How MCP Desk connects
Short reference for codes, hub, invite/connect, and the agent. Not a wall of text.
Your code (MAC → 9 digits)
Each machine gets a stable 9-digit code
(xxx xxx xxx) derived from its MAC. Same MAC → same
code.
- Normalize MAC → 12 lowercase hex digits
- Hash with the shared salt (hub + agent use the same algorithm)
- Map to a 9-digit display code
Local check:
servermcp anyai-code --mac aa:bb:cc:dd:ee:ff
Hub
The hub is the invite/connect registry: register, heartbeat, resolve invites. Peers find each other by code, not by IP.
-
Public hub (HTTPS, live):
https://hub.mcpdesk.io -
Agent URL:
https://hub.mcpdesk.io— agents connect over HTTPS with--hub-url.
Invite / connect
- Install agent → see code + short-lived OTP
- Share code (+ OTP when requesting access)
- Inviter sends invite by code
- Invited machine: Approve / Deny (who + from where)
- Session opens; heartbeat keeps the device online
Optional always-on service (Windows service / systemd) keeps the agent up after reboot. Each peer still needs Approve/Deny unless you opt into unattended access (see below).
Access & security
Every invite defaults to human approval on the Client. Unattended
access is optional and file-gated — like SSH
authorized_keys, not a hub account token.
- Default: stable 9-digit code + rotating OTP. Every invite needs Approve/Deny on the Client. There is no silent accept.
-
Unattended (optional): only if
<install_dir>/authorized_keysexists next to the Client binary. One public key per line (SSH-like format). Empty or missing file → OTP + Approve only. - Challenge / verify: the Client uses that file for key challenge. No file, or no matching key → fall back to OTP + Approve.
-
Hub account token alone does not grant unattended
access — credential ≠
authorized_keys.
On the agent
servermcp --hub-url <hub> auto-registers on start
and heartbeats about every 30s. MCP admin tools still work if the
hub is briefly down. Per-machine MCP uses bearer auth.
servermcp --hub-url https://hub.mcpdesk.io
The public HTTPS hub is live. Health check:
https://hub.mcpdesk.io/health.
Accounts (optional)
Hub signup/login can track ownership. The machine code is still what
you share for remote access. Web
signup /
login are live against the hub at
https://hub.mcpdesk.io.