Skip to content
worth noting Tools and apps

AWS and Anthropic described a reference deployment of Claude apps gateway on AWS Fargate

only one source so far

Anthropic and AWS have published a reference architecture for deploying Claude apps gateway – a management layer for Claude Code and Claude Desktop – on AWS Fargate with centralized OIDC authentication, group-based model access control and cost tracking via OTLP.

According to Anthropic and AWS, Claude apps gateway is a self-hosted management layer between Claude Code and Claude Desktop on one side and Amazon Bedrock or Claude Platform on AWS on the other. In the reference deployment described, the gateway container runs on AWS Fargate inside a private VPC; according to the source, the same image can also run on Amazon EKS or EC2. The gateway is launched using the same CLI binary as Claude Code, with the command claude gateway --config gateway.yaml, which loads the configuration in YAML format.

Sign-in uses the OAuth 2.0 device authorization grant in conjunction with an OIDC identity provider – the source names Okta, Microsoft Entra ID, Auth0, Keycloak and Amazon Cognito, among others. The gateway issues a short-lived bearer token that is valid for one hour by default and is silently refreshed in the background. The gateway does not maintain its own user list – it gets groups directly from the identity provider without requiring SCIM synchronization, so revoking access involves removing the user at the identity provider.

Group-based access to models and tools is defined in a single YAML policy block, with policies evaluated using the first matching rule. They should end with a catch-all rule match: {} for users who do not match any other rule; without it, these users have access to the entire catalog. Model restrictions are enforced on the server side, so they cannot be bypassed by modifying the client. The client sends usage metrics via the OpenTelemetry (OTLP) protocol to a selected collector, and the metrics are linked to the user's verified identity.

The source text also contains additional technical configuration details and interface examples that are incomplete in the available portion of the article. You can find the details in the source article.

What changed

Why it matters

For platform and IT teams, this provides a ready-made architectural pattern for centrally controlling who in the company may use Claude Code and Claude Desktop, which models they may access and what spending limits apply, without having to build their own authentication and record-keeping layer. For individual developers, it means signing in once through corporate SSO, with model access and any revocation of permissions managed centrally by an administrator through the identity provider.

Two audiences, two different impacts

What this means

01

For individuals

Developers using Claude Code or Claude Desktop at a company that deploys the gateway sign in once through corporate SSO (OIDC) and see only the models enabled for their group; their access can be revoked immediately by deleting their account at the identity provider.

What to do When the gateway is deployed at your company, sign in through SSO according to the administrator's instructions and check which models are enabled for your group.
More practical updates →
02

For a business

Companies gain a reference approach for centralizing authentication, group-based model access control and enforcement of cost limits for Claude Code and Claude Desktop across the organization on AWS Fargate (or EKS/EC2).

Risks and compliance
What to decide Evaluate deploying Claude apps gateway on AWS Fargate to centralize management of authentication, model access and costs for Claude Code and Claude Desktop.
More business impacts →
AWS Claude apps gateway Claude Code Fargate Governance OIDC

Check the original

Event sources

only one source so far · 1 publisher, 0 independent. We count feeds from the same owner only once.

1
AWS Machine Learning Blog primary source · first detected Deploying Anthropic Claude apps gateway for AWS for enterprise workloads