Session teleport
Move a signed-in app session from this machine into a Space.
Move a signed-in app session from this machine into a Space.
| Tool | Description |
|---|---|
teleport_manifest | Describe what a session teleport would move. |
teleport_app | Move an app session into the Space. |
Describe what a session teleport would move.
Read on this machine from the app's own provider: items, sizes, which are sensitive and which are checked by default. With space, also reports whether the Space can import the app.
| Providers | all (cloud, local, direct, relay) |
| Platforms | all (macos, windows, linux) |
| Metering | free |
| Approval | permission spaces:teleport_manifest, in spaces:readonly; read-only, idempotent |
| Requires (this machine) | app_sessions |
| Swift SDK | space.sessions.manifest(for:scope:) |
| Rust | Teleport::manifest |
| Parameter | Type | Default | Description |
|---|---|---|---|
app | string | required | App id, e.g. firefox, chrome, claude-code. |
scope | string | full | full (the profile) or tabs. Default full. |
space | string | none | Space to check the receiving side of (GetManifest). Optional. |
JSON: app, display_name, scope, items (each relative_path, label, estimated_bytes, is_sensitive, is_checked_by_default), total_estimated_bytes, notes; with space, a receiver (supported, limitation, app_installed, supported_apps).
invalid_argument, not_found, ambiguous_sandbox, host_capability_missing
Move an app session into the Space.
Moves the app's signed-in session into the Space, but only through the Cua Keyvault and only with the user's consent. This tool never delivers on its own: the first call files a Keyvault access request and returns a request_id; the user approves it in Cua (Touch ID or the login password) or an unattended rule matches; a later call with the same request_id has the Keyvault broker perform the delivery over the daemon's authenticated channel. Without include the manifest's default-checked items move, never everything.
| Providers | all (cloud, local, direct, relay) |
| Platforms | all (macos, windows, linux) |
| Metering | free |
| Approval | permission spaces:teleport_app; destructive |
| Requires (spacesd) | teleport.* |
| Requires (this machine) | app_sessions |
| Swift SDK | space.sessions.send(_ approval:) |
| Rust | Teleport::send |
| Parameter | Type | Default | Description |
|---|---|---|---|
acknowledge_sensitive | boolean | none | Must be true when the selection holds a sensitive item (credentials, cookies). The consent is explicit rather than defaulted. |
app | string | required | App id, e.g. firefox, chrome, claude-code. |
include | string[] | none | Manifest rel_paths to send. Default: the manifest's default-checked items, never everything. An empty list is refused as ambiguous. |
request_id | string | none | The Keyvault request id returned by a previous call. Present on a retry after the user approved the teleport in Cua; the broker then performs the delivery. Absent on the first call. |
scope | string | full | full or tabs. Default full. |
space | string | required | Space id or name. |
JSON. First call: consent_required: true, a request_id, would_send and approve. Retry with request_id once the user approved: moved: true with transferred_paths (what the Space imported), import_ids and expires_ms; or still consent_required while pending; or an error with the Keyvault code (requires_cua_app, denied, disabled) when it cannot proceed.
invalid_argument, not_found, ambiguous_sandbox, spacesd_not_available, capability_missing, host_capability_missing, teleport_refused, transfer_failed