In one paragraph
Hostkeep is a small program that runs on a Windows machine or VM. It is an MCP server: it exposes tools that an AI assistant can call through the Model Context Protocol. The assistant can read logs, search code, query data and run commands the owner defined in advance, but only inside project folders the owner named, and every call is checked by code on the machine and recorded in an activity log. Hostkeep has no user interface of its own, no cloud service, and does nothing unless an assistant calls it.
What it does, and what it doesn't
Hostkeep does
- Run on a Windows 11 machine or VM, as a normal (non-admin) user.
- Expose 63 MCP tools: 38 on by default, 25 in optional families you switch on.
- Let an assistant list, read, search, hash and compare files inside named project folders.
- Query CSV, JSONL and SQLite (read-only), extract PDF text, OCR images, inspect media and archives.
- Show Git status, diffs and history, and create safe Git checkpoints.
- Write, edit, copy, move or delete files only where you allowed writing.
- Run tests and commands only if you defined them in the config, with typed parameters.
- Record every call in a hash-chained activity log on your machine.
- Refuse anything outside those rules, and record the refusal.
Hostkeep does not
- Send your files, logs or usage data to Hostkeep. There is no Hostkeep cloud and no telemetry.
- Act on its own. It only answers tool calls from an assistant you connected.
- Monitor machines or send alerts by itself (a morning incident summary is planned, not built).
- Give the assistant a shell. Arbitrary commands are refused unless you enable the separate advanced host module.
- Read or write outside the folders you named, including through links or junctions.
- Need or request administrator rights, or change system settings.
- Open ports to the internet. It listens on 127.0.0.1; remote access goes through a tunnel you run.
- Store or train on your data, or include an AI model. The AI is whichever assistant you choose.
- Ask for human approval before changes, yet. That is the next phase on the roadmap.
Who it's for, and who it isn't for
For: small technical teams, agencies and individual operators who run unattended workloads on Windows machines or VMs: trading and automation bots, scrapers and data jobs, client servers, build and test machines. The typical question is "why did last night's job fail?", asked without opening remote desktop.
Not for (today): large IT departments managing fleets of laptops (use an IT management suite), people who want an AI to click around their desktop (the desktop module is advanced and off by default), macOS or Linux servers (Windows-first; other systems are not supported yet), or anyone who needs a hosted service with an SLA.
Where data goes
- Your assistant (running wherever it runs) sends a tool call to Hostkeep over MCP, with your access token.
- Hostkeep, on your machine, checks the token, host name and rate limit, then the project and permission rules.
- If allowed, it performs the call and returns the result to the assistant. If not, it returns a refusal code such as
PATH_OUTSIDE_ROOTorCOMMAND_NOT_ALLOWED. - It writes one activity record (tool name, project, outcome, timing; no file contents or argument values) to a log on your machine.
The content the assistant reads is sent to that assistant's provider (for example Anthropic or OpenAI) under their terms. Hostkeep never receives a copy.
Current status and limits
- Stage: early access. Three build phases are complete (foundations, stability, hardening). Approvals and per-client keys are next.
- Platform: Windows 11, Node.js 22 LTS. Strict file containment requires local NTFS drives; other drives must be marked "best-effort" in the config.
- Assistants: clients that connect to remote MCP servers over streamable HTTP with an access token can connect today. Web assistants such as claude.ai and ChatGPT need OAuth sign-in, which is planned. A verified compatibility list ships with that release.
- Access control: one access token per installation today; whoever holds it has the access the config allows.
- Known gaps are published on the security page.
How it compares
| Approach | Who acts | Access | Record |
|---|---|---|---|
| Remote desktop | A person, by hand | The whole screen and machine | Usually none |
| IT management suites | IT staff and scripts | Fleet-wide, admin level | Central console |
| Computer-control MCP servers | An AI assistant | Often the whole machine or desktop | Varies |
| Hostkeep | An AI assistant you connect | Only named folders and defined tasks, read-only by default | Every call, hash-chained, on your machine |