The Claude desktop app is Anthropic’s native application for Claude. It is more than a chat window: Anthropic’s documentation describes three tabs, Chat for conversations, Cowork for longer agentic work, and Code for software development. Once an app can run sessions that read files and take actions, the connections it makes are worth knowing. This article summarises what Anthropic documents, then shows how to watch the app’s network behaviour with FireAI.
What the app is and how it is installed
Anthropic offers the macOS app as a universal build for Intel and Apple Silicon, downloaded as a disk image from claude.ai. After installing, you launch Claude, sign in and, for development work, open the Code tab. Each conversation in the Code tab is a session with its own chat history and project folder, and several sessions can run in parallel.
What it can access and the permission model
In the Code tab, a mode selector next to the send button controls how much autonomy Claude has: whether it asks before editing files, running commands, or both. The documented modes are Manual, Accept edits, Plan and Auto, and a Bypass permissions mode that appears once enabled. For Bypass permissions, Anthropic says to use it only in sandboxed containers or virtual machines. Earlier versions labelled the modes Ask permissions, Auto accept edits and Plan mode.
The desktop documentation also covers computer use, in which Claude acts on your actual desktop. Anthropic states that, unlike the sandboxed Bash tool, computer use runs on your desktop with access to whatever you approve, and that Claude checks each action and flags potential prompt injection from on-screen content. For browsing external sites, safety classifiers review Claude’s write actions, such as clicking and typing, in every permission mode.
The hosts the app documents
Anthropic’s desktop page says the app loads its application code and user content from Anthropic CDN hosts, and lists the domains to allow on a managed network. Traffic is HTTPS on port 443 unless you configure a custom port for OTLP, an LLM gateway or an MCP server.
- anthropic.com and *.anthropic.com
- claude.ai and *.claude.ai
- claude.com and *.claude.com
- claude.app and *.claude.app
- *.claudeusercontent.com, which serves artifacts
- *.claudemcpcontent.com, which serves interactive widgets from some connectors
Anthropic’s network page adds that allowing claude.ai while blocking the CDN hosts, including assets-proxy.anthropic.com, produces a blank page rather than an error, so blocking one of these by hand can break the app in a confusing way. That is a useful reason to review a flagged destination before blocking it.
Where the Code tab shares behaviour with Claude Code
The Code tab is the part of the app built around Claude Code. For proxy variables and custom certificate authorities, Anthropic documents that in sessions where the app manages the provider connection, Claude Code reads them only from managed settings and ~/.claude/settings.json. The companion article on Claude Code lists the additional hosts the command-line tool documents, such as api.anthropic.com and the optional telemetry hosts.
Why watch the app’s connections
The app’s connectors and MCP servers, its previews and its artifacts all reach out to hosts of their own. A firewall cannot tell you what a session did with your files, but it can show which hosts the app contacted and how much data it sent, which is the part you can verify from outside the app.
Watching the Claude desktop app with FireAI
FireAI is a firewall for macOS made by HisnLabs, and since version 1.0.2 it has a feature called Agent profile. It recognises 19 AI agents, learns where each one normally connects, and flags unusual behaviour for you to review. The Claude desktop app is recognised by its code signature, like Claude Code and Cursor.
the Claude desktop app is one of the three agents FireAI checks against its developer’s code signature, so a match is more than a name.
FireAI also recognises the agent’s child processes, such as a shell, git or curl that the agent runs, by walking up the process’s parents until it reaches the agent. Those connections are therefore counted as the agent’s own.
What FireAI flags
- For the first 3 days FireAI learns the destinations the agent normally contacts, grouped by domain. Nothing is flagged during this learning period.
- After that, a first-ever destination outside the learned baseline is flagged for review.
- An upload spike is flagged too: an hour in which the agent sent at least 4 times its busiest hour so far, and never less than 25 MB.
Agent profile uses only metadata, meaning host names and byte counts. FireAI never reads the payload of a connection, and it cannot read inside an encrypted one.
Set it up for the Claude desktop app
- Install FireAI and finish the setup, then keep using the Claude desktop app as you normally do. The 3-day learning period starts from what FireAI sees.
- Open Suggestions and look at the AI agents card. It lists the agents FireAI has recognised and what it has learned about each.
- When the Claude desktop app reaches a destination it has never contacted, the flag appears in the AI agents card and in Quick Review. Swipe left to block, or right for “It’s fine”.
- Block creates a rule for the process that connected. “It’s fine” adds the destination to the agent’s baseline so it is not flagged again.
- If you want the agent kept to the places it already uses, choose Agent profile in the security mode menu, next to Home, Coffee shop, Paranoid and Under attack. Once the agent has finished learning, a connection to a destination outside its baseline is blocked instead of flagged.
- A blocked destination shows in the AI agents card with Allow and Keep blocked. Allow adds it to the baseline and the agent can reach it right away. Keep blocked creates a block rule, so the destination stays blocked in every mode.
Limits
- FireAI does not prevent prompt injection. A prompt hidden in a web page or a file can still steer an agent. What FireAI can do is flag, and let you block, the path data would take out of your Mac.
- FireAI cannot see prompts, the contents of MCP tools, or which files the Claude desktop app reads, such as ~/.ssh. TLS hides the payload, and FireAI is not inside the agent.
- Child processes that exit very quickly may be missed, and child processes are matched by path, not by signature.
- During the 3-day learning period nothing is flagged.
- In the Agent profile mode, a connection to a bare IP address with no host name is matched by its address. If a service the agent normally uses answers from a new address, it is blocked until you allow it.
- FireAI’s plain-words explanation of a flag is written from facts it measured. It never says a destination is safe or dangerous. The decision is yours.
Related guides
The same approach applies to the other agents FireAI recognises: Claude Code, Cursor, the ChatGPT Mac app, Codex CLI, OpenClaw, Hermes Agent, Gemini CLI, GitHub Copilot CLI, Amp, Qwen Code, opencode, Aider, Goose, Crush, Windsurf, Kiro, Trae, Muse from Meta, any other AI agent run by Python or Node. The full feature description is in the Agent profile documentation.
How FireAI and HisnLabs fit in
A desktop assistant that can act on your files should also be visible on your network.
FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac.
You can read the technical decisions behind it, or try FireAI for 17 days, at FireAI, by HisnLabs.
