Running Claude Code on Amazon Bedrock

Claude Code can send every request to Claude models in your own AWS account instead of Anthropic’s API. Why teams do it, the setup as Anthropic documents it, the IAM policy, what does not work on Bedrock, and what to check when it fails.

8 min read

To run Claude Code on Amazon Bedrock, enable Anthropic’s models in your AWS account, give Claude Code AWS credentials, and set CLAUDE_CODE_USE_BEDROCK=1 with a region. The quickest route is the built-in wizard: run claude, choose 3rd-party platform, then Amazon Bedrock, or type /setup-bedrock in a session. For a team, set the variables yourself and pin model versions, because the built-in defaults can lag the newest release or point at a model your account has not enabled. Most of Claude Code works the same; the features that need a claude.ai account, such as cloud sessions and Remote Control, do not.

Why teams run it through Bedrock

  • Billing. Usage lands on the AWS bill as pay-as-you-go and shows in Cost Explorer, against commitments you may already have. Anthropic suggests a dedicated AWS account for Claude Code to make that easy to see.
  • Access control. Who can call which model is an IAM decision, and every call is logged in CloudTrail, which your security team probably already watches.
  • Data location. Requests stay in AWS. Bedrock’s data protection page (opens in a new tab) says model providers have no access to the accounts that serve the models, and so no access to prompts and completions. A geographic inference profile keeps processing within, for example, the EU; a global profile does not.
  • Less traffic to Anthropic. On Bedrock, Claude Code turns error reporting and telemetry to Anthropic off by default.

The trade is features. A Claude Team or Enterprise seat includes claude.ai, the desktop app, cloud sessions and the admin console; Bedrock gives you the CLI, the IDE extensions and the Agent SDK against your own AWS account. If you are choosing between them, rolling out Claude Code to a team covers the seat-based route.

Step 1: enable the models

In the Bedrock console, open the Model catalog, pick an Anthropic model and submit the use case form. Anthropic’s guide says access is granted as soon as you submit, once per AWS account; with AWS Organizations, the management account can submit it once with the PutUseCaseForModelAccess API and the approval reaches child accounts.

Step 2: credentials

Claude Code uses the standard AWS SDK credential chain, so whatever already works for the AWS CLI works here. Anthropic’s Bedrock guide (opens in a new tab) lists these options:

Pick one
# An SSO profile (the usual choice for people)
aws sso login --profile=dev
export AWS_PROFILE=dev

# Console credentials
aws login

# Access keys (CI, or a role you assume)
export AWS_ACCESS_KEY_ID=...
export AWS_SECRET_ACCESS_KEY=...
export AWS_SESSION_TOKEN=...

# A Bedrock API key
export AWS_BEARER_TOKEN_BEDROCK=...

On API keys, AWS’s page on Bedrock API keys (opens in a new tab) recommends short-term keys, which last up to 12 hours and inherit the permissions of whoever generated them, and says long-term keys are for exploration only. For SSO that expires mid-session, put a refresh command in settings and Claude Code runs it when credentials run out:

~/.claude/settings.json
{
  "awsAuthRefresh": "aws sso login --profile dev",
  "env": { "AWS_PROFILE": "dev" }
}

Step 3: switch Claude Code to Bedrock and pin models

Environment, or the env block of settings
export CLAUDE_CODE_USE_BEDROCK=1
export AWS_REGION=us-east-1        # optional if your profile sets a region

# Pin each alias to a version your account has enabled
# (us. is the US cross-region prefix; use the one for your geography)
export ANTHROPIC_DEFAULT_OPUS_MODEL='us.anthropic.claude-opus-5-5'
export ANTHROPIC_DEFAULT_SONNET_MODEL='us.anthropic.claude-sonnet-4-6'
export ANTHROPIC_DEFAULT_HAIKU_MODEL='us.anthropic.claude-haiku-4-5-20251001-v1:0'

Without pinning, the opus alias and the primary model resolve to Opus 5.5 on Bedrock, while sonnet still resolves to Sonnet 4.5. Background jobs such as naming the session use the default Sonnet model rather than Haiku, because Haiku may not be enabled in every account; set ANTHROPIC_DEFAULT_HAIKU_MODEL to change that. The same pinning variables are covered for every provider in Claude Sonnet vs Opus.

The prefix on the model ID decides where requests may run. Claude Code picks us., eu. or apac. from your region, us-gov. in GovCloud, and global. for any other region. AWS’s page on cross-Region inference (opens in a new tab) says geographic profiles keep processing within that geography and global profiles route to any commercial region, so if residency matters, check the prefix, or set ANTHROPIC_BEDROCK_REGION_PREFIX=eu. For your own routing, ANTHROPIC_MODEL also accepts an application inference profile ARN, and the modelOverrides setting maps several versions to their own ARNs. Run /status to confirm the provider and the resolved region.

The IAM policy

This is the policy from Anthropic’s guide. Narrow Resource to the inference profile ARNs you use once you know them.

IAM policy for Claude Code on Bedrock
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "AllowModelAndInferenceProfileAccess",
      "Effect": "Allow",
      "Action": [
        "bedrock:InvokeModel",
        "bedrock:InvokeModelWithResponseStream",
        "bedrock:ListInferenceProfiles",
        "bedrock:GetInferenceProfile"
      ],
      "Resource": [
        "arn:aws:bedrock:*:*:inference-profile/*",
        "arn:aws:bedrock:*:*:application-inference-profile/*",
        "arn:aws:bedrock:*:*:foundation-model/*"
      ]
    },
    {
      "Sid": "AllowMarketplaceSubscription",
      "Effect": "Allow",
      "Action": ["aws-marketplace:ViewSubscriptions", "aws-marketplace:Subscribe"],
      "Resource": "*",
      "Condition": { "StringEquals": { "aws:CalledViaLast": "bedrock.amazonaws.com" } }
    }
  ]
}

ListInferenceProfiles lets Claude Code find which profiles your account has; without it, it applies the region prefix without checking. GetInferenceProfile lets it resolve an application profile ARN to its model; without it, each new model costs an extra round-trip. If you use Bedrock’s Mantle endpoint instead of the Invoke API, it needs its own bedrock-mantle:CreateInference and bedrock-mantle:CountTokens permissions.

What works differently on Bedrock

Anthropic’s feature availability table (opens in a new tab) is the list to check. The CLI, the VS Code and JetBrains extensions, subagents, hooks, skills, plugins, MCP servers, checkpoints, sandboxing and OpenTelemetry work on every provider. On Bedrock:

  • Anything that needs a claude.ai account is unavailable: cloud sessions, Claude Code on mobile and in Slack, the desktop app (except through Claude Desktop on 3P), Remote Control, routines, Code Review, the Chrome extension and voice dictation.
  • Web search, fast mode, the advisor and channels are not available.
  • There is no analytics dashboard and no server-managed settings. Deliver policy through a managed settings file or MDM instead.
  • Connectors added in claude.ai do not load. Add MCP servers to Claude Code directly.
  • Auto mode, the starting permission mode from Claude Code v2.1.283, runs only on Sonnet 5, Opus 4.7 or later and the Fable models. On an older model, such as the unpinned sonnet alias, the session starts in Manual mode.
  • /logout is unavailable, since AWS credentials handle sign-in.
  • The Compliance API on a Claude Enterprise plan does not cover Bedrock sessions. CloudTrail is your record.
  • Claude Code calls the Bedrock Invoke API, not the Converse API.

The other two clouds, in one line each

  • Google Cloud: set CLAUDE_CODE_USE_VERTEX=1, CLOUD_ML_REGION and ANTHROPIC_VERTEX_PROJECT_ID; see Anthropic’s Google Cloud guide (opens in a new tab), which now calls the service Google Cloud’s Agent Platform, formerly Vertex AI.
  • Microsoft Foundry: set CLAUDE_CODE_USE_FOUNDRY=1 and ANTHROPIC_FOUNDRY_RESOURCE, with an API key or Entra ID; there is no setup wizard, and the default model is Sonnet 4.5.

Troubleshooting

  • “on-demand throughput isn’t supported”: you used a bare model ID. Use an inference profile ID, such as one starting us. or eu..
  • Region errors: list what your region offers with aws bedrock list-inference-profiles --region <region>, and confirm what Claude Code resolved with /status.
  • 400 errors after changing ANTHROPIC_BEDROCK_REGION_PREFIX: your account may have no inference profiles with that prefix enabled. Choose another prefix or pin full IDs.
  • A notice that Claude Code fell back to another model: the default is not enabled in your account. Enable it in Bedrock or pin a version.
  • Browser tabs opening again and again with SSO: a VPN or TLS-inspecting proxy is interrupting the flow. Remove awsAuthRefresh and run aws sso login before starting.
  • unable to get local issuer certificate behind a corporate proxy: add the root certificate to the OS trust store or NODE_EXTRA_CA_CERTS, and update Claude Code.
  • “Bedrock streaming response has content-type” behind a gateway: the gateway rewrote the stream. Forward the response and its Content-Type unchanged.
  • Prompt cache counts stuck at zero: caching is not available in every Bedrock region.

Your board works the same

MCP servers are local to Claude Code, so they work on Bedrock exactly as on a Claude plan; only claude.ai connectors are missing. A fenbs board is one command, claude mcp add --transport http fenbs https://fenbs.ai/api/mcp, then /mcp to sign in: each developer gets a token that lasts an hour with a refresh token, limited to the scopes they tick and to their role on the board, and revocable at any time. For a CI job with no browser, issue a token by hand under Settings with a name, scopes and an expiry. Model calls stay in your AWS account; task updates go to the board, recorded in History under the person whose assistant made them.

Related

Managed settings and plugins for a team: Claude Code for teams. Choosing and pinning models: Claude Sonnet vs Opus. Routing through a gateway or local models: Claude Code with Ollama. Connecting a board: Claude Code and fenbs and the MCP docs.

Questions people ask.

How do I set up Claude Code with Amazon Bedrock?

Enable Anthropic models in the Bedrock console, make sure AWS credentials work, then run claude and choose 3rd-party platform and Amazon Bedrock, or set CLAUDE_CODE_USE_BEDROCK=1 and AWS_REGION yourself. Pin model IDs with ANTHROPIC_DEFAULT_OPUS_MODEL and its Sonnet and Haiku counterparts.

Which model does Claude Code use on Bedrock by default?

Opus 5.5 as the primary model, as of Claude Code v2.1.280, while the sonnet alias resolves to Sonnet 4.5. Pin versions for a team so everyone moves to a new model when you decide.

Do I need a Claude subscription to use Claude Code on Bedrock?

No. Claude Code authenticates with your AWS credentials and usage is billed through AWS. Features that need a claude.ai account, such as cloud sessions, Remote Control and the desktop app, are not available that way.

Does Claude Code on Bedrock keep data in my region?

It depends on the inference profile. A geographic profile such as eu. keeps processing within that geography; a global profile can route to any commercial AWS region. Claude Code chooses the prefix from your region unless you set ANTHROPIC_BEDROCK_REGION_PREFIX or pin model IDs.

Start with one thing.

There is nothing to set up first. Write one line and you’ve started.