Amazon Bedrock
Connect models hosted on Amazon Bedrock using your own AWS credentials and region
Overview
Amazon Bedrock gives you a single AWS-hosted API in front of several model families. MagOneAI talks to Bedrock through the Converse API, which means one request and response shape covers every family Bedrock serves:
- Anthropic Claude
- Amazon Nova
- Meta Llama
- Cohere
- Mistral
- AI21
Pick Amazon Bedrock on the provider picker when you add an LLM configuration. It sits in the Cloud & self-hosted group alongside Google Vertex AI and Self Hosted.
Choose Bedrock when your organization already buys models through AWS, when you need model traffic to stay inside an AWS region for compliance reasons, or when you want one AWS bill instead of separate vendor invoices.
How Bedrock differs from the other providers
Bedrock does not use a bearer token and it does not have a fixed HTTPS endpoint. Two things follow from that.
Every other provider takes a single API key. Bedrock takes an AWS credential set, so the LLM configuration panel replaces the API Key field with a dedicated AWS Credentials block:
- Access key ID (required)
- Secret access key (required)
- Session token (optional, for temporary STS credentials)
MagOneAI signs each request with AWS SigV4 using those credentials.
Bedrock is region-scoped. You select an AWS Region on the configuration, and MagOneAI derives the runtime endpoint from it:
bedrock-runtime.{region}.amazonaws.comThe generic Endpoint field is ignored for Bedrock configurations. Do not try to set it.
MagOneAI never falls back to ambient AWS credentials, such as an instance role or profile on the server running the platform. Credentials are always the ones you supplied on the configuration.
This is deliberate. Every provider in MagOneAI is strictly bring-your-own-key and scoped to one organization. Falling back to the deployment's own IAM role would let every organization on the platform share its permissions.
A configuration saved with no credentials fails with AWS credentials required for Bedrock rather than silently using the server's identity.
Setup steps
Request model access in AWS
In the AWS console, open Bedrock and go to Model access. Request access to each model you intend to use, then wait for the status to become Access granted.
Bedrock does not grant model access by default. A model you have not requested will not appear in the MagOneAI model list, even with valid credentials.
Create an IAM user or role with Bedrock permissions
The credentials you give MagOneAI need two Bedrock actions:
| Action | Used for |
|---|---|
bedrock:ListFoundationModels | Loading the model list in the configuration panel |
bedrock:InvokeModel | Running the model at execution time |
Grant them in the region you plan to use. Keep the policy as narrow as your model list allows.
Generate an access key
Create an access key for that IAM identity. Copy the access key ID and the secret access key.
If you use temporary credentials from AWS STS, also copy the session token. Remember that temporary credentials expire, and the configuration stops working when they do.
Add the configuration in MagOneAI
Open LLM configurations for the organization and add a new configuration. Select Amazon Bedrock as the provider.
Fill in the AWS Credentials block and pick the AWS Region. The panel shows (required to load models) next to the credential label until you provide them.
Load the model list and pick a model
With credentials and a region in place, the model picker calls ListFoundationModels for that region and lists the text models available to your account.
Bedrock model IDs look like this:
anthropic.claude-sonnet-4-5-20250929-v1:0
amazon.nova-pro-v1:0
meta.llama3-3-70b-instruct-v1:0Cross-region inference profiles carry a geography prefix on the same ID, for example us.anthropic.claude-sonnet-4-5-20250929-v1:0.
Declare capabilities and save
Tick Supports Vision or Supports Audio if the model you selected has those capabilities, and fill in Advanced → Cost (USD per 1K tokens) so usage analytics reflect real spend.
Click Save. MagOneAI runs one test call through the full gateway pipeline before it stores the configuration, so a credential or region mistake surfaces immediately rather than on the first workflow run.
Editing an existing Bedrock configuration leaves the credentials in place if you leave the fields empty. The label changes to (leave empty to keep current) in edit mode. Only enter credentials again when you want to rotate them.
Extended thinking
Bedrock exposes extended thinking only for the Anthropic family, through additionalModelRequestFields.thinking. Every other family on Bedrock, including Nova, Llama, Cohere, Mistral and AI21, rejects the field outright.
MagOneAI recognises an Anthropic model by its Bedrock model ID, including any cross-region prefix, and sends the thinking field only to those models. You do not have to configure this per family.
Set Reasoning / thinking on the configuration to match what the model actually does. See Model capabilities for the available modes.
Vision
Bedrock vision models receive images as inline bytes. MagOneAI downloads any image given by URL first, then sends it to Bedrock.
Tick Supports Vision on the configuration for a vision-capable model. If the flag is off, MagOneAI refuses an image request with a clear capability error rather than sending an image the model will reject.
Set Image handling → Max image size (MB) and Advanced → Timeouts → Vision request (sec) on the same configuration. Vision requests are slower than text requests, so the vision timeout defaults to 300 seconds while the text timeout defaults to 120.
Credential storage
The AWS credential set is a structured secret. MagOneAI stores it in HashiCorp Vault as one JSON value and keeps only a Vault reference on the configuration row:
{
"aws_access_key_id": "...",
"aws_secret_access_key": "...",
"aws_session_token": "..."
}The region is not secret, so it is stored in plain text on the configuration. Only the credential trio goes to Vault. See Secrets management for how Vault-backed secrets are read and rotated.
Cost tracking
Bedrock charges per token, and the rate differs per model family and region. MagOneAI does not read AWS pricing, so fill in Advanced → Cost (USD per 1K tokens) on each Bedrock configuration yourself, for both Input and Output.
With those values set, Bedrock usage appears alongside every other provider in the usage dashboards. See Usage and quotas.
Troubleshooting
Cause: The configuration has no credentials stored.
Fix: Re-enter the access key ID and secret access key and save. Remember that MagOneAI has no ambient-credential fallback, so an empty credential set is always an error.
Cause: The stored secret is not readable as a credential object. This usually means the Vault secret was edited by hand outside MagOneAI.
Fix: Re-enter the credentials through the configuration panel so MagOneAI writes the secret in the shape it expects.
Cause: The configuration has credentials but no region, so there is no runtime endpoint to call.
Fix: Pick an AWS Region on the configuration.
Causes to check, in order:
- The IAM identity is missing
bedrock:ListFoundationModels. - You have not requested model access in the Bedrock console for this region.
- The models you want are not offered in the region you selected. Model availability differs by region.
- The credentials are for a different AWS account than the one with model access.
Cause: The IAM policy grants ListFoundationModels but not InvokeModel, or it grants InvokeModel only for some model ARNs.
Fix: Add bedrock:InvokeModel for the model you selected.
Cause: You used temporary STS credentials and the session token expired.
Fix: Use a long-lived IAM access key for a configuration that has to keep running, or re-enter fresh temporary credentials before each expiry.
Cause: An entry in Extra parameters is not accepted by this model family. Bedrock families do not accept the same parameter set.
Fix: Remove the parameter, or set it to null so MagOneAI drops the key before the request reaches Bedrock. See Model capabilities.