Claude Code can now see and control your Mac from the terminal. Anthropic ships it as a built-in MCP server named `computer-use`. It is off until you turn it on, it runs on your actual desktop, and it asks before it touches each app. That makes it a coding tool that can click through the app it just built. It is a different thing from a self-hosted agent like OpenClaw or Hermes that you run as a service.
The source for the Claude Code side is Anthropic's page Let Claude use your computer from the CLI and the computer use section of the Desktop docs. The OpenClaw and Hermes side reuses our OpenClaw vs Hermes Agent comparison and setup guides, which cite the OpenClaw docs and the Hermes docs.
Short answer
Use Claude Code computer use when a developer is sitting at the Mac and needs the agent to check a native app, a simulator, or a GUI-only tool during a coding session. Use OpenClaw or Hermes when the agent has to run as a service on a host you administer, answer in chat channels, run on a schedule, or serve more than one person. If an API or MCP tool exists for the job, give the agent that tool first. Both setups are better off with screen control as the last resort.
What Claude Code computer use is
The CLI version has firm limits, and Anthropic states them up front:
- It is a research preview.
- The CLI version is macOS only. The Desktop app version runs on macOS and Windows.
- It needs a Pro or Max plan. It is not available on Team or Enterprise plans.
- It needs an interactive session, so it does not work in non-interactive mode with the `-p` flag.
- You must sign in through claude.ai. It is not available when you reach Claude through Amazon Bedrock, Google Cloud, or Microsoft Foundry.
To turn it on, you run `/mcp` in a Claude Code session, find `computer-use` in the server list, and choose Enable. The setting is saved per project. The first time Claude tries to act, macOS asks you to grant Accessibility (to click, type, and scroll) and Screen Recording (to see the screen).
Claude picks the narrowest tool first
Anthropic calls computer use the broadest and slowest way to work with an app, so Claude tries other paths first. If you have an MCP server for the service, Claude uses it. A shell command goes to Bash. Browser work goes to Claude in Chrome if you have it set up. Screen control is left for native apps, simulators, and tools that have no API.
We made the same case in when an agent uses the browser instead of the MCP tool. A typed tool call is easier to check, log, and retry than a click on a screenshot. Anthropic has built that order into the product.
How permission works
Turning on the server does not give Claude every app. The first time it needs an app in a session, the terminal shows which apps it wants, any extra access such as the clipboard, and how many other apps will be hidden while it works. You choose Allow for this session or Deny. Approvals end with the session.
Control is also capped by app type. The Desktop docs list three tiers that you cannot change:
| Tier | What Claude can do | Applies to |
|---|---|---|
| View only | See the app in screenshots | Browsers, trading platforms |
| Click only | Click and scroll, but not type or use shortcuts | Terminals, IDEs |
| Full control | Click, type, drag, and use shortcuts | Everything else |
Some apps get an extra warning before you approve them. Terminals and IDEs are flagged as equal to shell access. Finder is flagged because it can read or write any file. System Settings is flagged because it can change the system. They are not blocked. The warning is there so you decide whether the task needs that much access.
What happens on screen
- One session at a time. A session takes a lock on its first computer-use action and keeps it until the session exits. A second session gets an error that names the session holding the lock.
- Other apps are hidden. While Claude works, apps you did not approve are hidden and come back when the turn ends. In the CLI this is always on. The Desktop app lets you turn it off and keep a denied apps list, which the CLI does not have yet.
- Your terminal stays out of the picture. The terminal window stays visible to you but is left out of the screenshots, so Claude never sees its own output.
- You can stop it. A macOS notification says Claude is using your computer. Pressing `Esc` anywhere stops the current action, and the key press is consumed so text on screen cannot use it to dismiss a dialog. `Ctrl+C` in the terminal also works.
- Screenshots are downscaled before they go to the model. Anthropic's example is a 16-inch MacBook Pro at 3456×2234 sent at about 1372×887. If text is too small to read, make it larger in the app.
The trust boundary is your own desktop
Anthropic's warning is direct. The sandboxed Bash tool in Claude Code isolates filesystem and network access. Computer use does not. It runs on your real desktop with whatever apps you approve. Claude checks each action and flags possible prompt injection from content on screen, but anything visible in an approved app can still try to steer it.
So the questions to settle before you approve an app are about your own machine. What is signed in inside that app? What could a page, email, or document on screen ask the agent to do? Would you approve Finder or a terminal for this task if a stranger were typing? Anthropic points to its computer use safety guide for practices.
OpenClaw and Hermes run a different kind of job
OpenClaw is a Gateway you run. It connects model providers, sessions, tools, messaging channels, the Control UI, and optional device nodes. Team use is configuration of that same Gateway. Sandboxing is off by default. When you turn it on, tool execution can move to Docker, Podman, SSH, OpenShell, or Crabbox while the Gateway stays on the host.
Hermes Agent is a process you run from a CLI, a messaging Gateway, an API server, or a supported editor. Tools come in toolsets you select, profiles keep roles apart, and terminal commands can run locally, in Docker, over SSH, or in several hosted sandboxes. Dangerous commands go through an approvals setting (`smart`, `manual`, or `off`) with a hardline blocklist that stays on underneath.
Both can schedule work, answer in chat, and keep running when nobody is at the keyboard. Claude Code computer use needs a person in an interactive session on that Mac, and the docs give you `Esc` to stop it at any moment.
Side by side
| Question | Claude Code computer use | OpenClaw or Hermes |
|---|---|---|
| Where does it act? | Your own Mac desktop (Windows too in the Desktop app) | The host and sandboxes you configure |
| Who is present? | A developer in an interactive session | Often nobody: channels, schedules, API calls |
| How is access granted? | Per app, per session, with fixed control tiers | Tool policy, toolsets, allowlists, pairing, and approvals in config |
| How many at once? | One session holds the screen lock | As many sessions as the Gateway or process is set up to serve |
| What is the main risk? | On-screen content steering an agent inside apps you approved | A broad tool or a weak sandbox on a host you run |
| Who maintains it? | Anthropic ships the server; you approve apps | You install, patch, and audit the runtime |
When you want both
The two fit together well. A developer can use Claude Code computer use to build and click-test the GUI for an internal tool on a Mac. The work that runs every day, such as filing tickets, syncing records, or answering a chat channel, belongs in a self-hosted agent with narrow MCP tools and clear approvals. See trust boundaries for self-hosted agents and permissions and human approval for that side.
If the job needs screen control without a person watching, look at products built around a separate machine. Our posts on Cursor Self-Hosted Machines, Muse Secure VM, and Simular Sai cover three ways vendors split who owns that computer.
How this fits implementation work
OrchestriAI does not operate Claude Code, OpenClaw, or Hermes for clients. MCP development builds the typed tool that lets an agent skip the screen. AI agent systems decide which jobs an agent may run and where a person approves. Systems integration connects those tools to the systems that hold the data.
Independence and limitations
OrchestriAI is an independent implementation provider. Product names are used for identification only. OrchestriAI is not affiliated with, endorsed by, or sponsored by Anthropic, OpenClaw, or Nous Research / Hermes. This article summarizes Anthropic's Claude Code computer use page and the Desktop computer use section as checked on October 6, 2026, plus our existing OpenClaw and Hermes guides. Computer use is a research preview, so plans, platforms, and controls can change. Confirm the current docs before you enable it on a machine that holds client data. This is not a security certification or a compliance conclusion.
