These pages describe PrivacyFence 5.0.0. Download it · What changed
Connect Claude Desktop¶
Claude Desktop works with both deployments:
- Local mode: PrivacyFence installed on the same computer. Claude Desktop connects through
PrivacyFence's extension,
PrivacyFence.mcpb, which finds the running daemon by itself. - Organization mode: PrivacyFence run centrally by your organization. Claude Desktop connects to it as a custom connector and you sign in with your organization account.
Which one you have is explained in Local mode and organization mode. Claude Desktop runs on macOS and Windows; on Linux, use Claude Code.
Local mode¶
Install the extension that came with PrivacyFence:
| Platform | Where the extension is | How to install it |
|---|---|---|
| macOS | PrivacyFence.mcpb on the DMG |
Double-click it; see Install on macOS. |
| Windows | %ProgramFiles%\PrivacyFence\PrivacyFence-<version>.mcpb |
The installer's last page offers it; see Install on Windows. |
| Linux | none | Claude Desktop does not run on Linux. |
Claude Desktop opens and offers to install the extension; accept. There is nothing to configure and no token to copy. The extension:
- waits until the daemon's
/mcpendpoint answers; - asks the daemon for your MCP token over its local control channel;
- reads the
/mcpURL from the file the daemon writes when it starts (mcp_urlin the handoff directory; see Platform support); - relays MCP messages between Claude Desktop and
/mcp, and reads and writes local files for the tools that need them (see Files).
Nothing is edited in Claude Desktop's configuration, and no token is stored in a file you can read. On a packaged install the extension never starts the daemon: the daemon belongs to the system and its own account. If the daemon is stopped, the extension waits for it and logs that you should choose Start PrivacyFence… from the companion's menu.
Organization mode¶
Your administrator gives you the deployment's URL, for example https://pf.example.com. In Claude
Desktop's connector settings, add a custom connector with the URL https://pf.example.com/mcp,
then click Connect on it and sign in with your organization account. Leave the optional OAuth
client ID and secret empty: Claude Desktop registers itself. On Team and Enterprise plans an owner
can add the connector for the whole organization, and each person connects it with their own
sign-in.
Access tokens last one hour and are refreshed silently; after 30 days you sign in again. Connect
your services at https://pf.example.com/connect. Setting up the deployment itself is
Organization deployment.
Do not install the extension as well when you use an organization deployment: it only talks to a PrivacyFence on the same computer.
Files¶
- Local mode, with the extension. Tools that read or save a file (
drive_upload_file'slocal_path,drive_download_file'sdestination_dir, email attachments) work with paths on your computer. The extension reads or writes the file as you and passes the bytes to or from the daemon (ADR 0007). On macOS, the first time a tool reads or saves a file outside Claude's own folders, macOS may ask whether Claude may access that folder; allow it once per folder. - Organization mode, as a custom connector. A local path means nothing to the server. Claude
uploads through
privacyfence_create_upload_slotand a one-time link, and a download comes back in the tool result or as a one-time link (ADR 0028).
Sizes, lifetimes and limits are in Files.
Confirmations¶
Two things can ask you before a tool runs:
- Claude Desktop's own tool prompt. Claude Desktop can ask before it calls a tool, and offers to allow it for the rest of the chat or always. Clients use a tool's annotations to decide when to ask.
- PrivacyFence's approval card. A gated call waits for you in Approvals, whatever Claude Desktop was told or allowed. This is the confirmation that decides; see Approvals and policy.
PrivacyFence always tells the client what each tool does: reads are read-only, writes are writes, and the two tools that delete something are destructive (What the AI system is told). So Claude Desktop may ask before a write, in front of PrivacyFence's own card. There is one extension and no switch that advertises writes as read-only. If you would rather confirm only once, on PrivacyFence's card, choose to always allow the tool the first time Claude Desktop asks about it; it does not ask about that tool again. Every call still goes through PrivacyFence's gate.
What we observed (Claude Desktop 2.9939.2 with the extension, PrivacyFence 5.0.0a2,
2026-09-28, evidence): with default tool permissions Claude Desktop asked before
calendar_create_event. Choosing to always allow the tool stopped it asking, and PrivacyFence's
approval card was still shown for the call. The custom connector (organization mode) has not been
checked yet.
How the client is identified¶
In local mode every approval card and Audit Log row shows the requester as Undetected: every AI
system on your computer uses the same credential, so PrivacyFence cannot tell them apart. The audit
log still records the name Claude Desktop sent: through the extension that is
local-agent-mode-<server>, which the audit log records as Claude Desktop.
In organization mode, Claude Desktop sends its own name when it registers and in the MCP handshake.
Its custom connector most likely registers through your claude.ai account exactly as claude.ai does,
as Claude, but that has not been verified. That name is a claim: the card says the caller says it is Claude Desktop and marks it Not verified,
because any program can send the same name. An administrator can pin Claude Desktop's registration on
Settings → AI systems; the cards for that registration are then verified.
See Which AI system is asking.
Troubleshooting¶
| What you see | What to do |
|---|---|
| Claude Desktop reports no PrivacyFence server, or the extension's tools never appear | The daemon is stopped. Choose Start PrivacyFence… from the companion's menu; the extension picks it up by itself. |
Double-clicking PrivacyFence.mcpb does nothing on Windows |
Drag the file onto Claude Desktop's Settings → Extensions page instead; see Install on Windows. |
| Every tool appears twice | The extension and a custom connector are both installed. Remove one. |
| Tools are listed but none of your services' tools | No service is connected yet. Ask Claude to call privacyfence_status; connect services in Settings (local mode) or at /connect (organization mode). See Connecting a service. |
| The custom connector's Connect fails | The URL must end in /mcp and be reachable over public HTTPS. Your administrator can check it with the validation checklist. |
| A call waits and nothing happens | It is waiting for your approval. Open Approvals from the companion, or /approvals in organization mode. |