Claude Managed Agents now applies host rules to search and fetch
By Steven Van ·
Blocked hosts produce fetch errors and disappear from search results; unrestricted networking and self-hosted environments are unaffected.
The host list for limited cloud networking now governs web search and fetching in Anthropic's Claude Managed Agents, even though those tools run on Anthropic's servers.
How blocked hosts are handled
A web_fetch call to a host outside allowed_hosts returns an error result to the agent, while web_search omits results from those hosts. If allowed_hosts is empty, neither tool returns a page or a search result.
Configuring access
Add a host to allowed_hosts to let the tools reach it. That also opens the host to the sandbox. The allow_package_managers and allow_mcp_servers settings do not grant these tools access to additional hosts.
Bare hostnames match only the exact host: example.com does not include docs.example.com. A wildcard such as *.example.com matches subdomains, but not example.com itself. The tools can be restricted further through allowed_domains or blocked_domains in the agent toolset.
Session validation and scope
With limited networking, creating a session or updating it to add an enabled web tool's allowed_domains entry outside allowed_hosts fails with a 400 error. To resolve it, add the host to allowed_hosts or remove the entry from allowed_domains.
Unrestricted networking and self-hosted environments do not impose these limits on the web tools. The environment networking documentation explains the host settings.