Show HN: OpenComputerUse – Background computer use for agents, as an MCP server OpenComputerUse launched as an open-source MCP server that lets AI agents drive macOS applications in the background without stealing pointer, keyboard focus or the frontmost app. The tool exposes MCP functions including start_session, screenshot, get_ui_tree, click, type_text and run_recipe, and routes recipe steps through a decision model — either TypeSafe Jev (jev-latest) or Cloudflare Clef/Clef-flash on Workers AI — that picks among a window's interactive elements with no branching and no generated text. The companion OpenComputerUse app, built with the IAmJSD/gpui fork, owns sessions and holds the Accessibility and Screen Recording permissions, and the server installs into Claude Code, Claude Desktop, Codex or OpenCode. Computer use for agents that runs in the background, as an MCP server. Start a session with an app and get back a session id. Drive the app with that id, then end the session. The app works behind your other windows, and your pointer, keyboard focus and frontmost app stay where they are. Sessions end when the MCP server exits, including when it is killed. | Tool | What it does | |---|---| | start session | Start an app a .app path, bundle id or name on macOS; an executable elsewhere and return a session id and its windows | | end session , list sessions , list windows | Manage sessions | | screenshot | Capture a session window, even a covered one; ui tree: true adds the accessibility tree | | get ui tree | One line per element: e12 Button "Save" @ x,y wxh actions=press | | click , move mouse , drag , scroll | Pointer actions at window coordinates, or click with element: "e12" | | type text , press key | Text, and chords such as cmd+s or ctrl+shift+tab enter | | set value , element action | Set an element's value, or run press, focus, showmenu, increment and similar actions | | wait | Let the app catch up | | run recipe | Run a fixed list of steps with a decision model see below | | permissions | What the OS needs granted, and whether it is | Every action returns a fresh screenshot unless you pass screenshot: false . Pass ui tree: true to also get the tree. Coordinates are points from the window's top-left, the same grid as its screenshot. run recipe runs straight-line chores without the calling model in the loop: { "session id": "…", "steps": "click the address bar", "type \"example.com\" into the address bar", "press enter", { "click": "the More information link" } } For each step, the runner sends the window's interactive elements to a decision model as the options of one choice question. It acts on the chosen element when the model is confident enough. There is no branching, and the model generates no text. A step it cannot place stops the recipe and returns a screenshot and the tree so the caller can take over. Two models are supported, chosen in the app's settings: - TypeSafe Jev api.typesafe.ai , model jev-latest - Cloudflare Clef / Clef-flash on Workers AI @cf/cloudflare/clef-flash Each platform implements the Platform and Session traits in crates/ocu-core . Everything above them is shared: session ids, ownership, cleanup, the MCP tools and recipes. - Launch: apps open without activating. Your app's windows are put back on top, so the session window sits behind them. - Screenshots: ScreenCaptureKit captures the window itself, so covered windows capture as they look. - Tree and element actions: the Accessibility API, which works on background windows. - Pointer and keys: posted to the app's process through SkyLight. The app is first told its window is active, without being raised; this "focus without raise" approach comes from yabai and trycua/cua. The MCP server is a thin client. The OpenComputerUse app owns the sessions, holds the Accessibility and Screen Recording permissions, and draws a halo and a gliding cursor over the window being driven. It is built with GPUI the IAmJSD/gpui fork . The MCP server starts the app through LaunchServices when needed, so the app keeps its own permissions whichever client started the server. Opening the app shows its window: permissions, one-click install into Claude Code, Claude Desktop, Codex or OpenCode, live sessions, and recipe settings. CODESIGN IDENTITY="Developer ID Application: …" scripts/bundle-macos.sh universal arm64 + x86 64 cp -R dist/OpenComputerUse.app /Applications/ && open /Applications/OpenComputerUse.app The icon is assets/icon.svg ; packaging/macos/icon.sh rebuilds the .icns from it. Sign the bundle with a real identity. An ad hoc signature changes on every build, and macOS then asks for the permissions again. - Display: each session gets a private Xvfb display with its own cookie. The app starts on it via DISPLAY and XAUTHORITY , with Wayland disabled. - Input and screenshots: input goes through XTEST; screenshots read the framebuffer, so menus and popups are included. - Cleanup: Xvfb and the app get PR SET PDEATHSIG , so they die with the server. - Where Xvfb is found: $OCU XVFB , next to the binary, or on PATH . - Not yet: the accessibility tree AT-SPI , so element actions and recipes are unavailable on Linux for now. - Watching a session: connect a VNC server to its display, for example x11vnc -display :N -auth