> ## Documentation Index
> Fetch the complete documentation index at: https://docs.forge.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Claude Desktop with Forge

> Connect Claude Desktop to Forge using your organization sign-in, model access, and budgets.

Employees sign in to Claude Desktop through Forge and use the models their
administrator allows. Requests go through the LLM Gateway, where Forge applies
policies and records usage against each person's identity.

## Before you start

* Use Claude Desktop with third-party inference support. Interactive sign-in
  requires version 1.6889.0 or later.
* Confirm that employees can sign in to the intended Forge organization through
  its enterprise sign-in setup.
* Connect an upstream model provider in Gateway. For Claude, the assigned
  profile needs an active route that serves the Anthropic Messages API.
* Confirm that the intended users have active organization membership and
  linked directory identities. Directory groups provide department assignments.

Collect users and groups through your configured directory source, such as
[Entra](/integrations/entra) or [Okta](/integrations/okta). Directory collection
does not configure enterprise SSO by itself. Check the
[authentication requirements](/secure/gateway-authentication) before distributing
the client setup.

This setup uses Forge's existing sign-in. You don't need to create a second
Okta or Entra app for Claude, install the Forge device agent, or enable network
traffic routing.

## 1. Assign access and budgets

In Gateway, create or select an active access profile containing the
providers and models employees should use. Check the route's upstream model
and enforcement settings before assigning it.

Open **Connect an app**, then **Manage access**. Set a default profile for your employees
or add overrides for specific people and groups. Set the usage period and
spend or token limits for those assignments. For a department budget, use the
department's directory group.

If a person belongs to several groups with access assignments, resolve the
overlap or add an explicit person assignment. Ambiguous group assignments
block access instead of selecting an arbitrary profile.

Membership alone doesn't grant inference access. The user's effective
assignment must resolve to an active profile. A valid sign-in token can't
bypass model permissions or budget limits.

## 2. Get the setup file

In **Gateway**, select **Connect an app → Claude Desktop**. Choose your
operating system and select **Download setup file**. The file contains public
connection settings; each person signs in separately.

| Operating system | File | Apply it with |
| - | - | - |
| macOS | `.mobileconfig` | Your device management tool |
| Windows | `.reg` | Your device management tool or registry policy |
| Linux | `.json` | `/etc/claude-desktop/managed-settings.json` |

See the [Claude Desktop configuration reference](https://claude.com/docs/third-party/claude-desktop/configuration)
for the managed setting names and platform requirements.

The Linux file and its parent directory must be owned by root, must not be
symlinks, and must not be writable by the group or other users.

If you already manage Claude settings, add the generated connection values to
your existing configuration. Managed settings take precedence over local
settings. Test the combined configuration on one device before distributing it.

### Set up one device manually

Open **Connection details and manual setup** in Forge. In Claude Desktop,
enable Developer Mode under **Help → Troubleshooting**, then open
**Developer → Configure Third-Party Inference**. Choose **Gateway** and
**Interactive sign-in**, enter the values shown in Forge, and apply the
configuration. Use the **Access token** choice and redirect port shown in Forge.

## 3. Sign in

Quit and reopen Claude Desktop. Choose **Sign in to your organization** and use
your Forge account. Select the intended organization if prompted.

When your sign-in expires, Claude may ask you to sign in again. If you cannot
sign in, confirm your organization access with your Forge administrator.

## 4. Check a first conversation

Select an available Claude model and send a short message. In Forge, open
Gateway → Usage and confirm the request's user, model, tokens
and cost. Open its session to inspect the conversation and policy decisions.

Use models with known rates when testing spend limits. If Forge reports unknown
cost, resolve the model's pricing before relying on dollar budgets for it.

## Connect Forge tools

To use Forge's inventory, investigation, policy, and other authorized tools in
Claude, open **Settings → Connectors → Add custom connector**. In Forge's
**Connect an app → Claude Desktop** dialog, expand **Connect Forge tools** and
copy the connector URL. Complete the separate Forge sign-in when Claude prompts
you. The connector uses your MCP permissions; the model connection above uses
your inference access assignment.

Remote connectors are reached by Anthropic's cloud service, including when you
use Claude Desktop. Your Forge MCP endpoint must be publicly reachable by that
service. After connecting, ask Claude to list an allowed Forge capability and
confirm its invocation appears in Forge's MCP activity. For an approved upstream
MCP server, use that server's endpoint from **Registry** instead of the global
Forge tools URL. See [MCP client setup](/developer/mcp) for both endpoint types.

Test one policy with a non-sensitive example before enabling it for everyone.
Check a limited test assignment's budget too: once its configured limit blocks
a request, Claude should receive an error and Forge should record the denial.
Restore the intended limit after testing.

### Verify model discovery separately

Enable **Model discovery**, then select **Test model discovery** in Claude's
inference configuration. Forge exposes `GET /llm-gateway/v1/models`; the base
URL shown in Forge already ends in `/llm-gateway`. Do not append another `/v1`
if the client adds it. An explicit **Model list** in Claude overrides discovery;
remove an old one-model override when you want the gateway's permitted list.

A model name appearing in the picker does not establish provider access. Send
one short request for each model you intend to distribute and check its Forge
ledger. The route must support Messages, streaming, and tool use for Claude;
an OpenAI Chat Completions-only route is insufficient. Bedrock is an upstream
provider choice, not a separate Claude Desktop identity or network surface.

Anthropic documents these client requirements and discovery behavior in its
[LLM gateway guide](https://claude.com/docs/third-party/claude-desktop/gateway).
Use Forge's access-token settings even when a vendor example defaults to an ID
token: the gateway's authentication contract determines which token is valid.

## Troubleshooting

| Symptom | Check |
| - | - |
| Sign-in fails or returns to the wrong account | Sign in to the intended Forge organization; confirm active membership and directory linkage. |
| Sign-in succeeds but requests are denied | Check Managed access, the profile's state, model permissions, and remaining budget. |
| No models appear | Confirm the profile has an eligible Messages route and the provider connection works. |
| Browser sign-in can't return to Claude | Confirm redirect port `53180` and that another local process isn't using it. |
| Claude asks for sign-in repeatedly | Reapply the connection settings and confirm your organization sign-in is available. |

For other applications and gateway-key setup, see
[Connect apps to Forge](/secure/connect-apps-to-forge).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.