Managed Agents limited networking now restricts web search and fetch
Managed Agents cloud environments using limited networking now apply allowed_hosts to server-side web_search and web_fetch. A mismatched enabled-tool allowed_domains entry can also make session creation or an update fail with HTTP 400.
Kingy verdict
Managed Agents workflows using limited networking can lose web results or fail session validation when the environment and tool domain lists disagree. Review both lists before adding hosts, because each allowed host also becomes reachable from the sandbox. This change does not apply to unrestricted networking or self-hosted environments.
Required action
Review environment allowed_hosts alongside each enabled web tool’s allowed_domains. Remove inconsistent entries or allow only the hosts the workflow needs, accounting for the different matching rules and the sandbox access each added host permits. Check session validation and denied-fetch handling before relying on the workflow.
Scope and notice
The October 7, 2026 release note applies to Claude Managed Agents cloud environments configured with limited networking. web_search and web_fetch run on Anthropic’s servers, but the environment’s allowed_hosts now constrains them too. Unrestricted networking and self-hosted environments are outside this change. The per-tool domain lists remain additional restrictions.
Runtime results and empty host lists
A web_fetch request to an unmatched host returns a url_not_allowed tool error. web_search omits results from unmatched hosts. If allowed_hosts lists no hosts, neither tool returns a page or search result. allow_package_managers and allow_mcp_servers add no hosts for these server-side web tools.
Session validation
Creating a session fails with HTTP 400 when an enabled web tool’s allowed_domains contains an entry outside allowed_hosts. A session update that adds such an entry also fails. Remove the inconsistent domain entry or add the required host to allowed_hosts after reviewing the access that grants.
The lists match differently
A per-tool domain entry covers the named host and its subdomains. An environment allowed_hosts entry matches an exact host unless it starts with *. For example, the tool domain docs.example.com does not fit within environment ["example.com"], but it fits within ["docs.example.com"] or ["*.example.com"]. The environment wildcard covers subdomains, not the bare domain. Use wildcard syntax only where the environment field accepts it; the per-tool domain list does not accept wildcards.
Review the sandbox impact
Adding a host to allowed_hosts for web tools also opens that host to the sandbox. Keep the list limited to the hosts the workflow needs. Messages API organization-level web search and fetch settings in the Claude Console are separate and do not apply to Managed Agents sessions.
Additional web-fetch condition
Anthropic’s October 7 release note also documents a separate prior-context check for web_fetch. An allowed host alone does not guarantee a fetch: the URL must already appear through qualifying session context, such as user-message text or web results. A URL appearing only in model output, the system prompt, an attached document, or bash/read/MCP output does not qualify and can return url_not_in_prior_context. The release note directs callers to supply the URL in user.message text. Kingy has not runtime-tested this condition; the linked tools guide did not yet repeat it at the October 7 evening review. The exclusions for unrestricted networking and self-hosted environments above describe the environment-host restriction; this notice does not establish the same exceptions for the separate context check.
Evidence limits
Historical first detection is unverified. The retained October 7 source observation establishes this evidence capture, not the earliest time Kingy detected the change. The documentation establishes the notice date and described behavior, but no precise rollout timestamp or migration deadline is asserted. Kingy has not created a session, tested network access or inspected an account for this packet.