Skip to content

These pages describe PrivacyFence 5.0.0. Download it · What changed

Connect Claude Desktop

Claude Desktop works with both deployments:

  • Local mode: PrivacyFence installed on the same computer. Claude Desktop connects through PrivacyFence's extension, PrivacyFence.mcpb, which finds the running daemon by itself.
  • Organization mode: PrivacyFence run centrally by your organization. Claude Desktop connects to it as a custom connector and you sign in with your organization account.

Which one you have is explained in Local mode and organization mode. Claude Desktop runs on macOS and Windows; on Linux, use Claude Code.

Local mode

Install the extension that came with PrivacyFence:

Platform Where the extension is How to install it
macOS PrivacyFence.mcpb on the DMG Double-click it; see Install on macOS.
Windows %ProgramFiles%\PrivacyFence\PrivacyFence-<version>.mcpb The installer's last page offers it; see Install on Windows.
Linux none Claude Desktop does not run on Linux.

Claude Desktop opens and offers to install the extension; accept. There is nothing to configure and no token to copy. The extension:

  1. waits until the daemon's /mcp endpoint answers;
  2. asks the daemon for your MCP token over its local control channel;
  3. reads the /mcp URL from the file the daemon writes when it starts (mcp_url in the handoff directory; see Platform support);
  4. relays MCP messages between Claude Desktop and /mcp, and reads and writes local files for the tools that need them (see Files).

Nothing is edited in Claude Desktop's configuration, and no token is stored in a file you can read. On a packaged install the extension never starts the daemon: the daemon belongs to the system and its own account. If the daemon is stopped, the extension waits for it and logs that you should choose Start PrivacyFence… from the companion's menu.

Organization mode

Your administrator gives you the deployment's URL, for example https://pf.example.com. In Claude Desktop's connector settings, add a custom connector with the URL https://pf.example.com/mcp, then click Connect on it and sign in with your organization account. Leave the optional OAuth client ID and secret empty: Claude Desktop registers itself. On Team and Enterprise plans an owner can add the connector for the whole organization, and each person connects it with their own sign-in.

Access tokens last one hour and are refreshed silently; after 30 days you sign in again. Connect your services at https://pf.example.com/connect. Setting up the deployment itself is Organization deployment.

Do not install the extension as well when you use an organization deployment: it only talks to a PrivacyFence on the same computer.

Files

  • Local mode, with the extension. Tools that read or save a file (drive_upload_file's local_path, drive_download_file's destination_dir, email attachments) work with paths on your computer. The extension reads or writes the file as you and passes the bytes to or from the daemon (ADR 0007). On macOS, the first time a tool reads or saves a file outside Claude's own folders, macOS may ask whether Claude may access that folder; allow it once per folder.
  • Organization mode, as a custom connector. A local path means nothing to the server. Claude uploads through privacyfence_create_upload_slot and a one-time link, and a download comes back in the tool result or as a one-time link (ADR 0028).

Sizes, lifetimes and limits are in Files.

Confirmations

Two things can ask you before a tool runs:

  1. Claude Desktop's own tool prompt. Claude Desktop can ask before it calls a tool, and offers to allow it for the rest of the chat or always. Clients use a tool's annotations to decide when to ask.
  2. PrivacyFence's approval card. A gated call waits for you in Approvals, whatever Claude Desktop was told or allowed. This is the confirmation that decides; see Approvals and policy.

PrivacyFence always tells the client what each tool does: reads are read-only, writes are writes, and the two tools that delete something are destructive (What the AI system is told). So Claude Desktop may ask before a write, in front of PrivacyFence's own card. There is one extension and no switch that advertises writes as read-only. If you would rather confirm only once, on PrivacyFence's card, choose to always allow the tool the first time Claude Desktop asks about it; it does not ask about that tool again. Every call still goes through PrivacyFence's gate.

What we observed (Claude Desktop 2.9939.2 with the extension, PrivacyFence 5.0.0a2, 2026-09-28, evidence): with default tool permissions Claude Desktop asked before calendar_create_event. Choosing to always allow the tool stopped it asking, and PrivacyFence's approval card was still shown for the call. The custom connector (organization mode) has not been checked yet.

How the client is identified

In local mode every approval card and Audit Log row shows the requester as Undetected: every AI system on your computer uses the same credential, so PrivacyFence cannot tell them apart. The audit log still records the name Claude Desktop sent: through the extension that is local-agent-mode-<server>, which the audit log records as Claude Desktop.

In organization mode, Claude Desktop sends its own name when it registers and in the MCP handshake. Its custom connector most likely registers through your claude.ai account exactly as claude.ai does, as Claude, but that has not been verified. That name is a claim: the card says the caller says it is Claude Desktop and marks it Not verified, because any program can send the same name. An administrator can pin Claude Desktop's registration on Settings → AI systems; the cards for that registration are then verified. See Which AI system is asking.

Troubleshooting

What you see What to do
Claude Desktop reports no PrivacyFence server, or the extension's tools never appear The daemon is stopped. Choose Start PrivacyFence… from the companion's menu; the extension picks it up by itself.
Double-clicking PrivacyFence.mcpb does nothing on Windows Drag the file onto Claude Desktop's Settings → Extensions page instead; see Install on Windows.
Every tool appears twice The extension and a custom connector are both installed. Remove one.
Tools are listed but none of your services' tools No service is connected yet. Ask Claude to call privacyfence_status; connect services in Settings (local mode) or at /connect (organization mode). See Connecting a service.
The custom connector's Connect fails The URL must end in /mcp and be reachable over public HTTPS. Your administrator can check it with the validation checklist.
A call waits and nothing happens It is waiting for your approval. Open Approvals from the companion, or /approvals in organization mode.

Platform-specific problems are on macOS and Windows.