DeskVNC agent hub
Platforms / macOS

macOS: signed and notarised, the same dvv inside the same bundle

DeskVNC on macOS is a signed and notarised universal bundle, runs natively on Apple Silicon and Intel, and stores every saved host's password in Keychain Services. The MCP server that an agent drives lives inside the bundle, at one well known path, and the same binary runs on Windows and Linux with no rebuild.

Signed, notarised, universal

The macOS build is signed with a Developer ID certificate and notarised by Apple, so it opens normally without a Gatekeeper detour. The DMG that contains it is a universal binary: it runs natively on Apple Silicon and on Intel, so the same download works on every Mac shipped in the last decade. The file name follows the same pattern as the other platform builds:

Terminal dmglob
DeskVNCViewer_<version>_universal.dmg

You can confirm the notarisation yourself from a Terminal window:

Terminal spctl
spctl -a -vv -t exec /Applications/DeskVNCViewer.app

Notarisation is what makes the second click unnecessary. A download that did not come back from Apple's notarisation service would prompt for an override the first time it is opened, and that is the same first-time-only detour a signed Windows installer can show on SmartScreen.

Permissions macOS asks for, and why

The first time a DeskVNC session needs to share a screen or receive keystrokes for global capture, macOS prompts the user for two permissions in System Settings. Both are deliberate: they are how macOS guarantees that recording the screen and synthesising input are deliberate user decisions.

  • Screen Recording. Granted to DeskVNCViewer so the local screen can be shared with a worker on the other side, and so the app itself can render an incoming RDP or VNC frame at full speed. macOS asks for it the first time the app would otherwise need to capture pixels, and the user can grant or decline from System Settings > Privacy & Security > Screen Recording.
  • Accessibility. Granted only when global input capture is turned on, which is the feature that lets system shortcuts reach the remote machine instead of your own. The grant is revocable in the same System Settings panel, and revoking it does not break the rest of the app.

A second pair of permissions is asked for on first use inside the installed app:

  • Local Network, for mDNS discovery and the polite subnet scan. Typed addresses work as well as discovered ones, and the permission can be revoked without breaking typed connections.

None of the permissions are bundled into a single prompt. Each one is asked for when the feature that needs it is first used, and each one can be granted or revoked from System Settings without uninstalling the app.

Where dvv lives inside the app bundle

macOS bundles keep their executables inside Contents/MacOS. The desktop app is /Applications/DeskVNCViewer.app/Contents/MacOS/DeskVNCViewer, and the agent binary, dvv, sits beside it at:

Terminal dvv path
/Applications/DeskVNCViewer.app/Contents/MacOS/dvv

That is the path to register with Claude Code, OpenCode, Codex or any other MCP client. The shell client, run from a Terminal window, also lives at this path. An agent registered on a Mac and moved to a Linux workstation points at the same binary shape, just at a different path on disk.

Terminal dvv doctor
dvv doctor

Keychain Services, the secret store macOS already audits

When a saved host has a password, the password goes to Keychain Services rather than into a file next to the saved host list. Keychain Services is the same store Safari uses for website logins and Mail uses for account credentials, with the same item level access control and the same per app consent that the rest of macOS uses.

DeskVNC creates one Keychain Services item per saved host, named in a way that ties it back to the host record in the profile database. The user profile holds the non sensitive parts: the address, the protocol, the display name, the colour, the thumbnail. It never holds a password, and the project carries a test that asserts it.

An agent that opens one of your saved machines can drive the desktop, and it can never read or supply the password that opens it. The credential is applied on the far side of the same call your click goes through, with no server method that returns a stored secret.

Day one on macOS

Everything below works the moment DeskVNC finishes installing, with no configuration required:

  • A native client on Apple Silicon and on Intel from a single universal binary.
  • Saved host library, live thumbnails, tabs and split panes.
  • Clipboard sync, with the direction the toolbar sets, including rich text.
  • SFTP file transfer, over the machine's own SSH server.
  • The dvv MCP server, the same 25-tool manifest as on every other platform.
  • mDNS browsing, the polite subnet scan with banner fingerprinting, Wake on LAN.
  • Keychain Services for every saved host's password, the store the rest of macOS uses.

Read more