Claude Desktop
Use the fhold desktop extension to connect Claude Desktop to an fhold
agent running on the same computer. It is the correct local integration:
Claude's remote-connector form requires
https://, while a desktop extension runs locally and can reach a loopback
service. Anthropic documents the same distinction in
When to use desktop and web connectors.
The extension is a transparent MCP bridge. It adds no fhold service, tool, policy, or permission. Guardian still authenticates the named credential, filters the MCP catalog, screens input, owns sessions, and writes audit events.
Install
Enable Guardian and create a dedicated credential. Start with read unless
Claude must modify the workspace or approve Assistant permissions:
fhold guardian enable
fhold credential add claude-desktop read
fhold connect claude --credential claude-desktop
Download fhold-claude-desktop-<version>.mcpb from the matching
GitHub release.
Admin's Apps → Claude → Desktop chat section provides the direct download;
fhold connect claude prints the same versioned URL. No source build is required.
In Claude Desktop:
- Open Settings → Extensions → Advanced settings.
- In Extension Developer, choose Install Extension….
- Select the
.mcpbfile. - In fhold Admin, open Apps → Claude → Desktop chat and choose Enable access for Claude Desktop if needed. Confirm whether to restart now or apply the saved change later.
- Under What can Claude Desktop do?, choose Chat only, Read files or Full access and select Create connection. Use Full access only for a trusted app needing agent tools and file changes; granting it requires confirmation. For an already configured extension, change its existing permissions with Apps → Advanced access → Manage; do not create another connection just to change permissions. fhold does not detect the extension's saved assignment.
- In the connection instructions, copy Local address and select Copy access key, then paste them into the extension's address and fhold access key fields. Keys appear here because the extension needs a pasted credential, not as a separate Admin management destination.
- Restart Claude Desktop if the tools do not appear.
The revised Admin workflow is a design preview, not live-verified client setup. Changing saved permissions affects all apps using that identity and requires confirmation; its key and conversations stay attached to the same identity. Creating a separate connection requires updating the extension and starts separate conversations; it does not replace or remove the old connection. Apps → Advanced access → Manage edits existing permissions. System → Connection keys → Rotate key replaces an exposed key, preserving permissions and conversations; update the extension with the new key afterward. The Claude remote connection uses native sign-in and permissions independently of this Desktop MCP connection.
These are Anthropic's documented steps for installing a custom desktop extension. The key field is marked sensitive in the MCPB manifest, so Claude Desktop uses the operating system's secure credential storage.
Open the + → Connectors menu in a conversation to enable fhold. The
credential policy determines the catalog Claude receives. A read credential
can run the guarded agent and inspect ordinary workspace files; a full
credential also receives session mutation and permission-approval operations.
Limits and safety
- The extension accepts only
http://127.0.0.1/...,http://localhost/..., orhttp://[::1]/...and requires the exact/mcppath. It cannot be pointed at a LAN or public host. - The extension neither starts nor updates fhold. Guardian must already be healthy.
- Credential rotation requires updating the extension setting.
- Removing the named credential immediately revokes its key.
- Extension updates are installed manually from the matching release.
Build the artifact from source with:
bun install
bun run --cwd packages/claude-desktop pack
The result is written to packages/claude-desktop/artifacts/. The standard
unsigned pack bundles runtime dependencies and validates the MCPB manifest.
Release MCPB downloads are unsigned; see the reviewed build-tool
advisory in the release runbook.
For access from Claude web/mobile or from another computer, use the public remote MCP deployment, not this extension.