Skip to content
AI Primer
release

Cua launches Spaces for agent-controlled desktops

Cua Spaces provides agent-controlled desktops on local or remote machines. The free, source-available release includes approved app-session transfers, a locked local Keyvault, and separate human and agent cursors.

6 min read
Cua launches Spaces for agent-controlled desktops
Cua launches Spaces for agent-controlled desktops

TL;DR

  • Cua Spaces shipped as a free, source-available Mac app for agent-controlled desktops, according to Cua's announcement.
  • Teleport moves approved app sessions into a Space; Cua says sensitive reads require Touch ID.
  • Humans and agents get separate cursors on the same desktop, with live takeover in Cua's demo.
  • Spaces extend to machines users own beyond their laptops, as described in Cua's multi-device announcement.

Chrome sessions cross machines through a neat bit of cookie decryption and re-encryption, without copying the source Mac's key. Cua's Keyvault guide documents a direct transfer path outside the vault, while its SDK reference says agents inside Spaces run auto-approved.

macOS VMs and Linux containers

Spaces gives agents VM or container desktops that humans can watch from a Mac app. Cua teased the launch with an “AGENT READY” video before announcing the macOS rollout in its launch thread.

The launch page and linked announcement describe the desktop abstraction; the platform requirements differ:

  • macOS: Virtual machines require Apple Silicon. Images are built locally on the Mac, according to Cua's launch page.
  • Linux: Container desktops run through Docker or Podman. The SDK walkthrough also supports Colima and calls for about 4 GB of free memory.

Each Space runs cua-spacesd, which handles streaming, input through Cua Driver, and incoming apps and files, according to the Spaces documentation.

Teleport support and opt-ins

Teleport's “any app” launch pitch has three concrete support levels in the transfer guide:

  • Full: Install the app, open files, or import its state. Listed apps are Firefox, Chrome, Slack, Discord, VS Code, Notion, Unity Hub, Steam, WhatsApp on macOS, and Claude Code.
  • Install only: Install from a pinned, checksum-verified manifest, optionally with files. Blender on x86_64 is listed here.
  • Unsupported: The app is disabled with a reason, such as no build for the destination CPU architecture.

The consent screen enumerates installs, host files and state items before execution. For browsers, three separate opt-ins start unchecked:

  1. Keep me signed in: Session cookies.
  2. Saved passwords: Stored browser logins.
  3. Browsing history: Visited-page history.

Site selection can narrow a transfer to particular domains. Identity providers such as Google, Microsoft, Apple and Okta are never selected automatically.

Chrome encrypts cookies using a per-machine Safe Storage key in the Mac's login Keychain. Cua's Teleport guide describes the session-transfer sequence:

  1. Decrypt selected cookies on the source Mac after approval for the Keychain read.
  2. Transfer the cookie values without transferring the source Safe Storage key.
  3. Re-encrypt them under the destination browser's key before Chrome reads them.

The same guide flags a Chrome password limitation: its Saved passwords transfer copies an encrypted Login Data file that a Space's Chrome cannot decrypt. The documented alternative is cua keyvault import-passwords, followed by vault-mediated site login.

A transferred session remains a live sign-in usable by whoever controls the destination Space, the guide warns.

Keyvault locks

Cua says teleported data stays in a local Keyvault, locked by default.

Vault contents are encrypted on disk and delivered by the Cua daemon, according to the Keyvault documentation. Its controls operate at item level:

  • Locked items: Each use requires approval with Touch ID or a password. One approval normally covers one use.
  • Unlocked items: Any agent with access to the Spaces MCP can request delivery into connected Spaces without another approval.
  • Identity-provider items: Always require approval and cannot be unlocked for unattended access.
  • Deletion: Ends access and wipes copies delivered to Spaces.

The documentation also narrows the launch claim about what passes through the vault: agent session capture through teleport_app and teleport_browser_session uses it, while the plain Teleport picker still moves a session directly without it.

Touch ID does not imply Secure Enclave-backed vault encryption. The guide says this build wraps the vault key with the macOS Keychain or a passphrase and does not use a Secure Enclave key.

Separate cursors

Humans can intervene in the shared desktop and hand control back to agents, each with their own cursor.

Multiple bots also have an explicit coordination primitive: the SDK's SpaceTurnLock serializes turns across threads on one Space, so bots take turns rather than issuing competing actions.

Agent-ready images

Cua pre-grants image permissions and preinstalls tools so agents avoid setup prompts.

Tools listed on Cua's launch page and in the linked launch announcement are distinct from session-access approvals. The original launch page describes the environment; the supplied announcement lists these preinstalled clients:

  • Claude Code
  • Codex
  • Cursor
  • Gemini CLI
  • Cline
  • Kiro
  • OpenClaw

Agent runtimes inside a Space currently run auto-approved, the SDK reference says. ApprovalRequestEvent exists as a type, but no in-Space agent runtime currently emits it; there is no separate approval RPC yet.

Cua Driver

Cua Driver operates native macOS apps without stealing focus, according to its repository.

It exposes separate integration paths:

  • MCP agents: cua-driver mcp, communicating over stdio.
  • Shell automation: cua-driver call.
  • Application SDKs: Python's cua_driver and TypeScript's @trycua/cua-driver call the same in-process native runtime through generated UniFFI bindings.

Direct SDK use requires no separate daemon. The generated bindings sit above a versioned C ABI.

Local, direct and relay machines

Cua presents connected machines in one list, each with a live desktop stream.

The app, CLI, SDKs and daemon share a registry at ~/.cua/spaces.json. The Spaces documentation defines three entry types:

  • Local: Create a new Space on the current machine with spaces.create(options).
  • Direct: Register an existing machine using spaces.add(url, token).
  • Relay: Automatically discover machines configured with cua host setup.

Streams use short-lived tickets bound to a target, codec and policy, then carry media over WebSocket or QUIC, according to the streaming guide.

Own-cloud availability is described differently across sources: Cua advertises it in the launch thread, while the Spaces documentation labels it “coming soon.”

Free access and licensing

Spaces is source-available under FSL-1.1-MIT; Cua Driver remains MIT-licensed.

The linked launch page describes free access, and the original announcement lists the hosted relay as free during early access.

Pro and Teams are announced as coming soon, with:

  • Shared team machines.
  • Session handoff.
  • Keyvault sync.
  • Admin controls.

Further reading

Discussion across the web

Where this story is being discussed, in original context.

On X· 1 thread
macOS VMs and Linux containers2 posts
Share on X