Tier Two Client

One app per machine. Every agent governed.

The Tier Two Client v0.1.2 runs as a menu-bar app: it owns the machine's device identity, registers Claude Code and Cursor automatically, serves any other MCP host from one local endpoint, and reports sessions and device posture to your dashboard.

macOS packages are signed with a Developer ID certificate and notarized by Apple — they install with no security overrides. Windows support is coming; agents there can keep using npx -y @tiertwo/mcp.

After installing

Pair once, then every agent on the machine is covered.

The client walks you through pairing from its tray icon, migrates existing npx entries in place, and any MCP host it doesn't know can connect through the local endpoint or the stdio shim.

1 · Pair from the tray

Click the tray icon, hit Pair, and confirm the verification number in your dashboard. Machines that already paired via npx keep their identity — nothing is re-registered.

2 · Hosts connect themselves

Claude Code and Cursor are registered automatically at first launch. Other hosts use the endpoint snippet shown in the tray.

3 · stdio-only host?

Point it at npx -y @tiertwo/mcp connect — a transparent pipe to the running client.

Rolling out a fleet? Push the client by MDM with a managed config, or bake an admin-minted enroll secret into your image. Machines enroll without a human, land unassigned, and fail closed — nothing is allowed until each device is bound to its owner at first sign-in.

Give your agents an identity you control.

Self-serve and free while in beta. Start with one agent and one connection.