Summer launch MouseMux V3 just launched. We'll be polishing it all summer with free updates, so early adopters get 25% off with code SUMMER26. See pricing
AI agents · MCP

Give your AI its own cursor.

MouseMux hosts a local MCP server. Connect your AI, arm it, and it gets its own cursor to click and type in any Windows app, no API required. One agent can drive many apps at once, each through its own locked virtual user.

In beta. The MCP server is local-only (127.0.0.1), off by default, and gated behind an Arm switch.

MouseMux · Input Mapper AI · MCP 127.0.0.1:41760 Arm
Your AI · MCP client
MouseMux · 127.0.0.1
connected · tools loaded · read-only until armed
Browser · user 1LOCKED
portal.example.com/search
Browser · user 2LOCKED
orders.example.com
Browser · user 3LOCKED
crm.example.com/login
Sign in
Agent
orders.xlsx
OrderCustomerTotal
10391Deforest BV412.50
10392Aster GmbH88.00
10393Novia Ltd1,204.90
10394Bright Co67.25
Orders 2.4 — [Entry]
File  Edit  Records  Help
SaveRecord saved ✓
Agent
Operations dashboard
API99.98%
Queue1,204ACK
DB12 ms
Workers48/48
PaymentsERR 502
Disk61%
Escalated to on-call ✓
Agent
Report.docx
Task queue · agentLOCKED
Invoice batch #221
Update 14 records
Export weekly report
Verify order status
You
Agent
Connect your AI. Arm it when ready. Three isolated browsers, one agent, in parallel. No API? It types into the real UI. Reads the screen. Acts on what it sees. A co-worker on its own cursor, never touching yours.
How it works

A node graph your AI can read, rewire and run

The Input Mapper turns MouseMux input into a live signal graph. MCP hands that graph to your AI, and an Arm switch decides when it can act.

The Input Mapper

The Input Mapper is a visual node graph inside MouseMux. Every device that connects becomes a live signal source, mouse, keyboard, pen and touch, that you wire through processing nodes and out to real or virtual users.

Three signal types flow through it: vector positions, scalar values like pressure and wheel, and binary key and button events. Over 130 nodes cover math, filters, gates, generators, coordinate transforms, screen reading with OCR and image match, and automation macros.

That makes it a genuinely powerful toolkit: any input can be routed to become any output, and you can spin up unlimited virtual users - driving normal Windows apps, isolated multi-seat browsers, and soon any app fully sealed in its own container.

The MCP server

The app hosts a local Model Context Protocol server, so any MCP-compliant AI can connect: Claude Desktop and Claude Code work out of the box, and so does any other assistant, coding agent or agent framework that speaks MCP. The AI reads the whole graph, builds and rewires nodes, and creates virtual users on the machine - as many as the task needs, one per app, each locked to its own window so parallel work stays isolated and no human's pointer is ever touched.

Reading and building is always safe. Acting, moving, clicking and typing, is gated behind an Arm switch that is off by default and turns red while live, and the server listens on 127.0.0.1 only. Inside the graph, an LLM node can call Claude, OpenAI or your own API when a step needs judgement.

This is the missing half of computer-use agents: on benchmarks like OSWorld, even the best agents still fail most desktop tasks when they must find every button by screenshot. Here the agent gets structured control instead: the graph, the screen-reading nodes and the locked windows do the grounding.

Isolation without the VMs

The usual way to isolate an agent is to give it a whole machine: a VM or a remote desktop per agent, heavy, slow to spin up, and another OS license each time. MouseMux virtualizes the input instead of the machine: each virtual user is locked to its own app window inside the one Windows session.

No hypervisor, no VM images, near-zero overhead, and as many agents' hands as the PC can hold. Window locking today; fully sealed app containers are on the roadmap.

What you can build

From browser farms to legacy data entry

Concrete things people set up with an agent, a graph and a stack of virtual users - all on one Windows PC:

A browser farm on one PC

The agent spins up isolated multi-seat browsers - Chrome, Firefox, our Multi-Browser - one locked virtual user per browser. Parallel research with separate profiles, logins and sessions, portals that are locked to your office IP, all driven at the same time, and nothing can escape its own window.

Legacy data entry, no API

Hand it a spreadsheet and let it work an old ERP or CRM through the real UI: OCR reads the screen, image match finds the buttons, and the agent types like a person - across several app windows in parallel when the backlog is big.

QA sweeps with judgement

Run the same app in several windows with different inputs, screen-read the results, and put the LLM node in the loop for the steps where pass or fail needs an actual judgement call instead of a pixel match.

Watch-and-react operations

Point it at a dashboard: it reads the screen, acknowledges the routine alerts itself and escalates the odd ones - acting as its own user on its own cursor, without ever touching yours.

An agent beside you

The agent grinds through its queue with its own cursor while you keep working on the same PC with yours. Window locks make collisions impossible - it is a co-worker, not a takeover.

Rewire any input to any output

The same graph remaps hardware too: gamepad to pointer, one mouse fanned out to many cursors, recorded macros replayed across virtual users. Describe the routing and the AI builds the graph for you.

What it's good for

  • Legacy and no-API apps, driven through the real UI
  • One agent driving many apps in parallel, one locked virtual user per app
  • An agent working as its own user, next to your team
  • Screen-aware steps with OCR and image matching
  • Repetitive and QA runs, with an LLM in the loop when needed
On the roadmap

Soon: sealed app containers

One app, fully isolated

A real app container: the app runs sealed off from the OS, the agent drives only that app, and it can't touch anything else on the machine. Today's window locking, upgraded to full containment.

Many agents in parallel

One agent already drives many apps at once; next, run several agents side by side, each in its own isolated container on one PC, with no crosstalk between them and nothing leaking to the OS.

Hand your AI a cursor

Get the Input Mapper app, connect your AI, and arm it when you're ready.