Firmi Hands is a small app on your Mac. Connect the chatbot you already use, and it can do real tasks on your computer with your apps and your logins. Anything that matters waits for your approval on your phone.
Claude, ChatGPT, Muse, or anything that supports connectors (MCP) or custom tools. The chatbot you already pay for keeps being the brain.
Our service checks who is asking and what they may do, then passes the task along. One sign-in per chatbot, revocable from your phone.
A small app does the task with your apps and your logins. It dials out to us and opens no ports. We never host your computer.
A screenshot and the exact action, and a Face ID check before anything important happens. Never an approval typed into a chat.
A browser inside a chatbot is not you. These are the jobs it loses to, and the ones Hands wins.
It acts in the browser you are already signed into: your sessions, your saved logins, your shopping account. No new accounts to hand a robot.
When a chatbot's built-in browser is offline, its web work stops. Hands runs on your Mac, so the task does not have to stop with it.
The task comes from your home connection and your everyday browser, because it really is you acting, with your approval on every step that matters.
Hosted browsers only see web pages. Hands sees and drives your desktop apps too.
When a CAPTCHA appears, the agent stops and hands it to you. You finish it on your phone and it carries on. It never solves them itself.
To your computer it is indistinguishable from a human's keyboard and mouse, because it is one. $29 shipped, free with annual Pro. The app works without it.
Some apps and fields ignore software-typed input. The kit works there, skips the macOS Accessibility permission, and you watch the pointer move. The app works without it.
A Raspberry Pi Pico, pre-flashed and tested, a small case, and a USB-C cable. Plug it in and the app finds and pairs it. No soldering, no firmware steps.
It shares a secret with your Mac at pairing and ignores every other computer. It only acts on tasks you approved, and pulling it out of the port stops everything.
Content from a page or a chat is treated as data: it cannot widen its own permissions, add sites, or change settings. Those changes wait for your approval. Every click and keystroke is logged with a screenshot, visible to you, encrypted and deleted after 7 days (90 on Pro).
It makes outbound connections only. It does not open a listening port and does not accept incoming remote access.
You add a Mac by confirming a code on that Mac's own screen. The device key lives in the Secure Enclave and never leaves it.
Each chatbot gets its own grant with scopes like look only or web only. One tap revokes a chatbot everywhere.
Read-only scopes can act without a tap. Anything that changes something, paying, sending, deleting, submitting, changing settings, visiting a new site, and anything the model is unsure about, waits for Face ID before it happens.
You sign in yourself, or your password manager fills. Secrets are masked in screenshots and logs.
A banner shows on screen while it works, moving your mouse pauses it, a hotkey stops it, and Stop all is on your phone.
Before any paid launch: an outside penetration test, and a bug bounty after.
Bring your own model key and both plans are $3 a month less. Waitlist members get the first invites and the launch pricing.
Phone approvals, any chatbot, every safety feature. The plan for one computer and one person.
Site and app allowlists on top of Personal, and 90 days of history instead of 7.
The pre-flashed USB stick, cased and cabled. Free with annual Pro.
Tell us the first thing you would have it do. Waitlist members get the first Mac beta invites.