lua apps new and release it with the agent.
What a web app is
A web app has two parts:- Pages. A Vite + React project in
src/apps/<name>/web. It runs in the browser. The template uses the@lua-ai-global/uicomponents and Tailwind, so the app looks like the rest of Lua. - Routes. Typed handlers in
src/apps/<name>/app.ts, defined withdefineWebApp. They run on Lua, in the same sandbox as your tools, withData,env(), andfetch. The page calls them withlua.api()from@lua-ai-global/app-client.
webApps on your LuaAgent. lua push webapp creates a version of it, and the agent version that pins that version makes it live. Rolling the agent back rolls the app back with it.
Where it opens
A live app opens full page, by URL:- In Lua Workspace in the browser, at
https://workspace.heylua.ai/apps/<agentId>/<appName>. All your apps are listed athttps://workspace.heylua.ai/apps. - In the admin console, at
https://admin.heylua.ai/admin/agents/<agentId>/apps.
Who can open it
The agent’s read permission decides. Anyone who can read the agent can open its apps: every member of the organization for an agent that is not private, and only the people who can see the agent for a private one. Anyone else, including people in other organizations, is told that the app does not exist or that they cannot open it. An admin can switch an app off, and on again, from the admin console.How it stays safe
- Its own origin. Each app runs on an origin of its own, separate from Lua Workspace, the admin console, and every other app. A page cannot read another app’s data or the shell’s.
- A handed-over session. When you open an app, the shell hands it a session for you. The page never sees your password or the shell’s own token, and it keeps the session in memory only.
- Routes run as you. Every route call carries the signed-in person as
auth. A route never runs anonymously or with an API key, so a write can record who made it, and the page needs no secrets: the keys your routes use stay on Lua.
Next steps
Build and open your first web app
Scaffold, run, push, and open an app in 20 minutes.
Write routes and pages
Schemas, the page client, versions, access, and limits.

