Claude Code on Amazon Bedrock changedamazon-bedrock
Nearest release: v2.1.294, published an hour after upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 8 Oct 2026 02:40 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 8 Oct 2026 03:07 UTC.
Upstream edited
Recorded here
Lines+38added
Lines−13removed
From line
122
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits29to this page, all time
#### Use `aws configure` #### Export an access key #### Use an SSO profile #### Use AWS Management Console credentials #### Use an Amazon Bedrock API key
The whole hunk
from line 122, old and new numbered
/
from line 122
122122
123123### 2. Configure AWS credentials
124124
125Claude Code uses the default AWS SDK credential chain. Set up your credentials using one of these methods:
125Claude Code uses the default AWS SDK credential chain. If the machine already supplies credentials to that chain, such as an Amazon EC2 instance profile or Amazon ECS task credentials, skip to [step 3](#3-configure-claude-code).
126126
127**Option A: AWS CLI configuration**
127AWS [warns against using an IAM user's access keys](https://docs.aws.amazon.com/cli/latest/userguide/cli-authentication-user.html) when you develop purpose-built software or work with real data. Set up your credentials with one of these methods:
128128
129* [`aws configure`](#use-aws-configure): save an IAM user's access key to a profile in your `~/.aws` directory
130* [Access key environment variables](#export-an-access-key): set an access key, or temporary credentials with a session token, in the current shell only
131* [SSO profile](#use-an-sso-profile): sign in through IAM Identity Center in your browser and get temporary credentials. Use this method if you access your AWS account through IAM Identity Center.
132* [AWS Management Console credentials](#use-aws-management-console-credentials): sign in through your browser with your AWS Management Console credentials and get temporary credentials. AWS [recommends this method](https://docs.aws.amazon.com/signin/latest/userguide/command-line-sign-in.html) if you access your AWS account as the root user, as an IAM user, or through federation with IAM.
133* [Amazon Bedrock API key](#use-an-amazon-bedrock-api-key): authenticate with a bearer token that works only for Amazon Bedrock, instead of AWS credentials
134
135#### Use `aws configure`
136
137Run `aws configure` and enter your access key ID, secret access key, and default region when prompted:
138
129139```bash theme={null}
130140aws configure
131141```
132142
133**Option B: Environment variables (access key)**
143The AWS CLI saves the key to the `default` profile in `~/.aws/credentials`, where the credential chain reads it.
134144
145#### Export an access key
146
147Export your access key as environment variables. `AWS_SESSION_TOKEN` is required only with temporary credentials, so leave that line out if your access key belongs to an IAM user:
148
135149```bash theme={null}
136150export AWS_ACCESS_KEY_ID=your-access-key-id
137151export AWS_SECRET_ACCESS_KEY=your-secret-access-key
from line 152
138152export AWS_SESSION_TOKEN=your-session-token
139153```
140154
141**Option C: Environment variables (SSO profile)**
155#### Use an SSO profile
142156
143Replace `your-profile-name` with the name of your AWS profile before running these commands.
157Create a profile with `aws configure sso` if you don't have one. Then sign in to IAM Identity Center and set `AWS_PROFILE` so the credential chain uses that profile. Replace `your-profile-name` with the name of your AWS profile before running these commands.
144158
145159```bash theme={null}
146160aws sso login --profile=your-profile-name
from line 164
150164
151165Claude Code requests role credentials from the IAM Identity Center region named by the profile's `sso_region`, which doesn't need to match the region you run Amazon Bedrock in. In v2.1.207, the Amazon Bedrock region overrode `sso_region`, so a profile whose IAM Identity Center instance is in a different region failed to authenticate with a `Session token not found or invalid` error.
152166
153**Option D: AWS Management Console credentials**
167#### Use AWS Management Console credentials
154168
169The `aws login` command requires AWS CLI 2.32.0 or later. For the IAM policy your identity needs, see the [AWS instructions for `aws login`](https://docs.aws.amazon.com/signin/latest/userguide/command-line-sign-in.html).
170
171Run the command to sign in through your browser with your AWS Management Console credentials:
172
155173```bash theme={null}
156174aws login
157175```
158176
159[Learn more](https://docs.aws.amazon.com/signin/latest/userguide/command-line-sign-in.html) about `aws login`.
177The session is valid for up to 12 hours, after which you run `aws login` again.
160178
161**Option E: Amazon Bedrock API keys**
179#### Use an Amazon Bedrock API key
162180
181An Amazon Bedrock API key is a bearer token that authenticates your requests in place of AWS credentials. AWS issues [two types of key](https://docs.aws.amazon.com/bedrock/latest/userguide/api-keys.html):
182
183* **Short-term keys**: last up to 12 hours. AWS prefers them over long-term keys for production environments.
184* **Long-term keys**: last until an expiration date you set. AWS recommends them only for exploration.
185
186Export the key as `AWS_BEARER_TOKEN_BEDROCK`:
187
163188```bash theme={null}
164189export AWS_BEARER_TOKEN_BEDROCK=your-bedrock-api-key
165190```
166191
167Amazon Bedrock API keys provide a simpler authentication method without needing full AWS credentials. [Learn more about Amazon Bedrock API keys](https://aws.amazon.com/blogs/machine-learning/accelerate-ai-development-with-amazon-bedrock-api-keys/).
192When `AWS_BEARER_TOKEN_BEDROCK` is set, Claude Code authenticates with the key and doesn't resolve the credential chain, even if other AWS credentials are present. [Learn more about Amazon Bedrock API keys](https://aws.amazon.com/blogs/machine-learning/accelerate-ai-development-with-amazon-bedrock-api-keys/).
168193
169194#### Credential caching and resolution timeout
170195
171196Claude Code resolves the AWS default credential provider chain once and keeps the resolved credentials in memory. It reuses them until five minutes before they expire, or for one hour when they carry no expiration, so an SSO-backed profile requests credentials from IAM Identity Center about once per credential lifetime. A credential error from the API clears the cache, and the retry resolves fresh credentials. Requires Claude Code v2.1.207 or later.
172197
173The cache covers every credential option above except an Amazon Bedrock API key, which doesn't use the provider chain. To resolve the chain on every request instead, set [`CLAUDE_CODE_SKIP_AWS_CRED_CACHE=1`](/docs/en/env-vars).
198The cache covers every credential method listed at the start of this step except an Amazon Bedrock API key, which doesn't use the provider chain. To resolve the chain on every request instead, set [`CLAUDE_CODE_SKIP_AWS_CRED_CACHE=1`](/docs/en/env-vars).
174199
175200The resolve that fills the cache times out after 60 seconds. If a step in the chain stalls, for example a `credential_process` helper that waits for input it can't receive, the request fails with [`AWS default-chain credential resolve timed out`](/docs/en/errors#aws-default-chain-credential-resolve-timed-out). If your chain runs an interactive sign-in that legitimately needs longer, such as browser-based SSO with MFA through a wrapper like `aws-vault`, raise the limit in milliseconds with [`CLAUDE_CODE_AWS_CHAIN_RESOLVE_TIMEOUT_MS`](/docs/en/env-vars). With `CLAUDE_CODE_SKIP_AWS_CRED_CACHE=1` set, each API request resolves the chain without this limit.
176201
No line in this hunk matches that.