> ## Documentation Index
> Fetch the complete documentation index at: https://docs.guild.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# AWS Bedrock

> Run Claude, GPT, gpt-oss, DeepSeek, Qwen, Kimi, and GLM models in Guild through your own AWS Bedrock account, authenticated with an IAM role.

AWS Bedrock is a third-party inference provider. It serves models from several publishers through your own AWS account. Guild never stores long-lived AWS keys: it assumes an IAM role you create, and AWS bills the calls to your account.

| | |
| - | - |
| **Inference provider** in the app | AWS Bedrock |
| Authentication | An IAM role that Guild assumes, matched by an external ID |
| Model IDs | Mapped from canonical names for you |

## Publishers on Bedrock

Guild routes six publishers through Bedrock. Models marked with a region list are only in those regions. The rest are in all four [supported regions](#regions-and-model-ids).

| Publisher | Models | Page |
| - | - | - |
| Anthropic | `claude-opus-5-5`, `claude-opus-5`, `claude-sonnet-5-5`, `claude-sonnet-5`, `claude-sonnet-4-6`, `claude-sonnet-4-5`, `claude-haiku-4-5`, `claude-fable-5-1`, `claude-fable-5`, `claude-opus-4-8`, `claude-opus-4-7`, `claude-opus-4-6`, `claude-opus-4-5` | [Anthropic](/platform/models/anthropic) |
| OpenAI | `gpt-6.1-sol`, `gpt-6-sol`, `gpt-6-luna`, `gpt-6-astra`, `gpt-5.6-sol`, `gpt-5.6-terra`, `gpt-5.6-luna`, `gpt-5.5`, `gpt-5.4`. Open-weight, not in `us-west-1`: `gpt-oss-120b`, `gpt-oss-20b`, `gpt-oss-safeguard-120b`, `gpt-oss-safeguard-20b` | [OpenAI](/platform/models/openai) |
| DeepSeek | `deepseek-v3.2`, `deepseek-r1` (not in `us-west-1`). `deepseek-v3` (`us-east-2`, `us-west-2`) | [DeepSeek](/platform/models/deepseek) |
| Alibaba | `qwen3-next-80b-a3b`, `qwen3-32b`, `qwen3-coder-30b-a3b`, `qwen3-vl-235b-a22b` (not in `us-west-1`). `qwen3-coder-480b-a35b`, `qwen3-235b-a22b-2507` (`us-east-2`, `us-west-2`). `qwen3-coder-next` (`us-east-1`) | [Qwen](/platform/models/qwen) |
| Moonshot AI | `kimi-k3`. `kimi-k2.5`, `kimi-k2-thinking` (not in `us-west-1`) | [Moonshot AI](/platform/models/moonshot) |
| Z.ai | `glm-5.3`. `glm-5`, `glm-4.7`, `glm-4.7-flash` (not in `us-west-1`) | [Z.ai](/platform/models/zai) |

Guild refreshes this list from Bedrock's catalog every day, so it can change. It keeps only models that are active and produce text. Bedrock also lists Llama models, but Guild doesn't route Meta models through Bedrock, and Gemini models aren't on Bedrock.

## Connect Bedrock

<Steps>
  <Step title="Start the credential">Click **Access & setup** in the left nav, then **Models & providers**. Click **Add API key** and choose **AWS Bedrock** from the menu.</Step>
  <Step title="Copy Guild's values">Give the credential a **Name**. Under **Add these to your role**, copy the **Principal** and the **External ID**. Keep the dialog open.</Step>
  <Step title="Create the role in AWS">In your AWS account, create an IAM role that can invoke the Bedrock models you want. Set its trust policy to let the **Principal** assume it, and match the **External ID** with a `StringLike` condition.</Step>
  <Step title="Enter the role and region">Paste the role's ARN, such as `arn:aws:iam::123456789012:role/GuildBedrock`, into **IAM role ARN**. Enter the region to call Bedrock in, such as `us-east-1`, under **AWS region**. Pick a region that has the models you want.</Step>
  <Step title="Choose publishers">Under **Models**, check each publisher this credential should reach, and keep or change each default model. Then click **Add Key**.</Step>
</Steps>

The trust policy looks like this, with the values from the form:

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": { "AWS": "<Principal from the form>" },
      "Action": "sts:AssumeRole",
      "Condition": {
        "StringLike": { "sts:ExternalId": "<External ID from the form>" }
      }
    }
  ]
}
```

The external ID ends in `:*` because Guild appends the credential's ID when it assumes the role. One role can serve every Bedrock credential on the same Guild account.

If the dialog says the deployment has no AWS role configured, Bedrock can't be connected on that deployment yet.

## Regions and model IDs

A Bedrock credential names one region. Guild supports `us-east-1`, `us-east-2`, `us-west-1`, and `us-west-2`. A model that isn't in your credential's region can't be routed through it, so add a credential for another region if you need one. Write canonical model names, such as `claude-sonnet-4-6` or `deepseek-r1`, in policies and `llmPreferences`. Guild maps each one to its Bedrock ID, such as `us.anthropic.claude-sonnet-4-6` or `us.deepseek.r1-v1:0`.

When a model has an inference profile, Guild prefers the profile for your region's geography, `us.`, over a `global.` profile. A global profile can serve a request from another continent, which may break data-residency terms or IAM policies scoped to regional ARNs. Guild uses a global profile only when AWS publishes nothing narrower.

## Audit calls in CloudTrail

Each call Guild makes assumes your role with a session name of `guild-<task-id>`. To trace a Bedrock call back to the Guild task that made it, look for that session name in CloudTrail.

## Related pages

* [Models & providers](/platform/llm-settings) for credentials, model policies, and the daily token limit
* [Fireworks AI](/platform/providers/fireworks) and [OpenRouter](/platform/providers/openrouter), the other third-party providers
