Share a Space
Let another cua.ai account watch or use one of your Spaces through the relay, and reach a Space from your other devices.
Let another cua.ai account watch or use one of your Spaces through the relay, and reach a Space from your other devices.
Share a Space with another cua.ai account by email or account ID. A viewer
joins with their own named cursor and watches; an editor can also use the
Space. They open it as relay:<machine> from cua spaces ls or the app.
cua spaces share local:studio bob@example.com # viewer
cua spaces share local:studio bob@example.com --role editor # change the role
cua spaces shares local:studio # who, and who is connected
cua spaces unshare local:studio bob@example.com # at once
cua spaces unshare local:studio --all # nobody; leaves the relayIn the app, Share in a Space's toolbar opens the same list.
| Viewer | Editor | |
|---|---|---|
| Presence, with their own named cursor | yes | yes |
| Watch the desktop stream | view only | yes |
| Pointer and keyboard input | refused | yes, as a human |
| Shell, files, clipboard, MCP | refused | yes |
The Space's own cua-spacesd enforces the role, not the caller. A refused call
fails with PermissionDenied (view-only share: <who> cannot call <method>).
Sharing uses the relay and allowlist that unattended access uses:
relay:<id> from cua host setup) is shared directly.allow (editors) and viewers.let shares = ada
.share_space(&info.id, "bob@example.com", ShareRole::Viewer)
.await
.unwrap();The SDK call in other languages is space.share(who, role), with
space.unshare(who) and space.shares(). The MCP tools are share_space,
unshare_space and space_shares.
Sharing asks you first:
cua daemon (the app, cua mcp, agents), with Touch ID or your
login password. An agent can ask to share a Space; only you can allow it.cua CLI without a daemon asks on the terminal. Pass --yes to confirm
up front.Removing someone needs no confirmation.
To reach a Space from your phone or another computer without sharing it with anyone, publish it on the relay:
cua spaces relay-register local:studio # prints relay:<machine>
cua spaces relay-unregister local:studiolet reg = ada.relay_register(&info.id).await.unwrap();Only your account's enrolled devices reach it until you share it. The MCP
tools are relay_register_space and relay_unregister_space.
cua spaces shares lists who has access now.~/.cua/shares-audit.jsonl, hash-chained) records
every share, removal, attach and detach.cua devices audit) records viewer_added,
share_added, share_removed and each shared access.refused ProcessService (view-only share)).| Space | Shareable | Why |
|---|---|---|
Host (relay:<id>) | yes | Already on the relay. |
| Local container or VM | yes, while this machine runs it | Its driver dials the relay. Suspending it disconnects everyone. |
| Cloud | yes | Its driver dials the relay from the cloud. |
Added by address (direct:) | yes, if its driver supports relay_attach | Older drivers report capability_missing. |
| A Space shared with you | no | Only the owner can share (permission_denied). |
An editor gets full control of the Space, including anything signed in there. Share as a viewer unless they need to act.