AIToday
Large Language ModelsAI Business & IndustryAmazon AI BlogPublished: Oct 2, 2026, 04:00 JST

AWS guide: Claude Platform on AWS in 3 accounts

AWS guide: Claude Platform on AWS in 3 accounts

3 Key Points

  1. What happened

    AWS published a step-by-step guide for Claude Platform on AWS showing three access patterns — cross-account SigV4 for AWS workloads, workspace-scoped API keys for developers, and OIDC federation for external environments — all under one subscription in a dedicated AI Services account.

  2. Why it matters

    Workloads reach the subscription through assumed roles and short-lived credentials rather than stored keys, and workspace settings keep production and development traffic apart. For organizations with more environments, the guide says to create a workspace per team or workload and repeat the cross-account role pattern.

  3. What to watch

    The pattern hinges on workspace isolation holding in practice — the post's test expects a development key to be denied access to the production workspace, and says to revisit the scoping step if it succeeds. Current inference geography options are "US" and "Global routing".

WHO IT HITSCloud and platform engineers at organizations already subscribed to Claude Platform on AWS, plus the security teams who must sign off on giving developer laptops and outside-cloud workloads access to the same subscription. The workspace-scoping detail matters most for anyone who has to prove production and development traffic stay separated.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

The post is positioned as the implementation follow-up to two earlier AWS posts, one on architecture patterns and one on authentication paths. It assumes those decisions are already made, and takes over from there with the CLI commands, console steps, and code snippets needed to stand the thing up.

The structure it lands on is a three-account split: a payer account for billing and governance, an AI Services linked account that owns the subscription, workspaces, API keys, and cross-account roles, and workload accounts that never touch the subscription directly. Each of the three access paths is aimed at a different consumer of the same subscription. AWS workloads assume a role scoped to the production workspace. Developer laptops go through a key that is by default attached to a policy granting every workspace, so the post walks through detaching that managed policy and replacing it with an inline policy naming only the development workspace. External environments authenticate through OIDC and receive a token that, for short-term keys, only works against the Regional endpoint where it was generated.

Several of the guide's sharpest warnings are about details that quietly break isolation. CallWithBearerToken has to be granted on Resource "*" or token generation fails outright, while CreateInference stays scoped to a workspace ARN so the token inherits that restriction. The stakes therefore sit less in whether the setup works at all than in whether teams follow the scoping steps exactly — the guide itself supplies the test that would reveal a mistake, and the cleanup section suggests it expects readers who are still evaluating rather than committed.

FAQ
How does a workload running on AWS authenticate to Claude Platform on AWS without storing API keys?
It assumes a cross-account role into the AI Services account and makes SigV4-signed inference calls. The post says there are no API keys stored and no secrets to rotate.
How long is the short-term token for external workloads valid?
The generated token expires after 1 hour, and the post says the expiry is configurable up to a maximum of 12 hours. After generation it works as a standalone bearer credential.
What happens if a developer's API key is used against the production workspace?
It should be denied. The verification step expects an access-denied permission error, and the post says to revisit the key-scoping step if the key reaches the production workspace instead.
Amazon AI BlogRead Original Article

AI news that matters for your work, delivered every morning.

Pick your industry and the AI tools you use, and get news related to your work every day.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleAI's real value may be routine work, not genius: essay