Remote access, built for AI agents

Let your AI agent operate the machine that has the bug.

TaskHatch gives Claude Code, Codex, and other agents a visible, authorized control surface for a real remote computer — screenshots, keyboard and mouse, terminal, files, and browser diagnostics — then writes a durable report and cleans up after itself.

LAN-first, works offline Consent-first & audited Bring your own agent
taskhatch — controller
$ taskhatch platform login
→ Open this URL to approve the controller:
  https://taskhatch.co/controller-login?code=H4TC-9K2Q
✓ Controller approved · org: acme-dev · seat 1/5

$ taskhatch session start --companion windows-desktop
✓ Paired over LAN · consent granted · audit stream open

agent> observe.screenshot → captured 1 frame
agent> browser.diagnostics --profile default
  ✓ DNS ok · ✗ CORS blocked on api.internal (mixed content)
agent> report.write --findings-first
✓ report saved · artifacts hashed · cleanup complete
How it works

From bug report to fixed machine, four steps.

TaskHatch is the bridge between your agent and the computer that has the problem.

01

Install the controller and companion

The controller CLI runs where your agent lives (macOS or Windows). The companion runs on the machine that needs help. Both are signed, visible apps — no hidden sessions, ever.

02

Pair over LAN or relay

On the same network, they discover each other and pair with a one-time code. Off-network, an authenticated relay brokers a short-lived session. Either way the operator identity is shown on screen.

03

The agent operates, with consent

Your agent drives observe, input, terminal, filesystem, and browser diagnostics through a typed protocol. Privileged actions require an explicit, visible approval on the remote machine.

04

It reports, then cleans up

Every session ends with a findings-first report, SHA-256-hashed artifacts, file backups where possible, and a cleanup pass that removes the agent's footprint.

Capabilities

A complete, typed control surface.

Everything an agent needs to diagnose and fix a real machine — nothing it shouldn't touch.

Typed control protocol

Screenshots, mouse and keyboard, PowerShell/terminal, filesystem with backups, and Chrome/Edge/Firefox diagnostics (including CDP) — all as structured, auditable actions.

Works offline after install

LAN-first design means a paired session keeps working with no internet. Reports and artifacts stay local and authoritative unless you explicitly upload them.

Hosted cockpit for support

Approved operators can drive a companion from the web through the relay — ideal for supporting a customer's Windows machine without shipping them a CLI.

Everything is audited

Each remote mutation emits audit metadata to your workspace: who, what, which session, and which policy allowed it. Kill switches can halt a session or an org instantly.

Entitlements and quotas

Relay minutes, concurrent sessions, storage, seats, and update channels are enforced per organization, so usage never surprises you.

Bring your own agent

TaskHatch is not a model. Point Claude Code, Codex, or your own agent at the CLI or SDK and it inherits the whole control surface.

Security posture

Hard boundaries, by design.

TaskHatch is built for authorized access to machines you own or are explicitly permitted to operate.

No hidden or stealth sessions

The companion always shows an active session and the operator's identity. There is no invisible mode.

No credential or secret extraction

TaskHatch never reads password managers, browser credential stores, cookies, or saved secrets.

No security-boundary bypass

We do not defeat UAC, the secure desktop, or OS permission prompts. Elevation is a visible, user-approved step.

No unauthenticated control path

Every relay and cockpit session is brokered with short-lived, HMAC-signed credentials minted by your workspace.

Backups before mutation

File-changing actions back up the target when feasible, so an agent's edits are reversible.

Real providers only

There are no mocked or faked capability providers. If a capability is unavailable on a platform, the agent gets a structured error — not a fabricated success.

Give your agent hands on the machine that matters.

Create a free workspace in minutes, install the controller and companion, and let your agent get to work.