{"version":"2.1.281","anchor":"claude-apps-gateway-per-user-aws-assume-role-sessions","canonical_anchor":"claude-apps-gateway-per-user-aws-assume-role-sessions","heading":"Claude Apps gateway: per-user AWS assume-role sessions","tier":null,"area":null,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/claude-apps-gateway-per-user-aws-assume-role-sessions","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Claude Apps gateway: per-user AWS assume-role sessions\n\nThe Claude Apps gateway can now take on an AWS role separately for each user, naming each session after that user's identity\n\n**What**\n\nThe `claude-apps-gateway` can now use sts:AssumeRole on behalf of each individual user. AssumeRole is the AWS request that borrows a role's permissions for a limited time. Each of these borrowed sessions is given a name taken from the user's login identity: the OIDC `sub` claim (a unique user ID) or the email claim.\n\n- Session names are cleaned of unsupported characters, and a name longer than 64 characters is shortened by hashing, which turns it into a fixed-length code.\n\n- A connection to AWS is kept per user and reused, up to a limit.\n\n- FIPS STS endpoints, the US government security-certified AWS addresses, are used when `AWS_USE_FIPS_ENDPOINT` is set.\n\n- Errors are detailed. One example is a message saying the user has no usable claim to name the session from.\n\n- The gateway never falls back to its own AWS credentials.\n\n**Why**\n\nAWS access made through the gateway carries a session name tied to the user it was made for. If a user's identity cannot be read, that user gets an error instead of quietly receiving the gateway's own access."}