Skip to content

Claude Platform on AWS

Point Claude Code at a Claude Platform on AWS workspace: AWS or API key authentication, the routing variables, model pinning, proxies and common errors.

Claude Platform on AWS is the Claude API run by Anthropic, but bought through AWS Marketplace and accessed with AWS authentication and IAM. Because requests go to Anthropic's own API, you get the same models and API features as the direct Claude API on the same release schedule. The difference from Amazon Bedrock is who operates the endpoint: here it is Anthropic, with AWS handling billing and identity.

From Claude Code's point of view it is another provider. Client-side features that Claude Code normally enables through Anthropic's feature-flag service are off by default, and the Advisor is unavailable. The feature availability page lists what else differs.

This page assumes you have already subscribed through AWS Marketplace and created a workspace. If not, do that first in the AWS and Claude Platform consoles.

Note: Subscribing through AWS Marketplace creates a brand-new Anthropic organisation linked to your AWS account. It is separate from any Claude Console organisation you already have, and credentials do not carry across. Use the workspace ID and keys from the AWS-linked organisation.

What you need

  • An active Claude Platform on AWS subscription.
  • A workspace in the AWS-linked organisation, and its workspace ID.
  • Either an IAM principal allowed to invoke the Anthropic service, or a workspace API key.
  • For SigV4, AWS credentials somewhere in the standard chain (environment, ~/.aws/credentials, an attached role). The AWS CLI is only needed for SSO logins.

Step 1: choose how to authenticate

AWS credentials (SigV4)Workspace API key
What it isRequests signed as an IAM principalA long-lived secret generated in the AWS Console
Good forTeams already using SSO or roles; CI with an attached roleSimple setups where you do not want federated credentials
Set withThe normal AWS credential chainANTHROPIC_AWS_API_KEY

SigV4 with AWS credentials

Claude Code signs requests using whatever the AWS SDK credential chain finds. Locally, sign in first:

aws sso login --profile data-platform
export AWS_PROFILE=data-platform

In CI, give the runner a role that can invoke the Anthropic service and set AWS_REGION; the chain picks the role up.

To avoid sessions dying when SSO credentials expire, set awsAuthRefresh in your settings:

{ "awsAuthRefresh": "aws sso login --profile data-platform" }

Claude Code then reruns the command and retries when credentials lapse. It also runs it at startup if it cannot validate your existing credentials, showing the output in an Authentication panel until you finish. With it configured, you can refresh by hand too: /login, choose 3rd-party platform, then Claude Platform on AWS · refresh credentials under Using 3rd-party platforms. No restart needed.

Workspace API key

Generate a key in the AWS Console under Claude Platform on AWS → API keys:

export ANTHROPIC_AWS_API_KEY=sk-ant-...

It is sent as x-api-key and wins over SigV4, so any AWS credentials present are ignored. Keys from a separate Console organisation will not work. Treat it like any production secret; I keep mine in the env block of user settings rather than exporting it in every shell.

/login and /logout do not sign you in to a claude.ai subscription here. Authentication is always your AWS credentials or the workspace key.

Step 2: route Claude Code to the platform

export CLAUDE_CODE_USE_ANTHROPIC_AWS=1
export ANTHROPIC_AWS_WORKSPACE_ID=wrkspc_01XYZEXAMPLE0000
export AWS_REGION=eu-west-1
  • ANTHROPIC_AWS_WORKSPACE_ID is mandatory and is sent on every request as the anthropic-workspace-id header. Your AWS credentials do not imply it.
  • The base URL is https://aws-external-anthropic.{region}.api.aws, with the region resolved exactly as for Bedrock (AWS_REGION, AWS_DEFAULT_REGION, the profile's region, then us-east-1). Override it with ANTHROPIC_AWS_BASE_URL.
  • The provider is opt-in even if AWS credentials are lying around. Bedrock and Foundry take precedence in routing, so unset CLAUDE_CODE_USE_BEDROCK and CLAUDE_CODE_USE_FOUNDRY if they are set.

Step 3: pin your models

The platform uses the same model IDs as the direct Claude API. The aliases fable, opus, sonnet and haiku resolve to Claude Code's built-in defaults for this provider, which may trail the latest release. Unpinned, opus means Opus 5.5 (before v2.1.280 it was Opus 5 from v2.1.219, Opus 4.8 from v2.1.207 and Opus 4.7 before that).

For a team, pin explicitly so a Claude Code update does not move everyone at once:

export ANTHROPIC_DEFAULT_FABLE_MODEL=claude-fable-5
export ANTHROPIC_DEFAULT_OPUS_MODEL=claude-opus-4-8
export ANTHROPIC_DEFAULT_SONNET_MODEL=claude-sonnet-5
export ANTHROPIC_DEFAULT_HAIKU_MODEL=claude-haiku-4-5

Prompt caching is on automatically. ENABLE_PROMPT_CACHING_1H=1 requests a one-hour TTL instead of five minutes, at a higher write price. See model configuration for every model variable.

Step 4: check it

Start claude. The banner should say Claude Platform on AWS. In /status, the API provider line reads Claude Platform on AWS, and you will see your Workspace ID, AWS region and, if overridden, the Claude Platform on AWS base URL.

Using it from the Agent SDK

The Agent SDK reads the same environment variables, so set them before your program starts the Claude Code process. A small Python example that summarises a repository's open TODOs:

import os
import asyncio
from claude_agent_sdk import query

os.environ["CLAUDE_CODE_USE_ANTHROPIC_AWS"] = "1"
os.environ["ANTHROPIC_AWS_WORKSPACE_ID"] = "wrkspc_01XYZEXAMPLE0000"
os.environ["AWS_REGION"] = "eu-west-1"

async def main():
    async for message in query(prompt="List the TODO comments in this repo, grouped by file"):
        print(message)

asyncio.run(main())

That relies on the ambient credential chain. Set ANTHROPIC_AWS_API_KEY instead to use a workspace key.

Going through a proxy or gateway

Point ANTHROPIC_AWS_BASE_URL at the proxy. Claude Code sends the same workspace and auth headers, so any gateway that forwards them untouched works:

export CLAUDE_CODE_USE_ANTHROPIC_AWS=1
export ANTHROPIC_AWS_WORKSPACE_ID=wrkspc_01XYZEXAMPLE0000
export ANTHROPIC_AWS_BASE_URL=https://llm-egress.example.internal

If the gateway signs requests itself, add CLAUDE_CODE_SKIP_ANTHROPIC_AWS_AUTH=1 so Claude Code sends them unsigned. If the gateway wants its own token, put it in ANTHROPIC_AUTH_TOKEN. See LLM gateway for the wider picture.

Troubleshooting

Start with /status: it shows the resolved provider, workspace ID, region, base URL override and whether auth is skipped.

SymptomLikely causeFix
403 Forbidden or AccessDenied on everythingThe IAM principal lacks the aws-external-anthropic actions, or a stale ANTHROPIC_AWS_API_KEY is overriding SigV4Grant the actions to the role; regenerate the key or unset it
Missing-workspace errorANTHROPIC_AWS_WORKSPACE_ID unset or emptyExport the workspace ID
Requests still go to api.anthropic.comCLAUDE_CODE_USE_ANTHROPIC_AWS unset or not truthy, or a higher-precedence provider variable is setSet it to 1; unset the Bedrock and Foundry variables