Running Claude Code on Amazon Bedrock
Claude Code can send every request to Claude models in your own AWS account instead of Anthropic’s API. Why teams do it, the setup as Anthropic documents it, the IAM policy, what does not work on Bedrock, and what to check when it fails.
8 min read
To run Claude Code on Amazon Bedrock, enable Anthropic’s models in your AWS account, give Claude Code AWS credentials, and set CLAUDE_CODE_USE_BEDROCK=1 with a region. The quickest route is the built-in wizard: run claude, choose 3rd-party platform, then Amazon Bedrock, or type /setup-bedrock in a session. For a team, set the variables yourself and pin model versions, because the built-in defaults can lag the newest release or point at a model your account has not enabled. Most of Claude Code works the same; the features that need a claude.ai account, such as cloud sessions and Remote Control, do not.
Why teams run it through Bedrock
- Billing. Usage lands on the AWS bill as pay-as-you-go and shows in Cost Explorer, against commitments you may already have. Anthropic suggests a dedicated AWS account for Claude Code to make that easy to see.
- Access control. Who can call which model is an IAM decision, and every call is logged in CloudTrail, which your security team probably already watches.
- Data location. Requests stay in AWS. Bedrock’s data protection page (opens in a new tab) says model providers have no access to the accounts that serve the models, and so no access to prompts and completions. A geographic inference profile keeps processing within, for example, the EU; a global profile does not.
- Less traffic to Anthropic. On Bedrock, Claude Code turns error reporting and telemetry to Anthropic off by default.
The trade is features. A Claude Team or Enterprise seat includes claude.ai, the desktop app, cloud sessions and the admin console; Bedrock gives you the CLI, the IDE extensions and the Agent SDK against your own AWS account. If you are choosing between them, rolling out Claude Code to a team covers the seat-based route.
Step 1: enable the models
In the Bedrock console, open the Model catalog, pick an Anthropic model and submit the use case form. Anthropic’s guide says access is granted as soon as you submit, once per AWS account; with AWS Organizations, the management account can submit it once with the PutUseCaseForModelAccess API and the approval reaches child accounts.
Step 2: credentials
Claude Code uses the standard AWS SDK credential chain, so whatever already works for the AWS CLI works here. Anthropic’s Bedrock guide (opens in a new tab) lists these options:
# An SSO profile (the usual choice for people) aws sso login --profile=dev export AWS_PROFILE=dev # Console credentials aws login # Access keys (CI, or a role you assume) export AWS_ACCESS_KEY_ID=... export AWS_SECRET_ACCESS_KEY=... export AWS_SESSION_TOKEN=... # A Bedrock API key export AWS_BEARER_TOKEN_BEDROCK=...
On API keys, AWS’s page on Bedrock API keys (opens in a new tab) recommends short-term keys, which last up to 12 hours and inherit the permissions of whoever generated them, and says long-term keys are for exploration only. For SSO that expires mid-session, put a refresh command in settings and Claude Code runs it when credentials run out:
{
"awsAuthRefresh": "aws sso login --profile dev",
"env": { "AWS_PROFILE": "dev" }
}Step 3: switch Claude Code to Bedrock and pin models
export CLAUDE_CODE_USE_BEDROCK=1 export AWS_REGION=us-east-1 # optional if your profile sets a region # Pin each alias to a version your account has enabled # (us. is the US cross-region prefix; use the one for your geography) export ANTHROPIC_DEFAULT_OPUS_MODEL='us.anthropic.claude-opus-5-5' export ANTHROPIC_DEFAULT_SONNET_MODEL='us.anthropic.claude-sonnet-4-6' export ANTHROPIC_DEFAULT_HAIKU_MODEL='us.anthropic.claude-haiku-4-5-20251001-v1:0'
Without pinning, the opus alias and the primary model resolve to Opus 5.5 on Bedrock, while sonnet still resolves to Sonnet 4.5. Background jobs such as naming the session use the default Sonnet model rather than Haiku, because Haiku may not be enabled in every account; set ANTHROPIC_DEFAULT_HAIKU_MODEL to change that. The same pinning variables are covered for every provider in Claude Sonnet vs Opus.
The prefix on the model ID decides where requests may run. Claude Code picks us., eu. or apac. from your region, us-gov. in GovCloud, and global. for any other region. AWS’s page on cross-Region inference (opens in a new tab) says geographic profiles keep processing within that geography and global profiles route to any commercial region, so if residency matters, check the prefix, or set ANTHROPIC_BEDROCK_REGION_PREFIX=eu. For your own routing, ANTHROPIC_MODEL also accepts an application inference profile ARN, and the modelOverrides setting maps several versions to their own ARNs. Run /status to confirm the provider and the resolved region.
The IAM policy
This is the policy from Anthropic’s guide. Narrow Resource to the inference profile ARNs you use once you know them.
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "AllowModelAndInferenceProfileAccess",
"Effect": "Allow",
"Action": [
"bedrock:InvokeModel",
"bedrock:InvokeModelWithResponseStream",
"bedrock:ListInferenceProfiles",
"bedrock:GetInferenceProfile"
],
"Resource": [
"arn:aws:bedrock:*:*:inference-profile/*",
"arn:aws:bedrock:*:*:application-inference-profile/*",
"arn:aws:bedrock:*:*:foundation-model/*"
]
},
{
"Sid": "AllowMarketplaceSubscription",
"Effect": "Allow",
"Action": ["aws-marketplace:ViewSubscriptions", "aws-marketplace:Subscribe"],
"Resource": "*",
"Condition": { "StringEquals": { "aws:CalledViaLast": "bedrock.amazonaws.com" } }
}
]
}ListInferenceProfiles lets Claude Code find which profiles your account has; without it, it applies the region prefix without checking. GetInferenceProfile lets it resolve an application profile ARN to its model; without it, each new model costs an extra round-trip. If you use Bedrock’s Mantle endpoint instead of the Invoke API, it needs its own bedrock-mantle:CreateInference and bedrock-mantle:CountTokens permissions.
What works differently on Bedrock
Anthropic’s feature availability table (opens in a new tab) is the list to check. The CLI, the VS Code and JetBrains extensions, subagents, hooks, skills, plugins, MCP servers, checkpoints, sandboxing and OpenTelemetry work on every provider. On Bedrock:
- Anything that needs a claude.ai account is unavailable: cloud sessions, Claude Code on mobile and in Slack, the desktop app (except through Claude Desktop on 3P), Remote Control, routines, Code Review, the Chrome extension and voice dictation.
- Web search, fast mode, the advisor and channels are not available.
- There is no analytics dashboard and no server-managed settings. Deliver policy through a managed settings file or MDM instead.
- Connectors added in claude.ai do not load. Add MCP servers to Claude Code directly.
- Auto mode, the starting permission mode from Claude Code v2.1.283, runs only on Sonnet 5, Opus 4.7 or later and the Fable models. On an older model, such as the unpinned
sonnetalias, the session starts in Manual mode. /logoutis unavailable, since AWS credentials handle sign-in.- The Compliance API on a Claude Enterprise plan does not cover Bedrock sessions. CloudTrail is your record.
- Claude Code calls the Bedrock Invoke API, not the Converse API.
The other two clouds, in one line each
- Google Cloud: set
CLAUDE_CODE_USE_VERTEX=1,CLOUD_ML_REGIONandANTHROPIC_VERTEX_PROJECT_ID; see Anthropic’s Google Cloud guide (opens in a new tab), which now calls the service Google Cloud’s Agent Platform, formerly Vertex AI. - Microsoft Foundry: set
CLAUDE_CODE_USE_FOUNDRY=1andANTHROPIC_FOUNDRY_RESOURCE, with an API key or Entra ID; there is no setup wizard, and the default model is Sonnet 4.5.
Troubleshooting
- “on-demand throughput isn’t supported”: you used a bare model ID. Use an inference profile ID, such as one starting
us.oreu.. - Region errors: list what your region offers with
aws bedrock list-inference-profiles --region <region>, and confirm what Claude Code resolved with/status. - 400 errors after changing
ANTHROPIC_BEDROCK_REGION_PREFIX: your account may have no inference profiles with that prefix enabled. Choose another prefix or pin full IDs. - A notice that Claude Code fell back to another model: the default is not enabled in your account. Enable it in Bedrock or pin a version.
- Browser tabs opening again and again with SSO: a VPN or TLS-inspecting proxy is interrupting the flow. Remove
awsAuthRefreshand runaws sso loginbefore starting. unable to get local issuer certificatebehind a corporate proxy: add the root certificate to the OS trust store orNODE_EXTRA_CA_CERTS, and update Claude Code.- “Bedrock streaming response has content-type” behind a gateway: the gateway rewrote the stream. Forward the response and its
Content-Typeunchanged. - Prompt cache counts stuck at zero: caching is not available in every Bedrock region.
Your board works the same
MCP servers are local to Claude Code, so they work on Bedrock exactly as on a Claude plan; only claude.ai connectors are missing. A fenbs board is one command, claude mcp add --transport http fenbs https://fenbs.ai/api/mcp, then /mcp to sign in: each developer gets a token that lasts an hour with a refresh token, limited to the scopes they tick and to their role on the board, and revocable at any time. For a CI job with no browser, issue a token by hand under Settings with a name, scopes and an expiry. Model calls stay in your AWS account; task updates go to the board, recorded in History under the person whose assistant made them.
Related
Managed settings and plugins for a team: Claude Code for teams. Choosing and pinning models: Claude Sonnet vs Opus. Routing through a gateway or local models: Claude Code with Ollama. Connecting a board: Claude Code and fenbs and the MCP docs.