Give Claude access to your tools changedclaude-tag/admins/add-connections
Nearest release: v2.1.283, published 10 hours before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 26 Sep 2026 05:31 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 26 Sep 2026 05:37 UTC.
Upstream edited
Recorded here
Lines+15added
Lines−11removed
From line
165
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits18to this page, all time
The whole hunk
from line 165, old and new numbered
/
from line 165
165165
166166For a custom connection, choose the credential type:
167167
168| Credential type | Use for |
169| :------------------------------------------ | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
170| Bearer | API keys and OAuth bearer tokens. Most SaaS REST APIs. |
171| Basic | HTTP Basic authentication. |
172| Body parameter | A token the API expects in the request body or query string instead of a header. |
173| AWS SigV4 | Signed requests to AWS service endpoints with an access key pair. |
174| GCP access token (with Service Account Key) | Google Cloud APIs via a service-account JSON key. Google Workspace services like Drive and Calendar also use this; see [the Google guide](/docs/claude-tag/admins/connections/google). |
175| GCP IAP (with Service Account Key) | Google Cloud services behind Identity-Aware Proxy. |
176| OAuth 2.0 JWT bearer | Server-to-server OAuth. |
177| OAuth 2.0 client credentials | Server-to-server OAuth. Salesforce uses this. |
178| MCP Connector | Sign in once as an admin; the agent acts as that account. |
168| Credential type | Use for |
169| :------------------------------------------ | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
170| Bearer | API keys and OAuth bearer tokens. Most SaaS REST APIs. |
171| Basic | HTTP Basic authentication. |
172| Body parameter | A token the API expects in the request body or query string instead of a header. |
173| AWS SigV4 | Signed requests to AWS service endpoints with an access key pair. |
174| GCP access token (with Service Account Key) | Google Cloud APIs via a service-account JSON key. Google Workspace services like Drive and Calendar also use this; see [the Google guide](/docs/claude-tag/admins/connections/google). |
175| GCP IAP (with Service Account Key) | Google Cloud services behind Identity-Aware Proxy. |
176| OAuth 2.0 JWT bearer | Server-to-server OAuth. |
177| OAuth 2.0 client credentials | Server-to-server OAuth. Salesforce uses this. |
178| MCP Connector | Sign in once as an admin; the agent acts as that account. The picker offers a fixed set of providers plus the [remote MCP connectors](/docs/connectors/custom/add-unlisted) your organization has added on claude.ai. Other OAuth APIs can't be connected this way. |
179179
180180For GitHub repositories, use the GitHub connection at [Configure GitHub access](/docs/claude-tag/admins/configure-github) rather than a credential from this table.
181181
from line 193
193193
194194List the hosts a connection's credential may be sent to. A wildcard works only as the leftmost label, like `*.example.com`; it covers subdomains at any depth but not `example.com` itself. You can't enter `*` alone here; a credential is always limited to specific hosts. To let Claude reach any host without a credential, see [Allow all hosts](#allow-all-hosts).
195195
196<Note>You can't save a connection whose **Allowed websites** include an `anthropic.com`, `claude.ai`, or `claude.com` host, such as `api.anthropic.com`.</Note>
197
196198To change a connection's name or allowed websites after saving, open the **⋮** menu on that connection's row in the bundle's **Credentials** tab and choose **Edit**; the **Edit connection** dialog labels the field **Allowed hosts**. The same menu has **Rotate secret** (where the credential type supports it) and **Delete**.
197199
198200Check the host against your account's region before saving. Some presets fill a default host that may not match your account's region; a Datadog key, for example, only works against your account's Datadog site, like `api.datadoghq.com` or `api.datadoghq.eu`.
201
202Where the connection form has a **Test connection** button, the test can check the preset's default host rather than the one you entered, so a key for a regional or self-hosted instance can fail the test and still work. Replace the prefilled host with your service's API host rather than adding yours alongside it. You can save the connection even if the test fails, and the credential is sent only to the hosts you listed.
199203
200204### Restrict by path or method
201205
No line in this hunk matches that.