Implementing Multi
You need Claude Platform on AWS (CPonAWS) inference from three environments: production workloads on AWS, developer laptops for local iteration, and external services on other cloud providers or on-premises continuous integration and continuous delivery (CI/CD) pipelines. Each environment has different authentication requirements, but all should share a single subscription with workspace-level isolation between production and development traffic. For organizations with additional environments, create a workspace per team or workload and repeat the cross-account role pattern for each.
This post walks you through the complete setup. You will deploy a dedicated AI Services account within your organization and configure cross-account SigV4 for AWS workloads. You will also generate workspace-scoped API keys for developers and wire up OIDC federation for external environments. Every step includes a CLI command, console instruction, or code snippet. If you’re evaluating which account structure is right for your organization, or which authentication path fits your workloads, see the related Architecture Patterns and Authentication Paths posts. This post picks up where those decisions end: a complete, step-by-step implementation.
The dedicated AI Services account pattern places the CPonAWS subscription in a dedicated AI Services linked account within your organization. This account owns the subscription, workspaces, API keys, and cross-account roles. Workload accounts don’t touch the subscription directly: they assume roles into the AI Services account to make inference calls. The result is a three-account structure: a payer (management) account for billing and governance, an AI Services account that hosts the CPonAWS subscription and workspaces, and one or more workload accounts that consume inference through cross-account roles, as shown in the following diagram.
Figure 1: Multi-account topology for Claude Platform on AWS with a dedicated AI Services account
The preceding diagram shows the high-level account topology. The following diagram shows the specific implementation we will build, including AWS Identity and Access Management (IAM) roles, access paths, and workspace mappings:
Figure 2: The three access patterns implemented in this guide
We will configure three access patterns:
Before starting, verify you have:
This walkthrough is divided into four parts. Each part configures one layer of the architecture: the CPonAWS subscription and workspace structure, cross-account SigV4 access for AWS workloads, workspace-scoped API keys for developers, and OIDC federation for external environments. Complete them in order. Each part builds on the resources created in the previous one.
Throughout this guide, replace these placeholders with your actual values:
Part 1: Set up the AI Services account
Follow the Introducing Claude Platform on AWS guide to subscribe your AI Services account to CPonAWS. After you’re subscribed, create two workspaces to isolate production and development traffic:
Figure 3: Claude Console dashboard showing how to create a workspace
Tip: Record both workspace ARNs now. You will reference them in IAM policies and code throughout this guide. Workspaces are created in a specific AWS Region, and your API calls must target the matching Regional endpoint (for example, aws-external-anthropic.us-east-1.api.aws). Note that the workspace Region determines the API endpoint, not where inference runs. Inference geography is controlled separately through the workspace’s Security settings in the Claude Console. Current options are “US” and “Global routing”. For short-term keys, this is enforced at both generation and use: the token only works against the same Regional endpoint where it was generated. Long-lived API keys are not Region-locked. For supported Regions and available models, see Supported Regions and models in the Claude Platform on AWS User Guide.
This section configures an EKS pod (or another workload) in the Workload account to make inference calls through SigV4 signing. The workload assumes a role in the AI Services account that grants access only to the production workspace.
First, create the trust policy file in the AI Services account. This allows a specific role in the Workload account to assume the cross-account role.
Note: CreateInference is scoped to the WORKSPACE_PROD_ID workspace ARN. This role cannot access the development workspace or additional workspace in the account.
The EKS pod role in the Workload account needs permission to assume the cross-account role. First, create the policy.
Part 3: Workspace-scoped API key for developer access
Developers can use API keys to call Claude from their laptops without configuring cross-account role chains. In the following section, you will generate a key, scope it to the development workspace, and verify isolation.
Figure 4: Generating a long-term API key from the Claude Console (API Keys page) with configurable expiration
By default, the generated key’s backing IAM user (AeaApiKey-*) has the AnthropicLimitedAccess managed policy attached. This policy grants access to every workspace. To enforce workspace isolation:
The admin distributes the scoped API key to the development team. Store it in the team’s preferred secret management solution. For AWS based teams, store it in AWS Secrets Manager within the workload or developer AWS account:
Note: The API key is self-authenticating. It works regardless of which AWS account (or non-AWS environment) it’s called from. Store it wherever your developers can retrieve it securely.
Expected output: A response from Claude confirming the development workspace is accessible.
Expected output: GOOD: Access denied as expected followed by a permission error. If the key successfully accesses the production workspace, revisit step 3.2 and confirm the managed policy was detached.
For workloads running on Google Cloud Platform (GCP), Kubernetes clusters outside AWS, or CI/CD pipelines (GitHub Actions, GitLab CI), OIDC federation authenticates them without storing AWS credentials. The flow: the external identity provider issues a token, and AWS Security Token Service (STS) exchanges it for temporary credentials. Those credentials then generate a short-lived CPonAWS bearer token.
Configure an IAM OIDC identity provider in your AI Services account for your external workload’s issuer. For example, for GCP workloads follow the Access AWS using a Google Cloud Platform native workload identity guide for the complete setup.
Important: CallWithBearerToken must be granted on Resource: "*". Scoping it to a workspace ARN causes all token generation calls to fail. CreateInference remains scoped to the workspace ARN for isolation: the generated token inherits the workspace restriction.
Key point: The generated token expires after 1 hour (configurable, maximum 12 hours). After generation, the token is a standalone bearer credential: the external workload no longer needs AWS credentials to make inference calls. For services that run continuously (for example, a GCP Cloud Run container), implement token renewal by refreshing the token before expiry.
To avoid ongoing charges if you are evaluating:
With cross-account SigV4, workspace-scoped API keys, and OIDC federation configured, your CPonAWS deployment supports AWS workloads, developer access, and external environments with workspace-level isolation. To harden for production:
To get started with Claude Platform on AWS, visit the Claude Platform on AWS service page, or go directly to the AWS Management Console. For full documentation, see the Claude Platform on AWS User Guide and the Anthropic documentation.
Related Stories
AI News
Top BBC Director Says He's Been Reviewing a Fully AI
3 minutes ago
AI News
Newsom signs law barring sole use of AI in hiring, firing decisions
1 hour ago
AI News
Google rolls out new Gemini AI model but restricts access over safety concerns
1 hour ago
AI News
Trump’s AI rebrand may stop at the White House
1 hour ago
AI News
Cardinal Fernández on the complementarity of humanity and AI
2 hours ago
AI News
AI chatbots remove hijabs from images of Muslim women when prompted
2 hours ago
AI News
AI agents tried to hack Library and Archives Canada website, research firm says
2 hours ago
AI News
Anthropic pushes for opt
3 hours ago