MCP Tunnels is a research-preview feature of 📝Claude Managed Agents that lets agents reach private 📝MCP Servers inside a customer's network without exposing them publicly.
A lightweight gateway runs inside the customer's network and establishes a single outbound encrypted connection to Anthropic's routing infrastructure. When an agent needs to call a private MCP tool, the request travels through that channel and reaches the server through the existing perimeter — no inbound firewall rules, no public DNS, no reverse proxy. Traffic remains end-to-end encrypted between the agent and the MCP server.
Tunnels are administered from workspace settings in the 📝Claude Console by organization admins and work with both Managed Agents and direct Messages API calls. The feature is access-gated; admins must request enrollment before tunnels appear in console settings. Announced at Code with Claude London in May 2026 alongside Self-Hosted Sandboxes as part of a broader push to make Managed Agents work inside customer security perimeters.
For teams running internal MCP servers — internal data lookups, private knowledge bases, on-premise tooling — MCP Tunnels remove the architectural choice between exposing the server to the public internet and forgoing agentic access entirely.
