October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk6 min

How to Troubleshoot Claude Code Authentication and Access Errors on Amazon Bedrock

A practical troubleshooting sequence for Claude Code on Amazon Bedrock, separating AWS credential problems from IAM denials, region and model mismatches, SSO loops, and proxy errors.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If Claude Code cannot connect to Amazon Bedrock, first confirm it is configured to use Bedrock, then identify the AWS credentials and region it actually resolved. A valid AWS login is not the same as permission to invoke a model: authentication, IAM authorization, model access, and network or proxy behavior are separate failure points. Work through them in that order, using /status and the exact error message to narrow the cause.

1. Confirm Claude Code is configured for Bedrock

Claude Code does not use its Anthropic account login flow to authenticate to Bedrock. Bedrock use must be enabled explicitly, either in the setup wizard or by setting CLAUDE_CODE_USE_BEDROCK=1 in the environment of the process that starts Claude Code. See Anthropic’s Claude Code on Amazon Bedrock guide for current setup details; options and behavior can vary by version.

  1. From an interactive Claude Code prompt: enter /setup-bedrock to open the setup wizard. If Bedrock has not been enabled yet, type the full command.
  2. From a shell or launcher: make sure CLAUDE_CODE_USE_BEDROCK=1 is exported or otherwise passed to the Claude Code process. Setting it in a different shell or environment will not affect an already-running session.
  3. Complete the wizard: it can use a detected AWS profile, a Bedrock API key, an access-key/secret pair, or credentials already present in the environment. It asks for a region, checks which Claude models the account can invoke, and can pin models; configuration is saved in the user settings file.

If Bedrock is enabled and the connection still fails, continue by checking which AWS identity Claude Code is using.

2. Check the active AWS credentials and identity

Claude Code uses the default AWS SDK credential chain. Potential sources include AWS CLI configuration, environment variables, an AWS IAM Identity Center (SSO) profile, AWS Management Console credentials, and an Amazon Bedrock API key. For temporary access-key credentials, the session token must also be present. The key question is not just whether credentials exist, but whether the running Claude Code process can see the intended source.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Verify an AWS profile or SSO session

  1. Check that AWS_PROFILE, if set, names the profile intended for the current shell or session.
  2. For an SSO profile, run aws sso login --profile <profile> in the same environment where you will launch Claude Code. Replace <profile> with the configured profile name.
  3. If the AWS CLI cannot open a browser, follow its displayed authorization fallback. AWS documents the browser and device authorization flows in Configuring IAM Identity Center authentication with the AWS CLI.

If credentials appear valid but the error persists after a fresh SSO login, check the installed Claude Code version and the credential source it is using. Credential caching and refresh behavior are version-sensitive; do not assume a running process has reloaded credentials just because the login was refreshed.

3. Distinguish authentication failures from AccessDeniedException

Authentication establishes which AWS principal is making the request. Authorization determines what that principal is allowed to do. An error such as missing or expired credentials points first to the credential chain or SSO session; AccessDeniedException more often calls for checking permissions and account-level access.

For AccessDeniedException, inspect permissions for the requested resource

Ask an AWS administrator to compare the active principal’s effective permissions with the exact model or inference profile Claude Code is requesting. The current Claude Code guide lists relevant actions including bedrock:InvokeModel, bedrock:InvokeModelWithResponseStream, bedrock:ListInferenceProfiles, and bedrock:GetInferenceProfile. Policies must cover the relevant foundation-model and inference-profile resources. Organization policies or service control policies can impose additional restrictions, and an explicit deny can block invocation even when another policy allows it. AWS provides examples in Identity-based policy examples for Amazon Bedrock.

Avoid treating broad administrator access as the default fix. Have the administrator check the active principal, allowed actions, resource scope, and any organization-level controls against the specific request.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check the model use-case prerequisite

The current Claude Code guide also identifies Anthropic’s model use-case form as a separate account-level prerequisite. In an AWS Organization, the management account may need to submit it using PutUseCaseForModelAccess, which requires the corresponding IAM permission. This is distinct from fixing an expired credential or granting invocation permission.

4. Verify the resolved region and model identifier

Claude Code selects its Bedrock region in this order: AWS_REGION, then AWS_DEFAULT_REGION, then the active AWS profile’s region, and finally us-east-1. Run /status in Claude Code to see the resolved region and, where applicable, its source. A valid AWS identity can still fail if that region does not support the requested model or inference profile, or if the account lacks access there.

Check model and inference-profile availability

  • Compare the region shown by /status with the region where the model or inference profile is available to your account.
  • List inference profiles in the selected region when diagnosing availability; use the profile identifier supported for the model and region, rather than assuming a base model ID will work.
  • For an error that says on-demand throughput is unsupported, check whether the request needs an inference-profile ID or ARN. Some models require an inference profile instead of a base model identifier.
  • Check the profile’s prefix and routing behavior. Availability depends on model and region; confirm current details in AWS’s Claude on Amazon Bedrock (Opus 4.6 and earlier) reference and the current Claude Code guide.

Do not change credentials to solve a region or model-routing mismatch unless the error also points to an identity problem.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

5. Investigate SSO browser loops and corporate proxy errors

AWS SSO keeps opening a browser

Repeated browser sign-in attempts can occur when a corporate VPN or TLS-inspection proxy interrupts the browser-based refresh flow. Anthropic’s current guide recommends removing awsAuthRefresh where browser sign-in is being disrupted, then completing aws sso login --profile <profile> manually before launching Claude Code. Because this guidance is version-sensitive, check the installed Claude Code version and the current guide before changing settings.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Certificate error behind a corporate proxy

When TLS inspection replaces certificates with an organization-issued CA, Claude Code may reject the connection unless that CA is trusted. The guide documents using the operating-system CA store or setting NODE_EXTRA_CA_CERTS for AWS requests. It also notes release-specific behavior affecting direct connections and setup-wizard checks, so updating Claude Code may be appropriate. Follow the current version’s instructions rather than disabling certificate validation.

6. Check custom gateways and streaming failures

Claude Code on Bedrock uses the Invoke API, not the Converse API. As Anthropic’s guide states: “Claude Code uses the Amazon Bedrock Invoke API and does not support the Converse API.” A gateway configured only for Converse is therefore not a compatible substitute.

If you use a custom gateway or proxy, it must preserve Bedrock’s streaming response body and headers. In particular, rewriting or mishandling the event-stream Content-Type can cause streaming errors that look unrelated to sign-in. Ask the gateway administrator to verify that the Bedrock response and content type pass through correctly.

Match the error to the next check

What you see Check first
Missing or expired credentials; “AWS credentials not found” Active credential source, AWS_PROFILE, temporary session token, SSO login, or Bedrock API key.
AccessDeniedException Active principal’s IAM actions and resource scope, organization restrictions, and model use-case access.
Model or Bedrock model not available in this region Resolved region in /status, account/model availability, and inference-profile region or prefix.
On-demand throughput isn’t supported Whether the model requires an inference-profile ID or ARN instead of a base model ID.
AWS SSO keeps opening a browser Complete SSO login manually and investigate VPN or TLS-inspection interference; check Claude Code’s current refresh guidance.
Certificate error behind corporate proxy Organization CA trust configuration and Claude Code version-specific guidance.
Streaming or content-type error through a gateway Whether the gateway uses the Invoke API path and preserves Bedrock’s event-stream response and headers.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.