# Connect Claude.ai and Claude Desktop to a gateway

Add an MCP gateway as a custom connector in Claude.ai or Claude Desktop with a sign-in through your identity provider.

Claude.ai and Claude Desktop reach an [MCP gateway](https://zato.io/docs/ai/mcp/index.html) through a custom connector, added once in the settings and shared between the web and the desktop application, after which the gateway's tools are available in every chat. A custom connector has no field for a header, so the gateway it connects to has [OAuth](https://zato.io/docs/ai/mcp/oauth.html) on.

## The connector form {#the-connector-form}

1. Open **Settings** > **Connectors** and choose **Add custom connector**.
2. Enter a name, e.g. `Billing`, and the gateway's URL as the **Remote MCP server URL**, e.g. `https://api.example.com/mcp/billing`.
3. Open **Advanced settings** and enter the **OAuth Client ID** that the person managing your identity provider registered for Claude. The **OAuth Client Secret** stays empty - the registration is a public client.
4. Save the connector.

Without a client ID, Claude tries to register itself with the provider, which works with Keycloak when dynamic registration is on and never with Entra ID.

In a Claude for Work organization, an owner adds the connector for the whole organization under **Admin settings** > **Connectors**, with the same fields, and each person then signs in to it on their own.

## What the identity provider needs {#what-the-identity-provider-needs}

The registration for Claude is a public client with one redirect URI:

- `https://claude.ai/api/mcp/auth_callback`

Claude asks for a token without naming the gateway, so the audience of the token is whatever the provider issues for the client and the scopes - with Entra ID, that means the API's scope has to be among the registration's permissions and in the gateway's Scopes field, as described on the [OAuth](https://zato.io/docs/ai/mcp/oauth.html#microsoft-entra-id) page.

## The sign-in {#the-sign-in}

1. The new connector appears in the list with a **Connect** button.
2. Clicking it opens your identity provider's sign-in page in a new browser tab, or in a window of the desktop application.
3. After the sign-in, the tab closes, the connector shows as connected and its tools appear in the tools menu of each chat, where they can be switched on and off per chat.

Claude keeps the token and refreshes it on its own until the provider's session ends. The connector's menu has **Disconnect**, which drops it.

## When access is refused {#when-access-is-refused}

A person whose token the gateway does not accept - outside the group the gateway's bearer definition lists, or signed in to the wrong tenant - sees the connector fail to connect, with a message that the server rejected the authentication, and **Connect** stays available. The reason is in the gateway's [audit log](https://zato.io/docs/ai/mcp/audit-log.html), in the **Reason** column of the `auth-failed` event, next to the person's name.

## See also {#see-also}

- [OAuth](https://zato.io/docs/ai/mcp/oauth.html) - How the sign-in works and how to set up Entra ID or Keycloak
- [Claude Code](https://zato.io/docs/ai/mcp/clients/claude-code.html) - The same gateway from the command line
- [Sharing with clients](https://zato.io/docs/ai/mcp/sharing-with-clients.html) - The export with the gateway's address and the other clients' snippets

## Learn more {#learn-more}

- [MCP tutorial](https://zato.io/tutorials/mcp/01.html) - Expose Python services as AI tools and connect Claude Code in minutes
- [AI Integrations overview](https://zato.io/docs/ai/) - Both directions of AI traffic in one platform, and where to start
- [MCP gateway reference](https://zato.io/docs/ai/mcp/) - Configuration, endpoint behavior and the governance controls
- [Tool schemas](https://zato.io/docs/ai/mcp/tool-schemas.html) - How a service's docstring and declared I/O become its tool definition
- [MCP gateway security](https://zato.io/docs/ai/mcp/security.html) - API keys, Basic Auth and bearer tokens for AI agents
- [MCP response controls](https://zato.io/docs/ai/mcp/response-controls.html) - PII removal, prompt-injection safeguards and token-denominated size caps
- [MCP audit log](https://zato.io/docs/ai/mcp/audit-log.html) - What each agent did, when and with what outcome - payloads never recorded
- [MCP alerts](https://zato.io/docs/ai/mcp/alerts.html) - Failing backends, agents stuck in a loop and gateways with too many tools
- [Cost and limits](https://zato.io/docs/ai/cost-and-limits.html) - Every knob that caps AI cost and traffic, with worked examples
- [GitOps for AI integrations](https://zato.io/docs/ai/enmasse.html) - LLM connections and MCP gateways as YAML in version control
- [AI examples](https://zato.io/docs/ai/examples/) - Complete, runnable scenarios - one real-world need per file
