To use Claude Code with Amazon Bedrock, first enable access to the Anthropic model in your AWS account, then authenticate to AWS, enable Bedrock in Claude Code, select a region and usable model route, and grant the required IAM permissions. The setup assistant is the simplest path for a local machine; manual environment configuration is better suited to CI and scripted deployments.
1. Enable Anthropic model access in your AWS account
Before Claude Code can invoke a model, the AWS account must have Bedrock enabled, access to the desired Claude model, and an identity with suitable IAM permissions. In the Amazon Bedrock model catalog, select an Anthropic model and submit the use-case form before its first invocation. The Claude Code on Amazon Bedrock guide describes access as granted after submission.
For an AWS Organizations deployment, the guide describes submitting through the management account with PutUseCaseForModelAccess. The submitting identity needs the corresponding IAM permission; approval then extends to member accounts.
2. Choose interactive or manual setup
| Approach | Best fit | What it does |
|---|---|---|
| Interactive setup assistant | Local developer workstation or initial setup | Guides authentication and region selection, checks model invocation access, and can pin models in the user settings file. |
| Manual environment configuration | CI, scripted deployment, or centrally managed environment | Lets an administrator set provider and region environment variables and manage AWS authentication outside the assistant. |
Use the setup assistant
- Make the intended AWS credentials available to your shell or profile before starting Claude Code.
- Run
claude. At the authentication prompt, choose the third-party platform option, then Amazon Bedrock, and follow the prompts. If Claude Code is already running, use/setup-bedrock. - Choose a detected AWS profile or another offered credential method, select a region, and let the assistant check model invocation access. Pin the models you want Claude Code to use when prompted.
The assistant can use a detected AWS profile, a Bedrock API key, access and secret keys, or credentials already present in the environment. It saves its settings to the user settings file.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11#1 Best Overall
Configure Bedrock manually
For a scripted setup, set CLAUDE_CODE_USE_BEDROCK=1 in the environment that launches Claude Code. Set a region override only if the selected AWS profile or the documented default is not the region you intend to use. The Anthropic guide also supports a Bedrock endpoint override for custom endpoints or gateways.
Keep temporary credential values out of source-controlled files. Use your deployment’s approved credential injection or AWS identity mechanism instead of committing secrets alongside application configuration.
Rank #2
3. Authenticate Claude Code to AWS
Claude Code does not use a Claude account login for Bedrock authentication. As the official guide states, “Claude Code uses the AWS SDK default credential chain.” Supported documented options include AWS CLI credentials, environment credentials, AWS SSO profiles, credentials already supplied by the environment, and Bedrock API keys. Choose the method that matches your organization’s identity and secret-management policy.
Use an AWS SSO profile
- Authenticate the profile with
aws sso login --profile=PROFILE_NAME, replacingPROFILE_NAMEwith the profile configured for your account. - Set
AWS_PROFILEto that same profile in the shell or process environment used to launch Claude Code. - Before launching Claude Code, run
aws sts get-caller-identitywith the intended profile and confirm that the returned principal and account are the ones you mean to use.
For other AWS credential methods, ensure the relevant credentials are available to the AWS SDK in the Claude Code process environment. In Bedrock mode, AWS credentials handle authentication, so Claude Code’s /logout command is unavailable; manage sign-in and expiration through the AWS credential provider you selected.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →4. Choose the region and model route
Claude Code resolves its Bedrock region in this order: AWS_REGION, AWS_DEFAULT_REGION, the active AWS profile’s region, then us-east-1. The active profile is the one named by AWS_PROFILE, or default when that variable is unset. In a Claude Code session, use /status to see the resolved region.
Bedrock model availability depends on the AWS account and region. Check the models or inference profiles available to your account in the region you intend to use; do not assume an example model ID, Claude Code default, or previously working route remains available.
Base model ID or inference profile?
A base model ID identifies a foundation model. An inference-profile ID or ARN identifies a Bedrock routing profile. Some requests cannot use on-demand throughput through a base model ID and instead need an inference profile. If Bedrock reports that on-demand throughput is unsupported for the chosen base model, select the appropriate inference profile available in your region and configure Claude Code to use that route.
For a team rollout, pin explicit model versions rather than relying on an alias to decide when the team moves to a newer version. The setup assistant can pin models; confirm the chosen identifiers against current account and regional availability before deploying them broadly.
Best Value
5. Grant the IAM permissions Claude Code needs
Start with the Claude Code-specific policy guidance in the Anthropic Bedrock setup guide, then adapt it to the models and profiles your deployment actually uses. The example covers these actions:
| Action | Why it is included |
|---|---|
bedrock:InvokeModel |
Invoke a model. |
bedrock:InvokeModelWithResponseStream |
Invoke a model with streaming responses. |
bedrock:ListInferenceProfiles |
Discover inference profiles. |
bedrock:GetInferenceProfile |
Look up an inference profile and its backing model. |
The example’s resources include inference-profile, application-inference-profile, and foundation-model ARN patterns. Narrow resource ARNs to the specific profiles or models needed wherever practical. The guide also includes aws-marketplace:ViewSubscriptions and aws-marketplace:Subscribe, conditionally limited to calls made through bedrock.amazonaws.com; retain those actions only when they are relevant to the way your account obtains model access.
bedrock:GetInferenceProfile lets Claude Code resolve an application inference profile ARN to its backing foundation model and choose the appropriate request shape. Without it, Claude Code may retry with an alternative request shape, adding a round trip. For broader IAM context, consult AWS’s identity-based policy examples for Amazon Bedrock.
The Anthropic example is a starting point, not a universal least-privilege policy. Administrators should align actions and resources with the actual model route, account configuration, and organizational policy.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Quick Recap
6. Verify the setup and troubleshoot failures
| Symptom | Checks and next step |
|---|---|
| AWS authentication fails | Confirm that the intended profile is selected, an SSO session is active if applicable, and the credentials are available in the environment that launched Claude Code. Use aws sts get-caller-identity to check the effective AWS identity. |
| Claude Code is using the wrong region | Run /status and compare its resolved region with the profile and region variables in the launching environment. Correct the applicable region setting and check that the desired model or profile is available there. |
| Bedrock reports unsupported on-demand throughput | Check whether the selected base model supports the requested route. If it does not, use an inference-profile ID or ARN that your account can invoke. |
| A model or profile cannot be found or invoked | Check availability in the chosen region and confirm that the IAM identity has the relevant invocation and profile permissions for the resource. Query the inference-profile list in that region when diagnosing a profile or throughput error. |
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

