# Claude Agents Get Private Sandbox _Anthropic's Claude Managed Agents now offer self-hosted sandboxes and MCP tunnels, bringing agent execution and private service access under enterprise control._ **Updated:** 2026-07-21 **Published:** 2026-05-19 **Source:** https://www.startuphub.ai/ai-news/startup-news/2026/claude-agents-get-private-sandbox --- Anthropic is giving enterprises more control over its Claude Managed Agents. Starting today, the AI agents can execute within self-hosted sandboxes, keeping compute and sensitive data within a company's own infrastructure or managed provider environments. This update also introduces Model Context Protocol (MCP) tunnels, enabling agents to connect to private servers and internal services without exposing them to the public internet. ## Keep Agent Execution In-House With self-hosted sandboxes, the sensitive files, packages, and services agents interact with remain within the enterprise's boundaries. While the core agent loop stays on Anthropic's infrastructure, the actual tool execution happens in a customer-controlled environment. This allows organizations to leverage their existing network policies, audit logging, and security tooling. Compute resources are also under direct control, letting businesses allocate specific CPU, memory, and capacity for demanding tasks like builds or image generation. ## Choose Your Sandbox Provider Customers can bring their own sandbox clients or utilize supported providers. Cloudflare offers scalable sandboxes using microVMs and isolates with granular control over outbound requests and secrets injection. Daytona provides stateful, composable sandboxes accessible via SSH or authenticated URLs, designed for long-running tasks. Modal offers a cloud platform optimized for AI workloads, providing scalable compute and storage primitives. Vercel combines VM security with rapid startup times, integrating with cloud environments and managing credentials at the network boundary. ## Secure Access to Private Services MCP tunnels are designed for secure connectivity to internal resources. A deployed gateway establishes a single outbound connection, eliminating the need for inbound firewall rules or public endpoints. Traffic is encrypted end-to-end, ensuring that internal databases, private APIs, and knowledge bases can be safely leveraged as agent tools. MCP tunnels are available in Managed Agents and the Messages API, managed via workspace settings in the Claude Console. --- Original analysis from [startuphub.ai](https://www.startuphub.ai), the #1 AI startup directory.