Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.281 ·

Gateway: Bedrock guardrail header block and per-user assumed role

The built-in gateway now refuses amazon-bedrock-* headers when a Bedrock guardrail applies, and can use a separate AWS role per user

Entry
JSON All of v2.1.281
EntryKind: in v2.1.281,
ChangesSection of the release
What

Claude Code has an embedded gateway that passes requests on to Amazon Bedrock, Amazon's service for running models. A guardrail is a Bedrock rule set that filters what goes in and out. Two changes apply:

  • When a guardrail applies to a request to /v1/messages, any request header starting with amazon-bedrock- is refused with a 400 error. A header is an extra piece of information sent with a request.
  • The gateway can now take on a separate AWS role for each user (an "assume-role" client). If Bedrock answers with a 401 or 403 permission error, it gets fresh credentials for that client.
Why

Blocking those headers stops a request from changing or skipping the guardrail. Per-user roles let each person's requests run with their own permissions, and the refresh keeps expired credentials from causing repeated failures.

See this entry in the whole of v2.1.281 →

Feedback