Connecting AWS Bedrock to Xcellerate AIG puts models from your own AWS account behind the same gateway as your other providers. AIG signs each request with AWS Signature Version 4 and uses Bedrock's Converse API, so every Bedrock model speaks one format. Your applications keep using AIG's OpenAI-compatible API with a virtual key. This guide is for admins at MSPs, SMEs and service businesses.
TL;DR
- You need an AWS region, an access key ID and a secret access key.
- Chat (without streaming) and rerank work through Bedrock.
- Streaming through Bedrock is not available yet: send streaming clients to another provider with a fallback.
Before you start
- Access to the models you want, enabled in Bedrock in the chosen AWS region.
- An IAM credential: Access key ID and Secret access key, plus a session token if you use temporary credentials. It must be allowed to call the Bedrock runtime (Converse) and, for rerank, the Rerank operation of the Bedrock agent runtime. Agree the exact IAM policy with your AWS admin.
- The AWS region, for example
eu-central-1. - Outbound HTTPS to
bedrock-runtime.<region>.amazonaws.com(andbedrock-agent-runtime.<region>.amazonaws.comfor rerank), or a VPC endpoint. - The Admin role in AIG, or a custom role with permission to create and edit providers.
Set up AWS Bedrock
1. Create the provider
Go to Connect → Providers and click Connect a provider (or Add provider). Choose the type AWS Bedrock and give it a name, for example "Bedrock Frankfurt". Leave Base URL empty: it is derived from the region. If you use a VPC endpoint, enter it here.
2. Enter the AWS credentials on the key
This type needs no main API key. Fill in these fields on the key; they show their technical names in every language:
regionaccess_key_idsecret_access_keysession_token
The first three are required. Only fill in session_token for temporary credentials.
3. Test and enable
Click Test connection, then Enable provider.
4. Call a model
Put the Bedrock model ID after the provider name, for example <provider-name>/anthropic.claude-3-5-sonnet-…-v1:0. Bedrock model IDs contain dots and colons. If the ID is not in the catalogue, add a pricing override under Cost → Pricing.
5. Rerank
For rerank, the model can be a bare ID; AIG expands it to the foundation-model ARN in your region. A full ARN works too.
What happens after you connect
- Chat via Converse: system prompt, temperature, top-p, max tokens, stop sequences and tool definitions are translated. Tool calls come back in OpenAI shape. Cached-read input tokens are reported for pricing.
- Rerank: returns all documents ranked, unless the caller sets
top_n. - Your data stays in the AWS region you choose.
Good to know
- Streaming is refused for Bedrock. If a client needs streaming, set up a fallback to another provider.
- Only chat and rerank are available through Bedrock: no embeddings, images or audio.
- The provider works with an access key ID and secret access key on the key.
- Credentials are write-only and never shown again. The secret never appears in error messages.
- Without a licence, AIG runs in free mode: 5 virtual keys with 5 requests per key per day.
Troubleshooting
Bedrock provider '<name>' has no region configured on its key.Fill inregionon the key.- A credential error can come from a signature computed for the wrong service or host. Check the region and Base URL before you rotate keys.
<model> did not answer (<ms> ms): <message>during the test. Check that model access is enabled in that region and that the model ID is right.Streaming is not available through AWS Bedrock on this gateway yet. Retry without "stream": true, or address a fallback that supports it.The client asked for streaming. Retry without streaming, or use a fallback.
Talk to us about AIG
Want to know how AIG brings Bedrock and your other providers under one set of rules? Talk to us about AIG. Read more about every provider in one catalogue and virtual keys.
