AWS has published an implementation guide for running Anthropic’s Claude Code with Claude Opus 5.5 and Claude Sonnet 5.5 through Amazon Bedrock in AWS GovCloud (US). For teams building on regulated or ITAR-related workloads, the guide provides a GovCloud-based route to AI-assisted coding, but requires organizations to assess the design against their own compliance and security obligations.
Claude Code is Anthropic’s agentic coding tool, able to read and edit code across files, run tests and other commands, inspect Git history, and work with development tools. AWS says the Bedrock configuration can be used from a terminal, supported IDEs, or background workflows through the Claude Agent SDK. Claude Code can also connect to tools and data sources through the Model Context Protocol, and teams can use memory files, skills, hooks, and CI/CD integrations to standardize workflows.
GovCloud offers two endpoint paths
AWS GovCloud exposes two Bedrock endpoint surfaces for the three named Claude models: bedrock-runtime and bedrock-mantle. Both use the same underlying Mantle inference engine and Zero Operator Access architecture, according to AWS. The runtime endpoint is available in both GovCloud regions, US-West and US-East; Mantle is available in GovCloud US-West.
The choice affects available governance features. Runtime uses the AWS SDK’s InvokeModel and Converse APIs and supports Bedrock Guardrails, Knowledge Bases, Agents, and invocation logging. AWS recommends it for most new applications, particularly deployments that need audit trails. Mantle supports Anthropic’s Messages API natively and, AWS says, exposes capabilities then limited to that surface, including server-side tools, background inference, and Projects.
Guardrails and invocation logging are exclusive to the runtime endpoint. That makes runtime the relevant choice for organizations that need content filtering or comprehensive invocation records, even where native Messages API access would otherwise be useful.
Certification status differs by model
AWS states that Claude Opus 5.5 and Claude Sonnet 5.5 hold FedRAMP Class D certification on Amazon Bedrock. Claude Sonnet 5 holds FedRAMP Class D certification as well as DoD Impact Level 4 and 5 authorization. AWS positions Sonnet 5 as the model to default to for workloads requiring IL4/IL5 authorization, while presenting Sonnet 5.5 as a lower-cost-per-task option for coding and knowledge work and Opus 5.5 for deeper reasoning or longer autonomous tasks where its certification level is sufficient.
These distinctions are deployment inputs rather than a blanket compliance determination. AWS directs readers to its current model compliance listing and says the approach may not suit every organization or compliance program.
Configuration requires model access, identity controls and explicit routing
AWS’s setup guide calls for a GovCloud account with Bedrock access, enabled model access for the selected Claude models, appropriate IAM permissions, and valid AWS CLI session credentials. Runtime deployments require model invocation and inference-profile permissions. Mantle deployments require permissions for inference, projects, and model listing, or the corresponding managed policy.
For an interactive deployment, developers can select Amazon Bedrock as a third-party platform in Claude Code’s login wizard, then choose authentication, the us-gov-west-1 region, and model pins. AWS also documents environment-variable configuration for scripted or enterprise rollouts: teams enable Bedrock, select the GovCloud West region, and supply the full Sonnet 5.5 or Opus 5.5 model identifier. Mantle uses its own routing setting. Claude Code’s status command can confirm the chosen provider and model.
Model pinning is important for predictable operations and cost. AWS says unpinned sonnet and opus aliases resolve to Claude Code defaults that can change between releases. Claude Code defaults to Opus 5.5, meaning an unpinned deployment is billed at the Opus per-token rate. Teams that want Sonnet 5.5 as their default should set its full model ID and can use default-model settings to control future migrations.
Enterprise rollout extends beyond the inference layer
AWS recommends using IAM Identity Center and temporary, role-based credentials to centrally govern developer access instead of relying on static keys. It also advises reviewing token-per-minute and request-per-minute quotas according to the number of active developers, as well as centrally managing configuration through settings files where appropriate.
Cost controls are another material consideration. AWS says Claude Code sessions can be token-intensive, particularly with Opus 5.5, which has a higher per-token cost than Sonnet 5.5. Its referenced per-user guardrail pattern can enforce daily token limits and alert at 80% and 100% thresholds using CloudWatch invocation logging, Lambda, and DynamoDB. Supported models also offer prompt caching with five-minute and one-hour TTL options.
Security teams can apply managed permissions that local configuration cannot override, deploy shared CLAUDE.md files for coding practices, and use hooks for actions such as formatting or linting. AWS cautions that while Bedrock secures the inference layer, Claude Code runs on local developer machines and therefore requires a separate risk assessment and management plan. The guide is an implementation reference, not a claim that a configuration automatically meets every regulatory requirement.
Source: AWS Machine Learning Blog.
Definition. Claude Code is Anthropic’s agentic coding tool that can read and edit code across files, run commands and tests, inspect Git history, and work with development tools.
| Endpoint | Supported governance and capabilities |
|---|---|
| bedrock-runtime | Available in GovCloud US-West and US-East; supports InvokeModel and Converse APIs, Bedrock Guardrails, Knowledge Bases, Agents, and invocation logging. |
| bedrock-mantle | Available in GovCloud US-West; supports Anthropic’s Messages API natively, server-side tools, background inference, and Projects. |
Key takeaways
- AWS GovCloud offers Bedrock runtime and Mantle endpoint paths for the named Claude models, with different governance and API capabilities.
- The runtime endpoint supports Bedrock Guardrails and invocation logging, while Mantle provides native Anthropic Messages API access and selected capabilities limited to that surface.
- Claude Opus 5.5 and Claude Sonnet 5.5 are stated to have FedRAMP Class D certification; AWS positions Sonnet 5 for workloads requiring DoD IL4 or IL5 authorization.
- Pinning full model IDs helps keep operations and costs predictable because unpinned aliases can change between Claude Code releases.
- AWS recommends temporary role-based credentials, centralized configuration, quota review, and separate local-device risk management.
FAQ
Which Bedrock endpoint supports Guardrails and invocation logging?
The bedrock-runtime endpoint supports Bedrock Guardrails and invocation logging. AWS says those features are exclusive to runtime.
When does AWS recommend using the runtime endpoint?
AWS recommends runtime for most new applications, particularly deployments that need audit trails.
Why should teams pin a Claude model ID?
AWS says unpinned sonnet and opus aliases resolve to Claude Code defaults that can change between releases; pinning helps provide predictable operations and cost.
Does a GovCloud configuration automatically meet regulatory requirements?
No. AWS describes the guide as an implementation reference and says organizations must assess the design against their own compliance and security obligations.