brand-mcp
Provides tools for controlling and automating the Hyprland compositor, including racing multiple focus-actuation paths, verifying window focus, dispatching pointer/keyboard/screenshot/session actions, managing stale targets, and enforcing security policies for agent control.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@brand-mcpfocus the terminal window and type 'ls -la'"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
🐎 brand
The Hyprland agent-control plane that refuses to lie about focus.
Why should I care? Every agent-control tool for Hyprland dispatches a focus command and trusts the
ok. On Hyprland 0.56.x the IPC Lua API silently broke (hlis booleantrue—hyprctl eval "return type(hl.dsp)"errors), so thoseoks were fiction and agents typed into the wrong window. brand races three independent actuation paths concurrently and only declares victory when the compositor itself reports the right window focused. A bareokthat didn't move focus is a loss — retried, aggregated, and reported honestly.
Rebirth of the archived Hypr-Agent-Portal — forked, re-themed, and actively maintained by toxicwind. The original author archived it believing CUA made it redundant; we disagree: nobody else verifies focus.
🎯 Hyper-race focus — plugin dispatcher,
wlrctl, and legacyhyprctlraced concurrently; first strictly-verified win takes it🧬 Native hyprpm plugin — dispatchers run inside the compositor, immune to the IPC-Lua breakage:
manage,pointer,keyboard,screenshot,session,panic,guard,approval🛡️ Stale-target refusal — windows are identified by
address@pid@starttime; a recycled address can never steal focus🔍 Honest errors —
VerificationFailed/StaleTargettaxonomy instead of silent success⌨️ AT-SPI input path — accessibility-native typing, no ydotool daemon
🔒 Security policy — capability allowlists, panic mode, privacy denylist for screenshots, human input preempts the agent instantly
🧪 Composable testing —
BRAND_MOCK_COMPOSITOR=1andBRAND_DRY_RUN=1let you develop the whole stack with no compositor at all
Diagram
flowchart LR
A[MCP client] --> B[brand-mcp.py]
B --> C{focus_window_race}
C -->|A| D["brand:manage focus<br/>(native plugin)"]
C -->|B| E["wlrctl<br/>(external)"]
C -->|C| F["hyprctl focuswindow<br/>(legacy)"]
D --> G[Hyprland compositor]
E --> G
F --> G
G --> H{"hyprctl -j activewindow<br/>== requested address?"}
H -->|yes| I[✅ verified win]
H -->|no| J[❌ path loses,<br/>errors aggregated]Related MCP server: astra-linux-agent
Quick start
hyprpm add https://github.com/toxicwind/brand && hyprpm enable brand && hyprpm reloadpython3 mcp/brand-mcp.py # stdio MCP server — point your agent at it# hyprland.conf — capabilities are opt-in
plugin {
brand {
allow_pointer = 1
allow_keyboard = 1
allow_screenshot = 1
allow_session = 1
}
}Architecture
Layer | Lives in | Job |
MCP server |
| Tool surface: |
Hyper-race |
| Races actuation paths, strict verification only |
Window mgmt |
| Stale-target refusal, |
Native plugin |
| In-compositor dispatchers; bypasses broken IPC Lua |
Input | AT-SPI | Focused-editable text insertion, no daemon |
The key insight: the plugin never touches the IPC Lua state, so the 0.56.x
hl-boolean breakage doesn't apply to it. The Python side treats the plugin as
the preferred path but never the only path — if the plugin is absent or
disabled, the race still runs on wlrctl + legacy hyprctl, verified the same
way.
Config
Plugin block (hyprland.conf, hyprlang or Lua under plugin.brand):
Key | Default | Purpose |
| 1 | Background pointer dispatchers |
| 1 | Background keyboard dispatchers |
| 1 | Compositor screenshot dispatchers |
| 1 | Workspace session dispatchers |
| 1 / 30000 | On-screen agent-activity indicator |
| 1 | Physical input preempts the agent |
| KeePassXC,1Password | Classes hidden from screenshots |
Environment (local dev / CI — see .env.example):
Variable | Purpose |
| Skip the native plugin path; race |
| Log every actuation, change nothing |
| Talk to the in-repo mock instead of a real compositor |
Dev
# plugin
cmake -S . -B build && cmake --build build # -> build/libbrand.so
# tests — self-contained runners, no pytest needed (mock compositor, no Hyprland)
python3 tests/mcp_smoke.py mcp/brand-mcp.py
for t in tests/*.py; do
case "$t" in tests/mcp_smoke.py|tests/mock_compositor.py) continue;; esac
python3 "$t"
doneLicense + security
GPL-3.0 — see LICENSE. Fork lineage: full upstream history preserved
(upstream remote → gfhdhytghd/Hypr-Agent-Portal).
Security model: SECURITY.md. Short version — the plugin is a
deliberately narrow gateway: callers can't name arbitrary Hyprland dispatchers,
every window target is address@pid@starttime qualified, the session lock
blocks all management, and one brand:panic freezes everything.
Related MCP Connectors
Securely control computers you explicitly pair through files, terminals, processes, screenshots, desktop UI/input, clipboard, browser automation, diagnostics, and document tools.
Preflight, approve, and prove consequential agent actions with signed evidence and x402 tools.
Operate Linux, macOS and Windows from your LLM. Every action runs through an auditable allowlist.
Agent-native security, trust, reliability, data and procurement tools for AI workflows.
Related MCP Servers
- FlicenseNot gradedqualityBmaintenanceEnables AI agents to control a Hyprland Wayland desktop by listing windows, capturing screenshots, and sending input to a dedicated agent workspace without disrupting the user's screen.-
- AlicenseNot gradedqualityDmaintenanceEnables an AI agent to see and control a Linux desktop via Wayland/Hyprland, providing screenshots, structured desktop state, pointer/keyboard input, semantic window/workspace tools, and a policy engine for safe execution.Apache 2.0
- AlicenseAqualityCmaintenanceEnables background window capture and input automation without moving the cursor or stealing focus, working across Windows, Linux X11, and Wayland systems.6Apache 2.0
- AlicenseNot gradedqualityCmaintenanceEnables a constrained subagent to perform foreground GUI actions on Hyprland—observing, focusing windows, clicking, typing, scrolling, dragging, and managing the clipboard—under per-action approval with lease, audit log, and kill-switch gating.MIT