Overview
- Anthropic announced on Tuesday that self-hosted sandboxes are now in public beta and MCP tunnels are available as a limited research preview.
- Self-hosted sandboxes move tool execution into customer or managed‑provider infrastructure so files, packages, and network egress stay inside an organization’s boundary.
- MCP tunnels create an outbound‑only, encrypted gateway so Claude agents can call private Model Context Protocol servers without opening inbound firewall ports or exposing services publicly.
- Cloudflare, Daytona, Modal, and Vercel are launch partners with Cloudflare offering microVMs, lightweight V8 isolates, zero‑trust egress controls, and built‑in observability for audited agent runs.
- A core limitation remains: Anthropic still manages the agent loop that handles orchestration, context and recovery, so the setup clears many but not the strictest fully on‑premise compliance requirements and signals a wider industry split of orchestration from execution.