Self-hosted sandboxes
Run Claude Managed Agents sessions in self-hosted sandboxes, keeping tool execution, files, and network egress in your own infrastructure.
By default, Managed Agents executes tools and code inside Anthropic-managed cloud sandboxes. Self-hosted sandboxes keep the orchestration on Anthropic's side but move tool execution into infrastructure you control. The agent's files, processes, and network traffic stay in your environment.
Self-hosting is a good fit when the agent needs to:
- Operate on data that cannot leave your network boundary
- Reach internal services that are not publicly routable
- Run under your organization's own compliance and audit controls
How it works
A self_hosted environment acts as a work queue. You run an environment worker, a process on your own infrastructure that serves that queue:
- You create a session that targets the environment. Anthropic enqueues the session as a work item.
- Your worker claims the work item and downloads the agent's skills and the session's memory stores.
- Claude runs on Anthropic's side and requests tool calls. Your worker runs each call locally and posts the result back.
Tool inputs and outputs still flow to Anthropic's control plane, so the model can see results and determine what to do next. Anthropic stores skills and memory stores. Your sandbox holds a copy for the session. See Security model for the full data-flow boundary.
Self-hosted sandboxes support every Claude model available in Managed Agents. The model is configured on the agent, not the environment.
The ant CLI and the Python, TypeScript, and Go SDKs ship pre-built workers. Sandbox providers such as Cloudflare, Daytona, and Modal also publish their own platform guides.
Quickstart
This quickstart runs one always-on worker with the ant CLI, sends it a session, and confirms that the agent's tool calls ran on your host.
Prerequisites
- An agent: If you don't have one, complete Get started with Claude Managed Agents first and note the agent ID.
- A Linux host: The host needs
/bin/bashat that exact path. The worker needs only outbound HTTPS. - A Claude API key: You use it from your own machine to create sessions and read queue stats. Keep it off the worker host, where agent tool calls could read it.
- The
antCLI on your own machine: The session and stats commands in this quickstart run there, not on the worker host. Install it the same way the install step does for the worker.
Run your first session
Create a self-hosted environment
In the Console: Workspace > Environments > New > Self-hosted
Or through the API:
ant apply environment.yamlenvironment.yaml# yaml-language-server: $schema=https://platform.claude.com/schemas/ant/beta/environment.json name: self-hosted config: type: self_hostedGenerate an environment key
In the Console, open the environment and click Generate environment key. The environment key authenticates the worker to its queue. You can generate one only in the Console, even for an environment you created through the API.
Export the environment ID and key on the worker host:
export ANTHROPIC_ENVIRONMENT_KEY="sk-ant-oat01-..." export ANTHROPIC_ENVIRONMENT_ID="env_..."Install the ant CLI
Run this on the worker host.
curl (Linux/WSL)For Linux environments, download the release binary directly.
VERSION=1.38.0 OS=$(uname -s | tr '[:upper:]' '[:lower:]') case $(uname -m) in x86_64) ARCH=amd64 ;; aarch64) ARCH=arm64 ;; esac curl -fsSL "https://github.com/anthropics/anthropic-cli/releases/download/v${VERSION}/ant_${VERSION}_${OS}_${ARCH}.tar.gz" \ | sudo tar -xz -C /usr/local/bin antYou can find all releases on the GitHub releases page.
Homebrew (macOS)brew install anthropics/tap/antStart the worker
Create the working directory, then start the worker.
--workdirdefaults to the current directory, so pass/workspaceto match the system default.sudo mkdir -p /workspace && sudo chown "$USER" /workspace ant beta:worker poll --workdir /workspaceThe worker reads the two variables you exported and polls until you stop it.
Verify the worker is connected
On your own machine, set
ANTHROPIC_API_KEYto your Claude API key (not the environment key) andANTHROPIC_ENVIRONMENT_IDto the environment ID. Confirm thatworkers_pollingis at least 1:ant beta:environments:work stats --environment-id "$ANTHROPIC_ENVIRONMENT_ID"If
workers_pollingstays at 0, see Troubleshooting.Start a session
Set
AGENT_IDto your agent's ID. Create a session that targets the environment, then send it a task:SESSION_ID=$(ant beta:sessions create \ --agent "$AGENT_ID" \ --environment-id "$ANTHROPIC_ENVIRONMENT_ID" \ --transform id --raw-output) ant beta:sessions:events send --session-id "$SESSION_ID" <<'YAML' events: - type: user.message content: - type: text text: Write the output of "uname -a" to hello.txt in your working directory. YAMLThe session waits in the environment's queue until a worker claims it. If no worker is connected, the session stays queued rather than failing.
Confirm the tools ran on your host
On the worker host, read the file the agent wrote:
cat /workspace/hello.txtThe file describes your own host's kernel, so the agent's tool calls ran there. To follow the agent's work as it happens, see Session event stream.
How it differs from cloud environments
| Cloud environment | Self-hosted sandbox | |
|---|---|---|
| Where tools run | Anthropic-managed sandboxes | Your infrastructure |
| Network reach | Anthropic's egress controls | Your network policy |
| File and GitHub repo mounting | Managed by Anthropic | Managed by you |
| Memory stores | Mounted by Anthropic at /mnt/memory/ | Downloaded to /mnt/memory/ and synced by the worker |
| Lifecycle | Managed by Anthropic | Managed by you |
For Zero Data Retention and HIPAA BAA eligibility, see API and data retention.
Session resources
Self-hosted sandboxes support memory_store resources only. A session on a self-hosted environment that includes a file or github_repository resource is rejected with a 400 error:
Environment env_... is a self-hosted environment. `resources` are not supported with self-hosted environments.Deployments that target a self-hosted environment follow the same rule. To give a session its own input files, see Stage files for a session.
Self-hosted sandboxes and MCP tunnels
Self-hosting controls where the agent's code executes. MCP tunnels control how Anthropic reaches MCP servers in your network. The two are independent:
- A session in Anthropic's cloud sandboxes can reach private MCP servers through a tunnel.
- A self-hosted session can use either tunneled or public MCP servers.
Use both when you want execution and tool access to stay inside your boundary. To skip the tunnel, wrap the MCP server as custom tools that your worker serves.
Platform guides
These pages describe how to build a worker on any sandboxing platform. Platform-specific guides are also available:
- AWS Lambda MicroVMs
- Blaxel
- Cloudflare
- Daytona
- E2B
- Fly.io
- GKE Agent Sandbox
- Modal
- Namespace
- Superserve
- Vercel
Next steps
Run the SDK worker, trigger workers from webhooks, or give each session its own sandbox.
Prepare the host, configure sync, and handle read-only stores and conflicts.
Serve your own tools from the worker, including tools from an MCP server inside your network.
Read queue depth, stop sessions and workers cleanly, and fix common failures.
CLI flags, environment variables, filesystem paths, and SDK helper options.
Shared responsibility model for self-hosted sandbox environments.
Was this page helpful?