Article

Claude Managed Agents: Configure Web Search and Fetch Allowlists

Configure Claude Managed Agents web retrieval under limited networking: align host and tool-domain lists, diagnose failures, and check source coverage.

Editorial illustration for Claude Managed Agents: Configure Web Search and Fetch Allowlists: documents enter a shared index with two query paths. Not documentary evidence.

On October 7, 2026, Anthropic announced that Claude Managed Agents cloud environments using limited networking now apply their allowed_hosts list to web_search and web_fetch. Teams using restricted web retrieval should check both configurations before starting or updating sessions.

The practical question is which sources the task needs, and whether both policy layers permit them. Web retrieval must satisfy both the environment allowlist and the tool’s domain policy. A configuration can start successfully yet still leave a research task short of essential sources.

Check the deployment boundary first

Managed Agents remains in beta, with access enabled by default for API accounts. Requests require the managed-agents-2026-04-01 beta header; Anthropic’s SDK supplies it automatically. This is a networking behavior change, not the product’s launch.

The environment restriction concerns cloud environments using limited networking. Unrestricted cloud and self-hosted environments do not impose this allowlist on the server-run web tools; per-tool filters still apply. Console organization-level web settings govern the Messages API, not Managed Agents sessions. Domain-policy documentation.

If the task needs browser interaction rather than search or page retrieval, see our Claude SDK browser and desktop driver guide. It addresses a separate implementation path.

Do not copy matching assumptions between lists

For environment allowed_hosts, a bare hostname matches only itself. example.com does not grant docs.example.com. The pattern *.example.com covers subdomains but excludes the apex, example.com. Do not include schemes, ports or paths. Environment matching rules.

Tool-level allowed_domains and blocked_domains instead cover each listed host and its subdomains. Wildcards are invalid there. Choose one list per tool, not both; lists accept 1–64 entries, without duplicates. Omit the field or use null for no per-tool filter, not an empty array. That does not remove the environment restriction. Tool-domain rules.

Set networking explicitly: an API environment-create request that omits it gets unrestricted networking, whereas the Console form starts with Limited and nothing allowed. Documented defaults.

Pair the environment with a web-only toolset

These documentation-derived JSON fragments illustrate a bounded research workflow; they have not been executed and are not complete agent/session requests. Replace docs.example.com with an authorized, provider-accessible hostname. An allowlist does not establish that a page is crawlable.

Environment request fragment, following the cloud configuration documentation:

{
  "name": "bounded-research",
  "config": {
    "type": "cloud",
    "networking": {
      "type": "limited",
      "allowed_hosts": [
        "docs.example.com"
      ],
      "allow_mcp_servers": false,
      "allow_package_managers": false
    }
  }
}

Agent tools fragment: default_config.enabled: false turns off the built-in baseline, and individual entries enable only search and fetch. Names identify the configs; the server can infer their types. Toolset configuration:

{
  "tools": [
    {
      "type": "agent_toolset_20260401",
      "default_config": {
        "enabled": false
      },
      "configs": [
        {
          "name": "web_search",
          "enabled": true,
          "allowed_domains": [
            "docs.example.com"
          ]
        },
        {
          "name": "web_fetch",
          "enabled": true,
          "allowed_domains": [
            "docs.example.com"
          ]
        }
      ]
    }
  ]
}

Adding a host also opens it to sandbox traffic. Anthropic documents this shared boundary. Our recommendation is to review tool access alongside the host change: if the task only needs retrieval, there is no reason to enable shell tools in this example.

The example does not require a human confirmation for each web call: built-in tools default to always_allow. Where review is required, configure always_ask. The auto policy can allow, deny or ask; it does not guarantee human review. Permission-policy documentation.

Separate startup rejection from missing retrieval

The October 7 release note documents three distinct outcomes. The suggested checks below are operational recommendations, not observed incident results.

Symptom

Documented behavior

First check

HTTP 400 on session creation or a tools update

An enabled web tool’s allowed_domains entry is outside allowed_hosts.

Align the needed host with both lists, or remove an unnecessary tool-domain entry.

web_fetch returns url_not_allowed

The requested host does not match the environment allowlist.

Check the exact hostname, including its subdomain.

Search omits expected hosts

web_search excludes results from hosts the environment denies.

Compare permitted hosts with the sources the task requires.

An empty allowed_hosts permits neither pages nor search results through these tools. allow_package_managers and allow_mcp_servers do not grant web-tool access. Release-note clarification.

Package installation has a separate requirement: a limited environment specifying packages must set allow_package_managers: true, even if registry hosts are explicitly allowed; otherwise the request fails with HTTP 400. The example specifies no packages. Package setup rules.

Update the saved configuration, then check coverage

For an existing session, use the documented update procedure:

  1. Wait until the session is idle. If necessary, send user.interrupt separately and wait for that status before updating.

  2. Retrieve the current session, edit its tool configuration and submit the full intended tools array. Updates replace the array; they do not merge entries. Preserve unrelated tools and policies.

  3. Update the reusable agent definition separately. A session-local correction does not change the agent used by future sessions.

Our proposed acceptance checks should answer two different questions: does access behave as intended, and can the task obtain enough evidence?

  • Use public fixtures you control on permitted and denied hosts. Check fetch outcomes and review which sources appear in search. Do not interpret an empty search as proof that relevant evidence does not exist.

  • Exercise an incompatible environment/tool-domain pairing in a disposable setup, and confirm that the application handles rejection without repeatedly submitting the same configuration.

  • Start a fresh session from the corrected agent. Record its environment and tool configuration, then verify that a web-only setup exposes only the intended tools.

  • Define required evidence categories before the run—for example, release notes and implementation documentation. If retrieval cannot cover them, report an incomplete task instead of accepting a fluent but under-supported answer.

This is the tradeoff for restricted research: a finite source list makes access reviewable, but it cannot stand in for open-web discovery. Decide whether missing sources are essential before expanding access. Keep the policy change and expected evidence coverage together for later review.

Budget the verification work too. Current USD list pricing includes model tokens, $0.08 per running session-hour and $10 per 1,000 web searches; idle time does not accrue runtime charges. Web fetch has no separate tool fee beyond tokens. A smaller result set is not evidence of a cheaper completed task.

The reviewed sources do not specify an exact rollout time or comprehensive treatment of sessions already running when enforcement changed. Do not assume a grace period.

Methodology: AI-assisted reporting and implementation analysis based on Anthropic’s release notes and documentation, rechecked on October 7, 2026. The examples and acceptance checks are proposals, not hands-on test results.