Documentation

Learn how to use the Dashboard

Quick Start Guide

Get up and running with the Dashboard in minutes.

1
Create Invite
Copy the link and share with your client
2
Client Opens URL Invite
They download installer and follow instructions. They can install client, set for unattended access, and share password
3
Connect
Dashboard user will need to enter password on first connection. Device appears with real-time status in Devices section

Remote Devices

The Devices screen is your central hub for managing all connected remote devices.

How to add a new computer in one minute

Quick Connect

Enter a Device ID directly to connect without adding to your device list. Useful for one-time support sessions. Choose Connect (opens the desktop app), Web (opens the connection in your browser, no install needed), or Files (file transfer via the desktop app).

Connecting to a Device

Each device row has up to four actions on the right:

  • Connect: opens a remote-desktop session in your installed HopToDesk app. Only shown for online devices.
  • Web Connect (globe icon): opens the connection in your browser via web.hoptodesk.com. No app install needed; works on Chrome OS, mobile browsers, or any machine where you can't install software.
  • File Transfer (file icon): opens a file-transfer session in the desktop app (desktop only).
  • Wake: replaces Connect for offline devices that have a known MAC address. Sends a Wake-on-LAN packet via another online device on the same local network.
  • (kebab): Notes, Delete device.

Adding a Connected Device to Your Dashboard

When you connect to a device that isn't on your dashboard yet, including ad-hoc Quick Connect sessions, you can enroll it without sending an install link. In the desktop app, click the green Add to Dashboard button in the session toolbar; in a Web Connect session, click the same button in the browser toolbar. The person at the remote device gets an Accept Dashboard Invite prompt, and once they accept, the device registers and appears in your Devices list.

Mobile Layout

On phones, the device list renders as a stack of tap-to-connect cards instead of a table. Tap a card to connect: if the HopToDesk app is installed on the phone, the tap opens the app on that device; otherwise a Web Connect session starts in the browser. Devices that sign in through SSO or need connection approval always use Web Connect. File Transfer is hidden on mobile because it needs the HopToDesk desktop app.

Device Management

  • Search & Filter: Find devices by name, group, or customer in the search box, narrow the list with the All Groups dropdown next to it, filter by online/offline status, or sort by various criteria
  • Bulk Actions: Select multiple devices (desktop only) to delete or move to groups at once
  • Export: Download your device list as a CSV file for reporting
  • Groups: Assign each device to a group from the inline + Add group button on the row

Device Details (Click device name to expand)

  • Device Name: Set a friendly name for easy identification
  • Notification Email: Get email alerts for this specific device
  • Online/Offline Sound: Toggle audio notifications when device status changes
  • Connection Info: View IP address, first connected date, last seen, and session count
  • Session Log: Review recent connection history and export logs. The CSV export includes technician, duration in minutes, and, with Session Notes enabled, the note and billable flag per session

Multiple Monitors

When the remote device has more than one display, the session toolbar shows a tile for each monitor plus an All tile. Click a number to view that monitor, or All to see every monitor side by side in one window. The display menu (the monitor icon) offers the same All Displays view and Each monitor in its own window, which opens one extra window per monitor. All the windows share the one session, so no second password is needed.

  • Closing an extra monitor window closes only that window; the session stays connected.
  • Closing the main session window ends the session and closes every monitor window with it.
  • The camera icon (or Ctrl+Shift+S) copies a screenshot of the monitor you are viewing to your clipboard. In the All view it captures every monitor as one image.
  • Adjust Window in the display menu resizes the session window to fit the remote display at the current zoom.

View Only

Turn on View only in the display menu to watch a device without sending mouse or keyboard input, for example to check whether someone is using it or to observe a problem without getting in the way. The remote cursor stays visible and clipboard and file copy pause while it is on. Turn it off to take control again. The choice is remembered per device.

Tip: If the desktop app isn't installed on the machine you're connecting from, use Web Connect. It works in any modern browser without an install.

Contacts

Contacts let you manage customer information independently of devices. Link multiple devices to one contact, track all interactions, and create tickets for specific customers.

Creating a Contact

  1. Click Contacts in the sidebar
  2. Click the Add Contact button
  3. Fill in customer details:
    • Name (required) - Customer's full name
    • Email - For notifications and correspondence
    • Phone - Contact number
    • Company - Their organization
    • Notes - Any relevant information
  4. Click Save Contact

Linking Devices to Contacts

Associate devices with their owners for better organization:

  • Manually: On the Devices page, click a device name to expand it, then under Edit Device pick a contact from the Contact dropdown and click Save Changes. Choose "No contact" to unlink.
  • Automatically on enrollment: When a device enrolls through an invite that includes the customer's name or email, it's linked to that contact automatically, and the contact is created if it doesn't already exist.
  • From an invite: Fill in the customer name/email when creating a Standard or SSO invite to link devices as they come online.
  • One contact can have multiple devices (e.g., laptop + desktop).

Managing Contacts

  • Search: Find contacts by name, email, or company
  • View History: See all tickets and sessions for a contact
  • Create Ticket: Open a contact and click Create Ticket to start a support request linked to that customer
  • Import/Export: Bulk import from CSV or export for backup

Tip: Create contacts before sending invites to track which customer received which invite and keep your device list organized.

Invite System

Invites are the easiest way to add client devices to your dashboard.

How to add your first device to HopToDesk

Creating an Invite

  1. Open the Devices screen
  2. Click + Create Invite in the top-right of the page header
  3. An invite link and code are generated immediately, no form to fill
  4. Copy the URL (or the short invite code) and share with your client

Need to find a previously-created invite? Click Pending Invites in the same header to browse, copy, or delete any open invite.

Reusable, Multi-Device by Default

Each invite link is reusable: one link can install HopToDesk on any number of devices. Each device that uses the link registers as a separate entry in your dashboard, automatically associated with the invite. This is ideal for rolling out a new fleet, sharing with a customer site, or letting an MSP team self-onboard.

SSO Invite Codes

If your account has SSO configured (see the SSO docs), you can also create SSO invite codes for org-wide auto-enrollment: the device installs the client, completes SSO sign-in once, and lands in your dashboard scoped to the right tenant. Useful for large deployments where you don't want to send a one-off URL to each user.

Sharing with Clients

Send the invite link to your client via:

  • Email: copy and paste the link
  • Chat / messaging: works in Slack, Teams, anywhere
  • SMS: works on mobile too
  • Short invite code: for users who'd rather type a 12-character code than a URL

What Happens When the Client Clicks

  1. Client sees your branded install page (configured under Client Builder → Invite Page)
  2. The right HopToDesk client downloads automatically: your generated/branded version if you've set one up under Client Builder, otherwise the default
  3. Once installed, the device registers and appears in your Devices list with real-time status
  4. You can connect (Connect, Web Connect, or File Transfer) as soon as the device is online

Mass Deployment (Zero-Touch Enrollment)

How to install HopToDesk on hundreds of computers

For large fleets there are two ways to onboard:

  • Reusable invite code: one code onboards any number of devices, but someone enters it once per device under Add to Dashboard. Best for small fleets or when you are already handling each device by hand.
  • Auto-enroll custom build (zero-touch): bakes a reusable enrollment token into the installer itself, so every device that installs it links to your dashboard automatically on first launch, with no per-device code. Best for hundreds or thousands of devices.

To create a zero-touch build, open Client Builder, choose your platform (Android .apk and desktop are supported), check Auto-enroll for mass deployment, and generate. Download the finished build once and distribute that single file to your whole fleet through your MDM or EMM (such as Intune or Workspace ONE) or during device setup. Auto-enroll is available on the Business plan.

The Android auto-enroll build is the full sideload APK, not the Play Store app, because a single public Play listing cannot carry your account's token. Push it through your MDM so installs are silent and skip the unknown-sources prompt.

The token is reusable and revocable: to stop new enrollments, delete the auto-enroll invite under Pending Invites. Devices already enrolled stay connected.

How the installer reaches your devices

Auto-enroll puts the dashboard link inside the installer. How that installer gets onto your devices is a separate step, and you have options:

  • With an MDM or EMM (Intune, Workspace ONE, SOTI, Jamf, Google Endpoint Management): the console your IT already uses to manage devices. You upload the installer once, assign it to a group of devices, and the console installs it silently on every device, with no prompts and no one touching them.
  • By hand: run the installer on each device yourself (run the .exe, or sideload the .apk). Still no per-device code to type, but someone touches each device. Fine for small numbers.
  • During setup or imaging: include the installer in your provisioning image or first-boot script so every new device ships with it.

The MDM is your tool, not ours. We provide the auto-enroll installer; your existing deployment method installs it.

Deploying through an MDM, step by step

  1. Generate an auto-enroll build for your platform under Client Builder (check Auto-enroll for mass deployment).
  2. Download the finished installer from the build list.
  3. In your MDM console, add it as a managed app (upload the .apk, .exe, .msi, or .pkg).
  4. Assign the app to a device group, for example "Warehouse tablets", and set it to install automatically (required).
  5. Deploy. The MDM pushes and installs it silently on every device in the group.
  6. Each device links itself to your dashboard on first launch. Watch them appear under Devices, then tag or group them.

Examples by platform

  • Windows with Microsoft Intune: Apps → Add → Windows app, upload the .exe or .msi, set the install command to run silently, and assign it to a device group as Required. Intune installs it on every assigned PC.
  • Android with an EMM (SOTI MobiControl, Workspace ONE, Intune, Google Endpoint Management): upload the auto-enroll .apk as an internal or line-of-business app, assign it to your device group, and set it to install silently. On managed devices the install needs no unknown-sources prompt. Rugged fleets deploy the same .apk through their provisioning tool (for example Zebra via StageNow, Samsung via Knox).
  • macOS with Jamf or Intune: upload the .pkg or .dmg as a managed app and scope it to a device group.

Windows with Microsoft Intune, in full

Intune installs Windows desktop apps as Win32 apps, which means the installer has to be wrapped in an .intunewin package and paired with a detection rule. The values below are the ones Intune asks for.

1. Wrap the installer

Download Microsoft's Win32 Content Prep Tool (IntuneWinAppUtil.exe), put the installer alone in a source folder, and run:

IntuneWinAppUtil.exe -c C:\hoptodesk-src -s HopToDesk.exe -o C:\hoptodesk-out

That produces HopToDesk.intunewin. Use the auto-enroll build from Deployment, Client Builder if you want the devices to link themselves to your dashboard.

2. Add the app

In the Intune admin center go to Apps, then Windows, then Add, and choose Windows app (Win32). Upload the .intunewin file.

3. Program

  • Install command: HopToDesk.exe --silent-install
  • Uninstall command: "%ProgramFiles%\HopToDesk\HopToDesk.exe" --uninstall
  • Install behavior: System
  • Device restart behavior: No specific action
  • Return codes: keep the defaults, and if your install command uses --wait-for-enrollment, add 2 as a success code. The installer returns 0 when the device enrolled, 2 when it installed but enrollment was not confirmed before the timeout, and 1 when the install itself failed. Without that entry Intune reports a working install as a failure.

4. Requirements

  • Operating system architecture: x64. Add arm64 only if you are uploading the ARM64 build; the x64 build runs on ARM devices under emulation.
  • Minimum operating system: Windows 10 1607, which is the floor for Win32 apps in Intune.

5. Detection rule

This is the step that most often goes wrong. Use one of these, not a version check:

  • File rule: path %ProgramFiles%\HopToDesk, file HopToDesk.exe, detection method File or folder exists.
  • Registry rule: key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HopToDesk, detection method Key exists.
  • MSI rule: only if you uploaded the .msi rather than the .exe. Intune reads the product code from the package for you.

Custom builds: a branded client installs under its own name, so replace HopToDesk in the paths, the registry key and the executable name with the application name you chose in the Client Builder.

6. Assign

Assign the app to a device group under Required. Device groups install without a signed-in user; user groups wait for a sign-in, which is usually not what you want for unattended access. Devices appear in your dashboard under Devices as they check in.

7. Enrollment token instead of a custom build

If you would rather deploy the stock installer, push the enrollment token as a registry value with an Intune configuration profile: HKLM\SOFTWARE\Policies\HopToDesk\EnrollmentToken. The client reads it on first launch and enrolls itself. Generate the token under Deployment, Client Builder, Managed deployment (EMM).

Which platforms this covers

Auto-enroll works on every platform the Custom Client Generator builds, because the dashboard link lives in the installer, not in the install method. Android, Windows, and macOS all deploy cleanly through an MDM. Linux has fewer MDM options, so there it is usually a scripted install (for example with a setup script or a tool like Ansible); the auto-enroll build still links itself the same way.

EMM managed configuration (no custom build)

If you run an EMM (Intune, Workspace ONE, SOTI, Jamf), you can skip the custom build entirely: deploy the standard app and push the enrollment token as managed configuration. The device reads it on first launch and enrolls itself. Generate the token under Client Builder → Managed deployment (EMM). The config target depends on the platform:

  • Android: app configuration key enrollment_token.
  • Windows: registry value HKLM\SOFTWARE\Policies\HopToDesk\EnrollmentToken (push via Intune, Group Policy, or a setup script).
  • macOS: a configuration profile setting the managed preference enrollment_token in the domain com.hoptodesk.hoptodesk.

The Windows registry path and macOS domain above are for the standard app. A custom-branded build uses your app name in place of HopToDesk, so its Windows key is HKLM\SOFTWARE\Policies\YourAppName\EnrollmentToken and its macOS domain is com.yourappname.yourappname. The Android enrollment_token key is the same for every build.

Linux has no standard managed-config mechanism; use the auto-enroll build there. Managed deployment is available on the Business plan.

Tip: One invite link can register an entire site or fleet. Combine with the Client Builder for an entirely white-labeled install experience.

Tickets

How to take support tickets from your customers

Manage support requests from your clients. Tickets can be created in three ways:

Remote access only? Owners and admins can turn the help desk off in Settings, in the Help desk card. Tickets, the Embed Widget and Satisfaction then leave the sidebar. A custom build can hide the ticket entry in the client as well (see Advanced Options under Custom Clients).

1. Customer Creates via Support Portal

When customers run your invite link, a Support Ticket Portal is installed on their device:

  • Customer right-clicks the support icon in their system tray
  • Selects Create Support Ticket
  • Fills in subject, description, and priority
  • Ticket appears in your dashboard automatically linked to their device

2. You Create Manually in Dashboard

Create tickets on behalf of customers or for internal tracking:

  1. Click Tickets in the sidebar
  2. Click Create Ticket button
  3. Fill in subject, description, priority, and optionally link a contact or device
  4. Click Create

Shortcut: You can also create tickets directly from a Device or Contact by clicking Create Ticket in their details view.

3. Customer Creates via Website Widget

Embed a support widget on your website (see Support Widget section):

  • Customer clicks the floating support button on your website
  • Fills in their email, subject, description, and priority
  • Ticket appears in your dashboard with their email for follow-up

4. Customer Creates via Your Web Portal (No Install)

Every account has a hosted support portal: a branded web page where customers raise tickets and follow their progress from any browser, without installing anything.

  • Find your portal link in the dashboard under Configuration, in the Customer portal link card of the ticket settings. Copy it, customize the address, or turn the portal off entirely.
  • Customers fill in their name, email, subject, and description. The ticket lands in your dashboard with the portal marked as its source.
  • Customers can check progress and reply from the portal: the "Already have a request?" link emails them a secure access link, valid for 60 days, that shows their own requests only.
  • Changing the portal address invalidates previously emailed access links, so treat a rename as a reset.
  • Submitted by: if the person raising the ticket types a name or email that differs from the contact on file for that email address, the ticket detail keeps a Submitted by line with what they typed, so shared mailboxes and coworkers stay identifiable.

Companies

Tickets and contacts group themselves by company automatically, using the domain of the customer's work email (free mail providers are excluded). On the Contacts screen you can rename companies, merge duplicates, and reassign contacts; the ticket list gains a company filter so one client's requests stay together.

Managing Tickets

  • Status: Open, In Progress, Waiting, Resolved, Closed
  • Priority: Low, Medium, High, Urgent
  • Replies: Respond to client messages (they see it in their portal)
  • Internal Notes: Add private notes only your team can see
  • Link Device: Connect to a device for quick remote access
  • Link Contact: Associate with a customer contact
  • Assign: Transfer tickets to team members
  • Tabs: The ticket list separates Open, Resolved, and Closed, with a channel filter showing where each ticket came from (app, portal, widget, email, session, or manual)
  • Export: In Reports, on the Tickets tab, Export CSV downloads tickets only; the Columns button beside it lets you pick exactly which columns the file includes

Customer Notifications

Keep the person who raised a ticket informed automatically. With Customer notifications enabled, they receive:

  • A confirmation email when their ticket is created (from the client, portal or widget), with the ticket number and a reply link
  • An update email whenever you change the ticket status
  • When a ticket is resolved with CSAT surveys enabled, the satisfaction survey is sent instead of a duplicate status email

Turn it on under Help Desk > Settings > Customer notifications (also available on Branding > Email Notifications; it is one setting). It is off by default and turns on automatically the first time you verify a sending domain. Emails use your branding and the customer email language you configure, and replies thread back onto the ticket when email intake is enabled. Sending is capped at 200 status emails per account per day.

Send From Your Own Domain (Pro)

By default, ticket emails to your customers are sent from support@hoptodesk.com with your company name. Pro and Business accounts can instead send from their own address, for example support@mail.yourcompany.com. Setup:

  1. Go to Branding > Email Notifications and find the Send from your own domain card
  2. Enter the address name and domain. Use a dedicated subdomain such as mail.yourcompany.com rather than your main domain, so your primary email reputation is never affected
  3. The card shows the DNS records to add at your domain provider (a verification TXT record, two DKIM CNAME records and a DMARC TXT record), each with a copy button
  4. Add the records at your DNS provider. For CNAME records on Cloudflare, set them to DNS only, not proxied
  5. Click Verify. DNS changes can take a few minutes to propagate; click Verify again if records show as missing at first

Once verified, every ticket email (confirmations, replies, status updates and CSAT surveys) leaves from your address, and Customer notifications switch on automatically if you have never configured them. The domain is re-checked daily: if its DNS records are ever removed, sending falls back to support@hoptodesk.com so no mail is lost, and the card shows a warning until the records are restored. Nothing changes until verification succeeds, so a typo in DNS can never interrupt your ticket mail.

Tip: Filter tickets by status, priority, assignee, or source (Portal, Dashboard, Widget) to quickly find what you need.

Groups

Organize your devices into logical groups for easier management.

How to group devices by customer and limit technicians

Creating Groups

  1. In the sidebar, click Devices to expand its dropdown. Your existing groups are listed underneath
  2. Click + Add Group at the bottom of the dropdown
  3. Enter a group name and click Create

You can also assign individual devices to groups inline from the device row's + Add group link, or use bulk actions to assign many at once.

Use Cases

  • By Client: "Acme Corp", "Smith Family"
  • By Location: "Office", "Remote Workers"
  • By Type: "Servers", "Workstations", "Laptops"

Tip: Use bulk actions to move multiple devices to a group at once.

Session Recording

Sessions can be recorded on either side of a connection. Recordings are saved as standard WebM video files on the machine that made them and are never uploaded to HopToDesk. The dashboard catalogs them so you can find any recorded session, and plays them back when the file is on the computer you are using.

Recording a Session

  • Manually: click the record button in the session toolbar, or press Ctrl+Shift+R
  • Automatically: in the client, open Settings and turn on Automatically record incoming sessions (recorded on the device being controlled) or Automatically record outgoing sessions (recorded on the technician's computer)

The person being controlled sees a recording indicator in the connection window whenever a session is being recorded.

Where Files Are Saved

  • Windows: %USERPROFILE%\Videos\HopToDesk
  • macOS: ~/Movies/HopToDesk
  • Linux: ~/Videos/HopToDesk

Use Open Recordings Folder in the client settings to jump straight there. Under Delete Recordings After, you can have the client remove recordings older than a chosen number of days.

The Recording Library

  1. Every finished recording reports its details to your dashboard automatically: device, direction, technician, duration, file name, and where the file is stored
  2. Open Recordings in the sidebar to search and filter the catalog; the Sessions report marks recorded sessions with a REC badge
  3. Click Connect recordings folder and select your local recordings folder to play any recording stored on that computer with one click

Fleet-Wide Recording

To require recording across a fleet, enable Record incoming sessions automatically on a Deployment, and every device enrolled through it starts with automatic recording on. Custom client builds can also lock the setting so end users cannot turn it off.

Privacy: recording files stay on your own machines. HopToDesk stores only the catalog details listed above, never the video itself.

Trash

When you delete a device, it goes to Trash instead of being permanently removed. This gives you a safety net to recover accidentally deleted devices.

How Trash Works

  • Deleted devices are moved to Trash and kept for 30 days
  • After 30 days, trashed devices are automatically cleaned up
  • The Trash icon in the sidebar shows the count of items currently in Trash

Managing Trash

  • View Trash: Click Trash in the sidebar to see all deleted devices
  • Restore: Click the restore button on a trashed device to move it back to your device list
  • Empty Trash: Click Empty Trash to permanently delete all items at once

Warning: Emptying Trash is permanent and cannot be undone.

Support Widget (Widget Creator)

Add a customizable support widget to your website for client inquiries.

Widget Customization

  • Brand Color: Match your website's color scheme
  • Position: Bottom right or bottom left corner
  • Greeting: Custom welcome message
  • Company Name: Displayed in the widget header

Installation

  1. Configure your widget settings in Widget Creator
  2. Copy the generated code
  3. Paste before the closing </body> tag on your website

Tip: Messages from the widget create support tickets automatically in your dashboard.

Client Builder

Create a professional, white-labeled experience for your clients. The Client Builder screen has three tabs:

  1. Custom Client Generator: build your own white-labeled HopToDesk binaries, or paste your own download URLs
  2. Invite Page: brand the page clients land on when they open an invite link
  3. Email Notifications: brand the emails sent from your account

1. Custom Client Generator

Build a fully white-labeled HopToDesk client (or paste your own self-hosted client URLs). Your app name, icons, company URLs, and branding images are baked into the binary at build time.

For a complete walkthrough (branding fields, plan tiers, build queue behavior, self-hosted URL setup, and troubleshooting), see the dedicated Custom Clients section below.

2. Invite Page

Brand the page clients land on when they open one of your invite links:

  • Company Name and Logo: shown at the top of the install page
  • Primary Color: color picker (hex), used for buttons and accents
  • Live preview on the right shows changes as you edit

3. Email Notifications

Brand the transactional emails your account sends: ticket replies, invite reminders, account notifications. Logo, sender name, and color are picked up from the Invite Page tab; this tab lets you customise the email-specific parts.

Tip: Set up the Custom Client Generator or the Custom Client Download URLs (one is enough) so your invite links download your branded app instead of the default HopToDesk.

Custom Clients

A custom client is a fully white-labeled HopToDesk binary: your app name, icons, company URLs, and branding images baked into the installer at build time. Customers see your brand from the moment they double-click the installer.

How to build your own branded remote support app

You have two options, both reachable from Client Builder:

  1. Generate: let HopToDesk build the binaries for you, server-side
  2. Host your own: if you compile the client yourself, paste per-OS download URLs and we'll use those instead

Either way, every invite link your account generates will deliver the right branded download to your customers automatically.

Path 1: Generate a Custom Build

Plan tiers

  • Trial: Windows builds only (.exe installer, code-signed)
  • Pro / Business: Windows, macOS (.dmg, unsigned, Gatekeeper warning), Linux (.deb, unsigned)

Step-by-step

  1. Open Client Builder in the sidebar
  2. Fill in the Branding column on the left:
    • App Name (required, max 40 characters, letters/numbers/spaces only): appears as the installed app name and window title
    • App Icon (required, square PNG, 1024×1024 recommended): all platform-specific icon files (.ico, .icns, etc.) are generated automatically in your browser, no separate uploads needed
    • Company Name, Company URL, Privacy Policy URL (all optional): shown in the app's About / settings screens
    • Featured Image (optional, PNG, suggested 200×134): replaces the default illustration on the Connect screen
    • Privacy Mode Image (optional, PNG exactly 1920×1080, ≤56,355 bytes, auto-padded to size): shown on the remote screen when privacy mode is engaged during a session
  3. Watch the Preview on the right update live as you type. This approximates what the real client window will look like (your icon top-left, your app name in the title bar, your featured image in the body)
  4. Pick which OSes to build under Platforms. Each one selected adds 5-20 minutes to the queue. Mac and Linux are greyed out on Trial accounts.
  5. Decide whether to be emailed when the build is done (checkbox under the button), then click Generate Custom Build
  6. Status appears in the panel below the form. The page also keeps a Your Custom Builds table further down with a row per build, status (queued, building, ready, failed), build time, and a Download link once ready

After the build

  • Click Download on any ready build to grab the installer
  • To use this build for invite links, scroll to Custom Client Download URLs below and click Use latest build for the matching OS. The field auto-fills with the right URL
  • You can keep generating new builds whenever you change branding. Old builds stay listed until you delete them. The download link for an app name always serves the newest completed build of that name, so a build you have not tested yet is live at that link as soon as it completes. Each build also has its own link that stays on that build: click Copy link to build in the table, or write it as /downloads/custom-builds/<user id>/<build id>/<app name>-install.exe. Hand out that link when a tested build must stay available after you build again
  • The Devices on this client panel above the table shows how many devices run an older build, with an Update devices button and the Keep devices on my newest build switch (Pro and Business). See Updating or Replacing a Custom Client below

Advanced Options

Pro and Business accounts get an Advanced Options button in the Custom Client Generator for locked-down, deployment-ready builds. Trial accounts see it locked.

  • Incoming-only (quick support) mode: the client only receives connections and hides outgoing controls, ideal for unattended support endpoints. Switch Sides and Show my screen still work from such a build, because the technician's own session authorizes the swap.
  • Windows package: choose a standard .exe installer or an .msi for silent, fleet-wide deployment through Group Policy or any MDM. Every MSI carries its own version, so a newer MSI upgrades the previous one in place and the device keeps its settings.
  • Locked settings: pre-set and lock options such as Keyboard & Mouse, Clipboard, File Transfer, Audio, Remote Terminal, Wake On LAN, Switch Sides, and the client language. Locked settings are enforced silently and end users cannot change them. Locking Audio off means a build never transmits sound from the remote device, which keeps technician phone or Teams calls out of sessions. Locking Switch Sides off hides Switch Sides and Show my screen on both ends of a session.
  • Hide the help desk in the client: removes the Submit Ticket entry from the tray menu and the ticket icon from the app, for partners who sell remote access without a help desk.
  • Connection approval: lock how incoming connections are approved so end users cannot change it. Always ask requires someone at the device to accept every session, which overrides unattended access on that machine, so it suits staffed computers rather than servers. Business plan.
  • Close protection: stops end users from quitting the app or turning off incoming connections. Uninstalling still works normally. Business plan.
  • Ask the user to name this device: the first time the client runs, the end user is asked for a company name and a device name, prefilled with the computer name. The combined name becomes the device name in your dashboard, so a mass rollout by emailed link arrives pre-labeled (for example BMW-SAP-SERVER) instead of a list of identical Windows hostnames. Renaming the device in the dashboard later always wins. Business plan.

Advanced Options are baked into the build, so every install from it is configured the same way with nothing for the end user to set up.

Path 2: Host Your Own Client

If you compile the HopToDesk client yourself (forked source, custom build pipeline, internal CDN, etc.) and host the installers somewhere, paste your download URLs into the Custom Client Download URLs card at the bottom of the Custom Client Generator tab. Invite links will fetch from those URLs instead of the default HopToDesk client.

Per-OS URL examples

  • Windows: https://yoursite.com/downloads/YourBrand.exe (.exe or .msi)
  • macOS: https://yoursite.com/downloads/YourBrand.dmg
  • Linux: https://yoursite.com/downloads/YourBrand.AppImage

Leave any field blank and that OS will fall back to the default HopToDesk download. Mix and match freely: for example, generate Windows yourself and host Mac externally.

Requirements for self-hosted URLs

  • Public HTTPS: the URL must be reachable without authentication (your customers' browsers fetch it directly)
  • Stable filename: if you rotate filenames per release, point at a redirect/symlink that always serves the latest
  • Correct content-type recommended (application/x-msdownload, application/x-apple-diskimage, etc.). Not strictly required but helps some browsers

How Invite Links Use Your Custom Client

Once a Custom Client Download URL is set for an OS, invite-link downloads work like this:

  1. Customer opens your invite link on, say, Windows
  2. Branded install page loads (configured under Client Builder → Invite Page)
  3. Customer clicks the download button. The file served is fetched from your custom_client_url_windows, with the filename rewritten to include the invite code (so the same binary can be reused across multiple invites without name collisions)
  4. Customer runs the installer: sees your name, your icon, your URLs throughout
  5. Once installed, the device registers in your dashboard automatically, scoped to the invite

No code or configuration on the customer side: the entire branded experience is delivered from your invite URL.

Updating or Replacing a Custom Client

  • Generated builds: change branding fields and click Generate Custom Build again. When the new build appears in the table, click Use latest build in the Download URLs card. Existing invite links pick up the new file immediately, no need to re-issue invites.
  • Self-hosted: push your new installer to the same URL. Same effect: existing invites serve the new file the next time they're clicked.
  • Devices already running your custom client: the Devices on this client panel on the Builds page counts how many devices run an older build. Pick a build (newest first) and click Update devices to send it to every device that is not on it, or only to devices with one tag. Picking an older build rolls those devices back to it, and a build made for a pilot or one customer is sent only when you pick it. Builds from before this feature can be sent only while they are the newest. With a tag, only devices that carry it get the build, now or when they next come online. A later click with another build, another tag or all devices replaces that choice. Each device downloads the build from your dashboard, checks it, installs it in place and comes back with its ID, password, settings and enrollment intact. It is offline for about half a minute while it installs. Offline devices update when they come back online. Owners and admins on Pro or Business.
  • Keep devices on my newest build: turn on this switch in the same panel and every new build goes to all devices on its own, with no click. It is off by default.
  • Devices the dashboard cannot update: devices running the standard HopToDesk app, or a custom build made before September 2026, report no build id and are listed as not counted. Install the new build on them once, by hand or with your deployment tool. From then on they take updates from the dashboard.
  • Every build is new: a rebuild gets a new build id even when the version number did not change, so the panel counts every device as behind until it takes the new build.
  • Same installer, same command: running the new installer over an existing install updates it in place and keeps settings and enrollment. On Windows the file name must end in install.exe, which the Download button already uses, or run it with --silent-install. Each MSI build carries its own version, so a newer MSI is an upgrade of the previous one in Intune or Group Policy.
  • Standard (unbranded) client: to update an installed HopToDesk client from a download, use the install-named link, for example https://dashboard.hoptodesk.com/downloads/clients/hoptodesk-x64-install.exe (hoptodesk-install.exe for 32-bit, hoptodesk-arm64-install.exe for ARM). A file whose name ends in install.exe installs over the current version and keeps the device ID, password and settings; the plain download would only open a second portable copy next to the installed app.

Troubleshooting

  • "Custom client URL appears unreachable" banner. The dashboard periodically health-checks each saved Download URL. If the URL stops responding (404, 5xx, DNS failure), this banner appears in the Custom Client Generator tab so you know the URL is broken before customers report it. Update the URL and the banner clears.
  • Build stuck in "queued" or "building" for >30 minutes. Click Refresh on the Your Custom Builds table. If still stuck, generate a new build and let support know. The original build may have failed silently.
  • Mac client says "unidentified developer" / Gatekeeper warning. Expected. Generated Mac builds are unsigned. Customers either right-click → Open the first time, or you can sign the .dmg yourself with your own Apple Developer ID before redistributing.
  • Linux .deb fails to install. Make sure your customers are on a Debian/Ubuntu-based distro. The generator only produces .deb. For RPM-based or other distros, use the self-hosted URL path with your own packaging.
  • App Name validation rejects characters. Letters, numbers, and spaces only, max 40 characters. No punctuation, slashes, or emoji. These would break filenames or installer registry keys on at least one platform.

Tip: If you only need light branding (logo + color on the install page) and don't care about the binary itself being white-labeled, just configure Client Builder → Invite Page and skip the Custom Client Generator entirely. Customers will still download the default HopToDesk client, but your install page will be branded.

Custom Network

By default your devices connect through HopToDesk's public signal and TURN servers. If you host your own, you can point your devices at them under Settings, in the Network Settings card (owners and admins only).

Choose HopToDesk Network for the default servers, or Custom Network to use your own. Any field left blank falls back to the HopToDesk default.

Signal Server

Set the Host, Port, and Protocol of your signal server. WSS is the secure (TLS) protocol and WS is the standard one. The web client always connects over the secure host.

TURN Server

Add one or more TURN servers, each with a Host, Port, Protocol (TURN or TURN-TLS), and credentials. Use Add TURN Server for additional relays.

When a device enrolls under your account, the dashboard delivers the full network configuration and the device applies it automatically, with no per-device setup. Switch back to HopToDesk Network at any time.

Every change you save is pushed to all online devices. Custom builds generated after you save the network carry it, so a host uses your servers from its first start, before it enrolls. On Windows the settings are stored once per machine, so the service that answers incoming connections and the signed-in user session both use the same network.

Firewall Mode

Some company networks only allow outbound traffic on ports 80 and 443. Firewall Mode makes a HopToDesk device work on such a network with nothing else opened: the device reaches the other side through the relay's port 443 instead of dialing a session-specific port, so no port range is needed.

Turn it on for one device

  1. On the device behind the strict firewall (the one being accessed), open Settings, then Network.
  2. Turn on Firewall Mode.
  3. Make sure the device that connects to it also runs a current HopToDesk version. Older versions do not understand the mode and cannot connect to a device that has it on.

Roll it out to a fleet

Bake it into a custom build so nobody touches Settings on each machine: open Client Builder, then Advanced Options, and under Hard-locked settings tick Firewall Mode and set it to On. Combine it with Auto-enroll for mass deployment and every installed device links to your dashboard and works over port 443 from its first start. Advanced Options are available on the Pro plan and up; mass deployment on Business.

What the network still needs

Outbound TCP on port 443 (and port 80 where possible) to these hosts:

  • api.hoptodesk.com, signal.hoptodesk.com, signal2.hoptodesk.com
  • turn.hoptodesk.com, turn-eu.hoptodesk.com and turn-sg.hoptodesk.com (relay servers)
  • dashboard.hoptodesk.com for devices linked to a dashboard, or eu.dashboard.hoptodesk.com for accounts in the EU region

Good to know

  • A session to a device in Firewall Mode tries a direct or LAN connection and the port 443 relay at the same time. Behind a strict firewall the direct attempt fails and the relay carries the session; on the same LAN the direct connection wins.
  • A device with the mode off still gets through a strict firewall: when its normal relay connection fails, it falls back to port 443 through the HopToDesk relays for that session. Turning the mode on only skips that wait, so it stays the right choice for a fleet behind such a firewall.
  • The session itself stays encrypted end to end by the app. The relay only forwards encrypted data.
  • The relay traffic on port 443 is not TLS. A firewall that inspects port 443 and insists on TLS still blocks it.
  • The web client does not support Firewall Mode. Use the desktop or mobile app to connect to such a device.
  • Without Firewall Mode, a device also needs outbound TCP to any port, for direct peer-to-peer sessions and for the relay port assigned to each session. Sessions never use UDP; only LAN discovery does, as a broadcast on the local network.

Headless Linux (no monitor attached)

On a Linux machine with no monitor plugged in, HopToDesk may report that no display was found even though the desktop session is running normally. This affects bare metal servers and mini PCs. Virtual machines and cloud instances are usually unaffected, because their virtual graphics adapter already presents a connected screen.

The cause is that the graphics driver marks every video output as disconnected when nothing is attached, so the system creates no screen for HopToDesk to capture. You can confirm this by running DISPLAY=:0 xrandr --listactivemonitors. If it reports Monitors: 0, this is what you are hitting.

Give the machine a screen and HopToDesk works normally. There are two ways to do that.

Option 1: a display emulator plug

Insert an HDMI or DisplayPort dummy plug, sold as an EDID emulator or headless display adapter. The output then reports as connected with no configuration at all. This is the simplest option and needs no changes to the system.

Option 2: create the screen in software

Linux can force an output on and supply it with built in monitor data, using kernel options. First find your output name:

ls /sys/class/drm/

The names there are what the kernel expects, and they can differ from what xrandr shows. An output xrandr calls HDMI-1 may be HDMI-A-1 to the kernel, while VGA-1 is often the same in both. Then add one option to your kernel command line and reboot, substituting your output name and a resolution:

video=VGA-1:1024x768e

The trailing e forces the output on even with nothing plugged into it. This is usually all that is needed, and it has been confirmed on Debian 13 with Intel HD Graphics and the modesetting driver. Your normal graphics driver stays in place, including hardware acceleration.

If the output still does not appear, you can also supply monitor data using one of the sets the kernel already includes, for 1024x768, 1280x1024, 1680x1050 or 1920x1080, by adding a second option alongside the first:

drm_kms_helper.edid_firmware=VGA-1:edid/1024x768.bin

After a reboot, xrandr --listactivemonitors should report one monitor, and HopToDesk will connect as usual. If the output name is wrong the setting is simply ignored, so a mistake here does not stop the machine booting.

You may see the Xorg dummy driver suggested elsewhere for this. It also works, but it replaces your graphics driver and gives up hardware acceleration, so the options above are usually preferable.

Headless Windows (no active display)

On a Windows machine that normally has no monitor attached, typically a server or a virtual machine administered over RDP, connecting with HopToDesk may show No displays even though the machine is running. A common variant: sessions work fine while an RDP window to the machine is open, and fail with that message as soon as it is closed.

The cause is that Windows only keeps a screen alive for a session that is attached to something: a physical monitor, a hypervisor console, or a connected RDP session. When the RDP client disconnects, Windows removes that session's screen, and a session that is logged on but disconnected does not count. With no screen present there is nothing for HopToDesk to capture.

Give the machine a screen and HopToDesk works normally. There are three ways to do that.

Option 1: a display emulator plug

On physical machines, insert an HDMI or DisplayPort dummy plug, sold as an EDID emulator or headless display adapter. The output then reports as connected with no configuration at all, exactly as on Linux above.

Option 2: a virtual display driver

On virtual machines and servers, install a virtual display driver, also called an indirect display driver or virtual monitor driver; free options exist. Windows then always presents a screen, whether or not anything is attached, and HopToDesk captures it like a real one. Set the virtual monitor to a normal resolution such as 1920x1080; very small virtual screens can still be treated as absent.

Option 3: keep a session attached

For occasional use, keep an RDP session connected while you work with HopToDesk; minimizing the RDP window is fine, but disconnecting it removes the screen even though you stay logged on. On virtual machines, keeping the hypervisor console open (for example Hyper-V or vSphere) has the same effect.

For machines you access regularly, the virtual display driver is the set-and-forget choice; the dummy plug is its hardware equivalent for physical machines.

Team Access

Collaborate with team members on support and device management.

Adding Team Members

  1. Go to Settings
  2. Find the Team Access section
  3. Enter the team member's email
  4. Click Invite

Team Collaboration

  • Shared access to all devices
  • Collaborate on support tickets
  • View team member activity
  • Add internal notes visible only to team

Tip: Team members must create their own HopToDesk account before being added.

Technician Identity

Business

Technician Identity puts a verified photo, name, and company on the accept prompt your customer sees when a technician connects. The identity is served by the HopToDesk dashboard over HTTPS, never by the connecting computer, and every photo is reviewed by HopToDesk before it can appear. The person accepting the connection needs no account and no setup.

Setting it up

  1. Open Settings and find the Technician Identity card under Team Access (owners and admins, Business plan).
  2. Upload a photo for each technician. Use a clear photo of the actual person; company logos and stock images are rejected. Add the display name and organization name your customers should see.
  3. Each photo starts as Pending review. Reviews typically complete within 1 business day, and the status updates to Approved or Rejected with a reason.
  4. Turn on "Show technician photos on the connection accept prompt". Approved identities then appear automatically whenever that technician connects.

What your customer sees

The accept prompt shows exactly one of three states. It always opens instantly with the standard prompt and upgrades to the verified identity when the check completes; the identity check never delays or blocks the connection.

HopToDesk
M
Maria
(482 913 674)
Connected 00:12
Dismiss Accept

1. Standard prompt. Shown when the feature is off, no identity was sent, or the check has not completed yet. Identical to today's prompt.

HopToDesk
Maria Fuentes
(482 913 674)
Northwind IT Services ✔ Verified
Connected 00:12
A photo does not guarantee identity. Only accept connections you expect.
Dismiss Accept

2. Verified identity. The photo, name, and company come from the dashboard, never from the connecting computer. A caution line always accompanies the photo.

HopToDesk
M
Maria
(482 913 674)
Connected 00:12
⚠ This connection claims an identity that could not be verified.
Dismiss Accept

3. Unverified claim. Shown when an identity was claimed but the dashboard rejected it, for example a revoked photo or an expired token. No photo or company ever renders in this state.

Review and safety

  • Every photo is reviewed by a person at HopToDesk before it can render anywhere. Brand logos, stock photos, and impersonation attempts are rejected, and repeated abuse can suspend the account.
  • The identity travels as a short-lived, single-connection token. The photo itself is fetched by the customer's computer directly from dashboard.hoptodesk.com over HTTPS.
  • Removing a photo, rejecting it, or turning the feature off stops it from appearing on new connections within minutes.
  • The identity row is informational only. It never changes permissions, security codes, or who can connect.

Technician Identity requires a HopToDesk client version with identity support on the customer's computer. Older clients simply keep showing the standard prompt.

Notifications

Stay informed about device status changes and support requests.

Toast Notifications

In-dashboard notifications appear in the bottom-right corner showing:

  • Device online/offline status changes (shows device name)
  • New support tickets
  • Action confirmations

Sound Notifications

Enable per-device sound alerts:

  1. Go to Devices
  2. Click on a device name to expand details
  3. Toggle Sound Alerts on

Sound is off by default to avoid noise with many devices. The toggle is per-device, so you can enable it only for the machines that matter.

Real-time Updates

The dashboard uses WebSocket connections for instant updates. Check the connection status indicator at the bottom of the sidebar.

Tip: Allow browser notifications for alerts even when the dashboard tab isn't active.

Monitoring & Alerts

Monitoring watches your devices and tells you when something needs attention, so you find out before your customers do.

How to monitor your computers and get alerts

Setting up alerts

Open Settings and find the Alerts card. Choose where alerts go, then turn on the alert types you want.

  • Send alerts to: one or more email addresses, separated by commas. Defaults to your account email.
  • Delivery: email, in-app, or both. In-app alerts appear in the bell menu at the top right.
  • Device offline: alert when a device has been offline longer than the number of minutes you set. Available on every plan.

Health monitoring (Business)

Business accounts can also alert on activity and device health. These checks ride each device's regular check-in, so they add no extra load on your fleet.

  • New remote connection: alert when someone connects to one of your devices.
  • Large file transfer: alert when a transfer is larger than the size you set.
  • Health monitoring: alert when a device's CPU, memory, or disk usage stays above your threshold (default 90%).

Health metrics come from a recent client. Devices on older versions start reporting once they update.

The alert center

The bell at the top right shows a red dot with your unread alert count. Click it to see recent alerts, then click an alert to jump straight to that device. Every alert email also includes an Investigate with AI link that opens the AI agent focused on the device.

Needs attention and one-click diagnosis

Open Fleet, then Monitoring & Alerts. The Needs attention list shows every device with an open alert, and Scan now runs a fresh fleet-wide health scan. Each row has a Diagnose button: one click runs a few read-only checks on the device (system information, disk usage, top processes, recent service log) and asks the AI Assistant for a short answer with the likely cause, the evidence and the next steps. Diagnosis uses the AI Assistant, so it needs the assistant enabled and credit on the account.

Per-device health

Expand any device row to see its latest CPU, memory, and disk usage in the Connection Info column, colored green, amber, or red so problems stand out at a glance.

Reports & Logs

Generate detailed reports on device activity, support tickets, and team performance.

Available Reports

  • Activity Summary: Overview of device connections, session durations, and activity trends
  • Device Status: Historical online/offline patterns for all devices
  • Ticket Analytics: Response times, resolution rates, and ticket volume
  • Team Performance: Team member activity and contribution metrics

Generating Reports

  1. Go to Reports from the sidebar
  2. Select the report type and date range
  3. Click Generate Report
  4. Export as CSV or PDF for sharing

Session Notes and Billable Flag (Business)

With Session Notes on, the technician is asked at the end of every remote session for a short comment (for example "SAP update 123 installed") and whether the session is billable. Billable is checked by default; untick it for warranty or goodwill work.

  • How to enable: Settings, then turn on Session notes. Owner or admin only, Business plan. The setting reaches all your enrolled devices automatically; there is nothing to configure in the client or the Client Builder.
  • Where it shows: the note and the billable flag attach to that session in the device Session Log, next to the technician name and duration.
  • In the export: the per-device session log CSV gains Technician, Duration (min), Note, and Billable columns. A customer can see what each billed hour was for, and a report can show, for example, 5 hours total with 3 hours billable.
  • Mid-session notes: a note typed during the session via Control Actions and Note lands in the same place.

Weekly Billing Workflow (Business)

The Sessions report is built for a recurring billing run: filter a period, check the totals, export, then mark those sessions as exported so nothing is billed twice.

  • Date presets: Today, Yesterday, This week, Last week, This month, Last month, This year, Last year, or a custom range. Weeks start on Monday. Your last preset is remembered.
  • Filters: narrow by device group, or show only sessions not yet exported.
  • Badges and totals: each session shows its REC, NOTE, BILLABLE or NOT BILLABLE, and EXPORTED badges, and the totals line above the list sums total time and billable time for the current filter.
  • Export: download the filtered list as CSV with a comma or semicolon delimiter; the delimiter choice is remembered for spreadsheet locales that expect semicolons.
  • Mark as exported: one click stamps every session in the current filter as exported. Combined with the Unexported only filter, next week's run starts clean.

Tip: Use date range filters to compare performance across different time periods. Export as CSV for further analysis in spreadsheets.

Two-Factor Authentication (2FA)

Protect your account with an additional layer of security using time-based one-time passwords (TOTP).

How to secure your HopToDesk account

Setting Up 2FA

  1. Go to Settings and find the Two-Factor Authentication section
  2. Click Enable Two-Factor Authentication
  3. Scan the QR code with your authenticator app (Google Authenticator, FreeOTP, Authy, etc.)
  4. Enter the 6-digit code from your app to verify setup
  5. Save the recovery codes you are shown
  6. Your account is now protected with 2FA

Compatible Authenticator Apps

  • Google Authenticator - Available for iOS and Android
  • FreeOTP - Open source option for iOS and Android
  • Authy - Supports multi-device sync
  • Microsoft Authenticator - Works with any TOTP-compatible service
  • Any app that supports TOTP (RFC 6238)

Logging In with 2FA

  1. Enter your email and password as usual
  2. When prompted, open your authenticator app
  3. Enter the current 6-digit code
  4. You're logged in!

Disabling 2FA

To disable 2FA, you'll need both your password and a current 2FA code:

  1. Go to Settings > Two-Factor Authentication
  2. Click Disable Two-Factor Authentication
  3. Enter your password and current 2FA code
  4. 2FA will be disabled

Recovery Codes

Enabling 2FA gives you ten single-use recovery codes. Each one works in place of a code from your authenticator app, both when logging in and when disabling 2FA.

  • Store them apart from the device that runs your authenticator app
  • Each code works once, then it is spent
  • Generate a fresh set at any time from Settings > Two-Factor Authentication

Passkeys

A passkey signs you in with the fingerprint reader, face recognition or screen lock already on your device, with no password to type and nothing to phish. A passkey counts as multi-factor by itself, so you are not asked for a separate 2FA code.

  1. Go to Settings and find the Passkeys section
  2. Click Add Passkey and confirm on your device
  3. The passkey is named after the browser and system that created it
  4. On the sign-in page, choose to sign in with a passkey

You can register several passkeys, for example one per computer, and remove any of them from the same screen.

Requiring 2FA Across the Team

Owners and admins can make two-factor authentication mandatory for everyone on the account, from Settings.

  • A member who has not set it up is asked to do so before they can use the dashboard
  • A passkey satisfies the requirement in place of an authenticator app
  • Members who sign in through SSO are exempt, because your identity provider handles their multi-factor

Security Tip: Keep your recovery codes somewhere safe and separate from your authenticator app. They are how you get back in if you lose that device, with no need to contact support.

Single Sign-On (SSO)

Allow your team to log in using your company's identity provider (IdP) instead of separate passwords. SSO uses the industry-standard OIDC (OpenID Connect) protocol.

What is SSO?

Single Sign-On lets employees use their existing corporate credentials (the same login they use for email, Slack, etc.) to access the Dashboard. Benefits include:

  • No password fatigue - Users don't need another password to remember
  • Centralized access control - Disable access instantly when employees leave
  • Automatic provisioning - New employees get access immediately
  • Enterprise compliance - Meet security requirements for corporate tools

Note: SSO login is available on the Pro plan.

Supported Identity Providers

  • Okta - Enterprise identity management
  • Microsoft Azure AD (Entra ID) - Included with Microsoft 365 Business
  • Google Workspace - Included with Google Workspace (paid plans)
  • Other OIDC Providers - Any provider supporting OpenID Connect (Auth0, OneLogin, Keycloak, etc.)

Setting Up SSO (Admin)

  1. Create an OIDC application in your IdP:
    • Application type: Web Application
    • Grant type: Authorization Code
    • Redirect URI: https://YOUR-DASHBOARD-URL/api?action=ssoCallback
  2. Get your credentials from the IdP:
    • Client ID
    • Client Secret
    • Issuer URL (e.g., https://your-company.okta.com)
  3. Configure in HopToDesk Dashboard:
    • Go to Settings → scroll to Single Sign-On (SSO)
    • Select your provider type
    • Enter the Issuer URL, Client ID, and Client Secret
    • Enter allowed email domains (e.g., yourcompany.com)
    • Click Test Connection to verify
    • Click Save SSO Settings

Provider-Specific Setup Guides

Okta

  1. Go to Okta Admin → Applications → Create App Integration
  2. Select OIDC - OpenID Connect, then Web Application
  3. Set the Sign-in redirect URI to your callback URL
  4. Copy the Client ID and Client Secret
  5. Your Issuer URL is: https://YOUR-ORG.okta.com

Microsoft Azure AD (Entra ID)

  1. Go to Azure Portal → Azure Active Directory → App registrations → New registration
  2. Set Redirect URI to your callback URL (Web type)
  3. Go to Certificates & secrets → New client secret
  4. Copy the Application (client) ID and the secret value
  5. Your Issuer URL is: https://login.microsoftonline.com/YOUR-TENANT-ID/v2.0

Google Workspace

  1. Go to Google Cloud Console → APIs & Services → Credentials
  2. Create OAuth 2.0 Client ID (Web application type)
  3. Add your callback URL to Authorized redirect URIs
  4. Copy the Client ID and Client Secret
  5. Your Issuer URL is: https://accounts.google.com

How Users Log In with SSO

  1. Go to the HopToDesk Dashboard login page
  2. Enter your work email address
  3. Click the SSO button (next to the Login button)
  4. You'll be redirected to your company's login page
  5. Sign in with your corporate credentials
  6. You'll be automatically logged into the dashboard

SSO Options (Pro)

  • Auto-provision users - Automatically create dashboard accounts for new SSO users on first login
  • Default role - Set the role (Admin, Member, or Viewer) for auto-provisioned users
  • Allowed domains - Restrict SSO to specific email domains

Note: Users can still log in with email/password if SSO is unavailable. SSO provides an additional login method, not a replacement. If you want to enforce SSO-only access, configure your IdP to require authentication for this application.

Organization Controls

Organization-level controls for granular access, compliance, security policy and integrations. Each one lives in the sidebar group it belongs to rather than in a single catch-all section: access policies, API keys and the credential vault under Settings → Security; custom roles and directory sync under Settings → Team; integrations under Settings → Integrations; compliance and service levels under Reports; customer satisfaction under Help Desk; and multi-tenant customers under Customers.

Getting started: Open Settings → Team, then Organization, for a summary of every feature and its current status, then click a feature row to jump straight to it.

Deployment Management

Track and manage mass device rollouts across your organization. Deployments help you plan, execute, and monitor large-scale HopToDesk installations.

How to create a deployment:

  1. Go to the Deployments tab and click New Deployment
  2. Enter a descriptive name (e.g., "Q1 2026 - Engineering Floor 3")
  3. Select the target device group and (optionally) the expected device count to track progress
  4. Pre-configure the devices (optional): tick Enable unattended access and set a default connection password. Every device that enrolls through this deployment then comes online already reachable, with no per-machine setup, and technicians connect with the password you set. (This replaces the old separate "Deployment Profiles" step. A deployment now carries this configuration directly.)

Zero-touch silent install:

Open the deployment and expand How to Deploy to Devices for ready-to-copy commands. The dashboard generates the exact command for each platform. It downloads the client, installs silently, auto-registers the device to this deployment, and returns an exit code your tool can act on. To update later, run the same command with the new installer file: the install replaces the app in place and the device keeps its settings and enrollment.

  • Windows (GPO, Intune, SCCM, ESET PROTECT, or any RMM): a PowerShell snippet using --silent-install --invite-code <code> --enrollment-token <token> --wait-for-enrollment. Exit codes: 0 enrolled, 2 installed but enrollment unconfirmed, 1 install failed. Runs fine as the SYSTEM account.
  • macOS (Jamf, Kandji, Intune, any MDM): an install script plus a downloadable PPPC profile (.mobileconfig) that pre-authorizes HopToDesk's permissions fleet-wide. Accessibility and Full Disk Access are granted automatically; Screen Recording and Input Monitoring are pre-approved for one-click user enablement (Apple does not allow any MDM to grant those two silently).
  • Linux: a .deb install via Ansible/apt with the same enrollment flags.

Antivirus / endpoint security: if you run ESET, CrowdStrike, SentinelOne, Defender for Endpoint, etc., allow outbound HTTPS to dashboard.hoptodesk.com and ws.dashboard.hoptodesk.com (eu.dashboard.hoptodesk.com for accounts in the EU region), and add process/HIPS exclusions for hoptodesk.exe, PrivacyMode.dll, privacyhelper.exe, and the HopToDesk Service. The deployment screen lists these inline.

Deployment statuses:

  • Active - Deployment is in progress; devices are still registering
  • Paused - Temporarily halted; no new registrations accepted
  • Completed - All target devices have been registered or the deployment was manually marked complete

Regular vs SSO invite:

  • Regular (multi-device) - the default. Devices auto-register with no sign-in. Combine with a default password for a fully unattended, zero-touch rollout.
  • SSO - for passwordless access via SSO Connect. Requires an Organization with SSO Connect enabled (Settings → Team → Organization). This path is not fully silent: each device completes an SSO sign-in once during enrollment, after which technicians connect without a device password. Choose Regular + default password if you need a completely hands-off install.

As devices enroll, the deployment's registered and online counts update live so you can monitor the rollout in real time.

Use case: You're rolling out HopToDesk to 500 machines in a new office. Create one deployment with unattended access and a default password, paste the generated command into your RMM (ESET, Intune, etc.), and watch the devices come online already reachable from your dashboard.

Conditional Access Policies

Access policies define rules that are evaluated before every connection attempt. If a connection does not meet all active policy conditions, it is blocked.

Policy types:

  • IP Whitelist - Only allow connections from specific IP addresses or CIDR ranges (e.g., 192.168.1.0/24). Use for office-only access.
  • Time-Based - Restrict connections to specific hours (e.g., Mon-Fri 8am-6pm). Prevents after-hours unauthorized access.
  • Feature Restriction - Disable specific session features (file transfer, clipboard, USB) for certain groups. Useful for compliance.
  • Device Group - Apply a policy only to devices within a specific group. Lets you have different rules for servers vs. workstations.
  • Approval Required - Require a manager or admin to approve each connection request before it proceeds. Best for sensitive production systems.
  • Geo-Fence - Restrict access by geographic region. Block connections originating from countries where your organization does not operate.

Tip: Policies can be combined for defense-in-depth. For example, combine IP whitelist + time-based + approval required for maximum security on critical infrastructure.

Plan: Conditional Access Policies are available on the Enterprise / MSP plan.

Roles & Permissions (RBAC)

Control exactly what each team member can see and do with fine-grained, role-based access control.

Built-in roles:

  • Owner - Full access to everything, including billing and enterprise settings. Cannot be deleted.
  • Admin - Full access except billing. Can manage team members, devices, and all features.
  • Member - Can view and connect to devices, manage tickets, but cannot change settings or manage team.
  • Viewer - Read-only access. Can view devices and tickets but cannot connect or make changes.

Available permissions (12 total):

Device ViewDevice Connect Device ManageTicket View Ticket ManageTeam Manage SettingsReports GroupsRecordings AdvancedBilling

Use case: Create a "Helpdesk L1" role with only Device View, Device Connect, and Ticket View/Manage permissions. Junior technicians can handle tickets and connect to devices without accessing settings or reports.

Directory Sync (AD/LDAP)

Automatically provision and deprovision dashboard users by syncing with your identity provider. When employees join or leave your organization, their dashboard access is updated automatically.

Supported providers:

  • Active Directory - On-premises AD via LDAP protocol
  • LDAP - Generic LDAP-compatible directories
  • Azure AD (Entra ID) - Microsoft's cloud identity service
  • Okta SCIM - Okta-based provisioning via SCIM protocol

Configuration fields:

  • Server URL - Your LDAP server address (e.g., ldap://dc.company.com:389 or ldaps://dc.company.com:636 for SSL)
  • Base DN - The root of your directory tree to search (e.g., DC=company,DC=com)
  • Bind DN - The service account used to authenticate with the directory (e.g., CN=ServiceAccount,OU=Users,DC=company,DC=com)
  • Bind Password - Password for the service account
  • Sync Interval - How often to sync: every hour, every 6 hours, every 24 hours, or manual only

Tip: Use "Test Connection" to verify your settings before enabling automatic sync. The Sync Status panel shows the last sync time and counts of added/updated/removed users.

SCIM provisioning (recommended):

SCIM is the production-ready provisioning path. Connect Okta, Microsoft Entra ID, or Google Workspace and users are created, updated, and deactivated automatically as your directory changes. Deprovisioning a user in your identity provider immediately revokes their dashboard access and terminates their active sessions, so departed technicians lose access the moment IT offboards them. LDAP/AD polling remains available in simulation mode for evaluation.

Plan: Directory Sync and SCIM provisioning are available on the Enterprise / MSP plan.

Device Policies

Enforce session-level security rules on a per-group basis. Device policies control what features are available during remote sessions for devices in a specific group.

Configurable controls:

  • File Transfer - Allow or block file transfers during sessions
  • Clipboard Sharing - Allow or block copy/paste between local and remote machines
  • Session Recording - Force-enable or disable session recordings
  • 2FA Requirement - Require two-factor authentication for connections to devices in this group
  • Session Timeout - Automatically disconnect sessions after a specified idle time

Use case: Create a "Production Servers" policy with file transfer disabled, recording enabled, and 2FA required. Apply it to your production device group. A separate "Development" policy can be more permissive.

Compliance Readiness Tracker

Self-assess your organization's readiness against major regulatory and industry compliance frameworks. Each framework is broken down into individual controls that can be marked as compliant, partially compliant, or non-compliant. This tool helps you prepare for formal audits by tracking your compliance posture internally.

Note: This is a readiness tracking tool for internal self-assessment. Formal compliance certifications (SOC 2 Type I/II reports, HIPAA attestations, ISO 27001 certificates, PCI DSS ROCs/SAQs) require engagement with a qualified third-party auditor or assessor.

Supported frameworks:

  • SOC 2 - Trust Service Criteria for security, availability, processing integrity, confidentiality, and privacy (37 controls)
  • ISO 27001:2022 - International standard for information security management systems (93 Annex A controls)
  • HIPAA - Health Insurance Portability and Accountability Act security rule safeguards (48 controls)
  • GDPR - General Data Protection Regulation for EU personal data protection (36 articles)
  • PCI DSS v4.0 - Payment Card Industry Data Security Standard (64 requirements)
  • NIST CSF - NIST Cybersecurity Framework: Identify, Protect, Detect, Respond, Recover (98 subcategories)

How to use:

  1. Select a framework from the dropdown filter
  2. Click "Update" on each control to set its status and document evidence
  3. Record notes about evidence, documentation links, or gaps that need attention
  4. Use "Export CSV" to generate a readiness assessment for your compliance team or auditor preparation

The readiness score cards at the top provide a quick overview of your self-assessed compliance posture across all frameworks. Scores are calculated as: (compliant controls + 50% of partial controls) / total applicable controls.

SLA Management

Define service level agreements that set response and resolution time targets for support tickets. The system automatically tracks whether your team meets these targets based on ticket activity.

How SLAs work:

  • Response Target - Maximum time before a team member first responds to a ticket (e.g., 15 min for Critical)
  • Resolution Target - Maximum time to fully resolve the ticket (e.g., 4 hours for Critical)
  • Priority Levels - Define different targets for Critical, High, Medium, and Low priority tickets

Dashboard metrics:

  • SLAs Met - Number of tickets resolved within the target timeframe
  • SLAs Breached - Number of tickets that exceeded the target
  • Compliance Rate - Percentage of tickets meeting SLA targets over the last 30 days

Use case: Set a 15-minute response target and 4-hour resolution target for Critical tickets. If compliance rate drops below 90%, investigate staffing during peak hours.

Plan: SLA Management is available on the Enterprise / MSP plan.

Customer Satisfaction (CSAT) Surveys

Measure how satisfied customers are with your support by automatically sending feedback surveys after tickets are resolved.

Setup:

  1. Toggle the survey switch to ON in the Survey Settings section
  2. Customize the Survey Prompt (the question customers see, e.g., "How would you rate your support experience?")
  3. Customize the Thank You Message shown after they submit their rating
  4. Click Save Settings

Understanding the metrics:

  • Avg Score (1-5) - Mean satisfaction rating across all responses. 4.0+ is generally considered good.
  • Total Responses - Number of customers who completed the survey
  • Response Rate - Percentage of resolved tickets where the customer submitted feedback
  • NPS Score (-100 to +100) - Net Promoter Score calculated from ratings. Scores above 0 are positive; above 50 is excellent.

Plan: CSAT Surveys are available on the Enterprise / MSP plan.

ITSM Integrations

Connect your dashboard to external IT Service Management tools for bi-directional data sync. Tickets, incidents, and notifications flow between systems automatically.

Available integrations:

  • ServiceNow - Sync tickets and incidents with your ServiceNow instance. Requires an API key from your ServiceNow admin.
  • Jira Service Management - Create and track Jira issues from dashboard tickets. Uses Jira API tokens for authentication.
  • Zendesk - Link dashboard tickets to Zendesk support tickets. Bi-directional status updates.
  • Freshdesk - Bi-directional ticket sync with Freshdesk helpdesk. Keeps both systems in sync.
  • Slack - Send real-time alerts (new tickets, SLA breaches, device events) to Slack channels via incoming webhooks.
  • Microsoft Teams - Post notifications and alerts to Teams channels. Uses Teams webhook connectors.

How to connect:

  1. Click Configure on the integration card
  2. Enter your API key, token, or webhook URL from the external service
  3. Save the configuration - the status will change to "Connected"
  4. Data sync begins automatically based on the integration type

Plan: ITSM Integrations are available on the Enterprise / MSP plan.

Multitenancy

Manage multiple isolated organizations (tenants) under a single parent console. Each tenant has its own devices, users, settings, and data that is completely separate from other tenants.

Creating a tenant:

  1. Click New Tenant and enter the organization name
  2. Assign a tenant admin (email address) who will manage that tenant
  3. The tenant admin receives an invitation and can begin adding devices and users

What gets isolated per tenant:

  • Devices and device groups
  • Team members and roles
  • Tickets and session history
  • Settings and branding
  • All advanced features (policies, SLAs, compliance data, etc.)

Ideal for: MSPs managing multiple client organizations, enterprises with regional offices or subsidiaries, and holding companies needing separate environments per business unit.

White-label per tenant:

  • Branding: each tenant can carry its own company name, logo, colors, and support email (Tenant detail, Branding tab). Blank fields inherit your account branding. Tenant branding is applied to ticket and invite emails for that tenant.
  • Custom builds: assign a branded client build to a tenant. With auto-enroll, every device that installs it joins that tenant automatically, so you can hand each client one installer.
  • Contacts: contacts can be shared account-wide or assigned to a tenant; tenant-scoped technicians see shared contacts plus their own tenant's.
  • Usage reports: the Usage Report card in the Multitenancy tab rolls up devices, sessions, session time, file transfers, exec commands, and tickets per tenant, with a CSV export for client rebilling. Above the table it shows the account-wide totals: technician seats in use, devices, the pooled device allowance (100 per seat) and any overage. Pick a month, a preset (This week, Last week, This month, Last month), or a custom date range. With Session Notes enabled the report also splits billable time from total session time and counts session notes per tenant, and each session is stamped with its tenant at session time, so devices moved later do not rewrite past reports.

Plan: Multitenancy is available on the Enterprise / MSP plan.

Unattended Easy Access

Connect to your managed devices without typing a stored password. When Easy Access is enabled for a device, the dashboard authorizes each connection with a single-use, short-lived token instead of a standing secret, so there is no permanent password baked into the device.

How to set up unattended access in HopToDesk
  1. Open the device's settings in the dashboard and enable Easy Access
  2. The device confirms the setting on its next check-in
  3. Connect from the dashboard as usual; authorization happens automatically and every connect is audit-logged

Plan: Easy Access is available on the Business plan and above. On the Enterprise / MSP plan it can additionally be gated by conditional-access policies and connection approvals.

Vendor Access Requests

Let a vendor ask for access when they need it and approve with one click, instead of creating links by hand. Open the contact in Contacts, turn on Vendor access, tick the devices this contact may request (only devices with Easy Access enabled are offered), and share the personal request link.

  1. The vendor opens their request link, picks a device and sends the request
  2. Owners and admins get an email and a live dialog in the dashboard: Allow for 1 hour up to 7 days, Deny, or Later
  3. Allow creates an Access Link for that device and emails it to the vendor, who connects from the browser
  • A request expires after 30 minutes if nobody answers
  • Pending requests also appear under Vendor requests in the Contacts header
  • New link replaces the contact's request link; the old one stops working
  • Every request, approval and denial is recorded in the audit trail

Plan: Business plan and above, owners and admins.

Guest Password (desktop client)

For a helper who connects with the HopToDesk app rather than through a link, the client can hold a second password. In the client, open Settings, then Security, then Guest Access, and set the guest password and a time to answer (30 seconds up to 10 minutes). Someone connecting with the guest password sees "Please wait for the remote side to accept" while the device shows a countdown on its connection prompt. The person at the device can accept or dismiss. If nobody answers before the time runs out, the guest is turned away. To let a helper in when nobody is at the device, for example a vendor who works on a server after hours, tick "Let the guest in if nobody answers in time" in the same dialog. The guest then gets in when the time runs out, unless someone dismisses the request first. Older versions of the app have no checkbox and always let the guest in, and a guest password set in an older version keeps doing so after an update until you clear the checkbox. Your permanent password keeps working as before, Account Access Only still refuses guests, and the guest password is never baked into a custom build.

Credential Vault

Store privileged device credentials in an encrypted vault with checkout tracking. Technicians request a credential when they need it, every checkout is recorded in the audit trail, and approval-gated connect can require a manager sign-off before a session to a sensitive device starts.

  • Encrypted at rest; values are never shown in device lists
  • Checkout history shows who accessed which credential and when
  • Pairs with approval-required access policies for privileged device groups

Plan: The credential vault and approval-gated connections are available on the Enterprise / MSP plan.

Compliance Pack (Audit Retention, SIEM, Reports)

Operational compliance tooling for audits and security reviews. This is separate from the Compliance Readiness Tracker, which is a self-assessment checklist.

  • Audit retention: extended, configurable retention for admin activity and session logs (30 days on Free/Pro, 90 days on Business, custom on Enterprise / MSP)
  • SIEM streaming: stream admin activity and session events to your SIEM or any webhook endpoint in near real time
  • Compliance reports: generate periodic reports of account activity, access changes, and session history for auditors

Plan: Custom retention, SIEM streaming, and report generation are available on the Enterprise / MSP plan.

Migrating from TeamViewer, AnyDesk, Splashtop, ScreenConnect, or Zoho Assist

Import your exported device list and roll your fleet over to HopToDesk without tracking spreadsheets. Found in the Deployments tab.

How to switch from TeamViewer or AnyDesk to HopToDesk
  1. Export your device list as CSV from your current tool: the TeamViewer Management Console, the AnyDesk address book, the Splashtop Business console (Computers, then Export), ConnectWise ScreenConnect (the Access session list report export; the machine name column is used as the device name), or Zoho Assist (Unattended Access, then Manage Devices, then Export). Include the device name and group columns where available; any other CSV with a device name column also works
  2. Upload it under Deployment → Import devices; the format is detected automatically
  3. Each imported group becomes a Deployment with its own enroll link; share the link or push the installer with your existing tools
  4. Imported machines are checked off automatically as devices with matching hostnames enroll, so you always know what is left to move

Plan: Migration import is available on the Business plan and above.

IP Allowlist

Restrict dashboard sign-ins to approved networks. Add IP addresses or CIDR ranges at the account level, or per team member, and sign-ins from anywhere else are rejected.

Configured under Settings. Security basics like the IP allowlist are included on every plan; on the Enterprise / MSP plan, IP restrictions are also available as a conditional-access policy condition on device connections.

API Keys

Generate API keys for programmatic access to your dashboard data via the REST API. Use API keys for automation, custom reporting, or integrating with your own internal tools.

API keys are for reading data on your own schedule, and are part of the Business plan. Full parameters and response fields for every action are in the API endpoint reference below. If you want HopToDesk to notify your systems the moment something happens, see Webhooks, which are included on every plan.

How to use:

  1. Click Generate API Key and enter a descriptive name
  2. Select permission scopes to control which data the key can access
  3. Copy the generated key immediately - it is only shown once
  4. Store the key as an environment variable: export HOPTODESK_API_KEY=hdpk_...
  5. Use the key as a Bearer token: Authorization: Bearer hdpk_...

Example request:

curl -H "Authorization: Bearer hdpk_..." "https://your-domain/api?action=getDevices"

Ticket reporting and export:

getTickets and exportTickets accept optional filters (status, priority, assigned_to, tag, archived, created_from, created_to, updated_since) plus limit and offset for pagination. exportTickets adds custom field values, first response times, reply counts, and tags to each row, and returns CSV when format=csv. getAgentStats returns per-agent performance metrics and getTicketTimeSeries returns daily created and resolved counts.

curl -H "Authorization: Bearer hdpk_..." "https://your-domain/api?action=exportTickets&status=resolved&created_from=2026-01-01&format=csv"

Available endpoints by scope:

API keys provide read-only access. Each key can only access endpoints matching its assigned scopes.

  • devices - getDevices, getDeviceStatuses, getDeviceDetails, getGroups
  • tickets - getTickets, getTicketStats, exportTickets, getAgentStats, getTicketTimeSeries
  • sessions - getActivityLogs, exportActivityLogs, getUnattendedLogs, getFileTransferLogs
  • contacts - getContacts, searchContacts
  • invites - getInvites
  • reports - getReportStats, getUsageAnalytics, getSecurityReport

Key management:

  • Track usage with the Requests (30d) counter per key
  • Last Used shows the most recent API call for each key
  • Revoke compromised keys immediately - revocation takes effect instantly
  • Create separate keys for different integrations or environments

Note: These organization controls are available on the Business plan, except multitenancy, conditional access policies, ITSM integrations, and directory sync with SCIM, which are on the Enterprise / MSP plan. All features are accessible from the sidebar group each one belongs to, listed at the top of this section. Hover over the info icons on each tab for quick explanations.

API endpoint reference

Every call is the same shape. One URL, one action name, your key as a Bearer token. Parameters go in the query string on a GET, or as form fields on a POST.

curl -H "Authorization: Bearer hdpk_..." "https://dashboard.hoptodesk.com/api?action=getDevices&status=online&per_page=50"

Accounts in the EU region use https://eu.dashboard.hoptodesk.com/api instead. An API key only works in the region of the dashboard that issued it.

Responses:

A success returns HTTP 200 and a JSON object holding the fields listed below. A failure returns a non-200 status and always the same shape, so you can handle every error in one place:

{"success": false, "error": "Permission denied", "message": "Permission denied", "code": "plan_required"}

401 means the key is missing, revoked or expired. 403 means the key is valid but its scopes do not cover that action, or the action needs a higher plan. The code field is only present on some errors.

Endpoints:

All parameters are optional unless marked required. A key can only call actions matching its scopes. Dates are YYYY-MM-DD, and days is a lookback window in whole days.

ScopeActionParametersReturns
devicesgetDevicessearch, group_name, status, sort_by, sort_order, page, per_pagedevices, total, page, per_page, total_pages, plan, device_limit, device_count
devicesgetDeviceStatusesnonedevices (device_id, status, last_seen only)
devicesgetDeviceDetailsdevice_id (required)device
devicesgetDeviceHistorydevice_id (required)history
devicesgetGroupsnonegroups
ticketsgetTicketsstatus, priority, assigned_to, tag, channel, company_id, archived, created_from, created_to, updated_since, limit (max 1000), offsettickets, total, unread_count, limit, offset
ticketsexportTicketssame filters as getTickets, plus format=csv, limit max 10000tickets, total, limit, offset, custom_field_keys
ticketsgetTicketStatsdaysavg_first_response_seconds, avg_resolution_seconds and their formatted forms
ticketsgetAgentStatsdaysdays, agents
ticketsgetTicketTimeSeriesdaysdays, series
sessionsgetActivityLogsuser_id, action_type, start_date, end_datelogs, team_members
sessionsexportActivityLogsuser_id, action_type, start_date, end_date, limit (max 5000), cursorlogs, count, next_cursor
sessionsgetUnattendedLogsdevice_id, start_date, end_date, limitlogs, devices
sessionsgetFileSessionLogsdevice_id, start_date, end_datelogs
sessionsgetFileTransferLogsdevice_id, transfer_type, start_date, end_datelogs
contactsgetContactsnonecontacts
contactsgetContactcontact_id (required)contact, devices, tickets, invites
contactssearchContactsquery (required)contacts, query
invitesgetInvitesnoneinvites
reportsgetReportStatsdaysdays, sessions, devices, tickets, file_transfers
reportsgetSecurityReportdaysdays, stats, failed_logins, login_history, rate_limited
reportsgetUsageAnalyticsdays, tz_offsetdays, daily_usage, hourly_usage, day_of_week, top_devices
reportsgetComplianceReportstart_date, end_date, report_typereport

Paging:

getDevices pages with page and per_page and tells you total_pages. The ticket actions page with limit and offset against total. exportActivityLogs is cursor based: pass the next_cursor it returns until it comes back empty.

The Enterprise / MSP plan adds a read-only enterprise scope over deployments, roles, policies, compliance, CSAT and tenants. Ask us if you need those and we will send the list.

Webhooks

Where an API key lets you pull data on your schedule, a webhook pushes it to you the moment something happens. HopToDesk sends a JSON POST to a URL you choose, so you can forward events into your own systems: a PSA or ITSM queue, a chat channel, an email or messaging API, or an automation platform such as n8n, Make or Zapier.

Plan: Webhooks are included on every plan. Alert events depend on device health alerts, which are on the Business plan.

Setting one up:

  1. Open Settings and find the Integrations panel. Owners and admins can edit it
  2. Paste your endpoint into Webhook URL, then tick the events you want
  3. Use Test webhook to send a sample payload before you rely on it
  4. Recent attempts, with response codes and errors, are listed under the delivery log

Events:

  • ticket.created - a new ticket arrives, from any source. Carries ticket_id, ticket_number, title, priority, status, customer_name, customer_email, device_name, source
  • ticket.customer_reply - a customer replies. Carries ticket_id, ticket_number, title, customer_name, message_preview, and reopened
  • ticket.status_changed - an agent moves a ticket. Carries ticket_id, title, previous_status, status, changed_by
  • ticket.sla_breached - a ticket passes its SLA due time. Carries ticket_id, title, priority, status, sla_due_at, breached_at
  • alert.fired - a device health alert opens. Carries alert_id, kind, device_id, title, severity, value, threshold, fired_at
  • alert.resolved - that alert clears. Same fields, with resolved_at
  • device.registered - a device enrolls on your account for the first time. Carries device_id, device_name, os, ip_address, registered_at
  • device.online - a device that was offline comes back. Carries device_id, device_name, os, ip_address, last_seen
  • device.offline - a device stops responding. Carries device_id, device_name, os, last_seen

Ticket status and SLA events share one checkbox, so enabling ticket status changes also enables SLA breaches.

A device has to be gone for 15 seconds before it counts as offline, so a brief network blip does not page you. A device enrolling for the first time sends device.registered rather than device.online.

Payload shape:

{"event": "ticket.created", "timestamp": 1756400000, "dashboard_user_id": "u_...", "data": { "ticket_id": 1234, "title": "Printer offline", "priority": "high" }}

The envelope is always the same four fields. Only data changes per event, so switch on event and read the fields listed above.

Request headers:

  • Content-Type: application/json
  • User-Agent: HopToDesk-Webhook/1.0
  • X-Webhook-Event - the event name, so you can route without parsing the body

Good to know:

  • Treat the URL as a secret. Anyone who knows it can post to your endpoint, so use a long unguessable path and check the payload before acting on it
  • Each event is delivered once. There is no automatic retry, so if your endpoint is down that event is missed. The delivery log records what happened
  • Your endpoint has 10 seconds to respond. Return 200 straight away and do slow work afterwards
  • Return a 2xx status. Anything else is recorded as a failed delivery

Slack and Discord:

The Slack Webhook URL field is separate. Paste an incoming webhook URL from Slack and the same events arrive as readable chat messages instead of raw JSON. You can use either field or both.

Discord needs nothing special: paste a Discord webhook URL into the ordinary Webhook URL field and the events are sent in the format Discord expects, as chat messages rather than JSON.

Billing & Subscription

Manage your plan, monitor usage, and view billing history from the Billing page.

Available Plans

  • Trial: Free, no credit card required. 3 devices, ticketing & CRM, basic reports.
  • Pro (from $15/mo): 120 to 350 devices, unlimited users, branding, SSO login, basic reports.
  • Business (from $49/mo): 500 to 2,000 devices, unlimited team members, unattended Easy Access, time-limited shareable access links, verified technician identity, zero-touch enrollment, TeamViewer/AnyDesk/Zoho Assist migration import, deployments, device policies, SSO Connect, advanced reports, SLA and CSAT management, and organization controls such as compliance tracking and custom roles.
  • Enterprise / MSP: Custom plan for larger fleets, scaling to unlimited devices. Adds multi-tenant isolation with per-tenant white-label branding and usage reports, conditional access policies, approval-gated sessions and the credential vault, audit retention with SIEM streaming and compliance reports, ITSM integrations, and directory sync with SCIM. Contact us for pricing.

Usage Tracking

The Billing page shows your current usage for:

  • Devices: How many devices you've added vs. your plan limit
  • Team Members: Active team members vs. your plan limit

Scaling beyond Business

Need more than 2,000 devices? Our Enterprise / MSP plan scales to unlimited devices, with custom pricing for larger fleets. Contact us to set it up.

Managing Your Subscription

  • Upgrade: Click the upgrade button on a higher plan to switch immediately
  • Cancel: Cancel your subscription from the Billing page. You'll retain access until the end of your billing period.
  • Resume: If you cancelled, you can resume your subscription before it expires
  • Payment Method: Update your card or view your payment portal via the links on the Billing page
  • Billing History: View past charges and payment events at the bottom of the page

Tip: You can change plans at any time. Upgrades take effect immediately, and you'll be prorated for the remaining billing period.

AI Assistant & MCP

AI agents like Claude can connect to your HopToDesk devices using the Model Context Protocol (MCP). This allows AI agents to take screenshots, move the mouse, click, type text, and interact with GUI environments, capabilities that SSH cannot provide. Use cases include automated QA testing, visual monitoring, and hands-free desktop workflows.

In the dashboard itself, the built-in AI Assistant opens from the AI Assistant button in the top bar on every screen, and from a device's detail view or a ticket with that context preloaded. Ask it for recurring work and it drafts a scheduled runbook or an auto-approve rule as a proposal: owners and admins review those under Automation in the Runbooks and Rules tabs, and nothing the AI proposes runs until a person approves it.

How to use the HopToDesk AI Assistant

AI Fix Runs on Tickets

When a ticket has a linked device, an Ask AI to fix button appears on it. Press it and the AI Assistant works the ticket for you: it reads the request, diagnoses the device over the secure command channel (system info, processes, disk, logs), applies low-risk fixes, and verifies the result.

  • You watch it work: every operation the AI runs appears on the ticket as an internal note the moment it happens, and the Automation screen's History tab keeps a permanent command record.
  • Risky operations never run on their own. They appear as Approve / Reject prompts on the ticket and wait for an owner or admin.
  • Every run ends with a verdict (fixed, needs approval, needs a human, or device unreachable) and a drafted customer reply that you review and send; the AI never emails your customer directly.
  • The feature is off by default. An owner or admin enables the AI Assistant, accepts its terms, and turns on "AI may act on devices from tickets" in the AI Assistant panel. Runs are billed from the AI wallet, about $0.25 each, shown before you confirm.

What is MCP?

The Model Context Protocol (MCP) is a standard for AI agents to interact with external tools. HopToDesk implements an MCP server that exposes desktop control tools over WebSocket. Your AI agent sends JSON-RPC 2.0 requests, and HopToDesk executes them on the target device.

Two connection modes are supported:

  • Local: Agent and HopToDesk on the same machine: direct localhost WebSocket
  • Remote: Agent connects through the dashboard relay to reach any enrolled device

Setup: Local Agent (Same Machine)

Use this when the AI agent runs on the same computer as HopToDesk. No dashboard enrollment or API key needed.

  1. Download and install HopToDesk from hoptodesk.com
  2. Run HopToDesk: the MCP server starts automatically and listens on ws://127.0.0.1:9333
  3. Add to your AI agent's MCP config (example for Claude Code):
    {
      "mcpServers": {
        "hoptodesk": {
          "url": "ws://127.0.0.1:9333"
        }
      }
    }
  4. Verify the connection: ask your AI agent to take a screenshot or list windows

Setup: Remote Agent (Via Dashboard)

Use this when the AI agent needs to reach a device on a different machine. Commands are relayed securely through the HopToDesk dashboard.

  1. Install HopToDesk on the target device(s) and enroll them using an invite link from the Devices screen
  2. Create an MCP API key from Settings, MCP API access in your dashboard
  3. Connect your AI agent to the MCP endpoint. One command for Claude Code:
    claude mcp add --transport http hoptodesk https://dashboard.hoptodesk.com/mcp \
      --header "Authorization: Bearer YOUR_API_KEY"
    Or the equivalent JSON config for any MCP client that supports Streamable HTTP:
    {
      "mcpServers": {
        "hoptodesk": {
          "type": "http",
          "url": "https://dashboard.hoptodesk.com/mcp",
          "headers": { "Authorization": "Bearer YOUR_API_KEY" }
        }
      }
    }
    Accounts in the EU region use https://eu.dashboard.hoptodesk.com/mcp in both places.
  4. Let the agent discover your fleet: fleet-level tools (device and tag listing, fleet commands and their history) are answered by the dashboard. All other tools run on a specific device via its device_id argument. The full tool catalog is shown in your dashboard under Settings, MCP API access
  5. Fleet operations follow your approval policy: fleet commands respect the same approval and auto-approve rules as the Fleet Management screen, so commands can be held for a human to approve in the dashboard

Security

  • Local connections are restricted to 127.0.0.1 only, no external access
  • Remote connections require a valid API key with the mcp scope
  • API keys can be revoked at any time from Settings, under MCP API access
  • All remote traffic is encrypted over WSS (TLS) through Cloudflare's network
  • Agent sessions are isolated: one API key cannot access another user's devices
  • MCP does not affect human users: human remote support sessions use a completely separate connection path (signal + TURN servers)

Troubleshooting

  • Cannot connect locally: Make sure HopToDesk is running. The MCP server starts automatically on port 9333. Check that nothing else is using that port.
  • Cannot connect remotely: Verify the API key has the mcp scope and has not expired or been revoked. Ensure the target device is online (green dot in the Devices tab).
  • Commands not reaching device: The device must be enrolled in your dashboard account and showing as online. Check the device_id is correct.
  • Screenshot returns empty: On some headless Linux servers, a display server (X11/Wayland) must be running for screenshots to work.
  • Second monitor: the screenshot tool captures the first display unless you pass a display index (0 is the first, 1 the second). Crop coordinates are relative to that display.

Tip: You can manage MCP API keys from Settings, MCP API access in your dashboard: setup snippets, key management, and the list of available tools.

Fleet Management

NEW

Manage one to unlimited devices from the dashboard. Issue a command once, let it target the right machines, and track progress device-by-device. Fleet Management is built on four composable building blocks: device tags, auto-approve rules, fan-out dispatch, and scheduled runbooks.

How to run a command on many computers at once

Remote command execution is off until you turn it on under Automation in the Remote Exec tab: one account switch, an hourly rate limit, and per-device enablement with enable or disable all. Device tags are managed at the bottom of the Devices screen.

Prerequisites

  • Click Enable AI Assistant in the AI Assistant panel and accept terms. This enables the AI only; to run commands, also turn on remote execution in Automation, Remote Exec.
  • Devices must be running the HopToDesk client with the MCP server active (default on recent builds)
  • Owner role required to manage global config and auto-approve rules; owner or admin for tags, fan-out, and runbooks

1. Device Tags

Tags are flat labels you attach to devices. A device can have many tags. Use them to group devices by role, location, OS, customer, or any dimension that matters for operations.

Setup

  1. Open Devices and select a device.
  2. In the Tags field, type a tag name and press Enter. Tag names are normalized to lowercase, with only a-z, 0-9, -, _, and : allowed (max 64 chars).
  3. Repeat for each device. A device can hold up to 32 tags.

Naming conventions that work well

  • By role: web, db, workstation, kiosk
  • By environment: prod, staging, dev
  • By location: office-nyc, office-london, home
  • By OS: win, mac, linux
  • By customer: client:acme, client:contoso

Tip: a device can belong to all of these at once. A server might be tagged linux, prod, web, office-nyc, client:acme, then any of those tags can target it.

2. Auto-Approve Rules

By default, destructive commands (reboot, kill process, clear temp files) need human approval before they run. Auto-approve rules let owners pre-authorize specific commands for specific people on specific devices, so routine work doesn't stall in the queue.

How a rule matches

A rule has three filters. All three are ANDed together. An empty filter means "match anything."

  • Role: owner, admin, member, viewer, or blank for any role
  • Operation: exact name (restart_hoptodesk), category glob (diagnostics:*), or * for any op
  • Tag: the device must have this tag (blank matches any device)

Rules are evaluated in priority order (lowest number first). The first match wins and its action (approve or deny) is applied. If nothing matches, the default approval flow runs.

Setup

  1. Open Automation, then the Rules tab (owner only).
  2. Click New Rule. Give it a descriptive name like "Admins auto-approve diagnostics on servers".
  3. Pick role (or leave blank), operation pattern, and tag. Set action to approve or deny.
  4. Set priority: 10-50 for deny rules that must win, 100+ for allow rules. Lower fires first.
  5. Enable the rule and save. It applies to all new commands immediately.

Recommended baseline

Priority 10: DENY "reboot_device" on tag "prod"  (any role)
Priority 20: DENY "kill_process" on tag "prod"    (role=member)
Priority 100: APPROVE "diagnostics:*" on any tag (role=owner)
Priority 110: APPROVE "diagnostics:*" on any tag (role=admin)
Priority 120: APPROVE "diagnostics:*" on tag "lab" (role=member)

This gives owners/admins frictionless diagnostics everywhere, lets the help desk run diagnostics on lab machines, and hard-blocks accidental reboots of production boxes.

3. Fan-Out: One Command, Many Devices

Fan-out takes an operation and a target (tags, device list, or everything) and runs it on every matched device in parallel. You get back a single job_id with aggregated progress, plus a per-device breakdown so you can see exactly what happened where. Update devices on the Builds page is a fan-out too: it shows up in the job history as update_client, but it is started only from that page, so it is not in the operation list here.

Target kinds

  • tags: union of all devices that have ANY of the listed tags
  • devices: explicit list of device IDs
  • all: every exec-enabled device on the account

Only devices that are exec-enabled and not deleted are included. A single fan-out can cover your whole fleet, up to 500 devices per job (Enterprise / MSP accounts: 1,000 per job). Narrow the target with tags if you hit the cap.

How it flows

  1. You submit the fan-out. The backend resolves the target to a device list.
  2. For each device: check auto-approve rules, create a remote_exec_log row, dispatch via the device's MCP channel.
  3. Auto-approved commands start immediately; commands that need approval land in the approval queue and stay paused until an admin clicks Approve.
  4. As each device responds, the per-device row is marked completed or failed, and the job's aggregate counters update.
  5. When all devices finish (or time out after 5 min), the job is marked completed / partial / failed and you get a fanout:completed event.

Tracking a job

  • Real-time progress arrives over your open dashboard WebSocket as fanout:progress events.
  • Final status (completed / partial / failed / cancelled) fires once as fanout:completed.
  • Full history is in AI Assistant → Fan-Out. Click any job to see the per-device status table.

Cancel a running job

Admins can cancel any in-flight fan-out. Pending commands in the approval queue are rejected immediately; commands already running on a device finish naturally (you can't un-send a command that's mid-flight).

4. Scheduled Runbooks

A runbook is a saved fan-out that re-runs on a schedule. Perfect for nightly hygiene, weekly patches, or hourly health checks. The scheduler ticks every 5 minutes server-side and dispatches any runbook whose next-run time has passed.

Setup

  1. Open Automation, then Runbooks and New runbook.
  2. Pick the operation (e.g. disk_usage, clear_temp_files, run_update_check).
  3. Pick the target: tags (recommended), explicit device list, or all.
  4. Pick the cadence:
    • Sub-daily: interval in minutes (min 5). Runs every N minutes from creation.
    • Daily or multi-day: set interval to 1440 (daily), 4320 (every 3 days), etc., plus anchor hour/minute in UTC. Runs at the specified wall-clock time.
  5. Save. The first run is scheduled based on the cadence; subsequent runs roll forward automatically.

Runbook behavior

  • Runbooks bypass approval: the act of saving an enabled runbook is the approval. Use them for trusted, pre-vetted operations only.
  • Each run creates a normal fan-out job tagged with source scheduler:<runbook_id>, so results sit alongside manual fan-outs in history.
  • Disable a runbook any time by toggling Enabled off. The row stays; its schedule just pauses.
  • Use Run Now to trigger an ad-hoc run without waiting for the next tick, handy for testing.

End-to-End Setup Example

Here's the full path from a freshly-enrolled account to a nightly cleanup job running across 50 workstations:

  1. Enable the AI Assistant. Open the AI Assistant panel, accept terms, click Enable AI Assistant. To run commands, also turn on remote execution in Automation, Remote Exec (default rate limit is 30 commands/hour) and enable it on your devices.
  2. Tag the devices. Bulk-tag your 50 workstations with workstation and your office tag (e.g. office-hq).
  3. Write an auto-approve rule. Owner auto-approve maintenance:* on tag workstation, priority 100. This lets the runbook proceed unattended.
  4. Create the runbook. Operation clear_temp_files, target tag workstation, interval 1440, hour 3 (3am UTC).
  5. Verify. Click Run Now. Watch the progress stream. Drill into the job in history to confirm every device completed.
  6. Leave it running. Tomorrow at 03:00 UTC the cron ticks, the runbook fires, 50 devices clean up temp files in parallel. You get a single job row in history to scan each morning.

Use Cases

Fleet-wide health snapshot

Problem: You manage 300 devices for 12 clients. You want a morning report on disk usage.

Solution: Daily runbook, operation disk_usage, target all, 07:00 UTC. Read the per-device results over coffee.

Incident response: restart a stuck service at one site

Problem: The NYC office reports every HopToDesk agent stopped responding after a network blip.

Solution: Fan-out restart_hoptodesk at tag office-nyc. With an auto-approve rule for admins on that tag, 40 devices restart in parallel without individual clicks.

Tiered help desk permissions

Problem: Tier-1 techs should run diagnostics but never reboot or kill processes. Tier-2 (admins) can do more.

Solution: Two rules: approve diagnostics:* for role member; deny everything else by omission. Admins fall through to the default approval flow for destructive ops, which an owner can approve from the queue.

Compliance: quarterly software inventory

Problem: You need an installed-software list across the fleet for audit.

Solution: Ad-hoc fan-out of installed_software at target all. Export the fan-out job's per-device output as your audit artifact.

Investigate a slow device with the AI Assistant

Problem: A user complains their laptop is "unusably slow."

Solution: In the AI Assistant panel, pick the device and ask "investigate high resource usage." Claude calls get_system_info, list_processes, disk_usage in sequence and summarises the culprit. No fan-out needed for a single-device investigation.

Weekly DNS cache flush on flaky workstations

Problem: One tagged group of workstations has chronic DNS issues that a flush fixes.

Solution: Weekly runbook, operation flush_dns, target tag dns-flaky, Mondays 04:00 UTC. Set an auto-approve rule that allows flush_dns on that tag for owners.

Troubleshooting

  • "Remote execution is off for this account." Turn it on in Automation, Remote Exec. Owner only.
  • "Remote execution is not enabled on this device." The device registered before you enabled Agents. Click Disable then Enable Agents again to opt every device back in.
  • "No exec-enabled devices matched the target." Either the tag has no devices, or none of the matched devices are exec-enabled. Check Devices filtered by that tag.
  • Command stuck in "running" for more than 5 min: The device didn't respond. The watchdog flips it to timeout automatically on the next 5-min cron tick.
  • Fan-out job hangs at partial progress: Same cause as above: some devices dropped off. Watchdog will close the job as partial or failed.
  • Auto-approve rule isn't firing: Check priority ordering (lowest fires first) and that the rule is enabled. A deny rule at a lower priority will shadow a later approve.
  • Rate limit exceeded: Default is 30 commands/hour/account.
  • Need to revoke everything immediately: turn off remote execution in Automation, Remote Exec. All in-flight and pending commands are blocked.

Pairs well with the AI Assistant: the AI Assistant panel can drive fleet operations for you in plain English. Ask it "check disk usage on linux-prod tag" and it will fan-out the right operation to the right devices. See the AI Assistant & MCP section for setup.

Android Kiosks

NEW

Enroll Android tablets and phones into your dashboard as managed devices and keep them online unattended. Once linked, a background service holds a persistent connection that survives backgrounding and reboot, reports device health on a heartbeat, and accepts agent commands. This is built for stationary, always-on devices: kiosks, digital signage, point-of-sale terminals, and lobby or gym tablets you manage centrally instead of touching by hand.

Prerequisites

  • Install the HopToDesk Android app. The sideloaded APK from hoptodesk.com adds remote input control; the Google Play build supports enrollment, persistence, and monitoring but is view-only for screen control (store policy).
  • A dashboard account and an invite code (open Invites to create one).
  • For low-battery and other health alerts: the Business plan.

Which Android build: Play Store or sideloaded APK

There are two Android builds. They share the same dashboard, enrollment, monitoring, and agent commands. The difference is screen control and how you distribute them.

Capability Play Store (AAB) Sideloaded APK
DistributionGoogle Play, or Play-managed through an EMMSideload, MDM app-push, or auto-enroll custom build
Enroll and stay online unattendedYesYes
Health monitoring (CPU, memory, disk, battery)YesYes
Agent commands (relaunch app, list apps, wake screen)YesYes
Remote screen viewYes (on-device consent)Yes (on-device consent)
Remote screen input (tap and type)No (Play policy)Yes
Device reboot and kiosk lock (device owner)NoYes (with ADB device-owner provisioning)
Zero-touch via auto-enroll custom buildNo (one generic listing, no per-account token)Yes
Zero-touch via EMM managed configurationYesYes
Install experienceStandard store install, auto-updatesUnknown-sources prompt unless pushed by an MDM

Use the Play Store build when you want broad, trusted distribution with automatic updates, you manage devices through an EMM, and you need monitoring, agent commands, and view-only screen, but not remote screen input. This fits most fleets.

Use the sideloaded APK when you need to remotely drive the screen (tap and type), device-owner control (reboot, kiosk lock), or zero-touch enrollment via a baked-token custom build. Push it through your MDM or install it directly. This is the full fleet-control build.

1. Enroll the device

  1. On the device, open the HopToDesk app and go to Settings.
  2. Tap Add to Dashboard, paste your invite code, and tap Link.
  3. Approve the battery-optimization prompt so the connection is allowed to persist.
  4. The device appears under Devices within a minute, marked as an Android device.

Onboarding many devices at once? Use zero-touch mass deployment instead of pasting a code on each one: generate an auto-enroll Android build and push the single APK through your MDM so every device enrolls itself.

2. Keep it online unattended

  • Foreground service: an ongoing notification keeps the connection alive when the screen is off or the app is in the background.
  • Start on boot: after a reboot the device reconnects on its own. On a PIN-locked phone, Android holds this until you unlock the phone once; after that, no need to reopen the app.
  • Best practice: keep always-on devices on a charger, and remove the screen lock to avoid the lock-screen barrier for screen control.

3. Monitor health

  • Each device reports CPU, memory, disk, and battery on every heartbeat, shown on the device's health line under Devices.
  • Set a low-battery alert (plus CPU, memory, and disk thresholds) under Settings, Alerts, Health monitoring. Battery alerts fire when a device drops to or below your threshold, so you hear about it before a kiosk dies. Available on the Business plan.

4. Run agent commands

  • Managed Android devices accept remote agent commands over the same channel that powers Fleet Management: pull device info and health, send navigation actions (home, back, recents), and tap the screen.
  • Use the AI Assistant panel to query a device in plain English, or run a command across a whole tagged group of kiosks at once. See Fleet Management.

5. Remote screen connection (optional, secondary)

Monitoring and agent commands are the primary, fully unattended way to manage a fleet. A live remote screen connection is also available as a secondary tool for visual troubleshooting, but it has stricter requirements.

  • It works only on the sideloaded APK, not the Play Store build, and the device must have Input Control (accessibility) and screen capture permissions enabled on the device.
  • Input control and the agent channel survive a reboot and reconnect on their own. Screen capture does not, by default: after a device restarts, Android asks someone to approve the screen-capture prompt again before the screen can be viewed remotely. This is a stock-Android rule, not a HopToDesk one.
  • You can remove that prompt permanently with a one-time USB step per device. See Provision a device for hands-off screen access below.

6. Provision a device for hands-off screen access

Android will not let any app, MDM, or device-owner policy grant screen capture over the air. It can be granted locally, once per device, and it then survives every reboot. Do this while the device is on the bench, alongside imaging, and you never see the capture prompt again.

Connect the device by USB with USB debugging enabled, accept the authorisation prompt on its screen, then run:

adb shell appops set com.hoptodesk.app PROJECT_MEDIA allow
adb shell appops write-settings

The second command matters. Android writes app-op changes to disk lazily, so a device rebooted immediately after the first command comes back with the permission lost. Writing the settings flushes it, and the grant then persists.

Using a custom-branded client? Substitute its own package name. Read it off the device with adb shell pm list packages.

For remote tapping and typing, also enable the app's accessibility service once in Android Settings, under Accessibility. That grant survives reboots on its own.

Finish with the settings that keep a kiosk reachable:

  • Start on boot and Keep screen on, both in the HopToDesk app.
  • Battery optimisation set to unrestricted, and on Samsung devices add the app to Never sleeping apps.
  • A permanent unattended password, so connections do not need approval.
  • No secure lock screen. A PIN or pattern keyguard sets FLAG_SECURE, which makes the remote screen render black and leaves nobody able to unlock it.

Know the limits before a fleet rollout

  • Verified on stock Android 14. Manufacturer builds, Samsung One UI in particular, can behave differently. Prove it on one device of each model before rolling out.
  • It requires physical USB access at staging. There is no over-the-air route: a device owner cannot set app-ops through Android's public APIs, and no MDM can run a shell command on Android.
  • Zebra and Symbol hardware is a special case. On those devices the client drives input through the Zebra event-injection service, so remote tapping and typing works without the accessibility grant. Screen capture still needs the step above.

Common use cases

  • Digital signage and menu boards
  • Retail and point-of-sale terminals
  • Gym, lobby, and reception check-in tablets
  • Information and self-service kiosks
  • Field and warehouse tablets

Frequently asked questions

Do I need the sideloaded APK or the Play Store app?

Either one works for enrollment, persistence, and health monitoring. Remote input control (tapping and typing on the device) requires the APK from hoptodesk.com; the Play Store build is view-only for screen control because store policy forbids input automation.

Does it reconnect after a reboot on its own?

Yes. The device restarts its connection on boot. On a PIN-locked phone, Android holds that until you unlock the phone once; after that it reconnects without opening the app.

Can I remotely view and control the screen unattended after a reboot?

Yes, once the device has been provisioned. Monitoring, agent commands, and input control all come back on their own after a reboot. Screen capture is the exception: out of the box Android asks someone to re-approve the capture prompt after each restart. A one-time USB step per device removes that prompt for good, described under Provision a device for hands-off screen access. Screen control is the sideloaded APK only.

Can I do the provisioning remotely, through Intune or another MDM?

No. Screen capture is one of the few permissions Android reserves to the person holding the device. A device owner cannot set it through the public APIs, and no MDM can run a shell command on Android. Plan for one USB connection per device at staging. Everything else, including enrollment itself, deploys over the air.

Why is the remote screen black?

Almost always a secure lock screen. A PIN, pattern, or password keyguard sets FLAG_SECURE, and Android blanks captured video while it is showing. Because the screen is black, nobody can see it to unlock it either. Remove the screen lock on kiosk devices, or keep them somewhere the lock never engages.

Will it drain the battery?

The background connection uses little power, and the device reports its own battery level so you can alert on it. For always-on kiosks, keep the device on a charger.

Does this work on iPhone or iPad?

No. iOS does not allow the background persistence or input control this relies on. Managed kiosk devices are Android only.