Windows computer-use MCP server that lets AI agents interact with the Windows operating system through UI state, keyboard and mouse actions, application control, file navigation, QA testing, and browser DOM mode.
Windows MCP can interact with native Windows UI, open applications, control windows, simulate keyboard and mouse input, capture UI state, and automate browser content., Agents may interact with logged-in apps, desktop files, system dialogs, browsers, email clients, terminals, or enterprise software visible on the desktop., Use a test Windows account or VM for automation and require human approval before sending messages, submitting forms, changing settings, deleting files, or controlling sensitive applications., Background installation creates a per-user scheduled task and log files; review whether persistent background automation is appropriate before installing it.
Privacy notes
Window titles, UI text, file names, desktop state, browser content, application data, logs, and user input may be exposed to the MCP client and model., Automation logs can include private document names, customer data, credentials shown on screen, internal URLs, and enterprise application state., Browser DOM mode may expose page content from logged-in Chrome, Edge, or Firefox sessions.
Author
CursorTouch
Submitted by
oktofeesh1
Claim status
unclaimed
Last verified
2026-06-05
Decision playbook
Review trust signals before you adopt
Signals are present but mixed. Use the checklist below to confirm the source and operational safety for your environment.
Compare context
Selected
0
Current score
63
Baseline
—
Delta
No baseline selected
No major trust-signal divergence detected in the current selection.
Source and provenance checks
Needs review
Confirm ownership and provenance before trusting install instructions.
Source link availableRequired
Open the canonical repository and verify ownership.
Done
Source provenance statusRequired
Marked as source-backed.
Done
Metadata reviewed
No reviewed flag detected in metadata.
Pending
Safety and privacy checks
Complete
Validate risk disclosures before installation or API wiring.
Safety notes presentRequired
Review the listed safety guidance before running commands.
Done
Privacy notes presentRequired
Review data handling notes before connecting accounts or secrets.
Done
Trust level risk gateRequired
Trust level does not block evaluation.
Done
Package and install checks
Needs review
Check package metadata and artifact integrity signals.
Install payload available
Install or copy payload is available for review.
Done
Package verification flag
No package verification flag provided.
Pending
Checksum metadata
No checksum provided for downloaded artifact.
Pending
Compare-driven decision checks
Needs review
Use compare context to validate trade-offs before adoption.
Compare tray has multiple entries
Add at least one more entry to compare trust differences.
4 safety and 3 privacy notes across 3 risk areas. Review closely: credentials & tokens.
3 areas
SafetyGeneralWindows MCP can interact with native Windows UI, open applications, control windows, simulate keyboard and mouse input, capture UI state, and automate browser content.
SafetyLocal filesAgents may interact with logged-in apps, desktop files, system dialogs, browsers, email clients, terminals, or enterprise software visible on the desktop.
SafetyLocal filesUse a test Windows account or VM for automation and require human approval before sending messages, submitting forms, changing settings, deleting files, or controlling sensitive applications.
SafetyLocal filesBackground installation creates a per-user scheduled task and log files; review whether persistent background automation is appropriate before installing it.
PrivacyLocal filesWindow titles, UI text, file names, desktop state, browser content, application data, logs, and user input may be exposed to the MCP client and model.
PrivacyCredentials & tokensAutomation logs can include private document names, customer data, credentials shown on screen, internal URLs, and enterprise application state.
PrivacyCredentials & tokensBrowser DOM mode may expose page content from logged-in Chrome, Edge, or Firefox sessions.
Safety notes
Windows MCP can interact with native Windows UI, open applications, control windows, simulate keyboard and mouse input, capture UI state, and automate browser content.
Agents may interact with logged-in apps, desktop files, system dialogs, browsers, email clients, terminals, or enterprise software visible on the desktop.
Use a test Windows account or VM for automation and require human approval before sending messages, submitting forms, changing settings, deleting files, or controlling sensitive applications.
Background installation creates a per-user scheduled task and log files; review whether persistent background automation is appropriate before installing it.
Privacy notes
Window titles, UI text, file names, desktop state, browser content, application data, logs, and user input may be exposed to the MCP client and model.
Automation logs can include private document names, customer data, credentials shown on screen, internal URLs, and enterprise application state.
Browser DOM mode may expose page content from logged-in Chrome, Edge, or Firefox sessions.
Prerequisites
Windows 7, 8, 8.1, 10, or 11.
Python 3.13 or newer.
uv package manager installed.
English as the preferred Windows language, or the App tool disabled for other languages.
MCP client such as Claude Desktop, Perplexity Desktop, Gemini CLI, Qwen Code, or another compatible host.
Windows MCP is a computer-use MCP server for Windows. It bridges AI agents to
the Windows operating system so they can inspect UI state, control apps and
windows, simulate keyboard and mouse input, navigate files, and automate QA
testing or desktop tasks.
The project also documents a browser DOM mode that focuses on web page content
for Chrome, Edge, and Firefox automation.
These sources were reviewed on 2026-06-05. Prefer the live repository for
current client snippets, Windows requirements, transport options, persistent
login-task behavior, and troubleshooting details.
Features
Native Windows UI automation for apps, windows, keyboard, and mouse actions.
UI state capture for agent reasoning.
File navigation and desktop workflow automation.
QA testing support for Windows applications.
Browser DOM mode for cleaner web automation in Chrome, Edge, and Firefox.
PyPI package with uvx windows-mcp serve setup.
Optional background task install for running the server at login.
Installation
Install uv, then configure your MCP client to run Windows MCP from PyPI:
Restart the client after saving the configuration. See the README for
client-specific notes for Claude Desktop, Perplexity Desktop, Gemini CLI, Qwen
Code, and other Windows MCP hosts.
Use Cases
Automate Windows desktop QA flows from an AI assistant.
Test application UI behavior by clicking, typing, and inspecting state.
Drive repetitive desktop workflows in a controlled Windows VM.
Use browser DOM mode for web automation that focuses on page content.
Let an agent open apps and gather UI state during troubleshooting.
Safety and Privacy
Windows MCP acts on the real Windows desktop. Use a test VM or dedicated account
for automation, keep sensitive apps closed, and require confirmation before
messages, purchases, account changes, system settings changes, or file deletion.
Treat UI state, browser DOM content, window titles, logs, file names, and screen
text as sensitive. These can expose personal data, enterprise data, credentials,
and private application state to the MCP client and model.
Duplicate Check
No CursorTouch/Windows-MCP entry or source URL was found in content/mcp.
This entry is separate from browser-only automation servers and general terminal
or filesystem MCP servers because it focuses on native Windows computer use.
Show that Windows MCP Server is listed on HeyClaude. Paste this Markdown into your README — it renders the badge and links back to this page.
[](https://heyclau.de/entry/mcp/windows-mcp-server)
How it compares
Windows MCP Server side by side with its closest alternative on trust, install, platform support, and disclosed safety notes — all from reviewed registry metadata.
1 trust signal differ across this comparison (Submitter).
Windows computer-use MCP server that lets AI agents interact with the Windows operating system through UI state, keyboard and mouse actions, application control, file navigation, QA testing, and browser DOM mode.
Hyperbrowser's MCP server for AI agents that need hosted browser scraping, crawling, structured extraction, Bing search, persistent browser profiles, and browser-use, OpenAI CUA, or Claude computer-use browser agents.
✓Windows MCP can interact with native Windows UI, open applications, control windows, simulate keyboard and mouse input, capture UI state, and automate browser content.
Agents may interact with logged-in apps, desktop files, system dialogs, browsers, email clients, terminals, or enterprise software visible on the desktop.
Use a test Windows account or VM for automation and require human approval before sending messages, submitting forms, changing settings, deleting files, or controlling sensitive applications.
Background installation creates a per-user scheduled task and log files; review whether persistent background automation is appropriate before installing it.
✓Hyperbrowser MCP can scrape pages, crawl linked pages, extract structured data, search with Bing, create persistent profiles, delete profiles, list profiles, and run browser automation agents.
Browser-use, OpenAI CUA, and Claude computer-use tools can click, type, navigate, and interact with web apps. Keep human approval around authenticated, paid, destructive, or account-changing actions.
Persistent browser profiles can retain session state. Delete profiles that should not be reused and avoid sharing profile identifiers in public logs or prompts.
Scraping and crawling should respect site terms, robots expectations, rate limits, authentication boundaries, and internal data handling rules.
Do not give the MCP server broad access to private web apps, admin consoles, payments, or production dashboards without a scoped task and review plan.
Privacy notes
✓Window titles, UI text, file names, desktop state, browser content, application data, logs, and user input may be exposed to the MCP client and model.
Automation logs can include private document names, customer data, credentials shown on screen, internal URLs, and enterprise application state.
Browser DOM mode may expose page content from logged-in Chrome, Edge, or Firefox sessions.
✓Webpage URLs, page content, screenshots or extracted data, search queries, browser actions, profile identifiers, and tool outputs may be processed by Hyperbrowser and the connected model provider.
Authenticated browser sessions can expose cookies, account data, private documents, customer data, admin UI state, and generated artifacts to the MCP client and model provider.
Keep `HYPERBROWSER_API_KEY`, cookies, one-time codes, session URLs, API responses, and extracted private data out of prompts, commits, issue comments, screenshots, and shared logs.
For regulated or customer-sensitive data, review Hyperbrowser, MCP client, and model-provider retention policies before using browser automation.
Prerequisites
Windows 7, 8, 8.1, 10, or 11.
Python 3.13 or newer.
uv package manager installed.
English as the preferred Windows language, or the App tool disabled for other languages.
Node.js 18 or newer for the `hyperbrowser-mcp` npm package.
A Hyperbrowser account and `HYPERBROWSER_API_KEY` for hosted browser sessions.
An MCP client such as Claude Desktop, Claude Code, Cursor, Windsurf, or another client that can run stdio MCP servers.
Explicit approval for the URLs, websites, accounts, browser profiles, and data classes the agent may access.
Install
uvx windows-mcp serve
claude mcp add hyperbrowser -e HYPERBROWSER_API_KEY=your-api-key -- npx -y hyperbrowser-mcp