Claude Platform on AWS Adds Multi-Environment Access with Secure Patterns
Claude Platform on AWS now supports unified, multi-environment access from a single subscription with secure isolation and flexible authentication for AWS workloads, developers, and external services.
What changed?
Claude Platform on AWS (CPonAWS) now supports secure, multi-environment access from a single subscription and account. This update introduces three official access patterns: 1. Cross-account SigV4 IAM role for AWS workloads (e.g., EKS pods), 2. Workspace-scoped API keys for developers' local use, 3. OIDC federation for generating short-term keys/tokens for external workloads (e.g., other clouds or CI/CD pipelines). All environments share a single subscription, using workspace-level isolation between production and development traffic. Authentication and authorization are centrally managed in a dedicated AI Services account, improving isolation and manageability.

Why does it matter to an everyday developer?
This approach streamlines how teams integrate Claude Platform into varied environments: - Developers no longer need separate Anthropic subscriptions or duplicate configurations for each environment. - Access control is cleaner: production vs. development access and billing are separated at the workspace level. - IAM roles, keys, and tokens are managed in a single AWS account, reducing security risks from secret sprawl and aiding onboarding/offboarding. - External automation (CI/CD, third-party clouds) can use OIDC for ephemeral, scoped access—improving security by avoiding long-lived tokens. - Teams can expand to multiple environments or workloads by creating additional workspaces without restructuring their subscription.
What can the developer do now?
How to use multi-environment access with CPonAWS
- 1
