Models & Providers

Amazon Bedrock

Connect models hosted on Amazon Bedrock using your own AWS credentials and region

Overview

Amazon Bedrock gives you a single AWS-hosted API in front of several model families. MagOneAI talks to Bedrock through the Converse API, which means one request and response shape covers every family Bedrock serves:

  • Anthropic Claude
  • Amazon Nova
  • Meta Llama
  • Cohere
  • Mistral
  • AI21

Pick Amazon Bedrock on the provider picker when you add an LLM configuration. It sits in the Cloud & self-hosted group alongside Google Vertex AI and Self Hosted.

Choose Bedrock when your organization already buys models through AWS, when you need model traffic to stay inside an AWS region for compliance reasons, or when you want one AWS bill instead of separate vendor invoices.

How Bedrock differs from the other providers

Bedrock does not use a bearer token and it does not have a fixed HTTPS endpoint. Two things follow from that.

Every other provider takes a single API key. Bedrock takes an AWS credential set, so the LLM configuration panel replaces the API Key field with a dedicated AWS Credentials block:

  • Access key ID (required)
  • Secret access key (required)
  • Session token (optional, for temporary STS credentials)

MagOneAI signs each request with AWS SigV4 using those credentials.

Bedrock is region-scoped. You select an AWS Region on the configuration, and MagOneAI derives the runtime endpoint from it:

bedrock-runtime.{region}.amazonaws.com

The generic Endpoint field is ignored for Bedrock configurations. Do not try to set it.

Setup steps

Request model access in AWS

In the AWS console, open Bedrock and go to Model access. Request access to each model you intend to use, then wait for the status to become Access granted.

Bedrock does not grant model access by default. A model you have not requested will not appear in the MagOneAI model list, even with valid credentials.

Create an IAM user or role with Bedrock permissions

The credentials you give MagOneAI need two Bedrock actions:

ActionUsed for
bedrock:ListFoundationModelsLoading the model list in the configuration panel
bedrock:InvokeModelRunning the model at execution time

Grant them in the region you plan to use. Keep the policy as narrow as your model list allows.

Generate an access key

Create an access key for that IAM identity. Copy the access key ID and the secret access key.

If you use temporary credentials from AWS STS, also copy the session token. Remember that temporary credentials expire, and the configuration stops working when they do.

Add the configuration in MagOneAI

Open LLM configurations for the organization and add a new configuration. Select Amazon Bedrock as the provider.

Fill in the AWS Credentials block and pick the AWS Region. The panel shows (required to load models) next to the credential label until you provide them.

Load the model list and pick a model

With credentials and a region in place, the model picker calls ListFoundationModels for that region and lists the text models available to your account.

Bedrock model IDs look like this:

anthropic.claude-sonnet-4-5-20250929-v1:0
amazon.nova-pro-v1:0
meta.llama3-3-70b-instruct-v1:0

Cross-region inference profiles carry a geography prefix on the same ID, for example us.anthropic.claude-sonnet-4-5-20250929-v1:0.

Declare capabilities and save

Tick Supports Vision or Supports Audio if the model you selected has those capabilities, and fill in Advanced → Cost (USD per 1K tokens) so usage analytics reflect real spend.

Click Save. MagOneAI runs one test call through the full gateway pipeline before it stores the configuration, so a credential or region mistake surfaces immediately rather than on the first workflow run.

Editing an existing Bedrock configuration leaves the credentials in place if you leave the fields empty. The label changes to (leave empty to keep current) in edit mode. Only enter credentials again when you want to rotate them.

Extended thinking

Bedrock exposes extended thinking only for the Anthropic family, through additionalModelRequestFields.thinking. Every other family on Bedrock, including Nova, Llama, Cohere, Mistral and AI21, rejects the field outright.

MagOneAI recognises an Anthropic model by its Bedrock model ID, including any cross-region prefix, and sends the thinking field only to those models. You do not have to configure this per family.

Set Reasoning / thinking on the configuration to match what the model actually does. See Model capabilities for the available modes.

Vision

Bedrock vision models receive images as inline bytes. MagOneAI downloads any image given by URL first, then sends it to Bedrock.

Tick Supports Vision on the configuration for a vision-capable model. If the flag is off, MagOneAI refuses an image request with a clear capability error rather than sending an image the model will reject.

Set Image handling → Max image size (MB) and Advanced → Timeouts → Vision request (sec) on the same configuration. Vision requests are slower than text requests, so the vision timeout defaults to 300 seconds while the text timeout defaults to 120.

Credential storage

The AWS credential set is a structured secret. MagOneAI stores it in HashiCorp Vault as one JSON value and keeps only a Vault reference on the configuration row:

{
  "aws_access_key_id": "...",
  "aws_secret_access_key": "...",
  "aws_session_token": "..."
}

The region is not secret, so it is stored in plain text on the configuration. Only the credential trio goes to Vault. See Secrets management for how Vault-backed secrets are read and rotated.

Cost tracking

Bedrock charges per token, and the rate differs per model family and region. MagOneAI does not read AWS pricing, so fill in Advanced → Cost (USD per 1K tokens) on each Bedrock configuration yourself, for both Input and Output.

With those values set, Bedrock usage appears alongside every other provider in the usage dashboards. See Usage and quotas.

Troubleshooting

Next steps

MagOneAI© 2026 Magure, Inc.

On this page