environments changedmanaged-agents/environments
Nearest release: v2.1.287, published 4 hours before this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Recorded here
Lines+76added
Lines−25removed
From line
28
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits13to this page, all time
#### Risks of unrestricted networking
The whole hunk
from line 28, old and new numbered
/
from line 28
2828 "name": "python-dev",
2929 "config": {
3030 "type": "cloud",
31 "networking": {"type": "unrestricted"}
31 "networking": {"type": "limited", "allow_package_managers": true}
3232 }
3333 }
3434 EOF
from line 46
4646 config:
4747 type: cloud
4848 networking:
49 type: unrestricted
49 type: limited
50 allow_package_managers: true
5051 ```
5152 </File>
5253
from line 59
5859 name="python-dev",
5960 config={
6061 "type": "cloud",
61 "networking": {"type": "unrestricted"},
62 "networking": {"type": "limited", "allow_package_managers": True},
6263 },
6364 )
6465
from line 71
7071 name: "python-dev",
7172 config: {
7273 type: "cloud",
73 networking: { type: "unrestricted" },
74 networking: { type: "limited", allow_package_managers: true },
7475 },
7576 });
7677
from line 84
8384 Name = "python-dev",
8485 Config = new BetaCloudConfigParams
8586 {
86 Networking = new BetaUnrestrictedNetwork(),
87 Networking = new BetaLimitedNetworkParams
88 {
89 AllowPackageManagers = true,
90 },
8791 },
8892 });
8993
from line 100
96100 Config: anthropic.BetaEnvironmentNewParamsConfigUnion{
97101 OfCloud: &anthropic.BetaCloudConfigParams{
98102 Networking: anthropic.BetaCloudConfigParamsNetworkingUnion{
99 OfUnrestricted: &anthropic.BetaUnrestrictedNetworkParam{},
103 OfLimited: &anthropic.BetaLimitedNetworkParams{
104 AllowPackageManagers: anthropic.Bool(true),
105 },
100106 },
101107 },
102108 },
from line 118
112118 var environment = client.beta().environments().create(EnvironmentCreateParams.builder()
113119 .name("python-dev")
114120 .config(BetaCloudConfigParams.builder()
115 .networking(BetaUnrestrictedNetwork.builder().build())
121 .networking(BetaLimitedNetworkParams.builder()
122 .allowPackageManagers(true)
123 .build())
116124 .build())
117125 .build());
118126 IO.println("Environment ID: " + environment.id());
from line 129
121129 ```php PHP
122130 $environment = $client->beta->environments->create(
123131 name: 'python-dev',
124 config: ['type' => 'cloud', 'networking' => ['type' => 'unrestricted']],
132 config: [
133 'type' => 'cloud',
134 'networking' => ['type' => 'limited', 'allow_package_managers' => true],
135 ],
125136 );
126137 echo "Environment ID: {$environment->id}\n";
127138 ```
from line 142
131142 name: "python-dev",
132143 config: {
133144 type: "cloud",
134 networking: {type: "unrestricted"}
145 networking: {type: "limited", allow_package_managers: true}
135146 }
136147 )
137148
from line 150
139150 ```
140151</CodeGroup>
141152
142Use a unique, descriptive `name` so you can tell environments apart.
153Use a unique, descriptive `name` so you can tell environments apart. This example uses `limited` [networking](https://platform.claude.com/docs/en/managed-agents/environments#networking) with package managers allowed, so the sandbox can reach the package registries and code hosts. To let it reach other hosts, add them to `allowed_hosts`.
143154
144155## Use the environment in a session
145156
from line 253
242253 "pip": ["pandas", "numpy", "scikit-learn"],
243254 "npm": ["express"]
244255 },
245 "networking": {"type": "unrestricted"}
256 "networking": {"type": "limited", "allow_package_managers": true}
246257 }
247258 }
248259 EOF
from line 278
267278 npm:
268279 - express
269280 networking:
270 type: unrestricted
281 type: limited
282 allow_package_managers: true
271283 ```
272284 </File>
273285 </CodeGroupItem>
from line 293
281293 "pip": ["pandas", "numpy", "scikit-learn"],
282294 "npm": ["express"],
283295 },
284 "networking": {"type": "unrestricted"},
296 "networking": {"type": "limited", "allow_package_managers": True},
285297 },
286298 )
287299 ```
from line 307
295307 pip: ["pandas", "numpy", "scikit-learn"],
296308 npm: ["express"]
297309 },
298 networking: { type: "unrestricted" }
310 networking: { type: "limited", allow_package_managers: true }
299311 }
300312 });
301313 ```
from line 325
313325 Pip = ["pandas", "numpy", "scikit-learn"],
314326 Npm = ["express"],
315327 },
316 Networking = new BetaUnrestrictedNetwork(),
328 Networking = new BetaLimitedNetworkParams
329 {
330 AllowPackageManagers = true,
331 },
317332 },
318333 });
319334 ```
from line 343
328343 Npm: []string{"express"},
329344 },
330345 Networking: anthropic.BetaCloudConfigParamsNetworkingUnion{
331 OfUnrestricted: &anthropic.BetaUnrestrictedNetworkParam{},
346 OfLimited: &anthropic.BetaLimitedNetworkParams{
347 AllowPackageManagers: anthropic.Bool(true),
348 },
332349 },
333350 },
334351 },
from line 367
350367 .pip(List.of("pandas", "numpy", "scikit-learn"))
351368 .npm(List.of("express"))
352369 .build())
353 .networking(BetaUnrestrictedNetwork.builder().build())
370 .networking(BetaLimitedNetworkParams.builder()
371 .allowPackageManagers(true)
372 .build())
354373 .build())
355374 .build());
356375 ```
from line 383
364383 'pip' => ['pandas', 'numpy', 'scikit-learn'],
365384 'npm' => ['express'],
366385 ],
367 'networking' => ['type' => 'unrestricted'],
386 'networking' => ['type' => 'limited', 'allow_package_managers' => true],
368387 ],
369388 );
370389 ```
from line 397
378397 pip: %w[pandas numpy scikit-learn],
379398 npm: %w[express]
380399 },
381 networking: {type: "unrestricted"}
400 networking: {type: "limited", allow_package_managers: true}
382401 }
383402 )
384403 ```
from line 418
399418
400419The `networking` field controls the sandbox's outbound network access. It does not affect the `web_search` or `web_fetch` tools, which run on Anthropic's servers; to restrict the sites those tools can reach, set `allowed_domains` or `blocked_domains` on the tool's entry in the agent toolset. See [Restrict web search and web fetch domains](https://platform.claude.com/docs/en/managed-agents/tools#restrict-web-search-and-web-fetch-domains).
401420
402| Mode | Description |
403| -------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
404| `unrestricted` | Full outbound network access, except for a general safety blocklist. This is the default. |
405| `limited` | Restricts sandbox network access to the hosts in `allowed_hosts`. Set `allow_package_managers` and `allow_mcp_servers` to `true` to allow additional access. |
421| Mode | Description |
422| -------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
423| `limited` | Restricts sandbox network access to the hosts in `allowed_hosts`. Set `allow_package_managers` and `allow_mcp_servers` to `true` to allow additional access. Use this mode unless the agent must reach sites you cannot list in advance. |
424| `unrestricted` | Full outbound network access, except for a general safety blocklist. Before you use it, read [Risks of unrestricted networking](https://platform.claude.com/docs/en/managed-agents/environments#risks-of-unrestricted-networking). |
406425
426<Note>
427 Set `networking` explicitly in API requests; a create request that omits it gets `unrestricted`. The Claude Console's form for creating an environment starts with **Limited** selected and nothing else allowed.
428</Note>
429
407430The following example creates an environment with `limited` networking:
408431
409432<CodeGroup defaultLanguage="CLI">
from line 588
565588</CodeGroup>
566589
567590<Info>
568 For production deployments, use `limited` networking with an explicit `allowed_hosts` list. Follow the principle of least privilege by granting only the minimum network access your agent requires, and regularly audit your allowed domains.
591 Use `limited` networking with an explicit `allowed_hosts` list. Follow the principle of least privilege by granting only the minimum network access your agent requires, and regularly audit your allowed domains.
569592</Info>
570593
594With `limited` networking and no other fields set, no hosts are allowed. Files, memory stores, and GitHub repositories that you attach to the session stay available. When a request from the sandbox on port 80 or 443 is refused because its host is not allowed, the response is a 403 that names the blocked host.
595
571596When using `limited` networking:
572597
573598* `allowed_hosts` specifies domains the sandbox can reach. Specify bare hostnames or wildcard patterns (such as `*.example.com`). Do not include a URL scheme, port, or path.
574* `allow_mcp_servers` allows outbound access to MCP server endpoints configured on the agent, beyond those listed in the `allowed_hosts` array. Defaults to `false`.
599* `allow_mcp_servers` allows outbound access to MCP server endpoints configured on the agent, beyond those listed in the `allowed_hosts` array. Defaults to `false`. While it is `false`, session creation fails with a 400 error if the agent declares an MCP server whose host is not in `allowed_hosts`. The same applies to [an agent it can delegate to](https://platform.claude.com/docs/en/managed-agents/multiagent-orchestration). To fix it, add the host to `allowed_hosts` or set `allow_mcp_servers` to `true`.
575600* `allow_package_managers` allows outbound access to a set of public package registries and code hosts beyond those listed in the `allowed_hosts` array. See [Package manager hosts](https://platform.claude.com/docs/en/managed-agents/environments#package-manager-hosts) for the list. Defaults to `false`. Set it to `true` whenever the environment specifies `packages`; otherwise the request is rejected with a 400 error, even if the registry hosts are listed in `allowed_hosts`.
576601
577602#### Package manager hosts
from line 619
594619<Warning>
595620 Network access is granted per host, not per operation. The sandbox can send any request to an allowed host, including uploads such as `git push` and package publishing, with any credential the command supplies. If the agent processes untrusted input (repository files, fetched web content, or third-party tool output), a successful prompt injection could use an allowed host to copy files out of the sandbox. To reduce this risk, set the `bash` tool's [permission policy](https://platform.claude.com/docs/en/managed-agents/permission-policies) to `always_ask` or `auto`. If the environment does not specify `packages`, you can instead leave `allow_package_managers` set to `false` and list only the hosts your agent needs in `allowed_hosts`.
596621</Warning>
622
623#### Risks of unrestricted networking
624
625With `unrestricted` networking, code in the sandbox can send requests to any host on the internet, except for hosts on a general safety blocklist. Before you choose this mode, consider what the agent can do with that access:
626
627* **The agent can change things on external sites, not only read them:** The `bash` tool can send any request. The agent can post data, submit forms, call APIs, and run scripts that change data on external sites. Even a request that only fetches a URL can change data on some sites.
628* **Nothing pauses these requests by default:** The agent toolset's default [permission policy](https://platform.claude.com/docs/en/managed-agents/permission-policies) is `always_allow`, so `bash` commands run without approval.
629* **Anything in the sandbox can leave it:** This includes files, tool outputs, and any credentials or secrets you put in the sandbox.
630* **Fetched content can steer the agent:** Web pages, API responses, and other content the agent reads can contain instructions (prompt injection) that change what it does next.
631* **The agent acts on your behalf:** Its actions can violate a site's terms of service, or create accounts and records there.
632* **Model behavior is not a security control:** The agent can act on external sites in ways you did not ask for, including retrying in a different way after a site blocks a request. Use network settings and permission policies to limit what it can do.
633* **The safety blocklist is not an allowlist:** It does not limit which other sites the agent reaches, or what the agent does on them.
634
635To reduce these risks, use `limited` networking with an explicit list of hosts. The following `networking` value allows `api.example.com`, plus the [package manager hosts](https://platform.claude.com/docs/en/managed-agents/environments#package-manager-hosts) for an agent that installs packages:
636
637```json
638{
639 "type": "limited",
640 "allowed_hosts": ["api.example.com"],
641 "allow_package_managers": true
642}
643```
644
645An agent that only uses the `web_search` and `web_fetch` tools does not need `unrestricted` networking if you can list the sites it needs. [Networking](https://platform.claude.com/docs/en/managed-agents/environments#networking) says when `allowed_hosts` applies to those tools. Where it does, list those sites in `allowed_hosts`. Listing them in `web_search`'s `allowed_domains` too makes it search those sites. A host that you add to `allowed_hosts` is also open to the sandbox. To restrict the tools further, see [Restrict web search and web fetch domains](https://platform.claude.com/docs/en/managed-agents/tools#restrict-web-search-and-web-fetch-domains).
646
647Use `unrestricted` only when the agent must reach sites you cannot list in advance. In that case, keep secrets and sensitive files out of the sandbox, and give the agent only the credentials the task needs. Consider setting the `bash` tool's permission policy to `always_ask` or `auto`, and [watch the session's events](https://platform.claude.com/docs/en/managed-agents/events-and-streaming).
597648
598649## Environment lifecycle
599650
No line in this hunk matches that.