All posts

Agents

Computer use drives software. It does not house it.

Claude can operate a desktop now. That makes more small tools get built, which makes the question of where those tools live sharper rather than softer.

3 min read

People keep asking us a version of this question: if Claude can already use a computer, what is a hosting platform for? It is a fair thing to wonder, and the answer is not a turf dispute. The two things sit on opposite sides of the same gap.

What computer use actually is

Computer use is a tool the model calls. You declare one toolset entry in the request and Claude gets seventeen member tools: screenshot, left_click, type, zoom, and the rest of the mouse and keyboard surface. It takes a screenshot, decides where to click, and clicks there.

The important line in those docs is about who owns the machine. “Your application runs every call in an environment you control.” Anthropic processes the screenshots and returns the actions. The desktop is yours to stand up and yours to tear down.

Read the security precautions on that page and you can see what shape that environment is meant to be. Anthropic recommends a dedicated virtual machine or container with minimal privileges, no access to sensitive data such as login credentials, internet access limited to an allowlist, and a human confirming anything with real consequences.

That is a description of a disposable box. It is the correct design for a thing that drives software on your behalf for the next twenty minutes. It is not a description of somewhere your colleague’s commission calculator lives for the next two years.

What that leaves unsolved

Say the agent drives a browser and produces something useful. A reconciliation script, a dashboard, a form that writes to a database. Now Priya in finance needs to open it on Tuesday.

Nothing about computer use answers that. The environment was ephemeral on purpose, so it has no stable address and no sign-in. It knows about one person, the one who launched the session. Those are hosting questions, and they arrive the moment the agent’s work is worth keeping.

Computer use Sploot
What it is A tool the model calls to drive a GUI A place to run and share an app
Who supplies the machine You do, per session We do, and it stays
Lifetime The session Until you delete it
Access control Whatever your sandbox enforces Per person, by work email, before the app boots

The gap has been widening for a year. Every capability that makes software cheaper to produce raises the number of small tools sitting in a Downloads folder with no address. We wrote about that pile in your assistant wrote the tool, now what. Computer use adds to it.

The part that does overlap

There is a real point of contact, and it is not the desktop. It is MCP.

The Model Context Protocol is an open standard for connecting AI applications to external systems, described in its own docs as a USB-C port for AI applications. Sploot generates an MCP server for every app it hosts, from the routes, CLI entrypoints and function signatures it finds in the source. Even a tool with no web server gets an agent endpoint.

So the same app an agent might have clicked through pixel by pixel can instead be called as a function, by name, with typed arguments. Computer use is the fallback for software that was never built to be driven by anything but a human. An app with an MCP endpoint does not need the fallback.

Where Sploot is aiming

Since this is our blog: the bet is that the folder is the input and that sign-in with a work email belongs on the door, before the app boots rather than wired up afterwards. An agent should get a function call instead of a screenshot.

Sploot is in private beta and there is nothing to log into yet, so read that as intent rather than an offer. If you are wiring up computer use this week, none of this competes with that. It starts mattering on the day something the agent built is worth opening again.

Tags

  • AI
  • agents
  • hosting
  • small software

Sploot is the place this ends up

Hand it the folder your assistant wrote and get back a link your team can open. Private beta, soon.

One email when it's live. Nothing else, ever.