RMM Labs
Integrations 3 min read 28 September 2026 By Fred

Connect AWS Bedrock to Xcellerate AIG

Put models from your own AWS account, through Amazon Bedrock, behind Xcellerate AIG, with IAM keys and the region of your choice.

Connecting AWS Bedrock to Xcellerate AIG puts models from your own AWS account behind the same gateway as your other providers. AIG signs each request with AWS Signature Version 4 and uses Bedrock's Converse API, so every Bedrock model speaks one format. Your applications keep using AIG's OpenAI-compatible API with a virtual key. This guide is for admins at MSPs, SMEs and service businesses.

TL;DR

  • You need an AWS region, an access key ID and a secret access key.
  • Chat (without streaming) and rerank work through Bedrock.
  • Streaming through Bedrock is not available yet: send streaming clients to another provider with a fallback.

Before you start

  • Access to the models you want, enabled in Bedrock in the chosen AWS region.
  • An IAM credential: Access key ID and Secret access key, plus a session token if you use temporary credentials. It must be allowed to call the Bedrock runtime (Converse) and, for rerank, the Rerank operation of the Bedrock agent runtime. Agree the exact IAM policy with your AWS admin.
  • The AWS region, for example eu-central-1.
  • Outbound HTTPS to bedrock-runtime.<region>.amazonaws.com (and bedrock-agent-runtime.<region>.amazonaws.com for rerank), or a VPC endpoint.
  • The Admin role in AIG, or a custom role with permission to create and edit providers.

Set up AWS Bedrock

1. Create the provider

Go to Connect → Providers and click Connect a provider (or Add provider). Choose the type AWS Bedrock and give it a name, for example "Bedrock Frankfurt". Leave Base URL empty: it is derived from the region. If you use a VPC endpoint, enter it here.

2. Enter the AWS credentials on the key

This type needs no main API key. Fill in these fields on the key; they show their technical names in every language:

  • region
  • access_key_id
  • secret_access_key
  • session_token

The first three are required. Only fill in session_token for temporary credentials.

3. Test and enable

Click Test connection, then Enable provider.

4. Call a model

Put the Bedrock model ID after the provider name, for example <provider-name>/anthropic.claude-3-5-sonnet-…-v1:0. Bedrock model IDs contain dots and colons. If the ID is not in the catalogue, add a pricing override under Cost → Pricing.

5. Rerank

For rerank, the model can be a bare ID; AIG expands it to the foundation-model ARN in your region. A full ARN works too.

What happens after you connect

  • Chat via Converse: system prompt, temperature, top-p, max tokens, stop sequences and tool definitions are translated. Tool calls come back in OpenAI shape. Cached-read input tokens are reported for pricing.
  • Rerank: returns all documents ranked, unless the caller sets top_n.
  • Your data stays in the AWS region you choose.

Good to know

  • Streaming is refused for Bedrock. If a client needs streaming, set up a fallback to another provider.
  • Only chat and rerank are available through Bedrock: no embeddings, images or audio.
  • The provider works with an access key ID and secret access key on the key.
  • Credentials are write-only and never shown again. The secret never appears in error messages.
  • Without a licence, AIG runs in free mode: 5 virtual keys with 5 requests per key per day.

Troubleshooting

  • Bedrock provider '<name>' has no region configured on its key. Fill in region on the key.
  • A credential error can come from a signature computed for the wrong service or host. Check the region and Base URL before you rotate keys.
  • <model> did not answer (<ms> ms): <message> during the test. Check that model access is enabled in that region and that the model ID is right.
  • Streaming is not available through AWS Bedrock on this gateway yet. Retry without "stream": true, or address a fallback that supports it. The client asked for streaming. Retry without streaming, or use a fallback.

Talk to us about AIG

Want to know how AIG brings Bedrock and your other providers under one set of rules? Talk to us about AIG. Read more about every provider in one catalogue and virtual keys.

Frequently asked questions

Does AIG support streaming through Bedrock?
Not yet. Retry without streaming, or send streaming clients to a provider that supports it through a fallback.
Which AWS credentials do I need?
An access key ID and a secret access key, the region, and a session token if you use temporary credentials.
Which Bedrock features can I use through AIG?
Chat through the Converse API, and rerank. Embeddings, images and audio do not go through Bedrock.
Sources: Verified against the Xcellerate AIG source code by the product team on 2026-09-28. Feature pages: https://rmmlabs.io/en/contact; https://rmmlabs.io/en/products/aig/features/providers; https://rmmlabs.io/en/products/aig/features/virtual-keys.

Ready to solve time registration compliance?

Xcellerate OPS covers Belgian 2027 time registration requirements out of the box — no extra module needed.

Related articles