The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →If Claude Code cannot access Amazon Bedrock, first determine whether it is using Bedrock, which AWS identity it has, and whether that identity can invoke the selected model in the resolved region. Authentication proves who you are; it does not grant Bedrock permissions. Follow the checks below in order, and use the error message to choose the right branch.
1. Confirm Claude Code is configured for Bedrock
Claude Code does not use its Anthropic account sign-in flow to authenticate to Bedrock. Enable Bedrock through the setup wizard or set CLAUDE_CODE_USE_BEDROCK=1 in the environment of the process that launches Claude Code.
If Claude Code is already open, enter /setup-bedrock to launch the wizard. Until Bedrock is enabled, you may need to type the full command. The wizard can use a detected AWS profile, a Bedrock API key, access-key credentials, or credentials already in the environment. It asks for a region, checks which Claude models the account can invoke, and can pin models; it saves settings in the user settings file. See Anthropic’s Claude Code on Amazon Bedrock guide for version-specific setup details.
2. Check which AWS credentials and identity Claude Code is using
Claude Code uses the default AWS SDK credential chain. Depending on your setup, credentials may come from AWS CLI configuration, environment variables, an AWS SSO profile, AWS Management Console credentials, or a Bedrock API key. Temporary environment credentials need the session token as well as the access key and secret key.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
If you intend to use a named profile, confirm that AWS_PROFILE is set to that profile in the same shell or environment that starts Claude Code. For SSO, test the login there first:
aws sso login --profile <profile>
Replace <profile> with the configured profile name. AWS CLI can open a browser for authorization and provides fallback instructions when it cannot. If authentication still fails after login, check Claude Code’s installed version and active credential source: credential caching and refresh behavior can vary by version, so a refreshed SSO session does not by itself prove the running process is using it.
For details on browser and device authorization in AWS CLI, see AWS’s IAM Identity Center authentication guide.
3. Distinguish an authentication failure from an authorization failure
Valid credentials identify an AWS principal. They do not automatically authorize that principal to invoke a Bedrock model. An AccessDeniedException or similar denial after successful sign-in points toward permissions, resource scope, or organization policy—not necessarily a bad credential.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
Ask an AWS administrator to check whether the active principal is allowed to perform the actions needed for the exact model or inference profile, including:
bedrock:InvokeModelbedrock:InvokeModelWithResponseStreambedrock:ListInferenceProfiles, when listing profilesbedrock:GetInferenceProfile, when inspecting a profile
Permissions must apply to the relevant foundation-model or inference-profile resources. An organization policy or service control policy can impose additional restrictions; explicit denies on invocation actions also block inference. AWS provides examples in its identity-based policy guide for Amazon Bedrock. Do not treat broad administrator access as a first diagnostic fix.
Rank #4
The Claude Code guide also lists Anthropic’s model use-case form as a separate account-level prerequisite. In an AWS Organization, its documented process may require the management account to submit the form using PutUseCaseForModelAccess; that action itself requires the corresponding IAM permission.
4. Verify the resolved region and model identifier
A valid identity can still fail if Claude Code targets a region where the requested model or inference profile is unavailable. Claude Code resolves the Bedrock region in this order: AWS_REGION, AWS_DEFAULT_REGION, the active AWS profile’s region, and finally us-east-1. Run /status in Claude Code to see the resolved region and, where applicable, its source.
Recommended Free Tools
Best Value
Compare that region with the account’s model and inference-profile availability. The Claude Code guide recommends listing inference profiles in the selected region as one check. Availability depends on the model, region, and account; verify it against current AWS information rather than assuming a model identifier works everywhere.
When on-demand throughput is unsupported
If the error says on-demand throughput is unsupported, the model may require an inference-profile ID or ARN rather than a base model ID. Use the profile appropriate to the requested model and region. Inference-profile prefixes route requests geographically, so check that the selected profile and its routing are suitable for your environment. Anthropic’s supplemental Bedrock model integration page provides model-ID and inference-profile context; for Claude Code configuration, use the current Claude Code guide.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.5. Resolve SSO browser loops and corporate certificate errors
AWS SSO keeps opening a browser
Repeated browser tabs can occur when a corporate VPN or TLS-inspection proxy interrupts the sign-in flow. The Claude Code guide recommends removing awsAuthRefresh when browser sign-in is being interrupted, then completing SSO manually before launching Claude Code:
- Run
aws sso login --profile <profile>in the environment you will use for Claude Code. - Complete the browser authorization, following the AWS CLI fallback instructions if the browser does not open.
- Launch Claude Code with the intended AWS profile and check
/status. - If the browser loop persists, investigate VPN or TLS-inspection behavior and consult the current Claude Code guidance for the version you have installed.
Certificate error behind a corporate proxy
With TLS inspection, the proxy may present a certificate signed by a corporate certificate authority that Node.js or the AWS request path does not trust. Claude Code documents using the operating-system CA store or NODE_EXTRA_CA_CERTS to configure CA trust for AWS requests. Follow the instructions for your installed version; the guide also describes release-specific behavior affecting direct connections and setup-wizard checks, so updating may be necessary.
6. Check gateways for Bedrock API and streaming compatibility
Claude Code on Bedrock uses the Invoke API, not the Converse API. As Anthropic states, “Claude Code uses the Amazon Bedrock Invoke API and does not support the Converse API.” A custom gateway or proxy must therefore support the Invoke API and preserve Bedrock’s streaming response body and headers. Rewriting or mishandling the event-stream content type can produce streaming errors that may be mistaken for an authentication problem.
Quick Recap
Choose the next check from the error
| Error or symptom | Check next |
|---|---|
| “AWS credentials not found,” expired credentials, or sign-in failure | Confirm Bedrock mode is enabled; inspect the active profile, environment credentials, session token, SSO session, or Bedrock API key. |
AccessDeniedException or a permission denial |
Verify the active principal’s IAM actions and resource scope, organization controls, and model use-case access. |
| Bedrock model not available in this region | Check /status, region resolution, account access, and model or inference-profile availability. |
| On-demand throughput isn’t supported | Check whether the model requires an inference-profile ID or ARN instead of a base model ID. |
| AWS SSO keeps opening a browser | Complete aws sso login manually before launching Claude Code; investigate VPN or TLS inspection and the awsAuthRefresh setting. |
| Certificate error behind corporate proxy | Check trusted CA configuration and Claude Code version; consult the guide for the operating-system CA store or NODE_EXTRA_CA_CERTS. |
| Streaming or event-stream error through a gateway | Confirm the gateway supports the Invoke API and passes the Bedrock response body and Content-Type through correctly. |
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

