Connect Claude.ai and Claude Desktop to a gateway

Add an MCP gateway as a custom connector in Claude.ai or Claude Desktop with a sign-in through your identity provider.

Claude.ai and Claude Desktop reach an MCP gateway through a custom connector, added once in the settings and shared between the web and the desktop application, after which the gateway's tools are available in every chat. A custom connector has no field for a header, so the gateway it connects to has OAuth on.

The connector form

  1. Open Settings > Connectors and choose Add custom connector.
  2. Enter a name, e.g. Billing, and the gateway's URL as the Remote MCP server URL, e.g. https://api.example.com/mcp/billing.
  3. Open Advanced settings and enter the OAuth Client ID that the person managing your identity provider registered for Claude. The OAuth Client Secret stays empty - the registration is a public client.
  4. Save the connector.

Without a client ID, Claude tries to register itself with the provider, which works with Keycloak when dynamic registration is on and never with Entra ID.

In a Claude for Work organization, an owner adds the connector for the whole organization under Admin settings > Connectors, with the same fields, and each person then signs in to it on their own.

What the identity provider needs

The registration for Claude is a public client with one redirect URI:

  • https://claude.ai/api/mcp/auth_callback

Claude asks for a token without naming the gateway, so the audience of the token is whatever the provider issues for the client and the scopes - with Entra ID, that means the API's scope has to be among the registration's permissions and in the gateway's Scopes field, as described on the OAuth page.

The sign-in

  1. The new connector appears in the list with a Connect button.
  2. Clicking it opens your identity provider's sign-in page in a new browser tab, or in a window of the desktop application.
  3. After the sign-in, the tab closes, the connector shows as connected and its tools appear in the tools menu of each chat, where they can be switched on and off per chat.

Claude keeps the token and refreshes it on its own until the provider's session ends. The connector's menu has Disconnect, which drops it.

When access is refused

A person whose token the gateway does not accept - outside the group the gateway's bearer definition lists, or signed in to the wrong tenant - sees the connector fail to connect, with a message that the server rejected the authentication, and Connect stays available. The reason is in the gateway's audit log, in the Reason column of the auth-failed event, next to the person's name.

See also

FeatureWhat it does
OAuthHow the sign-in works and how to set up Entra ID or Keycloak
Claude CodeThe same gateway from the command line
Sharing with clientsThe export with the gateway's address and the other clients' snippets

Learn more