Self-Hosted Claude Code (Amazon Bedrock)
If Claude Code runs on AWS Bedrock, Antenna can read usage data directly from Model Invocation Logging in S3. This requires no changes to your Claude Code deployment — Antenna assumes an IAM role in your account and reads the invocation logs from your S3 bucket.
Prerequisites
- An AWS account running Claude Code on Amazon Bedrock
- Model Invocation Logging enabled and configured to write to an S3 bucket
- IAM permissions to create policies and roles
Model Invocation Logging must be enabled in your Bedrock settings before Antenna can read usage data. Go to Amazon Bedrock > Settings > Model invocation logging and configure an S3 destination.
Setup
Get your External ID
On app.antenna.dev, go to Settings > Sources > Claude Code > Connect. Find the Self-Hosted Claude Code method and copy the External ID.
Create an IAM policy
In your AWS account, create an IAM policy that grants read access to the S3 bucket where Bedrock writes invocation logs.
Bedrock Model Invocation Logging identifies users by the identity ARN in each invocation event (e.g. arn:aws:sts::123456789012:assumed-role/RoleName/session-name). If your developers assume IAM roles with unique session names, Antenna can automatically identify individual users.
- Go to IAM > Policies > Create policy.
- Select the JSON tab and paste the following, replacing
YOUR_BUCKET_NAMEwith the bucket where Bedrock writes invocation logs.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:GetObject",
"s3:ListBucket"
],
"Resource": [
"arn:aws:s3:::YOUR_BUCKET_NAME",
"arn:aws:s3:::YOUR_BUCKET_NAME/*"
]
}
]
}- Name the policy (e.g.,
Antenna-Bedrock-ReadOnly) and create it.
Create an IAM role
Create an IAM role that allows Antenna to read from your S3 bucket. The trust policy below grants access to arn:aws:iam::134217665810:role/software-app-prod, which is the IAM role managed by Antenna.
- Go to IAM > Roles > Create role.
- Select Custom trust policy and paste the following, replacing
YOUR_EXTERNAL_IDwith the value from Step 1:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::134217665810:role/software-app-prod"
},
"Action": "sts:AssumeRole",
"Condition": {
"StringEquals": {
"sts:ExternalId": "YOUR_EXTERNAL_ID"
}
}
}
]
}- Click Next and attach the policy you created in the previous step.
- Name the role (e.g.,
Antenna-Bedrock-Role) and create it. - Copy the Role ARN from the role summary page.
Connect in Antenna
Back on app.antenna.dev, enter the following on the Model Invocation Logging (AWS Bedrock) setup page:
- Role ARN — the ARN of the IAM role you just created
- Region — the AWS region where Bedrock is configured (e.g.
us-west-2) - S3 Bucket Name — the bucket where Model Invocation Logging writes data
- S3 Prefix (optional) — if you configured a prefix in your Bedrock logging settings, enter it here
Click Connect to save. Antenna will begin reading invocation logs and data will appear within an hour.
How it works
Bedrock Model Invocation Logging writes a gzipped JSON file to S3 for each invocation. These files are organized by date under a path like:
s3://YOUR_BUCKET/AWSLogs/ACCOUNT_ID/BedrockModelInvocationLogs/REGION/YYYY/MM/DD/Each file contains one JSON object per line (NDJSON format) with fields including:
timestamp— when the invocation occurredidentity.arn— the identity ARN of the caller (used for user identification)modelId— the Bedrock model usedinput.inputTokenCountandoutput.outputTokenCount— token usage
Antenna reads these files daily, aggregates token usage per user, and surfaces the data in your AI dashboards. Users are identified by their identity ARN — if your developers assume IAM roles with unique session names (e.g. arn:aws:sts::123456789012:assumed-role/DeveloperRole/jane.smith), Antenna will automatically create a user for each unique session name.
Sanitizing sensitive prompt data
If your Model Invocation Logging configuration includes request or response body content (for example, prompts), you can deploy sanitize-lambda in your AWS account to process invocation logs and remove that sensitive data from the logged payloads.
Antenna does not require request or response bodies for usage analytics. Only the metadata fields listed in Data collected below are processed.
Alternative: S3 Replication (Push)
If your organization prefers not to grant Antenna cross-account IAM role access, you can use S3 Cross-Account Replication instead. In this model, your S3 bucket automatically pushes data into a dedicated Antenna-managed bucket. Antenna never accesses your account, and you never access Antenna’s account — replication is handled entirely by AWS’s S3 service internally.
This is a push model — you stay in full control and can disable replication at any time by deleting the replication rule. Replication only applies to new objects going forward. If historical data needs to be ingested, a separate S3 Batch Replication job can be run as a one-time backfill.
What you need
- Admin access to your AWS account
- The Destination Bucket ARN and AWS Account ID provided by Antenna
Replication setup
Enable versioning on your source bucket
S3 Cross-Account Replication requires versioning on the source bucket.
- Go to S3 > your source bucket > Properties.
- Under Bucket Versioning, click Edit and select Enable.
- Click Save changes.
Enabling versioning may slightly increase your S3 storage costs, as AWS retains previous versions of objects.
Create a replication IAM role
Create an IAM role in your account that allows S3 to replicate objects to Antenna’s destination bucket.
- Go to IAM > Roles > Create role.
- Select Custom trust policy and paste the following:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"Service": "s3.amazonaws.com"
},
"Action": "sts:AssumeRole"
}
]
}- Click Next, then Create policy and paste the following inline policy. Replace
YOUR_SOURCE_BUCKETwith your bucket name andANTENNA_DESTINATION_BUCKET_ARNwith the ARN provided by Antenna:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:GetReplicationConfiguration",
"s3:ListBucket"
],
"Resource": "arn:aws:s3:::YOUR_SOURCE_BUCKET"
},
{
"Effect": "Allow",
"Action": [
"s3:GetObjectVersionForReplication",
"s3:GetObjectVersionAcl",
"s3:GetObjectVersionTagging"
],
"Resource": "arn:aws:s3:::YOUR_SOURCE_BUCKET/*"
},
{
"Effect": "Allow",
"Action": [
"s3:ReplicateObject",
"s3:ReplicateDelete",
"s3:ReplicateTags"
],
"Resource": "ANTENNA_DESTINATION_BUCKET_ARN/*"
}
]
}- Name the role (e.g.,
Antenna-S3-Replication-Role) and create it.
Create a replication rule
- Go to S3 > your source bucket > Management > Replication rules > Create replication rule.
- Give the rule a name (e.g.,
Antenna-Replication). - Under Source bucket, scope the rule to the appropriate prefix for your data (e.g.,
AWSLogs/for Bedrock invocation logs orq-developer-user-data/for Amazon Q usage data). - Under Destination, select Specify a bucket in another account, and enter the Account ID and Destination Bucket ARN provided by Antenna.
- Select the IAM role you created in the previous step.
- Click Save.
Verify replication
After creating the rule, new objects written to your source bucket under the configured prefix will automatically replicate to Antenna’s bucket. You can verify replication status in the S3 > Management > Replication rules section of your bucket.
Backfill historical data with S3 Batch Replication (one-time, optional)
The replication rule created above only applies to new objects going forward. To replicate existing objects that were written before the rule was created, run a one-time S3 Batch Replication job.
- Go to S3 > your source bucket > Management > Replication rules.
- Select the replication rule you created in the previous step, then choose Create Batch Replication job.
- Under Batch manifest, select Generate manifest to let S3 automatically identify all eligible existing objects, or provide your own manifest using an S3 Inventory report or CSV file.
- Under Batch replication filters, set the replication status filter to Not replicated to target only objects that have never been replicated.
- Choose a destination for the Completion report so you can verify the results after the job finishes.
- For the IAM role, select the same replication role you created earlier (e.g.,
Antenna-S3-Replication-Role). - Review the job details and choose Create job. The job starts in a Ready state — select the job and choose Run job to begin replication.
- Monitor progress in S3 > Batch Operations. Once complete, review the completion report to confirm all objects replicated successfully.
S3 Batch Replication is a one-time operation. You only need to run this once to backfill historical data. All future objects are handled automatically by the live replication rule.
Data collected
For Bedrock deployments, Antenna reads Model Invocation Logging data from your S3 bucket. Each invocation log contains:
- Timestamp, model ID, and API operation
- Input and output token counts
- Identity ARN (used to identify individual users)
- Cache token usage (creation and read)
Antenna does not read the request or response body content. Only the metadata fields listed above are processed. All data stays in your AWS account — Antenna reads it via a cross-account IAM role with read-only S3 access.