Claude Connectors Explained: What They Can Reach

A connector lets Claude read from and act in another service, as you and never as more than you. The three kinds — directory, custom and desktop extensions — where each one works, what the approval settings do, and the controls Team and Enterprise owners have.

7 min read

Claude connectors let Claude reach into your other services — search your files, read a channel, create an issue — from inside a conversation. Each connector brings a set of tools written by whoever built it, and Claude uses them as you: it inherits your permissions in the connected service, so it can never see or change more than you could yourself. There are three kinds: connectors from Anthropic’s directory, custom connectors you add by URL, and desktop extensions that run on your own computer. What a connector can actually do is decided by three things together: the tools its server offers, what you approved when you signed in, and the approval settings in Claude.

What a connector is

In Anthropic’s words on using connectors (opens in a new tab), connectors let Claude access your apps and services, retrieve your data, and take actions within connected services. If you cannot open a file, channel or record in the source system, the connector cannot reach it from Claude either. Under the hood most connectors are servers speaking the Model Context Protocol; what that means is covered in what is MCP, and you do not need to know it to use one.

Once a service is connected, Claude can bring it into a conversation when it fits your request, without you naming it each time. You can also switch individual connectors on or off per conversation from the “+” menu under Connectors.

The three kinds

Directory connectors

Pre-built connectors listed in the Connectors Directory (opens in a new tab), each with a page describing its use cases, its read and write capabilities, and where it is available. You add one from Customize, then Connectors, press Connect, and sign in to the service. Some are marked Interactive: they can show a live interface, such as a dashboard or a task board, inside the conversation, and anything you do in it uses the permissions you granted when connecting.

Custom connectors

Any remote MCP server, added by name and URL. The help page on custom connectors using remote MCP (opens in a new tab) says they are available in Claude, Cowork and Claude Desktop on Free, Pro, Max, Team and Enterprise plans, with Free limited to one. Two details catch people out:

  • Claude connects from Anthropic’s cloud, not from your machine. The server must be reachable over the public internet; one behind a VPN or firewall will not connect even if your own browser can reach it, unless you allowlist Anthropic’s IP ranges.
  • Custom connectors are not verified by Anthropic. Connect only to servers from organisations you trust, and read what the sign-in screen asks for.

Desktop extensions

Local MCP servers packaged as one-click installs, found under Settings, then Extensions, in Claude Desktop. The help page on local MCP servers in Claude Desktop (opens in a new tab) describes them as installing like browser extensions, with any keys you enter encrypted in the operating system’s secure storage. Custom ones install from an .mcpb file.

Which kind works where

Anthropic’s guide on when to use desktop and web connectors (opens in a new tab) draws the line simply: if the tool is a cloud service you sign in to, use a remote connector; if it runs on your computer or needs your filesystem, use a desktop extension.

  • Remote connectors (directory and custom): web, desktop, mobile, Cowork and Claude Code. Connect once and they follow your account.
  • Desktop extensions: Claude Desktop and Claude Code only, not web or mobile.
  • Plugins can bundle either. One that includes a local server works in Cowork and Claude Code, not in chat.

Developers calling Claude through the API get the same reach another way: the MCP connector (opens in a new tab) lets a Messages API request name a remote MCP server directly.

What a connector can read and do

The server’s author decides what its tools do: read data, create, change or delete it, or act on your behalf. A connector for a mail service might search and summarise; the same connector might also send. You find out which from the directory page or the tool list, not from the name.

  • Sign-in sets the outer limit. Most connectors use OAuth: you sign in to the service, it shows what it is granting, and Claude never sees your password. Deny or narrow anything that looks broader than you need.
  • Tool permissions set the inner limit. For each connector’s tools, grouped into read-only and write or delete, you choose Always allow, Needs approval or Blocked.
  • Approve with care. Anthropic’s own advice is to click “Allow always” only for a server and tool you trust to run unsupervised.
  • Research is different. When Claude runs Research, it can call connector tools without asking again, so the help centre suggests switching off tools that write before you start.
  • Watch for prompt injection. A malicious server can hide instructions in what it returns. Claude has protections, but the help centre asks you to watch tool inputs and outputs anyway.

If you have ten or more connectors switched on, the Tool access setting in the same menu can load them on demand rather than all at once, which leaves more room in the conversation.

Controls on Team and Enterprise plans

  • Owners enable first. On Team and Enterprise, an Owner or Primary Owner adds a connector for the organisation under Organization settings, then Connectors. That makes it available; it grants nobody access. Each person still signs in individually.
  • Only owners add custom connectors to the organisation. Members then find them in their own connector list, usually labelled Custom, and connect.
  • Owners can restrict actions organisation-wide — for example, allow reading a drive but block creating or editing documents — and individual users cannot override it. It only ever narrows what the source system allows.
  • Owners can switch off the tool calls that render interactive connectors.
  • On Enterprise, owners can stop services on the organisation’s verified domains from being connected to Claude accounts outside it, and enterprise-managed auth (in beta) authorises a connector once for everyone.
  • Desktop extensions have their own controls: turn the public directory on or off, keep an allowlist, and upload the organisation’s own extensions.

Connectors inside projects

Connectors work in project chats, and they are the cleanest way to give a project live material rather than uploaded copies that go stale. Two rules apply on Team and Enterprise plans, both from the connectors page: connectors are only available in private projects, and chats with synced content cannot be shared. A shared team project therefore works from its uploaded knowledge; the connector is for each person’s own chats. How projects share material more generally is in can Claude projects reference each other?.

An example: a task board as a custom connector

fenbs is a remote MCP server, so in Claude it is a custom connector: Customize, Connectors, “+”, “Add custom connector”, then the URL below. Claude opens fenbs in your browser; you sign in, tick what the assistant may do — read, write, comment — and approve.

Connector URL
https://fenbs.ai/api/mcp

The layers stack the way this post describes. Claude holds your role on the board, narrowed by the scopes you ticked; the sign-in gives it an hour-long access token that refreshes; every change it makes is recorded as “Claude via” you; and revoking the token ends its access without touching your own sign-in. The full walk-through is in how to connect Claude to your project board with MCP, and the fenbs side is on the Claude integration page.

Related

Adding a server without touching a terminal: MCP without coding. The ChatGPT equivalent: ChatGPT connectors and apps. What an assistant’s token is allowed to do on a board: assistant tokens and scopes.

Questions people ask.

Can a Claude connector see more than I can?

No. Claude inherits your permissions from the connected service, so anything you cannot open there, the connector cannot reach. Admin restrictions in Claude can narrow that further but never widen it.

What is the difference between a custom connector and a desktop extension?

A custom connector is a remote MCP server reached by URL from Anthropic’s cloud, and works on web, desktop, mobile, Cowork and Claude Code. A desktop extension is a local MCP server installed in Claude Desktop and works only there and in Claude Code.

Why can my colleagues not use the connector I set up?

On Team and Enterprise plans an owner enables a connector for the organisation, and then each person signs in to the service individually. Your connection is yours alone.

Can I use connectors in a shared Claude project?

On Team and Enterprise plans, the help centre says connectors are only available in private projects, and chats with synced content cannot be shared.

Start with one thing.

There is nothing to set up first. Write one line and you’ve started.