How to use Jev for computer use
Here's how to wire Jev into a computer-use agent so it vets every action before it clicks: one call returns a typed 'safe?', the action type, and a calibrated confidence — and your loop acts on it in about 70–500ms.
A live demo of the loop on this page: each step is one /api/v1/decide call — a choice over the on-screen actions plus a noul safety gate. No real device is touched.
A computer-use model is good at proposing an action from a screenshot and bad at knowing when not to. The pattern below drops Jev between 'propose' and 'run': it turns each proposed action into a typed, calibrated decision your code can branch on — no prose to parse, no runaway generation to wait on.
Drop it into your agent — no code
The fastest way in isn't code — it's pasting a rule into your agent. Give it the decide tool once, then drop in a skill (Claude Code) or an AGENTS.md rule (Codex / opencode) that makes it check risky actions before running them.
npx github:codaaiteam/jev-mcp # gives the agent a `decide` tool (set JEV_API_KEY=jv_live_...)Claude Code — save this as .claude/skills/jev-gate/SKILL.md:
---
name: jev-gate
description: Check risky, irreversible actions with Jev before running them; pause for the human when unsafe or destructive.
---
# Jev safety gate
Before any irreversible action — delete, overwrite, git push --force, deploy, a
network write, or a computer-use click that submits/sends — call the `decide`
tool (from jev-mcp) with:
state: the exact action + one line of context
questions:
safe: { type: "noul", instructions: "Safe and reversible to run without a human?" }
kind: { type: "choice", criteria: { read, write, network, destructive } }
If safe < 0.8 or kind == "destructive" -> STOP and ask the human. Else proceed.
Read-only actions (read files, git status, search) skip the check.Codex / opencode — paste the same rule into your AGENTS.md. Both files, plus a hard PreToolUse hook the agent can't skip, are in the starter repo linked below.
Or wire it yourself (code)
// Computer-use loop: vet every action with Jev before it runs
async function step(screenshot) {
const action = await cua.propose(screenshot); // your computer-use model
const res = await fetch("https://jevtypesafeai.com/api/v1/decide", {
method: "POST",
headers: {
"Content-Type": "application/json",
Authorization: `Bearer ${process.env.JEV_KEY}`, // jv_live_...
},
body: JSON.stringify({
state: { action, screen: describe(screenshot) },
questions: {
safe: { type: "noul", instructions: "Is this action safe and reversible to run without asking a human?" },
kind: { type: "choice", instructions: "Classify the action.",
criteria: { click: "a click", type: "typing text", navigate: "go to a page", destructive: "deletes/sends/submits" } },
},
}),
});
const { answers } = await res.json();
if (answers.safe.noul > 0.85 && answers.kind.choice !== "destructive") {
await cua.run(action); // confident + non-destructive → act
} else {
await askHuman(action, answers.safe.noul); // otherwise → pause for a human
}
}answers.safe.noul is a calibrated probability from 0 to 1 that RLCD training makes trustworthy; answers.kind.choice is locked to the criteria you listed, so there is no invalid class to handle. Both come back in the same call. Tune the 0.85 threshold against your own logs — raise it on destructive surfaces, lower it where a mistake is cheap.
Wire it into your loop
- Add the decide call between 'propose action' and 'run action'
- Proceed only when answers.safe.noul clears your threshold and answers.kind.choice isn't destructive
- Send low-confidence or destructive actions to a human, then resume the loop
- Log safe.noul next to the outcome so you can calibrate the threshold over time
Which primitive to use
- noul — a calibrated yes/no such as 'safe to run?' or 'did this step succeed?'
- choice — pick one of a fixed set of allowed actions, or classify the action's risk
- score — rate risk on an ordered scale when you want a graded threshold
Want a working reference? Command Safety and the Agent Loop Detector are two computer-use gates already built on this exact call.
Real setups people built
Jev launched in September 2026 and people wired it into their agents fast. A few real examples of this exact 'gate the agent' pattern from the community (links go to the authors):
- @Saccc_c — "Jev Use" — wrapped Jev around Codex's computer use for faster, smoother Mac control
- @mdlahfir — routes tasks across Claude Code, Codex and opencode with a Jev gate + a deterministic hook
- @milindlabs — local computer use — CoreML segments the UI, Jev picks the element to click, ~90ms per step
- @gregpr07 (browser-use) — browser agent + Jev finds a flight in about 7 seconds
Prefer a starter you can clone? The jev-computer-use starter wires this gate into Claude Code, Codex or opencode in one file — see the repo link below.
FAQ
Does Jev control the computer itself?
No — Jev doesn't click or type. It's the decision layer: your computer-use agent proposes an action, Jev returns a typed, calibrated call on whether to proceed, and your code runs it.
How do I gate a destructive action?
Add a choice question that classifies the action (e.g. click / type / navigate / destructive) and never auto-run the 'destructive' class — route it to a human regardless of confidence, or require a much higher noul threshold.
Won't a check on every step slow the agent down?
Not meaningfully — a Jev decision returns in about 70–500ms in a single pass, versus seconds for a second LLM prompt, so you can afford to vet every action instead of sampling.
See also: Starter repo (GitHub) · Command Safety · Agent Loop Detector · Jev for AI agents
Gate your computer-use agent with Jev
Grab a jv_live_ key and add a typed, calibrated check before every action.