OmniRunDocs

Claude Managed Agents

Anthropic runs the agent loop and model; each session's tool calls (bash, read, write, edit, glob, grep) execute in an isolated OmniRun microVM on your infrastructure.

One microVM per sessionSelf-hosted worker

A worker polls Anthropic's work queue and, for each claimed session, spawns a fresh claude-agentsandbox (8 GB, restored from snapshot in a few seconds).

Setup

  1. Create a self_hosted environment in the Anthropic Console and generate an environment key.
  2. Run the worker (shown here) on your box. We ship a claude-worker systemd unit that polls with graceful drain on restart.
  3. Point a session at that environment: its tool calls now run in your microVMs.
Run the self-hosted worker
# Install Anthropic's worker CLI (ant)
$ curl -fsSL .../ant_1.10.0_linux_amd64.tar.gz \
    | tar -xz -C /usr/local/bin ant

# Env from your self_hosted environment (Console)
$ export ANTHROPIC_ENVIRONMENT_KEY=sk-ant-oat01-...
$ export ANTHROPIC_ENVIRONMENT_ID=env_...

# Each claimed session runs in a fresh microVM
$ ant beta:worker poll --on-work ./spawn.sh
Never set ANTHROPIC_API_KEY on the worker. The spawner refuses to start if it's present, so it can never reach a sandbox. Only the scoped ANTHROPIC_ENVIRONMENT_KEY is forwarded into the VM.

How it runs

spawn.sh: per-session launcher

ant invokes your spawn script once per claimed session, passing ANTHROPIC_SESSION_ID / ANTHROPIC_WORK_ID. It creates the microVM, starts ant beta:worker run inside, polls until the session exits, then tears the sandbox down. Customize template, env, concurrency cap, and egress here.

Egress: open by default

Agent sandboxes get full outbound by default: real agents need package registries and git. To lock a deployment down, set sniProxy: true with allowDomains in the create body; the SNI proxy then forwards only HTTPS (port 443) connections to allow-listed hostnames, so list what you need (including pypi/npm). Other ports are not filtered by the proxy, and it is not proof against domain fronting.

Session lifecycle

One microVM per session, one snapshot restore per spawn. Tool calls within a session share that VM; disk does not persist across sessions (no Persistent Memory yet). Outputs under /mnt/session/outputs can be copied back to the host before teardown.

Troubleshooting

Restarting the worker drains in-flight sessions (generous TimeoutStopSec). Run one poller per box: stray ant beta:worker poll processes compete for work. A per-template concurrency cap protects host RAM; sessions over the cap are deferred, not dropped.

Full guide