Local mode: your own token
Claude Code connects to PrivacyFence's /mcp endpoint on localhost with a bearer token. PrivacyFence mints one token per account on your computer, each with its own connectors, rules and approvals.
AI agent · Claude Code
Claude Code reaches your services only through PrivacyFence, which reviews reads before release and holds changes for your approval. It works with both deployments: PrivacyFence on your own computer (local mode) on macOS, Windows and Linux, and PrivacyFence run by your organization (organization mode).
How it connects
/mcp, over HTTP.Claude Code connects to PrivacyFence's /mcp endpoint on localhost with a bearer token. PrivacyFence mints one token per account on your computer, each with its own connectors, rules and approvals.
Claude Code discovers PrivacyFence's authorization server, registers itself, and opens your organization's sign-in page in the browser. It then holds its own tokens; there is nothing to copy or paste. Access tokens last one hour and are refreshed silently; after 30 days you sign in again.
Set it up
claude mcp add command./mcp URL from PrivacyFence's mcp_url file and print your token with --print-mcp-token. The docs have the paths for each platform.claude mcp add --transport http --scope user privacyfence with that URL and an Authorization: Bearer header carrying the token./mcp inside Claude Code to check that privacyfence is connected.https://pf.example.com.claude mcp add --transport http --scope user privacyfence https://pf.example.com/mcp./mcp inside Claude Code, choose privacyfence, and sign in with your organization account in the browser.https://pf.example.com/connect.Confirmations
PrivacyFence tells Claude Code truthfully what each tool does: reads are read-only, writes are writes, and the two tools that delete something are marked destructive. Whether Claude Code asks before it calls a tool from an MCP server depends on its permission mode and rules, not on those annotations.
If it asks, you can choose not to be asked again for that tool, or allow mcp__privacyfence under /permissions for all of PrivacyFence's tools at once. That only stops Claude Code asking: a gated call still waits for PrivacyFence's approval card, whatever Claude Code was told or allowed. There is no mode that advertises writes as read-only.
What we observed in local mode: with no permission rules configured, Claude Code did not ask before calling any PrivacyFence tool in the run, creating a calendar event included, and PrivacyFence's approval card was the only confirmation.
Files
Claude Code does not run PrivacyFence's Claude Desktop extension, so PrivacyFence never opens a path on your computer for it. To upload, Claude Code asks PrivacyFence for a single-use upload address and sends the file there. A download comes back as a one-time link, or in organization mode as the file itself when it is small enough. Files has the sizes and lifetimes.
How it's identified
Local mode. Every AI client on your computer uses the same credential, so PrivacyFence cannot tell them apart, and the approval card names the requester Undetected. The audit log still records the name Claude Code sent.
Organization mode. Claude Code registers as Claude Code (<name>), where <name> is the server name you gave claude mcp add, and PrivacyFence recognises it as Claude Code. That name is a claim: the card says Says it is Claude Code, marked Not verified, because any program can send the same name. An administrator can pin the registration on Settings → AI systems, and the cards for it are then verified.
Client settings worth knowing
--scope user makes PrivacyFence available in every project. Leave it out to add it to the current project only./permissions. Allowing mcp__privacyfence stops Claude Code asking about PrivacyFence's tools; PrivacyFence's card still decides./mcp. Shows whether privacyfence is connected, and is where you sign in again in organization mode.Next
Compare the AI clients PrivacyFence is tested with, or see what each connector lets them read and change.