MCP connector · switches on at setup
Desktop Reach
EnableableThe pod drives your machine for the things that have no API — per call, per approval, with a screenshot on the record.
Every tool, and its gate
Three gate modes on every discovered tool
first-useSee the screen (read-only)first-use asks youalwaysClick a targetalways asksalwaysType into a fieldalways asks
on the chain as mcp:<your-desktop>.<tool> · parameters hashed, never raw
What it cannot do
- Act while you are away without a live approval
- Reach another machine on your network
- Run unattended overnight
Where the credential lives
A paired agent on your desktop. The pod calls out; your machine is never exposed inbound.
write-only · never in logs · never in our cloud
Pies that use it
Setting it up
Three steps, one leash
- Pair the desktop agent
- Choose which apps are in scope
- Approve every call — non-read tools never inherit
Keep reading
Up to the directory and the gate it all shares — then two more tools on the same leash.
Wire Desktop Reach into a workforce with a record
See every connector's honest status alongside the rest, then choose your plan.