Skip to main content

kasm-use

Let an AI agent use a Kasm Workspaces desktop: start a session, look at the screen, click, type, press keys, scroll, and stop it — in plain language, from any MCP client (Claude Code, Claude Desktop, OpenCode, Cursor, …) or as a native Hermes Agent plugin.

Other Kasm MCP servers manage sessions (start, list, stop). kasm-use actually uses them: the agent sees the desktop and operates it, like computer-use or browser-use, inside your Kasm.

  • Works with stock Kasm images. Nothing is baked into the workspace; it drives the desktop through Kasm's own API.
  • You can watch and take over. Sessions are created as your Kasm user, so they show up in your Kasm dashboard. Open one to watch the agent work, or to handle a login or CAPTCHA yourself.
  • Your Kasm, your key. You run the server next to your own Kasm. Nothing goes through a third party.

Tools

Tool What it does
kasm_list Workspaces you can start, and your running sessions
kasm_start Start a workspace (e.g. Chrome) — takes ~2 min, see Limitations
kasm_look Screenshot of the session, returned as an image
kasm_click Click at x,y in the latest screenshot's coordinates
kasm_type Type text into the focused field
kasm_key Keys/shortcuts, e.g. ctrl+l, Return, Tab
kasm_scroll Scroll, optionally at a point
kasm_stop Destroy the session

Requirements

  • Kasm Workspaces 1.19 or newer (the screenshot API needs 1.19 images).
  • A Kasm API key: Admin → Settings → Developers → API Keys → Add. Grant it only the session permissions (create/list/destroy sessions, screenshot, exec). It does not need user or admin rights.
  • Your Kasm user ID, so sessions belong to you: Admin → Access Management → Users → open your user; the ID is in the page URL.
  • A workspace image based on Debian/Ubuntu (all official kasmweb/* images are).

Configuration

Variable Required Meaning
KASM_API_URL yes e.g. https://kasm.example.com
KASM_API_KEY / KASM_API_KEY_SECRET yes the API key pair
KASM_USER_ID yes the Kasm user sessions are created for
KASM_VERIFY_TLS no false to accept a self-signed Kasm certificate (default true)
KASM_USE_TOKEN HTTP only bearer token clients must send

Run it

Locally (stdio) — the usual way

Your MCP client starts the server itself. With uv installed:

{
  "mcpServers": {
    "kasm": {
      "command": "uvx",
      "args": ["kasm-use"],
      "env": {
        "KASM_API_URL": "https://kasm.example.com",
        "KASM_API_KEY": "…",
        "KASM_API_KEY_SECRET": "…",
        "KASM_USER_ID": "…"
      }
    }
  }
}

Claude Code:

claude mcp add kasm -e KASM_API_URL=https://kasm.example.com -e KASM_API_KEY=… -e KASM_API_KEY_SECRET=… -e KASM_USER_ID=… -- uvx kasm-use

As a service (streamable HTTP)

docker run -d -p 8000:8000 \
  -e KASM_API_URL=https://kasm.example.com -e KASM_API_KEY=… -e KASM_API_KEY_SECRET=… \
  -e KASM_USER_ID=… -e KASM_USE_TOKEN="$(openssl rand -hex 32)" \
  ghcr.io/rchurro/kasm-use:latest

Clients connect to http://host:8000/mcp with the header Authorization: Bearer <KASM_USE_TOKEN>. Health check: GET /healthz. Run one replica per Kasm user: the server remembers each session's last screenshot size in memory to map click coordinates.

Keep it on a private network (LAN, VPN, Tailscale). Anyone with the token can drive your desktops.

Hermes Agent

pip install kasm-use                      # into Hermes's Python environment
cp -r hermes-plugin/kasm ~/.hermes/plugins/kasm

Enable kasm under plugins.enabled, set the environment variables above, and start a new Hermes session (/new) so the tools load.

Limitations

  • First start is slow (~90 s extra). Stock images don't include xdotool, so kasm_start installs it in the session as root. Reusing a running session skips this.
  • Screenshots can lag a few seconds behind actions; the agent is told to look again to confirm.
  • Kasm's exec API returns no output, so actions report "sent", not "succeeded". The next screenshot is the confirmation.
  • CAPTCHAs, passwords, MFA and payments are handed to you. The tool descriptions tell the agent never to type them; open the session in Kasm and take over.
  • It's slow compared to a local browser tool: every step is a screenshot round trip.

How it works

  • Eyes: POST /api/public/get_kasm_screenshot (KasmVNC renders a JPEG).
  • Hands: POST /api/public/exec_command_kasm running xdotool inside the session.
  • Clicks are given in screenshot pixels and scaled to the real desktop size inside the session (xdotool getdisplaygeometry), using the JPEG's actual dimensions — Kasm keeps the desktop's aspect ratio, so the image is often not the size requested.

License

MIT

Metadata

Release files for kasm-use 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for kasm-use 0.1.0
File Size Uploaded
kasm_use-0.1.0.tar.gz 11.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for kasm-use 0.1.0
File Interpreter ABI Platform
kasm_use-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 23.3 kB

Release files / kasm_use-0.1.0.tar.gz

Download URL kasm_use-0.1.0.tar.gz
Size 11.3 kB
Tags Source
SHA-256 checksum
How to use checksums
467df7ed14623afed34658186073057ea1b5dcf42ce63c85b883a04f9e275110
BLAKE2b-256 checksum
How to use checksums
dfd685a79326be0b41e62bb1dc5deb40d9d3597d5511ad315f155f9d8d76bd50
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release files / kasm_use-0.1.0-py3-none-any.whl

Download URL kasm_use-0.1.0-py3-none-any.whl
Size 11.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
a8d2d928fe1248d837f24f9464ecfd2d28074993bca06e268be6f47cd2a54225
BLAKE2b-256 checksum
How to use checksums
3d7b2376792dc4717ec3b3dd33cc98eac3b5799fc456fc39c6ddf2c5d8876e10
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page