Overview
Claude Platform on AWS is Anthropic’s own platform, offered through your AWS account and billed on your AWS bill. It is a different service from Amazon Bedrock, and its credentials are separate from any Anthropic Console account you already have.
You need three things: a region, a workspace ID, and either an API key or IAM access keys.
Get a key
- 1In your AWS account, subscribe to Claude Platform on AWS through AWS Marketplace. This creates an Anthropic organisation linked to AWS, separate from any other you have.
- 2A default workspace is created for you. Find its ID (it looks like
wrkspc_…) on the Claude Platform on AWS page in the AWS Console, or in the Claude Console. A workspace belongs to one region, so note that region too. - 3In the Claude Platform on AWS console, open API keys and create a key.
- 4Copy the key. Alternatively, use an IAM user or role: you then enter an access key ID and secret instead of the API key.
Cost. Billed through AWS like your other services. Check your AWS budgets and alerts.
Add it to Loom
- 1Open Loom, then Providers in the menu, and choose Add provider.
- 2Pick Claude on AWS (the search box finds it).
- 3Fill in the fields in the table below.
- 4Choose Connect. Loom checks the key and says how many models it found. If it cannot check, it says so, and you can Save anyway and try a message.
- 5Open the model chip below the message box and pick a model.
- Choose the same Region as your workspace. Pick it from the list, or choose Other… to type one.
- Paste the Workspace ID. It is required, and Loom sends it with every request.
- Use either the API key or the access key ID and secret (plus a session token if your credentials are temporary), not both.
| Field in Loom | What to put | Needed |
|---|---|---|
| API key | Your API key. Leave empty if you use the access key pair instead | One of the two |
| Workspace ID | wrkspc_… Required by AWS on every request. Sent as the anthropic-workspace-id header. | Yes |
| Region | Pick from the list, or choose Other… to type one. us-east-1 The AWS region of your workspace. It must match the workspace. | Yes |
| Access key ID (instead of an API key) | AKIA… | Optional |
| Secret access key | Paste the secret | Optional |
| Session token (only for temporary credentials) | Optional | Optional |
| Endpoint | https://aws-external-anthropic.{region}.api.awsfilled in from the fields above | Pre-filled |
| Name | Anything you like. It is shown in the model picker | Optional |
At a glance
| Appears in Loom as | Claude on AWS |
| Sign-in | API key sent in the x-api-key header, or IAM access keys signed with AWS Signature V4 |
| Models | Loom fetches the list from your account |
| Tools (connectors, search) | Yes |
| Photos | Yes |
| PDFs | Yes |
Good to know
IAM route. The IAM user or role needs permission for the actions
aws-external-anthropic:CreateInference and aws-external-anthropic:CountTokens on your workspace. If the same principal also uses workspace API keys, add aws-external-anthropic:CallWithBearerToken.Header question. AWS’s documentation describes the API key as a bearer token, while Anthropic’s pages use
x-api-key. Loom sends x-api-key. If AWS ever rejects it, open Advanced → Authentication in the provider and switch to Bearer.Whose account? If the AWS account belongs to your employer, check that you are allowed to put its credentials on a personal device. A key you can revoke is better than long-lived access keys.
If something goes wrong
| What you see | What to do |
|---|---|
| 401 or 403 | Check that the key came from the AWS-linked organisation, not the regular Anthropic Console, and that the workspace ID matches. Try the Bearer option under Advanced. |
| “workspace not found” or a region error | The region in Loom must be the region of the workspace. |
| IAM keys fail | Check the policy lists the actions above, and the resource is your workspace ARN. |