Skip to content

Connect Amazon Bedrock to OpenClaw: AWS Setup Guide

Managing multiple AI models can get messy fast, especially when you are dealing with different authentication methods and API keys. If you are already running your infrastructure on AWS, you probably want a way to use Amazon Bedrock without adding more complexity to your setup.

OpenClaw makes this easy by using the Bedrock Converse streaming provider. Instead of hunting for API keys, it uses the standard AWS SDK credential chain you already know.

OpenClaw works with the following setup for Bedrock:

  • Provider: amazon-bedrock
  • API: bedrock-converse-stream
  • Auth: AWS credentials (env vars, shared config, or instance role)
  • Region: AWS_REGION or AWS_DEFAULT_REGION (default: us-east-1)

You don’t have to manually list every model you want to use. If OpenClaw detects AWS credentials, it can find Bedrock models that support streaming and text output on its own. It uses bedrock:ListFoundationModels and caches the results for an hour by default.

You can tweak these settings in your config under models.bedrockDiscovery:

{
models: {
bedrockDiscovery: {
enabled: true,
region: "us-east-1",
providerFilter: ["anthropic", "amazon"],
refreshInterval: 3600,
defaultContextWindow: 32000,
defaultMaxTokens: 4096,
},
},
}

A few things to keep in mind:

  • enabled is true automatically if AWS credentials exist.
  • region looks at your environment variables first, then defaults to us-east-1.
  • providerFilter lets you pick specific providers like anthropic.
  • refreshInterval is in seconds; use 0 to stop caching.
  • defaultContextWindow and defaultMaxTokens are fallbacks for discovered models.

First, make sure your AWS credentials are ready on your gateway host:

Terminal window
export AWS_ACCESS_KEY_ID="AKIA..."
export AWS_SECRET_ACCESS_KEY="..."
export AWS_REGION="us-east-1"
# Optional:
export AWS_SESSION_TOKEN="..."
export AWS_PROFILE="your-profile"
# Optional (Bedrock API key/bearer token):
export AWS_BEARER_TOKEN_BEDROCK="..."

Next, add the Bedrock provider and your chosen model to your configuration. You’ll notice that no apiKey is needed here:

{
models: {
providers: {
"amazon-bedrock": {
baseUrl: "https://bedrock-runtime.us-east-1.amazonaws.com",
api: "bedrock-converse-stream",
auth: "aws-sdk",
models: [
{
id: "us.anthropic.claude-opus-4-6-v1:0",
name: "Claude Opus 4.6 (Bedrock)",
reasoning: true,
input: ["text", "image"],
cost: { input: 0, output: 0, cacheRead: 0, cacheWrite: 0 },
contextWindow: 200000,
maxTokens: 8192,
},
],
},
},
},
agents: {
defaults: {
model: { primary: "amazon-bedrock/us.anthropic.claude-opus-4-6-v1:0" },
},
},
}

If you run OpenClaw on an EC2 instance with an IAM role, the AWS SDK usually handles authentication via the instance metadata service (IMDS). Right now, OpenClaw’s detection logic specifically looks for environment variables.

To fix this, set AWS_PROFILE=default. This tells OpenClaw that credentials are available, and the SDK will then pull them from IMDS.

Terminal window
# Add to ~/.bashrc or your shell profile
export AWS_PROFILE=default
export AWS_REGION=us-east-1

Your EC2 instance role needs these IAM permissions:

  • bedrock:InvokeModel
  • bedrock:InvokeModelWithResponseStream
  • bedrock:ListFoundationModels (for discovery)

You can also just attach the AmazonBedrockFullAccess managed policy.

Here is a quick way to get everything running using the AWS CLI:

Terminal window
# 1. Create IAM role and instance profile
aws iam create-role --role-name EC2-Bedrock-Access \
--assume-role-policy-document '{
"Version": "2012-10-17",
"Statement": [{
"Effect": "Allow",
"Principal": {"Service": "ec2.amazonaws.com"},
"Action": "sts:AssumeRole"
}]
}'
aws iam attach-role-policy --role-name EC2-Bedrock-Access \
--policy-arn arn:aws:iam::aws:policy/AmazonBedrockFullAccess
aws iam create-instance-profile --instance-profile-name EC2-Bedrock-Access
aws iam add-role-to-instance-profile \
--instance-profile-name EC2-Bedrock-Access \
--role-name EC2-Bedrock-Access
# 2. Attach to your EC2 instance
aws ec2 associate-iam-instance-profile \
--instance-id i-xxxxx \
--iam-instance-profile Name=EC2-Bedrock-Access
# 3. On the EC2 instance, enable discovery
openclaw config set models.bedrockDiscovery.enabled true
openclaw config set models.bedrockDiscovery.region us-east-1
# 4. Set the workaround env vars
echo 'export AWS_PROFILE=default' >> ~/.bashrc
echo 'export AWS_REGION=us-east-1' >> ~/.bashrc
source ~/.bashrc
# 5. Verify models are discovered
openclaw models list
  • You must enable model access in your AWS console for the specific region you are using.
  • Automatic discovery won’t work without the bedrock:ListFoundationModels permission.
  • If you use named profiles, remember to set AWS_PROFILE on your host.
  • OpenClaw checks for credentials in this order: AWS_BEARER_TOKEN_BEDROCK, then access keys, then AWS_PROFILE, and finally the default SDK chain.
  • Reasoning capabilities depend on the specific model you choose.
  • If you prefer using a managed key, you can put an OpenAI-compatible proxy in front of Bedrock and configure it that way.

To keep your AI interactions safe, you can use Amazon Bedrock Guardrails. These allow you to filter content, deny specific topics, or handle sensitive information. You can add them to your amazon-bedrock plugin config:

{
plugins: {
entries: {
"amazon-bedrock": {
config: {
guardrail: {
guardrailIdentifier: "abc123", // guardrail ID or full ARN
guardrailVersion: "1", // version number or "DRAFT"
streamProcessingMode: "sync", // optional: "sync" or "async"
trace: "enabled", // optional: "enabled", "disabled", or "enabled_full"
},
},
},
},
},
}
  • guardrailIdentifier is required (use the ID or the full ARN).
  • guardrailVersion is required (use a version number or "DRAFT").
  • streamProcessingMode lets you choose between "sync" or "async" evaluation.
  • trace helps with debugging by showing guardrail output in the response.

Make sure your IAM principal has the bedrock:ApplyGuardrail permission enabled.

Need help getting started? Check out the AI Setup Assistant.

OpenClaw

OpenClaw Expert

Still stuck?

If this page didn't answer your case, ask OpenClaw Expert for step-by-step guidance.