Remote access for AI agents

MCP Desk — reach any machine by a 9-digit code

AnyDesk-style remote MCP: one lightweight binary per host, a central hub, and stable invite codes so agents and operators can reach machines without brittle tunnels. Share a code, approve on the machine, connect.

Public brand: MCP Desk · Domain: mcpdesk.io · Hub: hub.mcpdesk.io

MCP Desk connecting a laptop to a remote desktop over a secure encrypted path

What it is

MCP Desk lets AI agents reach a machine the way AnyDesk reaches a desktop — one hub, stable machine codes, invite/connect.

One binary per machine

Install the MCP Desk agent (servermcp) on each host. Windows, Linux, macOS, and Android share the same hub protocol.

Central hub

Agents register and heartbeat to the hub. Peers find each other by code, not by IP — no per-session tunnel juggling.

Stable 9-digit codes

Each machine gets a shareable code (xxx xxx xxx) derived from its MAC — same MAC → same code, every time.

MCP Desk on Windows, Linux, and Android devices linked through one hub
One hub protocol across Windows, Linux, macOS, and Android.

How it works

Four steps from zero to a reachable MCP host.

  1. 1

    Install the agent

    Run MCP Desk on the machine you want AI tools to reach. Point it at the hub with --hub-url.

  2. 2

    See your code

    On first run the agent shows your stable 9-digit code plus a short-lived OTP. Share both when requesting access.

  3. 3

    Share or invite

    Inviter sends an invite by code. The invited machine sees who and from where — then Approve or Deny.

  4. 4

    Connected

    After approve, the session opens. Heartbeats keep the device online in the registry.

On the machine

Client behavior after install — code, OTP, approve, and optional always-on service.

Code + rotating OTP

After install the agent shows your stable code and a short-lived OTP. Share both to request access — the code alone isn’t enough.

Approve / Deny

Incoming connect requests pop Approve or Deny on the machine (who + from where). No tunnel until you approve.

Always-on service

Optional Windows service / systemd install keeps the agent online after reboot. Each peer still needs Approve/Deny — or opt-in unattended via <install_dir>/authorized_keys next to the Client binary (see docs).

Hub-aware agent

servermcp --hub-url <hub> auto-registers on start and heartbeats about every 30s. MCP admin tools still work if the hub is briefly down.

MCP Desk approve dialog for an incoming AI agent connection
Approve or deny each inbound session on the machine.

Hub & accounts

The hub is the invite/connect registry. The public hub is live over HTTPS at https://hub.mcpdesk.io — agents connect with --hub-url https://hub.mcpdesk.io.

  • Invite / connect: Inviter sends invite by code → invited machine Approve/Deny → session opens. Heartbeat keeps the device online in the registry.
  • Per-machine MCP: Bearer auth on the agent; optional hub signup/login for ownership. The machine code is what you share for remote access.
  • Accounts: Web signup / login are live against the hub.

Short docs →

Download MCP Desk

Windows, Linux, macOS, Android — same hub protocol. Artifact URLs are placeholders until Deploy publishes builds — swap them in js/config.js.