WireCanalby Qualiteg
smart_toy Connection guide

Use your in-house MCP server from Claude

From creating the canal to registering a custom connector in claude.ai, granting approval, and verifying it works. A careful step-by-step walkthrough with screenshots of the actual screens.

What this guide covers

We will make the MCP server running on your local (in-house) machine usable from claude.ai — without opening any inbound ports. The flow has 4 parts: create a canal in WireCanal → start the Agent → register the connector in Claude → approve the connection.

First, set things up on the WireCanal side

1

Create a canal — choose "MCP" as the type

On the dashboard, click "Create a new canal", choose MCP as the type, and click "Next".

Canal creation wizard: choosing MCP as the type
Select "MCP" in the creation wizard
2

Check "Claude" under "Which AI will you use?"

Just pick the AI you will use, and the connection settings for that AI are prepared automatically. Here, check Claude.

Which AI will you use: checking Claude
Select Claude under "Which AI will you use?"
3

Choose the public address

For the public address (hostname), the "auto-assigned subdomain" is fine. You can also reserve a name of your choice or use a custom domain.

Choosing the public address
Leaving it on "auto-assigned subdomain" is fine
4

Set the forwarding target to your local MCP server

For the forwarding target, enter the address of the MCP server running on your machine (e.g. localhost:9310).

Entering the forwarding target
Set the forwarding target to your local MCP server
5

Review and create

Confirmation screen
Review the type, public address, forwarding target, and AI selection, then click "Create"
lightbulbNo need to note down the client ID and secret

Right after creation, the "MCP connection" tab shows client credentials — but for Claude, you connect by simply pasting the canal URL (the necessary settings are configured automatically). The client credentials are only for cases where you want to configure things manually.

6

Decide which tools to expose, and start the Agent

Download the configuration file wirecanal.json from the "Setup" tab, and list only the tool names you are willing to show to the outside AI in tools.allow (the default is deny-all). For the syntax and all options, see the wirecanal.json configuration reference.

wirecanal.json on the Setup tab
The "Setup" tab. This local json is the one and only allowlist
wirecanal.json
{
  "access_key": "ck_...",
  "forward_target": "localhost:9310",
  "mode": "mcp",
  "tools": { "default": "deny", "allow": ["get_time", "echo"] }
}

Start the Agent on the same machine. No inbound ports need to be opened. If you have not installed the Agent yet, or want to keep it running as a service (auto-start), see the OS-specific setup guides.

terminal
wirecanal.exe -config wirecanal.json

When the startup log shows a line saying that canal <ID> will deliver access to https://<hostname> to your local forwarding target, the connection is established.

That completes the WireCanal side. Now, over to Claude.

Setting up on the Claude side

7

Open the connector settings

In claude.ai, open Settings → CustomizeConnectors.

The connector settings screen in claude.ai
Settings → Customize → Connectors
8

Choose "Add custom connector"

Click "Add" at the top right, then choose "Add custom connector".

Adding a custom connector from the Add menu
"Add" menu → "Add custom connector"
9

Enter a name and the URL, then add it

lightbulbNo need to open "Advanced settings"

The OAuth Client ID / client secret under "Advanced settings" can be left empty (client registration is automatic). Only if you want to configure them manually, open "Advanced settings" and paste the client ID / secret from the canal's "MCP connection" tab.

The custom connector form in claude.ai
Enter the name and URL, then click "Add". No need to open Advanced settings
10

Click "Connect" to start the connection

On the screen for the connector you just added, click "Connect" — WireCanal's connection-consent screen will open.

The connector screen right after adding
Right after adding, it is not yet connected. Click "Connect"
11

Approve the connection

"Claude is requesting a connection to your canal" — review the details and simply click "Approve". Only the canal owner can grant approval.

lightbulbStay logged in on the same browser

Log in to both Claude and WireCanal in the same browser (same profile). If they are split across profiles, a login screen will open instead of the consent screen.

WireCanal's connection-consent screen
WireCanal's consent screen. Click "Approve" and the connection is complete
12

Connected — review the tool permissions

Once connected, the connector screen shows the tool list of your local MCP server along with its permission settings.

A connected connector and its tool permissions
Connected. You can choose when Claude may use each tool
13

Try it out

Just call the tool in a chat. The first time, a confirmation appears per tool — click "Always allow" once.

Tool usage confirmation
A usage confirmation appears the first time. "Always allow" makes it automatic from then on

For example, ask "Use get_time to tell me the current time in Japan" — and the real data returned by your local MCP server is used in Claude's answer.

Calling the tool from a Claude chat
If real data from your local MCP server comes back, it works
verified_userTools you have not allowed do not get through, even if called

If a tool is not in tools.allow, the local Agent refuses it on the spot even when the AI tries to call it. The decision about which tools to show always stays on your side (two-key).

No open ports. Connect from anywhere.

Sign-up is free. No credit card required — create your first canal right now.

Sign up free and get started