Large Language ModelsGenerate imagesGenerate videos
What Is Windows MCP in Claude? How to Use It
Windows MCP is an open source server that gives Claude hands on your Windows PC: it can open apps, click, type, read the screen and run PowerShell. This article explains how it works, how to install it in Claude Desktop, and how to keep it safe.
You asked Claude to sort 300 files in your Downloads folder, and it gave you a neat plan that you still had to carry out by hand. Windows MCP removes that last step. It is an open source server that gives Claude a pair of hands on your Windows PC: it can read what is on the screen, click buttons, type into fields, open apps, move files and run PowerShell commands, all from a normal chat in Claude Desktop. This article explains what Windows MCP is, how the pieces fit together, how to install it, which jobs it handles well and which settings stop it from causing damage. It also clears up a naming mix-up, because Microsoft uses the phrase MCP on Windows for a separate feature built into the operating system itself.
What Windows MCP Actually Is
MCP in one paragraph
The Model Context Protocol (MCP) is an open standard that Anthropic introduced in late 2024. It lets an AI app talk to outside tools through one shared format. Claude Desktop plays the client. Anything that speaks the protocol plays the server: a database connector, a calendar, a browser or, in this case, your whole desktop. The client asks the server which tools it offers, Claude picks the one that fits your request, and the server runs it and returns the result.
That split matters. Claude never touches your PC directly. It can only ask for actions the server has chosen to expose, and every one of them is a named tool you can inspect, limit or switch off.
The project behind the name
Windows-MCP is an MIT licensed project by CursorTouch, published on GitHub. Its README describes it as a lightweight bridge between language models and the Windows operating system, built for file work, app control and UI interaction without needing a specialized vision model. It supports Windows 7, 8, 8.1, 10 and 11, and it is featured as a Desktop Extension in Claude Desktop.
💡 Two things share one name. Windows-MCP is a community server you install yourself. MCP on Windows is Microsoft's own framework, described in a later section. Most of this article is about the first one.
How Claude Controls Your Screen
Snapshot first, then act
Claude does not watch your monitor. The server describes it. The Snapshot tool returns the full UI state with an ID for each element, so Claude can act on "element 14" instead of guessing at pixel positions. The Screenshot tool is the lighter option: a fast visual capture that includes the cursor and open windows. Based on what comes back, Claude picks the next tool, such as Click, Type, Scroll or Shortcut, and repeats the loop until the task is done. The project quotes a typical delay of 0.2 to 0.5 seconds between actions.
Screenshot or Snapshot mode
Mode
What Claude receives
Best for
Screenshot (default)
A fast image of the screen with cursor and windows
Quick visual checks, lower token cost
Snapshot
The UI state with element IDs, plus a screenshot when use_vision=True
Precise clicks inside crowded apps
Both modes support region capture and multi display selection, which keeps token use down. If screenshots are still too heavy, set WINDOWS_MCP_SCREENSHOT_SCALE to a value between 0.1 and 1.0 to shrink them.
The tools at a glance
The README lists about twenty tools. Grouped by job:
💡 Microsoft Store version of Claude Desktop? It keeps its config in a different folder, and the project README says to use the full path to the executable instead, for example C:\Users\<user>\.local\bin\uvx.exe. The packaged app may not see your normal PATH, so a bare uvx fails.
Prefer an extension? Windows-MCP also ships as a Desktop Extension. The project's steps are: install Anthropic's mcpb tool with npm, run npx @anthropic-ai/mcpb pack in the cloned project to build a .mcpb file, then install that file from the Extensions page in Claude Desktop settings.
Check that it works
Open a new chat and confirm the server shows as connected. Then start with something harmless:
"Take a screenshot and tell me which apps are open."
Once that works, raise the stakes a little:
"Open Notepad and type a three line shopping list. Do not save it."
Watch the screen while it runs. You will see the pointer move, windows open and text appear, which is the quickest way to build a feel for how fast and how literal Claude is when it drives a real desktop.
💡 You can always take control back. Move the mouse by a large amount, or press Ctrl+Alt+Shift+Backspace, and the desktop returns to you.
Jobs Worth Handing to Claude
File chores and cleanup
The FileSystem tool can list, search, copy, move and delete, so a messy Downloads folder is the classic first job. Ask for the plan before the action: "List what is in Downloads, propose sub folders by file type, and wait for my approval before moving anything." That single sentence turns a risky bulk operation into a reviewable one.
Spreadsheet and form work
Plenty of desktop software has no API. A purchasing tool from 2012 or an internal form with 40 fields still needs a person to type. MultiEdit fills several input fields in one go, Clipboard moves values between windows, and Snapshot gives Claude reliable targets. Treat the first few runs as supervised: watch the screen and check the totals yourself.
Testing apps and settings
The project lists QA testing among its uses. Click through an installer, flip a Windows setting, confirm an app opens, then ask Claude to describe what changed. This job fits a virtual machine best, where a mistake costs you a snapshot restore instead of a bad afternoon.
Here are four starter prompts and the tools they are likely to trigger:
Task
Starter prompt
Tools involved
Tidy a folder
"Propose a folder structure for Downloads and wait for my approval."
FileSystem, Snapshot
Fill a form
"Copy the five rows from this spreadsheet into the form."
Snapshot, MultiEdit, Clipboard
Check an app
"Open the app, go to Settings and tell me the version."
App, Click, Screenshot
Wait on a job
"Wait until the export window says finished, then notify me."
WaitFor, Notification
💡 Ask for a pause before anything destructive. A line such as "stop and ask me before deleting, overwriting or closing anything" costs nothing and catches most surprises.
Risks and Safe Settings
The project's own security policy is blunt. The server is not sandboxed, it runs with all the permissions of the Windows user that launched it, and many actions cannot be undone. Files removed through PowerShell or the interface may be gone for good, and screenshots can capture sensitive information that then travels to the model.
Switch off tools you do not need
The README says you can disable risky tools with the --exclude-tools option or the WINDOWS_MCP_EXCLUDE_TOOLS environment variable, so check it for the exact syntax. For a first week, leaving out Registry and PowerShell removes the two most powerful ways to break something. Telemetry is another setting worth knowing: it is on by default and anonymous according to the project, and you can switch it off by adding "env": {"ANONYMIZED_TELEMETRY": "false"} to the server entry.
If you ever expose the server over a network instead of the local Claude Desktop link, the project asks for more protection: an authentication token, an IP allowlist and TLS.
Use a sandbox or spare account
The security policy recommends a handful of habits:
Run inside a virtual machine with snapshots, or in Windows Sandbox
Use a restricted user account instead of an administrator
Keep fresh backups before any automation
Watch actions in real time instead of leaving a task unattended
Disable high risk tools when the job does not need them
It also advises against using Windows MCP on production servers, in compliance regulated environments, on machines with irreplaceable data or on shared multi user computers.
💡 Rule of thumb: if you would not leave a colleague alone with your open laptop for ten minutes, do not give Claude that same access on a machine that holds unsaved or irreplaceable work.
Windows MCP Versus Microsoft's Own MCP
Microsoft announced a public preview of native MCP support in Windows in May 2025. As described at the time, an on-device registry lists agent connectors, which are MCP servers published by app developers. Built-in connectors for the file manager and System Settings were part of the preview. Agent access is switched off by default, the registry only admits servers that meet baseline criteria such as code signing and fixed tool definitions, a system proxy applies policy and keeps an audit trail, and users get an approval prompt, similar to a UAC dialog, before sensitive tool calls.
Feature
Windows-MCP (community)
MCP on Windows (Microsoft)
Built by
CursorTouch, open source, MIT license
Microsoft, part of Windows
Install
Config file or Desktop Extension
On-device registry managed by Windows
Reach
The whole desktop through UI automation, PowerShell, files and Registry
Only the connectors that apps register
Safety model
Your user permissions, no sandbox
Off by default, signed servers, proxy and approval prompts
Both are moving targets, so check the project README and Microsoft's current documentation before you build a workflow on either. For now, the community server is the one that lets Claude drive any app on screen, while Microsoft's route is narrower and more tightly controlled.
Where Windows MCP Falls Short
The README is honest about the limits:
It cannot automate video games
The Type tool is not ideal for writing code inside an IDE
Partial text selection is not supported
The App tool works best when Windows runs in English
There is also a structural cost. Every step is a round trip through the model, so a long job runs slower, and uses more tokens, than a script would. When a task repeats every day, ask Claude to write a PowerShell script once and run that script from then on.
Common errors and fixes
Symptom
Likely cause
Fix
Server never shows as connected
uvx not found, Python older than 3.13, or a Store build without full paths
Install uv, update Python, use the full path to uvx.exe
Tools missing after restart
Typo in the config JSON, or Claude Desktop was not fully quit
Validate the JSON, quit from the tray, reopen
First start seems frozen
Dependencies are still installing
Wait one to two minutes
Clicks land in the wrong place
Display scaling or several monitors
Run DisplayInventory and prefer Snapshot element IDs over raw coordinates
App tool cannot open a program
Non English Windows language
Switch the display language, or open the program by path through PowerShell
Make Your Own Images and Videos
Windows MCP gives Claude a pair of hands. Picasso IA gives you a studio. Once Claude can drive your PC, the slow part of many creative jobs is no longer the clicking, it is producing the pictures and clips themselves.
Here is where to start:
PicassoIA Image turns a text prompt into a photo style picture
PicassoIA Video turns a text prompt or a still image into video
Claude Sonnet 5 and Claude Opus 4.7 handle chat and coding, handy for drafting the prompts and PowerShell snippets you later hand to Windows MCP
PicassoIA also offers an MCP connection of its own, so Claude can request images and videos from inside a conversation. With both servers connected, one chat can ask for an image and then use Windows MCP to save or place it where you need it. Check the PicassoIA site for how to connect your account and what your plan includes.
💡 Your next step: open Picasso IA, pick one model, write a prompt about a scene from your own desk, and generate your first image today. Then browse every model at picassoia.com/en/all-models and try a short video from that same image.