Remote MCP Without Port Forwarding: 3 Options Compared
In short: an MCP server on Windows lets an assistant such as Claude or ChatGPT use your PC: files, terminal, browser, programs. If the server must be reachable remotely (from your phone, from claude.ai, from another computer) there are three ways to do it. They differ mainly in how much technical work they need and how much they expose your PC.
What an MCP server is, in one line
MCP (Model Context Protocol) is the standard an AI assistant uses to call external tools. An MCP server installed on the PC exposes those tools: the assistant sees them and uses them during the conversation.
Option 1: local server (same PC only)
The server runs on the PC and talks to a client installed on the same computer, for example Claude Desktop, through its configuration file. It is the simplest route for developers, but it is not remote: it does not work from claude.ai in the browser, from your phone or from another PC. And you still need Python or Node.js and a hand-edited JSON file.
Option 2: HTTP server with open ports or a DIY tunnel
Many Windows MCP servers can listen on the network. To reach them from outside your home, though, it is up to you to:
- open and forward a router port, or build an SSH tunnel or a VPN;
- have a stable address (fixed IP or dynamic DNS);
- set up HTTPS with a valid certificate, which remote clients require;
- configure authentication, because a PC that can be controlled and reached from the internet without protection is a serious risk.
It works and gives you full control, but it is a sysadmin job you have to maintain over time.
Option 3: tunnel built into the server
This is how MCP DeskManager works: the installer creates an encrypted Cloudflare tunnel with a unique address, already on HTTPS and with OAuth authentication. No ports, no fixed IP, no certificates. You paste the address into Claude or ChatGPT as a custom connector and it works wherever the assistant works, phone included.
The three options side by side
| Local | Ports / DIY tunnel | Built-in tunnel (DeskManager) | |
|---|---|---|---|
| Usable remotely and from a phone | No | Yes | Yes |
| Router ports to open | No | Yes, or SSH tunnel/VPN | No |
| HTTPS and authentication | Not needed | To configure | Included |
| Config files to edit | Yes | Yes | No |
| Time to get started | Minutes, if you code | Hours | About 10 minutes |
Which one to choose
If you only use the assistant on the PC itself and you are comfortable with the command line, the local option is enough. If you want full control of the infrastructure and have time to spend on it, go with the second. If you want to use your PC from any chat, anywhere, without becoming a sysadmin, the third is built for you.
Frequently asked questions
Does a remote MCP server make my PC vulnerable?
It depends on how it is exposed. With a built-in tunnel the PC opens no ports and access goes through authentication; in DeskManager every assistant has its own key you can switch off, and operations that cannot be undone ask for confirmation.
Can I use the same server from Claude and ChatGPT?
Yes: you add the same address as a connector in both, each with its own key.
Want option three? Setup takes about ten minutes, with no configuration.
Installation guide Download MCP DeskManager