Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.288 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One change · claude-docs

Connect an AWS role changedclaude-tag/admins/federated-access/aws

Nearest release: v2.1.283, published 5 hours before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.

Upstream edited this page at 25 Sep 2026 23:59 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 28 Sep 2026 22:07 UTC.

Upstream edited
Recorded here
Lines+4added
Lines−4removed
From line 20 where the diff opens
First seen 10 Sep 2026 this site's first read of the page
Recorded edits8to this page, all time

The whole hunk

from line 20, old and new numbered
/
lines
from line 20
2020 
2121In **Cloud roles**, click **Connect an AWS role** and copy the **Issuer**, **Audience**, and **Subject prefix** rows from the **Set the role's trust policy to accept these values** card. Then click **Cancel**; you connect the role after creating it in AWS.
2222 
23| Value | What it is |
24| :------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
25| Issuer | `https://identity.anthropic.com/agents`. The URL of the identity provider you create in AWS, including the `/agents` path. |
26| Audience | `sts.amazonaws.com`. The same for every organization, so it can't identify yours. |
23| Value | What it is |
24| :- | :- |
25| Issuer | `https://identity.anthropic.com/agents`. The URL of the identity provider you create in AWS, including the `/agents` path. |
26| Audience | `sts.amazonaws.com`. The same for every organization, so it can't identify yours. |
2727| Subject prefix | `wimse://identity.anthropic.com/org/<your organization ID>/agent/`. Every token's subject starts with this prefix and ends with one agent's ID. The trust policy must require at least this prefix. |
2828 
2929## Create the identity provider and role in AWS
Feedback