What
The claude-apps-gateway can now use sts:AssumeRole on behalf of each individual user. AssumeRole is the AWS request that borrows a role's permissions for a limited time. Each of these borrowed sessions is given a name taken from the user's login identity: the OIDC sub claim (a unique user ID) or the email claim.
- Session names are cleaned of unsupported characters, and a name longer than 64 characters is shortened by hashing, which turns it into a fixed-length code.
- A connection to AWS is kept per user and reused, up to a limit.
- FIPS STS endpoints, the US government security-certified AWS addresses, are used when
AWS_USE_FIPS_ENDPOINTis set. - Errors are detailed. One example is a message saying the user has no usable claim to name the session from.
- The gateway never falls back to its own AWS credentials.
Why
AWS access made through the gateway carries a session name tied to the user it was made for. If a user's identity cannot be read, that user gets an error instead of quietly receiving the gateway's own access.