
MateMCP
io.github.vrassouliv0.1.0更新於 Sep 29, 2026
Your agent hit a limit? Keep working. MateMCP securely connects AI chats to your computer via MCP.
概覽
MateMCP 透過 MCP 把 AI 聊天用戶端連接到你的 Windows 或 macOS 電腦,讓助理可以處理專案檔案、終端機、瀏覽器與桌面應用程式。
- 功能
- MateMCP 會在本機執行一個 Agent,並透過託管的 Relay 將它提供給相容的 MCP 用戶端。助理可以在設定好的專案根目錄內讀取與修改檔案、執行指令並維持互動式終端機工作階段、以截圖和點擊操作瀏覽器與原生桌面介面、傳輸對話附件,並保留專案脈絡與技能。敏感操作可要求核准,憑證存放在作業系統的認證儲存區,活動可供稽核。
- 適用情境
- 當你希望以聊天為主的 AI 用戶端在供應商內建的程式代理達到用量上限後,仍能繼續在你真實的本機專案上工作,或希望同一個帳號下的一個助理能存取多台已註冊裝置上的檔案、終端機與桌面工具時,值得加入。
- 執行需求
- 需要一個 MateMCP 帳號,並在每台電腦上安裝 MateMCP Desktop Agent(完整體驗需 macOS Apple Silicon 或 Windows x64;Intel Mac 與 Windows ARM64 為部分支援)。把 Agent 的 MCP URL 加入支援 MCP 的用戶端(例如 ChatGPT、Claude 或 Grok),並以 OAuth 授權。Computer Use 需要 macOS 的輔助使用與螢幕錄製權限。需要能連線到 Relay 的網路。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 MateMCP,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。
其他 MCP 客戶端
把它新增到你客戶端的 mcpServers 設定中。
{
"mcpServers": {
"matemcp": {
"type": "http",
"url": "https://relay.matemcp.com/mcp/{agent_id}"
}
}
}README
MateMCP
Your agent hit a limit? Keep working.
Website: matemcp.com · Account portal: api.matemcp.com · Releases: agent-latest
MateMCP helps you get more useful work from the AI plan you already pay for. When a provider's built-in coding or agent tool reaches its usage limit but the AI chat itself is still available, MateMCP gives that conversation a controlled path to your own Windows or macOS computer — so useful work can keep moving on your real projects and tools.
MateMCP does not increase or bypass a provider's usage quota. It gives compatible AI clients another way to work through MCP, using your machines and your access rules.
Bring your own AI. Connect ChatGPT, Claude, Grok, or another compatible MCP client to an enrolled MateMCP Agent. The Agent can work with project files, shells, browsers, desktop applications, attachments, secrets, and durable project context while MateMCP keeps access scoped, authenticated, observable, and approval-aware.
The public website at matemcp.com is the product and onboarding surface. The authenticated account portal at api.matemcp.com handles account access, enrolled devices, approvals, and administration. The normal desktop experience remains simple: install MateMCP Desktop, enroll the device, copy its MCP URL into your AI client, and authorize it with OAuth. You do not copy Agent credentials or expose local ports to the Internet.
Why MateMCP?
- Keep going when built-in agents stop — if the chat is still available, give it a controlled path to your own tools instead of ending the work session.
- Make more of the AI plan you already have — use capable chat time for real local work without requiring MateMCP to replace your AI provider.
- Bring your own AI — use ChatGPT, Claude, Grok, or another compatible MCP client with the same local Agent model.
- Work on real machines — files, shells, browsers, desktop apps, attachments, and project context live where your work already lives.
- Stay in control — project scopes, OAuth, approvals, auditability, and local secret handling keep powerful access explicit.
What can MateMCP do?
- Project-scoped filesystem access — read and modify files only inside configured projects.
- Shell and interactive terminal sessions — run commands, keep long-lived shells, resume output after transient reconnects, and inject approved secrets without revealing them to the AI.
- Computer Use — inspect screenshots, interact with browser/native UI, click, type, scroll, and use semantic accessibility actions where supported.
- Browser automation and visual QA — navigate applications, inspect responsive layouts, capture screenshots, and support frontend/desktop verification workflows.
- Secure attachment transfer — upload conversation files to a selected Agent using bounded, resumable, integrity-checked transfers.
- Approvals — require local or remote approval for sensitive actions and keep decisions auditable.
- Secret Manager — keep user-managed credentials in the operating system credential store instead of model context or project files.
- Activity, audit, and diagnostics — see what the Agent is doing, inspect approval/credential activity, and diagnose connectivity or execution failures.
- Skills & Memory — keep global cross-project knowledge in the Agent, while project-specific knowledge lives as versioned repository
SKILL.mdfiles and travels with Git. - Multi-device access — enroll multiple independently revocable Agents under one account.
- Resilient connectivity — logical sessions survive short Agent/Relay disconnects, operations use stable identities, and supported streams/transfers can resume safely.
How it fits together
The public website explains the product and provides onboarding entry points. The account portal is the browser-based user/admin surface for accounts, devices, approvals, and administration. The Relay carries remote MCP traffic to the correct online Agent. The Control Plane handles accounts, Agent ownership, OAuth, authorization, and remote approval coordination. The Agent performs work locally. The Companion gives the user a native view of status, approvals, shells, secrets, activity, diagnostics, updates, and Agent lifecycle controls.
Trust and security model
MateMCP is designed to be a boundary between an AI and the user's computer, not a tunnel around local security.
- Every Agent has a random public ID and a separate high-entropy private credential.
- Agent credentials and user-managed secrets are stored in macOS Keychain or Windows Credential Manager.
- The MCP URL identifies an Agent; it is not itself the Agent's secret credential.
- OAuth tokens are bound to the user, Agent/resource, and granted scopes. Access tokens can be refreshed without repeatedly asking the user to reconnect.
- Filesystem access stays inside configured project roots.
mcp:read,mcp:write, andmcp:shellcapabilities are enforced rather than inferred from the URL.- Sensitive actions can require explicit approval; approvals and credential use are auditable.
- The Relay never needs the user's OS secrets.
- Attachment transfers are approved, bounded, resumable, and optionally SHA-256 verified.
- Agent and Relay reconnects use stable session/operation identities to reduce duplicate side effects after transient failures.
See docs/security.md and docs/approval.md for the detailed model.
Quick start
- Create or sign in to your MateMCP account at api.matemcp.com.
- Install MateMCP Desktop for your computer using one of the commands below.
- Open Companion and finish device enrollment if prompted.
- Copy the Agent's unique MCP URL, for example
https://relay.matemcp.com/mcp/agt_.... - Add that URL to ChatGPT, Claude, Grok, or another MCP-capable AI client.
- Complete OAuth with the same MateMCP account that owns the Agent.
- Try a safe first task, such as asking the AI to list a configured project or inspect a file.
- Review approvals in Companion or the account portal when a sensitive operation requires consent.
After an Agent update that adds or changes MCP tools: some clients can retain a previous tool snapshot. For ChatGPT, see ChatGPT MCP tool refresh after Agent updates.
Install / upgrade MateMCP Desktop
macOS
For Apple Silicon Macs:
The bootstrap installs or upgrades Agent + Companion in place, starts the Agent, opens Companion for interactive setup when needed, and preserves existing configuration and secure credentials.
Manual package: MateMCP Desktop for macOS Apple Silicon · latest stable release
The Agent runs as a per-user LaunchAgent. Companion is installed under ~/Applications/MateMCP Agent Companion.app. Private configuration lives under ~/Library/Application Support/MateMCP; credentials and secrets use macOS Keychain.
Computer Use requires the relevant macOS Accessibility and Screen Recording permissions. Production signing/TCC identity hardening is still being improved, so development/ad-hoc builds may require permissions to be granted again after some updates.
Windows
Run from PowerShell:
On Windows x64 the bootstrap installs or upgrades Agent + Companion, starts the background Agent, opens Companion when interactive setup is needed, and preserves the user-scoped configuration and credentials.
Manual package: MateMCP Desktop for Windows x64 · latest stable release
Private configuration lives under %APPDATA%\MateMCP; enrolled credentials and secrets use Windows Credential Manager.
Platform status
Remote MCP client status
Public Relay reachability can depend on the network path used by the client provider. The production MateMCP deployment can use Cloudflare or another HTTPS edge/reverse proxy in front of the public hostnames without changing the Agent-facing MCP URL model.
Companion at a glance
Companion is the user's local control surface. Current functionality includes:
- Agent Start / Stop / Restart and status.
- MCP endpoint visibility and copy actions.
- Pending Approvals and policy management.
- Interactive Shell sessions.
- Secret Manager backed by the OS credential store.
- Activity & Audit history.
- Agent Logs and diagnostics.
- Global Skills & Memory inspection and management; project Skills are ordinary versioned files inside each repository.
- Computer Use preview/status.
- Prevent Sleep While Using controls, with a 15-minute idle grace period after the latest Agent activity.
- Manual update checks and optional automatic Desktop updates on supported platforms.
Account portal at a glance
The browser-based account portal at api.matemcp.com complements the local Companion. Current portal capabilities include:
- Login and registration with normal account/session controls.
- Device management for enrolled devices, including status and revoke/remove flows supported by the control plane.
- Approvals with pending actions and recent/history views supported by the backend.
- Administration for authorized admins, including user search/status management and appropriate device management.
- Server-side authorization for user/admin actions; sensitive Agent credentials and stored secrets are not exposed through the portal.
Self-host Web + Account Portal/API + Relay
For the usual single-server deployment there is one canonical install/update command:
The installer is update-safe: it preserves existing configuration, asks only for missing setup values, refreshes the current Compose definitions, pulls/recreates the public Web, API, and Relay services, keeps the private API↔Relay credential synchronized, and health-checks the services before reporting success. On supported Debian/Ubuntu hosts it can bootstrap Docker Engine + Compose when needed.
Use component installers only for advanced deployments where Web, API, and Relay are managed separately:
The API supports SQLite for a small single-server deployment and SQL Server for external database deployments. Web, API, and Relay should sit behind HTTPS reverse proxies; their container ports should not be exposed directly to the Internet. Keep matemcp.com, api.matemcp.com, and relay.matemcp.com routed to their independent backends.
External identity providers are optional and deployment-specific. Provider configuration, callback URLs, and account-linking behavior are documented in docs/external-login-providers.md; enable only providers that have been configured and verified for the deployment.
Cloudflare is optional. When it is used in front of MateMCP, keep the three public hostnames independently routed, preserve the original HTTPS host/scheme, and do not cache authenticated API responses. The same deployment pattern also works with other HTTPS reverse proxies/edges.
Production hostname/TLS routing is documented in docs/production-web-deployment.md. Web deployment details are in deploy/web/README.md, and Relay-specific reverse-proxy guidance remains in deploy/relay/README.md.
Documentation
Current limitations and active work
MateMCP is under active development. Some areas intentionally remain conservative or are still being hardened:
- Native Companion packaging is currently focused on Windows x64 and macOS Apple Silicon.
- Windows ARM64 uses screenshot fallback rather than the native WGC preview helper.
- macOS production signing/TCC identity still needs hardening so permissions survive every production update reliably.
- Global Skills & Memory and repository Skills exist today, but proactive automatic context use across different AI clients is still evolving.
- ChatGPT remains the primary full end-to-end compatibility target; Claude and Grok connectivity has also been verified, while provider-specific feature behavior can still differ.
- Safe & Informed Approvals is being expanded so approval dialogs explain consequences and risk rather than relying only on raw command syntax.
Releases
main is the source of truth for stable development. The moving agent-latest release contains current stable Agent packages and native Desktop packages for supported architectures. Version tags such as v0.1.0 publish versioned release assets.
Contributions and field-test reports are welcome through GitHub Issues and Pull Requests.
來源:README.md,提交 659675a
工具
0版本歷史
1- v0.1.0最新Sep 29, 2026
