Skip to main content
Claude Web — claude.ai in the browser and the iOS and Android apps — has no setting to point it at a gateway. The app talks to Anthropic’s backend, which calls the model server-side. That means there is no token-metered request for the AI Gateway to see, so cost tracking is not available on Web on any plan. What you can do is put the gateway’s guardrails and audit trail on the content users send and receive. There are two ways, and which one you use depends on your plan.

Enterprise: Anthropic Inference Hooks

Anthropic Inference Hooks let a Claude Enterprise organization send every governed prompt to an HTTPS endpoint for an allow/deny verdict before inference runs. The AI Gateway implements that protocol at POST /hooks/anthropic-inference, so your TrueFoundry guardrails decide whether each prompt reaches the model. Because the hook runs on Anthropic’s side, one configuration in the admin console covers claude.ai, Claude Desktop, the mobile apps, Claude Code, and Claude in Slack for the whole org, with nothing to install on user devices. That makes it the right choice for Web on Enterprise, and a useful org-wide backstop even where Code and Desktop are already pointed at the gateway. What it does and doesn’t cover:
  • Validation only — a prompt is allowed or denied. Rewriting or redacting is not possible, so nominate validation guardrails only.
  • Covers the prompt and tool results flowing back into the model; does not scan the model’s response, and cannot stop a client-side tool call before it runs.
  • Enterprise plan only, and not available on Amazon Bedrock or Google Vertex AI.
  • Attachments arrive as extracted text; raw file and image bytes, system prompts, tool definitions, and voice mode are not sent.
  • Ships in beta — Anthropic says field names and headers may change before GA.
Setup, header configuration, shadow-mode rollout, and the response contract are on Guardrails using Anthropic Inference Hooks.

Team, Pro, and Max: aitori

Subscription plans don’t have access to Inference Hooks, so governance has to happen on the device. TrueFoundry ships aitori, an open-source (Apache-2.0) agent that runs as the machine’s HTTPS proxy. For an allowlist of AI hosts it terminates TLS with a certificate authority that exists only on that device, identifies the model and MCP calls, and reroutes them through the AI Gateway. Everything else passes straight through, never decrypted. Claude (Web, Desktop, and Code) and ChatGPT are covered by built-in profiles, so there are no rules to write. Try it on one machine:
aitori up points the system proxy at the agent. Always run sudo aitori down to revert it — if the process is killed without reverting, the system proxy keeps pointing at a stopped agent and traffic breaks.
For a call worth governing, aitori keeps the original request intact — same method, path, body, and the app’s own credentials — and only redirects the upstream connection to the gateway, adding x-tfy-api-key, x-tfy-original-url, and x-tfy-metadata headers. The gateway authenticates the user, runs guardrails, logs the call, strips the x-tfy-* headers, and forwards to the original destination. The app notices nothing. What you get and don’t:
  • Guardrails and audit on the visible content of claude.ai conversations. Fail-open by default (the request goes to its original destination if the gateway is unreachable), switchable to fail-closed.
  • No cost tracking — the metered model call runs in Anthropic’s cloud.
  • Desktop and laptop only. Mobile apps aren’t covered; on Team/Pro/Max the controls for those are Anthropic’s own (SSO, domain capture, admin settings).
  • Certificate-pinned apps and HTTP/3 over QUIC need handling — see known limitations.
Fleet rollout (config file, MDM deployment, CA distribution), the header contract, and how aitori fits alongside an existing Secure Web Gateway are on Govern all AI traffic through the AI Gateway.

MCP servers on Web

Independent of the model call, any MCP server a user adds to claude.ai as a custom connector can point at the TrueFoundry MCP Gateway. Those tool calls get the full set of controls — allowlisting, per-user auth, tool-level RBAC, guardrails, and audit — regardless of plan. See Govern MCP traffic.