Claude Managed Agents now includes two security improvements designed to give organizations greater control over agent execution. Self-hosted sandboxes keep the agent’s execution environment within an organization’s own infrastructure or with a managed sandbox provider. MCP tunnels enable agents to connect to services inside a company’s security perimeter.
The updates address deployment concerns for teams managing sensitive workloads. Organizations can now maintain full control over where Claude Managed Agents run their code and which services they access. Support for self-hosted sandboxes includes integration with Cloudflare, Daytona, Docker, Modal, and Vercel.
Session Management and Performance Improvements
Claude Managed Agents now supports live session tool swapping without requiring a restart. Users can switch tools, MCP servers, or vault IDs while a session remains active. This capability simplifies workflow adjustments during agent operations.
The platform also improved handling of large MCP tool outputs. Tool responses exceeding 100,000 tokens are automatically offloaded to Sandbox files. This prevents token limits from constraining agent functionality when processing substantial data sets.
Developer Resources and Documentation
Anthropic published cookbooks for self-hosted sandbox implementation across popular deployment platforms. Documentation covers setup procedures for each supported provider. A new Claude API skill bundled with Claude Code offers developers quick access to agent management functions.
Technical guidance is available through official documentation and a dedicated launch blog post. These resources help development teams onboard to the new sandbox capabilities and understand integration patterns for their security infrastructure.
Industry Context and Business Applications
Organizations increasingly require tools that operate within strict security boundaries. The ability to run Claude Managed Agents in self-hosted environments addresses compliance requirements for regulated industries. MCP tunnel support reduces the need for agents to access external networks, lowering exposure risk. These improvements position Claude Managed Agents for deployments where infrastructure control and data isolation are business requirements.
The security enhancements reflect growing demand for agent platforms that maintain data within enterprise boundaries. Self-hosted sandbox options provide flexibility for organizations with varying infrastructure preferences and compliance mandates. By supporting multiple deployment providers, Claude Managed Agents enables teams to select sandbox solutions aligned with their existing technology stacks and security policies.
Source: X (@ClaudeDevs)




