Skip to main content
An Amazon Bedrock Provider Key lets FireRouter use an IAM role or API key from your AWS account for supported models. Fireworks stores the credential securely. Bedrock usage and charges remain in your AWS account. Bedrock uses the same account-admin workflow as Anthropic and OpenAI, but each model also needs a Bedrock model ID and region. See Provider Keys for shared states, rotation, and security.
Before setup, confirm that your AWS account can invoke every model you plan to add. Some third-party or restricted models require explicit Bedrock model access, a Marketplace agreement, or approval from AWS or the model provider. Anthropic may also require a one-time use-case form.

Supported models

Where each column is used:
  • Model: the name shown in the dashboard model picker. You select it; you never type an ID.
  • Served model ID: the ID in the response model field, such as claude-opus-5-5. Your application still sends a router slug such as firerouter/claude-opus-5-5. firectl uses the served ID as routes[].firerouter_model_id. You do not type it in the dashboard.
  • Bedrock model ID: the AWS identifier. Copy it exactly from AWS. Paste it into each route’s Model ID field, or set routes[].bedrock.model_id. Any geo/global profile or ARN that AWS lists for the model also works, as long as your region can invoke it.
  • Region: the AWS source region. In Fireworks, select it in each route’s Region field, or set routes[].bedrock.aws_region. The supported regions are us-east-1, us-east-2, us-west-1, and us-west-2.

Prepare AWS

In the AWS account that will pay for inference, request or verify access to each model.
  • For Anthropic models, complete the one-time use-case form and Marketplace agreement if AWS requires them.
  • For restricted models, complete any additional AWS or provider approval.
  • Confirm that the account can invoke the selected model or inference profile.
Set sts:ExternalId to your exact Fireworks account ID.
1

Configure the trust policy

In AWS IAM → Roles → Create role, choose Custom trust policy and paste:
Configuring the Fireworks principal ARN and account-specific External ID in an AWS IAM custom trust policy
2

Add Bedrock permissions

In Step 2: Add permissions, select Create inline policy and paste:
Resource: "*" covers all Bedrock inference targets and the default project. SCPs, permission boundaries, and explicit denies still apply.
Adding an inline Bedrock invocation policy in the AWS IAM Create role wizard
3

Create the role

In Step 3, name the role FireworksBedrockBYOK or use another name that begins with FireworksBedrock. Use the default IAM path; custom role paths are not supported. Review the trust policy and permissions, then create the role.
Reviewing the FireworksBedrockBYOK role name and trust policy before creating the AWS IAM role
Copy the role ARN from the role summary.
AWS IAM role summary showing the FireworksBedrockBYOK role ARN and inline policy
Set the External ID to your exact Fireworks account ID:
Create the role and trust policy:
Add the Bedrock permission policy:

Connect in the dashboard

1

Connect the key

Open Settings → Provider Keys. On the Amazon Bedrock row, click Connect.Select IAM Role. Keep the External ID exactly as shown, then complete the AWS steps. Paste the IAM role ARN, not the permission policy ARN, and click Continue.
Connecting an Amazon Bedrock IAM role in the Provider Keys dashboard
In Add models to Amazon Bedrock, select the models that should use this credential, then click Connect. You must select at least one.
Selecting models for an Amazon Bedrock Provider Key
The card shows Connecting for about a minute while we finish setup.
2

Fill in the model routes

Connecting stores the credential but does not route any traffic yet. Once the card is connected, the models you picked appear as empty rows that you must complete.
  1. For each row under Models using Bedrock, paste the AWS Model ID and select a Region.
  2. Click Save. Save stays disabled until every row has both values.
Bedrock model rows with Model ID and Region fields after saving an IAM role connection
After saving, each row displays its Model ID and Region. Traffic for those models is now billed to your AWS account. Every other model keeps its current provider.

Change model routes later

Use Add model or the trash icon on a row to add or remove models. Use Edit models to change the Model ID or Region of existing rows. Then click Save. Use Update Key to replace the API key or IAM role ARN without changing the routes. This is the Replace action described in Provider Keys. Use Remove to delete the Bedrock credential and all of its routes.
Amazon Bedrock card menu with Add model, Edit models, Update Key, and Remove

Manage with firectl

Upload the key

Fireworks returns the full role ARN in KEY_HINT for list output and key_hint for JSON. A role ARN is an identifier, not a secret.
Save the returned key ID as KEY_ID. upload only stores the credential; it does not route traffic.

Write the routes file

Create routes.json. Each entry maps one FireRouter model to one Bedrock region and model ID. The file holds only model and region values, not the key.
Rules:
  • Use only the served model IDs in Supported models.
  • Each model appears once and maps to one (aws_region, model_id) target.
  • Copy model_id exactly from AWS; geo/global prefixes and ARNs are significant.

Bind the key and routes

  • Always pass the complete route file. Every bind replaces the whole route set; omitted routes are deleted.
  • Confirm removed routes. If a bind removes routes, firectl asks for confirmation. Pass --yes to skip the prompt.
Confirm both the state and the route list. CONNECTED with empty routes serves no Bedrock traffic. Before the first bind, get returns NOT_FOUND.
Unbind and delete are the same as other providers. See Delete a key.

Troubleshooting

  • AssumeRole is denied (IAM role): check that the trust policy uses the exact Fireworks principal ARN and your Fireworks account ID as sts:ExternalId. The role name must start with FireworksBedrock and use the default IAM path. IAM changes can take a few seconds to apply.
  • InvokeModel is denied: check the role permission policy, SCPs, permission boundaries, model access, and Marketplace or provider approval in the same AWS account.
  • API key is unauthorized or expired: generate a replacement, then upload and bind it. Expiring or revoking a key in AWS does not change the Fireworks state.
  • Model not found: copy the exact model or profile ID from AWS. Never derive it from the served model ID.
  • Region unavailable: confirm the region can invoke that exact inference profile.
  • “This ARN isn’t in the right format.” (dashboard): paste the full IAM role ARN from the role summary page. A permission policy ARN or a role name alone won’t work.
  • “Test failed” on a model row (dashboard): see “Model not found” and “Region unavailable” above. If every model fails, see “AssumeRole is denied.”
  • Save button stays disabled (dashboard): a row is missing its Model ID or Region.
  • A route disappeared (firectl): every bind replaces the whole route set. Include all routes you want to keep.
  • Connected but traffic does not reach Bedrock: confirm the route list is not empty and that requests use a route containing one of the configured served model IDs.