Resources · Claude connector

Claude MacOS connectorWhat Claude can do on your Mac.

The Claude MacOS connector, MacOS-MCP, exposes 11 tools: 3 read, 7 write, 1 undocumented. Claude can look at your screen, then click, type, launch apps and run commands on the Mac itself. Here is what each tool does, what macOS must allow first, and the one nobody documents.

Verified Trustpilot reviews · AI, automation & growth agency

Overview

Why give Claude hands on your Mac

Most connectors open one online account to Claude. This one, an open-source extension from CursorTouch, opens the computer itself. Through the macOS accessibility layer, Claude can read what is on screen, move the pointer, type, press shortcuts, switch apps and run shell commands or AppleScript, all from a conversation in Claude Desktop.

Get through a fiddly settings screen. You ask Claude to set up an app you rarely open. Claude takes a Snapshot of the interface, then uses Click and Type on the fields instead of reciting instructions for you to follow.

Run a quick terminal job without the terminal. You want a folder of files renamed without opening a shell; Claude passes the command through Shell, which also accepts AppleScript.

Pull a web page into the conversation. Scrape converts a page to Markdown so Claude can quote or summarise it.

What it will not do: CursorTouch says it cannot interact with system authentication dialogs, some apps expose little or nothing to the accessibility layer, and certain specialised fields ignore simulated keystrokes. Nothing happens on a timer either: Claude acts only while it is answering you. For unattended jobs between apps, the Integrations hub lists the automation platforms we cover.

Vocabulary

Five words before you install

The Claude vocabulary around this connector, in one minute.

Connector
The link you set up once between Claude and something you already own, here your Mac, so Claude can use it while it answers.
Tool
One named thing the connector lets Claude do. Claude picks the ones it needs by itself; the directory sheet lists all eleven.
Authorization
The access you grant once so Claude can use what the connector opens. It is given per person and can be taken back.
Approval
The confirmation Claude waits for before doing something that changes things, shown in the conversation at that moment.
MCP
The shared standard connectors are built on: it is what lets an assistant like Claude talk to an outside program, here one running on your Mac.
Connect

Set up the Claude MacOS connector in three steps

  1. 01

    Check the requirements

    CursorTouch lists four prerequisites: macOS 12 or later, Python 3.11 or later, the UV package manager, and Accessibility permission for the app that runs the server. UV installs with the one-line command given on the directory sheet.

  2. 02

    Add the extension in Claude Desktop

    The directory lists MacOS-MCP as a local extension for Claude Desktop. Neither CursorTouch nor the sheet describes the install screens step by step, so follow what Claude Desktop shows you from the connector's sheet.

  3. 03

    Grant the macOS permissions

    In System Settings, grant Accessibility by hand to the app running the server; CursorTouch says this grant is manual. Add Screen Recording if you want Snapshot to capture screenshots. If Snapshot fails, CursorTouch says to check both permissions.

Tools

The 11 tools, sorted by what they do

MacOS-MCP gives Claude 11 tools: 3 that read your account, 7 that change something in it, and 1 no official source describes.

Three tools look or wait, seven act on the Mac, and one is described by no source. Names stay exactly as Claude shows them.

  • 3 read
  • 7 write
  • 1 not documented

What Claude reads (3)

3 tools

Three tools that capture the screen, fetch a web page or pause, without changing anything on the Mac.

Snapshot

Reads the current macOS interface, the windows and on-screen elements, and can include a screenshot.

When it helps
before touching anything, Claude needs to know which window is in front and where the button sits.
Watch out
the screenshot needs Screen Recording permission on top of Accessibility.

Sourcegithub.com · October 1, 2026 ↗

Wait

Pauses execution for a set duration before the next step. CursorTouch says nothing more about it: it is listed with the reads only because CursorTouch describes no effect on your files or apps, not because it reads data.

When it helps
a heavy application is still opening and clicking right away would land on an empty screen.

Sourcegithub.com · October 1, 2026 ↗

Scrape

Pulls the content of a web page and turns it into Markdown that Claude can read, quote or summarise inside the conversation.

When it helps
you want the main points of a supplier's terms page without copying it by hand.

Sourcegithub.com · October 1, 2026 ↗

What Claude does on your Mac (7)

7 tools

Seven tools that click, type, move, launch or run commands. No source describes a confirmation for them: the general rule below applies.

App

Approval: see the rule

Opens an application by name or bundle ID, switches between apps, and resizes or moves their windows.

What Claude asks for
no source describes a confirmation step for this tool; the general approval rule below is what covers it.
When it helps
you want Mail and Calendar side by side before a planning session.

Sourcegithub.com · October 1, 2026 ↗

Shell

Approval: see the rule

Executes shell commands, or AppleScript in its dedicated mode, directly on the Mac. It is the broadest tool in the set: whatever the command does, it does on your machine.

What Claude asks for
CursorTouch documents no specific prompt here, so rely on the default rule and read each command before you agree.
When it helps
batch-renaming a folder of exported photos.

Sourcegithub.com · October 1, 2026 ↗

Click

Approval: see the rule

Presses the mouse at given coordinates, with left, right or double click, exactly as your hand would.

What Claude asks for
nothing tool-specific is documented; the general rule applies.
When it helps
ticking a checkbox buried three levels deep in an app's preferences.

Sourcegithub.com · October 1, 2026 ↗

Type

Approval: see the rule

Enters text where the cursor sits, and can clear what the field already holds before typing.

What Claude asks for
no dedicated confirmation is described for this tool in any source.
When it helps
filling the same contact details into a desktop form that has no import option.
Watch out
CursorTouch notes that some specialised input fields do not receive simulated keystrokes.

Sourcegithub.com · October 1, 2026 ↗

Scroll

Approval: see the rule

Scrolls vertically or horizontally, in the window that has focus or in a given region, to bring hidden content into view.

What Claude asks for
the sources stay silent on a prompt for scrolling; the default rule holds.
When it helps
reaching the bottom of a long settings list before Claude can click the last option.

Sourcegithub.com · October 1, 2026 ↗

Move

Approval: see the rule

Moves the pointer to coordinates, or drags from one point to another. CursorTouch describes nothing beyond the pointer movement itself.

What Claude asks for
no confirmation specific to dragging appears in the documentation.
When it helps
dropping an attachment onto an app that only accepts drag and drop.

Sourcegithub.com · October 1, 2026 ↗

Shortcut

Approval: see the rule

Sends keyboard combinations such as Cmd+C or Cmd+Tab, the quickest way to copy, paste, switch app or trigger a menu command.

What Claude asks for
nothing beyond Claude's general approval rule is documented.
When it helps
copying a figure from one document and pasting it into a spreadsheet.

Sourcegithub.com · October 1, 2026 ↗

Not documented (1)

1 tool

Listed on the directory sheet, but no official source explains what it does. Nothing here is a capability.

Notification

No official source describes this tool. The directory sheet publishes its name only, and the CursorTouch documentation does not mention it, so whether it reads or changes anything is unknown. Claude's general approval rule, described below, is the only reference.

Approvals

What Claude asks before acting

By default, Claude stops and asks before any action it takes on your behalf. With a connector that drives your Mac, that prompt is your main safeguard.

On Team and Enterprise workspaces, owners decide whether members may let certain actions through without being asked each time, and they can restrict what a connector may do for the whole organisation, keeping reads and closing writes for instance. Claude also works with your rights and nothing more: here, those are the rights macOS gives the app running the extension, through the permissions you granted in System Settings.

Plans

Which plans include it

None of the 819 sheets in the official directory shows availability by plan. Connector by connector, the answer is published nowhere.

The general rule is public: remote connectors are open to all users on Claude, Cowork, Claude Desktop and mobile, while desktop extensions such as MacOS-MCP install on Claude Desktop. On Team and Enterprise, an Owner or Primary Owner opens a connector for the organisation first. For this one's current status, check its sheet in the official directory. Only CursorTouch documents it; no Claude help page does.

Limits

Where this connector stops

A connector is not an automation. Claude calls these tools while it answers you; nothing clicks or types on its own when you are away.

The directory's badge is not a security audit, and Anthropic says on every sheet that it does not choose a publisher's tools or guarantee they behave as described. CursorTouch publishes it as an open-source Python package under the MIT licence, which lets you read its code before installing. That matters more than usual here, since these tools act on the whole computer. Install only what you have reason to trust. Other apps and their connectors are listed on the Integrations hub.

Need help

Need help connecting MacOS-MCP to Claude?

A person reads every message.

FAQ

Questions about the Claude MacOS connector

01What can Claude do with the MacOS-MCP connector?
Claude can see and operate your Mac from a conversation in Claude Desktop. It captures the screen state, scrapes a web page into Markdown and pauses between steps. It also launches and arranges apps, clicks, types, scrolls, drags, presses keyboard shortcuts and runs shell commands or AppleScript. CursorTouch documents ten of the eleven tools; the remaining one, Notification, has no description in any source. Everything happens through the accessibility layer of macOS, which is why the permissions matter so much.
02Can Claude change things or run commands on my Mac?
Yes, seven of the eleven tools act on the computer. The broadest is Shell, which runs commands or AppleScript directly on the machine. The others click, type, scroll, drag, press shortcuts and launch or rearrange apps, which means Claude can change settings or documents the same way you would by hand. One tool, Notification, is undocumented, so nobody can say whether it changes anything. Each of these actions plays out live on your screen.
03Does Claude ask before it clicks or runs a command?
By default, Claude asks for confirmation before any action it takes on your behalf. Neither Anthropic nor CursorTouch describes a prompt specific to Shell, Click, Type or the other tools, so that default rule is what applies. Read each proposed command before agreeing. On Team and Enterprise workspaces, owners decide whether members may let some actions through without a fresh prompt, and they can block writes for the whole organisation.
04Which Claude plans is the MacOS-MCP connector available on?
No official source publishes plan availability connector by connector, and none of the 819 directory sheets shows it. The general rule says remote connectors are open to all users on Claude, Cowork, Claude Desktop and mobile, while desktop extensions such as MacOS-MCP install on Claude Desktop. On Team and Enterprise, an Owner or Primary Owner enables a connector first. The connector's directory sheet shows its current status. Only CursorTouch documents the connector itself.
05Does Claude see everything on my Mac?
Claude sees what the macOS permissions you granted let the extension see. With Accessibility on, it reads windows and interface elements; with Screen Recording on, Snapshot can also include screenshots. Claude works with those rights and nothing more, so revoking a permission in System Settings narrows what it can reach. A workspace owner can also restrict the connector. Some apps expose little to the accessibility layer and stay partly invisible.
06Why can't Claude click or type in some apps?
One documented cause is that the app gives the macOS accessibility layer little to work with. CursorTouch lists that as a known limit, alongside specialised input fields that do not receive simulated keystrokes and slow traversal in interfaces packed with elements. Check that Accessibility, and Screen Recording for screenshots, are granted to the app running the extension. System password dialogs are out of reach whatever you do: those still need you.
07Claude or an automation platform to control my Mac?
They do different jobs, so the choice depends on the task rather than a ranking. Claude with MacOS-MCP suits one-off work in conversation: sorting out a settings screen, filling a desktop form, running a command you would not type yourself. It acts only while you are talking to it, and only in apps that expose enough to the macOS accessibility layer. An automation platform suits repeated runs that happen without you, triggered by an event in another tool.