
15 Sep 2026
Coder puts Claude Code on Agent Relay so the work stays on your machines
Coder said Claude Code now runs through Agent Relay, so the coding agent’s work happens inside the customer’s own Coder workspaces — sandboxed and logged — while Anthropic still handles billing and the agent loop.
SOFTWARE desk — same-day company primary that a workspace vendor put Anthropic’s coding agent on customer-owned machines for regulated shops, without claiming a general ship.
The split, still company: Anthropic continues to handle billing and run the agent loop — the step-by-step plan the coding agent follows — while everything the agent touches lives on machines the customer controls. The work runs inside Coder workspaces on the customer’s cloud, VPC, or on-premises setup: network-governed, sandboxed, and fully auditable. A VPC is a virtual private cloud, a private slice of a public cloud. Sandboxed here means the session is walled off so it cannot wander the rest of the network by default. File that Anthropic-bills-and-steers / customer-owns-the-machines picture as Coder’s. This desk did not sit on a workspace.
Why the company says this exists: Claude Code has become the coding agent enterprise developers ask for by name, but adoption in regulated industries has been limited by deployment, not demand. Financial-services and other regulated shops, Coder says, cannot let an autonomous agent reach source code, credentials, and internal services on infrastructure outside the organization’s control. Agent Relay is meant to answer the approval questions: where code runs, who has access, what the agent can reach, and what record exists afterward. File that deployment-gap picture as Coder’s. This desk did not audit a bank’s review board.
Timeline, as the same wire has it: Coder launched Agent Relay on 2 Sep 2026 with Cursor as its first agent provider. Anthropic’s engineering team then worked with Coder to bring Claude Code onto the relay within days of that launch. For platform teams already running Agent Relay, turning on Claude Code needs no new deployment and no fresh security review — the workspace model, the egress policy, and the audit trail are already in place, and Claude Code inherits all of it on day one. Egress policy is the rule for what traffic may leave the workspace. Coder says it plans to extend the integration over time, and that any provider of self-hosted cloud agents will be able to build on the same governed model. File that Sept 2 / Cursor-first / Claude-within-days / inherit-the-controls picture as Coder’s. This desk did not watch the Sept 2 launch or a security review.
How the integration works, still company: it is built on Claude Code’s publicly available self-hosted environments. Each Coder workspace starts a Claude Code runner that opens an outbound connection to Anthropic’s backend. Developers keep the Claude Code experience they already use in Claude Desktop and claude.ai. Anthropic continues to handle account administration, billing, and inference — the model-compute that produces the next action. Tool calls execute inside the self-hosted workspaces, so the agent’s filesystem, credentials, and access to internal services stay in the customer-controlled environment. Workspaces are sandboxed, ephemeral, and scoped to a single Claude Code session, with permitted data sources and network egress defined once at the environment level and inherited by every workspace that follows. Every run produces an audit record of workspace provisioning and lifecycle, correlated to the Claude Code session and the user it served. Teams can add process-level network policy that blocks and logs every request the agent makes. File that runner / outbound / local-tool-call / ephemeral / audit picture as Coder’s. This desk did not open a runner or read an audit log.
Named voices on the release: Cat Wu, head of product for Claude Code at Anthropic; and Josh Epstein, president at Coder. File the names and titles as theirs, via Coder. Their quotes are color only and stay in Sources. Wu’s line is Anthropic via the Coder wire — not a separate Anthropic newsroom primary.
Availability, company: Claude Code support in Coder Agent Relay is in early access with select design partners. Documentation and deployment guides are at coder.com/anthropic. File that early-access / design-partners line as Coder’s. This desk did not join the preview. The release does not print a price. This desk is not inventing one. This is not general availability.
About-box context, optional and company-attributed: Coder calls itself the AI Operating Layer for the enterprise — self-hosted, model- and cloud-agnostic infrastructure that runs AI inside the organization’s own environment. It says Global 2000 enterprises and government agencies use Coder to give developers and autonomous agents one governed workspace, moving source code off laptops onto centrally managed infrastructure. The same box claims more than 125,000 GitHub stars. File those about-box lines as Coder’s. This desk did not count stars or call a Global 2000 customer.
Plain English for the rest of the card: Agent Relay = Coder’s bridge that keeps a cloud coding agent’s experience while running the file-and-tool work on your machines. agent loop = the step-by-step plan the coding agent follows. inference = the model-compute that produces the next action. VPC = virtual private cloud, a private slice of a public cloud. sandbox = a walled-off session. egress policy = the rule for what traffic may leave. early access = a limited preview with design partners, not a general ship.
PRIMARY here: Coder’s 15 Sep 2026 GlobeNewswire company release — Tier A PRIMARY company source, the original record. The coder.com/anthropic docs page is product-home context, not a second originating newsroom. The Claude Code-on-Agent-Relay announce, the Anthropic-bills-and-runs-the-loop / customer-owns-the-machines split, the cloud / VPC / on-prem workspace picture, the regulated-industry deployment-gap framing, the 2 Sep 2026 Cursor-first launch, the Anthropic-within-days add, the no-new-deployment / no-fresh-security-review inherit line, the self-hosted runner / outbound-to-Anthropic / local-tool-call / ephemeral-session / audit-record / process-level-policy picture, the Wu and Epstein titles, the early-access / select-design-partners / coder.com/anthropic availability, the AI-Operating-Layer about-box, the Global 2000 / government-agency line, and the more-than-125,000 GitHub stars claim are company-attributed. Capability lists and the star count stay company-attributed — not independently verified here. Wu’s quote is Anthropic via Coder. NOT claimed: pricing, general availability, named design partners, independently verified GitHub-star or customer counts, that every Agent Relay tenant already has Claude Code on, that this desk tested Agent Relay or Claude Code, a stock tip, or investment advice. Distinct from the already-filed stackhawk-wingman, wso2-agent-manager-ga, rockwell-anthropic-glasswing, nofire-brig-open-source, augmentir-augie-command-center, and digicert-ai-trust-manager.
RELATED
- StackHawk launches Wingman to fix security holes while the AI is still coding
- WSO2 ships Agent Manager GA to govern enterprise AI agents without locking to one stack
- Rockwell joins Anthropic’s Project Glasswing for industrial cyber defense
- NOFire open-sources Brig, a microVM sandbox for AI coding agents
- Augmentir launches Augie Command Center so factories run ops in plain language
- DigiCert launches AI Trust Manager with agent passports and a kill switch
On 15 Sep 2026 Coder announced Claude Code support with Agent Relay. Agent Relay, as the company tells it, is a self-hosted execution environment for cloud coding agents — the agent’s thinking can stay in the vendor’s cloud, while the files it touches run on machines the customer already operates. The company PRIMARY is Coder Technologies, Inc.’s GlobeNewswire release “Coder Brings Claude Code to Agent Relay, Unlocking Agentic Development for the World’s Most Regulated Enterprises,” dated September 15, 2026, 09:05 ET, SOURCE Coder Technologies, Inc., and datelined AUSTIN, Texas. That company wire is the filing event. These are company claims. This desk did not run Agent Relay or Claude Code.



















