Skip to main content
AWS Bedrock is a third-party inference provider. It serves models from several publishers through your own AWS account. Guild never stores long-lived AWS keys: it assumes an IAM role you create, and AWS bills the calls to your account.

Publishers on Bedrock

Gemini models aren’t on Bedrock. Guild only lists Bedrock models that are active and produce text, so retired, image, and embedding models don’t appear.

Connect Bedrock

1

Start the credential

Click Access & setup in the left nav, then Models & providers. Click Add API key and choose AWS Bedrock from the menu.
2

Copy Guild's values

Give the credential a Name. Under Add these to your role, copy the Principal and the External ID. Keep the dialog open.
3

Create the role in AWS

In your AWS account, create an IAM role that can invoke the Bedrock models you want. Set its trust policy to let the Principal assume it, and match the External ID with a StringLike condition.
4

Enter the role and region

Paste the role’s ARN, such as arn:aws:iam::123456789012:role/GuildBedrock, into IAM role ARN. Enter the region to call Bedrock in, such as us-east-1, under AWS region.
5

Choose publishers

Under Models, check each publisher this credential should reach, and keep or change each default model. Then click Add Key.
The trust policy looks like this, with the values from the form:
The external ID ends in :* because Guild appends the credential’s ID when it assumes the role. One role can serve every Bedrock credential on the same Guild account. If the dialog says the deployment has no AWS role configured, Bedrock can’t be connected on that deployment yet.

Regions and model IDs

A Bedrock credential names one region, which must be one Guild supports for Bedrock. Write canonical model names, such as claude-sonnet-4-6 or deepseek-r1, in policies and llmPreferences. Guild maps each one to its Bedrock ID. When a model has an inference profile, Guild prefers the profile for your region’s geography, such as us. or eu., over a global. profile. A global profile can serve a request from another continent, which may break data-residency terms or IAM policies scoped to regional ARNs. Guild uses a global profile only when AWS publishes nothing narrower.

Audit calls in CloudTrail

Each call Guild makes assumes your role with a session name of guild-<task-id>. To trace a Bedrock call back to the Guild task that made it, look for that session name in CloudTrail.