AI agents

Keep your AI client. PrivacyFence sits behind it.

An AI client reaches your services only through PrivacyFence's /mcp endpoint. Whichever client asks, PrivacyFence's own gate decides: reads are reviewed before release, and changes wait for your approval. These are the clients we test with, one page each.

Tested clients

One page per client.

Each page says how the client connects, what it asks you before PrivacyFence's own card, how it is named on that card, and links its setup steps in the docs.

Claude Desktop

Local mode and organization mode. On your own computer, through PrivacyFence's extension, PrivacyFence.mcpb: no token to copy. With an organization deployment, as a custom connector with your organization sign-in.

Claude Desktop with PrivacyFence

Claude Code

Local mode and organization mode. On your own computer, straight to /mcp over HTTP with your own token. With an organization deployment, it registers itself and you sign in with your organization account.

Claude Code with PrivacyFence

claude.ai

Organization mode only. claude.ai connects from Anthropic's servers, so it needs a PrivacyFence it can reach over public HTTPS. It is added as a custom connector, and you sign in with your organization account.

claude.ai with PrivacyFence

Other MCP clients

Any client that speaks MCP over Streamable HTTP connects the way Claude Code does: on your own computer with the /mcp URL and your bearer token, and to an organization deployment with OAuth 2.1 and dynamic client registration. Clients not listed here have not been tested.

How an AI system connects

Whichever client

The same gate, the same card.

PrivacyFence tells every client truthfully what each tool does: reads are read-only, writes are writes, and the two tools that delete something are marked destructive. A client may use that to ask you before a write, and may let you always allow a tool. Either way, a gated call still waits for PrivacyFence's approval card, and that card is the confirmation that decides.

On your own computer every client uses the same credential, so the card names the requester Undetected. In an organization deployment the card shows the name the client sends as a claim, marked Not verified, until an administrator pins that client's registration.

Which AI system is asking

Next

Choose what the assistant can reach.

See what each connector lets an AI client read, what is reviewed, and which writes need your approval.