Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One capture · claude-docs

One read of Claude Documentationclaude-docs-20261005T190707Z

56 pages moved out of 261 read.

Pages moved 56 significant first
Pages read 261 in this capture
Captured 19:07 UTC
Corpus hash 67472caaae39 corpus-hash

What this read moved

1-25 of 56, page 1 of 3

This capture is too large to show at once. Changes 1-25 of 56 are below, significant first; the rest are on the following screens.

claude-tag/admins/add-connections Changed · +286 / -168 lines

## Add a connector ### Connect a service for one workspace or channel ### Claude Tag connectors vs personal claude.ai connectors ## Change an existing connector ### Restrict a connector to some channels ### Manage a connector's credentials ### Use a different credential in one workspace or channel ## Create a bundle ## Verify the connector saved ## Your first Access bundle ## Add a connection ### Connections vs claude.ai connectors ## Verify the connection saved

from line 1
11# Give Claude access to your tools
22 
3> An Access bundle bundles the credentials Claude Tag acts with. See how to create the dedicated service accounts, what to connect first, and how allowed websites limit reach.
3> Add connectors so Claude Tag acts in your tools with its own credentials. Covers service accounts, bundles, allowed websites, domain entries, and plugins.
44 
55export const BetaNote = () => <Info>Claude Tag is in public beta. Features and behavior described here may change before general availability.</Info>;
66 
from line 8
88 
99<Tip>Claude starts delivering work before you connect anything. On Slack content alone, it can [catch a team up on a channel or thread](/docs/claude-tag/users/use-cases/catch-up), [triage a request channel](/docs/claude-tag/users/use-cases/triage-requests), [turn a discussion into a doc](/docs/claude-tag/users/use-cases/create-artifacts), and [track a project from channel history](/docs/claude-tag/users/use-cases/track-projects).</Tip>
1010 
11## Your first Access bundle
11A connector gives Claude its own credential for one of your tools, like a Datadog API key or a warehouse service account, so Claude can act in that tool from Slack channels. This page is for the admins who add connectors and decide where they apply. To let Claude act as a member with that member's own claude.ai connectors, see [Personal connectors](/docs/claude-tag/concepts/personal-connectors) instead.
1212 
13An [Access bundle](/docs/claude-tag/concepts/glossary#access-bundle) is a named set of credentials, domain entries, repository grants, plugins, and instructions that Claude uses in the channels the bundle covers. A connection is one service credential inside a bundle, like a Datadog API key or a warehouse service account, that Claude uses to act in that service from any channel under the bundle's [scope](/docs/claude-tag/concepts/glossary#scope).
13Adding connectors and bundles requires the **Owner** role or the [**Claude Tag Admin** permission](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) in your Claude organization. You manage both in [**Organization settings > Claude Tag**](https://claude.ai/admin-settings/claude-tag), under **Claude's access**, which appears once the **Enable Claude Tag in Slack** switch is on.
1414 
15You create your first bundle on the admin page, after you finish [setup](/docs/claude-tag/admins/setup-overview) and launch.
15Connectors belong to the [agent identity](/docs/claude-tag/concepts/agent-identity), not to any person. Personal claude.ai connectors apply in one-to-one DMs. Claude can also [use a member's own connectors in a channel](/docs/claude-tag/concepts/personal-connectors) for that member's own tasks, after the member allows it.
1616 
17<Steps>
18 <Step title="Open the admin page">
19 Go to [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag). Under **Claude Tag's access**, the **Slack** tab lists your scopes: **Default Slack** (organization-wide), then each workspace and any channels under them. Selecting **Default Slack** opens the **Default Slack access** panel.
20 </Step>
21 
22 <Step title="Create a bundle on a scope">
23 On the scope where you want the bundle to apply, click **+** next to **Access bundles** and choose **Create new bundle**. This creates the bundle and attaches it to that scope in one step; the bundle dialog opens.
24 </Step>
25 
26 <Step title="Name the bundle">
27 A bundle created on a workspace or channel scope is named after that scope, like **Acme bundle** for a workspace named Acme or **#engineering bundle** for that channel. A bundle created on **Default Slack** is named **Untitled access bundle** until you rename it. To rename a bundle, click the pencil next to the name (the console uses "profile" and "Access bundle" interchangeably).
28 </Step>
29</Steps>
30 
31You can also create an unattached bundle by clicking **Create** on the **Access bundles** page in the left navigation, then attach it to scopes afterward. A bundle created there is named **Untitled access bundle** until you rename it.
32 
33Connections belong to the [agent identity](/docs/claude-tag/concepts/agent-identity), not to any person. Personal claude.ai connectors apply in one-to-one DMs. Claude can also [use a member's own connectors in a channel](/docs/claude-tag/concepts/personal-connectors) for that member's own tasks, after the member allows it.
34 
35Name a bundle after what it grants, since the name is what you'll read when deciding which bundles to bind to a channel: `data-readonly`, `github-write`, `monitoring`, `gtm-tools`. A capability name stays meaningful when the same bundle serves several teams; a team name (`devprod-team`) works when one team's full access is the unit you'll reuse.
36 
37### Why create more than one bundle
38 
39Multiple bundles let you grant access by capability and compose it per channel. For example, with separate `data-readonly`, `github-write`, and `monitoring` bundles: `#platform-eng` gets all three, `#gtm-analytics` gets only `data-readonly`, and `#incidents` gets `monitoring` plus `github-write`. Each credential is defined once, so rotating a Datadog key means editing one bundle without touching the others.
40 
41A bundle also has Domains, Plugins, and Instructions tabs alongside Credentials and Repositories. Use the bundle's Instructions for guidance that should travel with a credential; use [per-scope custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions) for guidance tied to a place.
42 
4317## Decide what to connect
4418 
45Six categories cover most of the work teams hand to Claude. Any service with an HTTP API can be added; start with the categories that match what your teams already do.
19Six categories cover most of the work teams give Claude. Any service with an HTTP API can be added; start with the categories that match what your teams already do.
4620 
47Read-only connections are most useful in combination: an answer that joins the ticket, the deploy, and the error rate needs all three systems connected.
21Read-only connectors are most useful in combination: an answer that joins the ticket, the deploy, and the error rate needs all three systems connected.
4822 
4923| Connect | Examples | Recommended access | What it adds |
5024| :- | :- | :- | :- |
from line 33
5933 
6034### Create a dedicated account per service
6135 
62<Warning>The credential you connect is Claude's account in that tool, not yours. Anyone in a channel under the bundle's scope can use it through Claude, so connect a dedicated identity you control rather than your personal login.</Warning>
36<Warning>The credential you connect is Claude's account in that tool, not yours. Anyone in a channel where the connector applies can use it through Claude, so connect a dedicated identity you control rather than your personal login.</Warning>
6337 
6438For each tool, create that identity specifically for the agent rather than reusing a shared bot key. The pattern depends on the service.
6539 
from line 44
7044| SaaS without service accounts (Linear, Asana) | Create a dedicated user seat for the agent and use a personal access token from that seat |
7145| Cloud APIs (AWS, GCP) | Create a dedicated IAM principal with the narrowest policy that covers the work |
7246 
73A dedicated account keeps the agent's activity separately auditable in each tool's logs and lets you revoke its access without touching anyone else's. Grant read-only wherever the categories below say read; Claude can never exceed what the key allows.
47A dedicated account keeps the agent's activity separately auditable in each tool's logs and lets you revoke its access without touching anyone else's. Grant read-only wherever the categories above say read; Claude can never exceed what the key allows.
7448 
75If the person who administers a service isn't you, send them this:
49If the person who administers a service isn't you, [send them a setup link](#send-a-setup-link-to-another-admin), or send them this:
7650 
7751```text wrap theme={null}
7852Please create a service account in [service] for our Claude agent, scoped to [read-only / the specific project], and send me the credential through [your secrets channel]. It will be used by an org-managed agent, with the credential injected at a network proxy; the agent itself never holds the key. Details: https://claude.com/docs/claude-tag/admins/add-connections
from line 54
8054 
8155### Limit access to specific resources
8256 
83A connection has no setting for which pages, folders, or projects Claude can reach inside a tool. The connection's reach is whatever the connected account can access in that tool. To narrow Claude to a subset, narrow the account:
57A connector has no setting for which pages, folders, or projects Claude can reach inside a tool. The connector's reach is whatever the connected account can access in that tool. To narrow Claude to a subset, narrow the account:
8458 
8559* **Confluence or another wiki:** give the service account read access to only the spaces or pages Claude should see
8660* **Google Drive:** share only the relevant folders with the dedicated Google account; see [Google Workspace](/docs/claude-tag/admins/connections/google)
8761* **Project or ticket trackers:** add the service account to only the projects it needs
8862 
89The host, path, and method restrictions on a connection control which API endpoints Claude can call, not which records those endpoints return. Use them alongside account-level scoping, not instead of it.
63The host, path, and method restrictions on a credential control which API endpoints Claude can call, not which records those endpoints return. Use them alongside account-level scoping, not instead of it.
9064 
91For a shared or external channel, put the narrowed connection in its own bundle and [attach that bundle only to that channel](/docs/claude-tag/admins/attach-to-scope#attach-to-a-channel), so the credential is unavailable elsewhere.
65For a shared or external channel, put the narrowed credential in its own [bundle](#create-a-bundle) and add only that channel under the bundle's **Where it applies**, so the credential is unavailable elsewhere.
9266 
93## Connect a service that isn't in the list
67<a id="add-a-connection" />
9468 
95The services with **Connect** buttons on the Credentials tab are presets, not the full set Claude can connect to. Any app with an API can be connected: click **Connect** next to **Custom tool** at the bottom of the tab. See the [Custom connection guide](/docs/claude-tag/admins/connections/custom) for the form fields, credential types, and how to add a custom MCP server.
69<a id="where-a-new-connector-applies" />
9670 
97You can also add connections from a channel's [Configure page](/docs/claude-tag/users/good-habits#configure-claude-for-a-channel). The option to add one appears there only for people who can manage Claude's setup for that channel or for the whole organization. [Channel managers](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) can manage setup for their assigned channels. Other channel members see the channel's connections on the Configure page but can't add one.
71## Add a connector
9872 
99## Allow a host without a credential
73The first credential you add for a service from the **Connectors** tab is on in every workspace and channel as soon as you save it. You can give it narrower reach:
10074 
101Claude does channel work in an isolated [sandbox](/docs/claude-tag/concepts/agent-identity#channel-sessions). A network request is traffic that sandbox sends to a host, such as an API call, a `curl` fetch, or a package install. Before Claude can make one from a channel, the destination host has to be allowed by one of three settings, the allow layers:
75* **One workspace or channel from the start**: [connect it from that place's page](#connect-a-service-for-one-workspace-or-channel) instead.
76* **Some channels**: add it from the **Connectors** tab, then [restrict it on its page](#restrict-a-connector-to-some-channels).
77* **Off everywhere until you choose where it applies**: add it to a new [bundle](#create-a-bundle) instead.
10278 
103* **A domain entry**: a hostname listed on this bundle's **Domains** tab. Requests to it pass with no credential attached; see [Add a domain](#add-a-domain).
104* **A [connection](#add-a-connection)**: a credential on this bundle's **Credentials** tab. Requests matching its [allowed websites](#set-allowed-websites) pass with that credential attached.
105* **The scope's [environment](/docs/claude-tag/concepts/glossary#environment)**: the compute configuration the scope's sessions run in, which carries its own network access setting, starting at the Trusted access level that covers common package registries. Requests to hosts it allows pass with no credential; see [Broad web access through the environment](#broad-web-access-through-the-environment).
79If the service, or a custom connector's host, is already on the **Connectors** tab, the new credential starts off everywhere until you choose where it applies.
10680 
107A host that none of these allows stays unreachable, and when more than one bundle is attached to a scope, the entries of all of them apply. Web search is governed by none of them, because searching happens on Anthropic's servers rather than in the sandbox; see [Web search vs. network requests](#web-search-vs-network-requests).
81<Steps>
82 <Step title="Open the Connectors tab">
83 Go to [**Organization settings > Claude Tag**](https://claude.ai/admin-settings/claude-tag). Under **Claude's access**, select the **Connectors** tab and click **Add**.
84 </Step>
10885 
109### Add a domain
86 <Step title="Pick the service">
87 In the **Add a connector** dialog, search for the service and select it. A service Claude already holds a credential for shows **Connected**. For GitHub, see [Configure GitHub access](/docs/claude-tag/admins/configure-github). For a service that isn't listed, select **Custom connector** at the bottom of the list; see [Connect a service that isn't in the list](#connect-a-service-that-isn%E2%80%99t-in-the-list).
11088 
111A domain entry allowlists one hostname for every channel this bundle covers. After you add it, requests from those channels' sandboxes to that host go through with no credential attached.
89 For a service that offers a sign-in as well as a key, such as Amplitude, the dialog then shows **How Claude authenticates**. Leave **Paste an API key** selected, or select the sign-in option, such as **Sign in to Amplitude as Claude**, and click **Continue to** *service*.
90 </Step>
11291 
113To get there, open the bundle from the scope that covers the channel, under **Claude Tag's access** at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag); if the scope has no bundle yet, [create one](#your-first-access-bundle) first. On the bundle's **Domains** tab, fill in the form and click **Add domain**:
92 <Step title="Enter the credential">
93 In the connect form, enter the credential from the service's [dedicated account](#create-a-dedicated-account-per-service). On the form's **Advanced** tab, check the hosts under **Allowed websites** (see [Set allowed websites](#set-allowed-websites)), then click **Connect**.
11494 
115* **Domain**: the hostname to allow; a wildcard is allowed as the leftmost label, like `*.example.com`, and covers subdomains at any depth but not `example.com` itself
116* **Ports**: `443` unless the service listens on another port
95 If you chose the sign-in option, click the form's sign-in button, such as **Sign in with Amplitude**, and sign in with an account made for Claude.
96 </Step>
97</Steps>
11798 
118For example, to let Claude check a vendor's status page at `status.example.org`, enter `status.example.org` in the **Domain** field and leave the other fields as they are.
99After you click **Connect**, the connector's page opens. The line under the new credential's name in the **Access from** table reads **On for all of Slack.** when the credential applies everywhere, or **Not assigned yet. Choose where Claude can use it.** when it waits for you to pick its places under **Assign access**.
119100 
120You don't have to predict the full list up front. When a request is blocked, Claude says so in the thread and names the host, with wording like "blocked by the network egress proxy" (that is, by Agent Proxy); add that host here and retry. If the host is listed and Claude still reports it blocked, check these in order:
101### Connect a service for one workspace or channel
121102 
122* **The bundle is attached to the channel's scope.** Claude can use a Domains entry only in channels whose scope, or an ancestor scope, has this bundle attached; see [Attach bundles to scopes](/docs/claude-tag/admins/attach-to-scope).
123* **The entry matches the exact host.** A wildcard like `*.example.com` doesn't cover `example.com` itself, and `www.example.com` and `example.com` are different hosts.
124* **The request didn't move to another host.** If the page redirects, or loads from a CDN or a sign-in host, allow that host too; Claude names the host it was blocked on.
125* **The port is listed.** Needed only when the service listens on something other than 443.
126* **A minute has passed since you saved the entry.** Agent Proxy picks up a new entry within about a minute, in existing threads as well as new ones, so retry in the same thread after a short wait.
127* **The bundle was attached before the thread started.** A bundle you attach after a thread started isn't guaranteed to reach that thread, so start a fresh thread to use its entries.
128* **The request came from a channel, not a DM.** A bundle attached to a channel doesn't apply in DMs.
103To connect a service that applies in one workspace or channel only, start from that place's page instead of the **Connectors** tab.
129104 
130Typical entries are hosts the work calls without a key, such as a docs site or a public API. Common package registries are usually already reachable through the [environment's Trusted access default](#broad-web-access-through-the-environment), and a host that needs a credential belongs in a [connection](#add-a-connection) instead. Entries appear below the form, and each one can be edited or removed from its row.
105<Steps>
106 <Step title="Open the place's page">
107 Go to [**Organization settings > Claude Tag**](https://claude.ai/admin-settings/claude-tag). Under **Claude's access**, select the **Channels** tab and open the workspace's or channel's page.
108 </Step>
131109 
132<Note>[Agent Proxy](/docs/claude-tag/concepts/agent-identity#agent-proxy) carries only HTTP and HTTPS. A protocol that isn't HTTP, such as SSH, can't cross the proxy, so listing a host here doesn't make it reachable over SSH.</Note>
110 <Step title="Pick the service">
111 On that page, click **Add** under **Claude's access** and select **Connector**. On the dialog's **Connectors** tab, select the service under **Connect new**, or select **Custom connector** there for a service that isn't listed, and click **Continue**.
112 </Step>
133113 
134### Broad web access through the environment
114 <Step title="Enter the credential">
115 In the connect form, enter the credential from the service's [dedicated account](#create-a-dedicated-account-per-service) and click **Connect**.
116 </Step>
117</Steps>
135118 
136Domain entries allow hosts one at a time. For a scope whose work needs more of the web, the environment setting grants broader access. An [environment](/docs/claude-tag/concepts/glossary#environment) is the sandboxed compute configuration the scope's sessions run in, and it carries its own network access setting.
119The credential applies only in that workspace or channel, and a workspace's credential reaches every channel in it. To use it in more places, pick it in each place's row under **Assign access** on the connector's page, selecting **Add place** for a place that isn't listed.
137120 
138A new environment's network access level is Trusted access, which allows a [documented set of package registries and developer hosts](https://code.claude.com/docs/en/cloud-environments#default-allowed-domains). A channel can already reach hosts like `pypi.org` and `registry.npmjs.org` with no domain entry.
121### Set allowed websites
139122 
140To give a scope broader access, create an organization-shared environment with a more permissive level and set it on the scope, as described in [Configure the environment for a scope](/docs/claude-tag/admins/customize#configure-the-environment-for-a-scope). **Full access** allows any domain; see [Network access in the Claude Code docs](https://code.claude.com/docs/en/cloud-environments#network-access) for the other levels.
123List the hosts a credential may be sent to under **Allowed websites** in the connect form. A wildcard works only as the leftmost label, like `*.example.com`; it covers subdomains at any depth but not `example.com` itself. You can't enter `*` alone here; a credential is always limited to specific hosts. To let Claude reach any host without a credential, see [Allow all hosts](#allow-all-hosts).
141124 
142### Allow all hosts
125<Note>You can't save a connector whose **Allowed websites** include an `anthropic.com`, `claude.ai`, or `claude.com` host, such as `api.anthropic.com`.</Note>
143126 
144To allow every host, enter `*` alone as the domain. A `*` entry needs ports assigned. It admits any host on those ports, with no credential attached.
127Check the host against your account's region before saving. Some services fill a default host that may not match your account's region; a Datadog key, for example, only works against your account's Datadog site, like `api.datadoghq.com` or `api.datadoghq.eu`.
145128 
146With `*` active:
129Where the connect form has a **Test connection** button, the test can check the service's default host rather than the one you entered, so a key for a regional or self-hosted instance can fail the test and still work. Replace the prefilled host with your service's API host rather than adding yours alongside it. You can save the connector even if the test fails, and the credential is sent only to the hosts you listed.
147130 
148* Requests to hosts that no connection covers go through with no credential attached.
149* A `*` entry never carries a credential, and a connection's credential still travels only to its [allowed websites](#set-allowed-websites).
150* Private and internal network addresses and cloud metadata endpoints remain blocked.
131To change a credential's name or hosts after saving, open the **⋮** menu on its row in the connector page's **Access from** table and select **Edit**. Where the **Edit connection** dialog lets you change the hosts, the field is labeled **Allowed hosts**.
151132 
152### Web search vs. network requests
133### Send a setup link to another admin
153134 
154Web search needs no domain entry, connection, or environment setting. It's [Anthropic's built-in web search tool](https://platform.claude.com/docs/en/agents-and-tools/tool-use/web-search-tool), and the searching happens on Anthropic's servers rather than in the channel's sandbox, so no allow layer applies.
135When someone else holds a service's secret, send them a setup link instead of collecting the secret yourself. In the service's connect form, click **Copy setup link for another admin**. Whoever opens the link signs in to your Claude organization and submits the credential there. They don't need an admin role.
155136 
156Opening a page is not part of the search. A search returns content from the pages it matches, which Claude reads and cites; fetching a URL from the sandbox is a network request like any other, and the host needs an allow layer. Claude can answer from a page that search surfaced yet report that it can't open the same link.
137<Note>Setup links work for the Bearer and Basic credential types. For other types the button is unavailable.</Note>
157138 
158If the work needs Claude to open and read pages rather than answer from search results, allow those hosts through the settings above. [Web search vs. network requests](/docs/claude-tag/concepts/agent-identity#web-search-vs-network-requests) covers the session mechanics behind the split.
139After the teammate submits the credential, it waits for your approval. Go to [**Notifications**](https://claude.ai/admin-settings/notifications) in admin settings, open the **Requests** tab, and click **Review** on the **Approval needed** row. Then click **Approve** or **Reject**. The credential becomes active only after you approve it.
159140 
160## Add a connection
141A link that hasn't been used yet is listed in one of two places:
161142 
162On the bundle's **Credentials** tab, click **Connect** next to a listed service, or next to **Custom tool** for a service not in the list.
143* **If the service already has a connector page**: the link shows there as a row in **Access from** that reads **Setup link waiting for a teammate**, or **Setup link expired** once it lapses
144* **If no connector covers the service yet**: the link is listed on the **Connectors** tab, under **Setup links waiting for a teammate**
163145 
164For a custom connection, choose the credential type:
146In both places, the row's **⋮** menu has **Revoke link**, and **Copy link for another admin** until the link expires.
165147 
148### Claude Tag connectors vs personal claude.ai connectors
149 
150The **Add a connector** dialog lists services Claude can hold its own credential for, not the connectors your organization or its members have set up on claude.ai. A Claude Tag connector authenticates the agent, not a person; a connector on someone's personal claude.ai account doesn't appear there. For Google services, use a service-account key or sign in with an account made for Claude, both of which give the agent one credential with access to the data the channel needs. Personal connectors keep working in [DMs](/docs/claude-tag/concepts/agent-identity#direct-message-channels).
151 
152## Change an existing connector
153 
154You change where a connector applies, and which credentials it holds, on the connector's page. To open it, go to [**Organization settings > Claude Tag**](https://claude.ai/admin-settings/claude-tag), select the **Connectors** tab under **Claude's access**, and select the connector. On that page, **Assign access** lists where Claude can use the connector, and the **Access from** table lists each credential Claude holds for the service.
155 
156### Restrict a connector to some channels
157 
158For a connector you added from the **Connectors** tab, the **Slack** row under **Assign access** holds its first credential in the **Access** column, so every workspace and channel has it.
159 
160When a bundle holds the connector's credential along with other access, such as other connectors, **Assign access** can't add that credential to a place or take it off one. If **Assign access** refuses a credential with "This credential was added for one place only", that credential stays where it is. To use the service in another place, connect it again there, as [Use a different credential in one workspace or channel](#use-a-different-credential-in-one-workspace-or-channel) describes.
161 
162<Steps>
163 <Step title="Open the connector's page">
164 Go to [**Organization settings > Claude Tag**](https://claude.ai/admin-settings/claude-tag). Under **Claude's access**, select the **Connectors** tab, then select the connector to open its page.
165 </Step>
166 
167 <Step title="Take the credential off the Slack row">
168 Under **Assign access**, open the picker in the **Access** column of the **Slack** row and clear the credential's checkbox.
169 </Step>
170 
171 <Step title="Add each place that keeps the connector">
172 Click **Add place** and choose the workspace or channel under **Where**. The dialog fills in one of the connector's credentials under **Credential**, which you can change if the connector holds more than one. Click **Add**, and repeat for each place that should keep the connector. A workspace you add also covers every channel in it.
173 </Step>
174 
175 <Step title="Save">
176 Click **Save changes**.
177 </Step>
178</Steps>
179 
180Each row's **Access** picker lists the connector's own credentials first, then each bundle on the **Bundles** tab that holds one of its credentials. Selecting a bundle there attaches that bundle at the place, along with everything else the bundle holds.
181 
182### Manage a connector's credentials
183 
184A connector's credentials are listed in the **Access from** table on its page, which you open by selecting the connector on the **Connectors** tab.
185 
186* **Edit, rotate, or remove a credential**: open the row's **⋮** menu and select **Edit**, **Rotate secret** where the credential type supports it, or **Remove credential**
187* **Add a second credential for the same service**: open the **⋮** menu at the top of the connector's page and select **Add credential**. A second credential is off everywhere until you choose where Claude may use it under **Assign access**.
188* **Remove the connector and all its credentials**: select **Remove connector** from the menu at the top of its page. If a bundle holds one of its credentials, delete that credential on the bundle's page first.
189 
190The table's **Set by** column reads **Here** for a credential added directly, or names the bundle for a credential that a bundle on the **Bundles** tab holds. A credential whose **Set by** column names a bundle has no **Remove credential**; remove it on that bundle's page instead.
191 
192### Use a different credential in one workspace or channel
193 
194To give one workspace or channel its own credential for a service Claude already holds a credential for, start from that place's page and follow [Connect a service for one workspace or channel](#connect-a-service-for-one-workspace-or-channel). Under **Connect new**, the service shows **Connect a different** *service* **credential** under its name.
195 
196* **If the place has its own credential for that service**: the new one replaces it
197* **If the place inherits the service**: Claude uses the new credential there instead of the one it inherits from its workspace or from **Slack**
198 
199Where the credential can't be changed at that place, such as when a channel rule brings the service there, the row is unavailable and says why.
200 
201If you send a [setup link](#send-a-setup-link-to-another-admin) from the connect form for a custom connector or for a credential that replaces one, the place doesn't switch on its own. Once the link is used, pick the new credential for the place under **Assign access** on the connector's page.
202 
203### Restrict by path or method
204 
205After you save a credential, you can narrow it further than its allowed websites. Select **Edit** from the **⋮** menu on its row in the connector page's **Access from** table. Where the credential has an allow rule, the **Edit connection** dialog lets you restrict it by HTTP method and path, for example to allow `GET` but not `DELETE`.
206 
207To narrow a credential before any channel can use it, add the connector to a new [bundle](#create-a-bundle), select **Edit** from the menu on its row under **What's in it**, and add the bundle's places last.
208 
209Agent Proxy starts applying an edit to a credential or a domain entry within about a minute after you save it, in existing threads as well as new ones. It checks the channel's credentials and domain entries first, then the workspace's, then the organization's, and within each by priority. A request that matches no credential, no domain entry, and nothing in the environment's network access is blocked. Private IP ranges and cloud metadata endpoints stay blocked regardless.
210 
211<a id="your-first-access-bundle" />
212 
213## Create a bundle
214 
215A [bundle](/docs/claude-tag/concepts/glossary#access-bundle) is a named set of connectors, repositories, domain entries, plugins, and instructions that Claude takes on wherever the bundle applies. Use one to give a group of channels the same access, and to add a connector to only some channels from the start.
216 
217<Steps>
218 <Step title="Create the bundle">
219 Go to [**Organization settings > Claude Tag**](https://claude.ai/admin-settings/claude-tag). Under **Claude's access**, select the **Bundles** tab and click **Add**. In the **Create a bundle** dialog, enter a **Name** and an optional **Description**, pick a **Color** and **Icon**, and click **Create**. The bundle's page opens.
220 </Step>
221 
222 <Step title="Add what's in it">
223 Under **What's in it**, click **Add** and choose **Connector**, **Repository**, **Domain**, or **Plugin**. Each item saves as soon as you add it. A connector added here applies only where the bundle applies.
224 </Step>
225 
226 <Step title="Choose where it applies">
227 Under **Where it applies**, turn on the switch in the **Slack** row to apply the bundle in every workspace and channel, or in a workspace's row to apply it in that workspace. For a channel, click **Add place**, choose the channel under **Where**, and click **Add**. Then click **Save changes**. A bundle applies nowhere until you turn on a row or add a place.
228 </Step>
229</Steps>
230 
231To add an existing bundle from a workspace or channel instead, open that place's page from the **Channels** tab, click **Add** under **Claude's access**, and select **Bundle**. [Attach bundles to workspaces and channels](/docs/claude-tag/admins/attach-to-scope) covers channel rules and how bundles combine.
232 
233Name a bundle after what it grants, since the name is what you'll read when deciding which bundles to add to a channel: `data-readonly`, `github-write`, `monitoring`, `gtm-tools`. A capability name stays meaningful when the same bundle serves several teams; a team name (`devprod-team`) works when one team's full access is the unit you'll reuse.
234 
235Use the bundle's **Instructions** section for guidance that should travel with its connectors; use [workspace or channel instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions) for guidance tied to a place.
236 
237### Why create more than one bundle
238 
239Multiple bundles let you grant access by capability and compose it per channel. For example, with separate `data-readonly`, `github-write`, and `monitoring` bundles, `#platform-eng` gets all three, `#gtm-analytics` gets only `data-readonly`, and `#incidents` gets `monitoring` plus `github-write`. Each credential is defined once, so rotating a Datadog key means editing one bundle without touching the others.
240 
241## Connect a service that isn't in the list
242 
243The **Add a connector** list covers common services, not the full set Claude can connect to. Any app with an API can be connected. In the **Add a connector** dialog, select **Custom connector** at the bottom of the list. See the [custom connector guide](/docs/claude-tag/admins/connections/custom) for the form fields, credential types, and how to add a custom MCP server.
244 
245For a custom connector, choose the **Credential type** that matches how the service authenticates:
246 
166247| Credential type | Use for |
167248| :- | :- |
168249| Bearer | API keys and OAuth bearer tokens. Most SaaS REST APIs. |
from line 256
175256| OAuth 2.0 client credentials | Server-to-server OAuth. Salesforce uses this. |
176257| MCP Connector | Sign in once as an admin; the agent acts as that account. The picker offers a fixed set of providers plus the [remote MCP connectors](/docs/connectors/custom/add-unlisted) your organization has added on claude.ai. Other OAuth APIs can't be connected this way. |
177258 
178For GitHub repositories, use the GitHub connection at [Configure GitHub access](/docs/claude-tag/admins/configure-github) rather than a credential from this table.
259For GitHub repositories, use the Claude GitHub App at [Configure GitHub access](/docs/claude-tag/admins/configure-github) rather than a credential from this table.
179260 
180261Credentials are injected at the network boundary by Agent Proxy; the model and the sandbox are not given the key. A request to a host you haven't allowed is blocked, not sent. See [how Agent Proxy works](/docs/claude-tag/concepts/agent-identity#agent-proxy).
181262 
182### Send a setup link to another admin
263You can also add connectors from a channel's [Configure page](/docs/claude-tag/users/good-habits#configure-claude-for-a-channel). The option to add one appears there only for people who can manage Claude's setup for that channel or for the whole organization. [Channel managers](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) can manage setup for their assigned channels. Other channel members see the channel's connectors on the Configure page but can't add one.
183264 
184When someone else holds a service's secret, create a setup link instead of collecting the secret yourself. On the service's row in the **Credentials** tab, open the **Connect** button's menu and select **Copy link for another admin**. Whoever opens the link signs in to your Claude organization and submits the credential there. They don't need an admin role.
265## Allow a host without a credential
185266 
186The row tracks the link. It shows **Pending** until the credential is submitted, then **Approval needed**. Select **Review** to check the submission and approve or reject it. The credential becomes active only after you approve it. The row shows **Expired** for a link that went unused, and until the credential is submitted you can revoke the link from the row's **⋮** menu.
267Claude does channel work in an isolated [sandbox](/docs/claude-tag/concepts/agent-identity#channel-sessions). A network request is traffic that sandbox sends to a host, such as an API call, a `curl` fetch, or a package install. Before Claude can make one from a channel, the destination host has to be allowed by one of three settings, the allow layers:
187268 
188Setup links are available for services that use the Bearer or Basic credential type. For other types, the **Connect** menu has no link option.
269* **A domain entry**: a hostname added to a bundle that applies to the channel. Requests to it pass with no credential attached; see [Add a domain](#add-a-domain).
270* **A [connector](#add-a-connector)**: a credential that applies to the channel. Requests matching its [allowed websites](#set-allowed-websites) pass with that credential attached.
271* **The channel's [environment](/docs/claude-tag/concepts/glossary#environment)**: the compute configuration the channel's sessions run in, which carries its own network access setting, starting at the Trusted access level that covers common package registries. Requests to hosts it allows pass with no credential; see [Broad web access through the environment](#broad-web-access-through-the-environment).
189272 
190### Set allowed websites
273A host that none of these allows stays unreachable, and when more than one bundle applies to a channel, the entries of all of them apply. Web search is governed by none of them, because searching happens on Anthropic's servers rather than in the sandbox; see [Web search vs. network requests](#web-search-vs-network-requests).
191274 
192List the hosts a connection's credential may be sent to. A wildcard works only as the leftmost label, like `*.example.com`; it covers subdomains at any depth but not `example.com` itself. You can't enter `*` alone here; a credential is always limited to specific hosts. To let Claude reach any host without a credential, see [Allow all hosts](#allow-all-hosts).
275### Add a domain
193276 
194<Note>You can't save a connection whose **Allowed websites** include an `anthropic.com`, `claude.ai`, or `claude.com` host, such as `api.anthropic.com`.</Note>
277A domain entry allowlists one hostname for every channel a bundle applies to. After you add it, requests from those channels' sandboxes to that host go through with no credential attached.
195278 
196To change a connection's name or allowed websites after saving, open the **⋮** menu on that connection's row in the bundle's **Credentials** tab and choose **Edit**; the **Edit connection** dialog labels the field **Allowed hosts**. The same menu has **Rotate secret** (where the credential type supports it) and **Delete**.
279Open the bundle's page from the **Bundles** tab under **Claude's access** in [**Organization settings > Claude Tag**](https://claude.ai/admin-settings/claude-tag). Under **What's in it**, click **Add** and choose **Domain**. To add the domain for one workspace or channel instead, open that place's page from the **Channels** tab, click **Add** under **Claude's access**, and select **Domain**. Fill in the **Add a domain** dialog and click **Add**:
197280 
198Check the host against your account's region before saving. Some presets fill a default host that may not match your account's region; a Datadog key, for example, only works against your account's Datadog site, like `api.datadoghq.com` or `api.datadoghq.eu`.
281* **Domain**: the hostname to allow; a wildcard is allowed as the leftmost label, like `*.example.com`, and covers subdomains at any depth but not `example.com` itself
282* **Ports**: `443` unless the service listens on another port
283* **Advanced**: the HTTP methods the entry allows, **Read-only** (`GET`, `HEAD`, and `OPTIONS`) unless you change it. Select **All methods** or **Custom** for a host that needs other methods, such as the `POST` requests an MCP server or `git clone` sends
199284 
200Where the connection form has a **Test connection** button, the test can check the preset's default host rather than the one you entered, so a key for a regional or self-hosted instance can fail the test and still work. Replace the prefilled host with your service's API host rather than adding yours alongside it. You can save the connection even if the test fails, and the credential is sent only to the hosts you listed.
285For example, to let Claude check a vendor's status page at `status.example.org`, enter `status.example.org` in the **Domain** field and leave the other fields as they are.
201286 
202### Restrict by path or method
287You don't have to predict the full list up front. When a request is blocked, Claude says so in the thread and names the host, with wording like "blocked by the network egress proxy" (that is, by Agent Proxy); add that host here and retry. If the host is listed and Claude still reports it blocked, check these in order:
203288 
204After saving, you can narrow a connection. Select **Edit** on the connection's row in the bundle's **Credentials** tab. The **Edit connection** dialog lets you rename the connection and, where the connection has an allow rule, restrict it by HTTP method and path, for example to allow `GET` but not `DELETE`.
289* **The bundle applies to the channel.** The bundle's **Where it applies** list must include the channel, its workspace, a channel group that matches it, or **Slack**; see [Attach bundles to workspaces and channels](/docs/claude-tag/admins/attach-to-scope).
290* **The entry matches the exact host.** A wildcard like `*.example.com` doesn't cover `example.com` itself, and `www.example.com` and `example.com` are different hosts.
291* **The request didn't move to another host.** If the page redirects, or loads from a CDN or a sign-in host, allow that host too; Claude names the host it was blocked on.
292* **The port is listed.** Needed only when the service listens on something other than 443.
293* **The method is allowed.** A **Read-only** entry doesn't allow `POST`, `PUT`, `PATCH`, or `DELETE` requests to the host.
294* **A minute has passed since you saved the entry.** Agent Proxy picks up a new entry within about a minute, in existing threads as well as new ones, so retry in the same thread after a short wait.
295* **The bundle applied before the thread started.** A bundle added to a channel after a thread started isn't guaranteed to reach that thread, so start a fresh thread to use its entries.
296* **The request came from a channel, not a DM.** A bundle added to a channel doesn't apply in DMs.
205297 
206Agent Proxy starts applying an edit to a connection or a Domains entry within about a minute after you save it, in existing threads as well as new ones. It evaluates connections and Domains entries from the most specific scope outward (channel, then workspace, then organization), and within a scope by priority; the first match decides. A request that matches no connection, no Domains entry, and nothing in the environment's network access is blocked. Private IP ranges and cloud metadata endpoints stay blocked regardless.
298Typical entries are hosts the work calls without a key, such as a docs site or a public API. Common package registries are usually already reachable through the [environment's Trusted access default](#broad-web-access-through-the-environment), and a host that needs a credential belongs in a [connector](#add-a-connector) instead. Entries appear under **What's in it** with the type **Domain**, and each row's menu has **Edit** and **Remove**.
207299 
208### Connections vs claude.ai connectors
300<Note>[Agent Proxy](/docs/claude-tag/concepts/agent-identity#agent-proxy) carries only HTTP and HTTPS. A protocol that isn't HTTP, such as SSH, can't cross the proxy, so a domain entry doesn't make a host reachable over SSH.</Note>
209301 
210The connection gallery lists credential types the agent can hold, not the connectors your organization or its members have set up on claude.ai. A connection authenticates the agent, not a person; a connector on someone's personal claude.ai account doesn't appear here. For Google services, use a service-account key or the MCP Connector sign-in option, both of which give the agent one credential with access to the data the channel needs. Personal connectors keep working in [DMs](/docs/claude-tag/concepts/agent-identity#direct-message-channels).
302### Broad web access through the environment
211303 
212## Attach plugins
304Domain entries allow hosts one at a time. For a channel whose work needs more of the web, the environment setting grants broader access. An [environment](/docs/claude-tag/concepts/glossary#environment) is the sandboxed compute configuration the channel's sessions run in, and it carries its own network access setting.
213305 
214A plugin is a packaged set of skills: reusable instructions for working with a specific tool or following a specific process. Attach a plugin to the same Access bundle or scope that carries the connection, so the credential arrives with directions for using it.
306A new environment's network access level is Trusted access, which allows a [documented set of package registries and developer hosts](https://code.claude.com/docs/en/cloud-environments#default-allowed-domains). A channel can already reach hosts like `pypi.org` and `registry.npmjs.org` with no domain entry.
215307 
216A Datadog API key, for example, makes the API reachable, and a Datadog plugin tells Claude which endpoints answer which questions. Once you turn a plugin on for a bundle or add it to a scope, sessions in the channels that bundle or scope covers pick up the plugin automatically. A channel member can also add a plugin available to your organization, by asking Claude in the channel or from the channel's [Configure page](/docs/claude-tag/users/good-habits#configure-claude-for-a-channel), unless an admin has [restricted editing to admins](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions).
308To give a workspace or channel broader access, create an organization-shared environment with a more permissive level and set it on that place's page, under **Advanced > Sessions > Environment**, as described in [Configure the environment for a scope](/docs/claude-tag/admins/customize#configure-the-environment-for-a-scope). **Full access** allows any domain; see [Network access in the Claude Code docs](https://code.claude.com/docs/en/cloud-environments#network-access) for the other levels.
217309 
218Anthropic provides plugins for common tools and processes, and you can add your own from a [skills repository](/docs/claude-tag/admins/skills-repo). To give Claude organization-wide skills, package them as a plugin.
310### Allow all hosts
219311 
220Admins and channel members turn plugins on in different places:
312To allow every host, enter `*` alone as the **Domain** in the **Add a domain** dialog. A `*` entry needs ports assigned. It admits requests to any host on those ports that use a method the entry allows, with no credential attached. A new entry is **Read-only** until you select **All methods** or **Custom** under **Advanced**, as [Add a domain](#add-a-domain) describes.
221313 
222* A plugin added directly on a scope (the plugin chips on the scope's panel) is enabled there as soon as you add it.
223* A bundle's **Plugins** tab lists the plugins available to your organization, each off until you toggle it on.
224* A channel member can ask Claude to add a plugin to their channel, unless an admin has [restricted editing to admins](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions). Claude proposes the change and adds the plugin only after someone in that channel selects **Confirm**.
314With `*` active:
225315 
226Adding a plugin for your whole organization makes it available, not active. The plugin takes effect only where a bundle enables it or a scope adds it directly.
316* Requests the entry allows, to hosts that no connector covers, go through with no credential attached.
317* A `*` entry never carries a credential, and a connector's credential still travels only to its [allowed websites](#set-allowed-websites).
318* Private and internal network addresses and cloud metadata endpoints remain blocked.
227319 
320<a id="web-search-vs-network-requests" />
321 
322### Web search vs. network requests
323 
324Web search needs no domain entry, connector, or environment setting. It's [Anthropic's built-in web search tool](https://platform.claude.com/docs/en/agents-and-tools/tool-use/web-search-tool), and the searching happens on Anthropic's servers rather than in the channel's sandbox, so no allow layer applies.
325 
326Opening a page is not part of the search. A search returns content from the pages it matches, which Claude reads and cites; fetching a URL from the sandbox is a network request, and the host needs an allow layer. Claude can answer from a page that search surfaced yet report that it can't open the same link.
327 
328If the work needs Claude to open and read pages rather than answer from search results, allow those hosts through the settings above. [Web search vs. network requests](/docs/claude-tag/concepts/agent-identity#web-search-vs-network-requests) covers the session mechanics behind the split.
329 
330## Attach plugins
331 
332A plugin is a packaged set of skills: reusable instructions for working with a specific tool or following a specific process. Add a plugin wherever its connector applies, so the credential arrives with directions for using it.
333 
334A Datadog API key, for example, makes the API reachable, and a Datadog plugin tells Claude which endpoints answer which questions. Sessions in the channels where you add a plugin pick it up automatically.
335 
336Where you add a plugin decides where it applies:
337 
338* **All of Slack**: under **Claude's access**, select the **Skills and plugins** tab, click **Add**, pick the plugin or skill, and click **Add**. To limit it afterward, open its page from the same tab and use **Assign access**.
339* **Wherever a bundle applies**: on the bundle's page, under **What's in it**, click **Add** and choose **Plugin**.
340* **One workspace or channel**: on that place's page, under **Claude's access**, click **Add** and select **Plugin** or **Skill**, then pick the plugin or skill in the dialog and click **Add**. The dialog lists only the plugins and skills already on the **Skills and plugins** tab. For one that isn't on the tab yet, add it there and then limit it under **Assign access** on its page, or add a plugin to a bundle that applies to the place.
341* **Along with a connector**: when a connect form shows a checkbox to include the service's plugin, leave it selected to add that plugin with the credential.
342* **By a channel member**: a member can ask Claude to add a plugin available to your organization, in the channel or from the channel's [Configure page](/docs/claude-tag/users/good-habits#configure-claude-for-a-channel), unless **Channel member edits** is set to **Block**; see [Restrict who can set channel instructions](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions). Claude proposes the change and adds the plugin only after someone in that channel selects **Confirm**.
343 
344Anthropic provides plugins for common tools and processes, and you can add your own from a [skills repository](/docs/claude-tag/admins/skills-repo). To give Claude organization-wide skills, package them as a plugin. Adding a plugin to your organization's library on claude.ai makes it available to Claude, not active; it takes effect only where you add it in one of the ways above.
345 
228346Adding or removing plugins and skills applies to new threads only. A thread already running keeps the set it began with; start a fresh thread to pick up changes. See [What survives between replies](/docs/claude-tag/concepts/how-it-works#what-survives-between-replies).
229347 
230348Claude can't publish a new skill version from inside a thread; that update happens in admin settings.
from line 351
233351 
234352Anthropic's **Security Guidance** [plugin](https://code.claude.com/docs/en/plugins) has Claude review the code it writes. With the plugin on in a channel, Claude is warned about risky patterns as it edits files, and the plugin reviews the code changes in the session's repository when Claude commits, pushes, or finishes a reply, checking for vulnerabilities such as injection, cross-site scripting, and hardcoded secrets. Claude addresses the findings or reports them in the thread.
235353 
236**Security Guidance** is off by default. Add it directly on a scope, or turn it on in a bundle's **Plugins** tab, and new threads in covered channels pick it up. The plugin flags problems and suggests fixes; it doesn't block a commit or a push. To require review before code merges, use your repository's branch protection and required checks.
354**Security Guidance** is off by default. Add it on the **Skills and plugins** tab or a bundle's page, and new threads in the channels it covers pick it up. The plugin flags problems and suggests fixes; it doesn't block a commit or a push. To require review before code merges, use your repository's branch protection and required checks.
237355 
238## Verify the connection saved
356<a id="verify-the-connection-saved" />
239357 
240* Each connection is listed in the bundle with the host you set.
241* The [Access bundles page](https://claude.ai/admin-settings/claude-tag/access-bundles) shows a status for each connection when you expand the bundle.
242 * **Active**: Claude can send the credential to its allowed hosts
243 * **Not active**: the secret is stored but no allow rule uses it yet, so Claude can't send it.
244 * **Approval needed**: another admin submitted the credential through a shared setup link. Select **Review** on its row, then **Approve**.
245 * **Used** with a time, or **Never used**: when Claude last sent the credential; independent of the status
246* New threads pick up new connections on their own. An existing thread isn't told about a connection added after it started, but the connection works there; ask Claude to use the service by name.
358## Verify the connector saved
247359 
360* The connector appears on the **Connectors** tab, under **Services** or **Custom hosts**.
361* On the connector's page, the **Access from** table lists each credential with the hosts it's sent to, and its **Used at** column shows where it applies.
362* A credential marked **Not enabled** is stored, but no allow rule sends it yet, so Claude can't use it. To let Claude reach its hosts with the credential, click **Enable** beside it and confirm.
363* A credential a teammate submitted through a setup link waits on the **Requests** tab of [**Notifications**](https://claude.ai/admin-settings/notifications) as **Approval needed** until you review and approve it.
364* New threads pick up new connectors on their own, and a connector that uses a key or token works in a thread that started before you added it.
365 
248366## Related resources
249367 
250* [Set a spend limit](/docs/claude-tag/admins/set-spend-limit): fund usage so the connections you just added can run
368* [Set a spend limit](/docs/claude-tag/admins/set-spend-limit): fund usage so the connectors you just added can run
251369* [Configure GitHub access](/docs/claude-tag/admins/configure-github): repository access, managed through the Claude GitHub App
252370* [How agent identity works](/docs/claude-tag/concepts/agent-identity#agent-proxy): how the credentials you just added reach Claude without entering its sandbox
253371 

claude-tag/admins/attach-to-scope Changed · +131 / -99 lines

## Choose where a bundle applies #### Set up a channel before Claude joins ## Attach a bundle to channels by name ### Add a channel rule ### What a channel rule covers ### Where rule-attached bundles appear ## Add a single connector, repository, plugin, or skill ### Check or remove what a place has ## Set and restrict custom instructions #### Instruction format #### What Claude reads in a channel #### When a new instruction applies ## Attach the bundle ### Attach a bundle to channels by name #### Where rule-attached bundles appear ### Attach a single repository or connector

from line 1
11# Configure per-channel access
22 
3> Choose which Slack channels and workspaces a set of Claude Tag credentials applies to. Covers inheritance, overlap rules, and adding channels after setup.
3> Choose which Slack workspaces and channels a Claude Tag bundle applies to, attach bundles to channels by name, and see how access stacks when bundles overlap.
44 
55export const BetaNote = () => <Info>Claude Tag is in public beta. Features and behavior described here may change before general availability.</Info>;
66 
77<BetaNote />
88 
9This page covers adding access to more workspaces and channels, and how access stacks when several bundles apply to the same place. It assumes you have already [paired a workspace](/docs/claude-tag/admins/setup-overview#pair-your-slack-workspace) and [created an Access bundle](/docs/claude-tag/admins/add-connections). You must be an Owner in your Claude organization, or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration), to attach a bundle to the organization, a workspace, or a channel. [Attaching a bundle by channel name](#attach-a-bundle-to-channels-by-name) needs an Owner.
9A bundle applies at one of three levels, called scopes, and each has its own page on the **Channels** tab under **Claude's access** at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag). The **Slack** page covers every connected workspace and channel, a workspace's page covers the channels in that workspace, and a channel's page covers one channel. Bundles inherit downward through those scopes, and when credentials overlap, Claude uses the one from the narrowest scope.
1010 
11A scope is where a bundle applies: **Default Slack access** (the organization-wide root), a workspace, or a single channel. Bundles inherit downward through those scopes, and when credentials overlap, the narrowest scope wins.
11An Owner in your Claude organization, or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration), can choose where a bundle applies. Attaching a bundle to channels by name needs an Owner.
1212 
13This page assumes you have already [paired a workspace](/docs/claude-tag/admins/setup-overview#pair-your-slack-workspace) and [created a bundle](/docs/claude-tag/admins/add-connections).
14 
1315## How scopes inherit
1416 
15Bundles stack downward. A channel gets whatever is attached at Default Slack access, plus its workspace, plus anything attached to the channel itself.
17Bundles stack downward. A channel gets whatever applies on the **Slack** page, plus its workspace, plus anything added to the channel itself.
1618 
17<img className="block dark:hidden" src="https://mintcdn.com/claude-ai/5JFKyLlO7sHMMf5J/images/claude-tag/diagrams/scope-inheritance.svg?fit=max&auto=format&n=5JFKyLlO7sHMMf5J&q=85&s=673f78c6c43aceb03ed9c81a2de7b0b2" alt="Nested boxes. The outermost box is the Default Slack access scope: a bundle attached here is the baseline every channel gets. Inside it, two examples. Outside the workspace box, a channel called another-team in a different workspace gets only the default bundle. Inside the workspace box, which adds an optional bundle for channels inside it, two channel boxes: a public channel called general, with no channel bundle, gets the default plus the workspace bundle; a private channel, marked with a lock, with its own channel bundle, gets all three, the default, workspace, and channel bundles." width="1000" height="320" data-path="images/claude-tag/diagrams/scope-inheritance.svg" />
19<img className="block dark:hidden" src="https://mintcdn.com/claude-ai/RSTtvSydy0FU_pcP/images/claude-tag/diagrams/scope-inheritance.svg?fit=max&auto=format&n=RSTtvSydy0FU_pcP&q=85&s=7a225f1cefadc49cd6efaaf093f0b041" alt="Nested boxes. The outermost box is the Slack scope: a bundle attached here is the baseline every channel gets. Inside it, two examples. Outside the workspace box, a channel called another-team in a different workspace gets only the baseline. Inside the workspace box, which adds an optional bundle for channels inside it, two channel boxes: a public channel called general, with no channel bundle, gets the baseline plus the workspace bundle; a private channel, marked with a lock, with its own channel bundle, gets all three, the baseline, workspace, and channel bundles." width="1000" height="320" data-path="images/claude-tag/diagrams/scope-inheritance.svg" />
1820 
19<img className="hidden dark:block" src="https://mintcdn.com/claude-ai/5JFKyLlO7sHMMf5J/images/claude-tag/diagrams/scope-inheritance-dark.svg?fit=max&auto=format&n=5JFKyLlO7sHMMf5J&q=85&s=b53a534b076e6c22f0d86a81841b00a8" alt="Nested boxes. The outermost box is the Default Slack access scope: a bundle attached here is the baseline every channel gets. Inside it, two examples. Outside the workspace box, a channel called another-team in a different workspace gets only the default bundle. Inside the workspace box, which adds an optional bundle for channels inside it, two channel boxes: a public channel called general, with no channel bundle, gets the default plus the workspace bundle; a private channel, marked with a lock, with its own channel bundle, gets all three, the default, workspace, and channel bundles." width="1000" height="320" data-path="images/claude-tag/diagrams/scope-inheritance-dark.svg" />
21<img className="hidden dark:block" src="https://mintcdn.com/claude-ai/RSTtvSydy0FU_pcP/images/claude-tag/diagrams/scope-inheritance-dark.svg?fit=max&auto=format&n=RSTtvSydy0FU_pcP&q=85&s=02fd9b9128af1d3c681f3883ab47223d" alt="Nested boxes. The outermost box is the Slack scope: a bundle attached here is the baseline every channel gets. Inside it, two examples. Outside the workspace box, a channel called another-team in a different workspace gets only the baseline. Inside the workspace box, which adds an optional bundle for channels inside it, two channel boxes: a public channel called general, with no channel bundle, gets the baseline plus the workspace bundle; a private channel, marked with a lock, with its own channel bundle, gets all three, the baseline, workspace, and channel bundles." width="1000" height="320" data-path="images/claude-tag/diagrams/scope-inheritance-dark.svg" />
2022 
2123| Scope | What it covers | Access |
2224| :- | :- | :- |
23| Default Slack access | Every Slack workspace and channel | The baseline set every channel gets |
24| Workspace | All channels in one Slack workspace | Inherits Default Slack access, plus workspace-level bundles |
25| Channel | A single Slack channel, public or private | Inherits Default Slack access and workspace, plus channel-level bundles |
25| **Slack** | Every connected Slack workspace and channel | The baseline set every channel gets |
26| Workspace | All channels in one Slack workspace | Inherits **Slack**, plus workspace-level bundles |
27| Channel | A single Slack channel, public or private | Inherits **Slack** and the workspace, plus channel-level bundles |
2628 
27The same stacking applies in reverse. Detaching a bundle from a channel removes only that channel's additions, and bundles attached at the workspace or Default Slack access still apply there.
29The same stacking applies in reverse. Removing a bundle from a channel removes only that channel's additions, and bundles on the workspace or on **Slack** still apply there.
2830 
2931Memory is also scoped, but differently: there is no organization-wide memory, each channel keeps its own notes, workspace notes saved from public channels are read across the workspace, and a private channel reads the workspace notes but writes only to its own store. See [What Claude Tag remembers](/docs/claude-tag/users/memory).
3032 
31One-to-one DMs from members who have connected a Claude account run under the member's own claude.ai account, so bundles attached here don't apply to them. See [how DMs work in this model](/docs/claude-tag/concepts/agent-identity#direct-message-channels). A [DM from a member who hasn't connected a Claude account](/docs/claude-tag/admins/restrict-access#access-in-a-direct-message-from-a-member-without-a-claude-account) does reach access bundles. A [group DM](/docs/claude-tag/admins/restrict-access#group-dms) gets the bundles on the workspace's scope and on **Default Slack access**.
33One-to-one DMs from members who have connected a Claude account run under the member's own claude.ai account, so bundles don't apply to them. See [how DMs work in this model](/docs/claude-tag/concepts/agent-identity#direct-message-channels). A [DM from a member who hasn't connected a Claude account](/docs/claude-tag/admins/restrict-access#access-in-a-direct-message-from-a-member-without-a-claude-account) does reach bundles. A [group DM](/docs/claude-tag/admins/restrict-access#group-dms) gets the bundles on the workspace's page and on the **Slack** page.
3234 
33## Attach the bundle
35<a id="attach-the-bundle" />
3436 
35Attaching binds the bundle to a workspace scope, to a single channel under it, or to every channel whose name matches a pattern.
37## Choose where a bundle applies
3638 
37The binding takes full effect in new threads only. A thread already running keeps the skills, plugins, and custom instructions it started with. A connection added after a thread started still works there if you ask Claude to use the service by name, but Claude doesn't announce it, so test with a new top-level thread after attaching a bundle. See [What survives between replies](/docs/claude-tag/concepts/how-it-works#what-survives-between-replies).
39A bundle applies nowhere until you add places to it. A place is **Slack**, a workspace, or a channel, the same three scopes, or a [group of channels matched by name](#attach-a-bundle-to-channels-by-name). You can add a place from either side:
3840 
41* **From the bundle's page**: on the **Bundles** tab, open the bundle. Under **Where it applies**, turn on the switch for **Slack** or for a workspace, or select **Add place**, pick a channel under **Where**, and select **Add**. Then select **Save changes**.
42* **From a workspace's or channel's page**: on the **Channels** tab, open the page, select **Add** under **Claude's access**, choose **Bundle**, and pick the bundle.
43 
44To stop a bundle applying somewhere, open the bundle's page and turn off that place's switch under **Where it applies**. For a workspace or channel, you can instead choose **Remove from bundle** from its row menu. Then select **Save changes**. A workspace's or channel's page lists the bundles that reach it, and each links to the bundle's page, but the page itself doesn't remove them.
45 
46The change takes full effect in new threads only. A thread already running keeps the skills, plugins, and custom instructions it started with. A connector added after a thread started still works there if you ask Claude to use the service by name. Test with a new top-level thread after changing where a bundle applies. See [What survives between replies](/docs/claude-tag/concepts/how-it-works#what-survives-between-replies).
47 
3948At the channel's top level, outside any thread, Claude works from a single long-lived channel session. After a configuration change, Claude replaces that session on the next channel message, so top-level replies pick up the change from then on.
4049 
4150### Attach to a workspace
4251 
43Each paired workspace already has a scope; bind a bundle in the scope's **Access bundles** section. On the **Access bundles** page in the left navigation, each bundle's card shows how many places it's used in. To see which scopes those are, open the bundle's **Manage** dialog and hover over the usage count in its footer. To add another workspace, [pair it](/docs/claude-tag/admins/setup-overview#pair-your-slack-workspace) first.
52While a bundle is off for **Slack**, every paired workspace is listed under **Where it applies** on the bundle's page. Turn on the workspace's switch and select **Save changes**, or open the workspace's page on the **Channels** tab and add the bundle with **Add > Bundle** under **Claude's access**. To add another workspace, [pair it](/docs/claude-tag/admins/setup-overview#pair-your-slack-workspace) first.
4453 
4554### Attach to a channel
4655 
47Channels Claude was added to appear on the **Slack** tab automatically, each as a scope under its workspace. To give one of these channels access beyond the workspace baseline, select its row and bind bundles in the scope's **Access bundles** section. A channel row shows the name an admin gave the scope, the channel's name in Slack, or the raw channel ID.
56Channels Claude was added to appear on the **Channels** tab automatically, each listed under its workspace. To give one of these channels access beyond the workspace baseline, open its page and add bundles with **Add > Bundle** under **Claude's access**. A channel row shows the name an admin gave the channel's page, the channel's name in Slack, or the raw channel ID.
4857 
49To find a channel, use the **Search channels** field. It matches channel names and channel IDs (pasting a channel link copied from Slack also works), and searching a workspace's name shows that workspace's channels.
58To find a channel, use the search field on the **Channels** tab. It matches channel names and channel IDs (pasting a channel link copied from Slack also works), and searching a workspace's name shows that workspace's channels.
5059 
51To bind one bundle to several channels in one pass, open the bundle from a scope's **Access bundles** section on the **Slack** tab and select **Add to channels**. The dialog lists channel scopes grouped by workspace, with a search field and a checkbox per channel. Check the channels you want and select **Add**. The bundle binds to each checked channel, and channels it's already bound to directly are marked **Already added**.
60In a channel shared across more than one workspace in your Enterprise Grid, bundles on the channel or its workspace don't apply. See [Channels shared across workspaces in your Enterprise Grid](/docs/claude-tag/admins/restrict-access#channels-shared-across-workspaces-in-your-enterprise-grid) for what Claude does there instead.
5261 
53A channel that doesn't appear in the list yet needs a scope created for it:
62<Warning>A bundle attached to a public channel grants its access to anyone who joins that channel. In most Slack workspaces, anyone can join a public channel, so the channel's join policy becomes the effective access control for whatever the bundle grants. Keep elevated credentials in private channels.</Warning>
5463 
551. On [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), find the workspace on the **Slack** tab under **Claude Tag's access** and select **Add channel**.
562. Pick the channel in the **Channel** field. Type a name to search public channels, or paste a channel ID or channel link copied from Slack. Private channels don't appear in the search results, so for a private channel, paste its ID from the channel's details in Slack. Channel IDs start with `C`, or with `G` for some older private channels.
573. Save, then bind bundles in the new scope's **Access bundles** section, the same as for a workspace.
64#### Set up a channel before Claude joins
5865 
59In a channel shared across more than one workspace in your Enterprise Grid, bundles bound to the channel or its workspace don't apply. See [Channels shared across workspaces in your Enterprise Grid](/docs/claude-tag/admins/restrict-access#channels-shared-across-workspaces-in-your-enterprise-grid) for what Claude does there instead.
66A channel Claude isn't in yet has no page. To set up a public channel before Claude joins it, type at least two characters of its name in the search field. Public channels without a page are listed under **Channels Claude isn't in**. Select **Add Claude here** to create the channel's page, then add bundles to it. The page's settings apply once someone adds Claude to the channel in Slack, since selecting **Add Claude here** doesn't add Claude to the channel. For a private channel, add Claude to the channel in Slack, and its page appears on the **Channels** tab.
6067 
61<Warning>A bundle attached to a public channel grants its access to anyone who joins that channel. In most Slack workspaces, anyone can join a public channel, so the channel's join policy becomes the effective access control for whatever the bundle grants. Keep elevated credentials in private-channel scopes.</Warning>
68## Attach a bundle to channels by name
6269 
63### Attach a bundle to channels by name
70A channel rule attaches a bundle to every channel whose name matches a pattern, instead of channel by channel. Adding or removing a bundle on a pattern, or editing the patterns themselves, needs an Owner of your Claude organization.
6471 
65A bundle attach rule binds a bundle to every channel whose name matches a pattern, instead of channel by channel. Rules are listed in the **Auto-join channels** table, the same table that holds the [auto-join patterns](/docs/claude-tag/admins/restrict-access#block-or-auto-join-channels-by-name), in the collapsed **Advanced** section of the **Default Slack access** panel and of each workspace scope's panel at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag). A rule on **Default Slack access** covers matching channels in every connected workspace; a rule on a workspace scope covers only that workspace's matching channels. Adding or removing a bundle on a pattern, or editing the patterns themselves, needs an Owner of your Claude organization.
72### Add a channel rule
6673 
67Each table row is one channel-name pattern. To create a rule, select **Add bundle** on the pattern's row and pick the bundle; if the pattern isn't listed yet, add it with **Add pattern** first. A pattern added here is also an auto-join pattern, so Claude starts joining matching public channels when they're created or renamed.
74You can add a rule in any of three places under **Claude's access** at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag):
6875 
69For example, if your incident channel names start with `inc-`, add `inc-*` with **Add pattern** and attach your incident-response bundle to its row. Claude then joins each new public incident channel and has the bundle's access there.
76* **The Channels tab**: select **Add**, then **Add a channel rule…**. In the dialog, choose all workspaces or one workspace under **Applies to**, enter the **Channel name pattern**, pick the **Bundle**, and select **Add**. The rule's page opens.
77* **The Auto-join channels table**: on the **Advanced** tab of the **Slack** page or of a workspace's page, find **Auto-join channels** under **Channels**. Each row is one channel-name pattern. Select **Add bundle** on the pattern's row and pick the bundle. If the pattern isn't listed yet, add it with **Add pattern** first.
78* **The bundle's page**: under **Where it applies**, select **Add place** and type a pattern, such as `inc-*`, under **Where**. Select the **Create channel group** option for that pattern, choose the workspace under **Applies to** if you have more than one, and select **Add**. The rule saves at once and covers that one workspace.
7079 
71The rule grants the bundle in every matching channel Claude is in under the scope, including channels it was invited to before the rule existed. The rule itself doesn't add Claude to any channel; only the auto-join patterns, or an invite, do that. A channel whose name matches a [blocked pattern](/docs/claude-tag/admins/restrict-access#block-or-auto-join-channels-by-name) stays off-limits even when a rule matches it. After adding or changing a rule, test with a new thread in a matching channel.
80Whichever way you add it, the pattern is also an [auto-join pattern](/docs/claude-tag/admins/restrict-access#block-or-auto-join-channels-by-name), so Claude starts joining matching public channels when they're created or renamed. After adding or changing a rule, test with a new thread in a matching channel.
7281 
73A rule's pattern follows the same syntax as the other [channel name patterns](/docs/claude-tag/admins/restrict-access#block-or-auto-join-channels-by-name), lowercase with `*` matching any run of characters and `?` matching exactly one. Each scope holds up to 20 bundle attach rules. On a workspace scope, the table also lists the organization's patterns, marked **Org-wide**. You can attach a bundle to an **Org-wide** pattern from the workspace's table, and that rule covers only the workspace's matching channels; you edit the pattern itself on **Default Slack access**.
82For example, if your incident channel names start with `inc-`, add a channel rule for `inc-*` with your incident-response bundle. Claude then joins each new public incident channel and has the bundle's access there.
7483 
75<Warning>A bundle attach rule grants its bundle in every matching channel Claude is in, now or in the future, and anyone who can rename a channel can move it into or out of a pattern. Keep elevated credentials out of broad patterns, and add a [blocked channel pattern](/docs/claude-tag/admins/restrict-access#block-or-auto-join-channels-by-name) for name shapes that should never carry access; a blocked channel stays off-limits whatever rules match it.</Warning>
84### What a channel rule covers
7685 
77#### Where rule-attached bundles appear
86A channel rule grants its bundle under these conditions:
7887 
79When bundle attach rules cover a channel, the channel scope's panel lists their bundles under **Attached here by rule**. The list is read-only, because a channel scope doesn't take rules of its own; to change it, edit the rule on **Default Slack access** or the workspace scope. Rules on **Default Slack access** and rules on the channel's workspace apply together.
88* **Workspaces**: a rule for all workspaces, or on the **Slack** page, covers matching channels in every connected workspace. A rule on one workspace covers only that workspace's matching channels.
89* **Channels Claude is already in**: the rule grants the bundle in every matching channel Claude is in under the scope, including channels it was invited to before the rule existed
90* **Joining channels**: only the auto-join patterns, or an invite, add Claude to a channel. The rule itself doesn't.
91* **Blocked patterns**: a channel whose name matches a [blocked pattern](/docs/claude-tag/admins/restrict-access#block-or-auto-join-channels-by-name) stays off-limits even when a rule matches it
8092 
81### Attach a single repository or connector
93A rule's pattern has its own constraints:
8294 
83To grant a single repository or connector without opening a bundle first, use the **Repositories** and **Connectors** sections on the scope's own panel and select the **+** button (**Add repo** or **Add connector**). When you save the repository or finish connecting, the item is attached to that scope.
95* **Pattern syntax**: a rule's pattern follows the same syntax as the other [channel name patterns](/docs/claude-tag/admins/restrict-access#block-or-auto-join-channels-by-name), lowercase with `*` matching any run of characters and `?` matching exactly one
96* **Number of rules**: each scope holds up to 20 channel rules
97* **Organization patterns**: on a workspace's page, the **Auto-join channels** table also lists the organization's patterns, marked **Org-wide**. You can attach a bundle to an **Org-wide** pattern from the workspace's table, and that rule covers only the workspace's matching channels. You edit the pattern itself on the **Slack** page.
8498 
85Each connector or repository row in these sections carries an origin line that says which scope or bundle gave the scope that item.
99<Warning>A channel rule grants its bundle in every matching channel Claude is in, now or in the future, and anyone who can rename a channel can move it into or out of a pattern. Keep elevated credentials out of broad patterns, and add a [blocked channel pattern](/docs/claude-tag/admins/restrict-access#block-or-auto-join-channels-by-name) for name shapes that should never carry access; a blocked channel stays off-limits whatever rules match it.</Warning>
86100 
87| Origin line | What it means |
88| :- | :- |
89| **Inherited from** *scope* | The row comes from a wider scope. When an admin-made bundle carries it, the line adds **via** and the bundle's name |
90| **Attached from** *bundle* | The row was added on this scope through that admin-made bundle |
101### Where rule-attached bundles appear
91102 
92Select the scope name to open that scope, or the bundle name to open the bundle.
103Each channel rule is listed on the **Channels** tab, and its row opens the rule's page. The rule's page lists its bundles, with **Add bundle** for an Owner, and its **Matching channels** section lists the channels on the **Channels** tab whose names match the pattern. To delete the rule, an Owner chooses **Delete rule** from the page's **⋮** menu.
93104 
94An item you add with the **+** button is still stored in a bundle, chosen in this order:
105A channel's own page lists the bundles a rule attaches there as rows in its **Claude's access** table, alongside bundles added to the channel directly. A channel doesn't take rules of its own. To change which bundles a rule attaches, edit the rule. Rules for all workspaces and rules on the channel's workspace apply together.
95106 
961. The bundle that was created for that scope, if it exists
972. The scope's only bundle, if that bundle is bound nowhere else
983. A new bundle created for the scope
107## Add a single connector, repository, plugin, or skill
99108 
100When the receiving bundle is bound to other scopes too, the picker shows a note that the addition applies in every scope the bundle is bound to.
109To give a place one item without going through a bundle, open the **Slack** page or a workspace's or channel's page from the **Channels** tab, select **Add** under **Claude's access**, and choose **Connector**, **Repository**, **Plugin**, or **Skill**. The dialog opens on that kind's tab, and its **Connectors**, **Plugins**, **Skills**, and **Repositories** tabs switch between kinds. To let Claude reach a host without a credential in that place, choose **Domain** from the same menu, as [Add a domain](/docs/claude-tag/admins/add-connections#add-a-domain) describes.
101110 
111The dialog's **Connectors** tab lists the connectors already on the **Connectors** tab of **Claude's access**, and below them, under **Connect new**, services you can connect for that place; see [Add a connector](/docs/claude-tag/admins/add-connections#add-a-connection). A credential connected from a workspace's or channel's page applies only in that place, and one connected from the **Slack** page applies everywhere. The dialog's **Plugins** and **Skills** tabs list only the plugins and skills already on the **Skills and plugins** tab of **Claude's access**.
112 
113### Check or remove what a place has
114 
115The **Claude's access** table lists every connector, plugin, skill, and repository that reaches the place. A bundle from the **Bundles** tab that reaches the place has a row of its own, with the items it brings listed beneath it. The **Inheritance** column says where each bundle, and each item outside a bundle, comes from.
116 
117Some items are removed on that page, and others elsewhere:
118 
119* **A plugin, skill, or domain whose row reads Added here**: use the row's menu
120* **A connector**: the row has no menu. Select the row to open the connector's page, and change where it applies under **Assign access**.
121* **A repository**: the row has no menu. [Configure GitHub access](/docs/claude-tag/admins/configure-github) covers where a repository applies.
122 
102123## Precedence when bundles overlap
103124 
104A channel sees the **union** of every bundle bound at the channel itself, its workspace, and Default Slack access. Narrower scopes don't replace wider ones; they add to them. When two bundles in the resolved set carry rules for the same host, the rule from the narrower scope wins. Within that union, fixed rules decide which credential and which instructions apply.
125A channel sees the **union** of every bundle that applies at the channel itself, its workspace, and **Slack**. Narrower scopes don't replace wider ones; they add to them. When two bundles in the resolved set carry rules for the same host, the rule from the narrower scope wins. Within that union, fixed rules decide which credential and which instructions apply.
105126 
106127### Which credential wins
107128 
108129When two bundles each carry a credential for the same host:
109130 
110* The credential from the **narrowest scope** is used: channel beats workspace, which beats Default Slack access.
131* The credential from the **narrowest scope** is used: channel beats workspace, which beats **Slack**.
111132* Within the same scope, the order isn't admin-configurable. Avoid binding overlapping credentials at the same scope; if you can't predict which key acts, neither can a security review.
112133* There is no fallback. If the winning credential gets a `401` or `403`, Claude does not retry with the next one.
113134 
114135### Repositories and plugins
115136 
116Repository grants and plugins from every bound bundle are combined as a union; a channel gets every repo and plugin from any bundle in its chain. To see what applies to a channel, select its scope on the **Slack** tab. The scope's panel lists everything that applies there in its **Connectors**, **Repositories**, and **Plugins** sections, inherited items included. Each row's origin line says **Inherited from** the wider scope or **Attached from** the bundle that carries it. Select the scope or bundle name in the origin line to open it.
137Repository grants and plugins from every bundle that applies are combined as a union; a channel gets every repo and plugin from any bundle in its chain. To see what applies to a channel, open its page from the **Channels** tab. Its **Claude's access** table lists everything that applies there, inherited items included, as [Add a single connector, repository, plugin, or skill](#add-a-single-connector-repository-plugin-or-skill) describes.
117138 
118139### Custom instructions
119140 
120Per-scope custom instructions are **concatenated**, Default Slack access first, then workspace, then channel. A channel's instructions add to, rather than replace, what's set above it.
141Per-scope custom instructions are **concatenated**, **Slack** first, then workspace, then channel. A channel's instructions add to, rather than replace, what's set above it. To write them, see [Add custom instructions](#add-custom-instructions).
121142 
143## Set and restrict custom instructions
144 
145[Add custom instructions](#add-custom-instructions) on a scope's page, check the [other instruction layers](#instruction-layers) that apply in the same channel, and [restrict who can edit a channel's instructions](#restrict-who-can-set-channel-instructions).
146 
147### Add custom instructions
148 
149Each scope can carry custom instructions, which are standing guidance Claude reads in every session there, like team conventions or where to file tickets. The field is on the **General** tab of each scope's page on the **Channels** tab. It's labeled **Slack instructions** on the **Slack** page, and **Workspace instructions** or **Channel instructions** on a workspace's or channel's page. The field doesn't save as you type, so save your edit from the bar that appears under it.
150 
151Channel members reach the same field for the channel scope through the **Configure** page, linked in the footer of any Claude reply in the channel, without going through admin settings. Both entry points write the same instructions, so a change from either place is visible in the other.
152 
153To let a central team write a channel's instructions from its own Slack channel, see [Manage a channel's instructions from another channel](/docs/claude-tag/admins/managed-by).
154 
155#### Instruction format
156 
157The field is plain text, inserted as written; there is no include or template syntax, and `{{include:...}}` is passed through literally. To give Claude a repository's `CLAUDE.md`, [grant the repository](/docs/claude-tag/admins/configure-github#grant-repository-access) and name it in the request; its `CLAUDE.md` loads after the clone completes.
158 
159#### What Claude reads in a channel
160 
161What Claude reads in a channel is the concatenated custom instructions of its scope chain, the instructions of each bundle that applies there, the channel's [managed instructions](/docs/claude-tag/admins/managed-by#how-managed-instructions-load) if another channel manages it, and the `CLAUDE.md` of any repository it clones. Projects in claude.ai don't apply here; Claude doesn't read a Project's instructions or knowledge in Slack, and a channel can't be pointed at a Project.
162 
163#### When a new instruction applies
164 
165A new instruction applies to sessions started after you save it. Claude reads it in every new thread right away, keeps the old text in a thread that's already running, and picks it up at the channel's top level on the next channel message, when it replaces the channel's session (see [Choose where a bundle applies](#attach-the-bundle)). Claude doesn't read a channel's instructions in another channel or in a DM. To confirm what a session is reading, start a new thread and ask Claude to repeat its admin instructions.
166 
122167### Instruction layers
123168 
124169The table lists the kinds of standing instruction that can apply in a channel and who writes each.
from line 170
125170 
126171| Layer | Who writes it | Where |
127172| :- | :- | :- |
128| Custom instructions | Owner for any scope; [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) for workspace and channel scopes; channel members and [channel managers](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) for the channel scope, unless members are [restricted](#restrict-who-can-set-channel-instructions) | The scope's panel in admin settings, or the **Configure** link in any reply footer for the channel scope |
173| Custom instructions | Owner for any scope; [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) for workspace and channel scopes; channel members and [channel managers](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) for the channel scope, unless members are [restricted](#restrict-who-can-set-channel-instructions) | The instructions field on a scope's page in admin settings, or the **Configure** link in any reply footer for the channel scope |
174| Bundle instructions | An Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) | The **Instructions** section of the bundle's page. They apply wherever the bundle applies |
129175| Managed instructions | Full workspace members in one of the channel's [managing channels](/docs/claude-tag/admins/managed-by), which an Owner or a Claude Tag admin selects under **Managed by** on the channel's Configure page | By asking Claude in the managing channel and confirming the card it posts |
130176| Channel memory | Anyone in the channel | By telling Claude to remember |
131177| Task prompt | The requester | The message itself |
from line 180
134180 
135181Custom instructions are read ahead of the conversation and take priority in practice, but they're guidance, not an enforced guardrail. Don't rely on them to block actions; use access controls for that.
136182 
137### Add custom instructions
138 
139Each scope can carry custom instructions, which are standing guidance Claude reads in every session there, like team conventions or where to file tickets. The **Custom instructions** field is on the scope's panel, shown when you select the scope on the **Slack** tab in admin settings.
140 
141Channel members reach the same field for the channel scope through the **Configure** page, linked in the footer of any Claude reply in the channel, without going through admin settings. Both entry points write the same instructions, so a change from either place is visible in the other.
142 
143The field is plain text, inserted as written; there is no include or template syntax, and `{{include:...}}` is passed through literally. To give Claude a repository's `CLAUDE.md`, [grant the repository](/docs/claude-tag/admins/configure-github#grant-repository-access) and name it in the request; its `CLAUDE.md` loads after the clone completes.
144 
145What Claude reads in a channel is the concatenated custom instructions of its scope chain, the channel's [managed instructions](/docs/claude-tag/admins/managed-by#how-managed-instructions-load) if another channel manages it, and the `CLAUDE.md` of any repository it clones. Projects in claude.ai don't apply here; Claude doesn't read a Project's instructions or knowledge in Slack, and a channel can't be pointed at a Project.
146 
147A new instruction applies to sessions started after you save it. Claude reads it in every new thread right away, keeps the old text in a thread that's already running, and picks it up at the channel's top level on the next channel message, when it replaces the channel's session (see [Attach the bundle](#attach-the-bundle)). Claude doesn't read a channel's instructions in another channel or in a DM. To confirm what a session is reading, start a new thread and ask Claude to repeat its admin instructions.
148 
149To let a central team write a channel's instructions from its own Slack channel, see [Manage a channel's instructions from another channel](/docs/claude-tag/admins/managed-by).
150 
151183### Restrict who can set channel instructions
152184 
153By default, anyone in a channel who is also a member of your Claude organization can edit that channel's instructions from the **Configure** link in Claude's reply footer. The **Channel member edits** setting in a scope's **Advanced** settings controls this.
185By default, anyone in a channel who is also a member of your Claude organization can edit that channel's instructions from the **Configure** link in Claude's reply footer. The **Channel member edits** setting controls this. It's under **Channels** on the **Advanced** tab of the **Slack** page and of each workspace's and channel's page.
154186 
155187| Option | Effect |
156188| :- | :- |
from line 190
158190| **Allow** | Members can edit channel instructions from the Configure link |
159191| **Block** | Members can't change channel instructions, the channel's default model, or its [**Respond automatically**](/docs/claude-tag/users/when-claude-responds#turn-automatic-replies-on-or-off) setting |
160192 
161A chain of scopes that all inherit resolves to **Allow**. Set **Block** at the workspace or Default Slack access scope to lock channel instructions across every channel beneath it. A [channel manager](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) can still edit instructions, change the default model, and switch the **Respond automatically** toggle from the Configure page in a channel assigned to them when **Block** is set.
193A chain of scopes that all inherit resolves to **Allow**. Set **Block** on a workspace's page or on the **Slack** page to lock channel instructions across every channel beneath it. A [channel manager](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) can still edit instructions, change the default model, and switch the **Respond automatically** toggle from the Configure page in a channel assigned to them when **Block** is set.
162194 
163195## Verify the bundle is live
164196 
165* The bundle card's usage count includes the new scope. To see it named, open the bundle's **Manage** dialog and hover over the count in its footer.
197* The bundle's page lists the new place under **Where it applies**, and the place's page lists the bundle as a row in its **Claude's access** table.
166198* A test task in the pilot channel uses the bundle's connections, and the action appears in the connected service's audit log under your service account.
167199 
168Repeat the attach step for any additional scopes that need elevated access.
200Repeat the steps in [Choose where a bundle applies](#attach-the-bundle) for any other workspaces and channels that need the bundle's access.
169201 
170202## Related resources
171203 

claude-tag/admins/audit Changed · +8 / -8 lines

## What the Activity page lists ## What the Audit view lists

from line 1
11# Review what Claude Tag has done
22 
3> Claude Tag actions appear under its own service accounts in each connected tool's audit log. See what the Audit page covers, how to trace an action to its source, and where each connected tool keeps logs.
3> Claude Tag actions appear under its own service accounts in each connected tool's audit log. See what the Activity page covers, how to trace an action to its source, and where each connected tool keeps logs.
44 
55export const BetaNote = () => <Info>Claude Tag is in public beta. Features and behavior described here may change before general availability.</Info>;
66 
from line 8
88 
99Use this page to review what Claude Tag is doing across your organization: which routines are scheduled, what memory it has saved, and where to find a record of each action it took.
1010 
11The Audit page opens for Owners in your Claude organization. The other trails on this page are visible to anyone with access to the underlying surface.
11The **Activity** page opens for Owners of your Claude organization. The other trails on this page are visible to anyone with access to the underlying surface.
1212 
1313Claude Tag activity is auditable in four places:
1414 
15* **[The Audit page](#what-the-audit-view-lists)** in admin settings, with tabs for scheduled work, memory, and network events
16* **Memory files on each scope** (select the scope in the **Claude Tag's access** section, then choose **View memory files** from its **⋯** menu), where you can review what Claude has saved
15* **[The Activity page](#what-the-activity-page-lists)** in admin settings, with tabs for scheduled work, memory, and network events
16* **Memory files** for each workspace, and for each channel that has memory of its own (open the workspace's or channel's page from the **Channels** tab under **Claude's access**, then choose **View memory files** from its **⋯** menu, if the menu lists it), where you can review what Claude has saved
1717* **[Attribution on each action](#trace-an-action-to-its-source)** Claude takes in a connected tool
1818* **[The audit logs of each connected service](#trace-an-action-to-its-source)**, where its actions appear under the service account you provisioned
1919 
20## What the Audit view lists
20## What the Activity page lists
2121 
22The Audit page, labeled **Activity** in the admin console's left nav and page heading, at [`claude.ai/admin-settings/claude-tag/audit`](https://claude.ai/admin-settings/claude-tag/audit) has these tabs:
22To open the **Activity** page, go to [`claude.ai/admin-settings/claude-tag/audit`](https://claude.ai/admin-settings/claude-tag/audit), or select **Claude Tag** in the admin settings sidebar and then **Activity** under it. The page has these tabs:
2323 
2424| Tab | What it shows |
2525| :- | :- |
26| **Scheduled work** | The routines set up in channels across your organization, with a **Scope** filter and a per-row **⋮** menu (View details, Pause/Resume, Delete) |
26| **Scheduled work** | The routines set up in channels across your organization, with a **Scope** filter and a per-row **⋮** menu with actions such as **View details**, **Pause** or **Resume**, and **Delete** |
2727| **Memory** | Each scope's memory files, where you can read what Claude has saved for that workspace or channel. Owners can also edit or delete entries there. |
2828| **Network events** | An hourly JSON export of the outbound requests Claude made through [Agent Proxy](/docs/claude-tag/concepts/agent-identity#agent-proxy). Git and MCP traffic are not included. Select a date and hour to download. |
2929 
from line 35
3535 
3636* **In Slack**, it posts as the Claude app, and its work happens in threads anyone in the channel can read.
3737* **On code**, commits and pull requests show the Claude GitHub App as the author, and each one links back to the Slack thread it came from.
38* **In every other connected service**, actions appear under the service account you created for the connection.
38* **In every other connected service**, actions appear under the service account you created for the connector.
3939 
4040That last one is the general-purpose trail: because you provisioned the credential, the connected service's audit log shows everything Claude did there, under an account your security team already monitors.
4141 

claude-tag/admins/configure-github Changed · +51 / -19 lines

### Pick repositories for a workspace or channel ### Grant repositories through a bundle

from line 1
11# Configure GitHub access
22 
3> Claude Tag gives Claude its own GitHub identity, so it opens pull requests as Claude. See how to link your GitHub organization, grant repositories to a bundle, what loads when a repository is cloned into a session, how to get project dependencies installed, and what Claude can do with GitHub Actions.
3> Give Claude its own GitHub identity through the Claude GitHub App. Covers linking your GitHub organization, granting repositories, and GitHub Actions.
44 
55export const BetaNote = () => <Info>Claude Tag is in public beta. Features and behavior described here may change before general availability.</Info>;
66 
from line 10
1010 
1111Claude Tag gives Claude its own GitHub identity, the Claude GitHub App, so pull requests it opens from a channel or a DM are authored by Claude rather than by a person. You only need GitHub access if a team will hand Claude code work: branches, pull requests, review, or CI follow-up.
1212 
13You link GitHub once for your Claude organization, then grant repositories per Access bundle.
13You link GitHub once for your Claude organization, then choose which repositories Claude can use in each workspace and channel.
1414 
1515## Link your GitHub organization
1616 
from line 20
2020 
2121<Steps>
2222 <Step title="Open the GitHub settings page">
23 Open [`claude.ai/admin-settings/github`](https://claude.ai/admin-settings/github). This page is shared with Claude Code; one connection serves both products.
23 Open [`claude.ai/admin-settings/github`](https://claude.ai/admin-settings/github). This page is shared with Claude Code; one connection serves both products. Until the Claude GitHub App is installed, you can also reach this page from Claude Tag admin settings. On the **Connectors** tab under **Claude's access**, click **Add** and select **GitHub**.
2424 </Step>
2525 
2626 <Step title="Connect Claude to GitHub">
27 Click **Connect Claude to GitHub** (**Connect**, once any account is already linked) and complete the GitHub authorization. After authorizing, the **Connected GitHub accounts** table lists the GitHub accounts the Claude GitHub App is installed on. The **Type** column reads **Organization** or **Personal**. An account already linked to your Claude organization shows **Connected**, and one that still needs linking shows **Not linked**. Claude Tag uses **Organization** accounts only; a **Personal** row is someone's own GitHub account and can't be used for your repositories.
27 Click **Connect Claude to GitHub** (**Connect**, once any account is already linked) and complete the GitHub authorization. After authorizing, the **Connected GitHub accounts** table lists the GitHub accounts the Claude GitHub App is installed on. The **Type** column reads **Organization** or **Personal**. An account already linked to your Claude organization shows **Connected**, and one that still needs linking shows **Not linked**.
2828 </Step>
2929 
3030 <Step title="Link or install">
from line 40
4040 
4141## Grant repository access
4242 
43The remaining steps are in the Claude Tag admin page, not GitHub's settings. Repository grants live on the Access bundle; editing a bundle's Repositories tab requires the **Owner** role or the [**Claude Tag Admin** permission](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) in your Claude organization. A [channel manager](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) can also add repositories to their own channel, limited to repositories their GitHub account is an admin of.
43The remaining steps are in Claude Tag admin settings, not GitHub's settings. Granting repositories requires the **Owner** role or the [**Claude Tag Admin** permission](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) in your Claude organization. A [channel manager](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) can also add repositories to their own channel, limited to repositories their GitHub account is an admin of.
4444 
45The GitHub page, a bundle's page, and a workspace's or channel's own page each offer the repositories the Claude GitHub App's installations reach, so you can grant a repository that no bundle holds yet. Pick repositories for each place on the GitHub page, or put them in a bundle to give a group of places the same set.
46 
47### Pick repositories for a workspace or channel
48 
4549<Steps>
46 <Step title="Open the bundle's Repositories tab">
47 Open an [Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle) and go to its **Repositories** tab. Before any GitHub organization is linked, this tab shows a **Get started with GitHub** button that opens [`claude.ai/admin-settings/github`](https://claude.ai/admin-settings/github).
50 <Step title="Open the GitHub page">
51 Go to [**Organization settings > Claude Tag**](https://claude.ai/admin-settings/claude-tag). Under **Claude's access**, select the **Connectors** tab and open **GitHub**.
4852 </Step>
4953 
50 <Step title="Select repositories">
51 Choose the repositories Claude can read from and open pull requests against. Access is per listed repository, or choose **Connect all** for the organization.
54 <Step title="Find the place">
55 Under **Assign access**, find the row for where Claude should use the repositories: **Slack** for every workspace and channel, or a workspace or channel. If the place isn't listed, click **Add place**, choose it under **Where**, and click **Add**.
5256 </Step>
57 
58 <Step title="Pick the repositories">
59 In the place's **Access** column, click **Select access**, or the repositories already picked there, and select each repository Claude should use. Selecting **Every repository in** an account also covers repositories created in it later, and asks you to confirm with **Connect all**. To attach a bundle that holds repositories instead, select it under **Bundles** in the same picker.
60 </Step>
61 
62 <Step title="Save the changes">
63 Click **Save changes**.
64 </Step>
5365</Steps>
5466 
67To add a repository from a workspace's or channel's own page instead, open the page from the **Channels** tab, and under **Claude's access**, click **Add**, select **Repository**, pick the repository on the **Repositories** tab, and click **Add**.
68 
69### Grant repositories through a bundle
70 
71A [bundle](/docs/claude-tag/admins/add-connections#create-a-bundle)'s places decide which channels can use the repositories in it.
72 
73<Steps>
74 <Step title="Open a bundle">
75 Go to [**Organization settings > Claude Tag**](https://claude.ai/admin-settings/claude-tag). Under **Claude's access**, select the **Bundles** tab and open the bundle, or click **Add** to create one.
76 </Step>
77 
78 <Step title="Add repositories">
79 Under **What's in it**, click **Add** and choose **Repository**. In the dialog that opens, pick the **GitHub account** when more than one is linked, then search for a repository and select it. To grant every repository in the account's GitHub App installation, including ones added later, select the **Every repository in** option for that account. Click **Add**, and for the **Every repository in** option, confirm with **Connect all**. Before any GitHub account is linked, the dialog reads "Connect a GitHub account to your organization first."
80 </Step>
81 
82 <Step title="Choose where the bundle applies">
83 Under **Where it applies**, turn on the switch in the **Slack** row to apply the bundle in every workspace and channel, or in a workspace's row to apply it in that workspace. For a channel, click **Add place**, choose the channel under **Where**, and click **Add**. Then click **Save changes**.
84 </Step>
85</Steps>
86 
5587## Verify GitHub access
5688 
5789* The GitHub organization shows as **Connected** under **Connected GitHub accounts** at [`claude.ai/admin-settings/github`](https://claude.ai/admin-settings/github).
58* The granted repositories are listed in the bundle's **Repositories** tab.
90* On the **Connectors** tab under **Claude's access**, select **GitHub**. Its page shows how many GitHub accounts the Claude GitHub App is installed on. Its **Access from** table lists each repository picked for a place and each repository a bundle holds. The **Set by** column reads **Here** for a repository picked for a place, or names the bundle that holds it, and **Used at** names where each one applies.
5991* For the end-to-end check, open a draft PR from a test channel; see [Verify the bundle is live](/docs/claude-tag/admins/attach-to-scope#verify-the-bundle-is-live).
6092 
6193### If Claude can't reach a repository
from line 97
6597| Check | Where |
6698| :- | :- |
6799| The GitHub organization that owns the repository shows **Connected** under **Connected GitHub accounts** | [`claude.ai/admin-settings/github`](https://claude.ai/admin-settings/github). An installation still waiting on a GitHub organization owner shows **Needs permissions**; **Review permissions** opens the approval on github.com. |
68| The repository is listed on the bundle's **Repositories** tab, and that bundle is attached to the channel's scope | [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) → **Access bundles** → the bundle → **Repositories**. A repository granted in one bundle isn't reachable from a channel under a different bundle. |
100| The repository reaches the channel | In [**Organization settings > Claude Tag**](https://claude.ai/admin-settings/claude-tag), open the channel's page from the **Channels** tab under **Claude's access**, and look for the repository in its **Claude's access** table. A repository granted in a bundle that doesn't apply to the channel isn't reachable there. |
69101 
70Repository grants apply to new threads. After changing the **Repositories** tab, start a fresh thread in the channel and name the repository in the first message.
102After granting a repository, start a fresh thread in the channel and name the repository in the first message.
71103 
72104A `403` that names a GitHub Actions operation, such as "repository\_dispatch is not permitted for this session type.", is a different error. It says nothing about repository access; see [What Claude can do with GitHub Actions](#what-claude-can-do-with-github-actions).
73105 
74106## How granted repositories reach a session
75107 
76Granting a repository in a bundle makes it *available* to Claude in any channel under that bundle's scope. It doesn't clone the code into a session on its own. A session starts with no repositories checked out; Claude clones one when the request names it, or when someone in the thread tells it which repository to add. Tell your team to name the repository in the first message of a code task.
108Granting a repository in a bundle makes it *available* to Claude in any channel where that bundle applies. It doesn't clone the code into a session on its own. A session starts with no repositories checked out; Claude clones one when the request names it, or when someone in the thread tells it which repository to add. Tell your team to name the repository in the first message of a code task.
77109 
78110### What loads from a repository
79111 
from line 114
82114* `CLAUDE.md`, `.claude/CLAUDE.md`, and `.claude/rules/*.md` load as project context
83115* Skills in `.claude/skills/` load, so Claude can use them in the session
84116 
85[Hooks](https://code.claude.com/docs/en/hooks) in a repository's `.claude/settings.json` don't run in the session. A repository's `.mcp.json` is never loaded, and connections come only from the Access bundle.
117[Hooks](https://code.claude.com/docs/en/hooks) in a repository's `.claude/settings.json` don't run in the session. A repository's `.mcp.json` is never loaded.
86118 
87119Repository skills apply only in sessions that have the repository. To give a skill to every channel under a scope, add it through a [skills repository](/docs/claude-tag/admins/skills-repo).
88120 
from line 127
95127 
96128Claude follows `CLAUDE.md` as guidance when it starts work that needs it, not as an unconditional setup step. Write each install as a precondition of the work it supports, for example "install the SDK before building or running tests", so Claude runs it when a task touches that code. The sandbox is fresh for every session, so the installs repeat each time Claude works in the repository.
97129 
98Prefer the standard package manager and its default registry over a vendor install script or a third-party package source. Package managers such as `apt`, `pip`, `npm`, and `dotnet` reach their default registries from the sandbox; downloads from other hosts can be blocked at the sandbox's [egress boundary](/docs/claude-tag/concepts/security-and-data#network-egress). An Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) can allow an additional host on the bundle's Domains tab; see [Allow a host without a credential](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential).
130Prefer the standard package manager and its default registry over a vendor install script or a third-party package source. Package managers such as `apt`, `pip`, `npm`, and `dotnet` reach their default registries from the sandbox; downloads from other hosts can be blocked at the sandbox's [egress boundary](/docs/claude-tag/concepts/security-and-data#network-egress). An Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) can allow an additional host with a domain entry on a bundle; see [Allow a host without a credential](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential).
99131 
100132## What Claude can do with GitHub Actions
101133 
102In a channel, Claude acts on GitHub as the Claude GitHub App, and that identity carries a fixed set of GitHub Actions permissions. No admin setting changes it, and adding `api.github.com` as a [custom connection](/docs/claude-tag/admins/connections/custom) with your own token doesn't change it either; Claude's GitHub requests always act as the Claude GitHub App.
134In a channel, Claude acts on GitHub as the Claude GitHub App, and that identity carries a fixed set of GitHub Actions permissions. No admin setting changes it, and adding `api.github.com` as a [custom connector](/docs/claude-tag/admins/connections/custom) with your own token doesn't change it either; Claude's GitHub requests always act as the Claude GitHub App.
103135 
104136Claude can:
105137 
from line 173
141173 
142174GitHub Enterprise Server instances are supported when reachable from the public internet. A GHES host on a private network without a public address can't be connected.
143175 
144On GHES, you create the GitHub App on your own instance instead of installing Anthropic's. The setup is shared with Claude Code; follow the [Claude Code GitHub Enterprise Server guide](https://code.claude.com/docs/en/github-enterprise-server) to create and register the app. After registering the GHE host, a host picker appears on the bundle's **Repositories** tab; select your host there to grant its repositories.
176On GHES, you create the GitHub App on your own instance instead of installing Anthropic's. The setup is shared with Claude Code; follow the [Claude Code GitHub Enterprise Server guide](https://code.claude.com/docs/en/github-enterprise-server) to create and register the app. After you register the GHE host, the dialog for adding a repository to a bundle shows a **GitHub instance** picker; select your host there to grant its repositories.
145177 
146178Registering a GHE host with your Claude organization isn't fully self-serve. Raise it with your account team if the guide doesn't get you all the way through.
147179 
from line 186
154186 
155187If the sender hasn't connected their GitHub Enterprise account on claude.ai yet, Claude replies with a link to connect it. After connecting, the sender asks Claude to add the repository again.
156188 
157In channels, Claude uses the repositories granted on the bundle's **Repositories** tab, as it does for github.com. A person's own GitHub Enterprise connection doesn't apply in channels.
189In channels, Claude uses the repositories granted through bundles, as it does for github.com. A person's own GitHub Enterprise connection doesn't apply in channels.
158190 
159191## Related resources
160192 
161* [Configure per-channel access](/docs/claude-tag/admins/attach-to-scope): bind the bundle to the workspaces and channels that need it
193* [Configure per-channel access](/docs/claude-tag/admins/attach-to-scope): add the bundle to the workspaces and channels that need it
162194* [Set up routines](/docs/claude-tag/users/proactivity): the scheduled jobs that use this connection
163195 

claude-tag/admins/configure-gitlab Changed · +19 / -14 lines

## Add the token as a connector ## Add the token to an Access bundle

from line 1
11# Configure GitLab access
22 
3> Give Claude its own GitLab identity so it can read projects, manage issues, review merge requests, and check pipelines as a service account. Covers creating the account, scoping its access, generating a token, and adding it to a bundle.
3> Give Claude its own GitLab identity to read projects, manage issues, review merge requests, and check pipelines. Covers the account, token, and connector.
44 
55export const BetaNote = () => <Info>Claude Tag is in public beta. Features and behavior described here may change before general availability.</Info>;
66 
77<BetaNote />
88 
9Connecting GitLab lets Claude read repository contents, manage issues, review and comment on merge requests, and check pipeline status from any channel under a bundle's scope, all through the GitLab API. Unlike GitHub, there is no Claude app to install in GitLab. Instead, you give Claude its own GitLab user and add that user's personal access token to an Access bundle.
9Connecting GitLab lets Claude read repository contents, manage issues, review and comment on merge requests, and check pipeline status from any channel where the GitLab connector applies, all through the GitLab API. Unlike GitHub, there is no Claude app to install in GitLab. Instead, you give Claude its own GitLab user and add that user's personal access token as a connector.
1010 
11The connection is API-only. The token authenticates GitLab API requests, not git, so Claude gets a 401 error when it tries to clone a private project or push to any project over HTTPS, even with the connection in place. To clone a repository into the session workspace, connect it through [GitHub](/docs/claude-tag/admins/configure-github) instead.
11The connector is API-only. The token authenticates GitLab API requests, not git, so Claude gets a 401 error when it tries to clone a private project or push to any project over HTTPS, even with the connector in place. To clone a repository into the session workspace, connect it through [GitHub](/docs/claude-tag/admins/configure-github) instead.
1212 
1313A dedicated service account keeps Claude's GitLab activity attributed to a single identity you control. You decide which groups and projects it can reach by granting that account membership the same way you would for a person, and you can revoke or rescope it at any time without touching anyone else's access.
1414 
1515## Prerequisites
1616 
17* The **Owner** role or the [**Claude Tag Admin** permission](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) in your Claude organization to create an Access bundle.
17* The **Owner** role or the [**Claude Tag Admin** permission](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) in your Claude organization, to add a connector.
1818* Permission in GitLab to create a user (or a [service account](https://docs.gitlab.com/user/profile/service_accounts/) on tiers that offer it) and to add that user to the groups or projects Claude should reach.
19* An [Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle) to hold the credential. Create one first if you haven't already.
2019 
2120## Create a dedicated GitLab account for Claude
2221 
from line 42
4342 
4443<Note>Group access tokens and project access tokens also work in the same field. The service-account approach is recommended because one token covers every group you add the account to, and the identity on comments and issues is yours to name. A group or project token is scoped to that single group or project and appears under a GitLab-generated bot name.</Note>
4544 
46## Add the token to an Access bundle
45## Add the token as a connector
4746 
47The first GitLab token you add from the **Connectors** tab is on in every workspace and channel as soon as you save it. To add GitLab for only the channels a bundle covers, add it from the bundle's page under **What's in it** instead; see [Create a bundle](/docs/claude-tag/admins/add-connections#create-a-bundle). To add it for one workspace or channel, [connect it from that place's page](/docs/claude-tag/admins/add-connections#connect-a-service-for-one-workspace-or-channel).
48 
4849<Steps>
49 <Step title="Open the bundle's Credentials tab">
50 At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open **Access bundles**, click into the bundle, and go to **Credentials**.
50 <Step title="Open the Connectors tab">
51 Go to [**Organization settings > Claude Tag**](https://claude.ai/admin-settings/claude-tag). Under **Claude's access**, select the **Connectors** tab and click **Add**.
5152 </Step>
5253 
5354 <Step title="Connect GitLab">
54 Click **Connect** next to **GitLab** and paste the token into **Claude’s personal access token**.
55 Search for **GitLab** and select it. Paste the token into **Claude’s personal access token** and click **Connect**.
5556 </Step>
5657 
57 <Step title="Attach the GitLab plugin">
58 If your organization's plugin marketplace includes a GitLab plugin, add it on the bundle's **Plugins** tab so Claude knows how to call the GitLab API. See [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins). The connection works without the plugin, which adds ready-made workflows.
58 <Step title="Choose where GitLab applies">
59 If this is GitLab's first token, GitLab is now on in every workspace and channel. A later token starts off everywhere until you pick its places under **Assign access** on GitLab's page. To use GitLab in only some channels, [restrict it on GitLab's page](/docs/claude-tag/admins/add-connections#restrict-a-connector-to-some-channels).
5960 </Step>
61 
62 <Step title="Add the GitLab plugin">
63 If your organization's plugin library includes a GitLab plugin, add it where GitLab applies so Claude knows how to call the GitLab API. See [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins). The connector works without the plugin, which adds ready-made workflows.
64 </Step>
6065</Steps>
6166 
6267The token is held by [Agent Proxy](/docs/claude-tag/concepts/agent-identity#agent-proxy) and injected on every API request to your GitLab host. The model and the session sandbox never see it.
from line 72
6772 
6873## Verify GitLab access
6974 
70* GitLab is listed under the bundle's **Credentials** tab.
71* In a channel under the bundle's scope, `@Claude what can you access from this channel?` returns GitLab.
75* GitLab appears on the **Connectors** tab, and its page's **Access from** table lists the token, with where it applies under **Used at**.
76* In a channel where GitLab applies, `@Claude what can you access from this channel?` returns GitLab.
7277* In that same channel, ask Claude to list the open issues in one of your GitLab projects. Claude returns them without prompting for credentials.
7378 
7479## Related resources
7580 
7681* [Connect GitLab](/docs/claude-tag/admins/connections/gitlab): the credential field reference and how GitLab differs from GitHub
77* [Give Claude access](/docs/claude-tag/admins/add-connections): the full credential and bundle reference
82* [Give Claude access](/docs/claude-tag/admins/add-connections): the full connector and bundle reference
7883* [Configure GitHub access](/docs/claude-tag/admins/configure-github): the GitHub App path, which is different
7984 

claude-tag/admins/connections/amplitude Changed · +41 / -32 lines

## Add the connector with an API key ## Add the connector with Amplitude sign-in ## Add the connection with an API key ## Add the connection with Amplitude sign-in

from line 6
66 
77<BetaNote />
88 
9<Note>Connections are added inside an [Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle). At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open **Access bundles** in the left navigation, click into a bundle (or **Create** one), and go to its **Credentials** tab.</Note>
9Connecting Amplitude lets Claude answer product-analytics questions, such as funnel and retention numbers, event segmentation, a user's recent activity, and cohort sizes, in any channel where the connector is on. Claude connects with its own credential, not a person's.
1010 
11Connecting Amplitude lets Claude answer product-analytics questions, such as funnel and retention numbers, event segmentation, a user's recent activity, and cohort sizes, from any channel under the bundle's scope. You add it as a connection inside an [Access bundle](/docs/claude-tag/admins/add-connections); the credential belongs to the agent, not to any person.
12 
1311You can connect with a project API key and secret key, which you can limit to read requests, or by signing in as an Amplitude user, which gives Claude Amplitude's MCP tools for creating and editing content as well as reading it.
1412 
15For the API key route, pair the connection with a plugin that covers Amplitude so Claude knows how to call the REST API; see [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins). A member's own Amplitude connector on claude.ai is separate from this connection and applies in one-to-one DMs. Claude can also [use that connector in a channel](/docs/claude-tag/concepts/personal-connectors) for that member's own tasks, after the member allows it.
13For the API key route, pair the connector with a plugin that covers Amplitude so Claude knows how to call the REST API. Add the plugin on the [**Skills and plugins**](https://claude.ai/admin-settings/claude-tag?access=plugins) tab. A member's own Amplitude connector on claude.ai is separate from this connector and applies in one-to-one DMs. Claude can also [use that connector in a channel](/docs/claude-tag/concepts/personal-connectors) for that member's own tasks, after the member allows it.
1614 
1715## Choose an API key or Amplitude sign-in
1816 
19On a bundle's **Credentials** tab, clicking **Connect** next to **Amplitude** opens a form that offers two ways to connect: **Sign in with Amplitude**, selected by default, and **Use an API token** below it.
17When you select **Amplitude** in the **Add a connector** dialog, the dialog shows two routes under **How Claude authenticates**: **Paste an API key**, selected to start, and **Sign in to Amplitude as Claude**. Select a route and click **Continue to Amplitude** to open the connect form for that route.
2018 
2119| Route | What Claude can do | Amplitude data center | What you need |
2220| :- | :- | :- | :- |
23| **API key and secret key** (**Use an API token**) | Run analytics queries, such as event segmentation, funnels, and retention, through Amplitude's [Dashboard REST API](https://amplitude.com/docs/apis/analytics/dashboard-rest). The setup steps restrict the key pair to read requests. | US or EU | A project API key and a secret key generated for this connection |
24| **Amplitude sign-in** (**Sign in with Amplitude**) | Work with charts, dashboards, cohorts, and experiments through Amplitude's MCP tools, which can create and edit content as well as read it. Claude acts in Amplitude with the signed-in user's roles and project access. | US | A dedicated Amplitude user to sign in as |
21| **API key and secret key** (**Paste an API key**) | Run analytics queries, such as event segmentation, funnels, and retention, through Amplitude's [Dashboard REST API](https://amplitude.com/docs/apis/analytics/dashboard-rest). The setup steps restrict the key pair to read requests. | US or EU | A project API key and a secret key generated for this connector |
22| **Amplitude sign-in** (**Sign in to Amplitude as Claude**) | Work with charts, dashboards, cohorts, and experiments through Amplitude's MCP tools, which can create and edit content as well as read it. Claude acts in Amplitude with the signed-in user's roles and project access. | US | A dedicated Amplitude user to sign in as |
2523 
26Use the API key route when Claude should be limited to read requests. Also use the API key route when Amplitude hosts your organization's data in its EU data center (you sign in to Amplitude at `app.eu.amplitude.com` rather than `app.amplitude.com`), because the **Sign in with Amplitude** option connects to the MCP server for Amplitude's US data center, `https://mcp.amplitude.com/mcp`. Choose Amplitude sign-in when Claude should also build or change content in Amplitude, such as creating a chart or updating a dashboard.
24Use the API key route when Claude should be limited to read requests. Also use the API key route when Amplitude hosts your organization's data in its EU data center (you sign in to Amplitude at `app.eu.amplitude.com` rather than `app.amplitude.com`), because the **Sign in to Amplitude as Claude** option connects to the MCP server for Amplitude's US data center, `https://mcp.amplitude.com/mcp`. Choose Amplitude sign-in when Claude should also build or change content in Amplitude, such as creating a chart or updating a dashboard.
2725 
28With either route, Claude can use the connection in every channel under the bundle's scope. The form calls the sign-in option an MCP connector because Claude reaches Amplitude through Amplitude's hosted MCP server, and the result is still a connection in the bundle, not a personal claude.ai connector.
26With either route, Claude can use the connector in every channel where it's on. The form says the sign-in option uses Amplitude's MCP connector because Claude reaches Amplitude through Amplitude's hosted MCP server. The result is still a connector Claude holds for your organization, not a personal claude.ai connector.
2927 
3028## Get the API key and secret key from Amplitude
3129 
32The API key route uses two keys from one Amplitude project: the project's API key and a secret key. The connection sends them with HTTP Basic authentication, the API key as the username and the secret key as the password. Keys belong to a single project, so each connection reaches one project's data, and an organization with several Amplitude projects needs a key pair and a connection for each.
30The API key route uses two keys from one Amplitude project: the project's API key and a secret key. The connector sends them with HTTP Basic authentication, the API key as the username and the secret key as the password. Keys belong to a single project, so each credential reaches one project's data, and an organization with several Amplitude projects needs a key pair and a credential for each.
3331 
34You need the Manager or Admin role in Amplitude to generate keys. Generate a secret key dedicated to this connection and give it a name that identifies Claude, so you can rotate or revoke it without affecting the keys your other tools use. Amplitude shows the secret key's value only once and can't display it again, so copy it as soon as it appears; if you lose it, generate a new secret key.
32You need the Manager or Admin role in Amplitude to generate keys. Generate a secret key dedicated to this connector and give it a name that identifies Claude, so you can rotate or revoke it without affecting the keys your other tools use. Amplitude shows the secret key's value only once and can't display it again, so copy it as soon as it appears; if you lose it, generate a new secret key.
3533 
36An Amplitude key pair has no read-only option, and the same pair can also call Amplitude's write and user-deletion endpoints. In the next section you restrict the connection to `GET` requests, so the key pair authenticates read requests only. Read access still covers everything those APIs return for the project, including raw event export and individual users' event streams, so scope the bundle to channels whose members may see that data.
34An Amplitude key pair has no read-only option, and the same pair can also call Amplitude's write and user-deletion endpoints. In the next section you restrict the credential to `GET` requests, so the key pair authenticates read requests only. Read access still covers everything those APIs return for the project, including raw event export and individual users' event streams, so turn the connector on only in channels whose members may see that data.
3735 
3836Amplitude's own guide for creating the keys is at [amplitude.com](https://amplitude.com/docs/admin/account-management/manage-your-api-keys-and-secret-keys).
3937 
40## Add the connection with an API key
38## Add the connector with an API key
4139 
42A saved connection is live with every HTTP method in any channel under the bundle's scope. Add the connection to a bundle that isn't attached to a scope yet, and attach the bundle after you finish the restriction step below.
40A saved credential works with every HTTP method wherever the connector is on, and the first Amplitude credential added on the **Connectors** tab is on in every workspace and channel as soon as you save it. To restrict the key pair before any channel can use it, add Amplitude to a new bundle, which applies nowhere until you add places to it.
4341 
4442<Steps>
43 <Step title="Create a bundle for Amplitude">
44 Go to [**Organization settings > Claude Tag > Bundles**](https://claude.ai/admin-settings/claude-tag?access=presets), click **Add**, enter a name such as `Amplitude`, and click **Create**. The bundle's page opens.
45 </Step>
46 
4547 <Step title="Open the Amplitude form">
46 On the bundle's **Credentials** tab, click **Connect** next to **Amplitude**.
48 Under **What's in it**, click **Add**, select **Connector**, and select **Amplitude**. Leave **Paste an API key** selected and click **Continue to Amplitude**. The connect form opens.
4749 </Step>
4850 
4951 <Step title="Enter the key pair">
50 Select **Use an API token**, then fill in the two fields.
52 With **Use an API token** selected, fill in these fields.
5153 
5254 | Field | Value |
5355 | :- | :- |
5456 | Claude's API key | The project's API key from Amplitude |
55 | Claude's secret key | The secret key you generated for this connection |
57 | Claude's secret key | The secret key you generated for this connector |
58 | Allowed websites | `amplitude.com` (preset) |
5659 
57 The host is prefilled as `amplitude.com`. If Amplitude hosts your organization's data in its EU data center (you sign in to Amplitude at `app.eu.amplitude.com` rather than `app.amplitude.com`), replace the host with `analytics.eu.amplitude.com`.
60 If Amplitude hosts your organization's data in its EU data center (you sign in to Amplitude at `app.eu.amplitude.com` rather than `app.amplitude.com`), replace the host with `analytics.eu.amplitude.com`.
5861 
59 Click **Connect** to save the connection.
62 Click **Connect** to save the connector.
6063 </Step>
6164 
62 <Step title="Restrict the connection to read requests">
63 The connection is created with the `/api/` path prefix, which covers Amplitude's REST APIs and keeps the key pair off the rest of `amplitude.com`. Add the method restriction yourself: select **Edit** on the connection's row, then in the **Edit connection** dialog clear **All methods** under **Methods** and select `GET`. See [Restrict by path or method](/docs/claude-tag/admins/add-connections#restrict-by-path-or-method).
65 <Step title="Restrict the credential to read requests">
66 The credential is created with the `/api/` path prefix, which covers Amplitude's REST APIs and keeps the key pair off the rest of `amplitude.com`. Add the method restriction yourself: under **What's in it**, open the menu on the Amplitude row and click **Edit**. In the **Edit connection** dialog, clear **All methods** under **Methods**, select `GET`, and click **Save**.
6467 
65 With the restriction in place, the Agent Proxy attaches the key pair only to `GET` requests under `/api/`. A request outside that restriction, such as a write or a user-deletion call, doesn't match the connection. Agent Proxy never attaches the key pair to it, so the request can't authenticate to Amplitude.
68 With the restriction in place, the Agent Proxy attaches the key pair only to `GET` requests under `/api/`. A request outside that restriction, such as a write or a user-deletion call, doesn't match the credential. Agent Proxy never attaches the key pair to it, so the request can't authenticate to Amplitude.
6669 </Step>
70 
71 <Step title="Choose where the bundle applies">
72 Under **Where it applies**, click **Add place**, choose a workspace or channel under **Where**, and click **Add**. The bundle applies there and in every channel beneath it. Click **Save changes** to save the places.
73 </Step>
6774</Steps>
6875 
6976Amplitude rate-limits these APIs per project, with a cap on concurrent requests and an hourly budget in which queries that span more days or segments cost more. Claude's queries draw on the same budget as your project's other API clients. If Claude reports that Amplitude returned a rate-limit error (HTTP 429), narrow the date range, drop a group-by, or ask again later. Amplitude's [Dashboard REST API documentation](https://amplitude.com/docs/apis/analytics/dashboard-rest) lists the current limits.
from line 77
7077 
7178The Agent Proxy injects the credential at the network boundary; the model and the sandbox are not given the key. See [how Agent Proxy works](/docs/claude-tag/concepts/agent-identity#agent-proxy).
7279 
73## Add the connection with Amplitude sign-in
80## Add the connector with Amplitude sign-in
7481 
75<Warning>Sign in as a dedicated Amplitude user created for this connection (for example, `[email protected]`), not with your own account. Anyone in a channel under the bundle's scope can ask Claude to use the connection, so everything that user can reach in Amplitude is available to every member of those channels. Because Amplitude's MCP tools can create and edit charts, dashboards, and cohorts as well as read them, give the user the most limited role that covers what the channels need in each project, such as Viewer. A dedicated user also limits Claude to the projects you add that user to and keeps Claude's activity in Amplitude traceable to one account.</Warning>
82<Warning>Sign in as a dedicated Amplitude user created for this connector (for example, `[email protected]`), not with your own account. Anyone in a channel where the connector is on can ask Claude to use it, so everything that user can reach in Amplitude is available to every member of those channels. Because Amplitude's MCP tools can create and edit charts, dashboards, and cohorts as well as read them, give the user the most limited role that covers what the channels need in each project, such as Viewer. A dedicated user also limits Claude to the projects you add that user to and keeps Claude's activity in Amplitude traceable to one account.</Warning>
7683 
77This route connects to the MCP server for Amplitude's US data center. If you sign in to Amplitude at `app.eu.amplitude.com`, Amplitude hosts your organization's data in its EU data center, so use the [API key route](#add-the-connection-with-an-api-key) instead.
84This route connects to the MCP server for Amplitude's US data center. If you sign in to Amplitude at `app.eu.amplitude.com`, Amplitude hosts your organization's data in its EU data center, so use the [API key route](#add-the-connector-with-an-api-key) instead.
7885 
7986<Steps>
8087 <Step title="Open the Amplitude form">
81 On the bundle's **Credentials** tab, click **Connect** next to **Amplitude**.
88 Go to [**Organization settings > Claude Tag > Connectors**](https://claude.ai/admin-settings/claude-tag?access=connectors), click **Add**, and select **Amplitude**. Select **Sign in to Amplitude as Claude** and click **Continue to Amplitude**. The connect form opens.
8289 </Step>
8390 
8491 <Step title="Sign in as the dedicated user">
85 Leave **Sign in with Amplitude** selected. The **Sign in with Amplitude** option shows the MCP server the sign-in grants access to, `https://mcp.amplitude.com/mcp`, and the form sets the connection's allowed host to that server for you.
92 The **Sign in to Amplitude as Claude** option shows the MCP server the sign-in grants access to, `https://mcp.amplitude.com/mcp`, and the form sets the connector's allowed host to that server for you.
8693 
87 Click **Sign in with Amplitude** at the bottom of the form. A sign-in window opens. If your browser blocks pop-ups, allow them for claude.ai and click **Sign in with Amplitude** again. Sign in to Amplitude as the dedicated user and approve access. When the sign-in completes and the window closes, the connection is saved to the bundle and appears on its **Credentials** tab.
94 The first credential you add for a service from the **Connectors** tab is on in every workspace and channel as soon as you save it. To give it narrower reach, see [where a new connector applies](/docs/claude-tag/admins/add-connections#add-a-connection) before you sign in.
95 
96 Click **Sign in with Amplitude** at the bottom of the form. A sign-in window opens. If your browser blocks pop-ups, allow them for claude.ai and click **Sign in with Amplitude** again. Sign in to Amplitude as the dedicated user and approve access. When the sign-in completes and the window closes, the connector is saved and Amplitude's connector page opens, with the new credential marked **New**.
8897 </Step>
8998</Steps>
9099 
91Amplitude decides what the signed-in user can read and change, and that user's roles and project access apply to every request Claude makes through this connection. The `GET` restriction described for the API key route applies only to that route's key pair. If the sign-in succeeds but Claude reports that Amplitude denied a request, check the dedicated user's role and project access in Amplitude. See [Amplitude MCP](https://amplitude.com/docs/amplitude-ai/amplitude-mcp) for what Amplitude's MCP server can do.
100Amplitude decides what the signed-in user can read and change, and that user's roles and project access apply to every request Claude makes through this connector. The `GET` restriction described for the API key route applies only to that route's key pair. If the sign-in succeeds but Claude reports that Amplitude denied a request, check the dedicated user's role and project access in Amplitude. See [Amplitude MCP](https://amplitude.com/docs/amplitude-ai/amplitude-mcp) for what Amplitude's MCP server can do.
92101 
93102## Verify the connection
94103 
95In a channel under the bundle's scope, in a new thread:
104In a channel where the connector is on, in a new thread:
96105 
97106```text wrap theme={null}
98107@Claude can you reach Amplitude? List a few of our event types.
99108```
100109 
101With either route, Claude replies with event types from Amplitude once the connection is live. New threads pick up the connection on their own; in an existing thread, ask Claude to use Amplitude by name.
110With either route, Claude replies with event types from Amplitude once the connector is live. New threads pick up the connector on their own; in an existing thread, ask Claude to use Amplitude by name.
102111 
103112## Related resources
104113 
105114* [Answer data questions](/docs/claude-tag/users/use-cases/answer-data-questions): the question-to-chart pattern in a Slack thread, shown there with a data warehouse
106115* [Give Claude access](/docs/claude-tag/admins/add-connections): the full credential-type and allowed-hosts reference
107* [Connect a custom service](/docs/claude-tag/admins/connections/custom): for Amplitude APIs the preset doesn't cover, such as the User Profile API, which lives on `profile-api.amplitude.com` and authenticates with a different header
116* [Connect a custom service](/docs/claude-tag/admins/connections/custom): for Amplitude APIs the **Amplitude** entry doesn't cover, such as the User Profile API, which lives on `profile-api.amplitude.com` and authenticates with a different header
108117* Amplitude's [API authentication](https://amplitude.com/docs/apis/authentication), [API key and secret key management](https://amplitude.com/docs/admin/account-management/manage-your-api-keys-and-secret-keys), and [Amplitude MCP](https://amplitude.com/docs/amplitude-ai/amplitude-mcp) documentation
109118 

claude-tag/admins/connections/asana Changed · +9 / -9 lines

## Add the connector ## Add the connection to a bundle

from line 6
66 
77<BetaNote />
88 
9<Note>Connections are added inside an [Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle). At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open **Access bundles** in the left navigation, click into a bundle (or **Create** one), and go to its **Credentials** tab.</Note>
9Connecting Asana lets Claude file tasks and pull project status in any channel where the connector is on. Claude connects with its own credential, not a person's.
1010 
11Connecting Asana lets Claude file tasks and pull project status from any channel under the bundle's scope. You add it as a connection inside an [Access bundle](/docs/claude-tag/admins/add-connections); the credential belongs to the agent, not to any person.
11Pair this connector with the Asana plugin from Anthropic's plugin marketplace so Claude knows how to call the API. This connector calls Asana's HTTP API. It isn't an MCP server or a member's personal claude.ai connector.
1212 
13Pair this connection with the Asana plugin from Anthropic's plugin marketplace so Claude knows how to call the API; see [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins). This is an HTTP API connection, not an MCP server or a personal claude.ai connector.
14 
1513## Create the credential in Asana
1614 
1715On every Asana plan, create the personal access token from a dedicated Asana seat for Claude, and give that seat access to only the projects and teams Claude needs. Per Asana's guidance, avoid service account tokens, which carry organization-wide access.
from line 16
1816 
1917Asana's own guide for creating the credential is at [developers.asana.com](https://developers.asana.com/docs/personal-access-token).
2018 
21## Add the connection to a bundle
19## Add the connector
2220 
23In the bundle, click **Connect** next to **Asana**.
21Go to [**Organization settings > Claude Tag > Connectors**](https://claude.ai/admin-settings/claude-tag?access=connectors), click **Add**, and select **Asana**. Fill in these fields in the connect form.
2422 
2523| Field | Value |
2624| :- | :- |
2725| Claude's personal access token | The personal access token from Asana |
28| Allowed websites | `app.asana.com` |
26| Allowed websites | `app.asana.com` (preset) |
2927 
28If the connect form offers to include the Asana plugin, leave that box selected; otherwise add the plugin on the [**Skills and plugins**](https://claude.ai/admin-settings/claude-tag?access=plugins) tab. The first credential you add for a service from the **Connectors** tab is on in every workspace and channel as soon as you save it. To give it narrower reach, see [where a new connector applies](/docs/claude-tag/admins/add-connections#add-a-connection) before you save the connector. Click **Connect** to save the connector.
29 
3030The Agent Proxy injects the credential at the network boundary; the model and the sandbox are not given the key. See [how Agent Proxy works](/docs/claude-tag/concepts/agent-identity#agent-proxy).
3131 
3232## Verify the connection
3333 
34In a channel under the bundle's scope, in a new thread:
34In a channel where the connector is on, in a new thread:
3535 
3636```text wrap theme={null}
3737@Claude what can you access from this channel?
3838```
3939 
40Asana appears in the list once the connection is live. New threads pick up the connection on their own; in an existing thread, ask Claude to use the service by name.
40Asana appears in the list once the connector is live. New threads pick up the connector on their own; in an existing thread, ask Claude to use the service by name.
4141 
4242## Related resources
4343 

claude-tag/admins/connections/atlassian Changed · +37 / -15 lines

## Add the connector ## Connect a token with scopes through the Atlassian gateway ## Add the connection to a bundle

from line 6
66 
77<BetaNote />
88 
9<Note>Connections are added inside an [Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle). At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open **Access bundles** in the left navigation, click into a bundle (or **Create** one), and go to its **Credentials** tab.</Note>
9Connecting Atlassian Cloud lets Claude read and search Confluence pages and read, comment on, and update Jira issues in any channel where the connector is on. One credential covers both products on the same Atlassian site.
1010 
11Connecting Atlassian Cloud lets Claude read and search Confluence pages and read, comment on, and update Jira issues from any channel under the bundle's scope. One credential covers both products on the same Atlassian site.
11This connector calls the Jira and Confluence HTTP APIs. It isn't an MCP server or a member's personal claude.ai connector. Pair it with plugins that cover Jira and Confluence so Claude knows how to call the API. Add them on the [**Skills and plugins**](https://claude.ai/admin-settings/claude-tag?access=plugins) tab.
1212 
13This is an HTTP API connection, not an MCP server or a personal claude.ai connector. Pair it with a plugin that covers Jira and Confluence so Claude knows how to call the API; see [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins).
14 
1513## Create the credential in Atlassian
1614 
17Create a dedicated Atlassian account for Claude (for example `[email protected]`) and add it to the Jira projects and Confluence spaces it should reach. The connection can read whatever this account can read, so a dedicated account keeps Claude's reach to exactly what you grant it.
15Create a dedicated Atlassian account for Claude (for example `[email protected]`) and add it to the Jira projects and Confluence spaces it should reach. The connector can read whatever this account can read, so a dedicated account keeps Claude's reach to exactly what you grant it.
1816 
19Sign in as that account and create an API token at [id.atlassian.com/manage-profile/security/api-tokens](https://id.atlassian.com/manage-profile/security/api-tokens). Atlassian shows the token once; store it somewhere you can retrieve it. Atlassian API tokens expire, with a maximum lifetime of one year, so plan to create a new token and update the connection before the old one lapses.
17Sign in as that account and create an API token at [id.atlassian.com/manage-profile/security/api-tokens](https://id.atlassian.com/manage-profile/security/api-tokens). Atlassian shows the token once; store it somewhere you can retrieve it. Atlassian API tokens expire, with a maximum lifetime of one year, so plan to create a new token and rotate the connector's credential before the old one lapses.
2018 
21<Note>Create the API token without scopes. Atlassian accepts tokens with scopes, including service account tokens, only at its `api.atlassian.com` gateway, not at your site's hostname, so the preset can't use them.</Note>
19<Note>Create the API token without scopes. Atlassian accepts tokens with scopes, including service account tokens, only at its `api.atlassian.com` gateway, not at your site's hostname, so the **Jira & Confluence** entry can't use them.</Note>
2220 
23If your organization requires tokens with scopes, connect through the gateway instead of the preset. Add a [custom connection](/docs/claude-tag/admins/connections/custom) with the **Basic** credential type, the dedicated account's email and token, and `api.atlassian.com` under **Allowed websites**. Then [restrict the connection](/docs/claude-tag/admins/add-connections#restrict-by-path-or-method) to the path prefixes `/ex/jira/<cloud-id>/` and `/ex/confluence/<cloud-id>/`, because the cloud ID in a gateway request's path chooses which Atlassian site the request reaches. Atlassian documents [tokens with scopes](https://support.atlassian.com/atlassian-account/docs/manage-api-tokens-for-your-atlassian-account/), [service account tokens](https://support.atlassian.com/user-management/docs/manage-api-tokens-for-service-accounts/), and [how to find your site's cloud ID](https://support.atlassian.com/jira/kb/retrieve-my-atlassian-sites-cloud-id/).
21If your organization requires tokens with scopes, see [Connect a token with scopes through the Atlassian gateway](#connect-a-token-with-scopes-through-the-atlassian-gateway).
2422 
25## Add the connection to a bundle
23## Add the connector
2624 
27On the bundle's **Credentials** tab, click **Connect** next to **Jira & Confluence**.
25Go to [**Organization settings > Claude Tag > Connectors**](https://claude.ai/admin-settings/claude-tag?access=connectors), click **Add**, and select **Jira & Confluence**. Leave **Paste an API key** selected and click **Continue to Jira & Confluence**.
2826 
29The form asks for the dedicated account's email address and the API token from Atlassian. In the host field, replace the prefilled `*.atlassian.net` with your own site's hostname, such as `your-domain.atlassian.net`. The form rejects the wildcard because it would let the credential reach any Atlassian site, not just yours.
27In the connect form, with **Use an API token** selected, enter the dedicated account's email address, the API token from Atlassian, and your own site's hostname, such as `your-domain.atlassian.net`. Claude sends the token only to that site. The first credential you add for a service from the **Connectors** tab is on in every workspace and channel as soon as you save it. To give it narrower reach, see [where a new connector applies](/docs/claude-tag/admins/add-connections#add-a-connection) before you save the connector. Click **Connect** to save the connector.
3028 
3129The Agent Proxy injects the credential at the network boundary; the model and the sandbox are not given the key. See [how Agent Proxy works](/docs/claude-tag/concepts/agent-identity#agent-proxy).
3230 
33<Note>Atlassian Data Center (self-hosted) isn't covered by the preset because it authenticates with a personal access token sent as a Bearer header. Add a Data Center instance as a [custom connection](/docs/claude-tag/admins/connections/custom) with the **Bearer** credential type and your instance's hostname under **Allowed websites**. The instance must be reachable from the public internet.</Note>
31<Note>Atlassian Data Center (self-hosted) isn't covered by the **Jira & Confluence** entry because it authenticates with a personal access token sent as a Bearer header. Add a Data Center instance as a [custom connector](/docs/claude-tag/admins/connections/custom) with the **Bearer** credential type and your instance's hostname under **Allowed websites**. The instance must be reachable from the public internet.</Note>
3432 
33## Connect a token with scopes through the Atlassian gateway
34 
35If your organization requires tokens with scopes, connect through the gateway instead of the **Jira & Confluence** entry. Add the gateway connector inside a new bundle. A new bundle applies nowhere until you add places to it, so you can limit the token to your site's paths before any channel can use it.
36 
37<Steps>
38 <Step title="Create a bundle for the gateway">
39 Go to [**Organization settings > Claude Tag > Bundles**](https://claude.ai/admin-settings/claude-tag?access=presets), click **Add**, enter a name such as `Atlassian gateway`, and click **Create**. The bundle's page opens.
40 </Step>
41 
42 <Step title="Add the gateway connector">
43 Under **What's in it**, click **Add**, select **Connector**, and select **Custom connector**. In the [custom connector](/docs/claude-tag/admins/connections/custom) form, enter a **Name**, choose the **Basic** credential type, enter the dedicated account's email as the **Username** and the API token as the **Password**, and enter `api.atlassian.com` under **Allowed websites**. Click **Connect** to save the connector.
44 </Step>
45 
46 <Step title="Limit the credential to your site's paths">
47 Under **What's in it**, open the menu on the new connector's row and click **Edit**. In the **Edit connection** dialog, add `/ex/jira/<cloud-id>/` and `/ex/confluence/<cloud-id>/` under **Path prefixes**, then click **Save**. The cloud ID in a gateway request's path chooses which Atlassian site the request reaches.
48 </Step>
49 
50 <Step title="Choose where the bundle applies">
51 Under **Where it applies**, click **Add place**, choose a workspace or channel under **Where**, and click **Add**. Click **Save changes** to save the places.
52 </Step>
53</Steps>
54 
55Atlassian documents [tokens with scopes](https://support.atlassian.com/atlassian-account/docs/manage-api-tokens-for-your-atlassian-account/), [service account tokens](https://support.atlassian.com/user-management/docs/manage-api-tokens-for-service-accounts/), and [how to find your site's cloud ID](https://support.atlassian.com/jira/kb/retrieve-my-atlassian-sites-cloud-id/).
56 
3557## Verify the connection
3658 
37In a channel under the bundle's scope, in a new thread, ask Claude to fetch one issue or page by key or URL. The call lands under the dedicated account in Atlassian's audit log.
59In a channel where the connector is on, in a new thread, ask Claude to fetch one issue or page by key or URL. The call lands under the dedicated account in Atlassian's audit log.
3860 
3961```text wrap theme={null}
4062@Claude can you read PROJ-123 from Jira?
4163```
4264 
43New threads pick up the connection on their own; in an existing thread, ask Claude to use the service by name.
65New threads pick up the connector on their own; in an existing thread, ask Claude to use the service by name.
4466 
4567## Related resources
4668 
47* [Custom connection](/docs/claude-tag/admins/connections/custom): for a setup the preset doesn't cover, such as a self-hosted Data Center instance
69* [Custom connector](/docs/claude-tag/admins/connections/custom): for a setup the **Jira & Confluence** entry doesn't cover, such as a self-hosted Data Center instance
4870* [Give Claude access](/docs/claude-tag/admins/add-connections): the full connection model and how to scope a dedicated account
4971 

claude-tag/admins/connections/bigquery Changed · +10 / -17 lines

## Add the connector ## Add the connection to a bundle

from line 1
11# Connect BigQuery
22 
3> Connect BigQuery to Claude Tag so it can run read-only queries on your datasets. BigQuery has no preset, so it is added as a custom credential with a GCP service-account key.
3> Connect BigQuery to Claude Tag so it can run read-only queries on your datasets, using a GCP service-account key.
44 
55export const BetaNote = () => <Info>Claude Tag is in public beta. Features and behavior described here may change before general availability.</Info>;
66 
77<BetaNote />
88 
9<Note>Connections are added inside an [Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle). At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open **Access bundles** in the left navigation, click into a bundle (or **Create** one), and go to its **Credentials** tab.</Note>
9Connecting BigQuery lets Claude run queries against your datasets in any channel where the connector is on. Claude connects with its own credential, not a person's.
1010 
11Connecting BigQuery lets Claude run queries against your datasets from any channel under the bundle's scope. Add it as a custom credential with **Custom tool**; BigQuery has no preset button in the picker.
11This connector calls BigQuery's HTTP API, and it's separate from members' personal claude.ai connectors. Pair it with a plugin that covers BigQuery so Claude knows how to form and run queries; without one, Claude can reach the API but has to work out the request shape on its own. Add the plugin on the [**Skills and plugins**](https://claude.ai/admin-settings/claude-tag?access=plugins) tab.
1212 
13This is an HTTP API connection, not a personal claude.ai connector. Pair it with a plugin that covers BigQuery so Claude knows how to form and run queries; without one, Claude can reach the API but has to work out the request shape on its own. See [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins).
14 
1513## Create the credential in Google Cloud
1614 
1715Create a dedicated service account for the agent in the Google Cloud project that holds your BigQuery data, then create a JSON key for it. Google's guides cover [creating a service account](https://cloud.google.com/iam/docs/service-accounts-create) and [creating a service account key](https://cloud.google.com/iam/docs/keys-create-delete).
from line 16
1816 
1917## Grant access to specific datasets
2018 
21You scope what Claude can read on the Google Cloud side, through the service account's role grants. The connection itself has no dataset setting. Grant the service account two roles:
19You scope what Claude can read on the Google Cloud side, through the service account's role grants. The connector itself has no dataset setting. Grant the service account two roles:
2220 
2321* **BigQuery Data Viewer** (`roles/bigquery.dataViewer`) on each dataset Claude should query. Grant it on the specific datasets, not on the project, so Claude can read only those datasets.
2422* **BigQuery Job User** (`roles/bigquery.jobUser`) on the project, so the service account can run query jobs.
2523 
26Together the two grants let Claude run read-only queries against those datasets. To widen or narrow access later, edit the dataset grants in Google Cloud; the connection needs no change.
24Together the two grants let Claude run read-only queries against those datasets. To widen or narrow access later, edit the dataset grants in Google Cloud; the connector needs no change.
2725 
28## Add the connection to a bundle
26## Add the connector
2927 
30In the bundle, click **Connect** next to **Custom tool** and choose **GCP access token (with Service Account Key)**.
28Go to [**Organization settings > Claude Tag > Connectors**](https://claude.ai/admin-settings/claude-tag?access=connectors), click **Add**, and select **BigQuery**. The first credential you add for a service from the **Connectors** tab is on in every workspace and channel as soon as you save it. To give it narrower reach, see [where a new connector applies](/docs/claude-tag/admins/add-connections#add-a-connection) before you save the connector. In the connect form, paste the whole JSON key file from Google Cloud Console into **Claude's service account key (JSON)**, then click **Connect** to save the connector.
3129 
32| Field | Value |
33| :- | :- |
34| Credential type | **GCP access token (with Service Account Key)** |
35| GCP service account key (JSON) | The JSON key file from Google Cloud Console |
36| Scopes (optional) | `https://www.googleapis.com/auth/bigquery`. The field is labeled optional, but leave it empty and the token defaults to a broader scope. BigQuery's query endpoints don't accept a read-only scope; the dataset roles in the section above are what keep the connection read-only. |
37| Allowed websites | `bigquery.googleapis.com` |
30The access tokens Claude gets from this key carry only Google's `cloud-platform.read-only` scope, so Google refuses BigQuery API calls that create or delete tables or run load jobs. Queries still run with whatever the service account's roles allow, so the [dataset roles](#grant-access-to-specific-datasets) decide what a query can reach.
3831 
3932Agent Proxy exchanges the service-account key for an access token and injects it at the network boundary; the model and the sandbox are not given the key. See [how Agent Proxy works](/docs/claude-tag/concepts/agent-identity#agent-proxy).
4033 
4134## Verify the connection
4235 
43In a channel under the bundle's scope, in a new thread:
36In a channel where the connector is on, in a new thread:
4437 
4538```text wrap theme={null}
4639@Claude what can you access from this channel?
4740```
4841 
49BigQuery appears in the list once the connection is live. New threads pick up the connection on their own; in an existing thread, ask Claude to use the service by name.
42BigQuery appears in the list once the connector is live. New threads pick up the connector on their own; in an existing thread, ask Claude to use the service by name.
5043 
5144Then confirm a query runs against a dataset you granted:
5245 

claude-tag/admins/connections/custom Changed · +24 / -18 lines

### Fill out the custom connector form ## Verify the custom connector ### Fill out the Custom tool form ## Verify the connection

from line 1
11# Connect a service that isn't in the list
22 
3> Connect a tool that has no built-in preset to Claude Tag. Covers credential types, what each form field means, and how to add a custom MCP server.
3> Connect a tool that isn't in Claude Tag's connector list. Covers credential types, what each form field means, and how to add a custom MCP server.
44 
55export const BetaNote = () => <Info>Claude Tag is in public beta. Features and behavior described here may change before general availability.</Info>;
66 
77<BetaNote />
88 
9<Note>Connections are added inside an [Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle). At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open **Access bundles** in the left navigation, click into a bundle (or **Create** one), and go to its **Credentials** tab.</Note>
9For a service that isn't in the **Add a connector** list, add a custom connector. This works for any service with an HTTP API. The [BigQuery](/docs/claude-tag/admins/connections/bigquery) guide is a worked example.
1010 
11For a service that doesn't have a preset Connect button, use **Custom tool** on the bundle's Credentials tab. This works for any service with an HTTP API. The [BigQuery](/docs/claude-tag/admins/connections/bigquery) guide is a worked example.
11To open the form, go to [**Organization settings > Claude Tag**](https://claude.ai/admin-settings/claude-tag). Under **Claude's access**, select the **Connectors** tab, click **Add**, and select **Custom connector** at the bottom of the list. A connector added there for a host that isn't on the **Connectors** tab yet is on in every workspace and channel once you save it. For a host already listed under **Custom hosts**, the new credential starts off everywhere until you choose where it applies. For narrower reach:
1212 
13* **Some channels**: [restrict it on its page](/docs/claude-tag/admins/add-connections#restrict-a-connector-to-some-channels).
14* **One workspace or channel**: on that place's page, click **Add** under **Claude's access**, select **Connector**, select **Custom connector** under **Connect new** on the **Connectors** tab, and click **Continue**. See [Connect a service for one workspace or channel](/docs/claude-tag/admins/add-connections#connect-a-service-for-one-workspace-or-channel).
15* **The places a bundle applies**: add it to the [bundle](/docs/claude-tag/admins/add-connections#create-a-bundle). Open the bundle's page, and under **What's in it** click **Add**, choose **Connector**, and select **Custom connector**.
16 
1317## Add a custom HTTP API
1418 
1519### What you need from the service
from line 24
2024 
2125See [Create a dedicated account per service](/docs/claude-tag/admins/add-connections#create-a-dedicated-account-per-service) for the service-account patterns.
2226 
23### Fill out the Custom tool form
27<a id="fill-out-the-custom-tool-form" />
2428 
29### Fill out the custom connector form
30 
2531| Field | What to enter |
2632| :- | :- |
27| **Name** | A label for this connection (for example "Internal billing API") |
33| **Name** | A label for this connector (for example "Internal billing API") |
2834| **Credential type** | Pick the type that matches how the API authenticates; see [Credential types](#credential-types) |
2935| **Allowed websites** | The API's host (for example `api.example.com`). A wildcard is allowed as the leftmost label. You can't enter `*` alone here; a credential is always limited to specific hosts (see [Allow all hosts](/docs/claude-tag/admins/add-connections#allow-all-hosts)). The credential is sent only to hosts you list here. |
30| **Path prefixes** (optional) | Restrict the credential to specific URL paths under the host. Shown only for the MCP Connector type, and only when the provider you pick doesn't fix its own hosts and paths. |
36| **Path prefixes** (optional) | Restrict the credential to specific URL paths under the host. For the MCP Connector type, shown only when the provider you pick doesn't fix its own hosts and paths. |
3137| **Custom headers** | Any extra headers the API requires beyond the credential. Shown only for the Bearer credential type. |
3238 
33After saving, where the credential has an allow rule, you can narrow it by HTTP method and path from its **Edit connection** dialog; see [Restrict by path or method](/docs/claude-tag/admins/add-connections#restrict-by-path-or-method).
39After saving, where the credential has an allow rule, you can narrow it by HTTP method and path from its **Edit connection** dialog, opened from **Edit** in the credential's row menu on the connector's page; see [Restrict by path or method](/docs/claude-tag/admins/add-connections#restrict-by-path-or-method). To narrow a credential before any channel can use it, add the connector to a new [bundle](/docs/claude-tag/admins/add-connections#create-a-bundle), select **Edit** from the menu on its row under **What's in it**, and add the bundle's places last.
3440 
3541### Credential types
3642 
from line 52
4652| **OAuth 2.0 client credentials** | Machine-to-machine OAuth with a client ID and secret |
4753| **MCP Connector** | OAuth sign-in to one of the providers in the picker or to a [remote MCP connector](/docs/connectors/custom/add-unlisted) your organization has added on claude.ai. Sign in once as an admin; the agent acts as that account. Other OAuth APIs can't be connected this way. |
4854 
49<Note>The **MCP Connector** type signs in to a connector from your organization's connector library. If you register a new connector from this form with **Add custom connector…**, that connector is added to the library on the **Connectors** page at [`claude.ai/admin-settings/connectors`](https://claude.ai/admin-settings/connectors), not only to the bundle. Removing the connection from the bundle later leaves the library entry in place.</Note>
55<Note>The **MCP Connector** type signs in to a connector from your organization's connector library. If you register a new connector from this form with **Add custom connector…**, that connector is added to the library on the **Connectors** page at [`claude.ai/admin-settings/connectors`](https://claude.ai/admin-settings/connectors), not only to Claude Tag. Removing the Claude Tag connector later leaves the library entry in place.</Note>
5056 
51For GitHub repositories, use the GitHub connection at [Configure GitHub access](/docs/claude-tag/admins/configure-github) rather than a credential from this table.
57For GitHub repositories, use the Claude GitHub App at [Configure GitHub access](/docs/claude-tag/admins/configure-github) rather than a credential from this table.
5258 
5359If you're unsure which type, check the service's API authentication docs for which header or flow it expects.
5460 
from line 78
7278| Session token | Optional. Only needed for temporary credentials from AWS STS. |
7379| Allowed websites | The AWS service endpoint host, for example `s3.us-east-1.amazonaws.com` or `lambda.us-east-1.amazonaws.com` |
7480 
75Use long-lived credentials from a dedicated IAM user where you can. Temporary STS credentials work but expire on their own schedule, and the connection stops working when they do; you re-enter all three values to rotate.
81Use long-lived credentials from a dedicated IAM user where you can. Temporary STS credentials work but expire on their own schedule, and the connector stops working when they do; you re-enter all three values to rotate.
7682 
77Claude can call the endpoint with `curl`, an AWS SDK, or the AWS CLI. The sandbox holds no real AWS credentials, so a CLI or SDK signs the request with placeholder values; Agent Proxy strips that signature and re-signs with the stored credential before the request leaves for AWS. If a request comes back with HTTP 502 and a reason that begins `injection failed ("<connection name>")`, Agent Proxy couldn't sign it. The troubleshooting entry [An AWS request fails after a successful sign-in](/docs/claude-tag/admins/federated-access/troubleshooting#an-aws-request-fails-after-a-successful-sign-in) lists each cause the reason text names and its fix; the causes and fixes are the same for a connection that stores an access key.
83Claude can call the endpoint with `curl`, an AWS SDK, or the AWS CLI. The sandbox holds no real AWS credentials, so a CLI or SDK signs the request with placeholder values; Agent Proxy strips that signature and re-signs with the stored credential before the request leaves for AWS. If a request comes back with HTTP 502 and a reason that begins `injection failed ("<connection name>")`, Agent Proxy couldn't sign it. The troubleshooting entry [An AWS request fails after a successful sign-in](/docs/claude-tag/admins/federated-access/troubleshooting#an-aws-request-fails-after-a-successful-sign-in) lists each cause the reason text names and its fix; the causes and fixes are the same for a connector that stores an access key.
7884 
7985#### When AWS returns `SignatureDoesNotMatch`
8086 
from line 113
107113 
108114<Steps>
109115 <Step title="Add a plugin that declares the MCP server">
110 In the bundle's **Plugins** tab (or via your [skills repository](/docs/claude-tag/admins/skills-repo)), add a plugin whose `.mcp.json` points at the server URL. The plugin tells Claude the server exists and how to call it.
116 Add a plugin whose `.mcp.json` points at the server URL, from your organization's library or your [skills repository](/docs/claude-tag/admins/skills-repo), wherever the server should be available; see [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins). The plugin tells Claude the server exists and how to call it.
111117 </Step>
112118 
113119 <Step title="Add a credential for the server's host">
114 On the **Credentials** tab, click **Connect** next to **Custom tool** and add a credential for the MCP server's host (for example, a Bearer token with **Allowed websites** set to `your-mcp-host.example.com`). This lets the call leave the sandbox with auth attached.
120 Add a custom connector for the MCP server's host (for example, a Bearer token with **Allowed websites** set to `your-mcp-host.example.com`), where the plugin applies. This lets the call leave the sandbox with auth attached.
115121 </Step>
116122</Steps>
117123 
118124The plugin's `.mcp.json` is loaded because it's part of an attached plugin; an `.mcp.json` checked into a repository Claude clones is not loaded.
119125 
120## Verify the connection
126## Verify the custom connector
121127 
122In a channel under the bundle's scope, in a new thread, ask Claude to make a small read against the API:
128In a channel where the connector applies, in a new thread, ask Claude to make a small read against the API:
123129 
124130```text wrap theme={null}
125131@Claude can you reach api.example.com? Try a GET on /health.
126132```
127133 
128Check the service's own audit log to confirm the call landed under your service account. New threads pick up the connection on their own; in an existing thread, ask Claude to use the service by name.
134Check the service's own audit log to confirm the call landed under your service account. New threads pick up the connector on their own.
129135 
130If Claude reports that it can't use the credential, check its status on the [Access bundles page](https://claude.ai/admin-settings/claude-tag/access-bundles). **Not active** means no allow rule uses the credential yet. **Approval needed** means another admin submitted it through a shared setup link; select **Review**, then **Approve**. See [Verify the connection saved](/docs/claude-tag/admins/add-connections#verify-the-connection-saved).
136If Claude reports that it can't use the credential, open the connector from the **Connectors** tab, where custom connectors are listed under **Custom hosts**. In its **Access from** table, **Not enabled** means no allow rule sends the credential yet; click **Enable** and confirm. A credential a teammate submitted through a setup link waits on the **Requests** tab of [**Notifications**](https://claude.ai/admin-settings/notifications) as **Approval needed**; click **Review**, then **Approve**. See [Verify the connector saved](/docs/claude-tag/admins/add-connections#verify-the-connector-saved).
131137 
132138## Related resources
133139 
134* [Give Claude access](/docs/claude-tag/admins/add-connections): the full connection model
140* [Give Claude access](/docs/claude-tag/admins/add-connections): the full connector model
135141* [Allow a host without a credential](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential): for public APIs that need no auth
136142* [Allow all hosts](/docs/claude-tag/admins/add-connections#allow-all-hosts): the egress option that lets Claude reach any public host without a credential
137143 

claude-tag/admins/connections/datadog Changed · +12 / -12 lines

## Add the connector ## Add the connection to a bundle

from line 6
66 
77<BetaNote />
88 
9<Note>Connections are added inside an [Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle). At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open **Access bundles** in the left navigation, click into a bundle (or **Create** one), and go to its **Credentials** tab.</Note>
9Connecting Datadog lets Claude query metrics, logs, and monitors during debugging in any channel where the connector is on. Claude connects with its own credential, not a person's.
1010 
11Connecting Datadog lets Claude query metrics, logs, and monitors during debugging from any channel under the bundle's scope. You add it as a connection inside an [Access bundle](/docs/claude-tag/admins/add-connections); the credential belongs to the agent, not to any person.
11Pair this connector with the Datadog plugin from Anthropic's plugin marketplace so Claude knows how to call the API. This connector calls Datadog's HTTP API. It isn't an MCP server or a member's personal claude.ai connector.
1212 
13Pair this connection with the Datadog plugin from Anthropic's plugin marketplace so Claude knows how to call the API; see [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins). This is an HTTP API connection, not an MCP server or a personal claude.ai connector.
14 
1513## Create the credential in Datadog
1614 
1715Create an API key under a service account in Datadog. Also create an Application key under the same service account. The Application key carries the read scopes, so restrict it to read-only roles. The form doesn't require the Application key, but reading metrics, monitors, and dashboards does.
from line 16
1816 
1917Datadog's own guide for creating the credential is at [docs.datadoghq.com](https://docs.datadoghq.com/account_management/api-app-keys/).
2018 
21## Add the connection to a bundle
19## Add the connector
2220 
23In the bundle, click **Connect** next to Datadog. The picker has one Datadog entry per Datadog site. Datadog has a separate API host per site, and a key only works against its own, so pick the entry that matches your Datadog account's site.
21Go to [**Organization settings > Claude Tag > Connectors**](https://claude.ai/admin-settings/claude-tag?access=connectors), click **Add**, and select the Datadog entry for your Datadog account's site. Datadog has a separate API host per site, and a key only works against its own.
2422 
25| Picker entry | Site and API host |
23| Entry | Site and API host |
2624| :- | :- |
2725| **Datadog** | US1, `api.datadoghq.com`, Datadog's default site |
2826| **Datadog (US3)** | US3, `api.us3.datadoghq.com` |
from line 30
3230| **Datadog (AP2)** | AP2, `api.ap2.datadoghq.com` |
3331| **Datadog (US1-FED)** | US1-FED, `api.ddog-gov.com` |
3432 
35The form asks for the same fields in every entry.
33Every entry asks for the same fields in the connect form.
3634 
3735| Field | Value |
3836| :- | :- |
3937| Claude's API key | The API key from Datadog |
4038| Claude's application key | The Application key from Datadog. Optional in the form; add it so Claude can read metrics, monitors, and dashboards |
41| Allowed websites | Prefilled with the entry's API host |
39| Allowed websites | The entry's API host (preset) |
4240 
43The connection is created with path prefixes that cover Datadog's read and query routes: metric, log, trace, and RUM queries, monitors, downtimes, dashboards, SLOs, notebooks, events, hosts, service definitions, and incident search. It doesn't cover Datadog's key, user, integration, or log-configuration management routes, so Claude can't call those through it. To narrow the connection further, for example to `GET` only, or to allow another route, select **Edit** on the connection's row; see [Restrict by path or method](/docs/claude-tag/admins/add-connections#restrict-by-path-or-method).
41If the connect form offers to include the Datadog plugin, leave that box selected; otherwise add the plugin on the [**Skills and plugins**](https://claude.ai/admin-settings/claude-tag?access=plugins) tab. The first credential you add for a service from the **Connectors** tab is on in every workspace and channel as soon as you save it. To give it narrower reach, see [where a new connector applies](/docs/claude-tag/admins/add-connections#add-a-connection) before you save the connector. Click **Connect** to save the connector.
4442 
43The connector is created with path prefixes that cover Datadog's read and query routes: metric, log, trace, and RUM queries, monitors, downtimes, dashboards, SLOs, notebooks, events, hosts, service definitions, and incident search. It doesn't cover Datadog's key, user, integration, or log-configuration management routes, so Claude can't call those through it. To narrow the connector further, for example to `GET` only, or to allow another route, go to [**Organization settings > Claude Tag > Connectors**](https://claude.ai/admin-settings/claude-tag?access=connectors), click your Datadog connector, open the menu on the credential's row in the **Access from** table, and click **Edit**. See [Restrict by path or method](/docs/claude-tag/admins/add-connections#restrict-by-path-or-method).
44 
4545The Agent Proxy injects the credential at the network boundary; the model and the sandbox are not given the key. See [how Agent Proxy works](/docs/claude-tag/concepts/agent-identity#agent-proxy).
4646 
4747## Verify the connection
4848 
49In a channel under the bundle's scope, in a new thread:
49In a channel where the connector is on, in a new thread:
5050 
5151```text wrap theme={null}
5252@Claude what can you access from this channel?
5353```
5454 
55Datadog appears in the list once the connection is live. New threads pick up the connection on their own; in an existing thread, ask Claude to use the service by name.
55Datadog appears in the list once the connector is live. New threads pick up the connector on their own; in an existing thread, ask Claude to use the service by name.
5656 
5757## Related resources
5858 

claude-tag/admins/connections/gitlab Changed · +9 / -11 lines

## Add the connector ## Add the connection

from line 6
66 
77<BetaNote />
88 
9<Note>Connections are added inside an [Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle). At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open **Access bundles** in the left navigation, click into a bundle (or **Create** one), and go to its **Credentials** tab.</Note>
9Connecting GitLab lets Claude read and search projects, manage issues, comment on merge requests, and check pipeline status, all through the GitLab REST API. The connector holds a single access token.
1010 
11Connecting GitLab lets Claude read and search projects, manage issues, comment on merge requests, and check pipeline status, all through the GitLab REST API. The connection is a single access token added to a bundle.
12 
1311<Tip>This page is the credential field reference. The full setup walkthrough, including creating a dedicated GitLab service account for Claude and scoping its group access, is at [Configure GitLab access](/docs/claude-tag/admins/configure-gitlab).</Tip>
1412 
15If your plugin marketplace includes a GitLab plugin, pair it with this connection so Claude knows how to call the API. See [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins). The connection works without it.
13If your plugin marketplace includes a GitLab plugin, pair it with this connector so Claude knows how to call the API. Add the plugin on the [**Skills and plugins**](https://claude.ai/admin-settings/claude-tag?access=plugins) tab. The connector works without it.
1614 
17## Add the connection
15## Add the connector
1816 
1917<Steps>
2018 <Step title="Create the token in GitLab">
from line 19
2119 A personal access token from a [dedicated service account](/docs/claude-tag/admins/configure-gitlab#create-a-dedicated-gitlab-account-for-claude) is recommended, so one identity covers every group you add it to. Project and group access tokens also work if you only need a single project or group. Grant the `api` scope for read and write, or `read_api` for read-only. The token starts with `glpat-`.
2220 </Step>
2321 
24 <Step title="Add the credential to a bundle">
25 On the bundle's **Credentials** tab, click **Connect** next to **GitLab** and paste the token. For self-managed GitLab, switch to the form's **Advanced** tab and add your instance's hostname under **Allowed websites**.
22 <Step title="Add the connector">
23 Go to [**Organization settings > Claude Tag > Connectors**](https://claude.ai/admin-settings/claude-tag?access=connectors), click **Add**, select **GitLab**, and paste the token. For self-managed GitLab, switch to the form's **Advanced** tab and add your instance's hostname under **Allowed websites**. The first credential you add for a service from the **Connectors** tab is on in every workspace and channel as soon as you save it. To give it narrower reach, see [where a new connector applies](/docs/claude-tag/admins/add-connections#add-a-connection) before you save the connector. Click **Connect** to save the connector.
2624 </Step>
2725</Steps>
2826 
29**You'll see:** GitLab listed in the bundle's connections, and `@Claude what can you access from this channel?` returns it in a new thread under the bundle's scope. New threads pick up the connection on their own; in an existing thread, ask Claude to use the service by name.
27**You'll see:** GitLab on the **Connectors** tab, and `@Claude what can you access from this channel?` returns it in a new thread in any channel where the connector is on. New threads pick up the connector on their own; in an existing thread, ask Claude to use the service by name.
3028 
3129| Field | Value |
3230| :- | :- |
3331| Claude’s personal access token | The token from GitLab, starting with `glpat-`. Project and group access tokens work here too. |
34| Allowed websites | `gitlab.com` (preset). For self-managed GitLab, open the **Advanced** tab and add your instance's hostname here. |
32| Allowed websites | `gitlab.com` (preset) |
3533 
3634GitLab's own guide for creating tokens is at [docs.gitlab.com](https://docs.gitlab.com/api/rest/authentication/).
3735 
from line 39
4139| :- | :- | :- |
4240| Auth | A service account's personal access token | The Claude GitHub App, [installed separately](/docs/claude-tag/admins/configure-github) |
4341| Referencing a project in a thread | Give Claude the full project URL; it reads it through the API | Typing `owner/repo` in the message auto-attaches it |
44| Self-managed | Your hostname under **Advanced → Allowed websites** | [GitHub Enterprise setup](/docs/claude-tag/admins/configure-github#github-enterprise) |
42| Self-managed | Your hostname under **Advanced > Allowed websites** | [GitHub Enterprise setup](/docs/claude-tag/admins/configure-github#github-enterprise) |
4543| Handing back changes | Manages issues and comments on merge requests through the API | [Draft pull requests](/docs/claude-tag/users/use-cases/work-with-github) authored by the Claude GitHub App |
4644 
47The connection is API-only. The token authenticates GitLab API requests, not git, so Claude gets a 401 error when it tries to clone a private project or push to any project over HTTPS, even with the connection in place. To clone a repository into the session workspace, connect it through [GitHub](/docs/claude-tag/admins/configure-github) instead.
45The connector is API-only. The token authenticates GitLab API requests, not git, so Claude gets a 401 error when it tries to clone a private project or push to any project over HTTPS, even with the connector in place. To clone a repository into the session workspace, connect it through [GitHub](/docs/claude-tag/admins/configure-github) instead.
4846 
4947The token is auto-injected on every API request to your GitLab host. The model and the sandbox are not given the key; see [how Agent Proxy works](/docs/claude-tag/concepts/agent-identity#agent-proxy).
5048 

claude-tag/admins/connections/gong Changed · +9 / -9 lines

## Add the connector ## Add the connection to a bundle

from line 6
66 
77<BetaNote />
88 
9<Note>Connections are added inside an [Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle). At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open **Access bundles** in the left navigation, click into a bundle (or **Create** one), and go to its **Credentials** tab.</Note>
9Connecting Gong lets Claude pull call summaries and deal context in any channel where the connector is on. Claude connects with its own credential, not a person's.
1010 
11Connecting Gong lets Claude pull call summaries and deal context from any channel under the bundle's scope. You add it as a connection inside an [Access bundle](/docs/claude-tag/admins/add-connections); the credential belongs to the agent, not to any person.
11Pair this connector with the Gong plugin from Anthropic's plugin marketplace so Claude knows how to call the API. Add the plugin on the [**Skills and plugins**](https://claude.ai/admin-settings/claude-tag?access=plugins) tab. This connector calls Gong's HTTP API. It isn't an MCP server or a member's personal claude.ai connector.
1212 
13Pair this connection with the Gong plugin from Anthropic's plugin marketplace so Claude knows how to call the API; see [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins). This is an HTTP API connection, not an MCP server or a personal claude.ai connector.
14 
1513## Create the credential in Gong
1614 
1715A Gong technical admin generates the access key and secret; the key is tied to the admin who created it, so use a dedicated admin account where possible.
from line 18
2018 
2119Gong's own guide for creating the credential is at [help.gong.io](https://help.gong.io/docs/receive-access-to-the-api).
2220 
23## Add the connection to a bundle
21## Add the connector
2422 
25In the bundle, click **Connect** next to **Gong**.
23Go to [**Organization settings > Claude Tag > Connectors**](https://claude.ai/admin-settings/claude-tag?access=connectors), click **Add**, and select **Gong**. Fill in these fields in the connect form.
2624 
2725| Field | Value |
2826| :- | :- |
from line 28
3028| Claude's access key secret | The access key secret from Gong |
3129| Allowed websites | `api.gong.io` (preset) |
3230 
33Gong assigns each company its own API base URL, like `us-46459.api.gong.io`. Copy yours from **Company Settings** → **Ecosystem** → **API** in Gong, then switch to the connection form's **Advanced** tab and enter it under **Allowed websites**.
31Gong assigns each company its own API base URL, like `us-46459.api.gong.io`. Copy yours from **Company Settings > Ecosystem > API** in Gong, then switch to the connect form's **Advanced** tab and enter it under **Allowed websites**.
3432 
33The first credential you add for a service from the **Connectors** tab is on in every workspace and channel as soon as you save it. To give it narrower reach, see [where a new connector applies](/docs/claude-tag/admins/add-connections#add-a-connection) before you save the connector. Click **Connect** to save the connector.
34 
3535The Agent Proxy injects the credential at the network boundary; the model and the sandbox are not given the key. See [how Agent Proxy works](/docs/claude-tag/concepts/agent-identity#agent-proxy).
3636 
3737## Verify the connection
3838 
39In a channel under the bundle's scope, in a new thread:
39In a channel where the connector is on, in a new thread:
4040 
4141```text wrap theme={null}
4242@Claude what can you access from this channel?
4343```
4444 
45Gong appears in the list once the connection is live. New threads pick up the connection on their own; in an existing thread, ask Claude to use the service by name.
45Gong appears in the list once the connector is live. New threads pick up the connector on their own; in an existing thread, ask Claude to use the service by name.
4646 
4747## Related resources
4848 

claude-tag/admins/connections/google Changed · +20 / -18 lines

## Add the connector with Google sign-in ## Add the connector with a service account ## Add the connection with OAuth ## Add the connection with a service account

from line 6
66 
77<BetaNote />
88 
9<Note>Connections are added inside an [Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle). At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open **Access bundles** in the left navigation, click into a bundle (or **Create** one), and go to its **Credentials** tab.</Note>
9Connecting Google Drive, Calendar, and Gmail lets Claude read documents, spreadsheets, calendar events, and email in any channel where the connector is on. Claude connects with its own credential, not a person's.
1010 
11Connecting Google Drive, Calendar, and Gmail lets Claude read documents, spreadsheets, calendar events, and email from any channel under the bundle's scope. You add it as a connection inside an [Access bundle](/docs/claude-tag/admins/add-connections); the credential belongs to the agent, not to any person.
11This connector calls Google's HTTP APIs, and it's separate from members' personal claude.ai connectors. A member's own Google connector applies in one-to-one DMs. Claude can also [use it in a channel](/docs/claude-tag/concepts/personal-connectors) for that member's own tasks, after the member allows it.
1212 
13This is an HTTP API connection, not a personal claude.ai connector. A member's own Google connector applies in one-to-one DMs. Claude can also [use it in a channel](/docs/claude-tag/concepts/personal-connectors) for that member's own tasks, after the member allows it.
14 
1513## Choose OAuth or a service account
1614 
17The connection picker offers two routes:
15The **Add a connector** dialog offers two routes to Google:
1816 
1917| Route | When to use |
2018| :- | :- |
21| **OAuth (Connect button)** | Fastest path. An admin signs in with a Google account that has access to the content Claude needs. |
22| **GCP service-account key** | When you want a dedicated non-human identity in Google with auditable access, or need domain-wide delegation across your Workspace. |
19| **Google sign-in** (the **Google Drive**, **Google Calendar**, or **Gmail** entry) | Fastest path. An admin signs in with a Google account that has access to the content Claude needs. |
20| **GCP service-account key** (the **Custom connector** entry) | When you want a dedicated non-human identity in Google with auditable access, or need domain-wide delegation across your Workspace. |
2321 
24Both routes create a credential and an allowed-websites rule for the Google hosts the connection uses.
22Both routes create a credential and an allowed-websites rule for the Google hosts the connector uses.
2523 
26## Add the connection with OAuth
24## Add the connector with Google sign-in
2725 
28<Warning>Use a dedicated Google account for this connection (for example, `[email protected]`), not your own. The connection is shared: anyone in a channel under the bundle's scope can ask Claude to read whatever this account can see in Drive, Calendar, and Gmail. A dedicated account starts with no access until you share the specific folders and calendars Claude needs, and keeps its activity under a separate identity in Google's audit log.</Warning>
26<Warning>Use a dedicated Google account for this connector (for example, `[email protected]`), not your own. The connector is shared: anyone in a channel where it's on can ask Claude to read whatever this account can see in Drive, Calendar, and Gmail. A dedicated account starts with no access until you share the specific folders and calendars Claude needs, and keeps its activity under a separate identity in Google's audit log.</Warning>
2927 
30In the bundle, click **Connect** next to **Google Drive**, **Google Calendar**, or **Gmail**. The dialog lists the Google hosts the connection can reach; there are no scopes to choose. Click **Sign in with Google Drive** (or **Sign in with Google Calendar**, or **Sign in with Gmail**), approve the Google consent screen, and the credential is saved.
28Go to [**Organization settings > Claude Tag > Connectors**](https://claude.ai/admin-settings/claude-tag?access=connectors), click **Add**, and select **Google Drive**, **Google Calendar**, or **Gmail**. The connect form lists the Google hosts the connector can reach; there are no scopes to choose. The first credential you add for a service from the **Connectors** tab is on in every workspace and channel as soon as you save it. To give it narrower reach, see [where a new connector applies](/docs/claude-tag/admins/add-connections#add-a-connection) before you sign in. Click **Sign in with Google Drive** (or **Sign in with Google Calendar**, or **Sign in with Gmail**), approve the Google consent screen, and the credential is saved.
3129 
32The connection's reach is whatever the signed-in Google account can see. Share the relevant folders and calendars with that account in Google before testing.
30The connector's reach is whatever the signed-in Google account can see. Share the relevant folders and calendars with that account in Google before testing.
3331 
34## Add the connection with a service account
32## Add the connector with a service account
3533 
36In the bundle, click **Connect** next to **Custom tool** and choose **GCP access token (with Service Account Key)**.
34Go to [**Organization settings > Claude Tag > Connectors**](https://claude.ai/admin-settings/claude-tag?access=connectors), click **Add**, and select **Custom connector**. Fill in these fields in the connect form.
3735 
3836| Field | Value |
3937| :- | :- |
38| Name | A name for the connector, such as `Google Workspace` |
39| Credential type | **GCP access token (with Service Account Key)** |
4040| GCP service account key (JSON) | The JSON key file from Google Cloud Console |
41| Scopes (optional) | The Google API scopes to request (for example `https://www.googleapis.com/auth/drive.readonly`). If you leave the field empty, the connection requests `https://www.googleapis.com/auth/cloud-platform`. |
41| Scopes (optional) | The Google API scopes to request (for example `https://www.googleapis.com/auth/drive.readonly`). If you leave the field empty, the connector requests `https://www.googleapis.com/auth/cloud-platform`. |
4242| Subject (optional) | A user email to impersonate via domain-wide delegation. Set this for Workspace data (Drive, Calendar, Gmail, Docs). |
4343| Allowed websites | `*.googleapis.com` |
4444 
45The first credential you add for a service from the **Connectors** tab is on in every workspace and channel as soon as you save it. To give it narrower reach, see [where a new connector applies](/docs/claude-tag/admins/add-connections#add-a-connection) before you save the connector. Click **Connect** to save the connector.
46 
4547For Google Workspace data (Drive, Calendar, Gmail, Docs), the service account needs domain-wide delegation configured in your Google Admin console. In the service account's domain-wide delegation entry, list every scope you entered in **Scopes**, or `https://www.googleapis.com/auth/cloud-platform` if you left **Scopes** empty. Google's guide is at [developers.google.com/identity/protocols/oauth2/service-account](https://developers.google.com/identity/protocols/oauth2/service-account#delegatingauthority).
4648 
4749Google refuses the token request when the domain-wide delegation entry is missing one of the requested scopes. Claude then reports HTTP 502 with a reason that starts with `injection failed ("<connection name>")`.
from line 52
5052 
5153## Verify the connection
5254 
53In a channel under the bundle's scope, in a new thread:
55In a channel where the connector is on, in a new thread:
5456 
5557```text wrap theme={null}
5658@Claude what can you access from this channel?
5759```
5860 
59Google Drive, Calendar, or Gmail appears in the list once the connection is live. New threads pick up the connection on their own; in an existing thread, ask Claude to use the service by name.
61Google Drive, Calendar, or Gmail appears in the list once the connector is live. New threads pick up the connector on their own; in an existing thread, ask Claude to use the service by name.
6062 
61The credential row in the bundle shows **Never used** until Claude first uses the connection. The label tracks usage, not health, so a working connection stays on **Never used** until someone exercises it. To confirm the connection works, ask Claude in the same thread to read something from the service, such as today's calendar events or a named document. The label updates after that first read.
63To confirm the connector works, ask Claude in the same thread to read something from the service, such as today's calendar events or a named document.
6264 
6365## Related resources
6466 

claude-tag/admins/connections/hubspot Changed · +9 / -9 lines

## Add the connector ## Add the connection to a bundle

from line 6
66 
77<BetaNote />
88 
9<Note>Connections are added inside an [Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle). At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open **Access bundles** in the left navigation, click into a bundle (or **Create** one), and go to its **Credentials** tab.</Note>
9Connecting HubSpot lets Claude pull pipeline, deal, and contact state in any channel where the connector is on. Claude connects with its own credential, not a person's.
1010 
11Connecting HubSpot lets Claude pull pipeline, deal, and contact state from any channel under the bundle's scope. You add it as a connection inside an [Access bundle](/docs/claude-tag/admins/add-connections); the credential belongs to the agent, not to any person.
11Pair this connector with the HubSpot plugin from Anthropic's plugin marketplace so Claude knows how to call the API. This connector calls HubSpot's HTTP API. It isn't an MCP server or a member's personal claude.ai connector.
1212 
13Pair this connection with the HubSpot plugin from Anthropic's plugin marketplace so Claude knows how to call the API; see [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins). This is an HTTP API connection, not an MCP server or a personal claude.ai connector.
14 
1513## Create the credential in HubSpot
1614 
1715Create a private app and select the read scopes you need (typically `crm.objects.contacts.read`, `crm.objects.companies.read`, `crm.objects.deals.read`). The private app acts as its own identity in HubSpot's audit log.
from line 16
1816 
1917HubSpot's own guide for creating the credential is at [developers.hubspot.com](https://developers.hubspot.com/docs/apps/legacy-apps/private-apps/overview).
2018 
21## Add the connection to a bundle
19## Add the connector
2220 
23In the bundle, click **Connect** next to **HubSpot**.
21Go to [**Organization settings > Claude Tag > Connectors**](https://claude.ai/admin-settings/claude-tag?access=connectors), click **Add**, and select **HubSpot**. Fill in these fields in the connect form.
2422 
2523| Field | Value |
2624| :- | :- |
2725| Claude's private app token | The private app token from HubSpot |
28| Allowed websites | `api.hubapi.com` (preset). To add a different host, use the **Advanced** tab. |
26| Allowed websites | `api.hubapi.com` (preset) |
2927 
28If the connect form offers to include the HubSpot plugin, leave that box selected; otherwise add the plugin on the [**Skills and plugins**](https://claude.ai/admin-settings/claude-tag?access=plugins) tab. The first credential you add for a service from the **Connectors** tab is on in every workspace and channel as soon as you save it. To give it narrower reach, see [where a new connector applies](/docs/claude-tag/admins/add-connections#add-a-connection) before you save the connector. Click **Connect** to save the connector.
29 
3030The Agent Proxy injects the credential at the network boundary; the model and the sandbox are not given the key. See [how Agent Proxy works](/docs/claude-tag/concepts/agent-identity#agent-proxy).
3131 
3232## Verify the connection
3333 
34In a channel under the bundle's scope, in a new thread:
34In a channel where the connector is on, in a new thread:
3535 
3636```text wrap theme={null}
3737@Claude what can you access from this channel?
3838```
3939 
40HubSpot appears in the list once the connection is live. New threads pick up the connection on their own; in an existing thread, ask Claude to use the service by name.
40HubSpot appears in the list once the connector is live. New threads pick up the connector on their own; in an existing thread, ask Claude to use the service by name.
4141 
4242## Related resources
4343 

claude-tag/admins/connections/linear Changed · +9 / -9 lines

## Add the connector ## Add the connection to a bundle

from line 6
66 
77<BetaNote />
88 
9<Note>Connections are added inside an [Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle). At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open **Access bundles** in the left navigation, click into a bundle (or **Create** one), and go to its **Credentials** tab.</Note>
9Connecting Linear lets Claude file tickets and post status updates from a thread in any channel where the connector is on. Claude connects with its own credential, not a person's.
1010 
11Connecting Linear lets Claude file tickets and post status updates from a thread from any channel under the bundle's scope. You add it as a connection inside an [Access bundle](/docs/claude-tag/admins/add-connections); the credential belongs to the agent, not to any person.
11Pair this connector with the Linear plugin from Anthropic's plugin marketplace so Claude knows how to call the API. This connector calls Linear's HTTP API. It isn't an MCP server or a member's personal claude.ai connector.
1212 
13Pair this connection with the Linear plugin from Anthropic's plugin marketplace so Claude knows how to call the API; see [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins). This is an HTTP API connection, not an MCP server or a personal claude.ai connector.
14 
1513## Create the credential in Linear
1614 
1715Create a personal API key from a dedicated Linear seat for Claude, not your own account, so its activity shows under that seat in Linear's audit log.
from line 18
2018 
2119Linear's own guide for creating the credential is at [linear.app](https://linear.app/developers/graphql#personal-api-keys).
2220 
23## Add the connection to a bundle
21## Add the connector
2422 
25In the bundle, click **Connect** next to **Linear**.
23Go to [**Organization settings > Claude Tag > Connectors**](https://claude.ai/admin-settings/claude-tag?access=connectors), click **Add**, and select **Linear**. Fill in these fields in the connect form.
2624 
2725| Field | Value |
2826| :- | :- |
2927| Claude's API key | The API key from Linear |
30| Allowed websites | `api.linear.app` |
28| Allowed websites | `api.linear.app` (preset) |
3129 
30If the connect form offers to include the Linear plugin, leave that box selected; otherwise add the plugin on the [**Skills and plugins**](https://claude.ai/admin-settings/claude-tag?access=plugins) tab. The first credential you add for a service from the **Connectors** tab is on in every workspace and channel as soon as you save it. To give it narrower reach, see [where a new connector applies](/docs/claude-tag/admins/add-connections#add-a-connection) before you save the connector. Click **Connect** to save the connector.
31 
3232The Agent Proxy injects the credential at the network boundary; the model and the sandbox are not given the key. See [how Agent Proxy works](/docs/claude-tag/concepts/agent-identity#agent-proxy).
3333 
3434## Verify the connection
3535 
36In a channel under the bundle's scope, in a new thread:
36In a channel where the connector is on, in a new thread:
3737 
3838```text wrap theme={null}
3939@Claude what can you access from this channel?
4040```
4141 
42Linear appears in the list once the connection is live. New threads pick up the connection on their own; in an existing thread, ask Claude to use the service by name.
42Linear appears in the list once the connector is live. New threads pick up the connector on their own; in an existing thread, ask Claude to use the service by name.
4343 
4444## Related resources
4545 

claude-tag/admins/connections/notion Changed · +9 / -9 lines

## Add the connector ## Add the connection to a bundle

from line 6
66 
77<BetaNote />
88 
9<Note>Connections are added inside an [Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle). At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open **Access bundles** in the left navigation, click into a bundle (or **Create** one), and go to its **Credentials** tab.</Note>
9Connecting Notion lets Claude ground answers in your Notion workspace in any channel where the connector is on. Claude connects with its own credential, not a person's.
1010 
11Connecting Notion lets Claude ground answers in your Notion workspace from any channel under the bundle's scope. You add it as a connection inside an [Access bundle](/docs/claude-tag/admins/add-connections); the credential belongs to the agent, not to any person.
11Pair this connector with the Notion plugin from Anthropic's plugin marketplace so Claude knows how to call the API. This connector calls Notion's HTTP API. It isn't an MCP server or a member's personal claude.ai connector.
1212 
13Pair this connection with the Notion plugin from Anthropic's plugin marketplace so Claude knows how to call the API; see [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins). This is an HTTP API connection, not an MCP server or a personal claude.ai connector.
14 
1513## Create the credential in Notion
1614 
1715Create an internal integration in Notion and share the specific pages or databases Claude should read with that integration. Nothing is reachable until shared.
from line 16
1816 
1917Notion's own guide for creating the credential is at [developers.notion.com](https://developers.notion.com/docs/create-a-notion-integration).
2018 
21## Add the connection to a bundle
19## Add the connector
2220 
23In the bundle, click **Connect** next to **Notion**.
21Go to [**Organization settings > Claude Tag > Connectors**](https://claude.ai/admin-settings/claude-tag?access=connectors), click **Add**, and select **Notion**. Fill in these fields in the connect form.
2422 
2523| Field | Value |
2624| :- | :- |
2725| Claude's integration secret | The internal integration secret from Notion |
28| Allowed websites | `api.notion.com` |
26| Allowed websites | `api.notion.com` (preset) |
2927 
28If the connect form offers to include the Notion plugin, leave that box selected; otherwise add the plugin on the [**Skills and plugins**](https://claude.ai/admin-settings/claude-tag?access=plugins) tab. The first credential you add for a service from the **Connectors** tab is on in every workspace and channel as soon as you save it. To give it narrower reach, see [where a new connector applies](/docs/claude-tag/admins/add-connections#add-a-connection) before you save the connector. Click **Connect** to save the connector.
29 
3030The Agent Proxy injects the credential at the network boundary; the model and the sandbox are not given the key. See [how Agent Proxy works](/docs/claude-tag/concepts/agent-identity#agent-proxy).
3131 
3232## Verify the connection
3333 
34In a channel under the bundle's scope, in a new thread:
34In a channel where the connector is on, in a new thread:
3535 
3636```text wrap theme={null}
3737@Claude what can you access from this channel?
3838```
3939 
40Notion appears in the list once the connection is live. New threads pick up the connection on their own; in an existing thread, ask Claude to use the service by name.
40Notion appears in the list once the connector is live. New threads pick up the connector on their own; in an existing thread, ask Claude to use the service by name.
4141 
4242## Related resources
4343 

claude-tag/admins/connections/overview Changed · +9 / -9 lines

## When a connector fails after setup ## When a connection fails after setup

from line 6
66 
77<BetaNote />
88 
9Each guide covers one service: how to create the credential as a dedicated identity, what to paste into the Access bundle, and the Allowed websites value. For the model behind connections (credential types, Agent Proxy, allowed websites), see [Give Claude access](/docs/claude-tag/admins/add-connections).
9Each guide covers one service: how to create the credential as a dedicated identity, what to paste into the connect form, and the **Allowed websites** value. For the model behind connectors (credential types, Agent Proxy, allowed websites, bundles), see [Give Claude access](/docs/claude-tag/admins/add-connections).
1010 
11<Warning>Always connect a dedicated account for Claude (for example, `[email protected]`), not your personal login. Anyone in a channel under the bundle's [scope](/docs/claude-tag/admins/attach-to-scope) can use the connection through Claude, so whatever this account can reach is available to every member of those channels. See [Create a dedicated account per service](/docs/claude-tag/admins/add-connections#create-a-dedicated-account-per-service).</Warning>
11<Warning>Always connect a dedicated account for Claude (for example, `[email protected]`), not your personal login. Anyone in a channel where the connector applies can use it through Claude, so whatever this account can reach is available to every member of those channels. See [Create a dedicated account per service](/docs/claude-tag/admins/add-connections#create-a-dedicated-account-per-service). Before you add a connector, see [where a new connector applies](/docs/claude-tag/admins/add-connections#where-a-new-connector-applies).</Warning>
1212 
1313| Service | Category | Guide |
1414| :- | :- | :- |
from line 30
3030| Stripe | Billing | [Connect Stripe](/docs/claude-tag/admins/connections/stripe) |
3131| Vercel | Deployments | [Connect Vercel](/docs/claude-tag/admins/connections/vercel) |
3232 
33GitHub is managed through the Claude GitHub App rather than a connection in this list; see [Configure GitHub access](/docs/claude-tag/admins/configure-github).
33GitHub is managed through the Claude GitHub App rather than a credential; see [Configure GitHub access](/docs/claude-tag/admins/configure-github).
3434 
35Services marked (custom) have no preset button. Add them with **Custom tool** following their guide.
35Services marked (custom) aren't in the **Add a connector** list. Add them with **Custom connector** following their guide.
3636 
3737## Connect a service that has no guide
3838 
39You can add any app that has an API as a custom connection or a custom MCP server, including services this page has no guide for. See [Connect a custom service](/docs/claude-tag/admins/connections/custom) for the credential types and form fields.
39You can add any app that has an API as a custom connector or a custom MCP server, including services this page has no guide for. See [Connect a custom service](/docs/claude-tag/admins/connections/custom) for the credential types and form fields.
4040 
41## When a connection fails after setup
41## When a connector fails after setup
4242 
43If Claude says it can't reach a service you connected, start with the checks at the top of [Troubleshoot Claude Tag setup](/docs/claude-tag/admins/troubleshooting). Confirm the connection is in a bundle [attached to the channel's scope](/docs/claude-tag/admins/attach-to-scope), and rerun the test in a new thread, since a session loads its connections when it starts.
43If Claude says it can't reach a service you connected, start with the checks at the top of [Troubleshoot Claude Tag setup](/docs/claude-tag/admins/troubleshooting). Open the channel's page from the **Channels** tab under **Claude's access** and confirm the connector is listed in its **Claude's access** table. Then rerun the test in a new thread.
4444 
45Two entries on the troubleshooting page cover connection failures directly:
45Two entries on the troubleshooting page cover connector failures directly:
4646 
47* [A connection works in one channel but not another](/docs/claude-tag/admins/troubleshooting#a-connection-works-in-one-channel-but-not-another): bundles attach per scope, so the failing channel's scope is likely missing the bundle
47* [A connection works in one channel but not another](/docs/claude-tag/admins/troubleshooting#a-connection-works-in-one-channel-but-not-another): the connector, or the bundle that holds it, likely doesn't apply to the failing channel
4848* [I hit an authentication error and couldn't finish this turn](/docs/claude-tag/admins/troubleshooting#i-hit-an-authentication-error-and-couldn%E2%80%99t-finish-this-turn): Claude posts that message when its own request fails an authentication check. A connected service's failing credential surfaces as a tool error inside Claude's reply instead
4949 

claude-tag/admins/connections/pagerduty Changed · +10 / -10 lines

## Add the connector ## Add the connection to a bundle

from line 6
66 
77<BetaNote />
88 
9<Note>Connections are added inside an [Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle). At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open **Access bundles** in the left navigation, click into a bundle (or **Create** one), and go to its **Credentials** tab.</Note>
9Connecting PagerDuty lets Claude read incidents and on-call schedules during incident work in any channel where the connector is on. Claude connects with its own credential, not a person's.
1010 
11Connecting PagerDuty lets Claude read incidents and on-call schedules during incident work from any channel under the bundle's scope. You add it as a connection inside an [Access bundle](/docs/claude-tag/admins/add-connections); the credential belongs to the agent, not to any person.
11Pair this connector with the PagerDuty plugin from Anthropic's plugin marketplace so Claude knows how to call the API. This connector calls PagerDuty's HTTP API. It isn't an MCP server or a member's personal claude.ai connector.
1212 
13Pair this connection with the PagerDuty plugin from Anthropic's plugin marketplace so Claude knows how to call the API; see [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins). This is an HTTP API connection, not an MCP server or a personal claude.ai connector.
14 
1513## Create the credential in PagerDuty
1614 
17Generate a general-access read-only API key. A read-write key lets Claude acknowledge and resolve incidents; grant that only on a private incident-channel scope.
15Generate a general-access read-only API key. A read-write key lets Claude acknowledge and resolve incidents. If you use one, [turn the connector on only in a private incident channel](/docs/claude-tag/admins/add-connections#add-a-connection).
1816 
1917Creating a general-access key requires the PagerDuty Admin or Account Owner role; non-admins only see User Token keys, which also work but inherit that user's permissions.
2018 
2119PagerDuty's own guide for creating the credential is at [support.pagerduty.com](https://support.pagerduty.com/main/docs/api-access-keys#generate-a-general-access-rest-api-key).
2220 
23## Add the connection to a bundle
21## Add the connector
2422 
25In the bundle, click **Connect** next to **PagerDuty**.
23Go to [**Organization settings > Claude Tag > Connectors**](https://claude.ai/admin-settings/claude-tag?access=connectors), click **Add**, and select **PagerDuty**. Fill in these fields in the connect form.
2624 
2725| Field | Value |
2826| :- | :- |
2927| Claude's API key | The api key from PagerDuty |
30| Allowed websites | `api.pagerduty.com` |
28| Allowed websites | `api.pagerduty.com` (preset) |
3129 
3230PagerDuty accounts on the EU service region use `api.eu.pagerduty.com` instead.
3331 
32If the connect form offers to include the PagerDuty plugin, leave that box selected; otherwise add the plugin on the [**Skills and plugins**](https://claude.ai/admin-settings/claude-tag?access=plugins) tab. The first credential you add for a service from the **Connectors** tab is on in every workspace and channel as soon as you save it. To give it narrower reach, see [where a new connector applies](/docs/claude-tag/admins/add-connections#add-a-connection) before you save the connector. Click **Connect** to save the connector.
33 
3434The Agent Proxy injects the credential at the network boundary; the model and the sandbox are not given the key. See [how Agent Proxy works](/docs/claude-tag/concepts/agent-identity#agent-proxy).
3535 
3636## Verify the connection
3737 
38In a channel under the bundle's scope, in a new thread:
38In a channel where the connector is on, in a new thread:
3939 
4040```text wrap theme={null}
4141@Claude what can you access from this channel?
4242```
4343 
44PagerDuty appears in the list once the connection is live. New threads pick up the connection on their own; in an existing thread, ask Claude to use the service by name.
44PagerDuty appears in the list once the connector is live. New threads pick up the connector on their own; in an existing thread, ask Claude to use the service by name.
4545 
4646## Related resources
4747 

claude-tag/admins/connections/salesforce Changed · +8 / -8 lines

## Add the connector ## Add the connection to a bundle

from line 6
66 
77<BetaNote />
88 
9<Note>Connections are added inside an [Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle). At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open **Access bundles** in the left navigation, click into a bundle (or **Create** one), and go to its **Credentials** tab.</Note>
9Connecting Salesforce lets Claude read accounts, contacts, opportunities, and cases (and write, if you grant it) in any channel where the connector is on. Claude connects with its own credential, not a person's. The connector uses the OAuth 2.0 client credentials flow.
1010 
11Connecting Salesforce lets Claude read accounts, contacts, opportunities, and cases (and write, if you grant it) from any channel under the bundle's scope. You add it as a connection inside an [Access bundle](/docs/claude-tag/admins/add-connections); the credential belongs to the agent, not to any person. The connection uses the OAuth 2.0 client credentials flow.
12 
1311## Create the credential in Salesforce
1412 
1513Create a connected app (or External Client App) with the client credentials flow enabled, and set a dedicated integration user as the app's run-as user. Salesforce's guide is [Configure a Connected App for the OAuth 2.0 Client Credentials Flow](https://help.salesforce.com/s/articleView?id=xcloud.remoteaccess_oauth_client_credentials_flow.htm\&type=5).
from line 20
2220 
2321Assign the integration user a Permission Set scoped to the objects and fields Claude should reach. Read-only is the recommended starting point.
2422 
25## Add the connection to a bundle
23## Add the connector
2624 
27In the bundle, click **Connect** next to **Salesforce**.
25Go to [**Organization settings > Claude Tag > Connectors**](https://claude.ai/admin-settings/claude-tag?access=connectors), click **Add**, and select **Salesforce**. Fill in these fields in the connect form.
2826 
2927| Field | Value |
3028| :- | :- |
from line 29
3129| Client ID | The app's Consumer Key |
3230| Client secret | The app's Consumer Secret |
3331| Token URL | Your org's token endpoint, `https://yourcompany.my.salesforce.com/services/oauth2/token` |
34| Scopes (optional) | Leave empty unless your app requires specific scopes |
32| Scopes (optional) | On the **Advanced** tab. Leave empty unless your app requires specific scopes |
3533| Allowed websites | Your org's host, for example `yourcompany.my.salesforce.com` |
3634 
37The preset prefills Allowed websites with an example host that cannot resolve. Replace it with your org's host before saving, or every request fails. To change the host later, open the **⋮** menu on this connection in the bundle's Credentials tab and choose **Edit**.
35The first credential you add for a service from the **Connectors** tab is on in every workspace and channel as soon as you save it. To give it narrower reach, see [where a new connector applies](/docs/claude-tag/admins/add-connections#add-a-connection) before you save the connector. The **Allowed websites** field shows an example host that can't resolve. Enter your org's host there, then click **Connect** to save the connector.
3836 
37To change the host later, go to [**Organization settings > Claude Tag > Connectors**](https://claude.ai/admin-settings/claude-tag?access=connectors), click **Salesforce**, open the menu on the credential's row in the **Access from** table, and click **Edit**. In the **Edit connection** dialog, the **Allowed websites** setting is labeled **Allowed hosts**. Change the host there and click **Save**.
38 
3939The Agent Proxy injects the credential at the network boundary; the model and the sandbox are not given the key. See [how Agent Proxy works](/docs/claude-tag/concepts/agent-identity#agent-proxy).
4040 
4141## Verify the connection
4242 
43In a channel under the bundle's scope, in a new thread:
43In a channel where the connector is on, in a new thread:
4444 
4545```text wrap theme={null}
4646@Claude list the five most recently modified Opportunities in Salesforce.

claude-tag/admins/connections/sentry Changed · +10 / -10 lines

## Add the connector ## Add the connection to a bundle

from line 6
66 
77<BetaNote />
88 
9<Note>Connections are added inside an [Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle). At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open **Access bundles** in the left navigation, click into a bundle (or **Create** one), and go to its **Credentials** tab.</Note>
9Connecting Sentry lets Claude pull errors and stack traces into incident threads in any channel where the connector is on. Claude connects with its own credential, not a person's.
1010 
11Connecting Sentry lets Claude pull errors and stack traces into incident threads from any channel under the bundle's scope. You add it as a connection inside an [Access bundle](/docs/claude-tag/admins/add-connections); the credential belongs to the agent, not to any person.
11Pair this connector with the Sentry plugin from Anthropic's plugin marketplace so Claude knows how to call the API. This connector calls Sentry's HTTP API. It isn't an MCP server or a member's personal claude.ai connector.
1212 
13Pair this connection with the Sentry plugin from Anthropic's plugin marketplace so Claude knows how to call the API; see [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins). This is an HTTP API connection, not an MCP server or a personal claude.ai connector.
14 
1513## Create the credential in Sentry
1614 
1715Create an internal-integration token in Sentry (Settings → Developer Settings → Internal Integrations) rather than a user auth token; scope it to the projects Claude should read.
1816 
19The token starts with `sntrys_`. Prefer an internal-integration token over a user auth token so access is not tied to a person.
17Prefer an internal-integration token over a user auth token so access is not tied to a person.
2018 
2119Sentry's own guide for creating the credential is at [docs.sentry.io](https://docs.sentry.io/integrations/integration-platform/internal-integration/).
2220 
23## Add the connection to a bundle
21## Add the connector
2422 
25In the bundle, click **Connect** next to **Sentry**.
23Go to [**Organization settings > Claude Tag > Connectors**](https://claude.ai/admin-settings/claude-tag?access=connectors), click **Add**, and select **Sentry**. Fill in these fields in the connect form.
2624 
2725| Field | Value |
2826| :- | :- |
2927| Claude's auth token | The api key from Sentry |
30| Allowed websites | `sentry.io` |
28| Allowed websites | `sentry.io` (preset) |
3129 
3230Self-hosted Sentry uses your own hostname instead of `sentry.io`.
3331 
32If the connect form offers to include the Sentry plugin, leave that box selected; otherwise add the plugin on the [**Skills and plugins**](https://claude.ai/admin-settings/claude-tag?access=plugins) tab. The first credential you add for a service from the **Connectors** tab is on in every workspace and channel as soon as you save it. To give it narrower reach, see [where a new connector applies](/docs/claude-tag/admins/add-connections#add-a-connection) before you save the connector. Click **Connect** to save the connector.
33 
3434The Agent Proxy injects the credential at the network boundary; the model and the sandbox are not given the key. See [how Agent Proxy works](/docs/claude-tag/concepts/agent-identity#agent-proxy).
3535 
3636## Verify the connection
3737 
38In a channel under the bundle's scope, in a new thread:
38In a channel where the connector is on, in a new thread:
3939 
4040```text wrap theme={null}
4141@Claude what can you access from this channel?
4242```
4343 
44Sentry appears in the list once the connection is live. New threads pick up the connection on their own; in an existing thread, ask Claude to use the service by name.
44Sentry appears in the list once the connector is live. New threads pick up the connector on their own; in an existing thread, ask Claude to use the service by name.
4545 
4646## Related resources
4747 

claude-tag/admins/connections/snowflake Changed · +10 / -10 lines

## Add the connector ## Add the connection to a bundle

from line 6
66 
77<BetaNote />
88 
9<Note>Connections are added inside an [Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle). At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open **Access bundles** in the left navigation, click into a bundle (or **Create** one), and go to its **Credentials** tab.</Note>
9Connecting Snowflake lets Claude run queries against your warehouse in any channel where the connector is on. Claude connects with its own credential, not a person's.
1010 
11Connecting Snowflake lets Claude run queries against your warehouse from any channel under the bundle's scope. You add it as a connection inside an [Access bundle](/docs/claude-tag/admins/add-connections); the credential belongs to the agent, not to any person.
11This connector calls Snowflake's HTTP API, and it's separate from members' personal claude.ai connectors.
1212 
13This is an HTTP API connection, not a personal claude.ai connector.
14 
1513## Create the credential in Snowflake
1614 
1715Create a dedicated Snowflake user for the agent with a read-only role scoped to the databases and schemas Claude should query. In Snowsight (Snowflake's web interface), under **Governance & security** and then **Users & roles**, generate a programmatic access token for that user. Tokens expire after 15 days by default, so plan to rotate the credential.
1816 
19Snowflake's guide for programmatic access tokens is at [docs.snowflake.com](https://docs.snowflake.com/en/user-guide/programmatic-access-tokens). The connection authenticates with this token; key-pair authentication is not currently supported.
17Snowflake's guide for programmatic access tokens is at [docs.snowflake.com](https://docs.snowflake.com/en/user-guide/programmatic-access-tokens). The connector authenticates with this token; key-pair authentication isn't supported.
2018 
21## Add the connection to a bundle
19## Add the connector
2220 
23In the bundle, click **Connect** next to **Snowflake**.
21Go to [**Organization settings > Claude Tag > Connectors**](https://claude.ai/admin-settings/claude-tag?access=connectors), click **Add**, and select **Snowflake**. Fill in these fields in the connect form.
2422 
2523| Field | Value |
2624| :- | :- |
from line 25
2725| Claude's programmatic access token | The programmatic access token from Snowflake |
2826| Allowed websites | Your account's host, for example `yourorg-youraccount.snowflakecomputing.com` |
2927 
30The preset prefills Allowed websites with an example host that cannot resolve. Replace it with your account's host before saving, or every request fails. To change the host later, open the **⋮** menu on this connection in the bundle's Credentials tab and choose **Edit**.
28The first credential you add for a service from the **Connectors** tab is on in every workspace and channel as soon as you save it. To give it narrower reach, see [where a new connector applies](/docs/claude-tag/admins/add-connections#add-a-connection) before you save the connector. The **Allowed websites** field shows `*.snowflakecomputing.com` only as a hint, and a wildcard under `snowflakecomputing.com` can't be saved. Enter your account's host there, then click **Connect** to save the connector.
3129 
30To change the host later, go to [**Organization settings > Claude Tag > Connectors**](https://claude.ai/admin-settings/claude-tag?access=connectors), click **Snowflake**, open the menu on the credential's row in the **Access from** table, and click **Edit**. In the **Edit connection** dialog, the **Allowed websites** setting is labeled **Allowed hosts**. Change the host there and click **Save**.
31 
3232The Agent Proxy injects the credential at the network boundary; the model and the sandbox are not given the key. See [how Agent Proxy works](/docs/claude-tag/concepts/agent-identity#agent-proxy).
3333 
3434## Verify the connection
3535 
36In a channel under the bundle's scope, in a new thread:
36In a channel where the connector is on, in a new thread:
3737 
3838```text wrap theme={null}
3939@Claude what can you access from this channel?
4040```
4141 
42Snowflake appears in the list once the connection is live. New threads pick up the connection on their own; in an existing thread, ask Claude to use the service by name.
42Snowflake appears in the list once the connector is live. New threads pick up the connector on their own; in an existing thread, ask Claude to use the service by name.
4343 
4444## Related resources
4545 

claude-tag/admins/connections/stripe Changed · +9 / -9 lines

## Add the connector ## Add the connection to a bundle

from line 6
66 
77<BetaNote />
88 
9<Note>Connections are added inside an [Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle). At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open **Access bundles** in the left navigation, click into a bundle (or **Create** one), and go to its **Credentials** tab.</Note>
9Connecting Stripe lets Claude answer billing and subscription questions in any channel where the connector is on. Claude connects with its own credential, not a person's.
1010 
11Connecting Stripe lets Claude answer billing and subscription questions from any channel under the bundle's scope. You add it as a connection inside an [Access bundle](/docs/claude-tag/admins/add-connections); the credential belongs to the agent, not to any person.
11Pair this connector with the Stripe plugin from Anthropic's plugin marketplace so Claude knows how to call the API. Add the plugin on the [**Skills and plugins**](https://claude.ai/admin-settings/claude-tag?access=plugins) tab. This connector calls Stripe's HTTP API. It isn't an MCP server or a member's personal claude.ai connector.
1212 
13Pair this connection with the Stripe plugin from Anthropic's plugin marketplace so Claude knows how to call the API; see [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins). This is an HTTP API connection, not an MCP server or a personal claude.ai connector.
14 
1513## Create the credential in Stripe
1614 
1715Use a restricted key with read-only resource permissions, not your account's full secret key. Consider connecting test mode first.
from line 16
1816 
1917Stripe's own guide for creating the credential is at [docs.stripe.com](https://docs.stripe.com/keys).
2018 
21## Add the connection to a bundle
19## Add the connector
2220 
23In the bundle, click **Connect** next to **Stripe**.
21Go to [**Organization settings > Claude Tag > Connectors**](https://claude.ai/admin-settings/claude-tag?access=connectors), click **Add**, and select **Stripe**. Fill in these fields in the connect form.
2422 
2523| Field | Value |
2624| :- | :- |
2725| Claude's secret key | The secret key from Stripe |
28| Allowed websites | `api.stripe.com` (preset). To add a different host, use the **Advanced** tab. |
26| Allowed websites | `api.stripe.com` (preset) |
2927 
3028The field labeled Claude's secret key accepts a restricted key; the label is the field name, not a key-type constraint.
3129 
30The first credential you add for a service from the **Connectors** tab is on in every workspace and channel as soon as you save it. To give it narrower reach, see [where a new connector applies](/docs/claude-tag/admins/add-connections#add-a-connection) before you save the connector. Click **Connect** to save the connector.
31 
3232The Agent Proxy injects the credential at the network boundary; the model and the sandbox are not given the key. See [how Agent Proxy works](/docs/claude-tag/concepts/agent-identity#agent-proxy).
3333 
3434## Verify the connection
3535 
36In a channel under the bundle's scope, in a new thread:
36In a channel where the connector is on, in a new thread:
3737 
3838```text wrap theme={null}
3939@Claude what can you access from this channel?
4040```
4141 
42Stripe appears in the list once the connection is live. New threads pick up the connection on their own; in an existing thread, ask Claude to use the service by name.
42Stripe appears in the list once the connector is live. New threads pick up the connector on their own; in an existing thread, ask Claude to use the service by name.
4343 
4444## Related resources
4545 

claude-tag/admins/connections/vercel Changed · +9 / -9 lines

## Add the connector ## Add the connection to a bundle

from line 6
66 
77<BetaNote />
88 
9<Note>Connections are added inside an [Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle). At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open **Access bundles** in the left navigation, click into a bundle (or **Create** one), and go to its **Credentials** tab.</Note>
9Connecting Vercel lets Claude check deployment status and logs in any channel where the connector is on. Claude connects with its own credential, not a person's.
1010 
11Connecting Vercel lets Claude check deployment status and logs from any channel under the bundle's scope. You add it as a connection inside an [Access bundle](/docs/claude-tag/admins/add-connections); the credential belongs to the agent, not to any person.
11Pair this connector with the Vercel plugin from Anthropic's plugin marketplace so Claude knows how to call the API. Add the plugin on the [**Skills and plugins**](https://claude.ai/admin-settings/claude-tag?access=plugins) tab. This connector calls Vercel's HTTP API. It isn't an MCP server or a member's personal claude.ai connector.
1212 
13Pair this connection with the Vercel plugin from Anthropic's plugin marketplace so Claude knows how to call the API; see [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins). This is an HTTP API connection, not an MCP server or a personal claude.ai connector.
14 
1513## Create the credential in Vercel
1614 
1715Create the token from a dedicated team member seat, scoped to the team rather than your personal account.
from line 16
1816 
1917Vercel's own guide for creating the credential is at [vercel.com](https://vercel.com/kb/guide/how-do-i-use-a-vercel-api-access-token).
2018 
21## Add the connection to a bundle
19## Add the connector
2220 
23In the bundle, click **Connect** next to **Vercel**.
21Go to [**Organization settings > Claude Tag > Connectors**](https://claude.ai/admin-settings/claude-tag?access=connectors), click **Add**, and select **Vercel**. Fill in these fields in the connect form.
2422 
2523| Field | Value |
2624| :- | :- |
2725| Claude's access token | The access token from Vercel |
28| Allowed websites | `api.vercel.com` |
26| Allowed websites | `api.vercel.com` (preset) |
2927 
28The first credential you add for a service from the **Connectors** tab is on in every workspace and channel as soon as you save it. To give it narrower reach, see [where a new connector applies](/docs/claude-tag/admins/add-connections#add-a-connection) before you save the connector. Click **Connect** to save the connector.
29 
3030The Agent Proxy injects the credential at the network boundary; the model and the sandbox are not given the key. See [how Agent Proxy works](/docs/claude-tag/concepts/agent-identity#agent-proxy).
3131 
3232## Verify the connection
3333 
34In a channel under the bundle's scope, in a new thread:
34In a channel where the connector is on, in a new thread:
3535 
3636```text wrap theme={null}
3737@Claude what can you access from this channel?
3838```
3939 
40Vercel appears in the list once the connection is live. New threads pick up the connection on their own; in an existing thread, ask Claude to use the service by name.
40Vercel appears in the list once the connector is live. New threads pick up the connector on their own; in an existing thread, ask Claude to use the service by name.
4141 
4242## Related resources
4343 

claude-tag/admins/customize Changed · +28 / -24 lines

### Claude Tag connectors are separate from personal connectors ### Channel connections are separate from personal connectors

from line 10
1010 
1111| Layer | What it is | Who sets it | Where |
1212| :- | :- | :- | :- |
13| **Connections** | Credentials for the systems Claude can reach (GitHub, Drive, Datadog, your APIs) | Owner or [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration); a [channel manager](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) for their assigned channels | [Access bundles](/docs/claude-tag/admins/add-connections), or the channel's Configure page for a channel manager |
14| **Plugins and skills** | Instructions that teach Claude how to use a tool or follow a process. A plugin bundles one or more [skills](https://code.claude.com/docs/en/skills). | Owner or [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration); channel members can add plugins to their channel unless an admin restricts editing | [Bundle Plugins tab](/docs/claude-tag/admins/add-connections#attach-plugins), a [skills repository](/docs/claude-tag/admins/skills-repo), or the channel's Configure page |
13| **Connectors** | The systems Claude can reach and the credentials it uses for each (GitHub, Drive, Datadog, your APIs) | Owner or [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration); a [channel manager](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) for their assigned channels | The **Connectors** tab and [bundles](/docs/claude-tag/admins/add-connections) under **Claude's access**, or the channel's Configure page for a channel manager |
14| **Plugins and skills** | Instructions that teach Claude how to use a tool or follow a process. A plugin bundles one or more [skills](https://code.claude.com/docs/en/skills). | Owner or [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration); channel members can add plugins to their channel unless an admin restricts editing | The **Skills and plugins** tab under **Claude's access**, a [bundle](/docs/claude-tag/admins/add-connections#attach-plugins), a [skills repository](/docs/claude-tag/admins/skills-repo), or the channel's Configure page |
1515| **Custom instructions** | Standing guidance read in every session at a scope (team conventions, output formats). Outranks channel memory. | Owner for any scope; [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) for workspace and channel scopes; channel members for the channel scope, from the [Configure page](/docs/claude-tag/users/good-habits#configure-claude-for-a-channel) | [Per-scope instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions) |
1616| **Channel memory** | Facts Claude saves while working in a channel | Anyone in the channel | By [telling Claude](/docs/claude-tag/users/memory) |
1717 
18Connections and plugins decide what Claude *can do*; instructions and memory shape *how it does it*.
18Connectors and plugins decide what Claude *can do*; instructions and memory shape *how it does it*.
1919 
2020## Settings admins control
2121 
22Access and organization-wide behavior are set at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), per scope (a scope is a channel, a workspace, or your whole organization), so the same agent can work differently in different channels. Most controls below need the Owner role or, on the Enterprise plan, the [**Claude Tag Admin** permission](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration).
22Access and organization-wide behavior are set at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), per scope (a scope is a channel, a workspace, or your whole organization), so the same agent can work differently in different channels. Each scope has its own page on the **Channels** tab under **Claude's access**, and the **Slack** page there covers your whole organization. Most controls below need the Owner role or, on the Enterprise plan, the [**Claude Tag Admin** permission](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration); the [permissions table](/docs/claude-tag/admins/restrict-access#permissions-by-role) lists each action and who can take it.
2323 
2424| Setting | What it does | More |
2525| :- | :- | :- |
from line 27
2727| Managed by | Which other Slack channels' members can write a channel's standing instructions by asking Claude, including from a private channel. On the Enterprise plan, an Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) sets it on the **Admin** tab of the channel's Configure page. | [Manage a channel's instructions from another channel](/docs/claude-tag/admins/managed-by) |
2828| Respond automatically | Whether Claude replies to a channel's messages without an @-mention. **Respond automatically** exists only on channels, not on workspaces or your whole organization. Channel members can change it too, from Slack or the channel's Configure page, unless the scope's [**Channel member edits**](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) setting is **Block**. | [Turn automatic replies on or off](/docs/claude-tag/users/when-claude-responds#turn-automatic-replies-on-or-off) |
2929| Plugins | Bundles of skills that teach Claude how to use a specific tool | [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins) |
30| Connections | Which systems it can reach from each channel | [Add connections](/docs/claude-tag/admins/add-connections) |
31| Default model | Which Claude model handles sessions in a scope | [Choose the model for a scope](#choose-the-model-for-a-scope) |
30| Connectors | Which systems Claude can reach from each channel | [Add a connector](/docs/claude-tag/admins/add-connections) |
31| Model | Which Claude model handles sessions in a scope | [Choose the model for a scope](#choose-the-model-for-a-scope) |
3232| Auto mode allow rules | Actions pre-approved in a scope's sessions that Claude's permission checker would otherwise flag or stop | [Auto mode allow rules](#auto-mode-allow-rules) |
3333| Environment | Which cloud environment a scope's sessions run in | [Configure the environment for a scope](#configure-the-environment-for-a-scope) |
34| Enable Claude Tag | Turns Claude on or off in a scope | [Turn Claude Tag on or off and set the version for a scope](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) |
34| Enable Claude Tag | Turns Claude on or off in a scope. On the **Slack** page, the switch is labeled **Respond in all channels** or **Respond in channels** | [Turn Claude Tag on or off and set the version for a scope](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) |
3535| Claude Tag version | Which generation answers in a scope (**New** or **Legacy**) | [Turn Claude Tag on or off and set the version for a scope](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) |
3636 
37### Channel connections are separate from personal connectors
37<a id="channel-connections-are-separate-from-personal-connectors" />
3838 
39An Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) configures Claude's connections, plugins, and skills, and they apply per scope. They are separate from the connectors, skills, or MCP servers an individual user has set up in their own claude.ai or Claude Desktop account. A user's personal connectors are not part of a channel's configuration, and the channel's connections are not listed among that user's personal connectors in claude.ai. Claude can [use a user's personal connectors in a channel](/docs/claude-tag/concepts/personal-connectors) for that user's own tasks, after the user allows it. That work runs with the user's permissions and is recorded under their name. Projects in claude.ai are separate too. Claude doesn't read a Project's instructions or knowledge in Slack, and a channel can't be pointed at a Project. Put standing guidance for a channel in its [custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions).
39### Claude Tag connectors are separate from personal connectors
4040 
41To give Claude access to a tool that is not in the built-in connection list, including a custom MCP server, see [add a custom connection](/docs/claude-tag/admins/connections/custom).
41An Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) configures Claude Tag connectors, plugins, and skills, and they apply per scope. They are separate from the personal connectors, skills, or MCP servers an individual user has set up in their own claude.ai or Claude Desktop account. A user's personal connectors are not part of a channel's configuration, and the channel's connectors are not listed among that user's personal connectors in claude.ai. Claude can [use a user's personal connectors in a channel](/docs/claude-tag/concepts/personal-connectors) for that user's own tasks, after the user allows it. That work runs with the user's permissions and is recorded under their name. Projects in claude.ai are separate too. Claude doesn't read a Project's instructions or knowledge in Slack, and a channel can't be pointed at a Project. Put standing guidance for a channel in its [custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions).
4242 
43To give Claude access to a tool that isn't in the **Add a connector** list, including a custom MCP server, see [Connect a service that isn't in the list](/docs/claude-tag/admins/connections/custom).
44 
4345## Change behavior from the channel
4446 
4547Everything in the table below is open to channel members, with no admin involved.
from line 64
6264 
6365## Choose the model for a scope
6466 
65Each scope carries a **Default model** setting in its **Advanced** section, alongside the [environment](/docs/claude-tag/concepts/glossary#environment) and guest controls. It sets the model new channel sessions in that scope start on. The options are the models your organization allows, such as Opus and Sonnet models, regardless of any individual member's own model access. The picker also lists model families. A scope set to a family option starts sessions on the newest model of that family your organization allows, and moves to a newer one when your organization gets it, without you changing the setting. A scope without its own setting inherits from its parent, and a channel's setting overrides its workspace's. The **Inherit** option shows which model the scope resolves to.
67The **Model** setting sets the model new channel sessions in a scope start on. For your whole organization, it's the **Model** row on the main [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) page. For a workspace or channel, it's on the **General** tab of that scope's page on the **Channels** tab under **Claude's access**. The options are the models your organization allows, such as Opus and Sonnet models, regardless of any individual member's own model access. The picker also lists model families. A scope set to a family option starts sessions on the newest model of that family your organization allows, and moves to a newer one when your organization gets it, without you changing the setting.
6668 
67To keep sessions on a model you chose, set a specific model at the organization scope rather than leaving the setting unset; every scope without an override then follows it.
69A workspace or channel without its own setting shows **Inherit** and takes the model from its parent, and a channel's setting overrides its workspace's. The line under the setting names the model the scope uses and which scope it comes from.
6870 
71To keep sessions on a model you chose, set a specific model in the organization's **Model** row rather than leaving it unset; every scope without an override then follows it.
72 
6973When you change the setting, new sessions start on the new model. A thread already underway switches to it at the next message anyone posts there, unless someone in that thread has already had Claude switch models. The footer of each Claude reply in Slack names the model that handled it, so you can confirm what a scope is running.
7074 
7175Channel members can also change the model from Slack. Asking Claude in a thread switches that thread, and asking it to make a model the channel default changes this setting for the channel, unless the scope's [Channel member edits](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) setting is **Block**. See [choose the model Claude Tag uses](/docs/claude-tag/users/models).
from line 78
7478 
7579On the Team plan, Claude Tag doesn't apply the [`availableModels` allowlist](https://code.claude.com/docs/en/model-config#restrict-model-selection) from your Claude Code [server-managed settings](https://code.claude.com/docs/en/server-managed-settings), and on the Enterprise plan it applies the allowlist in only some organizations.
7680 
77* **Where the allowlist doesn't apply**: Claude offers your organization's full Claude Tag model list, both when someone asks it to switch and in the model selector for direct messages. It starts sessions on a scope's **Default model** without checking that model against the allowlist. The **Default model** picker in admin settings still lists only allowed models.
81* **Where the allowlist doesn't apply**: Claude offers your organization's full Claude Tag model list, both when someone asks it to switch and in the model selector for direct messages. It starts sessions on a scope's **Model** setting without checking that model against the allowlist. The **Model** picker in admin settings still lists only allowed models.
7882* **Where the allowlist applies**: sessions in a channel run as the [agent identity](/docs/claude-tag/concepts/agent-identity) you provisioned and without your server-managed settings. When someone in a channel asks Claude to switch models, Claude may decline a model outside the allowlist, though that check doesn't always run. In one-to-one direct messages from a member whose linked Claude account belongs to your organization, Claude runs on that member's own account, which receives your allowlist; see [Restrict model selection](https://code.claude.com/docs/en/model-config#restrict-model-selection) for what happens to a model the allowlist blocks.
7983 
8084In either case, Claude Tag offers only the models it supports, so a model your allowlist includes can be absent in Slack.
8185 
82On the Enterprise plan, turning a model off for the whole organization on your **Models** page removes it from the lists in Slack, and Claude declines requests to switch to it. If you turn off the model a scope's **Default model** is set to, Claude still starts sessions there on a fallback model that's still on, and declines only when every fallback is off too. The footer of the first reply names the model that served it.
86On the Enterprise plan, turning a model off for the whole organization on your **Models** page removes it from the lists in Slack, and Claude declines requests to switch to it. If you turn off the model a scope's **Model** setting names, Claude still starts sessions there on a fallback model that's still on, and declines only when every fallback is off too. The footer of the first reply names the model that served it.
8387 
8488### Allow fast mode
8589 
from line 101
97101 
98102## Configure the environment for a scope
99103 
100Claude runs every channel session in a sandbox that starts with a standard set of tools. When a channel's work needs something that sandbox doesn't have, such as a language runtime, a database client, a set of environment variables, or broader web access, give the channel an environment. An environment is an [organization-shared cloud environment](https://code.claude.com/docs/en/cloud-environments#organization-shared-environments): you create it once, then choose it on a scope, meaning a channel, a workspace, or **Default Slack access**. Both steps take an Owner; a [channel manager](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) can't change a channel's environment.
104Claude runs every channel session in a sandbox that starts with a standard set of tools. When a channel's work needs something that sandbox doesn't have, such as a language runtime, a database client, a set of environment variables, or broader web access, give the channel an environment. An environment is an [organization-shared cloud environment](https://code.claude.com/docs/en/cloud-environments#organization-shared-environments): you create it once, then choose it on a scope, meaning a channel, a workspace, or the **Slack** page for your whole organization. Both steps take an Owner; a [channel manager](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) can't change a channel's environment.
101105 
102106### Decide what goes in the environment
103107 
from line 112
108112| A tool installed before Claude starts, such as a runtime or a database client | The environment's setup script, a Bash script whose installs are on disk before Claude starts work |
109113| A value every session should see, such as a deployment target or a feature flag | The environment's environment variables, as `KEY=value` pairs, one per line |
110114| Web access without a credential | The environment's network access level; see [broad web access through the environment](/docs/claude-tag/admins/add-connections#broad-web-access-through-the-environment) |
111| An API key, token, or other credential | A [connection](/docs/claude-tag/admins/add-connections), never an environment variable |
115| An API key, token, or other credential | A [connector](/docs/claude-tag/admins/add-connections), never an environment variable |
112116| Setup for one repository, such as installing its dependencies | That repository's `CLAUDE.md`; see [install project dependencies](/docs/claude-tag/admins/configure-github#install-project-dependencies) |
113117 
114Keep credentials out of environment variables because every session on the environment reads them and Claude can print them. There is no separate secrets store. A connection stores the credential outside the sandbox and attaches it to matching requests at the network layer, so Claude uses the service without holding the raw value. [Agent Proxy](/docs/claude-tag/concepts/agent-identity#agent-proxy) describes how. A connection also travels with the access bundle, so you choose channel by channel which sessions can use it. Repository-specific setup goes in `CLAUDE.md` so the people who maintain the repository keep it current. Claude reads it when it starts work in that repository.
118Keep credentials out of environment variables because every session on the environment reads them and Claude can print them. There is no separate secrets store. A connector stores the credential outside the sandbox and attaches it to matching requests at the network layer, so Claude uses the service without holding the raw value. [Agent Proxy](/docs/claude-tag/concepts/agent-identity#agent-proxy) describes how. A connector in a bundle also travels with that bundle, so you choose channel by channel which sessions can use it. Repository-specific setup goes in `CLAUDE.md` so the people who maintain the repository keep it current. Claude reads it when it starts work in that repository.
115119 
116120### Create the environment and choose it on a scope
117121 
118Creating the environment and choosing it on a scope happen on two different admin pages. Choose it on a channel to change only that channel's sessions, on a workspace to cover every channel in the workspace where you haven't chosen one, or on **Default Slack access** to cover every workspace.
122Creating the environment and choosing it on a scope happen on two different admin pages. Choose it on a channel to change only that channel's sessions, on a workspace to cover every channel in the workspace where you haven't chosen one, or on the **Slack** page to cover every workspace.
119123 
120124<Steps>
121125 <Step title="Create the environment">
from line 127
123127 </Step>
124128 
125129 <Step title="Set the scope's environment">
126 The picker is at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) > **Claude Tag's access** > **Slack** > the scope (**Default Slack** is the organization-wide scope) > **Advanced** > **Environment**. Pick the environment there.
130 Go to [**Claude's access > Channels**](https://claude.ai/admin-settings/claude-tag?access=channels) and open the scope's page (**Slack** for the whole organization). On its **Advanced** tab, pick the environment in **Environment** under **Sessions**.
127131 </Step>
128132 
129133 <Step title="Confirm the environment in a new thread">
from line 141
137141 
1381421. The channel's **Environment** setting
1391432. The workspace's **Environment** setting
1403. The **Environment** setting on **Default Slack access**
1443. The **Environment** setting on the **Slack** page
1411454. The [organization's default environment](https://code.claude.com/docs/en/cloud-environments#the-default-environment), which an Owner chooses under **Cloud sessions** at [`claude.ai/admin-settings/claude-code`](https://claude.ai/admin-settings/claude-code)
142146 
143If you haven't chosen an environment on a scope, its picker shows **Organization default**, but sessions there may still run on an environment you chose on the workspace or on **Default Slack access**. In a channel where Claude runs with [channel-only access](/docs/claude-tag/admins/restrict-access#how-channel-only-works) because a guest is present, sessions run on the standard environment regardless of these settings. If a channel's sessions aren't on the environment you expect, see [channel sessions use the wrong environment](/docs/claude-tag/admins/troubleshooting#channel-sessions-use-the-wrong-environment-or-can%E2%80%99t-find-one).
147If you haven't chosen an environment on a scope, its picker shows **Organization default**, but sessions there may still run on an environment you chose on the workspace or on the **Slack** page. In a channel where Claude runs with [channel-only access](/docs/claude-tag/admins/restrict-access#how-channel-only-works) because a guest is present, sessions run on the standard environment regardless of these settings. If a channel's sessions aren't on the environment you expect, see [channel sessions use the wrong environment](/docs/claude-tag/admins/troubleshooting#channel-sessions-use-the-wrong-environment-or-can%E2%80%99t-find-one).
144148 
145149## Auto mode allow rules
146150 
from line 152
148152 
149153A rule is a plain sentence that describes work you approve in the scope, such as "Deploying to our staging cluster from a session in this channel is a normal, approved workflow." To add one:
150154 
1511. On [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open the **Slack** tab under **Claude Tag's access** and find the scope you want to change (the organization-wide **Default Slack** row, a workspace, or a channel). The **Default Slack** row opens as **Default Slack access**.
1522. Open the scope's **Advanced** section and find **Auto mode allow rules**, below the [**Default model**](#choose-the-model-for-a-scope) setting.
1551. Go to [**Claude's access > Channels**](https://claude.ai/admin-settings/claude-tag?access=channels) and open the page of the scope you want to change: **Slack** for the whole organization, a workspace, or a channel.
1562. Open the page's **Advanced** tab and find **Auto mode allow rules** under **Sessions**.
1531573. Select **Add rule** and write the rule as one plain sentence.
154158 
155159The rules list has three properties:
156160 
157161* **Limits:** a scope holds up to 50 rules, and each rule can be up to 1,024 characters
158* **Inheritance:** rules you set on a workspace or on [Default Slack access](/docs/claude-tag/admins/attach-to-scope#how-scopes-inherit) (the organization-wide root) carry down to the channels beneath, the way [custom instructions](/docs/claude-tag/admins/attach-to-scope#custom-instructions) stack. A channel's own rules add to those and never replace them, so put a rule on a single channel's scope to pre-approve an action there without changing any other channel.
162* **Inheritance:** rules you set on a workspace or on the [**Slack** page](/docs/claude-tag/admins/attach-to-scope#how-scopes-inherit) (the organization-wide root) carry down to the channels beneath, the way [custom instructions](/docs/claude-tag/admins/attach-to-scope#custom-instructions) stack. A channel's own rules add to those and never replace them, so put a rule on a single channel's scope to pre-approve an action there without changing any other channel.
159163* **Access:** you edit the list with the same admin access as the scope's other **Advanced** settings
160164 
161165<Warning>Once you add an allow rule, Claude runs the actions it names in every channel the scope covers without anyone approving them in the moment. Keep each rule narrow: name the tool, the action, and the environment it allows, and put rules that unlock sensitive systems on the narrowest scope that needs them.</Warning>
Feedback