Agents
Claude Code 2.1.281 adds Bedrock guardrails, STS assume_role and Desktop policy locks to the Claude apps gateway
The 23 Sept release lets admins attach an Amazon Bedrock guardrail {id, version} to every request through a gateway Bedrock upstream and have the gateway assume an IAM role through STS, optionally with one session per developer. Admins can also push Claude Desktop policies such as blockReadsOutsideWorkingDirectories and disableBypassPermissionsMode. The release also adds MCP URL-mode elicitation on 2026-07-28 protocol connections, which lets servers start browser-based flows. It adds MCP checks to 'claude plugin validate' that flag silently dropped .mcp.json entries and insecure URLs. The gateway is becoming the place where enterprises enforce agent policy centrally, not on each machine.
↳ Follow the thread