Claude Desktop code points to a possible self-hosted Cowork path

A public bundle contains an organization-host URL and Cowork-related capability checks, while Anthropic's current Cowork documentation describes cloud and local execution.

By · Published

RUNTIMEWIRE INVESTIGATION — Original analysis

Original reporting by RuntimeWire, based on documents, reverse engineering.

Why it matters

The code suggests Anthropic may be extending customer-controlled agent execution beyond coding, but the bundle does not prove Cowork availability or customer-hosted model inference.

Reporting record

Finding

A static review of public Claude JavaScript bundles found an undocumented session-host configuration associated with Cowork-related capability checks, but did not establish that customers can access or use it.

How we verified

Methods: documents, reverse engineering.

The reviewed bundles define selfHostedUrl as “public-undocumented,” associate it with the selfHostedSessions beta flag, include selfHostedCowork capability checks, and contain host-routing, credential, memory, skills, and scheduled-task interface strings. The review covered 2,726 public JavaScript assets totaling about 118.5 MB.

Reviewed public JavaScript assets, including the configuration and capability-check bundles, for host-routing settings and related Cowork code paths and interface strings. The static review did not test a backend or confirm customer availability.

Reproduction

Reproduction does not apply to this reporting (document-driven).

Company response

RuntimeWire requested comment; the company had not responded by publication time.

We reached out for comment.
A laptop is connected by cable to a small unbranded server, illustrating a possible self-hosted Cowork path.

Claude Desktop's public JavaScript bundles contain an unreleased configuration for sending agent-session requests to an organization-specified HTTPS host, alongside code paths that refer to Cowork. The code points to a possible customer-hosted execution option; it does not establish that Anthropic has enabled or launched one.

A Claude Desktop bundle labels selfHostedUrl as "public-undocumented" and associates it with a beta feature named selfHostedSessions. Separate capability checks include selfHostedCowork. The configuration describes routing sessions to a supplied HTTPS endpoint, with sign-in and credential options that include identity-provider flows, credential-helper scripts and a static bearer token.

Diagram of unreleased Claude Desktop session-host configuration, its credential options, and a separate Cowork capability check; customer availability is not established.
The bundles describe client-side host-routing configuration and Cowork-related code, not a confirmed customer-accessible service — AI explanatory diagram, not documentary evidence. RuntimeWire · AI-generated diagram.

Other bundle strings sketch out the surrounding product behavior: memory and skills routes, host connection and sign-in errors, and scheduled tasks described as running on an organization's session host. One user-facing message says, "Claude runs on your organization's infrastructure, not on this computer." These strings are evidence of client-side implementation and interface planning. They do not show that the server exists, that customers can connect to it, or that the paths work in a deployed account.

The uncertainty matters because Anthropic's current Cowork architecture documentation describes cloud sessions on Anthropic-managed infrastructure and local sessions on a user's device. It does not describe an organization-operated Cowork host. The documentation says cloud sessions run in isolated sandboxes on Anthropic's servers; local sessions run the agent loop on the user's device and execute code in a local virtual machine.

Independent lanes show documented Cowork cloud and local sessions; a separate callout notes that current documentation does not describe an organization-operated host.
Anthropic’s current Cowork documentation describes cloud sessions on its infrastructure and local sessions on a user’s device, not an organization-operated Cowork host — AI explanatory diagram, not documentary evidence. RuntimeWire · AI-generated diagram.

Anthropic has already made customer-operated execution available elsewhere. Its August 6th announcement put self-hosted environments for Claude Code into public beta for Team and Enterprise customers. Anthropic says those sessions run inside an organization's network, alongside its internal services and tools. The company's Managed Agents documentation describes another arrangement: customer infrastructure runs tools and holds files, while orchestration and model interactions remain with Anthropic.

Those products establish a precedent for separating agent execution from model inference. They do not identify the host in the Desktop bundle as a Cowork product. The code could be shared across Anthropic services or support a deployment path that is not customer-accessible. The bundle does not establish where inference would occur or what data-processing terms would apply. "Self-hosted" in this context should not be read as evidence that Claude's model runs inside a customer's network.

The code review covered 2,726 public JavaScript assets totaling about 118.5 MB, according to the analysis accompanying the finding. The reviewed entry asset carries an October 1st CDN modification timestamp; that dates the object, not the addition of the feature. The static review did not test a backend or confirm customer availability. Anthropic's public Cowork materials describe cloud and local modes, while its customer-hosted execution products remain separately documented for Claude Code and Managed Agents.

If Anthropic enables the path, an organization-hosted session could let administrators place agent work closer to internal systems and manage its execution environment. The same arrangement would make the host's access controls, credentials, network rules and operational security central to deployment. For now, the bundle supports a narrower conclusion: Claude Desktop contains unreleased session-host plumbing with Cowork-related flags, not a confirmed self-hosted Cowork beta.

Reader comments

Conversation for this story loads after sign-in.