# Licensing ## How licensing works here The root [`LICENSE.md`](LICENSE.md) is the MIT License, and it covers everything in this repository unless a subdirectory has its own LICENSE file. A subdirectory with its own LICENSE file is licensed under that file instead. Each package also states its licence in its metadata: `license` in `Cargo.toml` or `package.json`, and `project.license` in `pyproject.toml`. Third-party material keeps its original licence. Most of the repository is open source under MIT, including the cua SDK and its language packages, the `cua` command, `cua daemon`, Cua Driver and Lume. Cua Spaces is source-available under the [Functional Source License, Version 1.1, MIT Future License](https://fsl.software) (FSL-1.1-MIT); the table below marks each FSL directory. ## LICENSE files in this repository This table lists every licence file tracked in the repository. Each SPDX identifier comes from the file's text. Where the text alone cannot tell `-only` from `-or-later`, the table uses the variant the package metadata or notices declare. | Path | SPDX licence | Scope | | -------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | [`LICENSE.md`](LICENSE.md) | MIT | Repository default | | [`apps/cua-spaces/LICENSE`](apps/cua-spaces/LICENSE) | FSL-1.1-MIT | Cua Spaces desktop app (Tauri) | | [`apps/cua-spaces-macos/LICENSE`](apps/cua-spaces-macos/LICENSE) | FSL-1.1-MIT | Cua Spaces macOS app (SwiftUI) | | [`libs/cua-spacesd/LICENSE`](libs/cua-spacesd/LICENSE) | FSL-1.1-MIT | cua-spacesd and cua-relay | | [`libs/cua/crates/cua-spaces-app-core/LICENSE`](libs/cua/crates/cua-spaces-app-core/LICENSE) | FSL-1.1-MIT | Spaces app core (the apps' view models) | | [`libs/cua/crates/cua-keyvault/LICENSE`](libs/cua/crates/cua-keyvault/LICENSE) | FSL-1.1-MIT | Cua Keyvault | | [`libs/cua/crates/cua-teleport/LICENSE`](libs/cua/crates/cua-teleport/LICENSE) | FSL-1.1-MIT | Teleport providers and the app-teleport UX | | [`libs/cua/crates/cua-teleport-bundle/LICENSE`](libs/cua/crates/cua-teleport-bundle/LICENSE) | FSL-1.1-MIT | Teleport bundle format | | [`libs/cua/crates/cua-machine-seal/LICENSE`](libs/cua/crates/cua-machine-seal/LICENSE) | FSL-1.1-MIT | End-to-end sealing of secrets to a Space (machine key, pinning) | | [`libs/cua/crates/cua-volume/LICENSE`](libs/cua/crates/cua-volume/LICENSE) | FSL-1.1-MIT | Cua Volume (`cua-volume`) | | [`libs/cua/crates/cua-spaces-ext/LICENSE`](libs/cua/crates/cua-spaces-ext/LICENSE) | FSL-1.1-MIT | Cua Spaces extensions: teleport, the Cua Volume (`cua-volume`) tools, persistent agents, the streaming client behind `StreamSession`, and the daemon extension (Keyvault broker, site login, volume backends) | | [`libs/cua/crates/cua-spaces-ffi/LICENSE`](libs/cua/crates/cua-spaces-ffi/LICENSE) | FSL-1.1-MIT | The Spaces app export: the SDK plus the app core, teleport, the Keyvault client and decoded media (BGRA frames, PCM audio), for the SwiftUI app | | [`libs/cua/crates/cua-spaces-cli/LICENSE`](libs/cua/crates/cua-spaces-cli/LICENSE) | FSL-1.1-MIT | The Cua Spaces build of `cua` (`cua-spaces-cli`), including `cua viewer` and the decoding `cua sb stream-probe` | | [`libs/cua/crates/cua-media-protocol/LICENSE`](libs/cua/crates/cua-media-protocol/LICENSE) | FSL-1.1-MIT | Streaming | `cua-spaces`: `stream::StreamClient` / `StreamConnection` behind `StreamSession` (input crosses as JSON; without a registered client it fails with `host_capability_missing`); `cua-sdk`: `MediaSession` (encoded frames); `cua-cli`: `CliExtension::viewer` and `open_media_decoded`; `cua-proto` (`StreamService`) | `cua-spaces-ext::stream::MediaStreams` (the RCDP client over `cua-media-client`, `cua-media-protocol`, `cua-media-transport`); `cua-spaces-ffi::media_decode` (decoded BGRA and PCM); `cua-spaces-cli` (`cua viewer`, the decoding stream probe); `CuaSpacesStreaming` | | Presence cursors | `cua-spaces`: `presence::PresenceDatagrams` (without it cursors ride the Join stream and `UpdateCursor`) | `cua-spaces-ext::presence_datagrams::QuicPresence` (the `cua-presence/1` QUIC datagram channel) | | [`libs/cua/crates/cua-media-transport/LICENSE`](libs/cua/crates/cua-media-transport/LICENSE) | FSL-1.1-MIT | Streaming transport: RCDP framing and pinned QUIC | | [`libs/cua/crates/cua-media-client/LICENSE`](libs/cua/crates/cua-media-client/LICENSE) | FSL-1.1-MIT | Streaming client: the RCDP client state machine and decoding | | [`libs/cua/crates/cua-media-codec/LICENSE`](libs/cua/crates/cua-media-codec/LICENSE) | FSL-1.1-MIT | Streaming codecs: encoders, decoders, encoder probing and selection, audio capture and Opus | | [`libs/cua/crates/cua-viewer/LICENSE`](libs/cua/crates/cua-viewer/LICENSE) | FSL-1.1-MIT | Native proxy-window viewer for app shares | | [`libs/cua/crates/cua-spacesd-html5/LICENSE`](libs/cua/crates/cua-spacesd-html5/LICENSE) | FSL-1.1-MIT | HTML5 viewer (WebCodecs) and its standalone server | | [`libs/cua/crates/cua-logging/LICENSE`](libs/cua/crates/cua-logging/LICENSE) | FSL-1.1-MIT | Diagnostics for the streaming binaries | | [`libs/spaces-app-swift/LICENSE`](libs/spaces-app-swift/LICENSE) | FSL-1.1-MIT | Swift binding of the Spaces app export, the teleport picker and the streaming client (`CuaSpacesFFI`, `CuaSpacesTeleport`, `CuaSpacesStreaming`) | | [`samples/cua-bots-macos/LICENSE`](samples/cua-bots-macos/LICENSE) | FSL-1.1-MIT | Cua Bots for macOS sample (links the Spaces app export for the Keyvault client) | | [`samples/cua-bots-ios/LICENSE`](samples/cua-bots-ios/LICENSE) | FSL-1.1-MIT | Cua Bots for iPhone sample (builds on the macOS sample's package) | | [`samples/infinite-canvas-swift/LICENSE`](samples/infinite-canvas-swift/LICENSE) | FSL-1.1-MIT | Infinite Canvas sample (uses the streaming client) | | [`samples/openkoalabot-example-swift/LICENSE`](samples/openkoalabot-example-swift/LICENSE) | FSL-1.1-MIT | OpenKoalaBots Swift sample (uses the streaming client) | | [`samples/openkoalabot-example-tauri/LICENSE`](samples/openkoalabot-example-tauri/LICENSE) | FSL-1.1-MIT | OpenKoalaBots Tauri sample (uses the streaming client) | | [`libs/cua-bench/LICENSE`](libs/cua-bench/LICENSE) | MIT | Package | | [`libs/cua-bench-rl/LICENSE`](libs/cua-bench-rl/LICENSE) | MIT | Package | | [`libs/cua-bench-s1/python/LICENSE`](libs/cua-bench-s1/python/LICENSE) | MIT | Package | | [`libs/cua-s1/python/LICENSE`](libs/cua-s1/python/LICENSE) | MIT | Package | | [`libs/kasm/LICENSE`](libs/kasm/LICENSE) | MIT | Package; includes portions copyright Kasm Technologies Inc. | | [`libs/lume/metal-capability-shim/LICENSE`](libs/lume/metal-capability-shim/LICENSE) | MIT | Package | | [`libs/python/cua-sandbox/LICENSE`](libs/python/cua-sandbox/LICENSE) | MIT | Package; `THIRD_PARTY_NOTICES.md` beside it lists derived code | | [`libs/python/som/LICENSE`](libs/python/som/LICENSE) | AGPL-3.0-or-later | Package; `-or-later` per `pyproject.toml` | | [`libs/typescript/core/LICENSE`](libs/typescript/core/LICENSE) | MIT | Package | | [`libs/typescript/fleet/LICENSE`](libs/typescript/fleet/LICENSE) | MIT | Package | | [`libs/cua-driver/rust/crates/cua-perception/tests/quality-corpus/LICENSE`](libs/cua-driver/rust/crates/cua-perception/tests/quality-corpus/LICENSE) | MIT | Test corpus; Cua-authored synthetic data (see its `PROVENANCE.md`) | | [`libs/cua-driver/rust/crates/cua-perception/models/licenses/AGPL-3.0-only.txt`](libs/cua-driver/rust/crates/cua-perception/models/licenses/AGPL-3.0-only.txt) | AGPL-3.0-only | Third-party model licence text; see [`THIRD_PARTY_NOTICES.md`](libs/cua-driver/rust/crates/cua-perception/models/THIRD_PARTY_NOTICES.md) | | [`libs/cua-driver/rust/crates/cua-perception/models/licenses/Apache-2.0.txt`](libs/cua-driver/rust/crates/cua-perception/models/licenses/Apache-2.0.txt) | Apache-2.0 | Third-party model licence text; see [`THIRD_PARTY_NOTICES.md`](libs/cua-driver/rust/crates/cua-perception/models/THIRD_PARTY_NOTICES.md) | Packages without a LICENSE file of their own fall under the root MIT License. When you add a LICENSE file to a subdirectory, add a row here and set the same licence in the package metadata. ## FSL-1.1-MIT (source-available) You may use, copy, modify and self-host the FSL packages, and build on them, for any purpose except a Competing Use: making them, or something substantially similar, available to others as a commercial product or service. Two years after each release, that release is also available under the MIT License. The full terms are in each FSL `LICENSE` file. The FSL parts are Cua Spaces: the two Spaces apps, cua-spacesd, the Spaces app core, the Cua Keyvault, teleport, Cua Volume (`cua-volume`), the streaming client and its codecs and viewers (`cua-media-client`, `cua-media-codec`, `cua-viewer`, `cua-spacesd-html5`, `cua-logging`, the Swift `CuaSpacesStreaming`), and the glue that plugs them into the MIT runtime (`cua-spaces-ext`, `cua-spaces-ffi`, `cua-spaces-cli`, `libs/spaces-app-swift`). The samples that link those pieces are FSL too: Cua Bots (`samples/cua-bots-macos`, `samples/cua-bots-ios`), Infinite Canvas and the OpenKoalaBots Swift and Tauri samples. The streaming protocol (`cua-media-protocol`) and transport (`cua-media-transport`) are FSL too. The general `cua.env.v1` and `cua.daemon.v1` protobuf contract (`cua-proto`) stays MIT, since the whole SDK is built on it; it includes `StreamService` (tickets for a stream, its targets and preferences). The SDK's `MediaSession` (open a stream, receive its encoded frames and audio packets) and `@trycua/cua/spaces/pip` (a picture-in-picture wrapper around a canvas you paint) stay MIT. ## Commercial use and trademarks Offering Cua Spaces, or a product built on it, to others as a hosted or managed service needs a commercial licence: see [COMMERCIAL.md](COMMERCIAL.md). The Cua names and logo are trademarks; see [TRADEMARKS.md](TRADEMARKS.md) for how you may use them. ## How the MIT parts reach Cua Spaces MIT code defines extension points; FSL code implements them; MIT code never links FSL code. | Boundary | MIT side (defines) | FSL side (implements) | | --------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Spaces tools | `cua-spaces`: the tool contract (`cua-spaces-contract`) and `extension::SpacesExtension`; tools no extension serves fail with `host_capability_missing` and say they ship with Cua Spaces | `cua-spaces-ext`: `TeleportExtension` (`teleport_manifest`, `teleport_app`), `DriveExtension` (`drive_*`, persistent agents, routines, notifications, computer access) | | Keyvault and teleport seams | `cua-spaces`: `teleport_broker::SessionBroker`, `site_login::SiteLoginBroker`, `share::ShareConsent` | `cua-spaces-ext::daemon::keyvault` (the Keyvault broker) | | Daemon | `cua-daemon`: `extension::DaemonExtension` (registered per runtime or process-wide) | `cua-spaces-ext::daemon::CuaSpacesDaemon`: Cua Volume (`cua-volume`), teleport, the Keyvault broker and `keyvault.sock`, the persistent-agent supervisor, in the daemon's own process as before | | Command line | `cua-cli`: the `teleport`, `keyvault` and `drive config` command lines and `extension::CliExtension`; without it `cua` runs the Cua Spaces `cua` (`CUA_SPACES_CLI`, the Cua Spaces app bundle, or `cua-spaces-cli` on `PATH`) or says where the command ships | `cua-spaces-cli` | | Bindings | `cua-sdk` (UniFFI `cua_sdk`): every SDK API; `Space.teleport`, `Space.teleport_manifest`, the drive and persistent-agent methods call the Spaces tools, so they work against the Cua Spaces daemon | `cua-spaces-ffi` (UniFFI `cua_spaces_ffi`, one library with `cua_sdk`): the app core, the Keyvault client, host-side app teleport (`Cua.teleport()`) | | Streaming | `cua-spaces`: `stream::StreamClient` / `StreamConnection` behind `StreamSession` (without a registered client it fails with `host_capability_missing`); `cua-sdk`: `MediaSession` (encoded frames); `cua-cli`: `CliExtension::viewer` and `open_media_decoded`; the wire contract (`cua-proto`, `cua-media-protocol`, `cua-media-transport`) | `cua-spaces-ext::stream::MediaStreams` (the RCDP client over `cua-media-client`); `cua-spaces-ffi::media_decode` (decoded BGRA and PCM); `cua-spaces-cli` (`cua viewer`, the decoding stream probe); `CuaSpacesStreaming` | | TypeScript picker | `@trycua/cua/teleport`: the headless picker over a `TeleportHost` | the Spaces apps' hosts | Orchestration stays MIT on the client side. Creating, listing and deleting Spaces, including Spaces on your own machines (`cua host setup --provide-spaces`, `cua spaces create --on host:`, the host's limits and audit: `cua-spaces::host_spaces`, `cua-host`, the daemon's `HostSpacesService`), is in the MIT crates; the cua-spacesd and relay side of it is FSL like the rest of cua-spacesd. ## What ships under which licence | Artifact | Licence | | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------- | | `cua` CLI (install script, Homebrew, the Python wheel's `bin/cua`, the npm native packages) | MIT | | `cua` Python package, `@trycua/cua`, the Swift package `Cua`, the Kotlin package | MIT | | `cua-sandbox`, `cua-sandbox-apps`, `cua-agent`, `cua-core`, `cua-bench`, `cua-bench-rl` | MIT | | Cua Driver and Lume releases | MIT | | cua-spacesd releases | FSL-1.1-MIT | | Cua Spaces app bundles (Tauri and SwiftUI), including the `cua` they bundle (`cua-spaces-cli`) and the app export library (`libcua_spaces_ffi`, which contains the MIT SDK) | FSL-1.1-MIT as a combined work; the MIT parts inside keep their MIT licence | ## Dependency direction A package that is not FSL never depends on an FSL package: not at runtime, at build time, as a dev dependency or as an optional extra. FSL packages may depend on MIT and Apache-2.0 ones. `scripts/check-license-direction.py --include-dev` enforces this for Cargo, npm, Python and SwiftPM, and CI runs it (`license-check.yml`).