What
Claude Code has an embedded gateway that passes requests on to Amazon Bedrock, Amazon's service for running models. A guardrail is a Bedrock rule set that filters what goes in and out. Two changes apply:
- When a guardrail applies to a request to
/v1/messages, any request header starting withamazon-bedrock-is refused with a 400 error. A header is an extra piece of information sent with a request. - The gateway can now take on a separate AWS role for each user (an "assume-role" client). If Bedrock answers with a 401 or 403 permission error, it gets fresh credentials for that client.
Why
Blocking those headers stops a request from changing or skipping the guardrail. Per-user roles let each person's requests run with their own permissions, and the refresh keeps expired credentials from causing repeated failures.