Skip to content
ARC / Documentation
Agent index ↗Back to Arc ↗Buy Arc — $199

Agent capabilities

Computer use

Let an Arc-managed agent see and operate a Mac or Windows desktop in a Full Access room, share it safely with the operator, and know what Arc refuses.

On this page

Computer use lets an Arc-managed agent see the screen and click, type, scroll and drag in any app on the Mac or Windows PC where Arc runs. Arc offers it only in Full Access rooms, pauses the agent whenever the operator touches the mouse or keyboard, and never operates security prompts or password fields. Read this page before you use the computer tool, when an action is refused, or when you are choosing between the desktop, the room browser and Arc Desktop's own controls.

Check that computer use is available

  • A supported host. The daemon runs on macOS or Windows with Arc's computer helper installed. GET /v1/computer/status reports platform_supported, helper_installed and stop_hotkey.
  • A Full Access room. A Safe room offers no computer tool, and switching a room to Safe ends a running session. Full Access is the only grant; there is nothing else to enable.
  • A managed seat whose model sees images, on an API connection or a self-hosted model server. External harness agents, Arc-managed GGUF models and models marked text only in the operator's settings get no computer tool.
  • macOS permission. The operator allows Megastructure Arc under Accessibility and Screen Recording; Screen control in the right rail opens those panes. Windows asks for no permissions.

Find the computer tool

Claude on an Anthropic connection gets Anthropic's native computer tool; send its actions in a response of their own, not mixed with Arc tool calls. Other API models see Arc's computer tool listed directly. A self-hosted model finds it by calling arc_search_tools with the query computer, then calls it directly.

Send actions

The computer tool takes an actions array. A seat whose model passed Arc's pointing test may send up to 8 actions per call; every other seat sends exactly one. The tool description states your limit, and a larger batch returns batch_too_large without running. Actions run in order and stop at the first failure; later ones report not_executed. Arc attaches a fresh screenshot after each call unless it ended with screenshot or zoom.

text
computer {
  "actions": [
    {"action": "left_click", "coordinate": [412, 230]},
    {"action": "type", "text": "quarterly report"},
    {"action": "key", "text": "Return"}
  ]
}

With a limit of one, send each of these actions in its own call.

ActionFields
screenshot, cursor_positionnone
zoomregion [x0, y0, x1, y1], at least 4 by 4; later coordinates still refer to the full screenshot
left_click, right_click, middle_click, double_click, triple_clickcoordinate; optional text naming modifiers to hold, such as shift
left_click_dragstart_coordinate, coordinate
mouse_movecoordinate
left_mouse_down, left_mouse_upoptional coordinate
scrollscroll_direction (up, down, left, right), scroll_amount 1 to 50, optional coordinate
typetext, up to 2,000 characters per action
key, hold_keytext such as Return or super+s; hold_key also takes duration, up to 5 seconds
waitduration, up to 30 seconds

Modifiers are shift, ctrl, alt and super; super is Command on macOS and the Windows key on Windows.

Use the right coordinates

Coordinates refer to your latest screenshot of the main display, scaled to your model's image limits, so take one first. Most models use screenshot pixels. Gemini models use a 0–999 grid over the screenshot (x divided by width, times 1000), which Arc converts to pixels. Arc picks the convention from the model family and states it in the tool description and on every screenshot.

The pointing test asks a model for six clicks on three synthetic app screens in that convention. Five hits allow batches of up to 8; a model that misses, or answers in another convention, sends one action per call. Arc runs the test when the operator tests a connection or refreshes a self-hosted server. The native Anthropic tool always batches.

Share the screen with the operator

One agent drives the desktop at a time. Your session starts with your first action and ends when your turn ends. While you act, a light in Arc's status bar glows and pulses; a hollow ring means paused. It opens Screen control, where the operator watches the live screen and can Pause, Resume or Stop. The room's event feed records each session as computer.session_started, computer.session_paused, computer.session_resumed and computer.session_stopped.

When the operator touches the mouse or keyboard, Arc pauses you at once. Your next action waits up to 30 seconds for the operator to stay idle for 5 seconds with no modifier held. Then a screenshot runs as asked; any other action does not run and returns the current screen instead. The stop key (⌃⌥⌘. on macOS, Ctrl+Alt+Shift+. on Windows), the Stop button, or a switch to Safe ends the session for the rest of your turn. Arc keeps session screenshots on this machine for about a week.

Result errorWhat to do
desktop_busyAnother agent has the screen. Wait for its turn to end.
operator_activeNothing ran. Call again with a screenshot.
screen_changedYour action did not run. Decide from the attached screen.
pausedThe operator, or Arc after five refusals, paused the session. Tell the operator; only they resume it.
stopped_by_operator, session_stoppedDo not use the computer again this turn. Finish and say where you stopped.
screen_lockedThe screen is locked or, on Windows, a secure prompt such as User Account Control is up. Stop and tell the operator.
refusedArc's floor blocked it; read rule and reason, then choose another way or ask the operator.
stale_geometry, no_screenshot, coordinate_out_of_boundsNo current screenshot fits (the display may have changed). Take a new one and aim inside it.
computer_unavailableThe room is Safe or this machine cannot run computer use.

Know what Arc refuses

Arc never operates security and permission surfaces: authentication and privacy prompts, Gatekeeper and the login window on macOS; User Account Control, credential and Windows Hello prompts, Windows Security, SmartScreen and the lock screen on Windows. It never types into a password field, and never presses the stop key or a shortcut that logs out, locks the computer, or opens Force Quit, the Ctrl+Alt+Delete screen or Task Manager (or Alt+F4 on the Windows desktop). Hand those steps to the operator.

On Windows, Arc refuses windows that run as administrator. While one is in front, Arc does nothing in any window and returns elevated_foreground; wait, or ask the operator to switch windows. When Arc cannot check whether the focused field is a password field, it stops typing and returns focus_unverified; take a screenshot, click the field and type the rest. Neither counts as a refusal.

Read or control a session over HTTP

RouteCallerReturns
GET /v1/computer/statusAny; permissions=1 needs the operator keyPlatform, helper, stop key, live session (agents see its id, room, agent and state)
POST /v1/computer/permissions/requestOperator keyAsks macOS for its two permissions; Windows has none
GET /v1/computer/sessions/{id}Operator keyFull session with recent actions
POST /v1/computer/sessions/{id}/pause, /resume, /stopThe session's own agent may pause or stop; resume and other sessions need the operatorThe session
GET /v1/computer/sessions/{id}/screenOperatorLatest screenshot as PNG

Choose the computer, the room browser or Arc Desktop

ToolOperatesUse it for
computerThe whole desktop, by screenshot and pointerNative apps and anything the other two cannot reach
arc_browser_*Loopback pages in the room browser, by accessibility refsTesting a local web app; any agent in a Full Access room
arc_ui_commandArc Desktop's own window, by @eN refs, without the mouseSeeing and driving Arc itself; its see-and-drive verbs need a Full Access room

Prefer the room browser or arc_ui_command when they reach the target: they never move the operator's pointer.