Give AI agents computers they can use.
Cua Spaces gives your agents full desktops on your Mac and on machines you own. This repository also holds Cua Driver for desktop automation, Lume for local VMs, CUA-S1 decision models and Cua Bench for evaluating computer-use agents.
- Cua Spaces: Install the app and run your first Space.
- Cua Driver: Operate Calculator and verify its result.
- Lume: Create a Tahoe VM and connect over SSH.
- Cua SDK and CLI: Install
cuaand create a local sandbox. - CUA-S1: Explore small, specialized models for computer-use decisions.
- Cua Bench: Create and verify a simulated task.
Bring your own agent and model, or explore CUA-S1 for specialized decisions. Cua provides the computer and automation tools. Computer-Use 2.0 describes an agent moving between code, APIs, and graphical interfaces within the same task.
Cua Spaces is a desktop app that gives your agents full desktops. Each desktop is a Space: a macOS VM built locally on your Mac, or a Linux or Omarchy image. Spaces run on your Mac, on other machines you own, and in your own cloud account (AWS, Google Cloud or Modal), and the app keeps them in your menu bar and notch.
- Teleport. Move a signed-in app, such as Chrome or Slack, into a Space and it opens there still signed in. Your sessions stay in the Cua Keyvault, encrypted on your Mac, and reach a Space only after you approve.
- Multiplayer. You and your agents work on the same desktop, each with your own cursor. Step in to make a choice, then hand the desktop back.
- Agent-ready images. Spaces images ship with cua-spacesd, so agents get processes, files, screenshots and input as soon as a Space starts.
cua-spaces-demo.mp4
Install on macOS 26 or later
curl -fsSL https://cua.ai/install.sh | shOn macOS the installer selects the Cua Spaces app by default and adds the cua CLI. You can also download the signed .dmg, or get the .pkg from the Cua Spaces 0.1.0 release.
Spaces is free for individuals. Pro and Teams plans are coming soon. The app is source-available under FSL-1.1-MIT.
Quickstart | Teleport an app | Share a Space | Host Spaces on a spare Mac (relay, Tailscale or SSH) | Your own cloud | App source
Give your agent tools to inspect and operate native desktop apps and browsers on macOS, Windows, and Linux. Connect through the CLI, MCP, or typed SDKs. Background delivery lets agents work without moving your pointer or taking focus when the app and platform support it; see platform support for the boundaries.
macOS / Linux
/bin/bash -c "$(curl -fsSL https://cua.ai/driver/install.sh)"Windows (PowerShell)
irm https://cua.ai/driver/install.ps1 | iexYour first result: connect your agent, ask it to compute 6 × 7 in Calculator, and have it verify that the app displays 42. The tutorial covers platform setup, permissions, and agent connection.
Drive your first app | Installation | CLI Reference
Using Claude Code, Codex, Cursor, OpenClaw, or another agent? Find your integration. Source documentation and architecture notes live in libs/cua-driver/README.md.
Two Cua Driver sessions select cells in LibreOffice Calc and objects in Inkscape on an Omarchy desktop while a terminal stays in the foreground. Watch the 50-second demo.
recording.mp4
Create and manage local macOS and Linux VMs on Apple Silicon using Apple's Virtualization.Framework.
/bin/bash -c "$(curl -fsSL https://cua.ai/lume/install.sh)"Your first result: create a vanilla macOS Tahoe VM from an Apple restore image, start it, and connect over SSH. The tutorial uses the Lume CLI directly and explains the unattended setup defaults.
Create your first Lume VM | Installation | CLI reference
One SDK and one cua command for local VMs and containers, and for any machine that runs cua-spacesd.
macOS / Linux
curl -fsSL https://cua.ai/install.sh | shWindows (PowerShell)
irm https://cua.ai/install.ps1 | iexIn a terminal the script shows a short checklist: the cua CLI, the Cua Spaces app (default on macOS), the cua-driver MCP and skill for your agents, and hosting this machine. It then runs cua auth login, which signs you in and offers to install cua skills and the cua MCP server into your AI coding agents (Claude Code, Codex, Cursor, and others). Preselect items with sh -s -- --select cua-driver, or skip the checklist with --only cua-driver. See the installer options.
cua sb create ubuntu --name dev # a gVisor container, set up on first use
cua sb exec dev uname -a
cua sb screenshot dev
cua sb rm devThe same sandbox from Python:
from cua_sandbox import Image, Sandbox
async with Sandbox.ephemeral(Image.linux(), local=True) as sb:
print((await sb.shell.run("uname -a")).stdout)- SDK: the same API in Python (
pip install cua), TypeScript (@trycua/cua), Swift (Cua) and Kotlin (generated bindings), running embedded in your process or through a sharedcua daemon. - Sandboxes need no agent inside. Readiness comes from the runtime and optional port probes. Images that ship cua-spacesd (port 3211) add processes, files, screenshots, input through cua-driver, and low-latency video and audio streaming.
- Your own machines.
cua host setupmakes this machine reachable through the cua.ai relay with no port forwarding.
SDK README | Quickstart | CLI reference | Sandbox SDK reference
CUA-S1 is our family of small, specialized System 1 models for computer use. We use "System 1" as an engineering analogy for fast, bounded decisions, such as choosing which value belongs in a field or whether to leave an element alone. It is not a strict classification of model architectures or a replacement for a general-purpose agent's planning and reasoning.
The first research profile focuses on forms: scoring decisions from structured interface elements and document values rather than generating a response token by token. Application code orders the actions, and the optional Cua Driver integration handles execution with explicit action boundaries.
The project includes Python model code, synthetic-data generation, training, and evaluation. The GitHub component is an early, source-only research release; model weights are hosted separately on Hugging Face. The source is MIT-licensed. Check each model and dataset card for its scope, limitations, and artifact-specific license.
Explore CUA-S1 | Model card | Safety and deployment guidance
CUA-S1-FORMS on Hugging Face: Model weights | Dataset
Build computer-use tasks, evaluate agents, and export trajectories for training. Start with a simulated task that requires no VM, Docker, or model API key.
With Python 3.12 or 3.13 and uv installed:
uv tool install 'cua-bench[browser]'
uv tool run --from 'cua-bench[browser]' playwright install chromiumYour first result: create a small task, run its reference solution, and verify that its evaluator reports a reward of 1.0. Then try the same task yourself.
Build your first task | What is Cua-Bench? | CLI reference | Partner with us
| Package | Description |
|---|---|
| cua-driver | Background computer-use agent for macOS, Windows, and Linux |
| cua SDK and CLI | Rust core and the cua command: sandboxes, local runtimes, images, Spaces |
| cua (Python) | The cua SDK for Python (pip install cua) |
| @trycua/cua | The cua SDK for Node and the browser, plus @trycua/cua/spaces |
| Cua (Swift) | The cua SDK for Swift (SwiftPM, XCFramework) |
| cua-sandbox | High-level Python Sandbox/Image/Pool API, a thin wrapper over the cua SDK |
| cua-spacesd | In-sandbox daemon on port 3211: processes, files, desktop, streaming (gRPC) |
| Cua Spaces for macOS | The Spaces app on macOS: menu bar and notch, live streams, teleport, agent threads |
| Cua Spaces core | The shared Spaces app core, and the Tauri app for Linux and Windows |
| cua-agent | AI agent framework for computer-use tasks |
| cua-bench | Benchmarks and RL environments for computer-use |
| lume | macOS/Linux VM management on Apple Silicon |
| lumier | Docker-compatible interface for Lume VMs |
- Documentation: guides, examples, and API reference
- Blog: tutorials, updates, and research
- Discord: community support and discussions
- GitHub Issues: bug reports and feature requests
- Security: private vulnerability reporting
If Cua supports your research, please cite the software:
@software{cua2025,
author = {{Cua AI, Inc.}},
title = {Cua},
year = {2025},
url = {https://github.com/trycua/cua},
license = {MIT}
}For reproducibility, include the Cua release or commit used in your experiments. Citation metadata is also available in CITATION.cff.
We welcome contributions. See our Contributing Guidelines for details.
Everything outside Cua Spaces is MIT-licensed (LICENSE): the cua SDK and its Python, TypeScript, Swift and Kotlin packages, the cua command and cua daemon, Cua Driver, Lume and the rest of this repository unless a directory says otherwise.
Cua Spaces is source-available under FSL-1.1-MIT: the Spaces apps, cua-spacesd, the Cua Keyvault, teleport, Cua Volume (cua-volume) and the streaming client, codecs and viewers. The streaming wire protocol stays MIT. It is free to use, self-host and build on, with no competing hosted service, and each release becomes MIT two years after it ships.
The MIT parts never depend on the FSL parts. Some subdirectories carry their own licence; LICENSING.md lists each one and how the two fit together.
Offering Spaces as a hosted or managed service? See COMMERCIAL.md. For use of our names and logo, see TRADEMARKS.md.
Third-party components have their own licenses:
- Kasm (MIT)
cua-somis an optional package licensed under AGPL-3.0-or-later. Its Ultralytics dependency retains its own license; inspect the resolved dependency version and its notices before redistribution.- The Microsoft OmniParser repository states CC-BY-4.0 for its repository content. Model files downloaded from the separate OmniParser model repository are distinct artifacts; verify the terms published with the exact model revision before redistributing them.
- The optional
cua-perceptionextension is installed separately from the MIT Cua Driver, from the signed assets of acua-perception-v<version>GitHub release. Each release combines an AGPL-3.0-only OmniParser model artifact, Apache-2.0 PP-OCR model artifacts, and a separately packaged ONNX Runtime. The extension is not MIT licensed. Redistributing it, or offering it to users over a network, can trigger AGPL-3.0 source obligations. Cua does not relicense the detector and cannot grant other terms for it. Read the perception third-party notices and precautions before you install, redistribute, or host an extension artifact.
Apple, macOS, Ubuntu, Canonical, and Microsoft are trademarks of their respective owners. This project is not affiliated with or endorsed by these companies.
Thank you to all our GitHub Sponsors.
| Adam Cohen Hillel | CodeRabbit | Zephyr Cloud IO |
|---|---|---|