Setting your assistant up is a button, not a document. Open Pomeroy’s
Assistants pane, find yours, press Set up. Each assistant has
its own page here with the exact configuration.This section is the mechanism underneath: what to pick when the button is not
enough, and what each door means for who can reach your Mac.
The three doors
All three land on the same socket and the same app. The first two are the
stdio door, which Pomeroy’s Connections pane calls
Direct and which cannot be switched off. The third is the
local endpoint, which is off until you switch it
on.
Stdio
The extension and the pipe: no port, no credential, nothing to revoke.
HTTP local endpoint
One address on this Mac, credentialled, for what stdio cannot serve.
Choosing a door
1
Claude Desktop? Take the extension.
One button, nothing to configure. Set up Claude
Desktop.
2
An assistant on this Mac that runs a command? Take the pipe.
The default for Claude Code, Cursor, VS Code, Codex and most of the rest.
Nothing listens, and nothing needs a credential.
3
A container, a VM, a runner, or an HTTP-only client? Take the endpoint.
Keep the default Token mode unless you have a specific reason not to.
After setup
Assistants differ on whether they notice a new server straight away. Pomeroy shows the right line for yours when setup finishes, and so does each assistant’s page here. Broadly: Claude Desktop and Codex want a full quit and reopen; Claude Code, Gemini CLI and goose want a new session; most editors pick the change up on their own.Several assistants at once
One Mac can serve as many as you like. They share the same toggles and the same weekly allowance, so connecting a second does not double your actions. No tier limits how many you may connect. A connection is a fact about now, not a grant. Nothing about an assistant survives it, so there is nothing to revoke: the only gate on a tool call is the app’s toggle.All 24 assistants
Each with its own page: what Set up does, and the configuration in full.
Why cloud assistants cannot connect
claude.ai, ChatGPT on the web, and what to use instead.
How Pomeroy works
The architecture the doors share.
What can reach Pomeroy
The pledge page’s account of inbound access.