Observed Signal · May 20, 2026 · Technical Release · Source: DEV Community · Impact: 3/5 · Sentiment: Positive

Anthropic adds MCP tunnels and self-hosted sandboxes

Executive Signal Summary

Anthropic has released two infrastructure features for Claude agents: MCP tunnels and self-hosted sandboxes, both designed to enable safe enterprise deployment inside customer security perimeters. MCP tunnels create outbound-only connections (using Cloudflare as the transport layer) to allow Anthropic to reach privately hosted MCP servers without opening inbound firewall ports; the tunnel carries multiple encryption layers and uses OAuth per MCP server so Cloudflare can see metadata but not payloads. Self-hosted sandboxes move tool execution into customer-run infrastructure via a lightweight environment worker that polls Anthropic’s work queue and executes tool calls locally. Both features are in Research Preview and target regulated industries with data residency, isolation, and audit requirements; access must be requested.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

These controls lower enterprise adoption friction for agentic LLM deployments by addressing network isolation, data residency, and execution locality—critical for regulated industries and production agent governance.

SIGNAL RADAR

Track Anthropic Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Anthropic introduced MCP tunnels to let Claude connect to private MCP servers via an outbound-only connection using Cloudflare as transport.
  • MCP tunnels implement three encryption/authentication layers: mutual TLS between Anthropic and the tunnel edge, inner TLS between Anthropic backend and customer proxy, and OAuth per MCP server; Cloudflare can see metadata but not MCP payloads.
  • Self-hosted sandboxes run agent tool execution inside customer infrastructure using an 'environment worker' that polls Anthropic’s work queue, claims sessions, downloads skills, executes tools locally, and posts results back.
  • Pre-built environment workers exist for Cloudflare, Daytona, Modal, and Vercel; self-hosted sandboxes are not yet available on AWS Bedrock / Claude Platform on AWS.
  • Both MCP tunnels and self-hosted sandboxes are in Research Preview and require requesting access from Anthropic.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: May 20, 2026
Original Coverage Title: “Anthropic's MCP tunnels and self-hosted sandboxes: keeping agents inside your perimeter”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Sandboxing / Runtime Security for AI dev toolingMay 31, 2026

Anthropic Open-Sources Sandbox Runtime for MCP

Anthropic has open-sourced sandbox-runtime, a lightweight sandboxing layer (with CLI 'srt') designed to restrict filesystem and network access for locally run MCP (Model Context Protocol) servers. On macOS it uses sandbox-exec with dynamically generated Seatbelt profiles; on Linux it uses bubblewrap plus network namespace isolation. Network traffic from sandboxed processes is forced through host proxies that enforce domain allowlists. Developers can wrap MCP servers by replacing npx with srt in .mcp.json and configure permissions in ~/.srt-settings.json (denyRead, allowWrite, allowedDomains). Anthropic describes the tool as a beta research preview and the source is available for audit and integration.

Read assessment
Large Language Models (LLM) & AIApr 8, 2026

Anthropic Launches Claude Managed Agents

Anthropic launched Claude Managed Agents on April 8, 2026 — a managed runtime and composable API set for building and deploying production AI agents on Anthropic’s cloud without requiring teams to build their own runtime infrastructure. The product targets infrastructure needs such as secure sandboxing, session persistence, credential isolation, error recovery and observability. At launch five enterprise customers were already in production: Notion, Rakuten, Asana, Sentry and Atlassian. Anthropic’s pricing adds standard Claude API token rates plus $0.08 per session-hour of active runtime; the company positions the service as eliminating the need for servers, containers, or DevOps for agent runtimes. Customer outcomes cited at launch include Rakuten cutting critical errors by 97% and accelerated release cadence; Sentry and Asana reported large reductions in time-to-resolution and development velocity improvements.

Read assessment
Large Language Models (LLM) & AIApr 11, 2026

Anthropic Launches Claude Managed Agents Public Beta

Anthropic announced Claude Managed Agents, a hosted agent execution environment in public beta (April 2026). The service provides a managed runtime that separates reasoning (Claude models) from tool execution, offering sandboxed execution, long-running sessions, automatic checkpointing, credential vaulting, and a built-in toolset (bash, file ops, web search, code execution). API access requires the beta header anthropic-beta: managed-agents-2026-04-01 and the Python SDK exposes create/read session flows and SSE streaming. Runtime pricing is $0.08 per session-hour plus normal model token costs; examples use models like claude-opus-4-6 and claude-haiku-4-5. Research-preview features include an Outcomes API, multi-agent orchestration, and persistent memory. Anthropic positions Managed Agents as a faster alternative to self-hosted agent infrastructure while noting trade-offs around vendor lock-in and data residency; competitors include AWS Bedrock Agents and Google Vertex AI Agents.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.