Claude does the thinking. Your worker does the work: in a VM on your own machine, in a cloud sandbox, or both. The files, the network and the MCP servers stay on your side.
{{flowTitle}}{{flowSub}}
ANTHROPICClaude + sessionThinks, picks tools, holds skills and memory stores
WORK QUEUEself_hosted environmentSessions wait here until a worker claims them
{{workerTag}}{{workerName}}{{workerNote}}
YOUR SIDE{{sideName}}{{sideNote}}
{{f}}
The rollout, in 8 steps
tap a step to mark it done · {{doneCount}}/8
Where it can run
{{t.name}}{{t.good}}
{{t.tag}}
Private MCP servers: tunnel or wrap?
MCP TUNNELWRAP AS CUSTOM TOOLSWho calls the serverAnthropic, through the tunnelYour worker, inside your networkWorks with cloud sandboxesYesNo, self-hosted onlyNew tools appearWhen the server adds themOnly after you redeclare them and restart the workerApprovalsPermission policies applyNone: put them in your tool codePick it forShared servers many agents usecognitive-mcp and anything that must never be reachable from outside
Fleet healthsample
3workers polling
0sessions waiting
0claimed, not started
—oldest wait
Alert when workers polling = 0. Add a worker when sessions waiting keeps climbing.
Tricks worth stealing
● estate-specific · ● from the docs
{{k.title}}›
{{k.body}}
keysThe environment key goes in the vault on the worker box. Your Claude API key never goes on a worker at all. Neither ever goes in a chat. Keys are made in the Claude Console, which is the one step only you can do.Back to DevDesk