Claude Managed Agents Add Self-Hosted Sandboxes (Public Beta) and MCP Tunnels (Research Preview)
Anthropic says Claude Managed Agents can now run tool execution in a sandbox you control (public beta) and connect to private MCP servers via MCP tunnels (research preview). The update targets enterprise security requirements by keeping execution and private services within an organization’s perimeter.
Anthropic announced two security-focused additions to Claude Managed Agents: self-hosted sandboxes (public beta) and MCP tunnels (research preview).
Together, the features are aimed at a common enterprise blocker: teams want to run agent tool execution and connect to internal services without moving execution or private systems outside their security perimeter.
Self-hosted sandboxes (public beta)
Anthropic says self-hosted sandboxes let Claude Managed Agents run tool execution inside an environment you control.
Key details Anthropic describes:
- The sandbox can run on your own infrastructure, or through managed providers like Cloudflare, Daytona, Modal, or Vercel.
- The agent loop for orchestration, context management, and error recovery stays on Anthropic’s infrastructure, while tool execution moves to your configured environment.
- Anthropic says this helps keep files and repositories within your perimeter and lets you apply existing network policies, audit logging, and security tooling.
- You control compute characteristics like resource sizing and the runtime image.
MCP tunnels (research preview)
Anthropic says MCP tunnels let agents connect to private Model Context Protocol (MCP) servers inside your network without exposing them to the public internet.
Key details Anthropic describes:
- A lightweight gateway you deploy makes a single outbound connection.
- Anthropic says there are no inbound firewall rules required and no public endpoints, and that traffic is encrypted end-to-end.
- Anthropic says MCP tunnels work with both Managed Agents and the Messages API.
- Anthropic says MCP tunnels are managed from workspace settings in the Claude Console by organization admins.
Availability
| Feature | Availability | Notes |
|---|---|---|
| Self-hosted sandboxes | Public beta | Available on the Claude Platform |
| MCP tunnels | Research preview | Request access required |
Sources
- ClaudeDevs announcement post (May 19, 2026): https://x.com/ClaudeDevs/status/2056740346529468717
- Claude blog post, “New in Claude Managed Agents: self-hosted sandboxes and MCP tunnels” (May 19, 2026): https://claude.com/blog/claude-managed-agents-updates
Read next
Keep building the workspace playbookClaude Opus 4.7 Is Here: State-of-the-Art Coding, xhigh Effort, and a New Cyber Safeguards Tier
Anthropic launched Claude Opus 4.7 on April 16, 2026 -- a notable improvement on Opus 4.6 in advanced software engineering, with the same pricing, a new xhigh effort level, /ultrareview in Claude Code, higher-resolution vision, and the first deployment of cyber safeguards from the Mythos Preview track.
Claude Design Launches: Anthropic Labs Turns Opus 4.7 Into a Prototype, Deck, and Wireframe Surface
Anthropic launched Claude Design on April 17, 2026 -- a research preview from Anthropic Labs that turns a prompt, uploaded image, or codebase into polished prototypes, pitch decks, and mockups. Powered by Claude Opus 4.7 vision, it learns your team's design system, exports to Canva, PDF, PPTX, or HTML, and packages finished designs for Claude Code handoff.
Frequently Asked Questions
What are self-hosted sandboxes in Claude Managed Agents?
Anthropic says self-hosted sandboxes let Claude Managed Agents operate in a sandbox you control, running on your own infrastructure or with managed providers like Cloudflare, Daytona, Modal, or Vercel.
What are MCP tunnels?
Anthropic says MCP tunnels let agents reach private Model Context Protocol (MCP) servers inside your private network without exposing them to the public internet, using a lightweight gateway that makes a single outbound connection.
What’s the availability of these features?
Anthropic says self-hosted sandboxes are available in public beta on the Claude Platform, while MCP tunnels are in research preview and require requesting access.