Claude Managed Agents
Anthropic runs the agent loop and model; each session's tool calls (bash, read, write, edit, glob, grep) execute in an isolated OmniRun microVM on your infrastructure.
A worker polls Anthropic's work queue and, for each claimed session, spawns a fresh claude-agentsandbox (8 GB, restored from snapshot in a few seconds).
Setup
- Create a
self_hostedenvironment in the Anthropic Console and generate an environment key. - Run the worker (shown here) on your box. We ship a
claude-workersystemd unit that polls with graceful drain on restart. - Point a session at that environment: its tool calls now run in your microVMs.
# Install Anthropic's worker CLI (ant)
$ curl -fsSL .../ant_1.10.0_linux_amd64.tar.gz \
| tar -xz -C /usr/local/bin ant
# Env from your self_hosted environment (Console)
$ export ANTHROPIC_ENVIRONMENT_KEY=sk-ant-oat01-...
$ export ANTHROPIC_ENVIRONMENT_ID=env_...
# Each claimed session runs in a fresh microVM
$ ant beta:worker poll --on-work ./spawn.shANTHROPIC_ENVIRONMENT_KEY is forwarded into the VM.How it runs
spawn.sh: per-session launcher
ant invokes your spawn script once per claimed session, passing ANTHROPIC_SESSION_ID / ANTHROPIC_WORK_ID. It creates the microVM, starts ant beta:worker run inside, polls until the session exits, then tears the sandbox down. Customize template, env, concurrency cap, and egress here.
Egress: open by default
Agent sandboxes get full outbound by default: real agents need package registries and git. To lock a deployment down, set sniProxy: true with allowDomains in the create body; the SNI proxy then forwards only HTTPS (port 443) connections to allow-listed hostnames, so list what you need (including pypi/npm). Other ports are not filtered by the proxy, and it is not proof against domain fronting.
Session lifecycle
One microVM per session, one snapshot restore per spawn. Tool calls within a session share that VM; disk does not persist across sessions (no Persistent Memory yet). Outputs under /mnt/session/outputs can be copied back to the host before teardown.
Troubleshooting
Restarting the worker drains in-flight sessions (generous TimeoutStopSec). Run one poller per box: stray ant beta:worker poll processes compete for work. A per-template concurrency cap protects host RAM; sessions over the cap are deferred, not dropped.