Perception · Screen
Sees the screen and drives apps
Takes a screenshot, opens an app, runs an AppleScript. If two assistants ask at once, the second waits or is refused.
Learn moreMercury Device Commander for macOS
Mercury connects an AI assistant to your Mac. It sees the screen, works with files and programs, and controls a connected phone. Every action runs under your key and goes into the log.
Tested with ChatGPT and Claude via MCP
Perception · Screen
Takes a screenshot, opens an app, runs an AppleScript. If two assistants ask at once, the second waits or is refused.
Learn morePerception · Files
Reads a folder and writes the result to a file. A review-only assistant can get read-only access.
Learn moreAction · Commands
Commands run as an exact argument list, without a shell. The assistant reads the output and reports back.
Learn moreAction · Phone
Taps, swipes, text and key events over adb. iPhone and iPad are only listed in the device list for now.
Learn moreControl · Access
A separate revocable key with its own capability profile. Revocation applies from the next request. No key or permission, no action.
Learn moreFeedback · Log
A local JSON Lines log: assistant, tool, result, time. Request contents are not stored. An idempotency key keeps the same action from running twice.
Learn moreMercury governs the complete closed loop between AI reasoning and physical macOS and mobile environments with refusal by default when identity, authority or the outcome of a past action is unknown, and a local operations log.
Perception layer: captures displays, file structures, and connected Android/iOS hardware status.
Governance & context: validates per-client identity, enforces capability scopes, and coordinates screen actions that pass through Mercury.
Governed execution: commands run as explicit argument lists, file operations, AppleScript, and adb device actions.
Feedback: writes each call to the local operations log, refuses to repeat an action whose outcome is unknown (UNCERTAIN), and returns the result to the AI.
These capabilities run in the current macOS build, providing multi-AI coordination and governed access.
Each AI client can be issued an individual revocable key with its own capability profile (by default a shared launch token is used, which is not revocable in v1). Revocation takes effect on the next request.
Mutating operations require a durable idempotency key. Prevents duplicate side effects, replays recorded results, and safely handles UNCERTAIN states without blind retries.
An in-memory lock for calls that pass through Mercury (screenshots, opening apps, AppleScript). A second client waits up to 3 seconds and is then refused; the first client keeps the lock for 10 seconds after its last call.
Operations write a row to the local audit.jsonl log with client, tool, allowed/denied status, duration, and result timestamp; request payloads are not stored.
Direct native automation on macOS host drivers, Android actions over adb, and connected iOS / iPadOS device list discovery.
Commands run as an explicit argument list without a shell; access is governed by the client profile.
Practical automation workflows running through the local daemon and MCP bridge.
Ask an AI assistant to read a project folder, summarise it and write the result to a file. Give a review-only assistant a read-only token.
Let an assistant run a program or script on your Mac with explicit arguments and read its output.
Take a screenshot, open an app or run an AppleScript. If two assistants try at once, the second waits or is refused.
List connected Android devices and send taps, swipes, text and key events with adb. iPhone and iPad are listed only.
Each call is written to a local operations log with the client, tool, result and time. Request contents are not stored.
Every action runs without a confirmation prompt, according to the profile you assign.
Automation tools with system privileges must enforce explicit execution boundaries. In key scenarios, Mercury fails closed by default: when identity is missing, permissions are absent, or previous action outcome is unknown.
// Mercury MCP Client Registration (0600 token isolation) // products/mercury-device-commander/docs/client-identity-and-resource-lease.md $ node src/client-admin.js create claude-code --profile owner-full
token: runtime/clients/claude-code.token (chmod 0600) $ node src/client-admin.js create auditor --profile read-only
token: runtime/clients/auditor.token (read-only enforcement) // MCP Configuration (tested with Claude; a sample configuration is available for Gemini)
{
"mcpServers": {
"mercury": {
"command": "/Applications/Mercury Device Commander.app/Contents/MacOS/Mercury Device Commander",
"args": ["mcp", "--client", "claude-code"]
}
}
}
Tested with ChatGPT and Claude. Works with MCP clients; a sample configuration is available for Gemini.
Cloud sessions connect via user-configured tunnel to the local Mac daemon.
Local engineer CLI or desktop interface connected via standard stdio MCP bridge with designated clientId token.
A sample configuration is available for Gemini.
Planned roadmap from the V1 local control plane to multi-machine fleets (planned).
AI systems reason, plan and request actions. Mercury is the layer that acts on the machine: the eyes, ears and hands of AI in the real world.
Mercury is not the brain. Decisions, memory and business orchestration stay with the AI and the people who use it; Mercury authenticates, authorizes, executes and records what happens on the device.
Mercury Commander is a macOS app with a local daemon and an MCP bridge. AI assistants connect to it to work with files, programs, the screen and connected Android phones on your Mac.
No. Mercury v1 is a privileged tool for the machine owner. See Security for the known limits.
We have tested ChatGPT and Claude. Other MCP clients can connect; a sample configuration is available for Gemini.
Apple Silicon Macs (.app). Intel, Windows, Linux and iOS as a host are not supported.
The daemon listens on 127.0.0.1 only. What an AI assistant reads through Mercury goes to the AI service you connected. Reaching the daemon from a web AI needs a tunnel that you configure yourself.
Commander is 20 USD per month for one Mac. Checkout is not open yet. Fleet and Mesh prices are not announced.
Write to office@merlin-partners.com.