Claude Managed Agents ↗︎ runs its agent loop on the Anthropic platform. A self-managed environment runs the actions of the agent in your Cloudflare account instead. Cloudflare publishes an open-source template for that environment. Fork it, deploy it to your account, and change it as you need.
Get the template
When an agent session starts or ends, Anthropic sends a webhook to a Worker that the template deploys in your account. The Worker gives each session its own sandbox, applies an egress policy to its outbound traffic, saves the sandbox state while the session sleeps, and shuts the sandbox down when the session ends.
Each agent runs in one of two sandbox types:
- A Linux sandbox on Containers gives the agent a shell and any process it needs to run. The template builds these sandboxes with Sandbox SDK 0.x.
- A Dynamic Worker starts in milliseconds and costs less than a container session, but runs code in the Workers runtime without a Linux shell or processes.
For more information about the trade-offs, refer to Choose a sandbox environment.
The template also gives agents access to other Cloudflare products:
- Agents reach private services over Workers VPC and Cloudflare Mesh without exposing those services to the Internet.
- Outbound traffic passes through proxies that you configure. A proxy can add credentials to requests without the agent seeing them, restrict the domains an agent can reach, or run your own code on each request.
- Each session can have its own email address for sending and receiving messages with Email Service.
- Agents can use headless browsers from Browser Run to fetch pages, take screenshots, and control a browser over the Chrome DevTools Protocol.
- Agents can generate images with Workers AI.
- You add a tool by adding a function to one file. Tools run in the Worker with access to all of its bindings.
- A dashboard lists agents and sessions, shows logs, and opens a shell in a running Linux sandbox.
Use a self-managed Cloudflare environment when you need:
- Control over the sandbox infrastructure your agents run in
- Secure connections to private internal services
- Custom egress policies for credential injection and domain restrictions
- Custom tools that use Cloudflare bindings, such as R2, D1, KV, and Vectorize
- A choice between Linux sandboxes and Dynamic Workers for each agent
Follow the onboarding guide ↗︎ in the repository. It covers the Anthropic environment and webhook, secrets, D1 migrations, R2 credentials for snapshots, and dashboard security. Deploy with the Deploy to Cloudflare button, which builds the template in Workers Builds, or run npm run deploy from your terminal.
The repository documents each capability:
| Topic | What it covers |
|---|---|
| Connecting to private services ↗︎ | Reach services in other clouds, on-premises, or on your laptop with Workers VPC bindings |
| Applying egress policies ↗︎ | Allow and deny lists, header injection, custom Worker proxies, and VPC routing |
| Choosing a sandbox type ↗︎ | When to run an agent in a Dynamic Worker or a Linux sandbox |
| Agent email ↗︎ | Email addresses and sending for agents |
| Browser tools ↗︎ | Browser Run tools for agents |
| Adding custom tools ↗︎ | Declaring new tools in src/tools/custom-tools.ts ↗︎ |
| Customizing sandboxes ↗︎ | The Dockerfile and instance_type of Linux sandboxes |
| Snapshots and state persistence ↗︎ | How both sandbox types keep their state while a session sleeps |
| Architecture ↗︎ | The request path from webhook to sandbox, and every binding the Worker uses |
| Securing access ↗︎ | Securing the dashboard and API |