Cloudflare Integrates Claude Managed Agents: A Developer's Practical Guide
Cloudflare adds support for Claude Managed Agents, letting developers run Claude agents on Cloudflare's platform, connect to private systems, and deploy AI agents securely.


Cloudflare Integrates Claude Managed Agents: A Developer's Practical Guide
Cloudflare adds support for Claude Managed Agents, letting developers run Claude agents on Cloudflare's platform, connect to private systems, and deploy AI agents securely.
Cloudflare has added support for Claude Managed Agents. What this means: you can keep the "brain" of your Claude agent on Anthropic's platform while running the "hands" (code execution, data access, and so on) on Cloudflare's infrastructure. For teams that need to securely connect to private systems and meet compliance requirements, this is a practical integration path.
What This Is
Anthropic describes the architecture as "decoupling the brain from the hands":
- The brain (agent logic and orchestration): stays on Anthropic's platform
- The hands (code execution layer): runs on Cloudflare's infrastructure
Previously, using Claude Managed Agents meant running the entire stack on infrastructure provided by Anthropic. Now you can choose to move the execution layer to Cloudflare and gain greater control over your infrastructure.
Core Capabilities
Sandboxed Execution Environments
- Lightweight execution: fast-start sandboxes built on Cloudflare Workers
- Virtual machine execution: for scenarios demanding stronger isolation, VM-level sandboxes are available
- Both modes ship with sandbox controls and logging built in
Private Service Access
Through Cloudflare Mesh and Workers VPC services, agents can securely connect to your private systems without exposing services to the public internet:
- Private connections never touch the public internet
- Credentials are injected; the agent itself never holds them
- Agent operations are logged for auditability
Built-In Capabilities
- Browser automation: the Browser Run feature handles web operations
- Email functionality: built-in mail send and receive
- Custom tools: define the toolset your agents can call
- Logging and monitoring: full activity logs
Real-World Scenarios
Financial Services
Cloudflare regional director Sebastian Weiss offered a concrete scenario:
The agent runs inside the bank's own cloud environment and accesses core systems over a private connection that never touches the public internet. Credentials are injected, and agent operations are logged for auditors to review. Claude holds the decision-making power; control always stays with the bank.
Internal Enterprise System Integration
Teams that need AI agents to reach internal CRMs, ERPs, or databases can use Workers VPC to establish secure channels, with agents connecting only to approved internal services.
Custom AI Agent Workflows
Extend agent capabilities with Cloudflare's developer platform:
- Artifacts: Git-based code repository management
- Workers AI: edge inference
- Dynamic Workers: on-demand application hosting
How to Get Started
Prerequisites
- A Cloudflare account
- An Anthropic API key (Claude access)
- Basic Workers development experience
Quick Start
Cloudflare provides an open-source deployment template as a quick start. Developers can customize the control plane on top of the template, then configure network proxies, secure connections, and toolsets according to their business needs.
On costs, developers manage expenses related to Claude API usage and Cloudflare resources separately.
How It Compares to Other Platforms
Cloudflare isn't the only provider supporting self-hosted Claude Managed Agents. The launch lineup also includes:
- Daytona: development environment management
- Modal: serverless compute
- Vercel: frontend deployment
Among them, Cloudflare occupies the "prime position," offering both Browser Run automation and quick-start templates.
Who It's For
- Enterprises with compliance requirements: industries like finance and healthcare with strict data-security demands
- Teams connecting to private systems: anyone who doesn't want internal services exposed to the public internet
- Developers who want infrastructure control: those who, for performance, cost, or security reasons, want to choose their own execution environment
Toolin Editorial Team
Categories
Related articles
WeChat Xiaowei Beta Hands-On: Swipe Right and Turn All of WeChat into an Agent
A beta look at WeChat's official AI assistant Xiaowei: chat summaries, auto-replies, invoking mini programs, money transfers, Moments browsing, and building small tools — eight capabilities in one read.

The Ministry of Education's "Sunshine Volunteer" AI Assistant: Free College-Application Plans Generated in Seconds
The Ministry of Education has officially upgraded its "Sunshine Volunteer" system, with the "Zhihui Xiaozhao" AI assistant online 24 hours a day, providing reach-match-safety application plans free of charge based on official data.

GenShield: An All-in-One Open Source Framework for AI-Generated Image Detection and Repair
A Peking University team has open sourced GenShield, unifying AI-generated image detection and artifact correction in a single autoregressive framework with 98.8% detection accuracy

OpenAI Codex OSS Mode: Connect Local Models with a Single Line of Config
Codex adds an OSS mode supporting local model services like Ollama and LM Studio, enabling offline operation and cost control

Claude Cowork Double-Credits Hands-On Guide: Getting Started Across 7 Work Scenarios
Claude Cowork is temporarily doubling usage credits for all paid users — $20/month for $236 of compute — with hands-on guides for 7 real-world work scenarios.

OpenAI Codex Launches Savings Reset: No More Waiting When Credits Run Out, and Referrals Pay Both Sides
Codex rolls out a Savings Reset feature giving paid users one credit-reset opportunity, with a limited-time referral promo that rewards both sides once each — flexible management of your coding compute.