UseMyMac
# UseMyMac

*Left: Claude Code, anywhere. Right: a Mac running `usemymac up`. The agent reaches it only through the printed URL.*
Turn your Mac into a remote computer-use host. One command on the Mac, one paste into
Claude Code or Codex, and the agent can see your screen, click, type, and open apps.
Built on [CUA](https://github.com/trycua/cua)'s `computer-server` for the macOS driver.
UseMyMac adds the parts that make it safe to reach from outside: a bearer token, a tool
allowlist that hides shell and filesystem access by default, a Cloudflare quick tunnel,
keep-awake, and a permissions preflight.
## Quick start
```
uvx usemymac up
```
Or without uv installed:
```
curl -fsSL https://raw.githubusercontent.com/yunfeng-enrich/usemymac/main/install.sh | sh
```
Either way UseMyMac fetches cloudflared on first run and starts the server. It prints one line to paste into your agent, plus the one-line commands:
```
claude mcp add --transport http usemymac https://<host>/<token>/mcp
codex mcp add usemymac --url https://<host>/<token>/mcp
```
The token lives in the URL so no client needs custom headers. `Authorization: Bearer <token>`
against `https://<host>/mcp` works too.
## Permissions
macOS grants Screen Recording and Accessibility per app, and the app is whichever
terminal launched `usemymac`. The first run triggers both prompts. Screen Recording only
takes effect after that terminal is fully quit and reopened. Without it, screenshots
are black and window titles are empty. Check with:
```
usemymac check
```
## What is exposed
By default: screenshot, mouse, keyboard, clipboard, windows, app launch, and the
accessibility tree. Not exposed unless you ask:
- `--allow-shell` adds `computer_run_command`
- `--allow-files` adds file read, write, and delete tools
Other flags: `--no-tunnel` for LAN or SSH-forwarded use, `--width/--height` to scale
screenshots and coordinates for the model, `--port`, `--token`.
## Security
This is your real desktop on a public URL. The token is the only lock, and it is in the
URL, so treat the URL like a password. Both the hostname and the token are new on every
run, so a leaked URL stops working the moment you Ctrl-C. Keep the terminal visible while
an agent is connected. Pass `--token` only if you need a fixed one.
## Status
Spike. Works end to end on macOS 15 with Claude Code over a Cloudflare tunnel.
Not yet: signed menu bar app, persistent tunnel hostnames, per-app allowlists, Lume VM
sandbox mode.
This server cannot be deployed
TDQS
Scored across 34 tools
Most tools are clearly distinct (screenshot, click, type, window management), but computer_get_desktop_state overlaps with computer_screenshot, and computer_get_active_window/computer_get_window_name could be confused. The mouse_down/up and key_down/up pairs are distinct but similar in purpose.
All tools follow a consistent computer_verb_noun pattern (e.g., computer_get_cursor_position, computer_set_window_size, computer_activate_window). The naming is uniform and predictable across the entire set.
34 tools is on the higher end, but the scope is broad (screen, mouse, keyboard, clipboard, windows, accessibility), so each tool covers a distinct action. It feels slightly heavy but justified for a full computer control server.
The tool surface covers the full lifecycle of computer interaction: observation (screenshot, accessibility tree), input (mouse, keyboard, clipboard), window management (get/set/activate/minimize/maximize/close), and app launching. No obvious dead ends for an agent automating a Mac.