Billing and plans
Does routing Claude through the gateway use our Claude Enterprise or Team seats, or create a separate API bill?
Does routing Claude through the gateway use our Claude Enterprise or Team seats, or create a separate API bill?
- Model account has an Anthropic API key → every request is billed per token to that key. The user’s seat is not involved. This is the only option for Claude Desktop / Cowork, and one of two options for Claude Code.
- Model account has no API key (subscription passthrough) → the gateway forwards the user’s own Claude login token, and usage draws from their seat or subscription. Only Claude Code can do this, because it is the only client with a Claude login flow.
We're on Pro, Max, or Team. Can Claude Code use our subscription through the gateway?
We're on Pro, Max, or Team. Can Claude Code use our subscription through the gateway?
ANTHROPIC_AUTH_TOKEN unset, and put your TrueFoundry key in ANTHROPIC_CUSTOM_HEADERS as x-tfy-api-key. The user signs in with their Claude account when Claude Code starts; the gateway authenticates them with the TrueFoundry key and forwards their Claude token to Anthropic. Usage draws from the subscription, and the gateway still records every request per user.Setup is under Authentication by plan.Does Claude Desktop / Cowork in third-party mode use the user's seat?
Does Claude Desktop / Cowork in third-party mode use the user's seat?
What happens when a subscription user hits their rate limit mid-session?
What happens when a subscription user hits their rate limit mid-session?
0 and a pay-per-token Anthropic account as the fallback. The gateway uses the subscription until it is rate-limited, then routes overflow to the API key. Only one target in a virtual model can be a passthrough account, since there is only one Authorization header to forward.Steps are under Fall back from the subscription to the Anthropic API.Is the cost shown in Analytics a bill?
Is the cost shown in Analytics a bill?
Can Claude apps use Bedrock, Vertex, or Microsoft Foundry instead of Anthropic directly?
Can Claude apps use Bedrock, Vertex, or Microsoft Foundry instead of Anthropic directly?
anthropic-beta headers and new request fields pass through unfiltered. On other providers the gateway checks each beta against a per-provider allowlist and drops the rest, Anthropic’s server-side tools (built-in web search) don’t run, and model ids differ. Claude Code and Desktop work, but some of their newest features arrive later or not at all. See Forwarding Anthropic beta features.Authentication and identity
How does the gateway know which user a request came from?
How does the gateway know which user a request came from?
Authorization: Bearer <token> or in the x-tfy-api-key header. The gateway recognises three kinds: tokens it issued (Personal Access Tokens, Virtual Account tokens, and the short-lived tokens tfy-local-ai-setup mints from a device login), JWTs from an identity provider you have registered, and, in SWG mode, an X-Authenticated-User assertion from a trusted upstream proxy.The identity is as good as the token. One Personal Access Token pasted into a shared managed-settings.json makes the whole fleet look like one user. The MDM binary mints a separate token per user from their own SSO login, which is what gives per-user attribution at scale. See Enforce with MDM.Why does the Claude Code config sometimes have the key in ANTHROPIC_AUTH_TOKEN and sometimes in x-tfy-api-key?
Why does the Claude Code config sometimes have the key in ANTHROPIC_AUTH_TOKEN and sometimes in x-tfy-api-key?
ANTHROPIC_AUTH_TOKEN becomes the Authorization header. On the gateway-key pattern that header carries your TrueFoundry key and nothing else is needed. On subscription passthrough Claude Code reserves Authorization for the user’s Claude login token, so the TrueFoundry key moves to x-tfy-api-key in ANTHROPIC_CUSTOM_HEADERS. The gateway checks both locations.If MDM pushes the Desktop config, can we still track cost per user?
If MDM pushes the Desktop config, can we still track cost per user?
tfy-local-ai-setup --claude-desktop mints that per user: it runs the device login as the signed-in user, writes that user’s token into the per-user managed preferences, locks the file, and refreshes it on every run. Each Desktop request then carries that user’s identity and appears under their name in Analytics, exactly as Claude Code does. See Claude Desktop → MDM.Can the gateway authenticate users with their Claude login token instead of a TrueFoundry token?
Can the gateway authenticate users with their Claude login token instead of a TrueFoundry token?
Claude Code configuration
Do I need CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS=1? Which beta headers reach the model?
Do I need CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS=1? Which beta headers reach the model?
0 if you want Claude Code’s newer features. Forward specific betas with "ANTHROPIC_CUSTOM_HEADERS": "x-tfy-anthropic-beta: <value>,<value>". x-tfy-anthropic-beta replaces, rather than merges with, a raw anthropic-beta header.On Anthropic /v1/messages there is no allowlist: beta values, safeguards, tool_reference, defer_loading, and thinking blocks pass through. On Bedrock, Vertex, and Foundry the gateway filters betas against a per-provider allowlist and silently drops unsupported ones, so a feature such as tool search may not run there. To see what was forwarded, check the trace attributes tfy.model.anthropic_betas_requested and tfy.model.anthropic_betas_sent. Note that DISABLE_EXPERIMENTAL_BETAS=1 also overrides ENABLE_TOOL_SEARCH=TRUE. See Forwarding Anthropic beta features.Claude Code asks for a model ending in [1m] and the gateway rejects it
Claude Code asks for a model ending in [1m] and the gateway rejects it
[1m] to the model name in settings.json (for example claude-code/claude-sonnet[1m]). Claude Code strips the suffix before sending and treats the model as the 1M-context variant internally, so the gateway sees the normal model name. Don’t create a model with brackets in its name on the gateway; brackets aren’t allowed in integration names. See the Claude Code FAQ.Claude Code's auto mode or classifier behaves differently through the gateway
Claude Code's auto mode or classifier behaves differently through the gateway
tfy.model.anthropic_betas_requested and tfy.model.anthropic_betas_sent from a failing request, the virtual model configuration, and the settings.json env block.Claude Desktop and Cowork
After pointing Desktop at the gateway, the Connectors panel is empty and I can't add a custom connector
After pointing Desktop at the gateway, the Connectors panel is empty and I can't add a custom connector
managedMcpServers managed preference, each pointing at a server on the MCP Gateway, and users click Connect to sign in as themselves; local stdio MCP servers remain user-addable via claude_desktop_config.json while isLocalDevMcpEnabled is true. Claude Desktop doesn’t support MDM-managed and user-added remote servers at the same time, so push a complete catalog. See Govern MCP traffic.My chats and projects disappeared when I switched Desktop to the gateway
My chats and projects disappeared when I switched Desktop to the gateway
claudeAiImport managed key and users get an Import from Claude wizard. On a Team or Enterprise workspace an owner must also allow members to export their own data, and uploaded file contents never come across. See Enforce with MDM.Desktop discovers models fine but every message fails with 401 Invalid bearer token
Desktop discovers models fine but every message fails with 401 Invalid bearer token
Every Desktop session starts with tens of thousands of tokens of MCP tool schemas
Every Desktop session starts with tens of thousands of tokens of MCP tool schemas
toolSearchEnabled managed preference (a plain boolean, MDM-only, Desktop 1.21459.0+); Desktop then loads a tool’s schema only when it is first used. Setting ENABLE_TOOL_SEARCH yourself has no effect, because Desktop strips it from the session environment while toolSearchEnabled is unset. Pilot with one group first: enabling it adds the tool-search-tool-2025-10-19 beta and tool_reference blocks to requests, which pass through on Anthropic direct but may be filtered on other providers. See Enforce with MDM.Governance and rollout
Can we govern claude.ai web and the mobile apps, and track their cost?
Can we govern claude.ai web and the mobile apps, and track their cost?
Users keep getting asked to log in again, or the Intune deployment can't open the login browser
Users keep getting asked to log in again, or the Intune deployment can't open the login browser
tfy-local-ai-setup releases; current binaries refresh silently from the token in ~/.tf/refresh-token, so update to the latest release and schedule the script hourly. The browser prompt should then appear only on first run or after 30 days without a refresh.Intune device-assigned deployments run as SYSTEM, which cannot open a browser. Use SYSTEM for the privileged parts (install the binary, write config under C:\ProgramData\TrueFoundry, write and lock managed-settings.json), have each user complete the TrueFoundry login once interactively, and let the hourly run refresh from then on. See Enforce with MDM.