> ## Documentation Index
> Fetch the complete documentation index at: https://www.truefoundry.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Claude Web

> Govern claude.ai and the Claude mobile apps with TrueFoundry — Anthropic Inference Hooks for Enterprise, aitori on-device interception for Team, Pro, and Max.

Claude Web — claude.ai in the browser and the iOS and Android apps — has no setting to point it at a gateway. The app talks to Anthropic's backend, which calls the model server-side. That means there is no token-metered request for the AI Gateway to see, so **cost tracking is not available** on Web on any plan.

What you *can* do is put the gateway's guardrails and audit trail on the content users send and receive. There are two ways, and which one you use depends on your plan.

| | Enterprise | Team · Pro · Max |
| - | - | - |
| Mechanism | [Anthropic Inference Hooks](#enterprise-anthropic-inference-hooks) — Anthropic calls the gateway before inference | [aitori](#team-pro-and-max-aitori) — an on-device agent reroutes the app's traffic through the gateway |
| Installed on devices | Nothing | aitori, deployed via MDM |
| Covers | Web, desktop and mobile apps, Claude Code, Slack — one org-wide setting | Whatever devices aitori runs on; mobile not covered |
| Guardrails | Allow / deny before the prompt reaches the model | Allow / deny and audit on the intercepted content |
| Audit | Every governed prompt traced on the gateway; denials in Anthropic's Activity Feed | Every intercepted call logged on the gateway |
| Cost tracking | No | No |

## Enterprise: Anthropic Inference Hooks

[Anthropic Inference Hooks](https://platform.claude.com/docs/en/manage-claude/inference-hooks) let a Claude Enterprise organization send every governed prompt to an HTTPS endpoint for an allow/deny verdict before inference runs. The AI Gateway implements that protocol at `POST /hooks/anthropic-inference`, so your TrueFoundry guardrails decide whether each prompt reaches the model.

Because the hook runs on Anthropic's side, one configuration in the admin console covers **claude.ai, Claude Desktop, the mobile apps, Claude Code, and Claude in Slack** for the whole org, with nothing to install on user devices. That makes it the right choice for Web on Enterprise, and a useful org-wide backstop even where Code and Desktop are already pointed at the gateway.

What it does and doesn't cover:

* Validation only — a prompt is allowed or denied. Rewriting or redacting is not possible, so nominate validation guardrails only.
* Covers the prompt and tool results flowing back into the model; does not scan the model's response, and cannot stop a client-side tool call before it runs.
* Enterprise plan only, and not available on Amazon Bedrock or Google Vertex AI.
* Attachments arrive as extracted text; raw file and image bytes, system prompts, tool definitions, and voice mode are not sent.
* Ships in beta — Anthropic says field names and headers may change before GA.

Setup, header configuration, shadow-mode rollout, and the response contract are on **[Guardrails using Anthropic Inference Hooks](/docs/ai-gateway/anthropic-inference-hooks)**.

## Team, Pro, and Max: aitori

Subscription plans don't have access to Inference Hooks, so governance has to happen on the device. TrueFoundry ships **[aitori](https://github.com/truefoundry/aitori)**, an open-source (Apache-2.0) agent that runs as the machine's HTTPS proxy. For an allowlist of AI hosts it terminates TLS with a certificate authority that exists only on that device, identifies the model and MCP calls, and reroutes them through the AI Gateway. Everything else passes straight through, never decrypted.

Claude (Web, Desktop, and Code) and ChatGPT are covered by built-in profiles, so there are no rules to write. Try it on one machine:

```bash theme={"dark"}
# Install (macOS / Linux)
curl -fsSL https://raw.githubusercontent.com/truefoundry/aitori/main/install.sh | sh

# Save the AI Gateway token on the device
mkdir -p ~/.aitori
echo '<your-api-key>' > ~/.aitori/tf_token
chmod 600 ~/.aitori/tf_token

# Govern this machine and open the live view at http://127.0.0.1:9100
sudo aitori up --ui \
  --gateway-url "https://gateway.truefoundry.ai/api/llm/ai-proxy/" \
  --token-file ~/.aitori/tf_token

# Revert the system proxy when you're done
sudo aitori down
```

<Warning>
  `aitori up` points the system proxy at the agent. Always run `sudo aitori down` to revert it — if the process is killed without reverting, the system proxy keeps pointing at a stopped agent and traffic breaks.
</Warning>

For a call worth governing, aitori keeps the original request intact — same method, path, body, and the app's own credentials — and only redirects the upstream connection to the gateway, adding `x-tfy-api-key`, `x-tfy-original-url`, and `x-tfy-metadata` headers. The gateway authenticates the user, runs guardrails, logs the call, strips the `x-tfy-*` headers, and forwards to the original destination. The app notices nothing.

What you get and don't:

* Guardrails and audit on the visible content of claude.ai conversations. Fail-open by default (the request goes to its original destination if the gateway is unreachable), switchable to fail-closed.
* No cost tracking — the metered model call runs in Anthropic's cloud.
* Desktop and laptop only. Mobile apps aren't covered; on Team/Pro/Max the controls for those are Anthropic's own (SSO, domain capture, admin settings).
* Certificate-pinned apps and HTTP/3 over QUIC need handling — see known limitations.

Fleet rollout (config file, MDM deployment, CA distribution), the header contract, and how aitori fits alongside an existing Secure Web Gateway are on **[Govern all AI traffic through the AI Gateway](/docs/ai-gateway/govern-traffic-through-ai-gateway#method-b-aitori-the-open-source-on-device-agent)**.

## MCP servers on Web

Independent of the model call, any MCP server a user adds to claude.ai as a custom connector can point at the [TrueFoundry MCP Gateway](/docs/ai-gateway/mcp/mcp-overview). Those tool calls get the full set of controls — allowlisting, per-user auth, tool-level RBAC, guardrails, and audit — regardless of plan. See [Govern MCP traffic](/docs/ai-gateway/claude-mcp-governance).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.