What Claude computer use does
Anthropic released computer use as a public beta on October 22, 2024. Claude looks at a screen and works it like a person, moving the cursor, clicking buttons and typing text. It's available through the Claude API, Amazon Bedrock and Google Cloud's Vertex AI. (Anthropic)
What matters here is where it runs. Claude doesn't come with a computer. It returns actions such as screenshot, left_click or type, your application carries them out in an environment you control, and the results go back to Claude. The loop repeats until the task is done. Anthropic's reference implementation is a Docker container with a virtual X11 display, a lightweight desktop and some preinstalled apps. (Claude docs)
Anthropic's docs also recommend some precautions (same source):
- Use a dedicated virtual machine or container with minimal privileges.
- Don't give the model sensitive data such as login credentials.
- Limit internet access to an allowlist of domains.
- Ask a human to confirm consequential actions.
The pattern
The model supplies the decisions, and you supply the computer. For a demo, that's a container on your laptop. For a product, you need one computer per user or per task, kept between sessions, with credentials the model doesn't see and a way for people to watch.
Build it with the Claude API and Burrowbox
A Burrowbox machine is a Linux desktop with its own MCP endpoint. Its tools include desktop control (screenshot, click, type_text, get_app_state), a persistent browser (browser_navigate, browser_snapshot, browser_login) and shell_run. With the Messages API's MCP connector, Claude calls these tools directly, so you don't need an MCP client or a tool loop of your own. Burrowbox isn't affiliated with Anthropic.
1. Create a machine
curl -X POST https://burrowbox.dev/api/machines \
-H "Authorization: Bearer $BURROWBOX_KEY" -H "Content-Type: application/json" \
-d '{"name": "ops-desk", "size": "small", "ttlMinutes": 30}'
# → { "id": "…", "mcpUrl": "https://burrowbox.dev/api/machines/…/mcp", "mcpToken": "tmm_…" }
2. Give Claude the machine (Python)
import os
import anthropic
client = anthropic.Anthropic() # reads ANTHROPIC_API_KEY
response = client.beta.messages.create(
model="claude-opus-5-5",
max_tokens=16000,
betas=["mcp-client-2025-11-20"],
mcp_servers=[{
"type": "url",
"url": os.environ["MCP_URL"], # the machine's mcpUrl
"name": "burrowbox",
"authorization_token": os.environ["MCP_TOKEN"], # the machine's mcpToken
}],
tools=[{
"type": "mcp_toolset",
"mcp_server_name": "burrowbox",
# allowlist: only the tools this task needs
"default_config": {"enabled": False},
"configs": {t: {"enabled": True} for t in [
"browser_navigate", "browser_snapshot", "browser_click", "browser_fill",
"browser_login", "screenshot", "file_write",
]},
}],
messages=[{"role": "user", "content": "Log in to the supplier portal, download this month's invoices and save a summary to ~/invoices.md"}],
)
for block in response.content:
if block.type == "text":
print(block.text)
The token only works for this one machine. Claude's tool calls show up in the response as mcp_tool_use and mcp_tool_result blocks, which you can log.
3. How this lines up with Anthropic's precautions
- Dedicated machine: every machine is its own isolated container with its own disk.
-
No credentials in the prompt: put the login in the machine's vault (
PUT /api/machines/{id}/vault/{name}).browser_loginfills the form without returning the password to Claude. -
Human confirmation: embed the live view so a person can watch (
"interactive": false) or take over ("interactive": true). For approval on each tool call, run your own tool loop instead of the connector. - Domain allowlist: Burrowbox doesn't filter a machine's outbound traffic. Enforce that in your own network layer if you need it.
4. Let Claude manage machines too
The platform MCP endpoint takes your API key. Through it, an agent can create, start, stop and destroy machines (machine_create, machine_stop, …) and call any machine tool with machine_call_tool:
claude mcp add --transport http burrowbox https://burrowbox.dev/mcp \
--header "Authorization: Bearer $BURROWBOX_KEY"
A small machine (1 vCPU, 6 GB) costs $0.11 an hour while running, and state is kept when it's off. See Billing.
Create an account to try it.
Sources
- Anthropic, Introducing computer use: https://www.anthropic.com/news/3-5-models-and-computer-use
- Claude docs, Computer use tool: https://platform.claude.com/docs/en/docs/agents-and-tools/tool-use/computer-use-tool
- Claude docs, MCP connector: https://platform.claude.com/docs/en/agents-and-tools/mcp-connector
- Burrowbox docs, MCP: https://burrowbox.dev/docs/mcp
Originally published on the Burrowbox blog.
Top comments (0)