Follow Discord
Sweep 09 Oct 2026 · 17:27Z Build v2.1.296 517 read Stable v2.1.287 Latest v2.1.296 Next v2.1.296 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One change · claude-code

Claude Code on Amazon Bedrock changedamazon-bedrock

Nearest release: v2.1.294, published an hour after upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.

Upstream edited this page at 8 Oct 2026 02:40 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 8 Oct 2026 03:07 UTC.

Upstream edited
Recorded here
Lines+38added
Lines−13removed
From line 122 where the diff opens
First seen 14 Aug 2026 this site's first read of the page
Recorded edits29to this page, all time

#### Use `aws configure` #### Export an access key #### Use an SSO profile #### Use AWS Management Console credentials #### Use an Amazon Bedrock API key

The whole hunk

from line 122, old and new numbered
/
lines
from line 122
122122 
123123### 2. Configure AWS credentials
124124 
125Claude Code uses the default AWS SDK credential chain. Set up your credentials using one of these methods:
125Claude Code uses the default AWS SDK credential chain. If the machine already supplies credentials to that chain, such as an Amazon EC2 instance profile or Amazon ECS task credentials, skip to [step 3](#3-configure-claude-code).
126126 
127**Option A: AWS CLI configuration**
127AWS [warns against using an IAM user's access keys](https://docs.aws.amazon.com/cli/latest/userguide/cli-authentication-user.html) when you develop purpose-built software or work with real data. Set up your credentials with one of these methods:
128128 
129* [`aws configure`](#use-aws-configure): save an IAM user's access key to a profile in your `~/.aws` directory
130* [Access key environment variables](#export-an-access-key): set an access key, or temporary credentials with a session token, in the current shell only
131* [SSO profile](#use-an-sso-profile): sign in through IAM Identity Center in your browser and get temporary credentials. Use this method if you access your AWS account through IAM Identity Center.
132* [AWS Management Console credentials](#use-aws-management-console-credentials): sign in through your browser with your AWS Management Console credentials and get temporary credentials. AWS [recommends this method](https://docs.aws.amazon.com/signin/latest/userguide/command-line-sign-in.html) if you access your AWS account as the root user, as an IAM user, or through federation with IAM.
133* [Amazon Bedrock API key](#use-an-amazon-bedrock-api-key): authenticate with a bearer token that works only for Amazon Bedrock, instead of AWS credentials
134 
135#### Use `aws configure`
136 
137Run `aws configure` and enter your access key ID, secret access key, and default region when prompted:
138 
129139```bash theme={null}
130140aws configure
131141```
132142 
133**Option B: Environment variables (access key)**
143The AWS CLI saves the key to the `default` profile in `~/.aws/credentials`, where the credential chain reads it.
134144 
145#### Export an access key
146 
147Export your access key as environment variables. `AWS_SESSION_TOKEN` is required only with temporary credentials, so leave that line out if your access key belongs to an IAM user:
148 
135149```bash theme={null}
136150export AWS_ACCESS_KEY_ID=your-access-key-id
137151export AWS_SECRET_ACCESS_KEY=your-secret-access-key
from line 152
138152export AWS_SESSION_TOKEN=your-session-token
139153```
140154 
141**Option C: Environment variables (SSO profile)**
155#### Use an SSO profile
142156 
143Replace `your-profile-name` with the name of your AWS profile before running these commands.
157Create a profile with `aws configure sso` if you don't have one. Then sign in to IAM Identity Center and set `AWS_PROFILE` so the credential chain uses that profile. Replace `your-profile-name` with the name of your AWS profile before running these commands.
144158 
145159```bash theme={null}
146160aws sso login --profile=your-profile-name
from line 164
150164 
151165Claude Code requests role credentials from the IAM Identity Center region named by the profile's `sso_region`, which doesn't need to match the region you run Amazon Bedrock in. In v2.1.207, the Amazon Bedrock region overrode `sso_region`, so a profile whose IAM Identity Center instance is in a different region failed to authenticate with a `Session token not found or invalid` error.
152166 
153**Option D: AWS Management Console credentials**
167#### Use AWS Management Console credentials
154168 
169The `aws login` command requires AWS CLI 2.32.0 or later. For the IAM policy your identity needs, see the [AWS instructions for `aws login`](https://docs.aws.amazon.com/signin/latest/userguide/command-line-sign-in.html).
170 
171Run the command to sign in through your browser with your AWS Management Console credentials:
172 
155173```bash theme={null}
156174aws login
157175```
158176 
159[Learn more](https://docs.aws.amazon.com/signin/latest/userguide/command-line-sign-in.html) about `aws login`.
177The session is valid for up to 12 hours, after which you run `aws login` again.
160178 
161**Option E: Amazon Bedrock API keys**
179#### Use an Amazon Bedrock API key
162180 
181An Amazon Bedrock API key is a bearer token that authenticates your requests in place of AWS credentials. AWS issues [two types of key](https://docs.aws.amazon.com/bedrock/latest/userguide/api-keys.html):
182 
183* **Short-term keys**: last up to 12 hours. AWS prefers them over long-term keys for production environments.
184* **Long-term keys**: last until an expiration date you set. AWS recommends them only for exploration.
185 
186Export the key as `AWS_BEARER_TOKEN_BEDROCK`:
187 
163188```bash theme={null}
164189export AWS_BEARER_TOKEN_BEDROCK=your-bedrock-api-key
165190```
166191 
167Amazon Bedrock API keys provide a simpler authentication method without needing full AWS credentials. [Learn more about Amazon Bedrock API keys](https://aws.amazon.com/blogs/machine-learning/accelerate-ai-development-with-amazon-bedrock-api-keys/).
192When `AWS_BEARER_TOKEN_BEDROCK` is set, Claude Code authenticates with the key and doesn't resolve the credential chain, even if other AWS credentials are present. [Learn more about Amazon Bedrock API keys](https://aws.amazon.com/blogs/machine-learning/accelerate-ai-development-with-amazon-bedrock-api-keys/).
168193 
169194#### Credential caching and resolution timeout
170195 
171196Claude Code resolves the AWS default credential provider chain once and keeps the resolved credentials in memory. It reuses them until five minutes before they expire, or for one hour when they carry no expiration, so an SSO-backed profile requests credentials from IAM Identity Center about once per credential lifetime. A credential error from the API clears the cache, and the retry resolves fresh credentials. Requires Claude Code v2.1.207 or later.
172197 
173The cache covers every credential option above except an Amazon Bedrock API key, which doesn't use the provider chain. To resolve the chain on every request instead, set [`CLAUDE_CODE_SKIP_AWS_CRED_CACHE=1`](/docs/en/env-vars).
198The cache covers every credential method listed at the start of this step except an Amazon Bedrock API key, which doesn't use the provider chain. To resolve the chain on every request instead, set [`CLAUDE_CODE_SKIP_AWS_CRED_CACHE=1`](/docs/en/env-vars).
174199 
175200The resolve that fills the cache times out after 60 seconds. If a step in the chain stalls, for example a `credential_process` helper that waits for input it can't receive, the request fails with [`AWS default-chain credential resolve timed out`](/docs/en/errors#aws-default-chain-credential-resolve-timed-out). If your chain runs an interactive sign-in that legitimately needs longer, such as browser-based SSO with MFA through a wrapper like `aws-vault`, raise the limit in milliseconds with [`CLAUDE_CODE_AWS_CHAIN_RESOLVE_TIMEOUT_MS`](/docs/en/env-vars). With `CLAUDE_CODE_SKIP_AWS_CRED_CACHE=1` set, each API request resolves the chain without this limit.
176201 
Feedback