
What happened
AWS published a step-by-step guide for Claude Platform on AWS showing three access patterns — cross-account SigV4 for AWS workloads, workspace-scoped API keys for developers, and OIDC federation for external environments — all under one subscription in a dedicated AI Services account.
Why it matters
Workloads reach the subscription through assumed roles and short-lived credentials rather than stored keys, and workspace settings keep production and development traffic apart. For organizations with more environments, the guide says to create a workspace per team or workload and repeat the cross-account role pattern.
What to watch
The pattern hinges on workspace isolation holding in practice — the post's test expects a development key to be denied access to the production workspace, and says to revisit the scoping step if it succeeds. Current inference geography options are "US" and "Global routing".
WHO IT HITSCloud and platform engineers at organizations already subscribed to Claude Platform on AWS, plus the security teams who must sign off on giving developer laptops and outside-cloud workloads access to the same subscription. The workspace-scoping detail matters most for anyone who has to prove production and development traffic stay separated.
Summaries like this, in your inbox every morning.
The post is positioned as the implementation follow-up to two earlier AWS posts, one on architecture patterns and one on authentication paths. It assumes those decisions are already made, and takes over from there with the CLI commands, console steps, and code snippets needed to stand the thing up.
The structure it lands on is a three-account split: a payer account for billing and governance, an AI Services linked account that owns the subscription, workspaces, API keys, and cross-account roles, and workload accounts that never touch the subscription directly. Each of the three access paths is aimed at a different consumer of the same subscription. AWS workloads assume a role scoped to the production workspace. Developer laptops go through a key that is by default attached to a policy granting every workspace, so the post walks through detaching that managed policy and replacing it with an inline policy naming only the development workspace. External environments authenticate through OIDC and receive a token that, for short-term keys, only works against the Regional endpoint where it was generated.
Several of the guide's sharpest warnings are about details that quietly break isolation. CallWithBearerToken has to be granted on Resource "*" or token generation fails outright, while CreateInference stays scoped to a workspace ARN so the token inherits that restriction. The stakes therefore sit less in whether the setup works at all than in whether teams follow the scoping steps exactly — the guide itself supplies the test that would reveal a mistake, and the cleanup section suggests it expects readers who are still evaluating rather than committed.
Pick your industry and the AI tools you use, and get news related to your work every day.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
Anthropic PBC reportedly aims to begin marketing its IPO the week of Nov
OpenAI confirmed it dismissed three safety researchers for violating policies on accessing and handling sensit…
Anthropic published best practices for human-AI agent teams, based on an interview with Slack CPO Jamie DeLang…

OpenAI's August 26 postmortem says its internal cybersecurity evaluation gave a research model "ExploitGym" ta…

Anthropic said it made the web service claude.ai and its desktop app about 3 times faster in 2 weeks, and that…

On October 1, OpenAI updated ChatGPT's release notes with shopping features — a 'try on' button on product car…
