GPT Windows Connector

GPT Windows Connector

Remote-first, model-independent Windows execution MCP for ChatGPT, Claude, Gemini, and other MCP-compatible AI clients.

Category
访问服务器

README

GPT Windows Connector

Remote-first, multi-user Windows execution MCP for ChatGPT, Claude, Gemini, and other MCP-compatible AI clients.

The product exposes local project files, Shell, long-running processes, Git, browser automation, and Windows desktop/UI Automation through a VPS Gateway. Codex, Claude Code, and Gemini CLI are not used as an execution layer.

Final architecture

ChatGPT / Claude / Gemini / other Remote-MCP client
                    |
                    | HTTPS / MCP
                    v
              VPS Gateway
          account / projects / logs
                    |
                    | WSS
                    v
              Windows Node
                    |
        files / shell / git / browser / desktop

All AI-to-Windows traffic is relayed through the VPS. A Windows computer makes an outbound WSS connection and does not require a public inbound port.

User experience

  1. Open the VPS Gateway website.
  2. Register with email/password or sign in with Google.
  3. Pair a Windows computer from Windows Nodes.
  4. Create a project from Projects.
  5. Select an online Windows computer.
  6. Browse that computer's allowed folder tree and select a workspace.
  7. Connect the Remote MCP endpoint to the AI client using the same account.
  8. The AI uses the project ID; the VPS resolves the correct user, Windows Node, and workspace automatically.

There is intentionally no conversation binding.

(user_id, project_id)
        |
        +-- node_id
        `-- workspace

Built-in VPS dashboard

Running gwc-gateway serves both the web dashboard and Remote MCP endpoint.

Dashboard sections:

  • Dashboard — project/node/activity overview
  • Projects — project → Windows computer → folder bindings
  • Windows Nodes — online/offline nodes and one-time pairing codes
  • Activity Logs — user-scoped audit history with filters
  • Account & Security — account/provider and security information

The folder picker never reads the VPS filesystem. It requests directory information from the selected Windows Node through the VPS WebSocket and only exposes directories inside GWC_ALLOWED_ROOTS.

Authentication

Supported login methods:

  • Email/password registration and login
  • Google OAuth 2.0 / OpenID Connect
  • JWT access tokens for MCP/API clients
  • HttpOnly login cookie for the built-in web dashboard

Passwords are hashed with Argon2. User/project/node/audit data is stored in the VPS gateway.db SQLite database. If GWC_JWT_SECRET is omitted, a random secret is generated once and persisted under GWC_DATA_DIR.

Google login

Create a Google OAuth Web application and configure:

GWC_GOOGLE_CLIENT_ID=...
GWC_GOOGLE_CLIENT_SECRET=...
GWC_GOOGLE_REDIRECT_URI=https://gwc.example.com/auth/google/callback

If GWC_GOOGLE_REDIRECT_URI is omitted while client ID/secret are present, the gateway derives it from GWC_PUBLIC_BASE_URL. Google login returns to the built-in dashboard by default.

Project binding and folder picker

The Windows Node advertises only configured allowed roots:

$env:GWC_ALLOWED_ROOTS = "G:\;D:\Projects"

The VPS dashboard can browse:

Office-PC
├─ G:\
│  ├─ NiceC-WMS
│  ├─ OpenAkita
│  └─ PartyGame
└─ D:\Projects
   └─ another-project

A selected project binding is persisted on the VPS:

user_id + "NiceC-WMS"
  -> Office-PC
  -> G:\NiceC-WMS

The Node validates the selected folder before the Gateway saves it. Paths outside allowed roots are rejected.

MCP tools

Projects and nodes

  • project_bind
  • project_get
  • project_list
  • project_unbind
  • node_pair
  • node_list
  • control_acquire
  • control_status
  • control_release

Files

files_tool(project_id, action, params) supports:

  • list
  • read
  • write
  • patch
  • search
  • stat
  • mkdir
  • move
  • copy
  • delete

Direct file operations are sandboxed inside the project's bound workspace.

Shell and processes

  • shell_run — PowerShell/CMD, stdout/stderr/exit code, timeout
  • process_tool — start/poll/stop/list with incremental output cursors

Git

git_tool supports status, diff, log, branch, branch create/switch, add, commit, pull, push, and show.

Browser

browser_tool supports browser discovery, CDP attach, persistent profile launch, tabs/pages, navigation, DOM inspection, click/type/select, workspace-scoped upload/download, screenshots, and close.

Windows desktop

computer_tool supports system/process information, application launch, window listing/activation, screenshots, mouse/keyboard, clipboard, and Windows UI Automation inspection/click/text entry.

Activity Logs

The VPS writes user-scoped audit events to gateway.db. The dashboard exposes only the authenticated user's records. Sensitive fields such as passwords, access tokens, authorization headers, cookies, clipboard data, and full content values are redacted by the UI API.

Multi-node and control locking

One account can have multiple Windows computers:

Gateway
├─ Office-PC
├─ Warehouse-PC
└─ Home-PC

Interactive browser/desktop operations use a per-node project lease so two projects do not fight over the same mouse/window.

Permission levels

Set on each Windows Node:

GWC_PERMISSION_LEVEL=read | operate | admin
  • read: inspection/read methods only
  • operate: normal coding and automation
  • admin: also allows direct file deletion and Git push

GWC_ALLOWED_ROOTS is a hard boundary for direct connector file operations and workspace selection. Shell commands still run with the normal Windows account permissions, so use a dedicated low-privilege Windows user or VM when strong OS-level isolation is required.

Install Gateway on VPS

Python 3.11+:

git clone https://github.com/Neal86/gpt-windows-connector.git
cd gpt-windows-connector
python -m venv .venv
source .venv/bin/activate
pip install -e .

Configure:

export GWC_HOST=0.0.0.0
export GWC_PORT=8787
export GWC_DATA_DIR=./data
export GWC_PUBLIC_BASE_URL=https://gwc.example.com
gwc-gateway

Public endpoints:

Dashboard:   https://gwc.example.com/
Remote MCP:  https://gwc.example.com/mcp
Node WSS:    wss://gwc.example.com/ws/node
Health:      https://gwc.example.com/health

A Dockerfile and docker-compose.yml are included. Put HTTPS/WSS in front of the service in production.

Install Windows Node

Install the package on Windows, create a one-time pairing code from the VPS dashboard, then run:

$env:GWC_NODE_ID = "Office-PC"
$env:GWC_NODE_NAME = "Office PC"
$env:GWC_GATEWAY_WS = "wss://gwc.example.com/ws/node"
$env:GWC_PAIRING_CODE = "123456"
$env:GWC_ALLOWED_ROOTS = "G:\;D:\Projects"
$env:GWC_PERMISSION_LEVEL = "operate"
gwc-node

After successful pairing, the Gateway issues a persistent random node token. The Node stores it in the current user's local app-data directory and reconnects automatically with heartbeat + exponential backoff.

Security

  • Use HTTPS/WSS in production.
  • Restrict GWC_ALLOWED_ROOTS.
  • Prefer read or operate; grant admin only when necessary.
  • Treat JWTs and persistent node tokens as secrets.
  • Run the Windows Node under a dedicated Windows account where practical.
  • The MCP Python SDK is pinned to >=1.27.2,<2 and explicit Host/Origin transport security is enabled.
  • The Windows Node is outbound-only; do not expose local CDP, Shell, or Node ports publicly.

Intended coding loop

AI -> VPS -> Windows Node
   read/search code
   -> patch/write
   -> build/test
   -> inspect errors
   -> patch again
   -> git diff/status
   -> commit/push when permitted
   -> VPS -> AI

The repository remains independent from CursorTouch/Windows-MCP. Windows-MCP is not required at runtime.

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选