AI agent · claude.ai

claude.ai, with every gated call waiting for you.

claude.ai reaches your services only through PrivacyFence, which reviews reads before release and holds changes for your approval. It works with organization mode only: PrivacyFence run by your organization, reachable over public HTTPS. On your own computer, use Claude Desktop or Claude Code instead.

How it connects

From Anthropic's servers, with OAuth sign-in.

Why an organization deployment

claude.ai connects to MCP servers from Anthropic's servers, not from your computer. A PrivacyFence on your own computer listens on localhost only, on purpose, so claude.ai cannot reach it. An organization deployment is reachable over public HTTPS.

OAuth with dynamic registration

claude.ai registers itself with PrivacyFence's authorization server, and you sign in with your organization account. There is no token to copy. Access tokens last one hour and are refreshed silently; after 30 days you sign in again.

Set it up

Add a custom connector, then sign in.

Local mode

Not available: claude.ai cannot reach a PrivacyFence on your own computer. Use Claude Desktop on macOS or Windows, or Claude Code on macOS, Windows or Linux.

Organization mode

  1. Your administrator gives you the deployment's URL, for example https://pf.example.com.
  2. In claude.ai's connector settings, add a custom connector with the URL https://pf.example.com/mcp. Leave the OAuth client ID and secret empty.
  3. Add the deployment's host, pf.example.com, to Settings → Capabilities → Domain allowlist, so claude.ai can move files larger than about 75 KB.
  4. Click Connect and sign in with your organization account.
  5. Connect your services at https://pf.example.com/connect.

Set it up Organization deployment

Confirmations

claude.ai may ask first. PrivacyFence's card decides.

PrivacyFence tells claude.ai truthfully what each tool does: reads are read-only, writes are writes, and the two tools that delete something are marked destructive. claude.ai decides from that whether to ask you before it calls a tool, so it may ask before a write, in front of PrivacyFence's own card. On the Team plan, a tool marked as a write prompts on every call.

Where claude.ai offers to always allow a tool, allowing it only stops claude.ai asking: a gated call still waits for PrivacyFence's approval card at /approvals, whatever claude.ai was told or allowed. There is no mode that advertises writes as read-only.

What we observed: claude.ai asked before creating a calendar event; choosing to always allow the tool stopped it asking, and PrivacyFence's approval card was still shown.

Files

Files travel through one-time links.

A local path means nothing to the server, and claude.ai does not run PrivacyFence's Claude Desktop extension. To upload, claude.ai asks PrivacyFence for a single-use upload address and sends the file there. A download of up to about 75 KB comes back in the tool result; a larger one becomes a short-lived, one-time link. Files has the sizes and lifetimes.

claude.ai opens a link and sends an upload from its own sandbox, which reaches only the domains on Settings → Capabilities → Domain allowlist. Put the deployment's host there, or the approval goes through and claude.ai then cannot reach the file.

To read a document, no download is needed: PrivacyFence returns a PDF, Word, PowerPoint or Excel file from Drive as text.

How it's identified

A name is a claim until an administrator pins it.

claude.ai registers with PrivacyFence as Claude, so the approval card says Says it is Claude, marked Not verified, because any program that can reach the deployment can register under the same name. An administrator can pin claude.ai's registration on Settings → AI systems, for example by matching its last-used time to their own sign-in from claude.ai, and the cards for it are then verified.

Which AI system is asking

Client settings worth knowing

Add it once for the whole organization.

  • Team and Enterprise plans. An owner adds the connector once for the whole organization, and each person connects it with their own sign-in.
  • Tool permissions. Where claude.ai lets you always allow a tool, doing so leaves PrivacyFence's card as the only confirmation for it.
  • Signing in again. A sign-in lasts 30 days; after that, click Connect on the connector again.

Next

Other clients, and what they can reach.

Compare the AI clients PrivacyFence is tested with, or see what each connector lets them read and change.