DeskMCP Download
LOCAL-FIRST · OPEN SOURCE · WINDOWS

Your desktop.
Connected to AI.

DeskMCP gives ChatGPT a controlled path to Windows files, owned terminal sessions, Windows UI, isolated Browser Automation and multi-agent virtual desktops — while permission decisions and UAC approval stay on your machine.

27 MCP tools 2 native Windows architectures 0 cloud-side filesystem policy
Current DeskMCP Control Panel showing Gateway, Tunnel and permission profile status
GatewayRunning locally
Permission boundary Explicit. Visible. Yours.
01Local-firstPolicy enforcement on your PC
02Stable surface27 discoverable MCP tools
03Native Windowsx64 + ARM64 installers
04Open sourceApache-2.0 · public releases
01 — CONTROL

Power without
the mystery.

Most bridges hide the dangerous part: what can actually touch your machine. DeskMCP puts that decision in front of you.

01

See the boundary.

Gateway health, Tunnel status, Workspace, permission profile and the Agent Desktop pool are visible in one native control surface.

02

Choose the boundary.

Move deliberately from Read to Write, Full or Unlock. Higher-risk profiles are explicit and session-owned.

03

Keep the boundary local.

The Tunnel transports requests. DeskMCP still decides locally whether filesystem, process, Browser Automation or Windows Computer Use is allowed.

02 — PERMISSIONS

Four modes.
No ambiguity.

The product language matches the risk model. Safe defaults are quiet. Elevated access becomes increasingly obvious.

01
ReadDefault

Inspect files, folders, metadata and bounded search inside the selected Workspace.

Safe default
02
WriteGuarded

Add create, edit, write and move operations while preserving Workspace and observation guards.

Workspace scoped
03
FullSession only

Enable Gateway-owned terminal sessions, including opt-in visible consoles, while retaining DeskMCP's Workspace boundary.

Elevated
04
UnlockSession only

Remove DeskMCP's filesystem sandbox for the session. Windows account permissions still apply, and administrator consoles still require local UAC approval.

Highest access
03 — PRODUCT
DESIGNED TO STAY OUT OF THE WAY

The control panel
is the contract.

One glance tells you whether the bridge is alive, which profile is active, what Workspace is in scope, whether your Tunnel is ready, and which Agent Desktops are available.

  • Live Gateway and Tunnel status
  • Agent Desktop pool for concurrent isolated agent control
  • Browser Automation with DeskMCP-owned profiles and lease lifetime
  • Windows Computer Use with UI Automation and fresh observations
  • Hidden background terminals remain the default
  • Opt-in visible CMD / PowerShell with window_mode: "visible"
  • Windows runas + UAC for hidden or visible admin processes
  • Hidden, visible and elevated process trees remain DeskMCP-owned
  • Local DPAPI protection for runtime secrets

Agent Desktop, Browser Automation and Computer Use stay behind local policy and lease/observation checks; visible consoles still receive keyboard input directly from their Windows window.

Current DeskMCP Control Panel
RuntimeGateway + Tunnel healthy
Active profileVisible before every action
04 — SECURITY

The connection is remote.
The decision stays local.

DeskMCP architecture showing the local Gateway and OpenAI Tunnel
01
Loopback first

The Gateway HTTP service binds to 127.0.0.1.

02
Workspace scoped

Read, Write and Full enforce canonical path boundaries before forwarding work.

03
Owned process sessions

Hidden, visible and elevated consoles stay attached to DeskMCP-owned process trees instead of arbitrary Windows PID control.

04
Native UAC boundary

Administrator processes use Windows runas and still require local approval whether their console is hidden or visible. DeskMCP does not bypass UAC.

05
Isolated agent control

Agent Desktop, Browser Automation and Windows Computer Use stay behind lease, observation and local permission checks.

06
Metadata-only audit

No file contents, secrets, terminal I/O or real PIDs in audit logs.

05 — START

From zero to connected
in three moves.

No Node.js, npm, .NET SDK, Git or source checkout required for the public Windows installer.

  1. 1
    Install DeskMCP

    Run Setup and choose the Workspace DeskMCP may access.

  2. 2
    Create your OpenAI Tunnel

    Paste the Tunnel ID and Runtime API Key into First Run.

  3. 3
    Connect ChatGPT

    Reuse the existing DeskMCP plugin if present; otherwise create it with Tunnel + No auth, then confirm all 27 DeskMCP tools.

LATEST STABLE

Ready when you are.

Choose the installer that matches your Windows architecture.

Latest releaseChecking GitHub…

Windows builds are currently unsigned while Authenticode signing remains pending, so SmartScreen may show an Unknown Publisher warning.

OPEN SOURCE · LOCAL FIRST

Give AI access.
Keep the keys.