Introducing Synthetic Trust

A durable audit trail for Claude’s tool activity

xCLAUDE records and classifies tool activity from Claude Code and wrapped MCP servers — locally on your Mac, in a record you control.

Download for Mac

Free · Audited locally · No account · No telemetry

Windows coming soon

xCLAUDE Gateway

Audited locally · No account · No telemetry

SourcesDetectionsClaude Code
1628
TOTAL
1606
LOW
14
MEDIUM
3
HIGH
5
CRITICAL
TIMESEVERITYMCPTOOL
17 Jun, 17:22:30LOWgithubget_file_contents
17 Jun, 17:12:57LOWgithubget_file_contents
17 Jun, 17:04:19LOWgithubget_release_by_tag
17 Jun, 16:37:10LOWgithubget_file_contents
17 Jun, 16:37:02LOWxcg-filesystemread_multiple_files
17 Jun, 16:25:06LOWstripetools/list

Why people install it

Every other tool you use has a log. Your AI shouldn't be different.

01

Keep a trail you can come back to

Tool activity from Claude Code and wrapped MCP servers stays in a local, reviewable record you control — across sessions and over time.

02

Know what deserves a second look

xCLAUDE classifies activity as it happens, surfacing credentials, PII, prompt-injection patterns, exports, email actions, and unexpected MCP tool changes.

03

One audit trail across Claude Code and Desktop MCP

Bring Claude Code tool activity and wrapped MCP traffic from Claude Desktop into one place, so you can review both without piecing together separate logs.

How it works

One download. One audit trail. Keep using Claude as usual.

01

Download

Download xCLAUDE for macOS and install it like any other Mac app.

xclaude.ai/download
02

Connect

Enable Claude Code auditing and connect or wrap the MCP servers you want xCLAUDE to observe.

claude_desktop_config.json
03

Review

Tool activity is recorded locally, classified by xCLAUDE, and available to review whenever you need it.

ls ~/Library/Application\ Support/xCLAUDE\ Gateway/wrappers/

The dashboard

Review tool activity, one line at a time.

A native app that lives in your menu bar. It auto-refreshes every 2 seconds and shows every event with severity, connector, and full tool call details. No telemetry leaves your laptop.

Severity-ranked event stream
Tool name and arguments per call
xCLAUDE Gateway — Claude Code viewxCLAUDE Gateway — Detections viewxCLAUDE Gateway — Detection detailxCLAUDE Gateway — Sources viewxCLAUDE Gateway — Add source modal

Connectors

Audit the MCP tools you already use.

xCLAUDE includes common MCP connectors, pre-configured to route through its local audit layer. Connect them through xCLAUDE — rather than Claude Desktop’s native Connectors — and their MCP activity is recorded and classified in your local audit trail.

Notion
Gmail
Slack
Linear
Atlassian
GitHub
Drive
Calendar
Stripe
Apollo

Native Claude Desktop Connectors (Settings → Connectors) bypass xCLAUDE entirely.

See how to reconnect through xCLAUDE →

Claude Code

Your coding agent, on the record.

xCLAUDE keeps an independent, local audit trail of Claude Code's tool activity. A one-click session hook records completed tool calls — built-in and MCP — and classifies them with the same detection engine used across xCLAUDE.

Review activity by session and project, filter by severity or tool, search the trail, and export it when you need it. Wrap Claude Code's MCP servers too for additional protocol-level visibility.

  • One-click setup from Add source
  • Same detection engine, same audit trail
xCLAUDE Gateway — Claude Code view

Coverage

Tool activity, classified and logged.

xCLAUDE records the tool activity it covers and classifies it across severity levels, so you can review what deserves attention without blocking the underlying call.

CRITICALHIGHMEDIUMLOW

Transparent about what it does and doesn't cover. See the full breakdown →

See what it doesn't cover →

EventTriggers when →

Prompt injection

CRITICAL

Tool arguments or response contain instruction-override or jailbreak patterns.

Credential detected

CRITICAL

Tool arguments or response contain an API key, token, or secret.

Email send warning

HIGH / MEDIUM

Tool arguments contain email-sending language, or the tool name signals sending, replying, or composing.

Tool manifest changed

HIGH / MEDIUM

A source's tools changed since the recorded baseline — descriptions, schemas, added or removed tools (tool poisoning).

Structured PII

MEDIUM

Tool arguments or response contain verifiable personal data — email, phone, IBAN, national ID, or credit card.

Data export warning

MEDIUM

Tool arguments contain bulk-extraction language — export, download, or dump targeting data or databases — or a tool response contains export language pointing at an explicit destination.

PII detected

LOW

Tool arguments contain named entities — person names, organizations, locations (async, best-effort enrichment).

Tool call allowed

LOW · BASELINE

Routine calls with no findings — still logged in full, so the audit trail includes ordinary activity, not just incidents.

Questions

Things people ask before installing.

No. xCLAUDE is an independent audit layer built on top of the Model Context Protocol, which is an open standard. Claude and Claude Desktop are trademarks of Anthropic.
Nothing goes to us — there is no xCLAUDE server, no account, and no telemetry. The audit log, dashboard, and detection engine run entirely on your Mac. Connector traffic goes from your Mac directly to each provider; xCLAUDE observes and records it locally.
Not necessarily — you need Claude Desktop, Claude Code, or both. With Claude Desktop, xCLAUDE audits the MCP connectors you route through it. With Claude Code, a one-click session hook records completed tool calls in your coding sessions. Each path works independently.
No — and it's a limit of where the traffic goes, not a missing feature. xCLAUDE audits what passes through your Mac. When you use Claude at claude.ai, it reaches your connected tools from Anthropic's servers, so that traffic never touches your machine and there is nothing for xCLAUDE to observe. Claude Desktop and Claude Code run on your machine, which is what makes the audit possible — though Claude Desktop's own native Connectors also bypass xCLAUDE, so add your services from the Sources tab instead. If you use the browser today, install Claude Desktop or Claude Code and route your tools through xCLAUDE there.
Yes. Install the session hook from Add source and completed tool calls in your Claude Code sessions are recorded and classified — with their own view in the app. You can also wrap Claude Code's MCP servers to observe the protocol level: tool manifests, stderr, and server-initiated traffic.
No. Native Claude Desktop Connectors (Settings → Connectors) connect directly to provider servers, bypassing xCLAUDE entirely. xCLAUDE audits the MCP servers configured through it — including the connectors you add in the app.
Yes — but it's guided, and the key is yours. xCLAUDE ships with no Google credentials of its own: you create your own project in Google Cloud and paste your own OAuth client into the app. A 4-step wizard with deep links walks you through it — Cloud project, OAuth client, Preview enrollment, paste your credentials. One free OAuth client serves Gmail, Calendar and Drive, and your credentials are stored in the macOS Keychain. Two things to know before you start: Google's Preview enrollment form requires an email on a custom domain (the Google account you connect and audit can be a regular Gmail), and approval arrives by email, usually within a couple of days. Because the client is yours, Google shows a "Google hasn't verified this app" screen when you authorize; that's expected — you continue past it. Choosing Publish app on the consent screen means you authorize once; leaving the project in testing expires the authorization every 7 days.
No. xCLAUDE runs entirely on your Mac. Tool calls go through a local proxy with synchronous, regex-based checks. There is no network roundtrip and no remote service to wait for, so the added overhead is imperceptible in normal use.
Before removing the app, open xCLAUDE, go to Settings, and click Uninstall to restore your MCP configuration. If you installed the Claude Code hook, remove it first from the Claude Code source (Uninstall). Then quit xCLAUDE from the menu bar, drag the app to the Trash, and restart Claude Desktop.
Not yet. The current beta requires macOS 13 or later on Apple Silicon (M1 or newer). An Intel build is on the roadmap.
Yes. xCLAUDE is MIT-licensed and the source code is on GitHub.

Make Claude’s tool activity reviewable.

Stay in the loop. Get notified about new detections, releases, and product updates.