Particle.news

Anthropic Lets Enterprises Run Claude Agent Tooling Inside Their Networks

The change gives companies control over where agent code runs while Anthropic continues to host the agent orchestration layer.

Overview

  • Anthropic announced on Tuesday that self-hosted sandboxes are now in public beta and MCP tunnels are available as a limited research preview.
  • Self-hosted sandboxes move tool execution into customer or managed‑provider infrastructure so files, packages, and network egress stay inside an organization’s boundary.
  • MCP tunnels create an outbound‑only, encrypted gateway so Claude agents can call private Model Context Protocol servers without opening inbound firewall ports or exposing services publicly.
  • Cloudflare, Daytona, Modal, and Vercel are launch partners with Cloudflare offering microVMs, lightweight V8 isolates, zero‑trust egress controls, and built‑in observability for audited agent runs.
  • A core limitation remains: Anthropic still manages the agent loop that handles orchestration, context and recovery, so the setup clears many but not the strictest fully on‑premise compliance requirements and signals a wider industry split of orchestration from execution.