environments changedmanaged-agents/environments
Nearest release: v2.1.283, published 3 hours after this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Recorded here
Lines+30added
Lines−11removed
From line
34
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits12to this page, all time
#### Package manager hosts
The whole hunk
from line 34, old and new numbered
/
from line 34
3434 EOF
3535 ```
3636
37 <MultiFileExample language="cli" label="CLI">
37 <CodeGroupItem>
3838 ```bash CLI
3939 ant apply environment.yaml
4040 ```
from line 49
4949 type: unrestricted
5050 ```
5151 </File>
52 </MultiFileExample>
5352
53 [`ant apply`](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/apply) creates the environment from `environment.yaml`, prints its ID, and records it in `claude-lock.json`. Commit `claude-lock.json` so the next `ant apply` updates this environment instead of trying to create it again.
54 </CodeGroupItem>
55
5456 ```python Python
5557 environment = client.beta.environments.create(
5658 name="python-dev",
from line 137
135137
136138 puts "Environment ID: #{environment.id}"
137139 ```
138
139 <ForLanguage tab="CLI">
140 [`ant apply`](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/apply) creates the environment from `environment.yaml`, prints its ID, and records it in `claude-lock.json`. Commit `claude-lock.json` so the next `ant apply` updates this environment instead of trying to create it again.
141 </ForLanguage>
142140</CodeGroup>
143141
144142Use a unique, descriptive `name` so you can tell environments apart.
from line 248
250248 EOF
251249 ```
252250
253 <MultiFileExample language="cli" label="CLI">
251 <CodeGroupItem>
254252 ```bash CLI
255253 ant apply environment.yaml
256254 ```
from line 270
272270 type: unrestricted
273271 ```
274272 </File>
275 </MultiFileExample>
273 </CodeGroupItem>
276274
277275 ```python Python
278276 environment = client.beta.environments.create(
from line 427
429427 }'
430428 ```
431429
432 <MultiFileExample language="cli" label="CLI">
430 <CodeGroupItem>
433431 ```bash CLI
434432 ant apply environment.yaml
435433 ```
from line 446
448446 allow_package_managers: true
449447 ```
450448 </File>
451 </MultiFileExample>
449 </CodeGroupItem>
452450
453451 ```python Python
454452 environment = client.beta.environments.create(
from line 572
574572
575573* `allowed_hosts` specifies domains the sandbox can reach. Specify bare hostnames or wildcard patterns (such as `*.example.com`). Do not include a URL scheme, port, or path.
576574* `allow_mcp_servers` allows outbound access to MCP server endpoints configured on the agent, beyond those listed in the `allowed_hosts` array. Defaults to `false`.
577* `allow_package_managers` allows outbound access to public package registries (such as PyPI and npm) beyond those listed in the `allowed_hosts` array. Defaults to `false`. Set it to `true` whenever the environment specifies `packages`; otherwise the request is rejected with a 400 error, even if the registry hosts are listed in `allowed_hosts`.
575* `allow_package_managers` allows outbound access to a set of public package registries and code hosts beyond those listed in the `allowed_hosts` array. See [Package manager hosts](https://platform.claude.com/docs/en/managed-agents/environments#package-manager-hosts) for the list. Defaults to `false`. Set it to `true` whenever the environment specifies `packages`; otherwise the request is rejected with a 400 error, even if the registry hosts are listed in `allowed_hosts`.
576
577#### Package manager hosts
578
579When `allow_package_managers` is `true`, the sandbox can reach the following hosts in addition to those in `allowed_hosts`. Anthropic maintains this list and can change it.
580
581| Ecosystem | Hosts |
582| ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
583| Code hosting | `github.com`, `api.github.com`, `codeload.github.com`, `raw.githubusercontent.com`, `objects.githubusercontent.com`, `release-assets.githubusercontent.com`, `gitlab.com`, `bitbucket.org` |
584| Node.js | `registry.npmjs.org`, `registry.yarnpkg.com`, `nodejs.org` |
585| Python | `pypi.org`, `files.pythonhosted.org` |
586| Rust | `crates.io`, `index.crates.io`, `static.crates.io`, `static.rust-lang.org` |
587| Go | `proxy.golang.org`, `sum.golang.org` |
588| Java | `repo1.maven.org`, `repo.maven.apache.org`, `services.gradle.org`, `plugins.gradle.org`, `plugins-artifacts.gradle.org` |
589| Ruby | `rubygems.org`, `index.rubygems.org` |
590| PHP | `packagist.org`, `repo.packagist.org` |
591| Ubuntu (apt) | `archive.ubuntu.com`, `security.ubuntu.com`, `ppa.launchpad.net` |
592| Containers | `registry-1.docker.io`, `auth.docker.io`, `production.cloudflare.docker.com`, `download.docker.com`, `ghcr.io` |
593
594<Warning>
595 Network access is granted per host, not per operation. The sandbox can send any request to an allowed host, including uploads such as `git push` and package publishing, with any credential the command supplies. If the agent processes untrusted input (repository files, fetched web content, or third-party tool output), a successful prompt injection could use an allowed host to copy files out of the sandbox. To reduce this risk, set the `bash` tool's [permission policy](https://platform.claude.com/docs/en/managed-agents/permission-policies) to `always_ask` or `auto`. If the environment does not specify `packages`, you can instead leave `allow_package_managers` set to `false` and list only the hosts your agent needs in `allowed_hosts`.
596</Warning>
578597
579598## Environment lifecycle
580599
No line in this hunk matches that.