Fleet logo
Menu An icon indicating that interacting with this button will open the navigation menu.
Fleet logo An 'X' icon indicating that this can be interacted with to close the navigation menu.

Solutions

a small chevron
Device management

Device management

Remotely manage, and protect laptops and mobile devices.

Orchestration

Orchestration

Automate tasks across devices, from app installs to scripts.

Software management

Software management

Inventory, patch, and manage installed software.

Linux management

Linux device management

Manage Linux devices with full visibility and control.

GitOps

Infrastructure as code

See every change, undo any error, repeat every success.

Deployment

Deployment

Run Fleet the way that fits your team.

Extend Fleet

Extend Fleet

Integrate your favorite tools with Fleet.


Customers
Pricing
Partners

More

a small chevron
Docs

Docs

Guides

Guides

Support

Support

Resources / blog

Resources / blog

Get your license

Get your license

The handbook

The handbook

GitOps for device management

In-person workshop for beginners.

Join us
Get a demo
Solutions A small chevron
Device management

Device management

Remotely manage, and protect laptops and mobile devices.

GitOps

Infrastructure as code

See every change, undo any error, repeat every success.

Orchestration

Orchestration

Automate tasks across devices, from app installs to scripts.

Deployment

Deployment

Run Fleet the way that fits your team.

Software management

Software management

Inventory, patch, and manage installed software.

Extend Fleet

Extend Fleet

Integrate your favorite tools with Fleet.

Linux management

Linux device management

Manage Linux devices with full visibility and control.

Customers Pricing Partners
More A small chevron

GitOps for device management

In-person workshop for beginners.

Join us
Docs

Docs

Guides

Guides

Support

Support

Resources / blog

Resources / blog

Get your license

Get your license

The handbook

The handbook

Get a demo
{{categoryFriendlyName}}/
{{thisPage.meta.articleTitle}}
search

Fleet Desktop

{{articleSubtitle}}

|
The author's GitHub profile picture

Mo Zhu

Share

Share this article on Hacker News Share this article on LinkedIn Share this article on Twitter

On this page

{{topic.title}}
Docs Docs REST API REST API Guides Guides Get a demoGet a demo
Suggest an editSuggest an edit

Fleet Desktop

{{articleSubtitle}}

| The author's GitHub profile picture

Mo Zhu

Fleet Desktop

Fleet Desktop is a self-service portal for your end users. It shows up in the menu bar on macOS and system tray on Windows/Linux.

Fleet Desktop unlocks two key benefits:

  • Self-remediation: end users can see which policies they are failing and resolution steps, reducing the need for IT and security teams to intervene. Available in Fleet Premium.
  • Scope transparency: end users can see what the Fleet agent can do on their machines, eliminating ambiguity between end users and their IT and security teams

If your end users have a hard time finding Fleet Desktop in the macOS menu bar, you can deploy this Fleet Desktop app.

Install Fleet Desktop

For information on how to install Fleet Desktop, visit: Adding Hosts.

Upgrade Fleet Desktop

Once installed, Fleet Desktop will be automatically updated via Fleetd. To learn more, visit: Self-managed agent updates.

Custom transparency link

Organizations with complex security postures can direct end users to a resource of their choice to serve custom content.

An icon indicating that this section has important information

The custom transparency link is only available for users with Fleet Premium

To turn on the custom transparency link in the Fleet UI, click on your profile in the top right and select Settings. On the settings page, go to Organization Settings > Fleet Desktop > Custom transparency URL.

For information on setting the custom transparency link via a YAML configuration file, see the configuration files documentation.

Secure Fleet Desktop

Requests sent by Fleet Desktop and the web page that opens when clicking on the "My Device" tray item use a Random (Version 4) UUID token to uniquely identify each host.

The server uses this token to authenticate requests that give host information. Fleet uses rate limiting and token rotation to secure access to this information.

Successfully brute-forcing this UUID is about as likely as you getting hit by a meteorite this year.

Rate limiting

To prevent brute-forcing attempts, Fleet rate-limits the endpoints used by Fleet Desktop on a per-IP basis. If an IP requests more than 1000 consecutive invalid UUIDs in a one-minute interval, Fleet will ban requests from such IP for one minute (fail requests with HTTP error code 429). This rate limit algorithm is used to support deployments of Fleet where all hosts are behind the same NAT (all hosts mapped to the same IP).

Token rotation

ℹ️  In Fleet v4.22.0, token rotation for Fleet Desktop was introduced.

Starting with Fleet v4.22.0, the server will reject any token older than one hour since it was issued. This helps Fleet protect against unintentionally leaked or brute-forced tokens.

As a consequence, Fleet Desktop will issue a new token if the current token is:

  • Rejected by the server
  • Older than one hour

This change is imperceptible to users, as clicking on the "My device" tray item always uses a valid token. If a user visits an address with an expired token, they will get a message instructing them to click on the tray item again.

About Fleet

Fleet is the single endpoint management platform for macOS, iOS, Android, Windows, Linux, ChromeOS, and cloud infrastructure. Trusted by over 1,300 organizations, Fleet empowers IT and security teams to accelerate productivity, build verifiable trust, and optimize costs.

By bringing infrastructure-as-code (IaC) practices to device management, Fleet ensures endpoints remain secure and operational, freeing engineering teams to focus on strategic initiatives.

Fleet offers total deployment flexibility: on-premises, air-gapped, container-native (Docker and Kubernetes), or cloud-agnostic (AWS, Azure, GCP, DigitalOcean). Organizations can also choose fully managed SaaS via Fleet Cloud, ensuring complete control over data residency and legal jurisdiction.

Fleet logo
Solutions Device management Orchestration Software management Integrations Pricing Partners
Documentation Support Docs API Release notes Get your license
Company About Trust Jobs Logos/artwork Why open source?
a small checkmarkSOC2 Type 2 Creative Commons Licence CC BY-SA 4.0
© 2026 Fleet Inc. Privacy
Slack logo GitHub logo LinkedIn logo X (Twitter) logo Youtube logo Mastadon logo