> ## Documentation Index
> Fetch the complete documentation index at: https://docs.forge.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect apps to Forge

> Connect applications to the Forge LLM Gateway using organization sign-in or a gateway key.

Open **Gateway → Connect an app** and choose your application. Forge shows
the connection methods available to your organization.

<Frame caption="Connect Claude Desktop to Forge">
  <img src="https://mintcdn.com/forge-93b579e9/Wy6unjHVP9m1ZNaR/images/screenshots/connect-an-app.png?fit=max&auto=format&n=Wy6unjHVP9m1ZNaR&q=85&s=0366745a7d7af476858bd7f35126aac6" alt="Forge app connection dialog with an application picker, operating system choice, and setup download" width="1440" height="1000" data-path="images/screenshots/connect-an-app.png" />
</Frame>

## Choose a connection method

| Application | Connection method | Setup |
| - | - | - |
| Claude Desktop | Organization sign-in | Download a setup file or configure one device manually. Follow [Claude Desktop with Forge](/secure/claude-desktop-with-forge). |
| Claude Code, when enabled by your administrator | Organization sign-in | Sign in with Forge CLI and deploy the generated managed settings file. See below. |
| Codex CLI and desktop app | Gateway key | Configure the Forge Responses endpoint and Forge MCP separately. Follow [Codex with Forge](/secure/codex-with-forge). |
| Other apps listed in Connect an app | Organization sign-in | Follow the app's instructions and use the connection details shown in Forge. |
| Apps with a configurable OpenAI-compatible or Anthropic-compatible endpoint | Gateway key | Configure the Forge endpoint and a key assigned to an access profile. |

Organization sign-in gives each person their own identity and applies their
current access assignment. An application must support the sign-in method
shown in Forge; a configurable API endpoint alone does not provide sign-in.

If your app is not listed, choose **Another app · Gateway key**. Applications
with a fixed provider endpoint may require [Forge for devices](/integrations/device-agent)
or a supported network integration instead of direct configuration.

## Connect with organization sign-in

1. Ask your administrator to assign an active access profile under **Manage access**.
2. Select your app and follow its setup instructions. For Claude Desktop, choose your operating system and download the setup file.
3. Sign in with your Forge organization account.
4. Send a short message using an allowed model.

Your membership, model permissions, policies, and budgets apply to requests.
Changes to your access assignment apply without replacing the app's connection
settings. If organization sign-in is unavailable, contact your Forge administrator.

### Claude Code with organization sign-in

An administrator must register a **Claude Code** public OAuth client for the
Forge gateway audience before this choice appears. In **Gateway → Connect
an app → Claude Code**, copy the sign-in command and run it on each user's
device. The command opens the Forge device authorization flow and stores that
person's refreshable gateway token in a separate Forge CLI profile.

Download **managed settings** from the same dialog and distribute the file with
your normal Claude Code settings deployment. It sets Forge as the Anthropic
endpoint, enables discovery of models the user may access, and calls Forge CLI
for a fresh token when Claude Code needs one. The file contains no user token.
Keep Forge CLI installed and available to Claude Code on the device. Run
`/status` inside Claude Code to check the gateway URL and helper, send a short
message, then confirm identity, model, tokens, and policy outcome in Forge
Usage. Each person's Forge access profile and budget apply. The helper's token
is for the inference gateway audience; a Forge REST API or MCP token cannot be
substituted.

Claude Code's [gateway connection guide](https://code.claude.com/docs/en/llm-gateway-connect)
describes managed settings, `apiKeyHelper`, and model discovery. Claude Code
in the Claude Desktop app uses the Desktop third-party inference configuration
instead; follow [Claude Desktop with Forge](/secure/claude-desktop-with-forge).

## Connect with a gateway key

1. Select **Another app · Gateway key**, then **Create gateway key**.
2. Choose the access profile and identity for the application.
3. Save the key securely. Forge displays its secret only once.
4. Copy the endpoint from Gateway into the application's provider settings and use the new key as its API key.
5. Choose a model allowed by the access profile and send a short message.

Use the endpoint exactly as shown. Applications that ask for a provider root
instead of an API base URL may append `/v1` themselves; follow their URL format
to avoid adding `/v1` twice. Use a separate key for each application or service
so you can revoke it independently.

## Confirm the connection

In **Gateway → Usage**, find your first request and confirm its
identity, model, outcome, and usage. A downloaded configuration or completed
sign-in alone does not confirm that model requests are working.

| Problem | Next step |
| - | - |
| App is not listed | Use a gateway key if the app supports a configurable endpoint. Ask your administrator about organization sign-in support. |
| No models appear | Check the access profile's models, routes, and provider connection. |
| Requests are denied | Check your current assignment, model permissions, policies, and budget. |
| Requests do not appear in Forge | Confirm the app is using the Forge endpoint and the intended connection settings. |
| Sign-in succeeds for the wrong organization | Sign out of the app, sign in again, and choose the intended Forge organization. |

## Validate the actual request path

Use the base URL and authentication method shown for your selected app. For
an OpenAI-compatible client, verify whether it expects a base ending in `/v1`;
for an Anthropic-compatible client, verify that it appends `/v1/messages`.
A duplicated `/v1/v1` path is a client configuration error.

Check discovery, a short non-streaming request, streaming, and a tool round trip
when the app uses tools. Match the resulting request in Forge by timestamp,
identity, profile, model, and status. A successful models response alone does
not test inference, budget admission, or upstream credentials.

| Result | Next check |
| - | - |
| `401` | Key or access token, issuer, audience, expiry, and selected environment. |
| `403` | Effective assignment, model/protocol permission, or policy denial. |
| `402` with a Forge budget message | Forge budget window and reservation; adding provider credits does not change that limit. |
| Upstream authentication or credit error | Provider connection and provider billing, independently of Forge budgets. |
| `503` during a new configuration | Configuration readiness and propagation; confirm it is applied before retrying. |


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.