Skip to content
sandadocs

Connect Claude

Add sanda to Claude as a custom connector, sign in, choose what Claude may do, and check that it works. Claude Code and the Claude API use a token.

Claude on the web and Claude Desktop connect to sanda as a custom connector. You paste one address, sign in to sanda, and choose what Claude may do. There is no key to copy and nothing to store.

Claude Code and the Claude API are set up once by a person and then used by a machine, so they hold an integration token instead. Both are covered below.

Before you start

  • Your workspace is on Standard or Enterprise, or on a trial. On Basic, sanda refuses the connection. See editions.
  • You are a member of the workspace. Any role except reader can connect Claude to ask questions. Only an owner or admin can grant the permissions that write, run SQL or send email. A person with the reader role cannot connect anything.
  • Something is on the map. Claude answers from the semantic fluid, so it needs at least one table there, and a metric to be useful. Intelligence · Agents shows a Harness panel that tells you which of these is missing.
  • Your Claude plan allows custom connectors. If your Claude organisation is managed by an administrator, they may need to add the connector for the organisation first.

Connect Claude on the web or in Claude Desktop

Menu names in Claude change from time to time, so look for the connectors section of Claude's settings. What you need is a name for the connector and sanda's address.

  1. Copy sanda's address. In the console, open Settings · Integrations and press the copy button beside MCP endpoint. It is the same for every workspace:

    Text
    https://console.sanda-os.com.au/api/mcp
  2. Add a custom connector in Claude. Open Claude's settings, go to its connectors, and choose to add a custom connector.

  3. Name it and paste the address. Call it sanda and paste the address. You do not need a client ID or a secret. If the form offers advanced settings for them, leave them empty.

  4. Connect. Claude opens sanda in a browser tab. If you are not signed in to sanda, sign in first. You come back to the consent screen on your own afterwards.

  5. Read the consent screen and choose what Claude may do (below).

  6. Press Allow. Claude takes you back and the connector shows as connected.

The screen has one job, which is to ask you a clear question. It is deliberately bare, with no console navigation around it.

Part What it tells you
The heading, which is the app's name followed by "wants to use your sanda data" Which app is asking, and the account you are signed in as. Only you can approve it, and you can disconnect it later under Settings · Integrations
It will be sent back to The web address sanda will return your browser to when you finish. Check it belongs to the app you started from
Which workspace The one workspace this grant reaches. If you belong to several, pick one
What it will be able to do One tick box per permission, each written as a sentence

The reading permissions are ticked: asking questions and, if the app asked for it, seeing connections and warehouses. Every permission that writes, runs SQL of its own or starts something starts unticked, and you tick only what the job needs. If you are not an owner or admin, the permissions that only an owner or admin can grant are greyed out with the note "Only a workspace owner or admin can grant this. It will be left out."

The note under the tick boxes follows what is ticked. While everything ticked only reads, it says the app can write nothing. Tick a permission that changes something (committing SQL, changing what is modelled, loading or adding rows, defining views, managing search, emailing reports or starting syncs) and the note says so instead, naming each one, with a warning sign beside it.

Press Allow followed by the app's name to approve, or Refuse to stop. Allow stays disabled until a workspace is chosen and at least one thing is ticked.

Start with the defaults. You can connect again later with different permissions: approving the same app again replaces the earlier grant. To widen what Claude may do, disconnect the connector in Claude, add it again, and tick more on the consent screen.

Check that it works

  1. Start a new conversation in Claude and make sure the sanda connector is switched on for it.
  2. Ask a question of your data. For example: "What metrics does sanda have?" Claude should call search_fluid and list what your workspace has modelled.
  3. Open Intelligence · Agents in the console. The connector appears under Agents as a connected app, and the call appears under Activity within about ten seconds. The Sessions tab refreshes itself every 10 seconds while you watch it.

If Claude says it cannot see any metrics, read the Harness panel first. The commonest cause is that definitions are waiting for review: an assistant sees only what has been accepted.

Connect Claude Code

Claude Code holds an integration token. An owner or admin creates one, then you add sanda as a remote server:

Add sanda to Claude Code
claude mcp add --transport http sanda https://console.sanda-os.com.au/api/mcp \
  --header "Authorization: Bearer bat_your_token_here"

The console shows this command with your new token already filled in, once, when you create the token.

Connect the Claude API

To give a Claude API request access to sanda, add sanda to the request's mcp_servers and add a matching toolset:

A Messages API request, abridged
{
  "mcp_servers": [
    {
      "type": "url",
      "url": "https://console.sanda-os.com.au/api/mcp",
      "name": "sanda",
      "authorization_token": "bat_your_token_here"
    }
  ],
  "tools": [{ "type": "mcp_toolset", "mcp_server_name": "sanda" }]
}

The MCP connector is a beta feature of the Claude API, so the request also needs its beta flag. Check Claude's documentation for the current name.

Disconnect Claude

To end access, open Settings · Integrations. A connected app is listed with the label "connected app", who connected it and when it was last used. Press Disconnect. The next call Claude makes fails. Removing the connector inside Claude does not by itself tell sanda, so disconnect it here too.

Owners and admins see every member's connected apps and can disconnect any of them. Everyone else sees their own.

A connection also stops when the person who approved it leaves the workspace. If they stay but are no longer an owner or admin, the permissions that need one are ignored and the row is marked "permissions inactive". Everything else it holds still works.

If it does not connect

You see Why What to do
"This workspace requires two-step sign-in" on the consent screen The workspace you chose asks every member to set up two-step sign-in, and you have not. This applies to the workspace you connect, even if you are signed in to a different one Set up an authenticator app in the console, then connect again
"Your access to this workspace is to its reports portal, so it cannot be connected to an assistant" Your role is reader Ask an owner or admin to connect it, or to change your role. See members and roles
"That redirect address is not one this client has registered" The app asked sanda to send you somewhere it never registered, so sanda refused Close the tab and start again from the app. Nothing was granted
Claude connects but a tool is missing The tool needs a permission you did not tick Disconnect, connect again and tick it. Permissions that write need an owner or admin
Claude connects but finds no metrics Nothing on the map, or definitions still waiting for review Check Harness on Intelligence · Agents, then review proposals in the semantic fluid

More help is in troubleshooting.

Next steps

Something unclear or out of date? Tell us, and we will fix the page.