Setting Up Amazon Bedrock
Amazon Bedrock runs AI models inside your own AWS account: Anthropic's Claude, OpenAI's GPT-6 family, and others such as Amazon Nova. Choosing it keeps AI billing with AWS and lets you decide which AWS Region processes your requests, but it asks more of the setup than a single API key.
Where to find it
Architect Panel → Configuration:
- AI Settings — the Amazon Bedrock section, and the roles table
Architect Panel → Activity:
- AI Usage — Test a role, with a hint per error that names the missing AWS permission
The model id decides the route
You do not pick an endpoint for each model: the platform reads it from the model id.
- Claude: an id such as
anthropic.claude-opus-5-5goes to Bedrock's Messages endpoint; a geographic or versioned id, or an ARN, goes to the runtime endpoint. - OpenAI GPT-6: an id such as
global.openai.gpt-6-lunaalways goes to Bedrock's OpenAI endpoint. Documents go to these models as text, without citations. - Any other provider (Nova, Llama, Mistral): always goes in prompt mode, with no citations, and is not priced on AI Usage.
Leave Endpoint on Automatic, from the model id. It only ever decides for an id that is neither OpenAI nor another provider's.
Region and where data is processed
Region blank means the platform's own AWS region. A model id starting eu., us. or another geography is a cross-Region profile: AWS may serve it from any Region in that geography, and the platform refuses one named from a Region outside it before anything is sent. An id starting global. may be processed in any commercial AWS Region. From UK and EU Regions the GPT-6 models are offered only through their global profile, so choosing them is a data-residency decision to make before go-live, not after.
Credentials
The first of these that is set is used:
- Bedrock API key: a bearer key. Works for Claude on the Messages endpoint and for GPT-6, not for the other routes.
- Access key ID and Secret access key (with Session token for temporary credentials).
- Named profile: a profile in the web server user's AWS configuration, set up by your hosting administrator.
- The platform's own AWS keys, unless Use the platform's AWS keys is No.
- The server's environment or instance role, only when Use the AWS default chain is on.
Give AI its own AWS user or role with only the Bedrock permissions it needs, and set Use the platform's AWS keys to No, so the keys that reach your file storage never sign an AI request. With that set to Default it means Yes, except while AI billing is on.
Setting it up
- In the AWS console, enable the model for your account in your chosen Region and note the exact id it takes there.
- Create a dedicated IAM user or role allowed to invoke that model, and its keys if it is a user.
- On AI Settings, in Amazon Bedrock, set Region, the credentials, Use the platform's AWS keys = No, and a Default model. Save.
- Point roles at Amazon Bedrock in the roles table, or make it the
builderprovider. Save. - On AI Usage, test each role. Note the provider request id: it is what AWS support asks for.
Other settings in the section
- Let Bedrock store OpenAI requests: off by default. Bedrock's own default for GPT-6 is to keep input and output for 30 days in whichever Region served them; leaving this off asks it not to.
- Structured outputs (Claude) and Strict tool schemas: off by default, because Bedrock's Claude endpoints do not accept them everywhere. Change them only on advice.
- Price multiplier: scales the cost estimates for every Bedrock model except GPT-6, for a regional premium or a negotiated rate.
- OpenAI reasoning summary: off by default. Run a test call with it on before relying on it; if Bedrock rejects it, switch it off again.
- Mantle address and OpenAI endpoint address: leave blank unless you reach Bedrock through a VPC endpoint.
What goes wrong, and how to tell
- auth: AWS refused the credentials. Check the key pair, session token or profile.
- permission: the credentials are valid but may not call this model in this Region. The test result names the grants needed.
- not_found: the id is wrong for this Region, or the model is not enabled on the account.
- invalid_request naming a geography: the id's prefix is outside the Region's geography. Use the id AWS offers in your Region.
- A "stream ... denied" warning on a real run: long answers are streamed, which needs a further permission the small test call does not use. Grant it, or the call is re-sent without streaming.
Worked example
A UK organisation must keep processing in the UK where it can. Its architect enables Claude in eu-west-2, creates an IAM user allowed only to invoke that model, and enters its keys with Use the platform's AWS keys set to No. The builder provider becomes Amazon Bedrock with the eu. Claude id. GPT-6 is considered and rejected for now, because from London it is offered only through its global profile. Every role is tested on AI Usage before users are told.
Recommendations
- Decide where requests may be processed first, then choose model ids that respect it.
- Use a dedicated, least-privilege AWS principal, never the storage keys.
- Copy model ids from the AWS console for your Region, not from another account's notes.
- Prove GPT-6 on your own account with a test call before any feature depends on it.
- Keep Let Bedrock store OpenAI requests off unless you have a reason to change it.