Desktop
Desktop is where you connect your own computer to Nexus, so assistants and workflows can work with your local files and apps. On the page it is titled Desktop Agent: "Connect your machine to APEX so agents and workflows can interact with your local desktop, files, and applications."
Open the page
Click Settings → Desktop in the Nexus sidebar (/workspace/desktop). You need Nexus admin permission to see it. Older addresses (/nexus/settings/desktop-agent and /settings/desktop-agent) forward here.
A Desktop Approvals button at the top right opens the Approvals page. To use a connected computer in a chat, see Cowork.
There are four tabs: My Devices (default), Folders, Folder Watches and Robot Accounts.
My Devices
An information banner explains: "The desktop key is a machine-scoped credential. It can only be used to authenticate the APEX Desktop Agent — it cannot call any other APEX APIs. Store it in the agent app; it never needs to go anywhere else."
1. Your Desktop Key
There are no short pairing codes. You connect with one long Desktop Key.
Generate a key
If you have none, the page says "You don't have a desktop key yet." Click Generate Desktop Key ("Generating…").
Copy the details
A window titled Your Desktop Key opens with the warning "This key is shown only once — copy it now". It has three copy boxes: Desktop Key, WebSocket URL and API URL.
Screenshot placeholderScreenshot to add: The one-time Your Desktop Key window with the three copy rows and the confirmation checkbox. Confirm
Tick "I've copied my key and understand it won't be shown again." Only then does Close work, and the backdrop and Esc will not close the window either.
If you already have a key, the page shows its Key prefix, Status, Created and Last used ("Never used" if so). Any status other than active shows in red.
- Rotate Key issues a new key. Rotating "immediately disconnects any active agent session and the old key stops working." You must type
ROTATEto enable the button ("Rotating…"). - Revoke asks "Revoke Desktop Key": "This will immediately disconnect any active agent session and remove your desktop key. No new key will be generated — use this only if your machine is lost or compromised." Choose Revoke Key. A toast says "Desktop key revoked."
2. Active Session
Shows the computer currently connected. With none: "No desktop agent connected." and, if the key has been used, "Last connected: (time)".
You see a Connected (Wi-Fi icon) or Offline indicator, Machine, OS with version, Agent version, Connected since, Last heartbeat and Status (connected, degraded or disconnected). The list refreshes every 30 seconds.
- Force Disconnect ends the session at once, with no confirmation. A toast says "Session disconnected."
- Other connected sessions lists other computers as "(machine) ((os))", each with a Force Disconnect link.
3. Capability Status
Read-only, shown once a computer is connected: "Read-only view of what your connected agent can do. Toggle capabilities from the agent window on your machine." A summary line counts abilities that are available, blocked by policy, disabled and unavailable.
| Group | Capabilities |
|---|---|
| Filesystem | Read Files, Write Files, Watch Folders |
| Clipboard | Read Clipboard, Write Clipboard |
| Screen | Screenshot, OCR, Find on Screen |
| Input Control | Type Text, Mouse Click, Hotkeys |
| Notifications | Send Notifications, Notifications w/ Buttons |
| Process | Launch Apps, Kill Processes, Shell Commands |
Each shows a state on hover: Unavailable ("Not available in the current agent session"), Disabled by user ("Disabled by user in the desktop agent window") or Blocked by policy ("Blocked by org policy — contact your administrator"). A † mark means "Requires approval before running — set by your org, or your own approval mode in agent settings."
4. Approval Modes
"How much friction each capability requires before it runs." Choose one per capability:
| Mode | Meaning |
|---|---|
| Always Ask (default) | Prompts you every time |
| Auto-approve this session | Skips the prompt until you disconnect |
| Trust Always | Skips it permanently |
Your organization may require approval regardless. Locked rows are greyed out: "Disabled by your organization — cannot run at all", or "Your organization requires approval on every action — this mode can only narrow friction, never bypass an org-forced gate." There is no confirmation message when you change a mode.
5. Download the desktop assistant
A card titled Download Tao Desktop Assistant ("Served from your APEX instance") has Windows, Linux and macOS tabs. The tab matches your computer.
- Windows offers
TaoDesktopAssistant-Setup.msi, marked Ready now, with its size: "MSI installer — installs the service, Assistant, and CLI automatically". - Linux says "Packaging in progress" and macOS says "Design-only so far". Neither has an installer.
- If no file is uploaded: "Not yet available — Upload via Admin → Agent Releases".
Set up on Windows
- Download and run the installer. You see one permission prompt.
- The Assistant starts with a tray icon. Open it.
- Under Settings → Connection, paste the Desktop Key, WebSocket URL and API URL, then Save.
- Click Connect. Both "Local service" and "TAO platform connection" turn green, and your computer appears under Active Session.
Folders
An information tab only: "Authorized folders are configured through your connected desktop agent. Open the APEX Desktop Agent on your machine and use the folder settings to authorize specific directories." With no computer connected: "No desktop agent connected. Connect a device first to configure folder access." Nothing can be changed on this page.
Folder Watches
A read-only list of folders being watched, each with its path, "Trigger: (event)", an optional "→ workflow (id)" and a status. Empty: "No folder watches configured."
To create a watch, use the Folder Watches page at /desktop/watches:
Open New Folder Watch
Choose the Machine and the Folder path (use Browse to pick one on that computer).
Set what to watch
Optionally add a File extension filter (comma-separated; blank means all). Under Watch for events choose File created, File modified and File deleted (created and modified are on by default). Optionally choose a Workflow to trigger.
Create
Click Create Watch ("Creating…"). A toast says "Folder watch created."
Each watch can be paused, resumed and deleted ("Delete folder watch?": "The workflow trigger will stop firing from this path."). Statuses are active, paused, offline and invalid.
Robot Accounts
Robot accounts are Windows credentials that let Nexus start sessions on your computers without you being there: "Windows credentials for unattended session spawning on your connected machines — a machine can back more than one."
"Credentials are stored in the platform's credential vault, never on the desktop agent's own disk. The Service fetches them fresh, over its authenticated connection, at the moment it needs to spawn a session — never cached anywhere."
Accounts are grouped by machine, with a connected, offline or unknown dot. Each row shows DOMAIN\username, a Verified or last-test badge, and its label. With none: "No robot accounts registered yet." With no computers connected: "No connected machines yet — Connect a desktop agent first, then come back to add a robot account for it."
Add a robot account
Click Add Robot Account
Choose the Machine ("Select a machine…"). A connected one is chosen for you.
Enter the details
Machine Label (optional, e.g. "Finance-VM-01"), Windows Username (e.g. "robot1"), Domain (optional, e.g. "CORP") and Password. The password is write-only: "Never shown again after this".
Add
Click Add Robot Account ("Adding…"). A toast says "Robot account added." The button stays disabled until machine, username and password are filled in.
Row actions
| Action | What it does |
|---|---|
| Edit | Change the machine, label, username or domain. It never touches the password. Toast "Robot account updated." |
| Vault check | Confirms the stored password reads back correctly. It does not try a real Windows logon. Toast "Vault round-trip ok." |
| Desktop test | Really tries to log in on the machine (up to about 45 seconds, "Testing…") |
| Rotate | Sets a new password ("New password"). Toast "Password rotated." |
| Delete | Removes the credential after "Delete Robot Account". Unattended sessions for that machine stop working. Toast "Robot account deleted." |
Desktop test results: "Logon succeeded — a real Windows session was created.", "Logon failed — check the username/password.", "Could not reach the machine over RDP.", "Logon test timed out." or "Unattended sessions are not available on this machine."
Who can do what
- The page and its menu item need Nexus admin permission, and the desktop permissions listed above.
- Organization administrators set the ceiling for each capability and can force approval on any of them.
- A key is machine-scoped and personal to you.