A durable audit trail for Claude’s tool activity
xCLAUDE records and classifies tool activity from Claude Code and wrapped MCP servers — locally on your Mac, in a record you control.
xCLAUDE Gateway
Audited locally · No account · No telemetry
Why people install it
Every other tool you use has a log. Your AI shouldn't be different.
Keep a trail you can come back to
Tool activity from Claude Code and wrapped MCP servers stays in a local, reviewable record you control — across sessions and over time.
Know what deserves a second look
xCLAUDE classifies activity as it happens, surfacing credentials, PII, prompt-injection patterns, exports, email actions, and unexpected MCP tool changes.
One audit trail across Claude Code and Desktop MCP
Bring Claude Code tool activity and wrapped MCP traffic from Claude Desktop into one place, so you can review both without piecing together separate logs.
How it works
One download. One audit trail. Keep using Claude as usual.
Download
Download xCLAUDE for macOS and install it like any other Mac app.
›xclaude.ai/downloadConnect
Enable Claude Code auditing and connect or wrap the MCP servers you want xCLAUDE to observe.
›claude_desktop_config.jsonReview
Tool activity is recorded locally, classified by xCLAUDE, and available to review whenever you need it.
›ls ~/Library/Application\ Support/xCLAUDE\ Gateway/wrappers/The dashboard
Review tool activity, one line at a time.
A native app that lives in your menu bar. It auto-refreshes every 2 seconds and shows every event with severity, connector, and full tool call details. No telemetry leaves your laptop.





Connectors
Audit the MCP tools you already use.
xCLAUDE includes common MCP connectors, pre-configured to route through its local audit layer. Connect them through xCLAUDE — rather than Claude Desktop’s native Connectors — and their MCP activity is recorded and classified in your local audit trail.
Native Claude Desktop Connectors (Settings → Connectors) bypass xCLAUDE entirely.
See how to reconnect through xCLAUDE →Claude Code
Your coding agent, on the record.
xCLAUDE keeps an independent, local audit trail of Claude Code's tool activity. A one-click session hook records completed tool calls — built-in and MCP — and classifies them with the same detection engine used across xCLAUDE.
Review activity by session and project, filter by severity or tool, search the trail, and export it when you need it. Wrap Claude Code's MCP servers too for additional protocol-level visibility.
- One-click setup from Add source
- Same detection engine, same audit trail

Coverage
Tool activity, classified and logged.
xCLAUDE records the tool activity it covers and classifies it across severity levels, so you can review what deserves attention without blocking the underlying call.
Transparent about what it does and doesn't cover. See the full breakdown →
Prompt injection
CRITICALTool arguments or response contain instruction-override or jailbreak patterns.
Credential detected
CRITICALTool arguments or response contain an API key, token, or secret.
Email send warning
HIGH / MEDIUMTool arguments contain email-sending language, or the tool name signals sending, replying, or composing.
Tool manifest changed
HIGH / MEDIUMA source's tools changed since the recorded baseline — descriptions, schemas, added or removed tools (tool poisoning).
Structured PII
MEDIUMTool arguments or response contain verifiable personal data — email, phone, IBAN, national ID, or credit card.
Data export warning
MEDIUMTool arguments contain bulk-extraction language — export, download, or dump targeting data or databases — or a tool response contains export language pointing at an explicit destination.
PII detected
LOWTool arguments contain named entities — person names, organizations, locations (async, best-effort enrichment).
Tool call allowed
LOW · BASELINERoutine calls with no findings — still logged in full, so the audit trail includes ordinary activity, not just incidents.
Questions
Things people ask before installing.
Make Claude’s tool activity reviewable.
Stay in the loop. Get notified about new detections, releases, and product updates.