Skip to main content
Employees sign in to Claude Desktop through Forge and use the models their administrator allows. Requests go through the LLM Gateway, where Forge applies policies and records usage against each person’s identity.

Before you start

  • Use Claude Desktop with third-party inference support. Interactive sign-in requires version 1.6889.0 or later.
  • Confirm that employees can sign in to the intended Forge organization through its enterprise sign-in setup.
  • Connect an upstream model provider in Gateway. For Claude, the assigned profile needs an active route that serves the Anthropic Messages API.
  • Confirm that the intended users have active organization membership and linked directory identities. Directory groups provide department assignments.
Collect users and groups through your configured directory source, such as Entra or Okta. Directory collection does not configure enterprise SSO by itself. Check the authentication requirements before distributing the client setup. This setup uses Forge’s existing sign-in. You don’t need to create a second Okta or Entra app for Claude, install the Forge device agent, or enable network traffic routing.

1. Assign access and budgets

In Gateway, create or select an active access profile containing the providers and models employees should use. Check the route’s upstream model and enforcement settings before assigning it. Open Connect an app, then Manage access. Set a default profile for your employees or add overrides for specific people and groups. Set the usage period and spend or token limits for those assignments. For a department budget, use the department’s directory group. If a person belongs to several groups with access assignments, resolve the overlap or add an explicit person assignment. Ambiguous group assignments block access instead of selecting an arbitrary profile. Membership alone doesn’t grant inference access. The user’s effective assignment must resolve to an active profile. A valid sign-in token can’t bypass model permissions or budget limits.

2. Get the setup file

In Gateway, select Connect an app → Claude Desktop. Choose your operating system and select Download setup file. The file contains public connection settings; each person signs in separately. See the Claude Desktop configuration reference for the managed setting names and platform requirements. The Linux file and its parent directory must be owned by root, must not be symlinks, and must not be writable by the group or other users. If you already manage Claude settings, add the generated connection values to your existing configuration. Managed settings take precedence over local settings. Test the combined configuration on one device before distributing it.

Set up one device manually

Open Connection details and manual setup in Forge. In Claude Desktop, enable Developer Mode under Help → Troubleshooting, then open Developer → Configure Third-Party Inference. Choose Gateway and Interactive sign-in, enter the values shown in Forge, and apply the configuration. Use the Access token choice and redirect port shown in Forge.

3. Sign in

Quit and reopen Claude Desktop. Choose Sign in to your organization and use your Forge account. Select the intended organization if prompted. When your sign-in expires, Claude may ask you to sign in again. If you cannot sign in, confirm your organization access with your Forge administrator.

4. Check a first conversation

Select an available Claude model and send a short message. In Forge, open Gateway → Usage and confirm the request’s user, model, tokens and cost. Open its session to inspect the conversation and policy decisions. Use models with known rates when testing spend limits. If Forge reports unknown cost, resolve the model’s pricing before relying on dollar budgets for it.

Connect Forge tools

To use Forge’s inventory, investigation, policy, and other authorized tools in Claude, open Settings → Connectors → Add custom connector. In Forge’s Connect an app → Claude Desktop dialog, expand Connect Forge tools and copy the connector URL. Complete the separate Forge sign-in when Claude prompts you. The connector uses your MCP permissions; the model connection above uses your inference access assignment. Remote connectors are reached by Anthropic’s cloud service, including when you use Claude Desktop. Your Forge MCP endpoint must be publicly reachable by that service. After connecting, ask Claude to list an allowed Forge capability and confirm its invocation appears in Forge’s MCP activity. For an approved upstream MCP server, use that server’s endpoint from Registry instead of the global Forge tools URL. See MCP client setup for both endpoint types. Test one policy with a non-sensitive example before enabling it for everyone. Check a limited test assignment’s budget too: once its configured limit blocks a request, Claude should receive an error and Forge should record the denial. Restore the intended limit after testing.

Verify model discovery separately

Enable Model discovery, then select Test model discovery in Claude’s inference configuration. Forge exposes GET /llm-gateway/v1/models; the base URL shown in Forge already ends in /llm-gateway. Do not append another /v1 if the client adds it. An explicit Model list in Claude overrides discovery; remove an old one-model override when you want the gateway’s permitted list. A model name appearing in the picker does not establish provider access. Send one short request for each model you intend to distribute and check its Forge ledger. The route must support Messages, streaming, and tool use for Claude; an OpenAI Chat Completions-only route is insufficient. Bedrock is an upstream provider choice, not a separate Claude Desktop identity or network surface. Anthropic documents these client requirements and discovery behavior in its LLM gateway guide. Use Forge’s access-token settings even when a vendor example defaults to an ID token: the gateway’s authentication contract determines which token is valid.

Troubleshooting

For other applications and gateway-key setup, see Connect apps to Forge.