Skip to main content
Claude Code is Anthropic’s coding agent. It can read repositories, edit files, run shell commands, and call external tools from a developer’s terminal. The TrustGuard plugin evaluates these actions through lifecycle hooks on the machine where Claude Code runs. TrustGate provides access to the MCP tools assigned to a consumer. For organization-wide inference hooks or managed MCP connectors, see Claude Enterprise.

NeuralTrust controls

Use the TrustGuard plugin to evaluate individual actions. Add TrustGate when Claude Code needs controlled access to MCP tools. Each has its own configuration and credentials.
TrustGuard uses a tgk_… collector key in claude-code.json. TrustGate authenticates MCP consumers with OAuth2 or an ag_… API key. A tgk_… key does not authenticate MCP, and the plugin’s managed settings do not accept an MCP URL.

Before you start

Create the policy in Observe mode. Observe records decisions in Activity without enforcing them. Review the results, then switch the policy to Enforce. See Policies.
Developers do not need NeuralTrust accounts to use the TrustGuard plugin. OAuth-backed MCP consumers require a login against the IdP configured for the consumer, which may be NeuralTrust.

TrustGuard plugin

The Claude Code plugin registers lifecycle hooks on the developer’s machine. Before an action runs, each hook calls POST /v1/evaluate with a collector tgk_… key. Unlike the Enterprise inference hook, the plugin receives shell commands and supports Ask on tool calls. Hooks fire only when all three pieces are present:
  1. Enable the plugin. Deploy this through server-managed settings (claude.ai Admin → Claude Code → Managed settings) or as the file /Library/Application Support/ClaudeCode/managed-settings.json:
    Do not add pluginConfigs, mcpServers, or an MCP URL. Organization-wide MCP access uses a separate organization connector.
  2. Deploy the collector config with MDM, and optionally pin the binary:
  3. Confirm the plugin is enabled. An installed plugin, including one with Scope: managed, does not run until its status is enabled:
  4. Start a new Claude Code session so hooks.json loads.
enabledPlugins: true in the admin JSON does not always enable the plugin in the CLI. Claude Code skips server-managed settings entirely when ANTHROPIC_BASE_URL or any CLAUDE_CODE_USE_* variable is set. This includes sessions pointed at a TrustGate LLM proxy. Deploy the file path instead in that case.

Connect to TrustGate

For centrally managed access, use a Claude organization connector. Claude Code loads that connector after the user completes the connection. Confirm in /mcp that TrustGate is the org connector, not “Provided by a plugin”. For local testing, add the MCP consumer directly to the CLI. This does not replace the organization connector. Copy the endpoint from the consumer’s Connect tab:
An API-key consumer sends the key as a header:
On a private (Hybrid) data plane, add --header "X-AG-Gateway-Slug: <gateway-slug>" as well.

Verify

TrustGuard plugin

Check that the binary and collector config are installed, then send a test lifecycle event:
A manual probe that shows up in Activity with source.application = claude-code-plugin means the binary and key work. If Claude Code still never evaluates, the plugin is disabled or hooks did not reload.

TrustGate MCP connection

  1. Confirm that /mcp lists TrustGate, then call a tool from a bound registry.
  2. Confirm the call in TrustGate telemetry. See Metrics.

Reference

Coverage

This table describes the TrustGuard plugin, not the TrustGate MCP connection. Ask. The plugin honors Ask on tool calls by raising Claude Code’s native permission dialog. The subtitle is the generic TrustGuard sentence A TrustGuard policy needs your approval to continue.; the title is Claude Code’s tool name and the plugin cannot change it. An ask on UserPromptSubmit does not stop the prompt. Claude Code has no confirmation dialog for that event, so it submits the prompt with a warning. Use a Block gate to stop a prompt. Limits. The plugin does not support redaction or evaluate tool declarations. There is no hook for assistant output, so model responses, system prompts, token usage, and extended thinking are not evaluated. Route MCP through TrustGate if you need controls over the available tool set. The plugin does not run in claude.ai or Desktop; use the Enterprise inference hook to evaluate model requests across the organization.

What is evaluated

The plugin sends one evaluation call per lifecycle hook. tool.name is payload.params.name: for mcp__<server>__<tool> that is the last segment. Gate on that short name, not the full hook tool_name. The policy’s detectors decide the verdict.

Configuration

Managed settings (plugin enablement only). managed-settings.json carries extraKnownMarketplaces and enabledPlugins. It does not hold a collector key or an MCP URL. claude-code.json (TrustGuard collector only). Keys: data_url, api_key, fail_mode. When the managed file contains api_key, that key plus data_url and fail_mode are locked. A user file cannot replace them. fail_mode: open plus an empty hook body {} means allow; that is also the response when evaluate returns allow. Binary discovery. The MDM path is checked first, then ~/.trustguard/bin. The user path is not required when the MDM binary exists. On a private fork of the plugin repository, an unauthenticated GitHub Releases request may return 404. Set TRUSTGUARD_GITHUB_TOKEN and pin the release version. If the download fails, the bootstrap fails open. Remote sessions. Over SSH or WSL, the hooks run on the remote host. An MDM-deployed binary on the Mac does not cover that session. The config and binary must exist where the agent runs. MCP auth. The CLI accepts OAuth2 or an ag_… consumer key as X-AG-API-Key. A private data plane needs X-AG-Gateway-Slug unless the MCP host already scopes the gateway. Which IdP backs the OAuth login is configured on the consumer. See Auth. Authenticating to TrustGate is separate from authenticating to the upstream servers; a registry using OAuth (forwarded) returns a connect link on the first call for a user without a stored credential. Deployment ownership. IT manages plugin enablement through managed-settings.json or server-managed settings, and deploys the organization collector key in claude-code.json through MDM. An Anthropic organization owner manages organization connectors. Configure the consumer’s available tools under Routing in the NeuralTrust console, or through a role for Identity-based consumers. To limit MCP tool calls, attach the Per-Tool Rate Limiter policy.

Attributes

The plugin stamps source.application = claude-code-plugin and a per-developer consumer_id. These values provide per-developer attribution in Activity. A gate on claude-code does not match the plugin. That value identifies Claude Code requests seen server-side by the Enterprise inference hook. Use a collector and default policy for each integration path, and configure their gates separately. To target the plugin, create a gate with source.application eq claude-code-plugin, then choose Ask or Block as appropriate for the event. The field is under Policies → Gates → Source application. Gates run before detectors. In Observe mode, Block is recorded but not enforced. Test the condition on the policy Test tab with Extra parameter Source application set to claude-code-plugin.

Troubleshooting