Anthropic launches Claude apps gateway for AWS, enabling centralized control of Claude Code and Claude Desktop deploymen
Anthropic has released Claude apps gateway for AWS, a self-hosted control plane that gives enterprises centralized management of Claude Code and Claude Desktop deployments. The gateway runs as a stateless container on AWS infrastructure and handles identity through OIDC, policy enforcement, telemetry, request routing to Amazon Bedrock or Claude Platform on AWS, and per-user spend caps.
Claude apps gateway for AWS
Anthropic has released Claude apps gateway for AWS, a self-hosted control plane that provides enterprises with centralized management of Claude Code and Claude Desktop deployments across development teams. The gateway runs as a stateless container on AWS infrastructure and replaces the need for individual cloud credentials per developer.
Architecture and deployment
The gateway is delivered inside the Claude Code CLI binary and runs in a single stateless container on Amazon ECS, Amazon EKS, or Amazon EC2. It requires a PostgreSQL database (Amazon RDS) that stores short-lived sign-in state and rate-limit counters. The system sits behind an internal Application Load Balancer with TLS certificates from AWS Certificate Manager.
Developers access the gateway through private networks, and the gateway uses an IAM task role to call upstream providers on their behalf. According to Anthropic, the gateway and client are built together, making the login flow gateway-aware with automatic application of managed settings.
Core capabilities
The gateway handles five functions:
Identity: Connects to any OpenID Connect (OIDC) identity provider. After browser SSO sign-in, the gateway issues short-lived tokens (one hour default lifetime). No long-lived secrets are stored on developer machines.
Policy: Administrators define managed settings once on the server. The gateway enforces allowed models, tool permissions (file writes, web access), and default settings centrally, scoped by IdP group. Developers cannot override these rules locally.
Telemetry: Usage metrics are relayed over OpenTelemetry Protocol (OTLP) to administrator-configured collectors like Amazon CloudWatch or Amazon Managed Service for Prometheus.
Routing: The gateway routes inference requests to Amazon Bedrock or Claude Platform on AWS with optional failover between AWS Regions or across multiple accounts.
Spend caps: Administrators set daily, weekly, and monthly spend limits per organization, group, or user. The gateway blocks requests when caps are exceeded until the period resets or limits are raised.
Configuration and authentication
The gateway reads a single YAML configuration file at startup. For Amazon Bedrock deployments, the Bedrock upstream uses the container's IAM role with no static credentials. For Claude Platform on AWS, administrators configure workspace ID and region.
Model IDs use Anthropic API naming (claude-sonnet-5, claude-opus-4-8) rather than Amazon Bedrock ARNs. Developers run claude /login and authenticate through corporate SSO. Sessions refresh silently using OIDC refresh tokens. Removing a user from the IdP revokes access at the next refresh.
Data handling
When used with Amazon Bedrock, inference requests are processed through Amazon Bedrock in administrator-configured AWS Regions, maintaining the same data handling controls as other Amazon Bedrock workloads. When used with Claude Platform on AWS, requests are processed by Anthropic.
What this means
The Claude apps gateway addresses a specific enterprise problem: managing AI tool access at scale without distributing individual credentials or manually pushing configuration to each developer machine. The self-hosted architecture means enterprises retain control over deployment, identity integration, and telemetry routing. The gateway's integration with both Amazon Bedrock and Claude Platform on AWS gives organizations flexibility in how they handle data residency requirements. For organizations already using Claude Code, this provides a path to broader deployment without creating new security or cost management challenges.
Related Articles
Claude Haiku 5.5 arrives on Amazon Bedrock; Anthropic claims ~75% lower cost than Haiku 4.5
Claude Haiku 5.5 is available on Amazon Bedrock and Claude Platform on AWS. According to Anthropic, it is the fastest and most efficient model in the Claude 5.5 family and costs around 75% less than Claude Haiku 4.5 for most tasks. It is the first Haiku model with effort controls.
Anthropic releases Claude Haiku 5.5, claims ~75% lower running cost than Haiku 4.5
Anthropic released Claude Haiku 5.5 on October 7, 2026. The company claims it costs around 75% less to run than Haiku 4.5 and is its fastest model to date. Anthropic also halved Claude Sonnet 5.5's cache read pricing and added a monthly API credit for Max and Team subscribers.
Anthropic Python SDK 1.12.0 adds claude-haiku-5-5 and typed computer and browser tool calls
Anthropic's Python SDK v1.12.0, dated 2026-10-07, adds the claude-haiku-5-5 model identifier and typed tool calls for the computer and browser toolsets. It also adds lifecycle fields to /v1/models and several admin API changes. The release notes give no pricing, context window, or benchmark data for the new model.
Anthropic Opens Cyber Verification Program to More Security Teams With Reduced Claude Safety Filters
Anthropic is expanding its Cyber Verification Program (CVP) to a much larger pool of vetted security professionals, giving them access to Claude's most powerful models with reduced safety filters. Access is split into three tiers: Defense, Red Team, and Specialized. Anthropic claims partners in its predecessor program, Project Glasswing, found at least 129,000 confirmed vulnerabilities between April and July 2026.
Comments
Loading...