Free tools Windows power users keep installed
One-click scans. No signup required.
If Claude Code cannot connect to Amazon Bedrock, first confirm it is configured to use Bedrock, then identify the AWS credentials and region it actually resolved. A valid AWS login is not the same as permission to invoke a model: authentication, IAM authorization, model access, and network or proxy behavior are separate failure points. Work through them in that order, using /status and the exact error message to narrow the cause.
1. Confirm Claude Code is configured for Bedrock
Claude Code does not use its Anthropic account login flow to authenticate to Bedrock. Bedrock use must be enabled explicitly, either in the setup wizard or by setting CLAUDE_CODE_USE_BEDROCK=1 in the environment of the process that starts Claude Code. See Anthropic’s Claude Code on Amazon Bedrock guide for current setup details; options and behavior can vary by version.
- From an interactive Claude Code prompt: enter
/setup-bedrockto open the setup wizard. If Bedrock has not been enabled yet, type the full command. - From a shell or launcher: make sure
CLAUDE_CODE_USE_BEDROCK=1is exported or otherwise passed to the Claude Code process. Setting it in a different shell or environment will not affect an already-running session. - Complete the wizard: it can use a detected AWS profile, a Bedrock API key, an access-key/secret pair, or credentials already present in the environment. It asks for a region, checks which Claude models the account can invoke, and can pin models; configuration is saved in the user settings file.
If Bedrock is enabled and the connection still fails, continue by checking which AWS identity Claude Code is using.
2. Check the active AWS credentials and identity
Claude Code uses the default AWS SDK credential chain. Potential sources include AWS CLI configuration, environment variables, an AWS IAM Identity Center (SSO) profile, AWS Management Console credentials, and an Amazon Bedrock API key. For temporary access-key credentials, the session token must also be present. The key question is not just whether credentials exist, but whether the running Claude Code process can see the intended source.
#1 Best Overall
Verify an AWS profile or SSO session
- Check that
AWS_PROFILE, if set, names the profile intended for the current shell or session. - For an SSO profile, run
aws sso login --profile <profile>in the same environment where you will launch Claude Code. Replace<profile>with the configured profile name. - If the AWS CLI cannot open a browser, follow its displayed authorization fallback. AWS documents the browser and device authorization flows in Configuring IAM Identity Center authentication with the AWS CLI.
If credentials appear valid but the error persists after a fresh SSO login, check the installed Claude Code version and the credential source it is using. Credential caching and refresh behavior are version-sensitive; do not assume a running process has reloaded credentials just because the login was refreshed.
3. Distinguish authentication failures from AccessDeniedException
Authentication establishes which AWS principal is making the request. Authorization determines what that principal is allowed to do. An error such as missing or expired credentials points first to the credential chain or SSO session; AccessDeniedException more often calls for checking permissions and account-level access.
For AccessDeniedException, inspect permissions for the requested resource
Ask an AWS administrator to compare the active principal’s effective permissions with the exact model or inference profile Claude Code is requesting. The current Claude Code guide lists relevant actions including bedrock:InvokeModel, bedrock:InvokeModelWithResponseStream, bedrock:ListInferenceProfiles, and bedrock:GetInferenceProfile. Policies must cover the relevant foundation-model and inference-profile resources. Organization policies or service control policies can impose additional restrictions, and an explicit deny can block invocation even when another policy allows it. AWS provides examples in Identity-based policy examples for Amazon Bedrock.
Avoid treating broad administrator access as the default fix. Have the administrator check the active principal, allowed actions, resource scope, and any organization-level controls against the specific request.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRank #3
Check the model use-case prerequisite
The current Claude Code guide also identifies Anthropic’s model use-case form as a separate account-level prerequisite. In an AWS Organization, the management account may need to submit it using PutUseCaseForModelAccess, which requires the corresponding IAM permission. This is distinct from fixing an expired credential or granting invocation permission.
4. Verify the resolved region and model identifier
Claude Code selects its Bedrock region in this order: AWS_REGION, then AWS_DEFAULT_REGION, then the active AWS profile’s region, and finally us-east-1. Run /status in Claude Code to see the resolved region and, where applicable, its source. A valid AWS identity can still fail if that region does not support the requested model or inference profile, or if the account lacks access there.
Rank #4
Check model and inference-profile availability
- Compare the region shown by
/statuswith the region where the model or inference profile is available to your account. - List inference profiles in the selected region when diagnosing availability; use the profile identifier supported for the model and region, rather than assuming a base model ID will work.
- For an error that says on-demand throughput is unsupported, check whether the request needs an inference-profile ID or ARN. Some models require an inference profile instead of a base model identifier.
- Check the profile’s prefix and routing behavior. Availability depends on model and region; confirm current details in AWS’s Claude on Amazon Bedrock (Opus 4.6 and earlier) reference and the current Claude Code guide.
Do not change credentials to solve a region or model-routing mismatch unless the error also points to an identity problem.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.5. Investigate SSO browser loops and corporate proxy errors
AWS SSO keeps opening a browser
Repeated browser sign-in attempts can occur when a corporate VPN or TLS-inspection proxy interrupts the browser-based refresh flow. Anthropic’s current guide recommends removing awsAuthRefresh where browser sign-in is being disrupted, then completing aws sso login --profile <profile> manually before launching Claude Code. Because this guidance is version-sensitive, check the installed Claude Code version and the current guide before changing settings.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsBest Value
Certificate error behind a corporate proxy
When TLS inspection replaces certificates with an organization-issued CA, Claude Code may reject the connection unless that CA is trusted. The guide documents using the operating-system CA store or setting NODE_EXTRA_CA_CERTS for AWS requests. It also notes release-specific behavior affecting direct connections and setup-wizard checks, so updating Claude Code may be appropriate. Follow the current version’s instructions rather than disabling certificate validation.
6. Check custom gateways and streaming failures
Claude Code on Bedrock uses the Invoke API, not the Converse API. As Anthropic’s guide states: “Claude Code uses the Amazon Bedrock Invoke API and does not support the Converse API.” A gateway configured only for Converse is therefore not a compatible substitute.
If you use a custom gateway or proxy, it must preserve Bedrock’s streaming response body and headers. In particular, rewriting or mishandling the event-stream Content-Type can cause streaming errors that look unrelated to sign-in. Ask the gateway administrator to verify that the Bedrock response and content type pass through correctly.
Quick Recap
Match the error to the next check
| What you see | Check first |
|---|---|
| Missing or expired credentials; “AWS credentials not found” | Active credential source, AWS_PROFILE, temporary session token, SSO login, or Bedrock API key. |
AccessDeniedException |
Active principal’s IAM actions and resource scope, organization restrictions, and model use-case access. |
| Model or Bedrock model not available in this region | Resolved region in /status, account/model availability, and inference-profile region or prefix. |
| On-demand throughput isn’t supported | Whether the model requires an inference-profile ID or ARN instead of a base model ID. |
| AWS SSO keeps opening a browser | Complete SSO login manually and investigate VPN or TLS-inspection interference; check Claude Code’s current refresh guidance. |
| Certificate error behind corporate proxy | Organization CA trust configuration and Claude Code version-specific guidance. |
| Streaming or content-type error through a gateway | Whether the gateway uses the Invoke API path and preserves Bedrock’s event-stream response and headers. |
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




