringId. callerKvCallerVerified caller. caller_fp / callerFpStringFingerprint. caller_display / callerDisplayStringOne-line verified identity. requestKvAccessRequestThe request. itemsVec<KvItem>Existing items it resolves to. needs_import / needsImportVec<KvSelector>Selectors approval would import. created_ms / createdMsu64Created.
KvRule record#
Field Type Default Description idStringId. itemsVec<String>Items. targetsVec<String>Targets (*: any Space). callersVec<KvRuleCaller>Callers. created_ms / createdMsu64Created. not_after_ms / notAfterMsu64Expires. enabledboolEnabled. noteStringNote.
KvRuleCaller record#
Field Type Default Description fpStringFingerprint. displayStringDisplay.
KvStatus record#
Field Type Default Description versionStringVersion. initializedboolA vault exists. unlockedboolUnlocked. disabledboolThe kill switch is on. caller_first_party / callerFirstPartyboolThis app is first party. caller_display / callerDisplayStringHow the broker sees this app. itemsu32Items. pendingu32Pending requests. unlock_policy / unlockPolicyOption<String>auto or presence.os_protector_available / osProtectorAvailableboolThe daemon can create the OS key store protector (setup offers Touch ID); false for a development daemon, which is passphrase-only. passphrase_available / passphraseAvailableboolA passphrase can always be chosen. unlock_protectors / unlockProtectorsVec<String>Protector kinds that can unlock this vault now (macos-keychain, windows-credential, passphrase, recovery).
KvVerification record#
Field Type Default Description okboolIntact. entriesu64Entries. unauthenticatedu64Entries without a MAC. tampered_line / tamperedLineOption<u64>First tampered line. reasonOption<String>Why.
KvCommand enum#
Swift Rust
.setup
.unlock
. setDisabled ( disabled : Bool )
. setUnattended ( itemIds : [ String ], unattended : Bool )
. revokeGrant ( id : String )
. removeRule ( id : String )
. release ( target : String )
. approve ( requestId : String , items : [ String ] ? )
. deny ( requestId : String )
Variant Description SetupCreate the vault with the OS key store (the daemon asks for presence). A passphrase never travels in a command: the shells pass it to KeyvaultCommands::setup_with_passphrase directly. UnlockUnlock with the OS key store (a passphrase goes to KeyvaultCommands::unlock_with_passphrase). SetDisabledThe kill switch (turning it off asks for Touch ID). Fields: disabled: bool SetUnattendedPer-item unattended (turning on asks for Touch ID). Fields: item_ids: Vec<String>, unattended: bool RevokeGrantRevoke a grant (*: all). Fields: id: String RemoveRuleRemove a rule. Fields: id: String ReleaseWipe a Space's copies. Fields: target: String ApproveApprove a request for exactly these items (the daemon asks for presence). None keeps everything the request asked for, which the approval sheet only sends when the user ticked every row. Fields: request_id: String, items: Option<Vec<String>> DenyDeny a request. Fields: request_id: String
Variant Description SetupNo vault yet. UnlockThe vault is locked.
KvMethod enum#
Variant Description TouchIdThe OS key store (the login keychain), confirmed with Touch ID. PassphraseA passphrase.
KvOutcome enum#
Swift Rust
.done
. recoveryKey ( key : String ? )
. items ( items : [KvItem])
. revoked ( count : UInt32 )
. wiped ( imports : [ String ])
. granted ( grant : KvGrant)
Variant Description DoneNothing to show. RecoveryKeyThe recovery key, shown once and never stored. Fields: key: Option<String> ItemsItems after a policy change. Fields: items: Vec<KvItem> RevokedGrants revoked. Fields: count: u32 WipedImports wiped. Fields: imports: Vec<String> GrantedThe grant an approval minted. Fields: grant: KvGrant
KvSelector enum#
Swift Rust
. item ( id : String )
. site ( app : String , site : String , account : String ? )
. app ( app : String )
. login ( site : String )
Variant Description ItemAn existing item. Fields: id: String SiteA site of an app. Fields: app: String, site: String, account: Option<String> AppA whole app. Fields: app: String LoginA site's saved password, used to sign in (never delivered). Fields: site: String
KvSigning enum#
Swift Rust
. signed ( teamId : String , identifier : String , cdhash : String )
. adHoc ( identifier : String , cdhash : String )
.unsigned
.unknown
Variant Description SignedTeam-signed. Fields: team_id: String, identifier: String, cdhash: String AdHocAd hoc. Fields: identifier: String, cdhash: String UnsignedUnsigned. UnknownUnknown platform.
KvStrength enum#
Variant Description WeakToo short, or easy to guess. FairAcceptable. StrongLong and varied.
The setup or unlock form for an overview (also KvPage.form): Touch ID
when the daemon can use the OS key store, else a passphrase.
Swift Rust
func kvCredentialForm ( overview : KeyvaultOverview) -> KvCredentialForm ?
Returns Option<KvCredentialForm>
kv_duration#
A duration in words ("5 min").
Swift Rust
func kvDuration ( ms : Int64 ) -> String
Parameter Type Default msi64required
Returns String
kv_labels#
The Keyvault's fixed words.
Swift Rust
func kvLabels () -> KvLabels
Returns KvLabels
kv_overview_from_json#
A Keyvault overview from JSON (fixtures, parity flows). Fixture data
only: it carries metadata, never a secret value.
Swift Rust
func kvOverviewFromJson ( json : String ) throws -> KeyvaultOverview
Parameter Type Default jsonStringrequired
Returns KeyvaultOverview ยท Raises CuaError
kv_passphrase_check#
The passphrase fields' hint and whether the form can be sent. Pure: the
passphrase is only measured, never kept.
Swift Rust
func kvPassphraseCheck ( mode : KvFormMode, passphrase : String , confirm : String ) -> KvPassphraseCheck
Parameter Type Default modeKvFormModerequired passphraseStringrequired confirmStringrequired
Returns KvPassphraseCheck
kv_recovery_key_text#
The banner after setup: the recovery key, shown once.
Swift Rust
func kvRecoveryKeyText ( key : String ) -> String
Parameter Type Default keyStringrequired
Returns String
kv_sharing_label#
The always-visible signal while Keyvault sign-ins are live in a Space
(the notch indicator and the menu bar line); none when nothing is live.
Swift Rust
func kvSharingLabel ( overview : KeyvaultOverview, nowMs : Int64 ) -> String ?
Returns Option<String>