Claude Managed Agents extends network restrictions to web_search and web_fetch
Claude Managed Agents now also applies the allowed_hosts list to the web_search and web_fetch tools in cloud environments with restricted network access. The web_fetch tool rejects addresses that are not allowed, and the web_search tool omits results from servers that are not allowed.
Claude Managed Agents now also applies the allowed_hosts list to the web_search and web_fetch tools in cloud environments with restricted network access. The web_fetch tool returns a url_not_allowed error when a request targets an address outside the allowed list. The web_search tool omits results from servers that are not allowed. If the allowed_hosts list is empty, neither tool returns a page or a search result.
The allow_package_managers and allow_mcp_servers settings do not add any allowed servers for these tools. Access must be granted by adding an entry to allowed_hosts, which also makes that server accessible to the sandbox environment. Environments with unrestricted network access and self-hosted environments do not apply these restrictions.
Why it matters
Network rules now also determine the availability of web source material for agents. In an environment with restricted network access, a missing entry in allowed_hosts can prevent a page from loading or exclude its content from search results.
Two audiences, two different impacts
What this means
For individuals
When troubleshooting a url_not_allowed error or missing search results, developers must take the allowed_hosts list into account; allowing package managers or MCP servers does not grant access to web tools.
For a business
Approving agent access to web resources also affects network access from the sandbox environment: adding a server to allowed_hosts makes it accessible to both.
Risks and complianceCheck the original
Event sources
only one source so far · 1 publisher, 0 independent. We count feeds from the same owner only once.