Claude Managed Agents' MCP tunnels and sandboxes move credential control to the network boundary — a production fix for ...