These pages describe PrivacyFence 5.0.0. Download it · What changed
Connect claude.ai¶
claude.ai works with organization mode only. claude.ai connects to MCP servers from
Anthropic's servers, not from your computer, so it needs a PrivacyFence it can reach over public
HTTPS. A local install listens on localhost only and is unreachable from outside your computer,
on purpose. Which deployment you have is explained in
Local mode and organization mode.
Local mode¶
Not available. On your own computer, use Claude Desktop or Claude Code instead: both work with a local install on every platform they run on.
| Platform | claude.ai with a local install |
|---|---|
| macOS | Not available; use Claude Desktop or Claude Code. |
| Windows | Not available; use Claude Desktop or Claude Code. |
| Linux | Not available; use Claude Code. |
Organization mode¶
Your administrator gives you the deployment's URL, for example https://pf.example.com.
- In claude.ai's connector settings, add a custom connector with the URL
https://pf.example.com/mcp. Leave the optional OAuth client ID and secret empty: claude.ai registers itself. - Click Connect on the connector and sign in with your organization account.
- Connect your services at
https://pf.example.com/connect.
On Team and Enterprise plans an owner adds the connector once for the whole organization, and each person connects it with their own sign-in. Access tokens last one hour and are refreshed silently; after 30 days you sign in again. Setting up the deployment itself is Organization deployment.
Files¶
A local path means nothing to the server, and claude.ai does not run PrivacyFence's Claude Desktop extension. Files travel through one-time links instead (ADR 0028):
- Upload (for example
drive_upload_file, or an email attachment): claude.ai callsprivacyfence_create_upload_slot, sends the file to the returned URL with an HTTPPUT, and passes the returnedupload_idto the tool. - Download (for example
drive_download_file): a file of up to about 75 KB comes back in the tool result; a larger one becomes a short-lived, one-time link that claude.ai fetches itself. claude.ai truncates a tool result over about 150,000 characters, which is why the default inline limit is well below that (ADR 0092).
Sizes, lifetimes and the organization settings are in Files and File delivery.
Confirmations¶
Two things can ask you before a tool runs:
- claude.ai's own tool prompt. claude.ai can ask before it calls a tool from a connector, and decides from the tool's annotations. On the Team plan, a tool marked as a write prompts on every call and cannot be allowed for the whole task, and an organization cannot pre-approve it (ADR 0086).
- PrivacyFence's approval card. A gated call waits for you at
/approvals, whatever claude.ai was told or allowed. This is the confirmation that decides; see Approvals and policy.
PrivacyFence always tells the client what each tool does: reads are read-only, writes are writes, and the two tools that delete something are destructive (What the AI system is told). So claude.ai may ask before a write, in front of PrivacyFence's own card. There is no switch that advertises writes as read-only (ADR 0089). Where claude.ai offers to always allow a tool, allowing PrivacyFence's tools leaves PrivacyFence's card as the only confirmation; every call still goes through PrivacyFence's gate.
What we observed (claude.ai web, PrivacyFence 5.0.0a2, 2026-09-28,
evidence): claude.ai asked before calendar_create_event. Choosing to always
allow the tool stopped it asking, and PrivacyFence's approval card was still shown for the call.
How the client is identified¶
Every approval card and audit entry names the AI system that asked. claude.ai gives a name when it
registers with PrivacyFence and again in the MCP handshake; the registered name is the one used
when PrivacyFence recognises it. claude.ai registers as Claude, so the card says the caller
says it is Claude. That name is a claim: the card says the caller says it is that system and marks it
Not verified, because any program that can reach the deployment can register under the same
name. An administrator can pin claude.ai's registration on Settings → AI systems, for
example by matching its last-used time to their own sign-in from claude.ai; the cards for that
registration are then verified. See
Which AI system is asking and
AI systems.
Troubleshooting¶
| What you see | What to do |
|---|---|
| Connect fails before the sign-in page opens | The URL must end in /mcp and be reachable over public HTTPS with a valid certificate. Your administrator can check it with the validation checklist. |
| The sign-in page refuses you | Your account is not allowed to sign in to this deployment. Ask your administrator. |
| The connector was working and now asks you to connect again | A sign-in lasts 30 days. Click Connect again. |
| Tools are listed but none of your services' tools | No service is connected yet. Ask Claude to call privacyfence_status, then connect services at /connect. See Connecting a service. |
| A call waits and nothing happens | It is waiting for your approval at /approvals. |
| Every card says Not verified | Expected until an administrator pins your registration. |
Deployment problems are in the organization guide's Troubleshooting.