Which assistants can connect?
Any that speak MCP, the open protocol published by Anthropic: Claude Desktop, Claude Code, Cursor, and the list grows every month. Kestro ships an ordinary MCP server, over stdio, launched by your client like any other. Nothing is tied to one editor, and you can connect several to the same app.
Does my data go through your servers?
No, and there is no server of ours in this story. The MCP server is a program shipped inside the app that talks to Kestro through a socket in your user directory, not over the network: a local TCP port would be reachable from any page open in your browser, and we did not want that door. What reaches your AI vendor is what you write to it and what it asks for, exactly as when you paste text into a chat.
What if the AI works around it by typing the command in a terminal?
It can, and we would rather say so. Kestro bounds its own door, not your machine’s shell: an assistant with terminal access can type whatever it likes, including the kestro command. What these settings protect is the door Kestro just opened, and that is already the point, because the real risk is not a malicious assistant, it is one that gets it wrong or that some text it read along the way manipulated. The instructions Kestro gives yours explicitly tell it not to look for a workaround, and to relay the refusal to you.
Can I see what it did while I was looking elsewhere?
Yes, if you switch it on: a history records every action asked for, when, what, on which object, allowed or refused. The refusals are often worth more than the rest: they show what your assistant tried. It is off by default and never leaves this Mac. Kestro keeps no record of what you do, and will not start keeping one unasked.
Can it grant itself permissions it does not have?
No, and it is the one rule in the whole design that is not adjustable. The permission settings are not among what the MCP server may request, nor among what the kestro command may do: they are reachable from the app window only, in front of their owner. An assistant asking you to go and tick a box is doing its job; one ticking it itself would not be.
Does this feature need a subscription or an API key?
No. The MCP server is in the app, like the kestro command: it is not sold separately, asks for no account and calls no service. You pay for Kestro once, and what it does today it will still do in two years, offline included.
Does the trial ask for a card?
No, and it does not ask for an account either. You download it and you get 7 full days. No card is requested until you decide to buy.