update
May 26, 2026
By Teun
Anthropic Adds Self-Hosted Sandboxes and MCP Tunnels
Anthropic said Claude Managed Agents can now run in self-hosted sandboxes and connect to private Model Context Protocol, or MCP, servers through MCP tunnels. The company announced the features at Code w/ Claude London 2026, and said teams including Amplitude, Clay and Rogo are already using the managed agents setup.
Anthropic used its Code w/ Claude London 2026 event to announce two new capabilities for Claude Managed Agents: self-hosted sandboxes and MCP tunnels.
The conference, held in London this week, brought together builders, developers and founders for two days of keynotes, breakout sessions and workshops with the teams behind Claude. Anthropic said the event was meant to show how teams are using Claude Code and related products to build software with less friction between an idea and a working program.
In the opening keynote, Boris Cherny, head of Claude Code, said he first felt the “magic” of coding as a student writing TI-83 programs and HTML for eBay listings. He argued that programming later became more complicated as compilers, typecheckers and build systems added more layers between “I have an idea” and “it runs.” According to Cherny, agents are reducing that gap again by letting developers describe a problem and get a program back.
Anthropic said it demonstrated that idea through workshops on using Claude Code beyond the basics, as well as sessions on adjusting thinking budgets and effort levels across its models. The company also pointed to customer examples from Spotify, Base44 and Legora.
The biggest product announcement was that Claude Managed Agents can now operate in a sandbox controlled by the customer and connect to private MCP servers. Anthropic said this means both the place where the agent executes tools and the services it reaches can stay inside enterprise boundaries.
Self-hosted sandboxes are in public beta. Anthropic said tool execution moves to an environment the customer configures, either on its own infrastructure or through a managed provider such as Cloudflare, Daytona, Modal or Vercel. The agent loop that handles orchestration, context management and error recovery remains on Anthropic’s infrastructure.
The company said this setup keeps files and repositories from leaving the customer’s perimeter, while network policies, audit logging and security tooling still apply. It also gives customers control over compute sizing and the runtime image for compute-heavy tasks.
Anthropic also announced MCP tunnels in research preview. MCP stands for Model Context Protocol, a way for agents to connect to tools and services. With tunnels, agents can reach MCP servers inside a private network without exposing them to the public internet.
According to Anthropic, the tunnel uses a lightweight gateway that makes a single outbound connection. The company said that avoids inbound firewall rules and public endpoints, while keeping traffic encrypted end to end. MCP tunnels are supported in Managed Agents and the Messages API, and organization admins manage them in the Claude Console.
Anthropic said teams including Amplitude, Clay and Rogo are already building on Managed Agents with self-hosted sandboxes. The company told developers to use the docs, follow its cookbooks or request access to MCP tunnels. It also said recordings from the London keynote and breakout sessions are available, and that Code w/ Claude will next head to Tokyo on June 5 and 6, with Day 1 sessions streamed live.