Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One change · api

environments changedmanaged-agents/environments

Nearest release: v2.1.283, published 3 hours after this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.

Recorded here
Lines+30added
Lines−11removed
From line 34 where the diff opens
First seen 14 Aug 2026 this site's first read of the page
Recorded edits12to this page, all time

#### Package manager hosts

The whole hunk

from line 34, old and new numbered
/
lines
from line 34
3434 EOF
3535 ```
3636 
37 <MultiFileExample language="cli" label="CLI">
37 <CodeGroupItem>
3838 ```bash CLI
3939 ant apply environment.yaml
4040 ```
from line 49
4949 type: unrestricted
5050 ```
5151 </File>
52 </MultiFileExample>
5352 
53 [`ant apply`](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/apply) creates the environment from `environment.yaml`, prints its ID, and records it in `claude-lock.json`. Commit `claude-lock.json` so the next `ant apply` updates this environment instead of trying to create it again.
54 </CodeGroupItem>
55 
5456 ```python Python
5557 environment = client.beta.environments.create(
5658 name="python-dev",
from line 137
135137 
136138 puts "Environment ID: #{environment.id}"
137139 ```
138 
139 <ForLanguage tab="CLI">
140 [`ant apply`](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/apply) creates the environment from `environment.yaml`, prints its ID, and records it in `claude-lock.json`. Commit `claude-lock.json` so the next `ant apply` updates this environment instead of trying to create it again.
141 </ForLanguage>
142140</CodeGroup>
143141 
144142Use a unique, descriptive `name` so you can tell environments apart.
from line 248
250248 EOF
251249 ```
252250 
253 <MultiFileExample language="cli" label="CLI">
251 <CodeGroupItem>
254252 ```bash CLI
255253 ant apply environment.yaml
256254 ```
from line 270
272270 type: unrestricted
273271 ```
274272 </File>
275 </MultiFileExample>
273 </CodeGroupItem>
276274 
277275 ```python Python
278276 environment = client.beta.environments.create(
from line 427
429427 }'
430428 ```
431429 
432 <MultiFileExample language="cli" label="CLI">
430 <CodeGroupItem>
433431 ```bash CLI
434432 ant apply environment.yaml
435433 ```
from line 446
448446 allow_package_managers: true
449447 ```
450448 </File>
451 </MultiFileExample>
449 </CodeGroupItem>
452450 
453451 ```python Python
454452 environment = client.beta.environments.create(
from line 572
574572 
575573* `allowed_hosts` specifies domains the sandbox can reach. Specify bare hostnames or wildcard patterns (such as `*.example.com`). Do not include a URL scheme, port, or path.
576574* `allow_mcp_servers` allows outbound access to MCP server endpoints configured on the agent, beyond those listed in the `allowed_hosts` array. Defaults to `false`.
577* `allow_package_managers` allows outbound access to public package registries (such as PyPI and npm) beyond those listed in the `allowed_hosts` array. Defaults to `false`. Set it to `true` whenever the environment specifies `packages`; otherwise the request is rejected with a 400 error, even if the registry hosts are listed in `allowed_hosts`.
575* `allow_package_managers` allows outbound access to a set of public package registries and code hosts beyond those listed in the `allowed_hosts` array. See [Package manager hosts](https://platform.claude.com/docs/en/managed-agents/environments#package-manager-hosts) for the list. Defaults to `false`. Set it to `true` whenever the environment specifies `packages`; otherwise the request is rejected with a 400 error, even if the registry hosts are listed in `allowed_hosts`.
576 
577#### Package manager hosts
578 
579When `allow_package_managers` is `true`, the sandbox can reach the following hosts in addition to those in `allowed_hosts`. Anthropic maintains this list and can change it.
580 
581| Ecosystem | Hosts |
582| ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
583| Code hosting | `github.com`, `api.github.com`, `codeload.github.com`, `raw.githubusercontent.com`, `objects.githubusercontent.com`, `release-assets.githubusercontent.com`, `gitlab.com`, `bitbucket.org` |
584| Node.js | `registry.npmjs.org`, `registry.yarnpkg.com`, `nodejs.org` |
585| Python | `pypi.org`, `files.pythonhosted.org` |
586| Rust | `crates.io`, `index.crates.io`, `static.crates.io`, `static.rust-lang.org` |
587| Go | `proxy.golang.org`, `sum.golang.org` |
588| Java | `repo1.maven.org`, `repo.maven.apache.org`, `services.gradle.org`, `plugins.gradle.org`, `plugins-artifacts.gradle.org` |
589| Ruby | `rubygems.org`, `index.rubygems.org` |
590| PHP | `packagist.org`, `repo.packagist.org` |
591| Ubuntu (apt) | `archive.ubuntu.com`, `security.ubuntu.com`, `ppa.launchpad.net` |
592| Containers | `registry-1.docker.io`, `auth.docker.io`, `production.cloudflare.docker.com`, `download.docker.com`, `ghcr.io` |
593 
594<Warning>
595 Network access is granted per host, not per operation. The sandbox can send any request to an allowed host, including uploads such as `git push` and package publishing, with any credential the command supplies. If the agent processes untrusted input (repository files, fetched web content, or third-party tool output), a successful prompt injection could use an allowed host to copy files out of the sandbox. To reduce this risk, set the `bash` tool's [permission policy](https://platform.claude.com/docs/en/managed-agents/permission-policies) to `always_ask` or `auto`. If the environment does not specify `packages`, you can instead leave `allow_package_managers` set to `false` and list only the hosts your agent needs in `allowed_hosts`.
596</Warning>
578597 
579598## Environment lifecycle
580599 
Feedback