Loom / Guides / Claude on AWS

Cloud · AWS

Claude on AWS

Use Claude through Claude Platform on AWS, billed to your AWS account.

Overview

Claude Platform on AWS is Anthropic’s own platform, offered through your AWS account and billed on your AWS bill. It is a different service from Amazon Bedrock, and its credentials are separate from any Anthropic Console account you already have.

You need three things: a region, a workspace ID, and either an API key or IAM access keys.

Get a key

  1. 1
    In your AWS account, subscribe to Claude Platform on AWS through AWS Marketplace. This creates an Anthropic organisation linked to AWS, separate from any other you have.
  2. 2
    A default workspace is created for you. Find its ID (it looks like wrkspc_…) on the Claude Platform on AWS page in the AWS Console, or in the Claude Console. A workspace belongs to one region, so note that region too.
  3. 3
    In the Claude Platform on AWS console, open API keys and create a key.
  4. 4
    Copy the key. Alternatively, use an IAM user or role: you then enter an access key ID and secret instead of the API key.

Cost. Billed through AWS like your other services. Check your AWS budgets and alerts.

Add it to Loom

  1. 1
    Open Loom, then Providers in the menu, and choose Add provider.
  2. 2
    Pick Claude on AWS (the search box finds it).
  3. 3
    Fill in the fields in the table below.
  4. 4
    Choose Connect. Loom checks the key and says how many models it found. If it cannot check, it says so, and you can Save anyway and try a message.
  5. 5
    Open the model chip below the message box and pick a model.
  • Choose the same Region as your workspace. Pick it from the list, or choose Other… to type one.
  • Paste the Workspace ID. It is required, and Loom sends it with every request.
  • Use either the API key or the access key ID and secret (plus a session token if your credentials are temporary), not both.
Field in LoomWhat to putNeeded
API keyYour API key. Leave empty if you use the access key pair insteadOne of the two
Workspace IDwrkspc_… Required by AWS on every request. Sent as the anthropic-workspace-id header.Yes
RegionPick from the list, or choose Other… to type one. us-east-1 The AWS region of your workspace. It must match the workspace.Yes
Access key ID (instead of an API key)AKIA…Optional
Secret access keyPaste the secretOptional
Session token (only for temporary credentials)OptionalOptional
Endpointhttps://aws-external-anthropic.{region}.api.aws
filled in from the fields above
Pre-filled
NameAnything you like. It is shown in the model pickerOptional

At a glance

Appears in Loom asClaude on AWS
Sign-inAPI key sent in the x-api-key header, or IAM access keys signed with AWS Signature V4
ModelsLoom fetches the list from your account
Tools (connectors, search)Yes
PhotosYes
PDFsYes

Good to know

IAM route. The IAM user or role needs permission for the actions aws-external-anthropic:CreateInference and aws-external-anthropic:CountTokens on your workspace. If the same principal also uses workspace API keys, add aws-external-anthropic:CallWithBearerToken.
Header question. AWS’s documentation describes the API key as a bearer token, while Anthropic’s pages use x-api-key. Loom sends x-api-key. If AWS ever rejects it, open Advanced → Authentication in the provider and switch to Bearer.
Whose account? If the AWS account belongs to your employer, check that you are allowed to put its credentials on a personal device. A key you can revoke is better than long-lived access keys.

If something goes wrong

What you seeWhat to do
401 or 403Check that the key came from the AWS-linked organisation, not the regular Anthropic Console, and that the workspace ID matches. Try the Bearer option under Advanced.
“workspace not found” or a region errorThe region in Loom must be the region of the workspace.
IAM keys failCheck the policy lists the actions above, and the resource is your workspace ARN.

Official documentation