Amazon Bedrock
Set up Bedrock with a stored key, AWS environment variables or a profile; how credentials reach agents; and the limits of SSO and instance roles.
Set up
- Worker UI → AI models → Add → advanced kinds →
bedrock. - Set
extra.region. Optionallyextra.profile, andbaseUrlfor a VPC endpoint. - Credentials — one of:
- a key stored for the provider:
ACCESS_KEY_ID:SECRET,ACCESS_KEY_ID:SECRET:SESSION_TOKEN, or JSON; - the
AWS_*environment variables of the worker; - a profile in
~/.aws/credentials(extra.profile, elseAWS_PROFILE, elsedefault).
- a key stored for the provider:
The worker signs health checks with SigV4 and lists models with ListFoundationModels.
How agents get credentials
A stored key is passed to agents as AWS_* variables. Claude Code runs with CLAUDE_CODE_USE_BEDROCK=1.
OpenCode (as amazon-bedrock) and Aider use Bedrock directly too. ~/.aws stays readable inside the OS sandbox,
because Bedrock agents may use it.
SSO and instance roles
With AWS SSO or instance roles, the worker cannot sign a health check itself. The provider is then shown as usable, and problems appear when an agent runs.