Claude Code is the coding agent enterprise developers ask for by name. The catch, until now, has been deployment: financial services firms and other regulated industries couldn’t let an autonomous agent touch source code, credentials, and internal services on infrastructure they don’t control.
Coder just removed that barrier with Agent Relay, a self-hosted execution environment for cloud coding agents. Claude Code support launched this month.
️ How It Works
Each Coder workspace starts a Claude Code runner that opens an outbound connection to Anthropic’s backend. Anthropic continues to operate the agent loop and handle billing. Everything the agent actually touches, including the file system, credentials, and internal service access, stays inside the customer-controlled workspace.
Workspaces are sandboxed, ephemeral, and scoped to a single Claude Code session. Permitted data sources and network egress are defined once at the environment level and inherited by every workspace that follows. Every run produces a full audit record tied to the Claude Code session and the user it served.
What Regulated Teams Get
- Claude Code running on the team’s own cloud, VPC, or on-premises environment
- Network egress policy set and enforced by the platform team
- Process-level network policy that blocks and logs every agent request
- A complete audit trail for security review: where code runs, who has access, what the agent can reach, and what record exists afterward
- No new deployment or fresh security review for teams already running Agent Relay
Rollout
Coder launched Agent Relay with Cursor as its first agent provider. Anthropic’s engineering team brought Claude Code onto the relay within days of that launch. Coder says any provider of self-hosted cloud agents will be able to build on Agent Relay over time.
Claude Code support in Coder Agent Relay is currently in early access with selected design partners.
