ReMCP
MCP serverEverything elseSecurely use files, terminals, screenshots and processes on computers you pair with ReMCP.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use ReMCP
From the project's README
As published by antonbaider/remcp in README.md.
ReMCP connects a computer you own or administer to ChatGPT, Codex, Claude Code, or another MCP client. The device agent makes an outbound connection only — no inbound port, no tunnel, no third-party desktop relay. This repository contains the public device client/runtime plus the host-specific OpenAI and Anthropic plugin packaging.
Packages
| Package | What it is |
|---|---|
@remcp/remcp | The device client: pairing, the outbound agent, the background service, and the usage-metrics switch. |
@remcp/runtime | The first-party local runtime: 44 MCP tools for files, images, binary transfer, archives, screenshots, search, terminal sessions, processes, and narrowly scoped runtime preferences, with two direct dependencies. |
Install
Requires Node.js 22.5 or newer.
npm install --global @remcp/remcp@latest
Then open ReMCP → Connect a machine and generate a one-time pairing command. Run that exact command on the computer you want to connect; it installs the runtime and registers the background service.
Pairing codes are generated in the authenticated workspace, expire automatically, and are single-use. Do not invent or reuse a code from documentation.
Commands
| Command | Purpose |
|---|---|
remcp start | Start the device agent in the foreground |
remcp status | Show pairing, runtime, telemetry, and service health as JSON |
remcp doctor | Alias for status |
remcp install | Install or repair the persistent user service |
remcp update | Update the client and runtime, then restart the service |
remcp uninstall | Stop and remove the user service |
remcp uninstall --purge | Remove the service and the global packages |
remcp telemetry [status|on|off] | Show or change usage metrics for the client and the runtime |
remcp godmode [status|on|off] | Show or change this computer's local unrestricted mode |
remcp --version | Print the installed client version |
Plugins
For users, ReMCP is catalog-first:
Install from your AI host → sign in to ReMCP → use your paired computers.
You do not need to paste an MCP server URL, edit a manifest, clone this repository, or configure a local path just to use the published plugin.
Shareable install guides:
- ChatGPT & Codex: https://remcp.site/install/chatgpt
- Claude Code: https://remcp.site/install/claude
ChatGPT & Codex / OpenAI
ChatGPT and Codex share OpenAI's public plugin directory.
- ChatGPT: open https://chatgpt.com/plugins?q=ReMCP, open the ReMCP card when it is available, and choose Install plugin.
- Codex: in a supported task view open Sources → Use plugins, then search for and select the installed ReMCP plugin.
- When prompted, choose Connect and complete ReMCP OAuth. After that, use the computers already paired to your account.
If ReMCP is not visible yet, the listing or rollout is not available to that account. There is no manual MCP endpoint an ordinary plugin user needs to configure while waiting.
Claude Code / Anthropic
ReMCP was submitted through Claude Platform on September 18, 2026 and currently shows Submitted and pending review.
After approval, the preferred user path is https://claude.com/plugins → search ReMCP → Install → complete ReMCP authorization.
Claude Code terminal users can also use Anthropic's community marketplace after approval:
/plugin marketplace add anthropics/claude-plugins-community
/plugin install remcp@claude-community
Until the directory listing is approved, ReMCP also publishes a validated early-access marketplace:
claude plugin marketplace add antonbaider/remcp
claude plugin install remcp@remcp --scope user
That optional fallback uses Claude Code's supported marketplace mechanism. Users still do not need
git clone, --plugin-dir, or a manual MCP endpoint.
Start with Plugin overview →.
Cursor, Gemini CLI, GitHub Copilot and VS Code
ReMCP also publishes host-native discovery metadata for the other major coding harnesses:
| Host | User path |
|---|---|
| Cursor | Find ReMCP in Cursor Marketplace and install it; the plugin already carries its MCP + skills configuration. |
| Gemini CLI | Find ReMCP in the Gemini CLI Extension Gallery and install the extension; OAuth discovery is automatic. |
| GitHub Copilot CLI | Install ReMCP from the default marketplace after review, or add the ReMCP marketplace while the listing is pending. |
| VS Code Agent Plugins | Install the same Agent Plugins 1.0 package from the plugin UI/default marketplace. |
| Official MCP Registry | ReMCP publishes its hosted server to the official MCP Registry for registry-aware MCP clients. |
The same rule applies on every host: install the catalog item, sign in to ReMCP, use your paired computers. Ordinary users do not copy an MCP URL from this repository.
Distribution manifests and submission status are documented in DISTRIBUTION.md →.
Developer / reviewer internals
Host-specific manifests, MCP configuration, validation commands, submission artifacts, and local development workflows remain documented separately:
The OpenAI files and Claude files deliberately do not overwrite each other. Release checks fail if either host-specific contract drifts from the shared ReMCP version or production endpoint.
The local runtime
@remcp/runtime is a clean-room MCP server written for ReMCP. It is not a fork of, and shares no code
with, DesktopCommanderMCP or any other MCP
server.
44 tools:
| Area | Tools |
|---|---|
| Read | read_file, read_files (glob), read_multiple_files, read_image, read_binary, list_directory, get_file_info, hash_file, diff_files |
| Write / edit | write_file, write_files (bulk), write_binary, apply_patch, set_permissions, edit_block, replace_lines, replace_in_files |
| Organise | create_directory (bulk), move_file, copy_file, copy_paths, move_paths, move_to_trash, create_archive, extract_archive |
| Delete | delete_path, delete_paths |
| Transfer | read_binary and write_binary move any file in base64 chunks both ways; create_archive and extract_archive move whole trees |
| Screen | take_screenshot returns the desktop as an image |
| Search | start_search, get_more_search_results, stop_search, list_searches |
| Processes | start_process, read_process_output, wait_for_process_output, interact_with_process, force_terminate, list_sessions, list_processes, kill_process |
| Runtime | get_system_info, get_runtime_info, get_runtime_stats, set_config_value |
The hosted ReMCP endpoint adds eight account/relay tools, so ChatGPT currently scans 52 tools.
Why the tool list looks different from other computer-control servers. Security-sensitive configuration remains deliberately narrow, and everything else the alternatives can do has an equivalent here — usually more than one:
| Not included | Why |
|---|---|
write_pdf, spreadsheet and DOCX editing | These are the reason other servers ship Puppeteer, sharp, and exceljs — ReMCP does not bundle that browser/document-rendering stack. |
| Broad configuration mutation | set_config_value can change only telemetry and context/output preferences. Access roots, blocked commands, command policy, shell, write limit and unrestricted mode stay local to the computer. |
URL fetching in read_file | It is a server-side request forgery surface. The runtime reads your computer, not the internet. |
What ReMCP adds beyond the usual set: image reads and screenshots that any MCP client can
display, binary transfer in both directions, archive create/extract, wait_for_process_output instead
of polling, line-range replacement, project-wide replace, unified diffs, checksums, trash instead of
deletion, and host resource reporting.
Nothing is gated. There is no approval prompt, no "are you sure", and no mandatory dry run: a tool
call executes with the full rights of the account running the agent — the same trust model as SSH.
Writes replace by default and moves/copies replace the destination. The catastrophic-command
guardrail defaults to warn (advisory, not blocking); an operator may choose allow or block.
Files are never written to a local history log, so tool arguments and output are not recorded there.
Unrestricted by design
- No per-call approval contour. ReMCP does not add a confirmation dialog before each tool call.
The local runtime's configured roots, command blocklist and command policy still apply, as do the
operating-system permissions of the account running the agent. Within those boundaries,
start_processcan operate services, packages, databases, containers,sudo, git, and other local tools. - Full transfer in both directions.
read_binary/write_binarymove any file,create_archiveandextract_archivemove whole trees, andtake_screenshotshows the desktop. - Optional hardening, explicit security boundaries.
remcp godmode onlifts the roots, the blocklist and the command guardrail for one computer — and only a person at that computer can turn it on; no MCP tool accepts it.allowedRootsandblockedCommandsare empty until an operator configures them.dangerousCommandsdefaults towarn: matching catastrophic commands still run, but the result carries an advisory note;allowsilences it andblockrefuses it. The runtime refuses to start — loudly — ifruntime.jsoncannot be parsed, so configured safety boundaries are never silently dropped. - Crash-resistant. A bad shell, a closed stdin, or a 40 MB line cannot take the runtime down; the agent restarts it if it exits, so a device recovers instead of going quietly offline.
- Outbound-only. Per-device revocable credential, hashed server-side, stored locally with
restrictive permissions. Runtime metadata from a custom server requires an explicit
--trust-runtimedecision. - No local history. Tool arguments and outputs are never written to a log on your computer.
Usage metrics
Both the client and the runtime collect opt-out usage metrics: tool names, durations, outcomes, coarse error classes, session counts, and device health samples. They never include file paths, file contents, command strings, tool arguments, or tool output — the event schema is a whitelist, so those fields have nowhere to travel.
There is no telemetry endpoint and no third-party processor. The runtime emits MCP notifications to the agent, and the agent forwards them over the authenticated WebSocket it already holds to your ReMCP account. No install ping, no postinstall script, no remote feature flags, no A/B assignment.
remcp telemetry off # one switch for the client and the runtime
remcp telemetry status
Development
npm install
npm run check
npm test
Both workspaces are plain ESM with no build step. The contract commands (--help, --version,
--print-tools, --describe) work with no dependencies installed, so CI can diff the advertised
tool surface against the published tarball.
License
MIT.
Advanced
- Delivery
- remcp MCP server → your ahel gateway (mcp.ahel.ai) → every connected AI client.
- Catalog kind
- mcp-server
- Gateway key
io-github-antonbaider-remcp- Source
- github.com/antonbaider/remcp
- Hosted endpoint
https://remcp.site/mcp