An AI agent with its own desktop
A workspace you can watch
Section titled “A workspace you can watch”An agent gets its own Linux account, desktop, Chromium browser and files. Its owner connects an MCP client with an agent token. The tools cover screenshots, keyboard, pointer, windows, clipboard, shell and browser automation.
Configure an agent
Section titled “Configure an agent”On NixOS, declare an owner and enable the module:
services.darpan = { enable = true; allowedUsers = [ "alice" ]; aiAgents.scout.owner = "alice";};Add your HTTPS origin or Cloud Connect configuration too. On Debian/Ubuntu, create a dedicated Linux account with a real shell, add it to the launcher’s allowlist, and configure DARPAN_AI_AGENTS=scout=alice in the host’s environment file. Check that file for the exact gateway options for your installed release.
Connect and supervise
Section titled “Connect and supervise”Open the host’s dashboard, create an agent token and copy the MCP endpoint into your client. Treat the token as a password. Keep it out of shared documents and logs.
Use Watch to follow the desktop, Pause to prevent further agent actions, and take over with your own input when needed. The agent can still observe while paused. Its task board lets you assign work and see progress.
Keep the boundary clear
Section titled “Keep the boundary clear”The agent can run shell commands as its Linux account. Give it access only to files and credentials it needs. This is your own trusted machine, not an isolation service for unknown tenants. Desktops share a host kernel.