> ## Documentation Index
> Fetch the complete documentation index at: https://docs.heylua.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Web apps

> Pages and typed routes that belong to an agent and open in Lua Workspace and the admin console, signed in as the person using them

A web app is a primitive of an agent, like a skill or a webhook. It gives the people who work with the agent a page of their own: a ticket board, a review queue, a dashboard. You build it with `lua apps new` and release it with the agent.

## What a web app is

A web app has two parts:

* **Pages.** A Vite + React project in `src/apps/<name>/web`. It runs in the browser. The template uses the `@lua-ai-global/ui` components and Tailwind, so the app looks like the rest of Lua.
* **Routes.** Typed handlers in `src/apps/<name>/app.ts`, defined with `defineWebApp`. They run on Lua, in the same sandbox as your tools, with `Data`, `env()`, and `fetch`. The page calls them with `lua.api()` from `@lua-ai-global/app-client`.

The app is listed under `webApps` on your `LuaAgent`. `lua push webapp` creates a version of it, and the [agent version](/concepts/releases-and-versions) that pins that version makes it live. Rolling the agent back rolls the app back with it.

## Where it opens

A live app opens full page, by URL:

* In Lua Workspace in the browser, at `https://workspace.heylua.ai/apps/<agentId>/<appName>`. All your apps are listed at `https://workspace.heylua.ai/apps`.
* In the admin console, at `https://admin.heylua.ai/admin/agents/<agentId>/apps`.

Neither has a menu entry for apps yet, and the native desktop app does not open them yet.

## Who can open it

The agent's read permission decides. Anyone who can read the agent can open its apps: every member of the organization for an agent that is not private, and only the people who can see the agent for a private one. Anyone else, including people in other organizations, is told that the app does not exist or that they cannot open it. An admin can switch an app off, and on again, from the admin console.

## How it stays safe

* **Its own origin.** Each app runs on an origin of its own, separate from Lua Workspace, the admin console, and every other app. A page cannot read another app's data or the shell's.
* **A handed-over session.** When you open an app, the shell hands it a session for you. The page never sees your password or the shell's own token, and it keeps the session in memory only.
* **Routes run as you.** Every route call carries the signed-in person as `auth`. A route never runs anonymously or with an API key, so a write can record who made it, and the page needs no secrets: the keys your routes use stay on Lua.

## Next steps

<Columns cols={2}>
  <Card title="Build and open your first web app" href="/build/apps/quickstart">Scaffold, run, push, and open an app in 20 minutes.</Card>
  <Card title="Write routes and pages" href="/build/apps/routes-and-pages">Schemas, the page client, versions, access, and limits.</Card>
</Columns>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.