Integrations

Connect Haven to Claude

Connect your Haven team to Claude, then manage members, seats, protected sites and policy by asking for it in plain language. Claude acts as you, on your team only, using the Haven account you already sign in with.

For Haven team owners and admins Time About 5 minutes You need Owner or admin on a Haven team
On this page
  1. Before you start
  2. The address you need
  3. Connect in Claude
  4. Connect in Claude Code
  5. What you can ask for — people, policy, groups, directory, reporting
  6. If you run several teams
  7. Access and disconnecting
  8. Troubleshooting

Before you start

Worth two minutes so the connection behaves the way you expect.

Haven publishes an MCP server — a standard way for an AI assistant to use a service on your behalf. Connecting it lets you run your Haven team from a Claude conversation instead of clicking through account.starthaven.com. Everything it can do, you can already do there.

You need to be the owner or an admin of a Haven team with an active subscription, and you sign in with the same Haven account you use for the account portal — Google, or email and password. Both work.

What Claude can do

  • See and manage your members, seats, roles and invitations
  • Add seats to your subscription, which is billed
  • Change your protection policy and enforcement mode, which affects every member's browser
  • Manage your groups, protected sites and allowed extensions
  • Read your security reporting — which protected sites were visited and by whom
  • Connect and disconnect your Workspace directory

What it cannot do

  • Touch any other organization's data. It can only act on teams you already administer
  • Read your full browsing history or the contents of pages. The reporting it can see is the same coarse telemetry your console already shows you — a site name, a category, a verdict
  • Give itself access you do not have. It acts as you, with your role
  • Change your plan, cancel your subscription, or delete your account
  • Change your Haven password, or sign anyone in

The address you need

One value. Both setup paths below use it.

Haven MCP server Production
https://account-mcp.starthaven.com
Connector name Haven
Transport HTTP
Sign in with Your Haven account — Google, or email and password
Sign-in page account.starthaven.com
Claude sends you here to approve the connection. Haven never asks for your password inside Claude.
Use the address exactly as written

Paste the address with no extra path on the end. The server publishes that exact hostname as its own identity, so a connection registered at any other address is refused during setup rather than half working.

Connect in Claude

Claude on the web or the desktop app. Custom connectors need a paid Claude plan.

  1. Open Claude and go to:

    Settings › Connectors › Add custom connector
  2. Name it Haven and paste the server address:

    https://account-mcp.starthaven.com
  3. Click Add, then Connect. Claude opens Haven's sign-in page in your browser.

  4. Sign in with your Haven account, the same way you sign in to the account portal.

  5. Read the approval screen — it names the account Claude will act as and lists exactly what it will be able to do — then click Connect Claude.

  6. You land back in Claude with the connector enabled. Ask "which Haven team am I signed in to?" to confirm it works.

Connect in Claude Code

Same server, same sign-in, from the terminal.

Register the server once:

claude mcp add --transport http haven https://account-mcp.starthaven.com

Then start Claude Code and run /mcp. Pick haven and choose to authenticate — your browser opens on the same Haven sign-in and approval screen as above. Once it says connected, the Haven tools are available in that session.

Where the connection lives

The approval is tied to your Haven account, not to a device. Connect from Claude on the web and from Claude Code separately if you use both.

What you can ask for

Ask in your own words. These are the areas behind the answers.

You do not need any of the names below — "invite jo@acme.com as an admin" is enough. They are here so you know the reach. Anything you can configure in the Haven console, you can ask for here.

People and seats "who is on my team?"
See your team Members, roles, seat numbers, email aliases, and invitations that have not been accepted
Invite and remove Invite by email as a member or admin; invitations expire in 7 days. If every seat is taken, one is added automatically and billed. Removing someone does not reduce your seat count, and the owner cannot be removed
Fix mistakes Change someone's role, correct their display name, or correct a mis-typed invitation address — which reissues it, so the original link stops working
Seats and aliases Add seats (billed, up to 30). Register a teammate's other email so Haven recognizes mail from it as internal — they confirm it themselves, and it is not a way to sign in
Protection policy "what are we enforcing?"
See everything at once Your enforcement mode, the categories and sites locked on or denied, allowed extensions, and which optional features are on
Enforcement mode Switch between Monitor-Only and Active Enforce — see the warning below
Locked and denied The categories and sites you force on for everyone, or forbid outright, which members cannot override
Protected sites Add or remove the sites Haven protects for your team, up to 30
Extensions Allow a browser extension so it keeps working on protected sites, remove one, and approve or turn down the requests your team sends you
Enforcement mode changes every member's browser

In Monitor-Only, Haven watches and records but does not interrupt anyone. In Active Enforce, it acts — blocking, warning, and switching off extensions on protected sites. Moving to Active Enforce is the single biggest change you can make by asking, and your team feels it immediately. Ask Claude what the current mode is before you change it.

If your team is inside a monitor-first trial period, the switch to Active Enforce is refused until that period ends. Claude will tell you when it lifts. Switching back to Monitor-Only is always allowed.

Setting policy replaces it

Changing the enforced policy writes the whole thing at once — the lists you end up with become the entire policy, not an addition to it. The same is true of a group's policy. Ask Claude to show you the current policy first, and to confirm the full list back to you before it writes. It will tell you which entries a change removed.

Groups "give the finance team stricter rules"
Create and organize Make a group, rename it, add and remove members. Deleting a group also deletes the policy attached to it — Claude will tell you what it removed
Per-group policy A group can have its own enforcement mode, locked and denied lists, allowed extensions, and optional features
Groups only tighten A group can be stricter than your team, never looser. Setting a group to Monitor-Only will not relax a team that is enforcing, and a group's locked sites are added to the team's rather than replacing them
Workspace directory "sync my Google groups"
Check the connection Whether a directory is connected, which domain and admin it uses, when it last synced, and which of your Google groups are mapped to Haven groups
Map and sync Bind a Google group to a Haven group, then reconcile membership — either one group or all of them. People in a Google group who are not yet Haven members are skipped, and Claude will list them so you can invite them
Disconnecting is one-way Claude can disconnect the directory, but it cannot reconnect one — that needs you at a browser to approve Google's consent screen again. Your groups and their members stay as they are; they simply stop syncing
Reporting "what's our security posture this week?"
The overview How much of your team has Haven installed, who is carrying a risky extension, and activity across the org — then ask who is behind any number
The Browser Risk Report The report you would take to a review: coverage, risky extensions and who has them, sensitive sites visited, link verdicts, campaigns hitting more than one person, out-of-date browsers, and what to do about it
One person A member's installed extensions and the individual phishing warnings and paused downloads behind their totals
This is the part worth connecting for

Reporting is where asking beats clicking. "Compare this month's risky extensions to last month, and tell me which of them are on more than two machines" is one question here and a lot of clicking in the console.

Claude sees the same coarse telemetry your console does — a site name, a category, a verdict — never a full browsing history or the contents of a page. And when a part of a report cannot be loaded, Claude will say so rather than reporting a zero, so an outage never looks like a clean week.

If you run several teams

Skip this if you administer exactly one team, which is most people.

Managed service providers and anyone owning more than one organization can reach each of them from the same connection. Two things make that safe:

  • Claude never guesses which team you mean. Ask it to do something without naming one and it lists your teams and waits, rather than picking the first.
  • Every answer names the team it acted on. If the wrong name comes back, you know before the next request.

Start with "list my Haven teams", then name one in each request: "in Globex, who has an admin role?". A name Haven does not have you down as administering is refused, and nothing is sent.

Nothing is remembered between requests. There is no current team to get out of step with what you meant, which is deliberate.

Access and disconnecting

Who Claude is when it acts, and how to stop it.

Claude acts as you. It carries your own Haven sign-in, so it has exactly your permissions on exactly the teams you administer, and Haven checks that on every single request — not once at setup. If your role is reduced or your access ends, the connection loses the same access at the same moment.

To disconnect:

  • Remove the Haven connector in Claude's connector settings, or run claude mcp remove haven in Claude Code. That ends it for that Claude.
  • To end it everywhere at once, sign out of Haven on all devices from account.starthaven.com. Any connected Claude loses access immediately.

Troubleshooting

The five things that come up most often.

Claude will not add the connector, or setup fails right after I paste the address

Almost always the address. It must be exactly https://account-mcp.starthaven.com, with no trailing slash, no path, and no other hostname. The server publishes that hostname as its own identity, so Claude refuses a connection registered at a different one.

Custom connectors also need a paid Claude plan. If Add custom connector is missing from Claude's settings, that is why.

Claude says I do not administer any team

The connection works and you are signed in — Haven simply does not have you down as an owner or admin of a team. Two common reasons: you are a member rather than an admin, or the team's subscription has lapsed, which puts team management out of reach until it is active again.

Sign in to account.starthaven.com and check what you see there. Claude can do exactly what that page lets you do, no more.

I signed in to Haven but Claude still says it is not connected

The approval screen was not completed. Signing in is only the first half — the connection is made when you click Connect Claude on the screen that lists what Claude will be able to do.

Start the connection again from Claude and follow it through to that button. If the browser tab was closed early, nothing was granted.

Claude acted on the wrong team

This is possible only across teams you genuinely administer — Haven refuses anything else. Every answer names the team it acted on, so check that line first.

Name the team in each request rather than relying on a default: "in Globex, invite jo@acme.com". Ask Claude to list your teams if you are not sure of the exact names.

Will Claude add seats or spend money without asking?

Adding seats is billed, and inviting someone when every seat is taken adds one seat automatically. Both are things you asked for, and Claude tells you what it did, but neither needs a second confirmation step from Haven.

If you want to be sure, ask for your seat count before inviting: "how many Haven seats are free?"

Still stuck?

Tell us what you asked Claude, what came back, and the email address you signed in with, and we will help you sort it.

Contact Haven support