Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.281 ·

Claude Apps gateway: per-user AWS assume-role sessions

The Claude Apps gateway can now take on an AWS role separately for each user, naming each session after that user's identity

Entry
JSON All of v2.1.281
EntryKind: in v2.1.281,
ChangesSection of the release
What

The claude-apps-gateway can now use sts:AssumeRole on behalf of each individual user. AssumeRole is the AWS request that borrows a role's permissions for a limited time. Each of these borrowed sessions is given a name taken from the user's login identity: the OIDC sub claim (a unique user ID) or the email claim.

  • Session names are cleaned of unsupported characters, and a name longer than 64 characters is shortened by hashing, which turns it into a fixed-length code.
  • A connection to AWS is kept per user and reused, up to a limit.
  • FIPS STS endpoints, the US government security-certified AWS addresses, are used when AWS_USE_FIPS_ENDPOINT is set.
  • Errors are detailed. One example is a message saying the user has no usable claim to name the session from.
  • The gateway never falls back to its own AWS credentials.
Why

AWS access made through the gateway carries a session name tied to the user it was made for. If a user's identity cannot be read, that user gets an error instead of quietly receiving the gateway's own access.

See this entry in the whole of v2.1.281 →

Feedback