InvokeFlow operates unmodified applications on Windows, macOS and Linux — new or decades old — and gives every one of them a face any MCP-capable agent can call.
Turns a real desktop into a programmable surface of real applications. Launch, place, call and close the software the machine already has — then save the arrangement by name and push it across a fleet.
Windows · macOS · Linux
The same protocol pointed at a screen. A programmable, observed surface of tiles for kiosks, floors, lobbies and rooms — governed the same way, recorded the same way.
Shipping in real deployments
What is running, where, across every device — with the same record behind it. The view an operator needs before a fleet is a fleet.
MQTT · HTTP · MCP
Same envelope. Same scopes. Same screen states. Same record. Same fleet.
The runtime asks the running application what it can do and publishes that list. Modern software exposes rich, structured commands; older software exposes less, so the runtime discovers the commands live and assembles them itself. No plugin. No vendor cooperation. Nothing to rebuild when the application updates.
Each command is checked at the exact live window it is about to touch, for a bounded time. Not a seat. Not a standing grant. Not a policy written last quarter and hoped for today.
The call goes to the application’s own commands, in place, on the machine where the work lives — with a person in the seat. Every command re-resolves its target, including across launcher hand-offs and application restarts.
Every command — and every refusal — lands in a hash-chained record you can query, export and hand to an auditor. Where a declared check can observe the effect, the step is verified; otherwise the record says so.
In one runtime, across every desktop OS.
Unmodified applications, where they already run — without a vendor-authored plugin.
Pulls from one, acts in another, keeps them in sync as they change.
Every command finds the exact live window again before it acts.
The person stays in the seat. The agent works alongside them on the same surface, and either can take the controls.
Uses the application’s own responses and live state where available, then records what ran and what proved it.
The API is what the vendor chose to expose. The application can do more. We call all of it — every command the software already knows, with no plugin and no permission asked.
Commands discovered from the running application are re-exposed as tools any MCP-capable agent can call — giving software that never shipped an interface a working one.
Your real applications joined into one live workspace, arranged for the task — grounded in the software itself, not a dashboard generated beside it.
Routine steps run deterministically, with no model round-trip. Faster, and a fraction of the agent tokens. Your AI budget goes to judgement, not clicks.
What it learns, it can run — in the same runtime — and prove it ran. It never records your screen to do it.
Bring the agent and the model you already chose. A local model works the same way as a cloud one — and nothing leaves the endpoint either way.
A live view of the estate. See what is running, where, and whether it is healthy, across every desktop — while the work happens. Over time, the record shows which applications and workflows your teams lean on most, so the next automation is obvious.
Point InvokeFlow at the applications it lives in. It runs governed and on the record from the first command.