Skip to main content
A web app is a primitive of an agent, like a skill or a webhook. It gives the people who work with the agent a page of their own: a ticket board, a review queue, a dashboard. You build it with lua apps new and release it with the agent.

What a web app is

A web app has two parts:
  • Pages. A Vite + React project in src/apps/<name>/web. It runs in the browser. The template uses the @lua-ai-global/ui components and Tailwind, so the app looks like the rest of Lua.
  • Routes. Typed handlers in src/apps/<name>/app.ts, defined with defineWebApp. They run on Lua, in the same sandbox as your tools, with Data, env(), and fetch. The page calls them with lua.api() from @lua-ai-global/app-client.
The app is listed under webApps on your LuaAgent. lua push webapp creates a version of it, and the agent version that pins that version makes it live. Rolling the agent back rolls the app back with it.

Where it opens

A live app opens full page, by URL:
  • In Lua Workspace in the browser, at https://workspace.heylua.ai/apps/<agentId>/<appName>. All your apps are listed at https://workspace.heylua.ai/apps.
  • In the admin console, at https://admin.heylua.ai/admin/agents/<agentId>/apps.
Neither has a menu entry for apps yet, and the native desktop app does not open them yet.

Who can open it

The agent’s read permission decides. Anyone who can read the agent can open its apps: every member of the organization for an agent that is not private, and only the people who can see the agent for a private one. Anyone else, including people in other organizations, is told that the app does not exist or that they cannot open it. An admin can switch an app off, and on again, from the admin console.

How it stays safe

  • Its own origin. Each app runs on an origin of its own, separate from Lua Workspace, the admin console, and every other app. A page cannot read another app’s data or the shell’s.
  • A handed-over session. When you open an app, the shell hands it a session for you. The page never sees your password or the shell’s own token, and it keeps the session in memory only.
  • Routes run as you. Every route call carries the signed-in person as auth. A route never runs anonymously or with an API key, so a write can record who made it, and the page needs no secrets: the keys your routes use stay on Lua.

Next steps

Build and open your first web app

Scaffold, run, push, and open an app in 20 minutes.

Write routes and pages

Schemas, the page client, versions, access, and limits.