Follow Discord
Sweep 29 Sep 2026 · 18:10Z Build v2.1.285 506 read Stable v2.1.277 Latest v2.1.284 Next v2.1.285 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One capture · claude-docs

One read of Claude Documentationclaude-docs-20260928T220706Z

157 pages moved out of 255 read.

Pages moved 157 significant first
Pages read 255 in this capture
Captured 22:07 UTC
Corpus hash 9aad7bf66b91 corpus-hash

What this read moved

76-100 of 157, page 4 of 7

This capture is too large to show at once. Changes 76-100 of 157 are below, significant first; the rest are on the following screens.

connectors/building/directory-vs-custom Changed · +14 / -14 lines

from line 14
1414 
1515Directory and custom connectors differ only in what surrounds the runtime: who reviews the server, how users find it, and which Anthropic-side features it can use.
1616 
17| | Directory connector | Custom connector |
18| ------------------------------------------------------------------------------ | -------------------------------------------- | ---------------------------------------------------------- |
19| **Runtime** | Same | Same |
20| **Anthropic review** | Yes | No |
21| **In-product discovery** | Browse, search, Suggested Connectors | None |
22| **Distribution** | [Directory link](#share-an-install-link) | [Install link](#share-an-install-link) or manual URL entry |
23| **Anthropic-held client credentials** | Available | Not available |
24| **[External link](/docs/connectors/building/mcp-apps/external-links) confirmation** | Can allowlist destinations to skip the modal | Always shows the modal |
25| **Appears as** | Named card with logo | **Custom** |
17| | Directory connector | Custom connector |
18| - | - | - |
19| **Runtime** | Same | Same |
20| **Anthropic review** | Yes | No |
21| **In-product discovery** | Browse, search, Suggested Connectors | None |
22| **Distribution** | [Directory link](#share-an-install-link) | [Install link](#share-an-install-link) or manual URL entry |
23| **Anthropic-held client credentials** | Available | Not available |
24| **[External link](/docs/connectors/building/mcp-apps/external-links) confirmation** | Can allowlist destinations to skip the modal | Always shows the modal |
25| **Appears as** | Named card with logo | **Custom** |
2626 
2727## Share an install link
2828 
from line 48
4848 
4949The link takes these query parameters:
5050 
51| Parameter | Description |
52| --------------- | ---------------------------------------------------------------------------------------------------------- |
53| `modal` | Must be `add-custom-connector` |
54| `connectorName` | Display name shown to the user |
55| `connectorUrl` | Your MCP server URL, [percent-encoded](https://developer.mozilla.org/en-US/docs/Glossary/Percent-encoding) |
51| Parameter | Description |
52| - | - |
53| `modal` | Must be `add-custom-connector` |
54| `connectorName` | Display name shown to the user |
55| `connectorUrl` | Your MCP server URL, [percent-encoded](https://developer.mozilla.org/en-US/docs/Glossary/Percent-encoding) |
5656 
5757For example, an install link for a server at `https://mcp.example.com/` looks like this:
5858 

connectors/building/index Changed · +4 / -4 lines

from line 66
6666 
6767Keep tool results and tool call durations within these limits. They differ between the hosted surfaces and Claude Code.
6868 
69| Limit | claude.ai and Desktop | Claude Code |
70| ------------------------ | ------------------------- | -------------------------------------------------------- |
71| Maximum tool result size | \~150,000 characters | 25,000 tokens, configurable with `MAX_MCP_OUTPUT_TOKENS` |
72| Tool call timeout | 240 seconds per tool call | Configurable with `MCP_TOOL_TIMEOUT` |
69| Limit | claude.ai and Desktop | Claude Code |
70| - | - | - |
71| Maximum tool result size | \~150,000 characters | 25,000 tokens, configurable with `MAX_MCP_OUTPUT_TOKENS` |
72| Tool call timeout | 240 seconds per tool call | Configurable with `MCP_TOOL_TIMEOUT` |
7373 
7474### Decide whether to add interactive UI
7575 

connectors/building/managing-your-listing Changed · +7 / -7 lines

from line 36
3636 
3737The health badge summarizes your server's recent reliability as one of these statuses:
3838 
39| Status | Meaning |
40| ------------------- | -------------------------------------------------------------------- |
41| **Healthy** | Request errors are 2% or less of tool calls in the last 30 days |
42| **Worth a look** | Request errors are above 2% |
43| **Degraded** | Request errors are above 5% |
44| **Not enough data** | Request errors haven't been measured yet; metrics update daily |
45| **Not live** | The server isn't published yet, and health appears after publication |
39| Status | Meaning |
40| - | - |
41| **Healthy** | Request errors are 2% or less of tool calls in the last 30 days |
42| **Worth a look** | Request errors are above 2% |
43| **Degraded** | Request errors are above 5% |
44| **Not enough data** | Request errors haven't been measured yet; metrics update daily |
45| **Not live** | The server isn't published yet, and health appears after publication |
4646 
4747Request errors include tool calls rejected for authentication problems and exclude errors a tool returns in its own result.
4848 

connectors/building/mcp Changed · +4 / -4 lines

from line 23
2323 
2424Where the server runs determines which integrations it suits.
2525 
26| Type | Description | Use case |
27| ---------- | ------------------------- | --------------------------------- |
28| Local MCP | Runs on the user's device | Desktop integrations, local tools |
29| Remote MCP | Hosted on the internet | Web services, cloud applications |
26| Type | Description | Use case |
27| - | - | - |
28| Local MCP | Runs on the user's device | Desktop integrations, local tools |
29| Remote MCP | Hosted on the internet | Web services, cloud applications |
3030 
3131### Tools, resources, and prompts
3232 

connectors/building/mcp-apps/design-guidelines Changed · +91 / -91 lines

from line 293
293293 
294294Color tokens cover backgrounds, text, and borders, and semantic accent colors signal status. All tokens automatically adapt to light and dark mode.
295295 
296| | Light mode | Dark mode |
297| :--------------------------- | :-------------- | :-------------- |
298| **Background** | | |
299| `color-background-primary` | `#FFFFFF` | `#30302E` |
300| `color-background-secondary` | `#F5F4ED` | `#262624` |
301| `color-background-tertiary` | `#FAF9F5` | `#141413` |
302| `color-background-inverse` | `#141413` | `#FAF9F5` |
303| `color-background-ghost` | `#FFFFFF (0%)` | `#30302E (0%)` |
304| `color-background-info` | `#D6E4F6` | `#253E5F` |
305| `color-background-danger` | `#F7ECEC` | `#602A28` |
306| `color-background-success` | `#E9F1DC` | `#1B4614` |
307| `color-background-warning` | `#F6EEDF` | `#483A0F` |
308| `color-background-disabled` | `#FFFFFF (50%)` | `#30302E (50%)` |
309| **Text** | | |
310| `color-text-primary` | `#141413` | `#FAF9F5` |
311| `color-text-secondary` | `#3D3D3A` | `#C2C0B6` |
312| `color-text-tertiary` | `#73726C` | `#9C9A92` |
313| `color-text-inverse` | `#FFFFFF` | `#141413` |
314| `color-text-ghost` | `#73726C (50%)` | `#9C9A92 (50%)` |
315| `color-text-info` | `#3266AD` | `#80AADD` |
316| `color-text-danger` | `#7F2C28` | `#EE8884` |
317| `color-text-success` | `#265B19` | `#7AB948` |
318| `color-text-warning` | `#5A4815` | `#D1A041` |
319| `color-text-disabled` | `#141413 (50%)` | `#FAF9F5 (50%)` |
320| **Border** | | |
321| `color-border-primary` | `#1F1E1D (40%)` | `#DEDCD1 (40%)` |
322| `color-border-secondary` | `#1F1E1D (30%)` | `#DEDCD1 (30%)` |
323| `color-border-tertiary` | `#1F1E1D (15%)` | `#DEDCD1 (15%)` |
324| `color-border-inverse` | `#FFFFFF (30%)` | `#141413 (15%)` |
325| `color-border-ghost` | `#1F1E1D (0%)` | `#DEDCD1 (0%)` |
326| `color-border-info` | `#4682D5` | `#4682D5` |
327| `color-border-danger` | `#A73D39` | `#CD5C58` |
328| `color-border-success` | `#437426` | `#599130` |
329| `color-border-warning` | `#805C1F` | `#A87829` |
330| `color-border-disabled` | `#1F1E1D (10%)` | `#DEDCD1 (10%)` |
331| **Ring** | | |
332| `color-ring-primary` | `#141413 (70%)` | `#FAF9F5 (70%)` |
333| `color-ring-secondary` | `#3D3D3A (70%)` | `#C2C0B6 (70%)` |
334| `color-ring-inverse` | `#FFFFFF (70%)` | `#141413 (70%)` |
335| `color-ring-info` | `#3266AD (50%)` | `#80AADD (50%)` |
336| `color-ring-danger` | `#A73D39 (50%)` | `#CD5C58 (50%)` |
337| `color-ring-success` | `#437426 (50%)` | `#599130 (50%)` |
338| `color-ring-warning` | `#805C1F (50%)` | `#A87829 (50%)` |
296| | Light mode | Dark mode |
297| :- | :- | :- |
298| **Background** | | |
299| `color-background-primary` | `#FFFFFF` | `#30302E` |
300| `color-background-secondary` | `#F5F4ED` | `#262624` |
301| `color-background-tertiary` | `#FAF9F5` | `#141413` |
302| `color-background-inverse` | `#141413` | `#FAF9F5` |
303| `color-background-ghost` | `#FFFFFF (0%)` | `#30302E (0%)` |
304| `color-background-info` | `#D6E4F6` | `#253E5F` |
305| `color-background-danger` | `#F7ECEC` | `#602A28` |
306| `color-background-success` | `#E9F1DC` | `#1B4614` |
307| `color-background-warning` | `#F6EEDF` | `#483A0F` |
308| `color-background-disabled` | `#FFFFFF (50%)` | `#30302E (50%)` |
309| **Text** | | |
310| `color-text-primary` | `#141413` | `#FAF9F5` |
311| `color-text-secondary` | `#3D3D3A` | `#C2C0B6` |
312| `color-text-tertiary` | `#73726C` | `#9C9A92` |
313| `color-text-inverse` | `#FFFFFF` | `#141413` |
314| `color-text-ghost` | `#73726C (50%)` | `#9C9A92 (50%)` |
315| `color-text-info` | `#3266AD` | `#80AADD` |
316| `color-text-danger` | `#7F2C28` | `#EE8884` |
317| `color-text-success` | `#265B19` | `#7AB948` |
318| `color-text-warning` | `#5A4815` | `#D1A041` |
319| `color-text-disabled` | `#141413 (50%)` | `#FAF9F5 (50%)` |
320| **Border** | | |
321| `color-border-primary` | `#1F1E1D (40%)` | `#DEDCD1 (40%)` |
322| `color-border-secondary` | `#1F1E1D (30%)` | `#DEDCD1 (30%)` |
323| `color-border-tertiary` | `#1F1E1D (15%)` | `#DEDCD1 (15%)` |
324| `color-border-inverse` | `#FFFFFF (30%)` | `#141413 (15%)` |
325| `color-border-ghost` | `#1F1E1D (0%)` | `#DEDCD1 (0%)` |
326| `color-border-info` | `#4682D5` | `#4682D5` |
327| `color-border-danger` | `#A73D39` | `#CD5C58` |
328| `color-border-success` | `#437426` | `#599130` |
329| `color-border-warning` | `#805C1F` | `#A87829` |
330| `color-border-disabled` | `#1F1E1D (10%)` | `#DEDCD1 (10%)` |
331| **Ring** | | |
332| `color-ring-primary` | `#141413 (70%)` | `#FAF9F5 (70%)` |
333| `color-ring-secondary` | `#3D3D3A (70%)` | `#C2C0B6 (70%)` |
334| `color-ring-inverse` | `#FFFFFF (70%)` | `#141413 (70%)` |
335| `color-ring-info` | `#3266AD (50%)` | `#80AADD (50%)` |
336| `color-ring-danger` | `#A73D39 (50%)` | `#CD5C58 (50%)` |
337| `color-ring-success` | `#437426 (50%)` | `#599130 (50%)` |
338| `color-ring-warning` | `#805C1F (50%)` | `#A87829 (50%)` |
339339 
340340### Typography tokens
341341 
342342Typography tokens include the font family, sizes, weights, and line heights.
343343 
344| Family | |
345| :----------------------------- | :----------------------------- |
346| `font-sans` | `"Anthropic Sans, sans-serif"` |
347| `font-mono` | `"ui-monospace, monospace"` |
348| **Weight** | |
349| `font-weight-normal` | `400` |
350| `font-weight-medium` | `500` |
351| `font-weight-semibold` | `600` |
352| `font-weight-bold` | `700` |
353| **Size** | |
354| `font-text-xs-size` | `12px` |
355| `font-text-sm-size` | `14px` |
356| `font-text-md-size` | `16px` |
357| `font-text-lg-size` | `20px` |
358| `font-heading-xs-size` | `12px` |
359| `font-heading-sm-size` | `14px` |
360| `font-heading-md-size` | `16px` |
361| `font-heading-lg-size` | `20px` |
362| `font-heading-xl-size` | `24px` |
363| `font-heading-2xl-size` | `28px` |
364| `font-heading-3xl-size` | `36px` |
365| **Line-height** | |
366| `font-text-xs-line-height` | `1.4` |
367| `font-text-sm-line-height` | `1.4` |
368| `font-text-md-line-height` | `1.4` |
369| `font-text-lg-line-height` | `1.25` |
370| `font-heading-xs-line-height` | `1.4` |
371| `font-heading-sm-line-height` | `1.4` |
372| `font-heading-md-line-height` | `1.4` |
373| `font-heading-lg-line-height` | `1.25` |
374| `font-heading-xl-line-height` | `1.25` |
375| `font-heading-2xl-line-height` | `1.1` |
376| `font-heading-3xl-line-height` | `1` |
344| Family | |
345| :- | :- |
346| `font-sans` | `"Anthropic Sans, sans-serif"` |
347| `font-mono` | `"ui-monospace, monospace"` |
348| **Weight** | |
349| `font-weight-normal` | `400` |
350| `font-weight-medium` | `500` |
351| `font-weight-semibold` | `600` |
352| `font-weight-bold` | `700` |
353| **Size** | |
354| `font-text-xs-size` | `12px` |
355| `font-text-sm-size` | `14px` |
356| `font-text-md-size` | `16px` |
357| `font-text-lg-size` | `20px` |
358| `font-heading-xs-size` | `12px` |
359| `font-heading-sm-size` | `14px` |
360| `font-heading-md-size` | `16px` |
361| `font-heading-lg-size` | `20px` |
362| `font-heading-xl-size` | `24px` |
363| `font-heading-2xl-size` | `28px` |
364| `font-heading-3xl-size` | `36px` |
365| **Line-height** | |
366| `font-text-xs-line-height` | `1.4` |
367| `font-text-sm-line-height` | `1.4` |
368| `font-text-md-line-height` | `1.4` |
369| `font-text-lg-line-height` | `1.25` |
370| `font-heading-xs-line-height` | `1.4` |
371| `font-heading-sm-line-height` | `1.4` |
372| `font-heading-md-line-height` | `1.4` |
373| `font-heading-lg-line-height` | `1.25` |
374| `font-heading-xl-line-height` | `1.25` |
375| `font-heading-2xl-line-height` | `1.1` |
376| `font-heading-3xl-line-height` | `1` |
377377 
378378### Radius tokens
379379 
380380Radius tokens provide border radius values.
381381 
382| Radius | |
383| :------------------- | :------- |
384| `border-radius-xs` | `4px` |
385| `border-radius-sm` | `6px` |
386| `border-radius-md` | `8px` |
387| `border-radius-lg` | `10px` |
388| `border-radius-xl` | `12px` |
382| Radius | |
383| :- | :- |
384| `border-radius-xs` | `4px` |
385| `border-radius-sm` | `6px` |
386| `border-radius-md` | `8px` |
387| `border-radius-lg` | `10px` |
388| `border-radius-xl` | `12px` |
389389| `border-radius-full` | `9999px` |
390390 
391391### Border width tokens
from line 392
392392 
393393Border width tokens provide border width values.
394394 
395| | |
396| :--------------------- | :------ |
395| | |
396| :- | :- |
397397| `border-width-regular` | `0.5px` |
398398 
399399### Shadow tokens
from line 400
400400 
401401Shadow tokens provide drop-shadow values.
402402 
403| | |
404| :---------------- | :----------------------------------------------------------------------- |
405| `shadow-hairline` | `0 1px 2px 0 rgba(0, 0, 0, 0.05)` |
406| `shadow-sm` | `0 1px 3px 0 rgba(0, 0, 0, 0.1), 0 1px 2px -1px rgba(0, 0, 0, 0.1)` |
407| `shadow-md` | `0 4px 6px -1px rgba(0, 0, 0, 0.1), 0 2px 4px -2px rgba(0, 0, 0, 0.1)` |
408| `shadow-lg` | `0 10px 15px -3px rgba(0, 0, 0, 0.1), 0 4px 6px -4px rgba(0, 0, 0, 0.1)` |
403| | |
404| :- | :- |
405| `shadow-hairline` | `0 1px 2px 0 rgba(0, 0, 0, 0.05)` |
406| `shadow-sm` | `0 1px 3px 0 rgba(0, 0, 0, 0.1), 0 1px 2px -1px rgba(0, 0, 0, 0.1)` |
407| `shadow-md` | `0 4px 6px -1px rgba(0, 0, 0, 0.1), 0 2px 4px -2px rgba(0, 0, 0, 0.1)` |
408| `shadow-lg` | `0 10px 15px -3px rgba(0, 0, 0, 0.1), 0 4px 6px -4px rgba(0, 0, 0, 0.1)` |
409409 
410410### Example usage
411411 

connectors/building/mcp-apps/external-links Changed · +4 / -4 lines

from line 16
1616 
1717Each entry must be an HTTPS origin or a custom URI scheme:
1818 
19| Entry shape | Example | Matches |
20| ----------------- | ------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
21| HTTPS origin | `https://docs.example.com` | Any `https://` URL whose hostname is exactly `docs.example.com`, case-insensitive. Subdomains don't match implicitly, so list each one you need. Port isn't compared. |
22| Custom URI scheme | `example-app` or `example-app:` | Any URL with the scheme `example-app:`, typically a deep link into your native mobile or desktop app. |
19| Entry shape | Example | Matches |
20| - | - | - |
21| HTTPS origin | `https://docs.example.com` | Any `https://` URL whose hostname is exactly `docs.example.com`, case-insensitive. Subdomains don't match implicitly, so list each one you need. Port isn't compared. |
22| Custom URI scheme | `example-app` or `example-app:` | Any URL with the scheme `example-app:`, typically a deep link into your native mobile or desktop app. |
2323 
2424Entries that don't fit one of these shapes are ignored. This includes bare hostnames such as `example.com`, `http://` origins, and malformed values.
2525 

connectors/building/mcp-apps/getting-started Changed · +5 / -5 lines

from line 32
3232 <Step title="Add an example server">
3333 Add one of these example servers to your `claude_desktop_config.json`:
3434 
35 | Example | Description |
36 | ------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------- |
35 | Example | Description |
36 | - | - |
3737 | [Customer Segmentation](https://github.com/modelcontextprotocol/ext-apps/tree/main/examples/customer-segmentation-server) | Data visualization with scatter charts and clustering analysis |
38 | [Map](https://github.com/modelcontextprotocol/ext-apps/tree/main/examples/map-server) | Interactive 3D globe viewer using CesiumJS |
39 | [ShaderToy](https://github.com/modelcontextprotocol/ext-apps/tree/main/examples/shadertoy-server) | Real-time GLSL shader compilation and display |
40 | [Sheet Music](https://github.com/modelcontextprotocol/ext-apps/tree/main/examples/sheet-music-server) | ABC notation rendering with interactive audio playback |
38 | [Map](https://github.com/modelcontextprotocol/ext-apps/tree/main/examples/map-server) | Interactive 3D globe viewer using CesiumJS |
39 | [ShaderToy](https://github.com/modelcontextprotocol/ext-apps/tree/main/examples/shadertoy-server) | Real-time GLSL shader compilation and display |
40 | [Sheet Music](https://github.com/modelcontextprotocol/ext-apps/tree/main/examples/sheet-music-server) | ABC notation rendering with interactive audio playback |
4141 
4242 The MCP Apps repository has [more examples](https://github.com/modelcontextprotocol/ext-apps/tree/main/examples), each with a ready-to-use config snippet. The config entry for each example in the table runs its server with `npx`, which fetches the latest published version each time. Pin a version, such as `@modelcontextprotocol/[email protected]`, if you keep an entry beyond trying it out:
4343 

connectors/building/mcp-apps/transparent-theming Changed · +4 / -4 lines

from line 62
6262 
6363Claude passes a [`hostContext`](https://modelcontextprotocol.github.io/ext-apps/api/interfaces/app.McpUiHostContext.html) object to your widget during the [`connect()`](https://modelcontextprotocol.github.io/ext-apps/api/classes/app.App.html#connect) handshake. The fields relevant to theming are:
6464 
65| Field | Contents |
66| :----------------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------- |
67| `theme` | `"light"` or `"dark"` |
65| Field | Contents |
66| :- | :- |
67| `theme` | `"light"` or `"dark"` |
6868| `styles.variables` | CSS custom properties: `--color-background-*`, `--color-text-*`, `--color-border-*`, `--color-ring-*`, `--font-*`, `--border-radius-*`, `--border-width-*` |
69| `styles.css.fonts` | `@font-face` rules for Anthropic Sans, served from `https://assets.claude.ai` |
69| `styles.css.fonts` | `@font-face` rules for Anthropic Sans, served from `https://assets.claude.ai` |
7070 
7171The [Style variables](/docs/connectors/building/mcp-apps/design-guidelines#style-variables) section of the design guidelines lists every variable and its light- and dark-mode value.
7272 

connectors/building/mcpb Changed · +22 / -22 lines

from line 31
3131 
3232The table lists the needs that point to each option.
3333 
34| Choose MCPB when you need | Choose a remote connector when you need |
35| --------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------- |
34| Choose MCPB when you need | Choose a remote connector when you need |
35| - | - |
3636| Access to systems behind your firewall, such as your issue tracker, internal wikis, and private databases | Cloud services and public APIs with centralized infrastructure |
37| Authentication via existing SSO and browser sessions, no token management | OAuth flows with server-side token management |
38| Zero-trust compliance inside corporate network boundaries | Distribution across Claude on web, mobile, and desktop |
39| Direct filesystem access for code editing and Git operations | Centralized updates pushed to all users |
40| Integration with locally installed tools, such as Docker, IDEs, and databases | Public-facing integrations used by multiple organizations |
41| Hardware integration and desktop application control | |
42| Privacy-sensitive operations that should not leave the user's machine | |
43| One-click install with bundled Node.js runtime, no dependencies to manage | |
44| No cloud infrastructure, VPN configuration, or firewall rules | |
45| Organization-level admin controls, such as custom uploads and allowlists | |
46| Full control over authentication, authorization, and audit logs | |
37| Authentication via existing SSO and browser sessions, no token management | OAuth flows with server-side token management |
38| Zero-trust compliance inside corporate network boundaries | Distribution across Claude on web, mobile, and desktop |
39| Direct filesystem access for code editing and Git operations | Centralized updates pushed to all users |
40| Integration with locally installed tools, such as Docker, IDEs, and databases | Public-facing integrations used by multiple organizations |
41| Hardware integration and desktop application control | |
42| Privacy-sensitive operations that should not leave the user's machine | |
43| One-click install with bundled Node.js runtime, no dependencies to manage | |
44| No cloud infrastructure, VPN configuration, or firewall rules | |
45| Organization-level admin controls, such as custom uploads and allowlists | |
46| Full control over authentication, authorization, and audit logs | |
4747 
4848## Build the bundle
4949 
from line 105
105105 
106106The `manifest.json` file is required metadata describing what your MCPB does, how to run it, which tools it provides, and what configuration it needs. These references document it:
107107 
108| Reference | Contents |
109| ---------------------------------------------------------------------------------------- | --------------------------- |
108| Reference | Contents |
109| - | - |
110110| [MCPB Manifest Spec](https://github.com/modelcontextprotocol/mcpb/blob/main/MANIFEST.md) | Full schema with all fields |
111| [Example manifests](https://github.com/modelcontextprotocol/mcpb/tree/main/examples) | Real-world implementations |
112| [CLI documentation](https://github.com/modelcontextprotocol/mcpb/blob/main/CLI.md) | Command reference |
111| [Example manifests](https://github.com/modelcontextprotocol/mcpb/tree/main/examples) | Real-world implementations |
112| [CLI documentation](https://github.com/modelcontextprotocol/mcpb/blob/main/CLI.md) | Command reference |
113113 
114114### Add an icon
115115 
116116Icons are optional but recommended. Place `icon.png` in your bundle root and reference it in `manifest.json`. The icon must meet these requirements:
117117 
118| Requirement | Value |
119| ----------- | ---------------------------------------- |
120| File name | `icon.png`, or a custom path |
121| Size | 512×512px recommended, 256×256px minimum |
122| Format | PNG with transparency |
123| Location | Bundle root or specified path |
118| Requirement | Value |
119| - | - |
120| File name | `icon.png`, or a custom path |
121| Size | 512×512px recommended, 256×256px minimum |
122| Format | PNG with transparency |
123| Location | Bundle root or specified path |
124124 
125125You can also provide multiple icon variants for different sizes and for light and dark themes. See the [manifest spec icons section](https://github.com/modelcontextprotocol/mcpb/blob/main/MANIFEST.md#icons) for variant syntax and best practices.
126126 

connectors/custom/add-unlisted Changed · +7 / -7 lines

from line 18
1818 
1919A connector by URL suits internet-hosted services and public APIs. A desktop extension suits access to local files or tools, sensitive enterprise data, and work that needs offline capability.
2020 
21| You have | Use | Works in |
22| ------------------------------ | --------------------------------------------------------------------------------------------- | ---------------------------------------------- |
23| The URL of a remote MCP server | [Add a connector by URL](#add-a-connector-by-url) | Free, Pro, Max, Team, and Enterprise plans |
24| A desktop extension | [Install a local connector in the desktop app](#install-a-local-connector-in-the-desktop-app) | The Claude desktop app, signed in to claude.ai |
21| You have | Use | Works in |
22| - | - | - |
23| The URL of a remote MCP server | [Add a connector by URL](#add-a-connector-by-url) | Free, Pro, Max, Team, and Enterprise plans |
24| A desktop extension | [Install a local connector in the desktop app](#install-a-local-connector-in-the-desktop-app) | The Claude desktop app, signed in to claude.ai |
2525 
2626## Add a connector by URL
2727 
from line 171
171171 
172172Claude sends the value exactly as you enter it. It doesn't add an authentication scheme or any other prefix. For an `Authorization` header, include the scheme in the value, as this table shows.
173173 
174| You enter | Claude sends |
175| ------------------- | ---------------------------------- |
174| You enter | Claude sends |
175| - | - |
176176| `Bearer your-token` | `Authorization: Bearer your-token` |
177| `your-token` | `Authorization: your-token` |
177| `your-token` | `Authorization: your-token` |
178178 
179179Most servers that use bearer tokens reject a value without the `Bearer ` scheme. If your server's documentation shows `Authorization: Bearer YOUR_TOKEN`, enter `Bearer ` followed by your token, including the space. The same applies to Basic authentication, where you enter `Basic ` followed by the base64-encoded credentials.
180180 

connectors/github/index Changed · +6 / -6 lines

from line 117
117117 
118118The table lists what the integration reads from a repository and what it leaves out.
119119 
120| Retrieved | Not retrieved |
121| -------------- | ------------------- |
122| File names | Commit history |
123| File contents | Pull requests |
124| Branch content | Issues |
125| | Repository metadata |
120| Retrieved | Not retrieved |
121| - | - |
122| File names | Commit history |
123| File contents | Pull requests |
124| Branch content | Issues |
125| | Repository metadata |
126126 
127127## Best practices
128128 

connectors/google/drive Changed · +9 / -9 lines

from line 36
3636 
3737With the connector turned on in a conversation, Claude can search your Drive, list your recent files, check a file's details and who it's shared with, and read a file's content. The table shows which file types Claude can read this way.
3838 
39| File type | Claude can read it |
40| ------------------------------------------------------ | ------------------ |
41| Google Docs | Yes |
42| Google Sheets | Yes |
43| Google Slides | Yes |
44| PDF | Yes |
45| Word, Excel, and PowerPoint files | Yes |
46| OpenDocument text, spreadsheet, and presentation files | Yes |
47| PNG and JPEG images | Yes |
39| File type | Claude can read it |
40| - | - |
41| Google Docs | Yes |
42| Google Sheets | Yes |
43| Google Slides | Yes |
44| PDF | Yes |
45| Word, Excel, and PowerPoint files | Yes |
46| OpenDocument text, spreadsheet, and presentation files | Yes |
47| PNG and JPEG images | Yes |
4848 
4949Two limits apply to every type:
5050 

connectors/mcp-tunnels/oauth Changed · +6 / -6 lines

from line 39
3939 
4040When you add the tunneled MCP server as a custom connector in [**Organization settings > Connectors**](https://claude.ai/admin-settings/connectors), turn on **Tunnel OAuth configuration** in the connector dialog. The values you enter replace the ones Claude would otherwise read from the authorization server's metadata. Anthropic enables this option for each organization in the research preview on request, so if the toggle does not appear in the dialog, contact your Anthropic account team.
4141 
42| Field | What to enter | Example |
43| ------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------- |
44| **Issuer** | The issuer identifier your authorization server puts in its metadata and tokens. This can be an internal URL, because Claude uses it for validation rather than as an address to connect to. | `https://sso.example.corp:8443` |
45| **Authorization endpoint** | The sign-in URL that members' browsers are redirected to. It must be loadable from their devices, on the public internet or your corporate network. | `https://sso.example.corp/authorize` |
46| **Token endpoint** | The token endpoint Claude exchanges the authorization code at. Either the endpoint as reached through the tunnel (an `https://` URL under your tunnel domain), or a public `https://` URL on the same origin (scheme, host, and port) as the **Authorization endpoint**. | `https://auth.abc123.tunnel.anthropic.com/oauth/token` |
42| Field | What to enter | Example |
43| - | - | - |
44| **Issuer** | The issuer identifier your authorization server puts in its metadata and tokens. This can be an internal URL, because Claude uses it for validation rather than as an address to connect to. | `https://sso.example.corp:8443` |
45| **Authorization endpoint** | The sign-in URL that members' browsers are redirected to. It must be loadable from their devices, on the public internet or your corporate network. | `https://sso.example.corp/authorize` |
46| **Token endpoint** | The token endpoint Claude exchanges the authorization code at. Either the endpoint as reached through the tunnel (an `https://` URL under your tunnel domain), or a public `https://` URL on the same origin (scheme, host, and port) as the **Authorization endpoint**. | `https://auth.abc123.tunnel.anthropic.com/oauth/token` |
4747| **Registration endpoint (optional)** | The dynamic client registration endpoint, under the same rule as **Token endpoint**: a URL under your tunnel domain or one on the **Authorization endpoint**'s origin. Leave it blank if you select **Use your own OAuth client** and enter a client ID you registered with the authorization server yourself. | `https://auth.abc123.tunnel.anthropic.com/oauth/register` |
48| **Requested scopes** | The scopes Claude requests at sign-in, separated by spaces. | `openid wiki:read wiki:write` |
48| **Requested scopes** | The scopes Claude requests at sign-in, separated by spaces. | `openid wiki:read wiki:write` |
4949 
5050The paths after the hostname (`/authorize`, `/oauth/token`, and so on) are whatever your authorization server uses. Copy them from its metadata document, usually served at `/.well-known/oauth-authorization-server` or `/.well-known/openid-configuration`, and change only the scheme and host.
5151 

connectors/mcp-tunnels/overview Changed · +18 / -18 lines

from line 43
4343 
4444### Network requirements
4545 
46| Component | Destination | Port and protocol | Used during |
47| --------------- | ---------------------------------------------------- | ---------------------------- | ---------------------------- |
48| Setup component | `api.anthropic.com` | 443 TCP | Provisioning, token rotation |
49| cloudflared | Tunnel edge (`198.41.192.0/19`, `2606:4700:a0::/44`) | 7844 TCP and UDP | Runtime |
50| Proxy | Your MCP servers | As configured in your routes | Runtime |
46| Component | Destination | Port and protocol | Used during |
47| - | - | - | - |
48| Setup component | `api.anthropic.com` | 443 TCP | Provisioning, token rotation |
49| cloudflared | Tunnel edge (`198.41.192.0/19`, `2606:4700:a0::/44`) | 7844 TCP and UDP | Runtime |
50| Proxy | Your MCP servers | As configured in your routes | Runtime |
5151 
5252No inbound rules are required. See [Cloudflare's tunnel firewall documentation](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/configure-tunnels/tunnel-with-firewall/) for the authoritative edge IP list.
5353 
from line 55
5555 
5656Three independent layers protect every request through a tunnel.
5757 
58| Layer | Protects against |
59| --------------------------------------------------------------------------------- | ------------------------------------------------------------------------ |
60| Outer mutual TLS between Anthropic and the transport provider, with IP validation | Unauthorized clients reaching the tunnel |
61| Inner TLS from Anthropic's backend to your proxy | Payload inspection by the transport provider or any network intermediary |
62| OAuth on each MCP server | Unauthorized use of MCP tools by traffic that has reached the server |
58| Layer | Protects against |
59| - | - |
60| Outer mutual TLS between Anthropic and the transport provider, with IP validation | Unauthorized clients reaching the tunnel |
61| Inner TLS from Anthropic's backend to your proxy | Payload inspection by the transport provider or any network intermediary |
62| OAuth on each MCP server | Unauthorized use of MCP tools by traffic that has reached the server |
6363 
6464The proxy terminates inner TLS with a certificate signed by a certificate authority (CA) that the setup component generates inside your environment and registers with Anthropic. Only your deployment holds the private keys, so Cloudflare carries ciphertext and cannot read MCP requests or responses. Anthropic does not connect to a tunnel until a CA certificate is registered for it. Cloudflare does receive connection metadata: the egress IP address and a host fingerprint of the machine running cloudflared, connection timing and byte volume, and the `tunnel.anthropic.com` subdomain assigned to your tunnel. Cloudflare acts as a subprocessor for this research preview.
6565 
from line 67
6767 
6868### Shared responsibility
6969 
70| Anthropic handles | Your organization handles |
71| --------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------- |
72| Restricting tunnel access so that only Anthropic can connect | All content and traffic that transits your tunnel, and compliance with applicable third-party acceptable-use policies, including Cloudflare's |
73| Validating your CA certificate before connecting to your proxy | Securing the tunnel token, the Tunnels API key, and the TLS private keys |
74| Sending Claude's requests only to tunnels that your organization owns | Renewing the server certificate before it expires |
75| | Requiring OAuth on each MCP server and limiting each server to the tools it needs |
76| | Restricting network access for the proxy hosts and MCP servers |
77| | Notifying Anthropic if you suspect a compromise |
70| Anthropic handles | Your organization handles |
71| - | - |
72| Restricting tunnel access so that only Anthropic can connect | All content and traffic that transits your tunnel, and compliance with applicable third-party acceptable-use policies, including Cloudflare's |
73| Validating your CA certificate before connecting to your proxy | Securing the tunnel token, the Tunnels API key, and the TLS private keys |
74| Sending Claude's requests only to tunnels that your organization owns | Renewing the server certificate before it expires |
75| | Requiring OAuth on each MCP server and limiting each server to the tools it needs |
76| | Restricting network access for the proxy hosts and MCP servers |
77| | Notifying Anthropic if you suspect a compromise |
7878 
7979<Warning>
8080 An attacker who obtains your tunnel token and one of your TLS private keys could impersonate your proxy and read MCP request payloads, including OAuth tokens. Store both with your organization's secrets-management controls, restrict file permissions, and rotate them on a schedule and immediately after any suspected exposure. See [Rotate credentials](/docs/connectors/mcp-tunnels/setup#rotate-credentials).

connectors/microsoft/365 Changed · +6 / -6 lines

from line 15
1515 
1616All access is delegated: Claude acts on your behalf and can read or change only what your Microsoft 365 account can already read or change. The table lists what Claude can do in each service; the write column applies only when your administrators have turned on [write actions](#write-actions).
1717 
18| Service | Read and search | Write |
19| --------------------------- | --------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- |
20| **SharePoint and OneDrive** | Search and analyze documents across SharePoint sites and OneDrive libraries | Create and update files in SharePoint |
21| **Outlook** | Search email threads and archived email | Send mail and manage drafts, labels, mail filters, and automatic replies; create, update, and delete calendar events and find meeting times |
22| **Teams Calendar** | Review meeting information, summaries, and attendance | None |
23| **Teams Chat** | Read channel and chat discussions | Send chat and channel messages |
18| Service | Read and search | Write |
19| - | - | - |
20| **SharePoint and OneDrive** | Search and analyze documents across SharePoint sites and OneDrive libraries | Create and update files in SharePoint |
21| **Outlook** | Search email threads and archived email | Send mail and manage drafts, labels, mail filters, and automatic replies; create, update, and delete calendar events and find meeting times |
22| **Teams Calendar** | Review meeting information, summaries, and attendance | None |
23| **Teams Chat** | Read channel and chat discussions | Send chat and channel messages |
2424 
2525## Set up the connector
2626 

cowork/guide/dispatch Changed · +11 / -11 lines

from line 38
3838 
3939The Dispatch agent routes each child task to the surface that fits it.
4040 
41| Task type | Runs in | Examples |
42| -------------- | -------------------------------------------------------------------------------------- | ------------------------------------------ |
43| Coding work | Code, against a workspace you've already set up | Fix a bug, open a pull request, run tests |
41| Task type | Runs in | Examples |
42| - | - | - |
43| Coding work | Code, against a workspace you've already set up | Fix a bug, open a pull request, run tests |
4444| Knowledge work | Cowork, in the [project](/docs/cowork/guide/projects) you specify (or your default project) | Research, write a document, organize files |
4545 
4646When starting a task, you can tell the agent which Code workspace or Cowork project to use. If you don't, it lists what's available and chooses.
from line 49
4949 
5050Each child task shows its current state in the sidebar. Select any task to open its full transcript, the steps Claude took, and any files it produced.
5151 
52| State | Meaning |
53| --------------- | ---------------------------------------------------------- |
54| Running | Claude is actively working on the task |
55| Awaiting input | The task needs information from you before it can continue |
56| Awaiting answer | The task asked you a question and is waiting for a reply |
57| Completed | The task finished |
58| Error | The task stopped because something went wrong |
59| Archived | You marked the task as done and set it aside |
52| State | Meaning |
53| - | - |
54| Running | Claude is actively working on the task |
55| Awaiting input | The task needs information from you before it can continue |
56| Awaiting answer | The task asked you a question and is waiting for a reply |
57| Completed | The task finished |
58| Error | The task stopped because something went wrong |
59| Archived | You marked the task as done and set it aside |
6060 
6161## Approve actions Dispatch needs
6262 

cowork/guide/plugins Changed · +11 / -11 lines

from line 12
1212 
1313A plugin can contain any combination of the following components.
1414 
15| Component | What it adds |
16| ---------- | ---------------------------------------------------------- |
17| Skills | Reusable instructions that teach Claude a workflow |
15| Component | What it adds |
16| - | - |
17| Skills | Reusable instructions that teach Claude a workflow |
1818| Connectors | MCP servers that give Claude access to an external service |
19| Agents | Specialized subagents Claude can delegate to |
20| Hooks | Scripts that run at defined points in a session |
19| Agents | Specialized subagents Claude can delegate to |
20| Hooks | Scripts that run at defined points in a session |
2121 
2222After installing, open the plugin to see what it provides. Skills and agents appear as tabs; connectors and hooks have their own pages.
2323 
from line 71
7171 
7272The following are the default limits for plugin packages and marketplaces.
7373 
74| Limit | Value |
75| ---------------------------------- | ------ |
74| Limit | Value |
75| - | - |
7676| Plugin package size (uncompressed) | 200 MB |
77| Files per plugin package | 5,000 |
78| Marketplace repository archive | 512 MB |
79| Plugins per marketplace | 500 |
80| Marketplaces you can add | 25 |
77| Files per plugin package | 5,000 |
78| Marketplace repository archive | 512 MB |
79| Plugins per marketplace | 500 |
80| Marketplaces you can add | 25 |
8181 
8282The in-app skill viewer previews individual files up to 1 MB. Larger files appear in the file list as "too large to preview" but are still available to Claude at runtime.
8383 

cowork/guide/projects Changed · +12 / -12 lines

from line 10
1010 
1111Each project bundles the following, and you can change any of it after creation.
1212 
13| Item | Purpose |
14| ------------------ | ------------------------------------------------------------------------------------- |
15| Description | What the project is for; Dispatch reads it when choosing a project for a task |
16| Folders | One or more local folders Claude can read and write inside this project's sessions |
17| Instructions | Standing guidance applied to every session in the project |
18| Links | Reference URLs (documents, dashboards, repositories) Claude can consult |
13| Item | Purpose |
14| - | - |
15| Description | What the project is for; Dispatch reads it when choosing a project for a task |
16| Folders | One or more local folders Claude can read and write inside this project's sessions |
17| Instructions | Standing guidance applied to every session in the project |
18| Links | Reference URLs (documents, dashboards, repositories) Claude can consult |
1919| Projects from Chat | Projects you made in Chat (claude.ai) whose knowledge this Cowork project can draw on |
20| Memory | A project-scoped memory store that persists across sessions |
20| Memory | A project-scoped memory store that persists across sessions |
2121 
2222## Create a project
2323 
from line 55
5555 
5656A Cowork project is not the same thing as a project on claude.ai. They're stored separately and have different capabilities.
5757 
58| | Cowork project | claude.ai project |
59| ------------------------ | --------------------- | --------------------------- |
60| Lives | On your computer only | In your Claude account |
61| Holds local folders | Yes | No |
62| Shareable with teammates | No | Yes, on Team and Enterprise |
58| | Cowork project | claude.ai project |
59| - | - | - |
60| Lives | On your computer only | In your Claude account |
61| Holds local folders | Yes | No |
62| Shareable with teammates | No | Yes, on Team and Enterprise |
6363 
6464You can link a claude.ai project into a Cowork project so Cowork sessions can draw on its knowledge. Linking doesn't merge them; the claude.ai project stays where it is.
6565 

cowork/monitoring Changed · +83 / -83 lines

from line 16
1616 
17172. Configure the following fields:
1818 
19 | Field | Description | Example |
20 | ----------------- | ----------------------------------------- | ----------------------------------- |
21 | **OTLP endpoint** | Your OpenTelemetry collector URL | `http://collector.example.com:4318` |
22 | **OTLP protocol** | Transport protocol | `http/json` or `http/protobuf` |
23 | **OTLP headers** | Authentication headers for your collector | `Authorization=Bearer your-token` |
19 | Field | Description | Example |
20 | - | - | - |
21 | **OTLP endpoint** | Your OpenTelemetry collector URL | `http://collector.example.com:4318` |
22 | **OTLP protocol** | Transport protocol | `http/json` or `http/protobuf` |
23 | **OTLP headers** | Authentication headers for your collector | `Authorization=Bearer your-token` |
2424 
25253. Save your settings
2626 
from line 38
3838 
3939When a user submits a prompt, Cowork may make multiple API calls and run several tools. The `prompt.id` attribute links all events back to the single prompt that triggered them.
4040 
41| Attribute | Description |
42| ----------- | ------------------------------------------------------------------------------------ |
41| Attribute | Description |
42| - | - |
4343| `prompt.id` | UUID v4 identifier linking all events produced while processing a single user prompt |
4444 
4545To trace all activity triggered by a single prompt, filter your events by a specific `prompt.id` value.
from line 50
5050 
5151All events include these attributes:
5252 
53| Attribute | Description |
54| ---------------------- | -------------------------------------------------------------------------------------------- |
55| `session.id` | Unique session identifier |
56| `organization.id` | Organization UUID |
57| `user.account_uuid` | User's account UUID |
58| `user.account_id` | Account ID in tagged format matching Anthropic admin APIs (for example, `user_01BWBeN28...`) |
59| `user.id` | Anonymous device/installation identifier |
60| `user.email` | User email |
61| `workspace.host_paths` | Host workspace directories selected in the desktop app (string array) |
62| `terminal.type` | Terminal type (`non-interactive` for Cowork) |
53| Attribute | Description |
54| - | - |
55| `session.id` | Unique session identifier |
56| `organization.id` | Organization UUID |
57| `user.account_uuid` | User's account UUID |
58| `user.account_id` | Account ID in tagged format matching Anthropic admin APIs (for example, `user_01BWBeN28...`) |
59| `user.id` | Anonymous device/installation identifier |
60| `user.email` | User email |
61| `workspace.host_paths` | Host workspace directories selected in the desktop app (string array) |
62| `terminal.type` | Terminal type (`non-interactive` for Cowork) |
6363 
6464<Note>
6565 The account attributes — `organization.id`, `user.account_uuid`, `user.account_id`, and `user.email` — are populated from the user's Anthropic account, so they appear on first-party deployments only. On [third-party deployments](/docs/third-party/claude-desktop/overview) there is no Anthropic account and these attributes are absent; instead, the export carries the signed-in user's identity as the `enduser.id` resource attribute, described under [User attribution](/docs/third-party/claude-desktop/telemetry#user-attribution). The `process.owner` resource attribute (the operating-system login name) is standard OpenTelemetry process metadata and is present on all deployments.
from line 75
7575 
7676All [standard attributes](#standard-attributes), plus:
7777 
78| Attribute | Description |
79| ----------------- | --------------------------------------------------------------------- |
80| `event.timestamp` | ISO 8601 timestamp |
81| `event.sequence` | Monotonically increasing counter for ordering events within a session |
82| `prompt_length` | Length of the prompt |
83| `prompt` | Prompt content |
78| Attribute | Description |
79| - | - |
80| `event.timestamp` | ISO 8601 timestamp |
81| `event.sequence` | Monotonically increasing counter for ordering events within a session |
82| `prompt_length` | Length of the prompt |
83| `prompt` | Prompt content |
8484 
8585### Model response event
8686 
from line 92
9292 
9393All [standard attributes](#standard-attributes), plus:
9494 
95| Attribute | Description |
96| ----------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
97| `event.timestamp` | ISO 8601 timestamp |
98| `event.sequence` | Monotonically increasing counter for ordering events within a session |
99| `model` | Model that produced the response |
100| `request_id` | API request identifier |
101| `response_length` | Length of the response |
102| `response` | Model response text. Includes text output only; thinking content is excluded. Truncated to 60 KB. When model response capture is disabled, the value is the literal string `<REDACTED>`. |
95| Attribute | Description |
96| - | - |
97| `event.timestamp` | ISO 8601 timestamp |
98| `event.sequence` | Monotonically increasing counter for ordering events within a session |
99| `model` | Model that produced the response |
100| `request_id` | API request identifier |
101| `response_length` | Length of the response |
102| `response` | Model response text. Includes text output only; thinking content is excluded. Truncated to 60 KB. When model response capture is disabled, the value is the literal string `<REDACTED>`. |
103103 
104104Model responses are captured when [`otlpContentCapture`](/docs/third-party/claude-desktop/telemetry#content-capture) includes `assistantResponses`, and also whenever user prompts are captured.
105105 
from line 113
113113 
114114All [standard attributes](#standard-attributes), plus:
115115 
116| Attribute | Description |
117| ------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
118| `event.timestamp` | ISO 8601 timestamp |
119| `event.sequence` | Monotonically increasing counter for ordering events within a session |
120| `tool_name` | Name of the tool |
121| `success` | `"true"` or `"false"` |
122| `duration_ms` | Execution time in milliseconds |
123| `error` | Error message (if failed) |
124| `decision_type` | Either `"accept"` or `"reject"` |
125| `decision_source` | How the decision was made — `"config"`, `"hook"`, `"user_permanent"`, `"user_temporary"`, `"user_abort"`, or `"user_reject"` |
126| `tool_result_size_bytes` | Size of the tool result in bytes |
127| `mcp_server_scope` | MCP server scope identifier (for MCP tools) |
128| `tool_parameters` | JSON string containing tool-specific parameters, including `mcp_server_name` and `mcp_tool_name` for MCP tools |
129| `tool_input` | JSON-serialized tool arguments. Individual strings over 512 characters are truncated; entire string limited to \~4K characters. Applies to all tools including MCP tools. |
116| Attribute | Description |
117| - | - |
118| `event.timestamp` | ISO 8601 timestamp |
119| `event.sequence` | Monotonically increasing counter for ordering events within a session |
120| `tool_name` | Name of the tool |
121| `success` | `"true"` or `"false"` |
122| `duration_ms` | Execution time in milliseconds |
123| `error` | Error message (if failed) |
124| `decision_type` | Either `"accept"` or `"reject"` |
125| `decision_source` | How the decision was made — `"config"`, `"hook"`, `"user_permanent"`, `"user_temporary"`, `"user_abort"`, or `"user_reject"` |
126| `tool_result_size_bytes` | Size of the tool result in bytes |
127| `mcp_server_scope` | MCP server scope identifier (for MCP tools) |
128| `tool_parameters` | JSON string containing tool-specific parameters, including `mcp_server_name` and `mcp_tool_name` for MCP tools |
129| `tool_input` | JSON-serialized tool arguments. Individual strings over 512 characters are truncated; entire string limited to \~4K characters. Applies to all tools including MCP tools. |
130130 
131131### API request event
132132 
from line 138
138138 
139139All [standard attributes](#standard-attributes), plus:
140140 
141| Attribute | Description |
142| ----------------------- | --------------------------------------------------------------------- |
143| `event.timestamp` | ISO 8601 timestamp |
144| `event.sequence` | Monotonically increasing counter for ordering events within a session |
145| `model` | Model used (e.g., `claude-sonnet-5`) |
146| `cost_usd` | Estimated cost in USD |
147| `duration_ms` | Request duration in milliseconds |
148| `input_tokens` | Number of input tokens |
149| `output_tokens` | Number of output tokens |
150| `cache_read_tokens` | Number of tokens read from cache |
151| `cache_creation_tokens` | Number of tokens used for cache creation |
152| `speed` | `"fast"` or `"normal"` |
141| Attribute | Description |
142| - | - |
143| `event.timestamp` | ISO 8601 timestamp |
144| `event.sequence` | Monotonically increasing counter for ordering events within a session |
145| `model` | Model used (e.g., `claude-sonnet-5`) |
146| `cost_usd` | Estimated cost in USD |
147| `duration_ms` | Request duration in milliseconds |
148| `input_tokens` | Number of input tokens |
149| `output_tokens` | Number of output tokens |
150| `cache_read_tokens` | Number of tokens read from cache |
151| `cache_creation_tokens` | Number of tokens used for cache creation |
152| `speed` | `"fast"` or `"normal"` |
153153 
154154### API error event
155155 
from line 161
161161 
162162All [standard attributes](#standard-attributes), plus:
163163 
164| Attribute | Description |
165| ----------------- | --------------------------------------------------------------------- |
166| `event.timestamp` | ISO 8601 timestamp |
167| `event.sequence` | Monotonically increasing counter for ordering events within a session |
168| `model` | Model used |
169| `error` | Error message |
170| `status_code` | HTTP status code as a string, or `"undefined"` for non-HTTP errors |
171| `duration_ms` | Request duration in milliseconds |
172| `attempt` | Attempt number (for retried requests) |
173| `speed` | `"fast"` or `"normal"` |
164| Attribute | Description |
165| - | - |
166| `event.timestamp` | ISO 8601 timestamp |
167| `event.sequence` | Monotonically increasing counter for ordering events within a session |
168| `model` | Model used |
169| `error` | Error message |
170| `status_code` | HTTP status code as a string, or `"undefined"` for non-HTTP errors |
171| `duration_ms` | Request duration in milliseconds |
172| `attempt` | Attempt number (for retried requests) |
173| `speed` | `"fast"` or `"normal"` |
174174 
175175### Tool decision event
176176 
from line 182
182182 
183183All [standard attributes](#standard-attributes), plus:
184184 
185| Attribute | Description |
186| ----------------- | ------------------------------------------------------------------------------------------------------------------ |
187| `event.timestamp` | ISO 8601 timestamp |
188| `event.sequence` | Monotonically increasing counter for ordering events within a session |
189| `tool_name` | Name of the tool |
190| `decision` | Either `"accept"` or `"reject"` |
191| `source` | Decision source — `"config"`, `"hook"`, `"user_permanent"`, `"user_temporary"`, `"user_abort"`, or `"user_reject"` |
185| Attribute | Description |
186| - | - |
187| `event.timestamp` | ISO 8601 timestamp |
188| `event.sequence` | Monotonically increasing counter for ordering events within a session |
189| `tool_name` | Name of the tool |
190| `decision` | Either `"accept"` or `"reject"` |
191| `source` | Decision source — `"config"`, `"hook"`, `"user_permanent"`, `"user_temporary"`, `"user_abort"`, or `"user_reject"` |
192192 
193193## Event analysis
194194 
from line 216
216216 
217217All events are exported with the following resource attributes:
218218 
219| Attribute | Description |
220| ----------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
221| `service.name` | `cowork` |
222| `service.version` | Claude app version |
223| `host.arch` | Host architecture (e.g., `arm64`) |
224| `os.type` | Operating system type (e.g., `darwin`) |
225| `os.version` | Operating system version string |
226| `enduser.id` | The signed-in user's identity, on third-party deployments only. Controlled by the [`endUserAttribution`](/docs/third-party/claude-desktop/configuration#enduserattribution) setting; see [User attribution](/docs/third-party/claude-desktop/telemetry#user-attribution). |
227| `process.owner` | Operating-system login name |
219| Attribute | Description |
220| - | - |
221| `service.name` | `cowork` |
222| `service.version` | Claude app version |
223| `host.arch` | Host architecture (e.g., `arm64`) |
224| `os.type` | Operating system type (e.g., `darwin`) |
225| `os.version` | Operating system version string |
226| `enduser.id` | The signed-in user's identity, on third-party deployments only. Controlled by the [`endUserAttribution`](/docs/third-party/claude-desktop/configuration#enduserattribution) setting; see [User attribution](/docs/third-party/claude-desktop/telemetry#user-attribution). |
227| `process.owner` | Operating-system login name |
228228 
229229## Security and privacy
230230 

directory/publish Changed · +5 / -5 lines

from line 23
2323 
2424A plugin bundle is the main thing you submit: one listing that packages whatever the plugin contains, whether that's skills, an MCP connector reference, commands, agents, or any combination. If you also run the remote MCP server that plugin points at, you submit the server as its own MCP connector too. When you start a submission, the developer portal asks which kind you're submitting:
2525 
26| | Plugin bundle | MCP connector |
27| :------------------ | :------------------------------------------------------------------------------ | :------------------------------------------------------------------ |
28| What it is | A plugin folder with skills, commands, agents, hooks, and MCP server references | One remote MCP server that people connect to reach your app or data |
29| Where it comes from | A GitHub repository, which must be public before the listing goes live | The server's URL, with no repository needed |
30| How it's listed | As a plugin with all of its components | As a connector people connect to from the directory |
26| | Plugin bundle | MCP connector |
27| :- | :- | :- |
28| What it is | A plugin folder with skills, commands, agents, hooks, and MCP server references | One remote MCP server that people connect to reach your app or data |
29| Where it comes from | A GitHub repository, which must be public before the listing goes live | The server's URL, with no repository needed |
30| How it's listed | As a plugin with all of its components | As a connector people connect to from the directory |
3131 
3232If you have a remote MCP server, always submit it as an MCP connector, even when a plugin you're submitting already references it. Submitting the server as a connector gives your organization the connector's listing, its dashboard, and the option to pair it with your plugin:
3333 

directory/submission-status Changed · +19 / -19 lines

from line 16
1616 
1717Open the plugin from **Submissions** in the developer portal. The status appears next to the plugin's name, and the card under it says what happens next.
1818 
19| Status | What it means | Who acts next |
20| :---------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :---------------------------------------------------------------------------------------------------------------------------- |
21| **Draft** | Nothing has been sent to Anthropic yet | You. Select **Continue submission**. |
22| **Scanning** | You submitted, and the security scan is waiting to start or running. If a scan attempt fails on Anthropic's side or GitHub's, the directory retries it. | Anthropic. There's nothing to do on your side. |
23| **Needs changes** | The newest version didn't pass, or the scanner couldn't fetch or accept the plugin. The plugin's page names what to change. | You. [Fix a failed version](/docs/plugins/submit#fix-a-failed-version) covers pushing a fix and resubmitting. |
24| **In review** | An Anthropic reviewer is checking the listing. When the version was held, the card names the category it's held for. The reviewer's decision appears on the plugin's page. | Anthropic |
25| **Approved** | The version passed, and it isn't live yet. The card says who publishes it: an Anthropic reviewer, you, or the directory by itself. | Whoever the card names. [Publish a passing version](/docs/plugins/submit#publish-a-passing-version) explains the publish settings. |
26| **Published** | A version is live in the directory. The card also says what is happening with any newer version, such as being scanned, waiting with a reviewer, or not passing. A newer version that doesn't pass leaves the published one unaffected. | Nobody, unless the card names a newer version that needs changes |
27| **Not live yet** | The submission is marked published, and nothing is listed yet. The directory team has to list it. | Anthropic |
28| **Delisted** | The plugin isn't visible in the directory. Select **Relist plugin** to ask for it back. | You, if you want it listed again |
29| **Withdrawn** | Nothing is under review or listed | Nobody |
19| Status | What it means | Who acts next |
20| :- | :- | :- |
21| **Draft** | Nothing has been sent to Anthropic yet | You. Select **Continue submission**. |
22| **Scanning** | You submitted, and the security scan is waiting to start or running. If a scan attempt fails on Anthropic's side or GitHub's, the directory retries it. | Anthropic. There's nothing to do on your side. |
23| **Needs changes** | The newest version didn't pass, or the scanner couldn't fetch or accept the plugin. The plugin's page names what to change. | You. [Fix a failed version](/docs/plugins/submit#fix-a-failed-version) covers pushing a fix and resubmitting. |
24| **In review** | An Anthropic reviewer is checking the listing. When the version was held, the card names the category it's held for. The reviewer's decision appears on the plugin's page. | Anthropic |
25| **Approved** | The version passed, and it isn't live yet. The card says who publishes it: an Anthropic reviewer, you, or the directory by itself. | Whoever the card names. [Publish a passing version](/docs/plugins/submit#publish-a-passing-version) explains the publish settings. |
26| **Published** | A version is live in the directory. The card also says what is happening with any newer version, such as being scanned, waiting with a reviewer, or not passing. A newer version that doesn't pass leaves the published one unaffected. | Nobody, unless the card names a newer version that needs changes |
27| **Not live yet** | The submission is marked published, and nothing is listed yet. The directory team has to list it. | Anthropic |
28| **Delisted** | The plugin isn't visible in the directory. Select **Relist plugin** to ask for it back. | You, if you want it listed again |
29| **Withdrawn** | Nothing is under review or listed | Nobody |
3030 
3131**Approved** doesn't mean people can install the plugin. A plugin is installable only once its status is **Published**.
3232 
from line 36
3636 
3737A submission doesn't pass through every status in the table. Anthropic scans each connector submission automatically and, by default, lists it as a Community connector with no action from you. Some submissions also get a review from a person, and the statuses that mention a reviewer apply to those. [How Anthropic reviews directory submissions](/docs/directory/publish#prepare-for-review) describes both.
3838 
39| Status | What it means | Who acts next |
40| :-------------------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :----------------------- |
41| **Draft** | Nothing has been sent to Anthropic yet. A draft can have a reviewer's note if it was sent back and saved again. | You |
42| **In review** | A reviewer is checking the listing. Anthropic emails your primary contact if it needs anything. | Anthropic |
43| **Changes requested** | The reviewer left a note. Select **View feedback** on the card to read it, then address it and resubmit. | You |
44| **Not approved** | The reviewer's notes say why. Select **View feedback** to read them. You can edit the listing and resubmit. | You |
45| **Approved** | The review team cleared the listing, and it isn't in the directory yet. It goes live when someone who can edit the listing publishes it. If you edit the listing before you publish, it returns to draft for another review. | You. Select **Publish**. |
46| **Published** | The connector is live in the directory. If you submitted an edit, the card says whether that edit is in review, and the live listing stays until the edit is approved. | Nobody |
39| Status | What it means | Who acts next |
40| :- | :- | :- |
41| **Draft** | Nothing has been sent to Anthropic yet. A draft can have a reviewer's note if it was sent back and saved again. | You |
42| **In review** | A reviewer is checking the listing. Anthropic emails your primary contact if it needs anything. | Anthropic |
43| **Changes requested** | The reviewer left a note. Select **View feedback** on the card to read it, then address it and resubmit. | You |
44| **Not approved** | The reviewer's notes say why. Select **View feedback** to read them. You can edit the listing and resubmit. | You |
45| **Approved** | The review team cleared the listing, and it isn't in the directory yet. It goes live when someone who can edit the listing publishes it. If you edit the listing before you publish, it returns to draft for another review. | You. Select **Publish**. |
46| **Published** | The connector is live in the directory. If you submitted an edit, the card says whether that edit is in review, and the live listing stays until the edit is approved. | Nobody |
4747 
4848[Manage your directory listing](/docs/connectors/building/managing-your-listing) covers reviewer feedback, listing edits, and the health and usage metrics for a published connector.
4949 

government/account/profile Changed · +6 / -6 lines

from line 10
1010 
1111## What you'll see
1212 
13| Field | What it means | Where it comes from |
14| ---------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------- |
15| **Email** | The address you sign in with. It is the unique identifier for your account, and notifications such as sign-in links are sent to it. | Your agency's identity provider. |
16| **Organization** | The organization you belong to within your agency's tenant. A tenant is your agency's overall space in Claude for Government, and it can contain several organizations (for example, one per bureau or office). Your organization determines which administrators manage your access and which usage pool your activity draws from. | Set when your account was created or when directory sync placed you. |
17| **Role** | What you are allowed to manage. **User** means you can use Claude but do not administer anything. **Owner** means you can manage your organization's users, seats, and settings. **Primary Owner** is the same as Owner with a few additional safeguards: a primary owner cannot be removed by other owners, and each organization can have at most three of them. | Assigned by an organization owner or by directory sync. |
18| **Seat tier** | The allowance you have been given. A seat tier is a named package that sets two things for you: how much Claude usage you get (shown on the [Usage](/docs/government/account/usage) tab) and which Claude models you are allowed to use. The tiers themselves, their names, and what each one includes are defined by your agency, so the name you see here is specific to your deployment. | Assigned to you by an organization owner. |
13| Field | What it means | Where it comes from |
14| - | - | - |
15| **Email** | The address you sign in with. It is the unique identifier for your account, and notifications such as sign-in links are sent to it. | Your agency's identity provider. |
16| **Organization** | The organization you belong to within your agency's tenant. A tenant is your agency's overall space in Claude for Government, and it can contain several organizations (for example, one per bureau or office). Your organization determines which administrators manage your access and which usage pool your activity draws from. | Set when your account was created or when directory sync placed you. |
17| **Role** | What you are allowed to manage. **User** means you can use Claude but do not administer anything. **Owner** means you can manage your organization's users, seats, and settings. **Primary Owner** is the same as Owner with a few additional safeguards: a primary owner cannot be removed by other owners, and each organization can have at most three of them. | Assigned by an organization owner or by directory sync. |
18| **Seat tier** | The allowance you have been given. A seat tier is a named package that sets two things for you: how much Claude usage you get (shown on the [Usage](/docs/government/account/usage) tab) and which Claude models you are allowed to use. The tiers themselves, their names, and what each one includes are defined by your agency, so the name you see here is specific to your deployment. | Assigned to you by an organization owner. |
1919 
2020The name and avatar at the top come from your agency's directory. The avatar is generated from your name; you cannot upload a custom picture.
2121 

government/connectors/microsoft-365 Changed · +52 / -52 lines

from line 86
8686 
8787The connector calls Microsoft directly from each member's device, so devices need outbound HTTPS access to the Microsoft Entra and Microsoft Graph hosts for your cloud.
8888 
89| Azure cloud | Sign-in host | Microsoft Graph host |
90| ---------------------- | --------------------------- | ------------------------ |
91| Commercial | `login.microsoftonline.com` | `graph.microsoft.com` |
92| US Government GCC-High | `login.microsoftonline.us` | `graph.microsoft.us` |
93| US Government DoD | `login.microsoftonline.us` | `dod-graph.microsoft.us` |
89| Azure cloud | Sign-in host | Microsoft Graph host |
90| - | - | - |
91| Commercial | `login.microsoftonline.com` | `graph.microsoft.com` |
92| US Government GCC-High | `login.microsoftonline.us` | `graph.microsoft.us` |
93| US Government DoD | `login.microsoftonline.us` | `dod-graph.microsoft.us` |
9494 
9595No outbound access to any Anthropic host is needed for the connector's Microsoft 365 calls.
9696 
from line 98
9898 
9999On the [Config](/docs/government/org-admin/configuration) page, expand the **Microsoft 365** card and fill in the form.
100100 
101| Field | What to enter |
102| --------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
103| **Tenant ID** | The **Directory (tenant) ID** from the application's Overview page. |
104| **Client ID** | The **Application (client) ID** from the application's Overview page. |
105| **Azure cloud** | **Commercial** for most tenants, including Microsoft 365 GCC. Choose **US Government GCC-High** or **US Government DoD** only if your Microsoft tenant is in one of those clouds. |
106| **Access** | The Microsoft Graph permissions the connector requests when a member signs in. The standard read-only permissions are already selected; add or remove permissions as needed. See [Choose which Microsoft 365 permissions to allow](#choose-which-microsoft-365-permissions-to-allow). |
101| Field | What to enter |
102| - | - |
103| **Tenant ID** | The **Directory (tenant) ID** from the application's Overview page. |
104| **Client ID** | The **Application (client) ID** from the application's Overview page. |
105| **Azure cloud** | **Commercial** for most tenants, including Microsoft 365 GCC. Choose **US Government GCC-High** or **US Government DoD** only if your Microsoft tenant is in one of those clouds. |
106| **Access** | The Microsoft Graph permissions the connector requests when a member signs in. The standard read-only permissions are already selected; add or remove permissions as needed. See [Choose which Microsoft 365 permissions to allow](#choose-which-microsoft-365-permissions-to-allow). |
107107 
108108Save the card. The connector reaches each member's Claude Desktop the next time it starts or the member signs in to Claude for Government. Members who already have Claude Desktop open are prompted to relaunch the next time the app checks for changes, which it does about every 10 minutes (about every 30 minutes on Claude Desktop versions earlier than 1.46388.1), and the connector appears after the relaunch.
109109 
from line 115
115115 
116116### Read access
117117 
118| Permission | What it lets Claude do |
119| --------------------------------- | ------------------------------------------------------------------------------------------------------------ |
120| `Mail.Read` (Default) | Read the member's mail |
121| `Mail.Read.Shared` (Default) | Read mail in mailboxes shared with the member |
122| `Calendars.Read` (Default) | Read the member's calendar events |
123| `Calendars.Read.Shared` (Default) | Read events on calendars shared with the member and find free meeting times |
124| `Files.Read.All` (Default) | Read files the member can open in OneDrive and SharePoint |
125| `Sites.Read.All` (Default) | Read SharePoint site content the member can open |
126| `Chat.Read` (Default) | Read the member's Teams chats |
127| `OnlineMeetings.Read` (Default) | Read the member's online meetings |
128| `MailboxSettings.Read` | Read the member's mailbox time zone so that dates in requests follow the member's local time rather than UTC |
118| Permission | What it lets Claude do |
119| - | - |
120| `Mail.Read` (Default) | Read the member's mail |
121| `Mail.Read.Shared` (Default) | Read mail in mailboxes shared with the member |
122| `Calendars.Read` (Default) | Read the member's calendar events |
123| `Calendars.Read.Shared` (Default) | Read events on calendars shared with the member and find free meeting times |
124| `Files.Read.All` (Default) | Read files the member can open in OneDrive and SharePoint |
125| `Sites.Read.All` (Default) | Read SharePoint site content the member can open |
126| `Chat.Read` (Default) | Read the member's Teams chats |
127| `OnlineMeetings.Read` (Default) | Read the member's online meetings |
128| `MailboxSettings.Read` | Read the member's mailbox time zone so that dates in requests follow the member's local time rather than UTC |
129129 
130130### Read access requiring administrator approval
131131 
132132These two permissions always require the **Grant admin consent** step in Entra, regardless of your tenant's user-consent policy. Until that step is done, sign-in fails for every member when either permission is requested.
133133 
134| Permission | What it lets Claude do |
135| ---------------------------------- | ----------------------------------------------------- |
136| `ChannelMessage.Read.All` | Include Teams channel messages in chat search results |
137| `OnlineMeetingTranscript.Read.All` | Read meeting transcripts |
134| Permission | What it lets Claude do |
135| - | - |
136| `ChannelMessage.Read.All` | Include Teams channel messages in chat search results |
137| `OnlineMeetingTranscript.Read.All` | Read meeting transcripts |
138138 
139139### Write access
140140 
141141Write permissions let Claude take actions in Microsoft 365 on the member's behalf, such as sending mail, creating calendar events, and editing files. Members approve each write action in Claude Desktop before it runs. The connector is read-only unless you select at least one of these.
142142 
143| Permission | What it lets Claude do |
144| --------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
145| `Mail.Send` | Send mail, send drafts, and forward mail on the member's behalf. Forwarding and sending drafts also use a mail read permission (any of `Mail.Read`, `Mail.Read.Shared`, or `Mail.ReadWrite`) for pre-send checks. |
146| `Mail.ReadWrite` | Create, edit, and delete drafts; trash, restore, and delete messages; apply and remove labels on messages |
147| `Calendars.ReadWrite` | Create, update, delete, and respond to calendar events |
148| `Files.ReadWrite.All` | Create, edit, rename, move, copy, and delete files and folders the member can edit in OneDrive and SharePoint |
149| `Sites.ReadWrite.All` | Additional SharePoint write access beyond files. No Claude action requires this permission; `Files.ReadWrite.All` covers file actions in both OneDrive and SharePoint. |
150| `ChatMessage.Send` | Send messages in the member's existing Teams chats |
151| `ChannelMessage.Send` | Post messages to Teams channels |
152| `Chat.Create` | Start new Teams chats |
153| `MailboxSettings.ReadWrite` | Create and delete the member's mail rules, manage labels, and configure automatic replies |
143| Permission | What it lets Claude do |
144| - | - |
145| `Mail.Send` | Send mail, send drafts, and forward mail on the member's behalf. Forwarding and sending drafts also use a mail read permission (any of `Mail.Read`, `Mail.Read.Shared`, or `Mail.ReadWrite`) for pre-send checks. |
146| `Mail.ReadWrite` | Create, edit, and delete drafts; trash, restore, and delete messages; apply and remove labels on messages |
147| `Calendars.ReadWrite` | Create, update, delete, and respond to calendar events |
148| `Files.ReadWrite.All` | Create, edit, rename, move, copy, and delete files and folders the member can edit in OneDrive and SharePoint |
149| `Sites.ReadWrite.All` | Additional SharePoint write access beyond files. No Claude action requires this permission; `Files.ReadWrite.All` covers file actions in both OneDrive and SharePoint. |
150| `ChatMessage.Send` | Send messages in the member's existing Teams chats |
151| `ChannelMessage.Send` | Post messages to Teams channels |
152| `Chat.Create` | Start new Teams chats |
153| `MailboxSettings.ReadWrite` | Create and delete the member's mail rules, manage labels, and configure automatic replies |
154154 
155155<Note>
156156 Removing a permission from the **Access** picker changes what Claude Desktop requests the next time a member signs in, but it does not revoke permissions that Microsoft Entra has already approved for the application. To revoke a permission entirely, remove it in the Entra admin center under **Enterprise applications** > your application > **Permissions**.
from line 168
168168 
169169Brokered sign-in requires the broker redirect URIs from step 2, **Allow public client flows** set to **Yes** (step 3), and the following on each device:
170170 
171| Platform | Broker availability requirements |
172| -------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
173| Windows | Windows 10 or Windows Server 2019 or later. The device is joined or registered to Entra ID (Entra joined, Entra hybrid joined, or Entra registered). |
174| macOS | macOS 10.15 or later. The Mac is enrolled in device management and registered in Entra ID. **Intune Company Portal** is installed, and an **Extensible SSO** configuration profile of type **Redirect** pointed at the Microsoft Enterprise SSO plug-in is deployed through device management. The broker is unavailable without Company Portal and the SSO profile. |
171| Platform | Broker availability requirements |
172| - | - |
173| Windows | Windows 10 or Windows Server 2019 or later. The device is joined or registered to Entra ID (Entra joined, Entra hybrid joined, or Entra registered). |
174| macOS | macOS 10.15 or later. The Mac is enrolled in device management and registered in Entra ID. **Intune Company Portal** is installed, and an **Extensible SSO** configuration profile of type **Redirect** pointed at the Microsoft Enterprise SSO plug-in is deployed through device management. The broker is unavailable without Company Portal and the SSO profile. |
175175 
176176When the broker is unavailable, Claude Desktop falls back to browser sign-in automatically and stays on browser sign-in until Claude Desktop restarts.
177177 
from line 179
179179 
180180## Common problems
181181 
182| What the member sees | What it means | How to fix it |
183| ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
184| Entra error `AADSTS50011` at sign-in | One of the redirect URIs from step 2 is missing from the app registration, was entered with a different value, or was added under the **Web** platform instead of **Mobile and desktop applications**. The error message names the URI that Claude Desktop sent. | Compare it with step 2 and add or correct that URI under **Mobile and desktop applications**. |
185| Entra error `AADSTS900971` at sign-in on macOS | No redirect URI is registered for macOS brokered sign-in. | Add `msauth.com.anthropic.claudefordesktop://auth` under **Mobile and desktop applications** (step 2). |
186| Entra error `AADSTS65001` at sign-in | The Microsoft Graph permissions have not been approved for the tenant, or a permission the connector requests is not listed under the app registration's **API permissions** (so **Grant admin consent** never covered it). | Confirm that every permission selected under **Access** on the Config page, plus `User.Read` and `offline_access`, is listed under the app registration's **API permissions**. Add any that are missing, then select **Grant admin consent** (step 4). |
187| A Microsoft consent prompt appears at sign-in even though you selected **Grant admin consent** | Same cause as `AADSTS65001` above, on a tenant that allows members to approve permissions themselves. | See the `AADSTS65001` row above. |
188| Entra error `AADSTS7000218` at sign-in | **Allow public client flows** is set to **No** on the app registration. | Set it to **Yes** (step 3). |
189| Entra error `AADSTS53000` or `AADSTS53003` when Claude calls Microsoft 365 | A Conditional Access policy requires a compliant or managed device, and either sign-in fell back to the browser because brokered sign-in is not available, or the device does not satisfy the policy's grant control. | Meet the [brokered sign-in requirements](#brokered-sign-in-requirements) for the member's platform, confirm the device satisfies whichever grant control your policy applies (marked compliant, or hybrid joined), and restart Claude Desktop. On macOS, the most common broker cause is a missing Company Portal install or Extensible SSO profile. |
190| Entra error `AADSTS700016` at sign-in | The **Client ID** or **Tenant ID** on the Config page does not match an application in the selected **Azure cloud**. | Re-check the Client ID and Tenant ID against the application's Overview page, and confirm that **Azure cloud** matches the cloud where you registered the application. |
191| Sign-in or Claude's Microsoft 365 calls fail with a network error and no `AADSTS` code | The member's device cannot reach the Microsoft Entra or Microsoft Graph host for your Azure cloud. | Allow outbound HTTPS to the hosts listed under [Allow outbound network access](#allow-outbound-network-access). |
192| A tool returns a permission error | The Microsoft Graph permission that tool needs is not approved on the app registration, or is not selected under **Access**. | Add the permission in both places and select **Grant admin consent** again. |
182| What the member sees | What it means | How to fix it |
183| - | - | - |
184| Entra error `AADSTS50011` at sign-in | One of the redirect URIs from step 2 is missing from the app registration, was entered with a different value, or was added under the **Web** platform instead of **Mobile and desktop applications**. The error message names the URI that Claude Desktop sent. | Compare it with step 2 and add or correct that URI under **Mobile and desktop applications**. |
185| Entra error `AADSTS900971` at sign-in on macOS | No redirect URI is registered for macOS brokered sign-in. | Add `msauth.com.anthropic.claudefordesktop://auth` under **Mobile and desktop applications** (step 2). |
186| Entra error `AADSTS65001` at sign-in | The Microsoft Graph permissions have not been approved for the tenant, or a permission the connector requests is not listed under the app registration's **API permissions** (so **Grant admin consent** never covered it). | Confirm that every permission selected under **Access** on the Config page, plus `User.Read` and `offline_access`, is listed under the app registration's **API permissions**. Add any that are missing, then select **Grant admin consent** (step 4). |
187| A Microsoft consent prompt appears at sign-in even though you selected **Grant admin consent** | Same cause as `AADSTS65001` above, on a tenant that allows members to approve permissions themselves. | See the `AADSTS65001` row above. |
188| Entra error `AADSTS7000218` at sign-in | **Allow public client flows** is set to **No** on the app registration. | Set it to **Yes** (step 3). |
189| Entra error `AADSTS53000` or `AADSTS53003` when Claude calls Microsoft 365 | A Conditional Access policy requires a compliant or managed device, and either sign-in fell back to the browser because brokered sign-in is not available, or the device does not satisfy the policy's grant control. | Meet the [brokered sign-in requirements](#brokered-sign-in-requirements) for the member's platform, confirm the device satisfies whichever grant control your policy applies (marked compliant, or hybrid joined), and restart Claude Desktop. On macOS, the most common broker cause is a missing Company Portal install or Extensible SSO profile. |
190| Entra error `AADSTS700016` at sign-in | The **Client ID** or **Tenant ID** on the Config page does not match an application in the selected **Azure cloud**. | Re-check the Client ID and Tenant ID against the application's Overview page, and confirm that **Azure cloud** matches the cloud where you registered the application. |
191| Sign-in or Claude's Microsoft 365 calls fail with a network error and no `AADSTS` code | The member's device cannot reach the Microsoft Entra or Microsoft Graph host for your Azure cloud. | Allow outbound HTTPS to the hosts listed under [Allow outbound network access](#allow-outbound-network-access). |
192| A tool returns a permission error | The Microsoft Graph permission that tool needs is not approved on the app registration, or is not selected under **Access**. | Add the permission in both places and select **Grant admin consent** again. |
193193 
194194## Things to know
195195 

government/deploy-desktop/configure Changed · +33 / -33 lines

from line 10
1010 
1111There are two ways to get Claude Desktop installed and connected to Claude for Government. They differ in who runs the installer, what rights that requires, and how the setting reaches the app.
1212 
13| | Configure a single machine | Deploy to your fleet |
14| ------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- |
15| Best for | Confirming the app works on a representative device before a wider rollout, or setting up a small group of devices by hand | Production rollout across your agency |
16| Who installs the app | A person at the device | Your device management system (for example Intune, Configuration Manager, or Jamf) |
17| Administrator rights to install | Needed by the person doing each install | Not needed by end users; the management system installs with elevated rights |
18| How the address is set | Entered in the app's built-in configuration window | Pushed as a configuration profile alongside the app |
13| | Configure a single machine | Deploy to your fleet |
14| - | - | - |
15| Best for | Confirming the app works on a representative device before a wider rollout, or setting up a small group of devices by hand | Production rollout across your agency |
16| Who installs the app | A person at the device | Your device management system (for example Intune, Configuration Manager, or Jamf) |
17| Administrator rights to install | Needed by the person doing each install | Not needed by end users; the management system installs with elevated rights |
18| How the address is set | Entered in the app's built-in configuration window | Pushed as a configuration profile alongside the app |
1919 
2020For a production rollout, use your device management system so end users never need administrator rights. The single-machine path is for testing first or for a small group you set up by hand, with an administrator doing each install. That path can also export a ready-made profile for your management system, so it is a useful starting point even when the fleet path is your destination.
2121 
from line 58
5858 
5959The configuration that the app downloads for a user includes the following settings, all of which you manage in this portal.
6060 
61| What the app receives | Where it is set |
62| ----------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
63| Which of Chat, Cowork, and Code the user can open, and whether Advanced file analysis is on in Chat | [Product availability](/docs/government/config/settings#product-availability) on the Config page |
64| The models the user can choose | The user's [seat tier](/docs/government/org-admin/seat-tiers) |
65| Connectors, plugins, and the settings for the built-in tools | The [tool and connector cards](/docs/government/config/settings#tool-and-connector-cards) on the Config page |
66| The hosts that tools may reach | [Allowed network hosts](/docs/government/config/settings#allowed-network-hosts) |
67| The folders a user can choose as a workspace | [Allowed workspace folders](/docs/government/config/settings#allowed-workspace-folders) |
68| The banner shown across the top of the app | [Claude Desktop banner](/docs/government/config/settings#claude-desktop-banner) |
69| Where the app sends your agency's own telemetry, if you have set a collector | [Telemetry endpoint](/docs/government/config/settings#telemetry-endpoint) |
61| What the app receives | Where it is set |
62| - | - |
63| Which of Chat, Cowork, and Code the user can open, and whether Advanced file analysis is on in Chat | [Product availability](/docs/government/config/settings#product-availability) on the Config page |
64| The models the user can choose | The user's [seat tier](/docs/government/org-admin/seat-tiers) |
65| Connectors, plugins, and the settings for the built-in tools | The [tool and connector cards](/docs/government/config/settings#tool-and-connector-cards) on the Config page |
66| The hosts that tools may reach | [Allowed network hosts](/docs/government/config/settings#allowed-network-hosts) |
67| The folders a user can choose as a workspace | [Allowed workspace folders](/docs/government/config/settings#allowed-workspace-folders) |
68| The banner shown across the top of the app | [Claude Desktop banner](/docs/government/config/settings#claude-desktop-banner) |
69| Where the app sends your agency's own telemetry, if you have set a collector | [Telemetry endpoint](/docs/government/config/settings#telemetry-endpoint) |
7070| Whether automatic updates are blocked, and the restart deadlines for a downloaded update and for a configuration change | [Block automatic updates](/docs/government/config/settings#block-automatic-updates), [Restart deadline for updates](/docs/government/config/settings#restart-deadline-for-updates), and [Restart deadline for configuration changes](/docs/government/config/settings#restart-deadline-for-configuration-changes) on the Config page |
7171 
7272## Configure a single machine
from line 121
121121 
122122The recommended profile contains two keys. In the macOS and Windows profiles below, write every value as a string exactly as shown, including booleans as the strings `"true"` or `"false"`; the Linux file uses native JSON types, as shown.
123123 
124| Key | Value | Purpose |
125| ------------------------------ | ----------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
126| `bootstrapUrl` | `https://<claude-for-government-host>/gateway-api/user/bootstrap` | Required. Points the app at Claude for Government. |
127| `disableDeploymentModeChooser` | `"true"` | Recommended. Hides the claude.ai sign-in option so users can only sign in to Claude for Government. Like any recognized key other than the automatic update settings, it also marks the device as managed (see [Order of deployment](#order-of-deployment)). |
124| Key | Value | Purpose |
125| - | - | - |
126| `bootstrapUrl` | `https://<claude-for-government-host>/gateway-api/user/bootstrap` | Required. Points the app at Claude for Government. |
127| `disableDeploymentModeChooser` | `"true"` | Recommended. Hides the claude.ai sign-in option so users can only sign in to Claude for Government. Like any recognized key other than the automatic update settings, it also marks the device as managed (see [Order of deployment](#order-of-deployment)). |
128128 
129129No other keys are needed to connect the app; Claude for Government supplies everything else per user after sign-in. If your agency distributes Claude Desktop updates itself, [Automatic updates](#automatic-updates) below describes one more key to add. The profile contains no secrets, only a host.
130130 
from line 235
235235 
236236## Troubleshooting
237237 
238| What you see | Likely cause | What to do |
239| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
240| Only the claude.ai sign-in screen; no organization option | The configuration never reached the app: the profile was not delivered, a key name is misspelled, the value is in the wrong location or registry type, or the app was not relaunched after the change. A profile that sets any `otlp*` telemetry key but no `bootstrapUrl` also produces this screen, even on a device that was set up in the app's configuration window | Verify delivery in your management console, generate a diagnostic report and check its Configuration section, then fully quit and reopen the app. If the profile sets telemetry keys but no `bootstrapUrl`, add `bootstrapUrl` to the profile or remove the profile, then fully quit and reopen the app |
241| Sign-in times out, or the browser says the code expired | The app stops waiting after about five minutes | Cancel and start sign-in again; a fresh code is issued |
242| Sign-in fails as soon as the user chooses **Sign in with your organization**, and the error on the sign-in screen or in `main.log` says that an address "must be same-origin" as the configured host | `bootstrapUrl` points at an alias that your agency operates, such as a DNS record or reverse proxy under your own domain, rather than the host provided to your agency | Use the host provided to your agency in `bootstrapUrl`, exactly as provided, redeploy the profile, then fully quit and reopen the app |
243| The diagnostic report or `main.log` shows "Managed configuration is invalid; local settings are disabled until it is fixed" | The app detected a managed profile but could not read any of its values | Correct the profile and redeploy; the report's Configuration section names each key that failed |
244| Signed in, but the model picker is empty, or the app shows a **Configuration can't be used** banner whose **Details** or **Copy report for IT** text says the provider returned no usable models | The user has no seat tier, or none of the tier's models is available in Claude for Government, so the app received an empty model list. Nothing is wrong with the device's configuration | Have an organization owner check the user's seat tier on the [Users](/docs/government/org-admin/users) page and the tier's models on the [Seat tiers](/docs/government/org-admin/seat-tiers) page |
245| An **Apply settings from your organization?** window appears after sign-in or at every launch, or the app quits when the user dismisses that window | The bootstrap address was entered in the app or set per user (for example under `HKEY_CURRENT_USER`), so the app asks each user to allow the gateway address that Claude for Government sends before it applies any of the organization's settings, and the user has not yet clicked **Allow**. Choosing **Quit**, pressing Esc, or closing the window quits the app, and it asks again on the next launch. | Have the user expand **Gateway base URL** in that window, confirm that the address is on your Claude for Government host, and click **Allow**. The window does not take focus when it opens, so have the user switch to the Claude app to find it. If the address is not on your host, check the bootstrap address configured on that device. To stop the prompt across a fleet, deliver the bootstrap address through machine-wide device management, as described under [Deploy to your fleet](#deploy-to-your-fleet). Versions earlier than 1.32352.0 that ask for this approval also show a **Configuration sync issue** banner that says "bootstrap response is missing required field(s): inferenceGatewayBaseUrl" for the same cause. Update the app to the latest version, then answer the prompt. |
246| The browser shows a connection error instead of Claude for Government or its sign-in page: "Secure Connection Failed" with `PR_CONNECT_RESET_ERROR` in Firefox, or `ERR_CONNECTION_RESET` in Chrome | A web filter, firewall, or proxy reset the connection, either on your agency's network or on the Claude for Government side. | If the address opens in another browser on the same computer, check the first browser's proxy and DNS settings. Otherwise, open the address from outside your agency's network, for example on a phone using cellular data. If the phone shows a web page, not a connection error, have your network team allow the host in that address and the hosts described under [Before you begin](#before-you-begin). If the phone also fails, or the team finds no block, contact your Anthropic representative with the address, the time and time zone of the error, and your network's public IP addresses. |
247| During sign-in, the browser shows a Microsoft page titled "You cannot access this right now", sometimes in one browser but not in another | Microsoft Entra ID shows this page when one of your agency's Conditional Access policies blocks the sign-in, for example a policy that limits which browsers, devices, or locations can sign in. The refusal happens before the sign-in reaches Claude for Government, so nothing in the app or in this portal changes it. | Ask your identity team to find the failed sign-in in the identity provider's sign-in logs. In the Microsoft Entra admin center, the sign-in event's **Conditional Access** tab names the policy that blocked it and the condition that was not met. Adjust the policy, or have the user sign in from a browser or device the policy allows (Claude Desktop opens sign-in in the computer's default browser). |
248| The app shows **Your session has expired** or **You've been signed out** with a **Sign in again** button, or a device that was already set up opens to the sign-in screen | The user's Claude for Government session ended, most often because they had not used Claude for longer than your tenant's [Session idle timeout](/docs/government/config/settings#session-idle-timeout). A device left idle, locked, or asleep does not keep a session alive. A session also ends at the Maximum session length, or when the user or an administrator signs it out. A user can have at most six active Claude Desktop sessions. When they sign in to Claude Desktop again while six are active, Claude for Government ends the Claude Desktop session that is closest to expiring. | Have the user sign in again. The app keeps its configuration and reconnects. If the session limit is the cause, the user can go to their [Sessions](/docs/government/account/sessions) page and sign out of sessions they no longer use. If people are asked to sign in more often than you intend, ask a tenant administrator to review **Session idle timeout** and **Maximum session length** on the [Config](/docs/government/tenant-admin/configuration) page. On Claude Desktop versions earlier than 1.34493.0 the same situation can appear as a **Configuration sync issue** banner instead, so update the app. |
249| On a Windows device, Cowork tasks fail, the app shows **Failed to start Claude's workspace** with a message under it about a Windows update, or Claude can't read some attached files in Chat, such as Word, Excel, or PowerPoint files | The device has installed the Windows update released September 8, 2026, but not Microsoft's later update that fixes the problem. The September 8 update stops Claude's workspace from reaching files on the device. Cowork tasks and Advanced file analysis in Chat need the workspace. | Install the latest Windows update on the device and restart it. On Windows 11 24H2 and 25H2, the fix is KB5129195. No Claude Desktop update is needed. See [Resolved: Cowork on Windows](/docs/cowork/changelog#resolved-cowork-on-windows) in the Claude Desktop changelog. |
250| Web search is on for your organization, but a user does not have it, and under **Customize**, then **Connectors**, **Web Search** shows as not connected and **Connect** fails, while chat works | A firewall or secure web gateway on that user's network path filters traffic by application. Claude Desktop connects to web search on your Claude for Government host over HTTPS, and such equipment can classify that connection as Model Context Protocol (MCP) traffic and block it even when the host itself is allowed. | Ask your network team to allow this traffic to your Claude for Government host for the affected users. The user's `main.log` records each failed attempt, including any block page the network returned. Then have the user select **Connect** next to **Web Search**, or restart the app. |
251| The app shows **Failed to start Claude's workspace** with a download error under it, or Chat conversations and Cowork tasks fail to start with "Host Claude Code binary not available. Check that the download completed." | Claude Desktop could not download a complete, verified copy of the Cowork workspace or the [agent helper](/docs/third-party/claude-desktop/installation#endpoint-security-software) from `downloads.claude.ai`. This usually means a proxy or web filter on the device's network path is blocking or altering the download. | Follow [Cowork workspace or Claude CLI fails to download](/docs/third-party/claude-desktop/installation#cowork-workspace-or-claude-cli-fails-to-download) in the Claude Desktop documentation. |
238| What you see | Likely cause | What to do |
239| - | - | - |
240| Only the claude.ai sign-in screen; no organization option | The configuration never reached the app: the profile was not delivered, a key name is misspelled, the value is in the wrong location or registry type, or the app was not relaunched after the change. A profile that sets any `otlp*` telemetry key but no `bootstrapUrl` also produces this screen, even on a device that was set up in the app's configuration window | Verify delivery in your management console, generate a diagnostic report and check its Configuration section, then fully quit and reopen the app. If the profile sets telemetry keys but no `bootstrapUrl`, add `bootstrapUrl` to the profile or remove the profile, then fully quit and reopen the app |
241| Sign-in times out, or the browser says the code expired | The app stops waiting after about five minutes | Cancel and start sign-in again; a fresh code is issued |
242| Sign-in fails as soon as the user chooses **Sign in with your organization**, and the error on the sign-in screen or in `main.log` says that an address "must be same-origin" as the configured host | `bootstrapUrl` points at an alias that your agency operates, such as a DNS record or reverse proxy under your own domain, rather than the host provided to your agency | Use the host provided to your agency in `bootstrapUrl`, exactly as provided, redeploy the profile, then fully quit and reopen the app |
243| The diagnostic report or `main.log` shows "Managed configuration is invalid; local settings are disabled until it is fixed" | The app detected a managed profile but could not read any of its values | Correct the profile and redeploy; the report's Configuration section names each key that failed |
244| Signed in, but the model picker is empty, or the app shows a **Configuration can't be used** banner whose **Details** or **Copy report for IT** text says the provider returned no usable models | The user has no seat tier, or none of the tier's models is available in Claude for Government, so the app received an empty model list. Nothing is wrong with the device's configuration | Have an organization owner check the user's seat tier on the [Users](/docs/government/org-admin/users) page and the tier's models on the [Seat tiers](/docs/government/org-admin/seat-tiers) page |
245| An **Apply settings from your organization?** window appears after sign-in or at every launch, or the app quits when the user dismisses that window | The bootstrap address was entered in the app or set per user (for example under `HKEY_CURRENT_USER`), so the app asks each user to allow the gateway address that Claude for Government sends before it applies any of the organization's settings, and the user has not yet clicked **Allow**. Choosing **Quit**, pressing Esc, or closing the window quits the app, and it asks again on the next launch. | Have the user expand **Gateway base URL** in that window, confirm that the address is on your Claude for Government host, and click **Allow**. The window does not take focus when it opens, so have the user switch to the Claude app to find it. If the address is not on your host, check the bootstrap address configured on that device. To stop the prompt across a fleet, deliver the bootstrap address through machine-wide device management, as described under [Deploy to your fleet](#deploy-to-your-fleet). Versions earlier than 1.32352.0 that ask for this approval also show a **Configuration sync issue** banner that says "bootstrap response is missing required field(s): inferenceGatewayBaseUrl" for the same cause. Update the app to the latest version, then answer the prompt. |
246| The browser shows a connection error instead of Claude for Government or its sign-in page: "Secure Connection Failed" with `PR_CONNECT_RESET_ERROR` in Firefox, or `ERR_CONNECTION_RESET` in Chrome | A web filter, firewall, or proxy reset the connection, either on your agency's network or on the Claude for Government side. | If the address opens in another browser on the same computer, check the first browser's proxy and DNS settings. Otherwise, open the address from outside your agency's network, for example on a phone using cellular data. If the phone shows a web page, not a connection error, have your network team allow the host in that address and the hosts described under [Before you begin](#before-you-begin). If the phone also fails, or the team finds no block, contact your Anthropic representative with the address, the time and time zone of the error, and your network's public IP addresses. |
247| During sign-in, the browser shows a Microsoft page titled "You cannot access this right now", sometimes in one browser but not in another | Microsoft Entra ID shows this page when one of your agency's Conditional Access policies blocks the sign-in, for example a policy that limits which browsers, devices, or locations can sign in. The refusal happens before the sign-in reaches Claude for Government, so nothing in the app or in this portal changes it. | Ask your identity team to find the failed sign-in in the identity provider's sign-in logs. In the Microsoft Entra admin center, the sign-in event's **Conditional Access** tab names the policy that blocked it and the condition that was not met. Adjust the policy, or have the user sign in from a browser or device the policy allows (Claude Desktop opens sign-in in the computer's default browser). |
248| The app shows **Your session has expired** or **You've been signed out** with a **Sign in again** button, or a device that was already set up opens to the sign-in screen | The user's Claude for Government session ended, most often because they had not used Claude for longer than your tenant's [Session idle timeout](/docs/government/config/settings#session-idle-timeout). A device left idle, locked, or asleep does not keep a session alive. A session also ends at the Maximum session length, or when the user or an administrator signs it out. A user can have at most six active Claude Desktop sessions. When they sign in to Claude Desktop again while six are active, Claude for Government ends the Claude Desktop session that is closest to expiring. | Have the user sign in again. The app keeps its configuration and reconnects. If the session limit is the cause, the user can go to their [Sessions](/docs/government/account/sessions) page and sign out of sessions they no longer use. If people are asked to sign in more often than you intend, ask a tenant administrator to review **Session idle timeout** and **Maximum session length** on the [Config](/docs/government/tenant-admin/configuration) page. On Claude Desktop versions earlier than 1.34493.0 the same situation can appear as a **Configuration sync issue** banner instead, so update the app. |
249| On a Windows device, Cowork tasks fail, the app shows **Failed to start Claude's workspace** with a message under it about a Windows update, or Claude can't read some attached files in Chat, such as Word, Excel, or PowerPoint files | The device has installed the Windows update released September 8, 2026, but not Microsoft's later update that fixes the problem. The September 8 update stops Claude's workspace from reaching files on the device. Cowork tasks and Advanced file analysis in Chat need the workspace. | Install the latest Windows update on the device and restart it. On Windows 11 24H2 and 25H2, the fix is KB5129195. No Claude Desktop update is needed. See [Resolved: Cowork on Windows](/docs/cowork/changelog#resolved-cowork-on-windows) in the Claude Desktop changelog. |
250| Web search is on for your organization, but a user does not have it, and under **Customize**, then **Connectors**, **Web Search** shows as not connected and **Connect** fails, while chat works | A firewall or secure web gateway on that user's network path filters traffic by application. Claude Desktop connects to web search on your Claude for Government host over HTTPS, and such equipment can classify that connection as Model Context Protocol (MCP) traffic and block it even when the host itself is allowed. | Ask your network team to allow this traffic to your Claude for Government host for the affected users. The user's `main.log` records each failed attempt, including any block page the network returned. Then have the user select **Connect** next to **Web Search**, or restart the app. |
251| The app shows **Failed to start Claude's workspace** with a download error under it, or Chat conversations and Cowork tasks fail to start with "Host Claude Code binary not available. Check that the download completed." | Claude Desktop could not download a complete, verified copy of the Cowork workspace or the [agent helper](/docs/third-party/claude-desktop/installation#endpoint-security-software) from `downloads.claude.ai`. This usually means a proxy or web filter on the device's network path is blocking or altering the download. | Follow [Cowork workspace or Claude CLI fails to download](/docs/third-party/claude-desktop/installation#cowork-workspace-or-claude-cli-fails-to-download) in the Claude Desktop documentation. |
252252 
253253For anything else, the app writes its log to `~/Library/Logs/Claude-3p/main.log` on macOS, `%LOCALAPPDATA%\Claude-3p\logs\main.log` on Windows, and `~/.config/Claude-3p/logs/main.log` on Linux. The log records which configuration keys were read or dropped and why. The diagnostic report from the verification checklist produces a bundle, without conversation content, that you can send to your Anthropic representative.
254254 

government/deploy-desktop/windows-checklist Changed · +5 / -5 lines

from line 25
2525 
2626If you enforce application control with AppLocker or App Control for Business (formerly Windows Defender Application Control), allow Claude Desktop by publisher or by package family name rather than by path, and let the rule match any version, so that it keeps matching as the app updates.
2727 
28| Identifier | Value |
29| ---------------------- | ---------------------- |
30| Package name | `Claude` |
31| Package family name | `Claude_pzs8sxrjxfjjc` |
32| Publisher display name | Anthropic, PBC |
28| Identifier | Value |
29| - | - |
30| Package name | `Claude` |
31| Package family name | `Claude_pzs8sxrjxfjjc` |
32| Publisher display name | Anthropic, PBC |
3333 
3434These values identify the `.msix` package from the download site and the offline installer, and they do not change between versions or architectures.
3535 
Feedback