Skip to content

Build1 publisher2 min readPublished

An undocumented flag in Claude Desktop points agent sessions at customer-run hosts

Claude Desktop's public JavaScript holds an undocumented setting to route agent sessions to an organization's host, a RuntimeWire review of 2,726 assets found. The code ties it to Cowork but proves neither a launch nor on-premises inference.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying An undocumented flag in Claude Desktop points agent sessions at customer-run hosts
Generated illustration

What happened

  • The setting, selfHostedUrl, sits behind a beta feature named selfHostedSessions, and the bundle labels it "public-undocumented".
  • Other strings in the bundle describe memory and skills routes, host sign-in errors, and scheduled tasks that run on an organization's session host.
  • Anthropic put self-hosted environments for Claude Code into public beta for Team and Enterprise customers in an August 6 announcement.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • cost Running Cowork sessions on an organization host would hand the customer's platform team an HTTPS endpoint to operate, its sign-in integration, and the uptime that scheduled tasks rely on.
  • decision Teams already in the Claude Code self-hosted beta have the closest working reference for what a Cowork host would ask of their network and identity setup.
  • constraint Data-residency and privacy reviews cannot count this host as keeping model inference inside the network, so their current terms with Anthropic still govern.

Sign-in is the most worked-out part of the client. To reach the organization's HTTPS endpoint, the configuration offers identity-provider flows, credential-helper scripts and a static bearer token [1][4]. In my view it was written to connect without knowing what identity system sits behind that endpoint. The static token is the option I would expect a security review to question first.

The interface copy is easy to misread. One user-facing message says, "Claude runs on your organization's infrastructure, not on this computer." [6] Read literally, that puts the model inside the customer's network. RuntimeWire did the review, and it says the bundle does not establish where inference would occur or what data-processing terms would apply [11].

Anthropic's shipped products divide the work differently. Its Managed Agents documentation has customer infrastructure run tools and hold files, while orchestration and model interactions stay with Anthropic [10]. Claude Code's self-hosted sessions run inside an organization's network, next to its internal services and tools [9]. RuntimeWire treats both as precedent for separating agent execution from model inference [17]. If a Cowork host ships, I'd expect the same split: the agent's work on customer machines, the model call at Anthropic.

Capability checks named selfHostedCowork [3] suggest a third place to run a Cowork session, beside the cloud and local modes Anthropic documents [7]. Scheduled work is where a third place would change behavior. A local session depends on the user's own device [7]. A task placed on the organization's session host [5] would not need an employee's laptop to stay on.

The evidence stops at the client. The review read about 118.5 MB of public JavaScript [13]. It did not test a backend or confirm that any customer can reach one [15]. RuntimeWire says the code could be shared across Anthropic services, or could support a deployment path that customers cannot use [12]. The entry asset has an October 1 CDN modification timestamp, and RuntimeWire says that dates the object, not the feature [14]. Anthropic had not responded to RuntimeWire's request for comment by publication [16].

What to watch

  • An Anthropic Cowork architecture page that adds an organization-operated host beside the cloud and local modes.
  • Documentation or data-processing terms stating where model inference runs for a session placed on a customer host.
  • The selfHostedSessions beta appearing as an admin setting for Team or Enterprise organizations, the tiers that got Claude Code's self-hosted beta.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories