Connect Amazon Bedrock to OpenClaw: AWS Setup Guide
Managing multiple AI models can get messy fast, especially when you are dealing with different authentication methods and API keys. If you are already running your infrastructure on AWS, you probably want a way to use Amazon Bedrock without adding more complexity to your setup.
OpenClaw makes this easy by using the Bedrock Converse streaming provider. Instead of hunting for API keys, it uses the standard AWS SDK credential chain you already know.
What pi-ai supports
Section titled “What pi-ai supports”OpenClaw works with the following setup for Bedrock:
- Provider:
amazon-bedrock - API:
bedrock-converse-stream - Auth: AWS credentials (env vars, shared config, or instance role)
- Region:
AWS_REGIONorAWS_DEFAULT_REGION(default:us-east-1)
Automatic model discovery
Section titled “Automatic model discovery”You don’t have to manually list every model you want to use. If OpenClaw detects AWS credentials, it can find Bedrock models that support streaming and text output on its own. It uses bedrock:ListFoundationModels and caches the results for an hour by default.
You can tweak these settings in your config under models.bedrockDiscovery:
{ models: { bedrockDiscovery: { enabled: true, region: "us-east-1", providerFilter: ["anthropic", "amazon"], refreshInterval: 3600, defaultContextWindow: 32000, defaultMaxTokens: 4096, }, },}A few things to keep in mind:
enabledistrueautomatically if AWS credentials exist.regionlooks at your environment variables first, then defaults tous-east-1.providerFilterlets you pick specific providers likeanthropic.refreshIntervalis in seconds; use0to stop caching.defaultContextWindowanddefaultMaxTokensare fallbacks for discovered models.
Onboarding
Section titled “Onboarding”First, make sure your AWS credentials are ready on your gateway host:
export AWS_ACCESS_KEY_ID="AKIA..."export AWS_SECRET_ACCESS_KEY="..."export AWS_REGION="us-east-1"# Optional:export AWS_SESSION_TOKEN="..."export AWS_PROFILE="your-profile"# Optional (Bedrock API key/bearer token):export AWS_BEARER_TOKEN_BEDROCK="..."Next, add the Bedrock provider and your chosen model to your configuration. You’ll notice that no apiKey is needed here:
{ models: { providers: { "amazon-bedrock": { baseUrl: "https://bedrock-runtime.us-east-1.amazonaws.com", api: "bedrock-converse-stream", auth: "aws-sdk", models: [ { id: "us.anthropic.claude-opus-4-6-v1:0", name: "Claude Opus 4.6 (Bedrock)", reasoning: true, input: ["text", "image"], cost: { input: 0, output: 0, cacheRead: 0, cacheWrite: 0 }, contextWindow: 200000, maxTokens: 8192, }, ], }, }, }, agents: { defaults: { model: { primary: "amazon-bedrock/us.anthropic.claude-opus-4-6-v1:0" }, }, },}EC2 Instance Roles
Section titled “EC2 Instance Roles”If you run OpenClaw on an EC2 instance with an IAM role, the AWS SDK usually handles authentication via the instance metadata service (IMDS). Right now, OpenClaw’s detection logic specifically looks for environment variables.
To fix this, set AWS_PROFILE=default. This tells OpenClaw that credentials are available, and the SDK will then pull them from IMDS.
# Add to ~/.bashrc or your shell profileexport AWS_PROFILE=defaultexport AWS_REGION=us-east-1Your EC2 instance role needs these IAM permissions:
bedrock:InvokeModelbedrock:InvokeModelWithResponseStreambedrock:ListFoundationModels(for discovery)
You can also just attach the AmazonBedrockFullAccess managed policy.
Quick setup (AWS path)
Section titled “Quick setup (AWS path)”Here is a quick way to get everything running using the AWS CLI:
# 1. Create IAM role and instance profileaws iam create-role --role-name EC2-Bedrock-Access \ --assume-role-policy-document '{ "Version": "2012-10-17", "Statement": [{ "Effect": "Allow", "Principal": {"Service": "ec2.amazonaws.com"}, "Action": "sts:AssumeRole" }] }'
aws iam attach-role-policy --role-name EC2-Bedrock-Access \ --policy-arn arn:aws:iam::aws:policy/AmazonBedrockFullAccess
aws iam create-instance-profile --instance-profile-name EC2-Bedrock-Accessaws iam add-role-to-instance-profile \ --instance-profile-name EC2-Bedrock-Access \ --role-name EC2-Bedrock-Access
# 2. Attach to your EC2 instanceaws ec2 associate-iam-instance-profile \ --instance-id i-xxxxx \ --iam-instance-profile Name=EC2-Bedrock-Access
# 3. On the EC2 instance, enable discoveryopenclaw config set models.bedrockDiscovery.enabled trueopenclaw config set models.bedrockDiscovery.region us-east-1
# 4. Set the workaround env varsecho 'export AWS_PROFILE=default' >> ~/.bashrcecho 'export AWS_REGION=us-east-1' >> ~/.bashrcsource ~/.bashrc
# 5. Verify models are discoveredopenclaw models list- You must enable model access in your AWS console for the specific region you are using.
- Automatic discovery won’t work without the
bedrock:ListFoundationModelspermission. - If you use named profiles, remember to set
AWS_PROFILEon your host. - OpenClaw checks for credentials in this order:
AWS_BEARER_TOKEN_BEDROCK, then access keys, thenAWS_PROFILE, and finally the default SDK chain. - Reasoning capabilities depend on the specific model you choose.
- If you prefer using a managed key, you can put an OpenAI-compatible proxy in front of Bedrock and configure it that way.
Guardrails
Section titled “Guardrails”To keep your AI interactions safe, you can use Amazon Bedrock Guardrails. These allow you to filter content, deny specific topics, or handle sensitive information. You can add them to your amazon-bedrock plugin config:
{ plugins: { entries: { "amazon-bedrock": { config: { guardrail: { guardrailIdentifier: "abc123", // guardrail ID or full ARN guardrailVersion: "1", // version number or "DRAFT" streamProcessingMode: "sync", // optional: "sync" or "async" trace: "enabled", // optional: "enabled", "disabled", or "enabled_full" }, }, }, }, },}guardrailIdentifieris required (use the ID or the full ARN).guardrailVersionis required (use a version number or"DRAFT").streamProcessingModelets you choose between"sync"or"async"evaluation.tracehelps with debugging by showing guardrail output in the response.
Make sure your IAM principal has the bedrock:ApplyGuardrail permission enabled.
Next Steps
Section titled “Next Steps”Need help getting started? Check out the AI Setup Assistant.
OpenClaw Expert
Still stuck?
If this page didn't answer your case, ask OpenClaw Expert for step-by-step guidance.