Docs
Sign in

Desktop

Desktop is where you connect your own computer to Nexus, so assistants and workflows can work with your local files and apps. On the page it is titled Desktop Agent: "Connect your machine to APEX so agents and workflows can interact with your local desktop, files, and applications."

Screenshot to add: The Desktop Agent page with the My Devices, Folders, Folder Watches and Robot Accounts tabs.

Open the page

Click Settings → Desktop in the Nexus sidebar (/workspace/desktop). You need Nexus admin permission to see it. Older addresses (/nexus/settings/desktop-agent and /settings/desktop-agent) forward here.

A Desktop Approvals button at the top right opens the Approvals page. To use a connected computer in a chat, see Cowork.

There are four tabs: My Devices (default), Folders, Folder Watches and Robot Accounts.

My Devices

An information banner explains: "The desktop key is a machine-scoped credential. It can only be used to authenticate the APEX Desktop Agent — it cannot call any other APEX APIs. Store it in the agent app; it never needs to go anywhere else."

1. Your Desktop Key

There are no short pairing codes. You connect with one long Desktop Key.

  1. Generate a key

    If you have none, the page says "You don't have a desktop key yet." Click Generate Desktop Key ("Generating…").

  2. Copy the details

    A window titled Your Desktop Key opens with the warning "This key is shown only once — copy it now". It has three copy boxes: Desktop Key, WebSocket URL and API URL.

    Screenshot to add: The one-time Your Desktop Key window with the three copy rows and the confirmation checkbox.
  3. Confirm

    Tick "I've copied my key and understand it won't be shown again." Only then does Close work, and the backdrop and Esc will not close the window either.

If you already have a key, the page shows its Key prefix, Status, Created and Last used ("Never used" if so). Any status other than active shows in red.

  • Rotate Key issues a new key. Rotating "immediately disconnects any active agent session and the old key stops working." You must type ROTATE to enable the button ("Rotating…").
  • Revoke asks "Revoke Desktop Key": "This will immediately disconnect any active agent session and remove your desktop key. No new key will be generated — use this only if your machine is lost or compromised." Choose Revoke Key. A toast says "Desktop key revoked."

2. Active Session

Shows the computer currently connected. With none: "No desktop agent connected." and, if the key has been used, "Last connected: (time)".

You see a Connected (Wi-Fi icon) or Offline indicator, Machine, OS with version, Agent version, Connected since, Last heartbeat and Status (connected, degraded or disconnected). The list refreshes every 30 seconds.

  • Force Disconnect ends the session at once, with no confirmation. A toast says "Session disconnected."
  • Other connected sessions lists other computers as "(machine) ((os))", each with a Force Disconnect link.

3. Capability Status

Read-only, shown once a computer is connected: "Read-only view of what your connected agent can do. Toggle capabilities from the agent window on your machine." A summary line counts abilities that are available, blocked by policy, disabled and unavailable.

GroupCapabilities
FilesystemRead Files, Write Files, Watch Folders
ClipboardRead Clipboard, Write Clipboard
ScreenScreenshot, OCR, Find on Screen
Input ControlType Text, Mouse Click, Hotkeys
NotificationsSend Notifications, Notifications w/ Buttons
ProcessLaunch Apps, Kill Processes, Shell Commands

Each shows a state on hover: Unavailable ("Not available in the current agent session"), Disabled by user ("Disabled by user in the desktop agent window") or Blocked by policy ("Blocked by org policy — contact your administrator"). A † mark means "Requires approval before running — set by your org, or your own approval mode in agent settings."

4. Approval Modes

"How much friction each capability requires before it runs." Choose one per capability:

ModeMeaning
Always Ask (default)Prompts you every time
Auto-approve this sessionSkips the prompt until you disconnect
Trust AlwaysSkips it permanently

Your organization may require approval regardless. Locked rows are greyed out: "Disabled by your organization — cannot run at all", or "Your organization requires approval on every action — this mode can only narrow friction, never bypass an org-forced gate." There is no confirmation message when you change a mode.

5. Download the desktop assistant

A card titled Download Tao Desktop Assistant ("Served from your APEX instance") has Windows, Linux and macOS tabs. The tab matches your computer.

  • Windows offers TaoDesktopAssistant-Setup.msi, marked Ready now, with its size: "MSI installer — installs the service, Assistant, and CLI automatically".
  • Linux says "Packaging in progress" and macOS says "Design-only so far". Neither has an installer.
  • If no file is uploaded: "Not yet available — Upload via Admin → Agent Releases".

Set up on Windows

  1. Download and run the installer. You see one permission prompt.
  2. The Assistant starts with a tray icon. Open it.
  3. Under Settings → Connection, paste the Desktop Key, WebSocket URL and API URL, then Save.
  4. Click Connect. Both "Local service" and "TAO platform connection" turn green, and your computer appears under Active Session.

Folders

An information tab only: "Authorized folders are configured through your connected desktop agent. Open the APEX Desktop Agent on your machine and use the folder settings to authorize specific directories." With no computer connected: "No desktop agent connected. Connect a device first to configure folder access." Nothing can be changed on this page.

Folder Watches

A read-only list of folders being watched, each with its path, "Trigger: (event)", an optional "→ workflow (id)" and a status. Empty: "No folder watches configured."

To create a watch, use the Folder Watches page at /desktop/watches:

  1. Open New Folder Watch

    Choose the Machine and the Folder path (use Browse to pick one on that computer).

  2. Set what to watch

    Optionally add a File extension filter (comma-separated; blank means all). Under Watch for events choose File created, File modified and File deleted (created and modified are on by default). Optionally choose a Workflow to trigger.

  3. Create

    Click Create Watch ("Creating…"). A toast says "Folder watch created."

Each watch can be paused, resumed and deleted ("Delete folder watch?": "The workflow trigger will stop firing from this path."). Statuses are active, paused, offline and invalid.

Robot Accounts

Robot accounts are Windows credentials that let Nexus start sessions on your computers without you being there: "Windows credentials for unattended session spawning on your connected machines — a machine can back more than one."

"Credentials are stored in the platform's credential vault, never on the desktop agent's own disk. The Service fetches them fresh, over its authenticated connection, at the moment it needs to spawn a session — never cached anywhere."

Screenshot to add: The Robot Accounts tab with accounts grouped by machine and their action buttons.

Accounts are grouped by machine, with a connected, offline or unknown dot. Each row shows DOMAIN\username, a Verified or last-test badge, and its label. With none: "No robot accounts registered yet." With no computers connected: "No connected machines yet — Connect a desktop agent first, then come back to add a robot account for it."

Add a robot account

  1. Click Add Robot Account

    Choose the Machine ("Select a machine…"). A connected one is chosen for you.

  2. Enter the details

    Machine Label (optional, e.g. "Finance-VM-01"), Windows Username (e.g. "robot1"), Domain (optional, e.g. "CORP") and Password. The password is write-only: "Never shown again after this".

  3. Add

    Click Add Robot Account ("Adding…"). A toast says "Robot account added." The button stays disabled until machine, username and password are filled in.

Row actions

ActionWhat it does
EditChange the machine, label, username or domain. It never touches the password. Toast "Robot account updated."
Vault checkConfirms the stored password reads back correctly. It does not try a real Windows logon. Toast "Vault round-trip ok."
Desktop testReally tries to log in on the machine (up to about 45 seconds, "Testing…")
RotateSets a new password ("New password"). Toast "Password rotated."
DeleteRemoves the credential after "Delete Robot Account". Unattended sessions for that machine stop working. Toast "Robot account deleted."

Desktop test results: "Logon succeeded — a real Windows session was created.", "Logon failed — check the username/password.", "Could not reach the machine over RDP.", "Logon test timed out." or "Unattended sessions are not available on this machine."

Who can do what

  • The page and its menu item need Nexus admin permission, and the desktop permissions listed above.
  • Organization administrators set the ceiling for each capability and can force approval on any of them.
  • A key is machine-scoped and personal to you.

Known gaps

Related pages