Claude Platform on AWS
Point Claude Code at a Claude Platform on AWS workspace: AWS or API key authentication, the routing variables, model pinning, proxies and common errors.
Claude Platform on AWS is the Claude API run by Anthropic, but bought through AWS Marketplace and accessed with AWS authentication and IAM. Because requests go to Anthropic's own API, you get the same models and API features as the direct Claude API on the same release schedule. The difference from Amazon Bedrock is who operates the endpoint: here it is Anthropic, with AWS handling billing and identity.
From Claude Code's point of view it is another provider. Client-side features that Claude Code normally enables through Anthropic's feature-flag service are off by default, and the Advisor is unavailable. The feature availability page lists what else differs.
This page assumes you have already subscribed through AWS Marketplace and created a workspace. If not, do that first in the AWS and Claude Platform consoles.
Note: Subscribing through AWS Marketplace creates a brand-new Anthropic organisation linked to your AWS account. It is separate from any Claude Console organisation you already have, and credentials do not carry across. Use the workspace ID and keys from the AWS-linked organisation.
What you need
- An active Claude Platform on AWS subscription.
- A workspace in the AWS-linked organisation, and its workspace ID.
- Either an IAM principal allowed to invoke the Anthropic service, or a workspace API key.
- For SigV4, AWS credentials somewhere in the standard chain (environment,
~/.aws/credentials, an attached role). The AWS CLI is only needed for SSO logins.
Step 1: choose how to authenticate
| AWS credentials (SigV4) | Workspace API key | |
|---|---|---|
| What it is | Requests signed as an IAM principal | A long-lived secret generated in the AWS Console |
| Good for | Teams already using SSO or roles; CI with an attached role | Simple setups where you do not want federated credentials |
| Set with | The normal AWS credential chain | ANTHROPIC_AWS_API_KEY |
SigV4 with AWS credentials
Claude Code signs requests using whatever the AWS SDK credential chain finds. Locally, sign in first:
aws sso login --profile data-platform
export AWS_PROFILE=data-platform
In CI, give the runner a role that can invoke the Anthropic service and set AWS_REGION; the chain picks the role up.
To avoid sessions dying when SSO credentials expire, set awsAuthRefresh in your settings:
{ "awsAuthRefresh": "aws sso login --profile data-platform" }
Claude Code then reruns the command and retries when credentials lapse. It also runs it at startup if it cannot validate your existing credentials, showing the output in an Authentication panel until you finish. With it configured, you can refresh by hand too: /login, choose 3rd-party platform, then Claude Platform on AWS · refresh credentials under Using 3rd-party platforms. No restart needed.
Workspace API key
Generate a key in the AWS Console under Claude Platform on AWS → API keys:
export ANTHROPIC_AWS_API_KEY=sk-ant-...
It is sent as x-api-key and wins over SigV4, so any AWS credentials present are ignored. Keys from a separate Console organisation will not work. Treat it like any production secret; I keep mine in the env block of user settings rather than exporting it in every shell.
/login and /logout do not sign you in to a claude.ai subscription here. Authentication is always your AWS credentials or the workspace key.
Step 2: route Claude Code to the platform
export CLAUDE_CODE_USE_ANTHROPIC_AWS=1
export ANTHROPIC_AWS_WORKSPACE_ID=wrkspc_01XYZEXAMPLE0000
export AWS_REGION=eu-west-1
ANTHROPIC_AWS_WORKSPACE_IDis mandatory and is sent on every request as theanthropic-workspace-idheader. Your AWS credentials do not imply it.- The base URL is
https://aws-external-anthropic.{region}.api.aws, with the region resolved exactly as for Bedrock (AWS_REGION,AWS_DEFAULT_REGION, the profile's region, thenus-east-1). Override it withANTHROPIC_AWS_BASE_URL. - The provider is opt-in even if AWS credentials are lying around. Bedrock and Foundry take precedence in routing, so unset
CLAUDE_CODE_USE_BEDROCKandCLAUDE_CODE_USE_FOUNDRYif they are set.
Step 3: pin your models
The platform uses the same model IDs as the direct Claude API. The aliases fable, opus, sonnet and haiku resolve to Claude Code's built-in defaults for this provider, which may trail the latest release. Unpinned, opus means Opus 5.5 (before v2.1.280 it was Opus 5 from v2.1.219, Opus 4.8 from v2.1.207 and Opus 4.7 before that).
For a team, pin explicitly so a Claude Code update does not move everyone at once:
export ANTHROPIC_DEFAULT_FABLE_MODEL=claude-fable-5
export ANTHROPIC_DEFAULT_OPUS_MODEL=claude-opus-4-8
export ANTHROPIC_DEFAULT_SONNET_MODEL=claude-sonnet-5
export ANTHROPIC_DEFAULT_HAIKU_MODEL=claude-haiku-4-5
Prompt caching is on automatically. ENABLE_PROMPT_CACHING_1H=1 requests a one-hour TTL instead of five minutes, at a higher write price. See model configuration for every model variable.
Step 4: check it
Start claude. The banner should say Claude Platform on AWS. In /status, the API provider line reads Claude Platform on AWS, and you will see your Workspace ID, AWS region and, if overridden, the Claude Platform on AWS base URL.
Using it from the Agent SDK
The Agent SDK reads the same environment variables, so set them before your program starts the Claude Code process. A small Python example that summarises a repository's open TODOs:
import os
import asyncio
from claude_agent_sdk import query
os.environ["CLAUDE_CODE_USE_ANTHROPIC_AWS"] = "1"
os.environ["ANTHROPIC_AWS_WORKSPACE_ID"] = "wrkspc_01XYZEXAMPLE0000"
os.environ["AWS_REGION"] = "eu-west-1"
async def main():
async for message in query(prompt="List the TODO comments in this repo, grouped by file"):
print(message)
asyncio.run(main())
That relies on the ambient credential chain. Set ANTHROPIC_AWS_API_KEY instead to use a workspace key.
Going through a proxy or gateway
Point ANTHROPIC_AWS_BASE_URL at the proxy. Claude Code sends the same workspace and auth headers, so any gateway that forwards them untouched works:
export CLAUDE_CODE_USE_ANTHROPIC_AWS=1
export ANTHROPIC_AWS_WORKSPACE_ID=wrkspc_01XYZEXAMPLE0000
export ANTHROPIC_AWS_BASE_URL=https://llm-egress.example.internal
If the gateway signs requests itself, add CLAUDE_CODE_SKIP_ANTHROPIC_AWS_AUTH=1 so Claude Code sends them unsigned. If the gateway wants its own token, put it in ANTHROPIC_AUTH_TOKEN. See LLM gateway for the wider picture.
Troubleshooting
Start with /status: it shows the resolved provider, workspace ID, region, base URL override and whether auth is skipped.
| Symptom | Likely cause | Fix |
|---|---|---|
403 Forbidden or AccessDenied on everything | The IAM principal lacks the aws-external-anthropic actions, or a stale ANTHROPIC_AWS_API_KEY is overriding SigV4 | Grant the actions to the role; regenerate the key or unset it |
| Missing-workspace error | ANTHROPIC_AWS_WORKSPACE_ID unset or empty | Export the workspace ID |
Requests still go to api.anthropic.com | CLAUDE_CODE_USE_ANTHROPIC_AWS unset or not truthy, or a higher-precedence provider variable is set | Set it to 1; unset the Bedrock and Foundry variables |