# Claude Platform on AWS
The full [[Claude Platform]], run by [[Anthropic]], that you buy and access through your AWS account. Same [[Claude API]], same features, same [[Claude Console]]. AWS handles sign-in (IAM), audit logs (CloudTrail) and the invoice (AWS Marketplace). It went GA on May 11, 2026, and AWS calls itself the first cloud provider to offer the native Claude Platform.
The thing is, the name is misleading. This is NOT Claude running inside AWS the way Amazon Bedrock is. Anthropic operates the service and Anthropic is the data processor. AWS is the front door and the cash register.
## What you get
- **Every Claude API endpoint** at `/v1/{endpoint}`, with the same request and response shapes, model IDs (`claude-opus-5-5`, no `anthropic.` prefix or ARNs) and context windows as the first-party API
- **New models and features the same day** they ship on the native API, betas included (the standard `anthropic-beta` header works)
- **[[Claude Managed Agents]]**: agents, environments, sessions, credential vaults, memory stores, webhooks, multiagent orchestration and self-hosted sandboxes
- **Platform tools**: advisor strategy, web search, web fetch, code execution, Files API, [[AI Agent Skills|Agent Skills]] (the PowerPoint, Excel, Word and PDF skills work out of the box), [[Model Context Protocol (MCP)|MCP]] connector, computer use, prompt caching (5-minute, 1-hour and automatic), citations, batch processing, extended thinking, streaming
- **Enterprise bits**: customer-managed encryption keys (AWS KMS only), the Compliance API, AWS PrivateLink, Zero Data Retention on request
- **The [[Claude Console]]** at platform.claude.com, opened from the AWS Console, with an "Account managed by AWS" badge
Models at launch were Opus 4.7, Sonnet 4.6 and Haiku 4.5. The docs now list 13, from Haiku 4.5 up to [[Claude Opus 5.5]], [[Claude Sonnet 5.5]] and [[Claude Fable 5.1]].
### What's missing
The parity has holes. Not available (October 2026):
- HIPAA readiness
- The new computer and browser toolsets (`computer_toolset_20260801`, `browser_toolset_20260801`); older computer use versions still work
- Most of the Admin API (members, invites, API keys, usage and cost reports). Only workspace and external key endpoints exist
- Per-workspace member management, OAuth, fast mode, OpenAI-compatible endpoints, MCP tunnels (public MCP servers only), and the dedicated Claude Code workspace and Analytics API
Managed Agents also behaves differently in two ways. A session can run without user events for 6 hours max, then needs a user event to reauthenticate (no limit on the first-party API). And sessions on self-hosted environments can't attach memory stores.
## How identity, billing and data work
**Identity.** Two auth options: SigV4 with your normal AWS credentials (the recommended path), or API keys generated in the AWS Console. Keys from the regular Claude Console don't work here. For processes that can't sign SigV4, AWS ships token generators (JS, Python, Java) that mint 12-hour keys from your AWS credentials. Access control lives in IAM: the namespace is `aws-external-anthropic`, the workspace (`wrkspc_...`) is the IAM resource, and AWS provides five managed policies (`AnthropicFullAccess`, `AnthropicReadOnlyAccess`, `AnthropicInferenceAccess`, `AnthropicLimitedAccess`, `AnthropicSelfHostedEnvironmentAccess`). Org membership is IAM too; the Console only has Admin and Developer roles.
**Audit.** CloudTrail logs workspace, key, compliance, vault and webhook operations by default. Inference, batches, files, skills and most Managed Agents calls are *data events*, so you must turn on data event logging (and pay CloudTrail for it). Each response carries an AWS request ID and an Anthropic request ID.
**Billing.** Pricing is the same as the Claude API. Anthropic rates your usage in USD at list price, applies any discount, then converts it into Claude Consumption Units (CCU) at $0.01 each (100 CCU = $1). Usage is metered hourly to AWS Marketplace and billed monthly in arrears. No prepaid credits, no CCU balance. The spend retires against your existing AWS commitments (one HN commenter notes Marketplace spend usually counts for at most 25% of a private pricing agreement; check yours), and you can follow it in AWS Cost Explorer next to everything else.
**Data.** Anthropic processes inference inputs and outputs under its own commercial terms, DPA and usage policy, with the same retention as the first-party API. AWS only sees billing and identity metadata. Where it runs depends on when you created the workspace: since September 18, 2026, Anthropic uses AWS infrastructure for inference and stored content; older workspaces may be processed outside AWS.
**Regions.** Workspaces are bound to one AWS region (17 regions at launch across North America, South America, Europe and Asia Pacific; the docs now say all commercial regions). The region does NOT decide where inference runs. That's `inference_geo`: `global` (default, list price) or `us` (US-only, 1.1x price, Claude 4.6 and later). There's no EU inference geography.
**Limits.** New orgs start on the Start tier, with Anthropic (not AWS quotas) managing rate limits. Tiers go up automatically as you pay Marketplace invoices; otherwise you ask your account rep. Each tier has a monthly spend cap, and you can set lower org or workspace limits yourself.
## Getting started
1. In the AWS Console, open the **Claude Platform on AWS** page and sign up. AWS handles the Marketplace subscription (a few minutes) and offers any private offer you have
2. Finish the Anthropic org setup at `platform.claude.com/partner-signup`. This always creates a NEW Anthropic org; an existing one can't be converted and its keys and workspaces don't carry over
3. Create a workspace and note its ID
4. Run `aws iam enable-outbound-web-identity-federation` once per AWS account. Skip this and every request fails (the docs call it the most common setup error)
5. Grant `aws-external-anthropic:CreateInference` on the workspace (plus `CallWithBearerToken` if you use API keys)
6. Use the `AnthropicAWS` client (`pip install "anthropic[aws]"`, `@anthropic-ai/aws-sdk` in TypeScript), set `AWS_REGION` and `ANTHROPIC_AWS_WORKSPACE_ID`, and call `https://aws-external-anthropic.{region}.api.aws`
Every inference request carries an `anthropic-workspace-id` header. AWS's launch post shows [[Claude Code]] and [[Claude Cowork]] working against it too, by pointing `ANTHROPIC_BASE_URL` at the regional endpoint and passing the workspace ID as a custom header.
If you have a Bedrock private offer, talk to your account rep BEFORE signing up. Discounts don't transfer between Bedrock and this offer, and they never apply retroactively.
## Native API vs Platform on AWS vs Bedrock
| | [[Claude API]] (direct) | Claude Platform on AWS | Claude in Amazon Bedrock |
|---|---|---|---|
| Who operates it | Anthropic | Anthropic | AWS |
| Data processor | Anthropic | Anthropic | AWS (Anthropic never sees the data) |
| API | Claude API | Claude API | Messages API at `/anthropic/v1/messages` (or legacy InvokeModel/Converse) |
| New features | First | Same day (with the gaps above) | On Bedrock's release schedule |
| Betas, Agent Skills, code execution | Yes | Yes | No |
| Managed Agents | Yes | Yes (6-hour autonomy limit) | Not listed |
| Auth | API key, Workload Identity Federation | SigV4 or AWS-issued API key | SigV4 |
| Billing | Anthropic, prepaid credits | AWS Marketplace, CCU in arrears | AWS native service |
| Rate limits | Anthropic | Anthropic | AWS |
| Compliance | Anthropic programs incl. HIPAA | No HIPAA | FedRAMP High, IL4/IL5, HIPAA-ready |
| AWS extras | None | IAM, CloudTrail, KMS, PrivateLink | Guardrails, Knowledge Bases, regional data residency |
Each of the three draws on its own capacity pool, so you can spread workloads across them and fail over. Moving from Bedrock is mostly a base URL, SigV4 service name, model ID and header change if you already use Bedrock's Messages API; from InvokeModel or Converse you also rewrite request shapes.
Anthropic has a sibling deal on Azure: Claude in Microsoft Foundry also bills through the Azure Marketplace in CCUs.
## My take
This is a procurement product, NOT a technical one. Anthropic's API was always one signup away. What this removes is the new-vendor contract, the security review of a new identity system and the separate invoice. The biggest thread on [[Hacker News]] (89 comments) said the same thing, some more bluntly ("launder your AI spend through your AWS bill"). People with real procurement experience confirmed it: new vendors mean lawyers and months; clicking a button in AWS doesn't.
So when does it make sense?
- **You're on AWS and want the real platform**: Managed Agents, Skills, betas on day one. Bedrock lags here, and HN commenters put that lag at months
- **You need AWS to be the only processor** (regulated industry, export compliance, EU residency): stay on Bedrock. This offer doesn't help you at all
- **You're a small team without AWS commitments**: go direct. Fewer moving parts
Watch the trade-offs. You get a fresh org on the lowest rate-limit tier, a mandatory IAM federation switch, CloudTrail data-event costs for inference logs, and a "data location" story that changed in September 2026 and still reads differently on AWS's own FAQ.
## References
- Announcement on X (@ClaudeDevs, 2026-05-11): https://x.com/ClaudeDevs/status/2053892878167072914
- Anthropic launch post, "Introducing the Claude Platform on AWS": https://claude.com/blog/claude-platform-on-aws
- Anthropic docs, Claude Platform on AWS (setup, auth, features, data residency, billing, Bedrock migration, IAM): https://platform.claude.com/docs/en/build-with-claude/claude-platform-on-aws
- Anthropic docs, pricing (CCU, inference geography, private offers, Foundry): https://platform.claude.com/docs/en/about-claude/pricing#claude-platform-on-aws-pricing
- AWS product page and FAQ: https://aws.amazon.com/claude-platform/
- AWS What's New, GA announcement and launch regions: https://aws.amazon.com/about-aws/whats-new/2026/05/claude-platform-aws/
- AWS Machine Learning Blog, "Introducing Claude Platform on AWS": https://aws.amazon.com/blogs/machine-learning/introducing-claude-platform-on-aws-anthropics-native-platform-through-your-aws-account/
- Hacker News discussion (227 points, 89 comments): https://news.ycombinator.com/item?id=48103042
## Related
- [[Claude Platform]]
- [[Claude API]]
- [[Claude Console]]
- [[Claude Managed Agents]]
- [[Anthropic]]
- [[Claude]]
- [[Anthropic SDK]]
- [[AI Wiki - AI Providers - Amazon Bedrock]]
- [[Vertex AI]]