Claude Code Computer Use: What I Let Claude Click on My Mac (and What It Will Not)

David IyaDavid Iya September 28, 2026 9 min read
A desktop monitor on a clean walnut desk showing a blank glowing application window, a wireless mouse resting on a grey felt pad and a closed notebook beside it, cool morning light from a side window
Original image, Claude Code Club

Claude Code Computer Use

Claude Code computer use lets Claude open the apps on your machine, see your screen, and click, type, scroll, and drag the way you would. In the desktop app it is a research preview on macOS and Windows, it needs a Pro or Max plan, and it is off by default. You turn it on under Settings, General, in the Desktop app section, and on a Mac you grant two system permissions, Accessibility and Screen Recording, before the toggle takes effect. After that, the first time Claude needs a specific app in a session, it asks, and you click Allow for this session or Deny. It is not the Browser pane and it is not the Chrome extension. Those handle web pages. Computer use is for everything that has no web page, no command line, and no API: a native Mac app, a design tool's export dialog, a simulator, a settings window.

I turned it on the week I needed Claude to test a small native utility I had it build for the club's publishing queue, an app with no browser surface at all. Below is what it did, what it asked for, what I said no to, and the order Claude tries other tools before it touches the screen. That order is the most useful thing on this page, because it is why computer use is rarely the tool you end up using and always the one you are glad exists.

The CCC Last-Resort Ladder: what Claude tries before it touches your screen

Computer use is the broadest tool Claude has and the slowest, because every step is a screenshot, a look, and a click. So Claude tries the most precise tool first and only falls through to screen control when nothing else reaches the task. I call the order the CCC Last-Resort Ladder, and if you learn nothing else here, learn this, because it explains most of the moments where you enable computer use and then watch Claude not use it.

  1. A connector. If the service has one, GitHub, Slack, Linear, or an MCP server you added, Claude uses that. Structured, fast, no screenshots.
  2. A shell command. If the task is a build, a test run, a file operation, Claude uses Bash. The sandboxed one.
  3. The Claude in Chrome extension. If the task is browser work and you have the extension set up, Claude drives your real browser as you.
  4. The iOS Simulator pane. If the task is running or testing an iOS app, the desktop app opens its dedicated simulator pane, which works without computer use switched on at all.
  5. Computer use. Only if none of the above apply. Native apps, hardware control panels, proprietary tools with no API.

The per-app tiers, covered next, reinforce the ladder on purpose. Browsers are capped at view-only and terminals at click-only even when computer use is on, so Claude is steered back to the Browser pane or the sandboxed shell rather than clicking around in a Chrome window. My first real prompt after enabling it was to check a page in the club site, and Claude told me it would rather do that in the Browser pane. It was right. [Claude Code skills vs MCP servers](/blog/claude-code-skills-vs-mcp-servers) is the same instinct one rung up: give Claude the precise tool and it stops needing the blunt one.

How to turn on Claude Code computer use in the desktop app

  1. Update the desktop app first. The toggle only appears on a current build; download or update from claude.com/download, then restart.
  2. Open Settings, General, and find Computer use under the Desktop app section. Turn it on. On Windows that is the whole setup. If you do not see the toggle, check that you are on macOS or Windows with a Pro or Max plan; it is not available on Team or Enterprise plans.
  3. On a Mac, grant Accessibility, which lets Claude click, type, and scroll, and Screen Recording, which lets Claude see the screen. The Settings page shows the status of each, and clicking a denied badge opens the right System Settings pane.
  4. Leave the desktop app running. Computer use needs it open, which matters if you are used to closing it and working from the terminal.
  5. Ask for something only the GUI can do. If you ask while it is still off, Claude tells you it could do the task if you enabled computer use, which is a decent way to find out whether a task actually needs it.

Two settings live next to the toggle and both are worth setting on day one. Denied apps is a list of apps Claude will never be allowed to control, rejected without a prompt; mine has my password manager and my banking app in it. Unhide apps when Claude finishes controls whether the windows Claude hid while it worked come back on their own. More on the hiding below.

App permissions: three fixed tiers and a prompt per session

Enabling computer use does not hand Claude the whole machine. The first time Claude needs a given app in a session, a prompt appears in the chat naming the app, any extra access it wants such as the clipboard, and the level of control that app category gets. You click Allow for this session or Deny. Approvals last for that session and then expire; in sessions started from Dispatch on your phone they expire after 30 minutes and re-prompt. The tiers are fixed by category and you cannot raise them.

Computer use control tiers, per Anthropic's Claude Code desktop docs

TierWhat Claude can doApplies to
View onlySee the app in screenshotsBrowsers, trading platforms
Click onlyClick and scroll, but not type or use keyboard shortcutsTerminals, IDEs
Full controlClick, type, drag, and use keyboard shortcutsEverything else

Apps with broad reach show an extra warning in the prompt. Terminals are flagged because approving one is equivalent to shell access. Finder on a Mac, or File Explorer on Windows, can read or write any file. System Settings can change the system. None of these are blocked; the warning is there so you decide whether the task justifies it. One catch to know: a denied app can still be affected indirectly by an action in an allowed app, so the denied list is a wall around direct control, not a wall around outcomes.

What computer use caught on a real native build

The utility I mentioned is a small menu bar app that watches the club's publishing queue and shows a count. Claude wrote it, compiled it, and, once computer use was on, launched it and clicked through it before telling me it was done. That is the part I could not get any other way: there was no page for the Browser pane to load and no test harness worth writing for an app this small. It opened the preferences window, changed the refresh interval, and reported that the label updated. Then it found the thing I would have shipped. At the default window size, the Save button in that preferences window sat below the visible area, so the interval could be changed and never saved. Claude resized the window to reproduce it, screenshotted the clipped state, fixed the layout, and re-ran the check.

A few things about how it works on screen are worth knowing before you rely on it. While Claude is controlling the screen it hides your other windows so it only interacts with the app you approved, and restores them when the turn ends, unless you turned that setting off. On macOS there is also a background mode where Claude works in the approved apps while you keep using the machine. Screenshots are downscaled automatically before they reach the model, so you do not have to lower your display resolution on a Retina screen; if Claude cannot read small text, make the text bigger in the app, not the screen smaller. And the documented emergency stop in the terminal version is the Esc key, which aborts the current action from anywhere and is consumed so nothing on screen can use it to dismiss a dialog.

The cost is time and tokens. A screenshot-look-click loop is slower than a shell command by a wide margin, so I do not leave computer use running on a long session where nothing native changes. [Claude Code context management](/blog/claude-code-context-management) covers why screenshots in the context window add up, and [how to debug with Claude Code](/blog/how-to-debug-with-claude-code) is where I send people once computer use has shown them the failing state, because from there it is ordinary debugging.

The trust boundary is different from the sandbox, and that is the whole risk

The sandboxed Bash tool runs commands in an isolated environment. Computer use does not. It runs on your actual desktop with access to whatever you approve. Claude checks each action and flags potential prompt injection from on-screen content, but the boundary is a different shape, and the guardrails are the tiers, the per-session prompt, the sentinel warnings, the denied list, and the fact that in the terminal version Claude never sees its own terminal window in a screenshot, so a prompt inside your session cannot feed back into the model. Those are real, and I still treat computer use as the one Claude Code feature where my judgment is the main safety control rather than a backup.

Practically, that means three habits. I only approve the app the task is about. I never run computer use on a machine that is signed into a client's systems, which is the same line I draw in [is Claude Code safe for client work](/blog/is-claude-code-safe-for-client-work). And I keep the Browser pane and the Chrome extension set up so Claude has somewhere better to go for anything web-shaped, which the ladder above then enforces for me. [Claude Code's sandbox, explained](/blog/claude-code-sandbox-explained) is the other half of this picture: what the Bash tool isolates, and the short list of things it was never meant to cover, computer use being one of them.

What computer use will not do, and what to reach for instead

  • Type into a browser or a terminal. Browsers are view-only and terminals are click-only, by design. Use the Browser pane or the Chrome extension for the web, and let the sandboxed shell run commands.
  • Test an iOS app by clicking the simulator. In the desktop app that request opens the iOS Simulator pane, which does not use screen control and does not need computer use enabled. [How to build a mobile app with Claude Code](/blog/build-a-mobile-app-with-claude-code) is where that pane earns its keep.
  • Run on Team or Enterprise plans, through a third-party provider like Bedrock or Foundry, or in non-interactive mode with the -p flag. It is a Pro and Max research preview signed in through claude.ai.
  • Control an app on the denied list, or control any app without asking once per session. If you want fewer prompts, that is what a connector or an MCP server is for; [what are MCP servers and why they matter](/blog/what-are-mcp-servers-and-why-they-matter) explains the trade.

Turn it on, approve one app, and watch what Claude does first

Enable it, set the denied list before you run anything, then give Claude a task that genuinely has no other route: a native build to click through, a GUI-only export, a settings window to verify. Watch the first prompt, approve exactly one app, and read what it reports. You will learn in ten minutes whether computer use belongs in your workflow, and the answer for most builders is: rarely, and when it does, nothing else will do.

Free Claude Code drops, straight to your inbox

Short, practical drops on skills, MCP, agents, prompts, and more. No spam, unsubscribe anytime.

Frequently asked questions

What is Claude Code computer use?

A research preview in the Claude desktop app, on macOS and Windows, that lets Claude open your apps, see your screen, and click, type, scroll, and drag the way you would. It is for tasks with no command line, web page, or API, such as native apps, simulators, and GUI-only tools. It needs a Pro or Max plan and is off until you enable it in Settings.

How do I enable computer use in Claude Code?

In the desktop app, open Settings, General, and turn on the Computer use toggle under the Desktop app section. On Windows that completes setup. On macOS, also grant Accessibility and Screen Recording in System Settings; the Settings page shows the status of each. In the terminal version, run /mcp and enable the built-in computer-use server, macOS only.

Is Claude Code computer use safe?

It runs on your real desktop, not in the sandbox, so the trust boundary is different from the Bash tool. The guardrails are per-app approval each session, fixed control tiers that cap browsers at view-only and terminals at click-only, warnings on apps with broad reach like Finder and System Settings, a denied-apps list, and action checks that flag potential prompt injection from on-screen content. Approve only the app the task needs.

Why is Claude not using computer use even though I enabled it?

Claude tries more precise tools first: a connector or MCP server, a shell command, the Claude in Chrome extension, and the iOS Simulator pane. Screen control is the fallback for tasks none of those reach. If the job is a web page, Claude will prefer the Browser pane or the extension, and browsers are view-only under computer use anyway.

Does Claude Code computer use work on Team or Enterprise plans?

No. The docs list it as a Pro and Max research preview. It is also not available through third-party providers such as Amazon Bedrock, Google Cloud's Agent Platform, or Microsoft Foundry, or in non-interactive mode with the -p flag.

Last reviewed by David Iya on September 28, 2026

David Iya

Written by

David Iya

Forbes 30 Under 30 · Y Combinator

Keep reading

Claude CodeWorkflows

Claude Code Browser: How I Let Claude Test Its Own Changes in the Desktop App

The Claude Code browser is the Browser pane inside the desktop app's Code tab. Claude starts your dev server, opens the app in the pane, takes screenshots, inspects the DOM, clicks through forms, and fixes what it finds, and by default it does this after every edit. It runs in a clean profile with none of your logins, which is why there is a second option, the Claude in Chrome extension, for anything that has to happen as you. Here is how the two fit together, how auto-verify behaved on a real build, and the prompts I run in the pane now.

David Iya 9 min
Read article
Claude CodeWorkflows

Claude Code Scheduled Tasks: How I Set Up a Daily Review in the Desktop App

Claude Code scheduled tasks are recurring jobs you create from the Routines page in the desktop app. Each one starts a fresh Claude Code session at the time you pick, in the folder you choose, with its own permission mode and model, and the run shows up in the sidebar for you to review. They run on your machine, so the app has to be open and the computer awake. Here is how I set up a weekday review of the previous day's commits, what went wrong in the first week, and the version of the prompt I run now.

David Iya 9 min
Read article

Ready to build it yourself?

Join Claude Code Club, the #1 community for learning claude code, for $9/month.

← Back to the blog