Internal AI Platform: LibreChat vs Open WebUI on Bedrock
Build an internal AI platform with Claude for all staff: LibreChat or Open WebUI, Entra SSO, Bedrock EU profiles, config snippets and the real operating effort.
TL;DR
An internal AI platform with Claude means a self-hosted chat UI, your identity provider, and Bedrock in EU mode. We recommend LibreChat (MIT, native Bedrock) over Open WebUI (branding clause above 50 users, no native Bedrock). Pin eu.anthropic.claude-sonnet-5-5, switch RAG embeddings to Bedrock, and budget for monthly patching.
What does an internal AI platform with Claude consist of?
An internal AI platform is four layers you own: a chat front end, single sign-on through your identity provider, an optional gateway for keys and budgets, and the model endpoint. For Claude with EU data residency the endpoint is Amazon Bedrock with an eu. inference profile. Everything else runs in your own AWS account or data center.
| Layer | Typical choice | What it decides |
|---|---|---|
| Chat UI | LibreChat or Open WebUI | Features, license, patch effort |
| Identity | Microsoft Entra ID via OpenID Connect | Who gets access, who is admin |
| Gateway (optional) | LiteLLM or none | Per-team budgets, OpenAI-compatible API |
| Model | Claude on Bedrock, eu. geo profile |
Where prompts are processed |
| Storage | MongoDB, Postgres with pgvector | Where chat history and documents live |
The model layer is the part people get wrong. On the Sonnet 5.5 model card, AWS lists three profiles: eu.anthropic.claude-sonnet-5-5 keeps data within EU regions, us. keeps it in the US and Canada, global. routes worldwide. Sonnet 5.5 launched on Bedrock on 28 September 2026 with a 1M token context window. Opus 5.5 launched on 22 September 2026 and also has an eu. profile. Neither model has an in-region option in an EU member state on bedrock-runtime, so the EU geo profile is the residency control.
The second point is the provider boundary. AWS states in its data protection page that model providers have no access to Bedrock logs or to customer prompts and completions. That is why the hosted Claude apps are a different decision: Anthropic’s privacy center says plainly that “data is stored in the US”.
The chat history is the third point and the one most teams forget. It sits in your database, not at AWS or Anthropic. Every conversation an employee has is stored in MongoDB (LibreChat) or in the Open WebUI database, in clear text, under your retention policy. Decide the retention period and who may read it before go-live, not after the first works council question.
LibreChat vs Open WebUI: which fits Claude on Bedrock?
LibreChat fits better for a Claude-on-Bedrock platform. It is MIT licensed, has a native Bedrock endpoint and supports MCP over stdio, SSE and streamable HTTP. Open WebUI has strong RAG and SCIM, but it has no native Bedrock connector and its license restricts rebranding once more than 50 people use it.
| Criterion | LibreChat | Open WebUI |
|---|---|---|
| License | MIT | Open WebUI License: BSD-style plus a branding clause |
| Rebranding | Allowed | Only up to 50 end users per rolling 30 days, with written permission, or with an enterprise license |
| Latest release (1 Oct 2026) | v0.8.8, 1 October 2026 | v0.11.4, 21 September 2026 |
| Releases since January 2026 | 7 numbered releases | 31 releases |
| Bedrock | Native endpoint, IAM role or Bedrock API key | Via an OpenAI-compatible proxy only (LiteLLM, stdapi.ai, Bedrock Access Gateway) |
| SSO | OpenID Connect, Entra example, required role, admin role mapping, LDAP | OAuth/OIDC, Microsoft single tenant, LDAP, SCIM 2.0, trusted headers |
| RAG | Separate RAG API with pgvector, embeddings default openai |
Built in, 9 vector databases, local embedding model by default |
| Admin controls | Admin panel for users, groups, roles, config overrides | Granular RBAC and user groups |
| MCP | stdio, SSE, streamable HTTP, per-user OAuth, share permissions | Native streamable HTTP only, MCPO proxy for other transports |
The Bedrock row is decisive. AWS lists the APIs per model, and for both Sonnet 5.5 and Opus 5.5 Chat Completions is marked not supported on bedrock-runtime and on bedrock-mantle. Open WebUI talks to cloud providers in the OpenAI Chat Completions format. Its provider guide offers Bedrock Mantle as the no-install option, but describes it as covering a limited selection of open weight models. For Claude you need a translation layer. The guide names the Bedrock Access Gateway first, and that AWS sample repository is archived. That leaves LiteLLM, which we cover in our LiteLLM EU gateway guide. It works, but it is one more service to patch.
The license row matters for corporate rollouts. The Open WebUI License is BSD-style with a fourth clause: you may not alter or remove the “Open WebUI” name or logo unless your deployment has at most 50 end users in any rolling 30-day period, you have written permission, or you hold an enterprise license. A company portal called “Acme AI” with 300 users is an enterprise sale, not a download. LibreChat’s MIT license has no such clause.
Open WebUI still wins in two places. RAG works out of the box with a local sentence-transformers/all-MiniLM-L6-v2 embedding model, so uploaded documents never leave the server for embedding. And SCIM 2.0 provisioning is documented for Entra ID. If you run Ollama or vLLM next to Claude, or if you already operate LiteLLM, Open WebUI is a reasonable choice.
How do you deploy LibreChat on Bedrock in the EU?
Clone LibreChat, set the Bedrock region and EU model list in .env, connect Entra ID through OpenID Connect, and mount a librechat.yaml via an override file. The default compose file starts LibreChat on port 3080 with MongoDB, Meilisearch, pgvector and the RAG API. By our estimate, a test instance takes an afternoon and production hardening several days.
- Clone the repository and copy the environment file:
git clone https://github.com/LibreChat-AI/LibreChat.git, thencp .env.example .env. - Give the host an IAM role with Bedrock invoke rights. The
.env.examplerecommends IAM roles or other short-term credentials in deployed environments; static keys are the fallback. - Replace the example model list. LibreChat’s own example lists
global.andus.profiles and notes thatglobal.has no regional premium. For EU residency, seteu.profiles explicitly. - Register an app in Entra ID with the redirect URI
https://your-domain/oauth/openid/callback, then fill theOPENID_*variables. - Switch RAG embeddings to Bedrock. The RAG API README defaults
EMBEDDINGS_PROVIDERtoopenai, which would send every uploaded file to OpenAI for embedding. - Create
docker-compose.override.yaml, thendocker compose up -d.
# .env (excerpt)
BEDROCK_AWS_DEFAULT_REGION=eu-central-1
BEDROCK_AWS_MODELS=eu.anthropic.claude-sonnet-5-5,eu.anthropic.claude-opus-5-5
ALLOW_EMAIL_LOGIN=false
ALLOW_REGISTRATION=false
ALLOW_SOCIAL_LOGIN=true
OPENID_CLIENT_ID=<application-client-id>
OPENID_CLIENT_SECRET=<client-secret>
OPENID_ISSUER=https://login.microsoftonline.com/<tenant-id>/v2.0/
OPENID_SESSION_SECRET=<random-string>
OPENID_SCOPE="openid profile email"
OPENID_CALLBACK_URL=/oauth/openid/callback
OPENID_REQUIRED_ROLE=ai-platform-users
OPENID_REQUIRED_ROLE_TOKEN_KIND=id
OPENID_REQUIRED_ROLE_PARAMETER_PATH="roles"
# RAG API: keep embeddings on Bedrock instead of the openai default
EMBEDDINGS_PROVIDER=bedrock
AWS_DEFAULT_REGION=eu-central-1
# docker-compose.override.yaml
services:
api:
image: registry.librechat.ai/librechat-ai/librechat:latest
volumes:
- type: bind
source: ./librechat.yaml
target: /app/librechat.yaml
# librechat.yaml (excerpt)
version: 1.3.17
endpoints:
bedrock:
availableRegions:
- 'eu-central-1'
The override does two things. It mounts librechat.yaml, and it swaps the image. The shipped docker-compose.yml pulls librechat-dev:latest, a development build. The override example in the repository uses librechat:latest, the numbered release image. For production, pin the release tag you tested. The OPENID_REQUIRED_ROLE line comes from the Entra ID guide and restricts login to members of an app role. OPENID_ADMIN_ROLE in the same file maps a second role to LibreChat admins.
Check the default compose file before you expose anything. MongoDB starts with --noauth, and pgvector uses myuser and mypassword. That is acceptable on a laptop. On a server, set credentials, keep both databases off public ports, and put the UI behind your reverse proxy with TLS.
Which settings keep data inside the EU?
Three defaults can move data out of the EU without anyone noticing: a global. or us. Bedrock profile, the openai embedding default in the RAG API, and Fable models that require AWS human review. Pin eu. profiles, set embeddings to Bedrock, and leave Fable off the model list unless legal has approved its retention terms.
Inference profile. Pin only eu. IDs in BEDROCK_AWS_MODELS. Anthropic’s pricing page states that regional and multi-region endpoints on Bedrock and Google Cloud cost 10% more than global ones for Sonnet 4.5 and later. That premium is the price of residency, and the reason example configs default to global..
Embeddings. Uploaded PDFs are chunked and embedded before Claude sees them. With the default openai provider that happens at OpenAI. Set EMBEDDINGS_PROVIDER=bedrock and check that the embedding model you choose is offered in your region.
Fable models. AWS’s data retention page says Claude Fable 5 and 5.1 require the mode aws_review. Prompts and completions are then retained within AWS for up to 30 days and may be reviewed by AWS; they are not shared with Anthropic. If cross-region inference is used, retained data sits in the destination region. For a chat tool that all staff use, we would not enable this by default. AWS also documents an SCP that blocks aws_review organization-wide.
MCP servers. Every MCP server you connect is a data flow of its own. LibreChat lets admins control who may use, create and share MCP servers via permission flags. Restrict CREATE to admins at launch.
When should you buy Claude Team or Enterprise instead?
Buy Claude Team or Enterprise when you need Claude’s own features, such as Claude Code, Projects and the desktop apps, more than EU processing, and when nobody in house wants to run a web application. Self-host when EU residency is mandatory or when you want token billing instead of seats.
According to claude.com/pricing, Team standard seats cost $20 per month billed annually or $25 billed monthly, for 2 to 150 people, with SSO and no training on your content by default. Enterprise costs $20 per seat plus usage at API rates and adds SCIM, audit logs, fine-grained roles and custom data retention. The pricing page mentions US-only inference at 1.1x, not an EU option. Our Claude Enterprise vs Bedrock comparison walks through the contract side.
The self-hosted platform bills per token. Sonnet 5.5 is listed at $2 per million input tokens and $10 per million output tokens on the Claude API; Bedrock bills through AWS Marketplace, and the EU profile adds 10%. An illustrative user who sends 2 million input and 0.4 million output tokens a month (our assumption, not a benchmark) costs about $8.80 on that basis. Light users cost cents, heavy users with long documents can exceed a seat. The infrastructure and the people who run it come on top, which is the subject of the next section.
Run it yourself or outsource?
Running the platform in house needs four roles: someone who patches containers and databases, an identity admin for Entra roles, an AWS admin for IAM, quotas and costs, and first-line support for users. Outsource when none of these exist with an on-call rota. Keep it in house when you already run containers on AWS.
The recurring work is concrete. Open WebUI shipped 31 releases between January and October 2026, LibreChat seven numbered releases plus release candidates. Each one needs a changelog review, a staging test and a rollout, and security fixes cannot wait for the next maintenance window. New models arrive just as fast: Opus 5.5 and Sonnet 5.5 reached Bedrock six days apart in September 2026, and each needs an entry in the model list and a decision on whether it replaces the default. Add backups and restore tests for MongoDB and pgvector, cost alerts in AWS, and user questions such as “why can’t I upload a 40 MB PDF?”. As our estimate for a few hundred users, this is a part-time job for one engineer plus support capacity, not a project that ends at go-live.
Outsourcing to a managed service provider makes sense when you need defined uptime and nobody in house can be woken at night, or when the platform must serve several subsidiaries with separate tenants. It makes less sense for a pilot with 30 users, or if the provider wants to host the platform in its own cloud account instead of yours.
What to demand from a provider for this platform:
- SLA for UI availability and a written patch window for security releases of the chat UI, the RAG API and the databases.
- DPA under Art. 28 GDPR that names the chat history as processed data, with retention and deletion periods.
- Subprocessor list that includes the hosting region, the AWS account owner, and any monitoring or ticketing tools that see prompts.
- Access model: who can read conversations in the database, how admin access is logged, and whether break-glass access needs your approval.
- Exit: deployment as code in your AWS account, export of users, conversations and configuration, and no proprietary fork of the UI.
We would insist on point 5. A platform that runs in your account with your IAM role can change operators without migrating data. One that runs in the provider’s account cannot.
FAQ
What does an internal AI platform with Claude cost per user?
Token costs depend on usage. Sonnet 5.5 is listed at $2 input and $10 output per million tokens, plus 10% for the Bedrock EU profile. An illustrative user with 2 million input and 0.4 million output tokens per month costs about $8.80. Hosting, databases and operating staff come on top.
LibreChat vs Open WebUI: which is better for Claude on Bedrock?
LibreChat. It has a native Bedrock endpoint and an MIT license. Open WebUI needs an OpenAI-compatible proxy such as LiteLLM, because Bedrock does not offer Chat Completions for Sonnet 5.5 or Opus 5.5, and its license restricts rebranding above 50 users.
Does Open WebUI work with Claude on Bedrock at all?
Yes, through a proxy. Its documentation lists LiteLLM, stdapi.ai and the Bedrock Access Gateway. The Bedrock Access Gateway repository is archived, so LiteLLM is the maintained choice. Bedrock Mantle’s Chat Completions route does not cover Claude 5.5 models.
Which Bedrock model ID keeps Claude in the EU?
Use the EU geo profile, for example eu.anthropic.claude-sonnet-5-5 or eu.anthropic.claude-opus-5-5. AWS states that EU geo keeps data within EU regions. The global. IDs in LibreChat’s example configuration route worldwide.
Can we use Entra ID groups to control access?
Yes. LibreChat reads app roles from the ID token with OPENID_REQUIRED_ROLE and maps admins with OPENID_ADMIN_ROLE. Open WebUI syncs groups through ENABLE_OAUTH_GROUP_MANAGEMENT and supports SCIM 2.0, but its Microsoft login is limited to a single tenant.
Is Claude Team simpler than self-hosting?
Yes. Team includes SSO, the apps and Claude Code for $20 to $25 per seat per month, with no infrastructure to run. The trade-off is data location: Anthropic says Claude app data is stored in the US, and there is no EU option on the pricing page.
Sources
- LibreChat on GitHub (MIT license, releases) (1 October 2026)
- LibreChat v0.8.8 release notes (1 October 2026)
- LibreChat docs: AWS Bedrock (1 October 2026)
- LibreChat docs: Entra ID OpenID (1 October 2026)
- LibreChat docs: MCP (1 October 2026)
- LibreChat .env.example (1 October 2026)
- LibreChat docker-compose.yml (1 October 2026)
- LibreChat RAG API README (1 October 2026)
- Open WebUI on GitHub (license, releases) (1 October 2026)
- Open WebUI License (1 October 2026)
- Open WebUI docs: OpenAI-compatible providers incl. Bedrock (1 October 2026)
- Open WebUI docs: SSO (1 October 2026)
- Open WebUI docs: MCP (1 October 2026)
- AWS Bedrock Access Gateway (archived) (1 October 2026)
- AWS: Claude Sonnet 5.5 model card (1 October 2026)
- AWS: Claude Opus 5.5 model card (1 October 2026)
- AWS: Bedrock data protection (1 October 2026)
- AWS: Bedrock data retention (1 October 2026)
- Anthropic: pricing (1 October 2026)
- Claude plans and pricing (1 October 2026)
- Anthropic Privacy Center: server location (1 October 2026)