Keyvault screens
The Keyvault page, sidebar, list, site detail and the approval prompt.
The Keyvault page, sidebar, list, site detail and the approval prompt.
These APIs are part of the Cua Spaces app export for building Spaces UIs. They are source-available under FSL-1.1-MIT and ship for Swift only (import CuaSpacesFFI); the Rust tab shows the cua-spaces-ffi crate they come from. The open source SDK packages for Python, TypeScript and Kotlin do not include them.
The kv_* functions derive each Keyvault screen from a KeyvaultOverview. kv_approval_open, kv_approval_reduce and kv_approval_view drive the approval prompt; the *_command functions return the KvCommand to send.
KvAccessRow record#| Field | Type | Default | Description |
|---|---|---|---|
kind | KvAccessKind | Kind. | |
key | String | Stable key. | |
text | String | Main text. | |
detail | String | Muted detail. | |
action_label / actionLabel | String | "Revoke", "Remove", "Wipe". | |
command | KvCommand | What the button sends. |
KvAccessKind enum#.grant
.rule
.delivery| Variant | Description |
|---|---|
Grant | A grant. |
Rule | An unattended rule. |
Delivery | Copies in a Space. |
KvRecentRow record#| Field | Type | Default | Description |
|---|---|---|---|
decision | KvDecision | The decision. | |
age | String | "now", "5 min ago". |
KvDecision record#| Field | Type | Default | Description |
|---|---|---|---|
entry | KvAuditEntry | The entry. | |
verb | String | "Approved". | |
tone | KvDecisionTone | Tone. | |
what | String | Item and target, or the actor. |
KvDecisionTone enum#.ok
.deny
.info| Variant | Description |
|---|---|
Ok | Allowed or delivered. |
Deny | Denied, refused, failed. |
Info | Everything else. |
KvTri enum#.on
.off
.mixed| Variant | Description |
|---|---|
On | All on. |
Off | All off. |
Mixed | Some. |
KvSelection enum#.category(category: KvCategory)
.site(key: String)| Variant | Description |
|---|---|
Category | A category. Fields: category: KvCategory |
Site | A site. Fields: key: String |
KvSigningBadge record#| Field | Type | Default | Description |
|---|---|---|---|
text | String | "signed, team X". | |
tone | KvTone | Tone. |
KvTone enum#.ok
.warn
.danger| Variant | Description |
|---|---|
Ok | Verified. |
Warn | Caution. |
Danger | Untrusted. |
KvApprovalRow record#| Field | Type | Default | Description |
|---|---|---|---|
key | String | Row key. | |
title | String | Site or app. | |
account | String | Account, or "Not imported yet". | |
selected | bool | Ticked. | |
is_import / isImport | bool | A new item the approval imports. |
KvApprovalState record#Returned by kv_approval_open, kv_approval_reduce.
| Field | Type | Default | Description |
|---|---|---|---|
request_id / requestId | String | The request. | |
selected | Vec<String> | Ticked row keys (item ids, or import:<n> for new items). |
KvApprovalView record#Returned by kv_approval_view.
| Field | Type | Default | Description |
|---|---|---|---|
request_id / requestId | String | The request. | |
title | String | "Allow com.example.koalabot?" | |
caller | String | Verified caller (short). | |
badge | KvSigningBadge | Signing badge. | |
targets | String | Where to ("dev-1"). | |
wants | String | For how long. | |
summary | String | One-line summary. | |
claims | Vec<String> | Unverified claims. | |
rows | Vec<KvApprovalRow> | Rows. | |
can_approve / canApprove | bool | Approve is enabled. | |
blocked_reason / blockedReason | Option<String> | Why not, in one line (none when it can, or nothing is ticked yet). | |
approve_label / approveLabel | String | "Approve 2 items". | |
gone | bool | The request is gone (answered elsewhere). |
KvCategoryRow record#| Field | Type | Default | Description |
|---|---|---|---|
category | KvCategory | Category. | |
title | String | Title. | |
symbol | String | SF Symbol. | |
count | Option<u32> | Count (none for Recent). | |
badge | Option<u32> | The sidebar badge: Waiting's count while something waits. |
KvConsentChip record#| Field | Type | Default | Description |
|---|---|---|---|
kind | KvConsentChipKind | Kind. | |
text | String | Text. |
KvItemRow record#| Field | Type | Default | Description |
|---|---|---|---|
item | KvItem | The item. | |
account | String | "ada@example.com", "Whole app session", or the profile. | |
consent | Vec<KvConsentChip> | Strongest first; asks when nothing else applies. | |
toggle_enabled / toggleEnabled | bool | The unattended switch can be changed (not an identity provider). | |
toggle_help / toggleHelp | String | The switch's tooltip. |
KvListView record#Returned by kv_list.
| Field | Type | Default | Description |
|---|---|---|---|
title | String | Title. | |
sites | Vec<KvSiteGroup> | Sites (All, or the one site). | |
pending | Vec<KvPendingRow> | Waiting. | |
access | Vec<KvAccessRow> | Access. | |
recent | Vec<KvRecentRow> | Recent. | |
empty_text / emptyText | Option<String> | "No items yet." and friends. |
KvPage record#Returned by kv_page.
| Field | Type | Default | Description |
|---|---|---|---|
ready | bool | Items can be shown. | |
unavailable_title / unavailableTitle | Option<String> | The unavailable heading. | |
message | Option<String> | The broker's sentence. | |
can_setup / canSetup | bool | "Set up Keyvault" shows. | |
can_unlock / canUnlock | bool | "Unlock" shows. | |
kill_switch_visible / killSwitchVisible | bool | The Disable switch shows (this app is first party, a vault exists). | |
kill_switch_enabled / killSwitchEnabled | bool | The switch can be flipped (unlocked). | |
disabled | bool | The kill switch is on. | |
disabled_banner / disabledBanner | Option<String> | "Keyvault is off. Nothing can be teleported." | |
partial_errors / partialErrors | Vec<String> | Sections that failed to load. | |
log_status / logStatus | Option<String> | "Log verified" / "Log tampered at #n". | |
log_tampered / logTampered | bool | The log check failed. | |
protection | Vec<AppFact> | Protection facts. | |
revoke_all / revokeAll | bool | "Revoke all" shows (more than one live grant). | |
has_items / hasItems | bool | Items exist. | |
search_visible / searchVisible | bool | Search shows (more than six items). | |
pending_count / pendingCount | u32 | Pending requests (the sidebar badge). | |
kill_switch_help / killSwitchHelp | String | The switch's tooltip (it reads "on" while the Keyvault works). | |
labels | KvLabels | The page's fixed words. | |
form | Option<KvCredentialForm> | The setup or unlock form, when one applies. |
KvPendingRow record#| Field | Type | Default | Description |
|---|---|---|---|
id | String | Request id. | |
caller | String | Short caller. | |
badge | KvSigningBadge | Signing badge. | |
summary | String | What and where. | |
wants | String | For how long. | |
claims | Vec<String> | Unverified claims (tooltip). |
KvSidebar record#Returned by kv_sidebar.
| Field | Type | Default | Description |
|---|---|---|---|
categories | Vec<KvCategoryRow> | All, Waiting, Access, Recent. | |
sites | Vec<KvSiteRow> | One row per site or app. |
KvSiteDetail record#Returned by kv_site_detail.
| Field | Type | Default | Description |
|---|---|---|---|
group | KvSiteGroup | The group. | |
site_switch / siteSwitch | bool | The site switch shows (more than one account). | |
site_state / siteState | KvTri | The site switch's state. | |
site_switch_enabled / siteSwitchEnabled | bool | The site switch can be flipped. | |
site_switch_help / siteSwitchHelp | String | Its tooltip. |
KvSiteGroup record#| Field | Type | Default | Description |
|---|---|---|---|
key | String | Stable key. | |
title | String | "github.com" or "Slack". | |
app | String | "Chrome", "Slack". | |
rows | Vec<KvItemRow> | Accounts. | |
unattended | KvTri | Unattended across rows. | |
locked | bool | Every row is an identity provider. |
KvSiteRow record#| Field | Type | Default | Description |
|---|---|---|---|
key | String | Group key. | |
title | String | "github.com" or "Slack". | |
accounts | u32 | Accounts. | |
waiting | bool | Something waits for this site. |
KvApprovalAction enum#.toggle(key: String)
.selectAll
.clear| Variant | Description |
|---|---|
Toggle | Tick or untick a row. Fields: key: String |
SelectAll | Tick every row. |
Clear | Untick every row. |
KvCategory enum#.all
.waiting
.access
.recent| Variant | Description |
|---|---|
All | Every site. |
Waiting | Requests waiting for approval. |
Access | Live grants, rules and copies. |
Recent | Recent decisions. |
KvConsentChipKind enum#.pending
.delivered
.granted
.rule
.asks| Variant | Description |
|---|---|
Pending | A request waits. |
Delivered | A copy is in a Space. |
Granted | A live grant. |
Rule | An unattended rule. |
Asks | Nothing: asks every time. |
kv_approval_approve_command#What Approve sends (none while it cannot).
func kvApprovalApproveCommand(overview: KeyvaultOverview, state: KvApprovalState) -> KvCommand?| Parameter | Type | Default |
|---|---|---|
overview | KeyvaultOverview | required |
state | KvApprovalState | required |
Returns Option<KvCommand>
kv_approval_deny_command#What Deny sends.
func kvApprovalDenyCommand(state: KvApprovalState) -> KvCommand| Parameter | Type | Default |
|---|---|---|
state | KvApprovalState | required |
Returns KvCommand
kv_approval_open#Opens the approval sheet with nothing selected.
func kvApprovalOpen(requestId: String) -> KvApprovalState| Parameter | Type | Default |
|---|---|---|
request_id | String | required |
Returns KvApprovalState
kv_approval_reduce#Advances the approval sheet.
func kvApprovalReduce(overview: KeyvaultOverview, state: KvApprovalState, action: KvApprovalAction) -> KvApprovalState| Parameter | Type | Default |
|---|---|---|
overview | KeyvaultOverview | required |
state | KvApprovalState | required |
action | KvApprovalAction | required |
Returns KvApprovalState
kv_approval_view#The approval sheet as drawn.
func kvApprovalView(overview: KeyvaultOverview, state: KvApprovalState) -> KvApprovalView| Parameter | Type | Default |
|---|---|---|
overview | KeyvaultOverview | required |
state | KvApprovalState | required |
Returns KvApprovalView
kv_list#The list for a sidebar selection.
func kvList(overview: KeyvaultOverview, selection: KvSelection, nowMs: Int64, query: String) -> KvListView| Parameter | Type | Default |
|---|---|---|
overview | KeyvaultOverview | required |
selection | KvSelection | required |
now_ms | i64 | required |
query | String | required |
Returns KvListView
kv_page#The page chrome.
func kvPage(overview: KeyvaultOverview, nowMs: Int64) -> KvPage| Parameter | Type | Default |
|---|---|---|
overview | KeyvaultOverview | required |
now_ms | i64 | required |
Returns KvPage
kv_sidebar#The Passwords-style sidebar.
func kvSidebar(overview: KeyvaultOverview, nowMs: Int64) -> KvSidebar| Parameter | Type | Default |
|---|---|---|
overview | KeyvaultOverview | required |
now_ms | i64 | required |
Returns KvSidebar
kv_site_detail#One site's detail.
func kvSiteDetail(overview: KeyvaultOverview, key: String, nowMs: Int64) -> KvSiteDetail?| Parameter | Type | Default |
|---|---|---|
overview | KeyvaultOverview | required |
key | String | required |
now_ms | i64 | required |
Returns Option<KvSiteDetail>
kv_site_toggle#The site switch's command.
func kvSiteToggle(group: KvSiteGroup, on: Bool) -> KvCommand| Parameter | Type | Default |
|---|---|---|
group | KvSiteGroup | required |
on | bool | required |
Returns KvCommand