FREE TOOL

AI Coding Tools on Bedrock Configurator

Pick a coding tool, your AWS credentials and a model, and get the exact settings, the inference profile ID it must send from your Region, a least-privilege IAM policy, whether the default quotas carry your sessions - or paste the error it shows.

  • Your data never leaves your browser: everything is calculated by JavaScript on this page, not on a server.
  • Nothing you enter is uploaded, processed on a server or stored. Check it in your browser's developer tools (Network tab).
  • Once the page has loaded, the tool works without an internet connection.

Tool and credentials

The coding tool, and how it gets AWS credentials - each tool takes its own set.

Model and Region

Only the models this tool can call from the Region, and only the IDs it can send - the model ID itself, a Geo or a Global inference profile.

Agent sessions

An agent makes one model call at a time per session and sends the whole conversation each time, mostly from the prompt cache. Checked against AWS's default quotas.

See the settings ↓
Credentials, IAM policies and calling AWS APIs from code are core AWS Developer Associate topicsTry free DVA-C02 practice questions with answers and explanations.DVA-C02 questions →

What each coding tool sends to Amazon Bedrock

Each tool talks to Bedrock its own way, so the settings, the IDs it accepts and the errors differ. Checked against each tool's documentation on 2026-10-02; the models, IDs and Regions come from AWS's model cards as of 2026-10-02.

ToolCallsCredentialsDocs
Claude CodeInvokeModelWithResponseStream on bedrock-runtime (not Converse), or the Anthropic Messages API on bedrock-mantleAWS profile / SSO, Access keys, Bedrock API keyClaude Code on Amazon Bedrock
Claude Code error reference
ClineConverseStream on bedrock-runtime, through the AI SDK's Amazon Bedrock providerBedrock API key, AWS profile / SSO, Access keysCline: AWS Bedrock with an API key
Cline: AWS Bedrock with a CLI profile (SSO)
Cline: AWS Bedrock with IAM credentials
Cursorbedrock-runtime from Cursor's servers, with your credentials or a role Cursor assumesIAM role Cursor assumes, Access keysCursor: AWS Bedrock
Cursor: Bring your own API key
OpenAI Codexthe OpenAI Responses API Bedrock serves at /openai/v1, on bedrock-runtime (profiles) or bedrock-mantle (in the Region)Bedrock API key, AWS profile / SSO, Access keysUse ChatGPT Work and Codex with Amazon Bedrock

Roo Code is not here: it shut down on May 15, 2026.

Which model ID or inference profile ID to send

Most current models have no on-demand throughput in a Region: they are called through an inference profile, the model ID with a prefix. A Geo profile (us., eu., apac., jp., au.) keeps requests in one geography and works only from its own Regions; a Global profile (global.) routes worldwide. Sending the bare model ID where a profile is needed fails with "on-demand throughput isn't supported"; sending a profile from outside its geography fails with "The provided model identifier is invalid".

  • Claude Code takes any ID in ANTHROPIC_MODEL and, unpinned, derives a prefix from the Region (ANTHROPIC_BEDROCK_REGION_PREFIX overrides it).
  • Cline adds the prefix itself from two checkboxes, trying jp. or au. before apac. in Tokyo, Osaka, Sydney and Melbourne; any other ID goes in as a custom model ID.
  • Cursor lists one prefix per team Region (us., eu., apac. or ca.) and takes no application inference profiles.
  • Codex sends a Geo or Global profile on bedrock-runtime and the bare ID on bedrock-mantle.

A least-privilege IAM policy

The policy allows bedrock:InvokeModel and bedrock:InvokeModelWithResponseStream - every tool streams - on exactly the ID chosen: the inference profile and the foundation model in each Region it routes to, only through that profile. A Global profile adds the Region-less model ARN with aws:RequestedRegion "unspecified". Codex's Responses API also needs bedrock:InvokeModel on the account's default project, a Bedrock API key needs CallWithBearerToken, and bedrock-mantle has its own actions on project/default. The first call of a model sold through AWS Marketplace also needs aws-marketplace:Subscribe once per account, and Anthropic models the use case form.

Will the default quotas carry a coding agent?

Bedrock deducts input plus max_tokens from the tokens per minute when a call starts and keeps what the call really used when it ends - with output counted 5 to 15 times for Claude. Agents send a large context on every call and a high output limit, so a few sessions can use up a default quota that looks generous. Cache reads count nothing, which is why prompt caching matters as much for throttling as for cost. The full rules and the 429 diagnosis are in the Bedrock Throttling Calculator.

Errors the tools show

  • invalid beta flag
  • Extra inputs are not permitted
  • AWS authentication failed
  • AWS credentials expired or invalid
  • Could not load credentials from any providers
  • AWS default-chain credential resolve timed out
  • Session token not found or invalid
  • The security token included in the request is expired
  • The security token included in the request is invalid
  • The request signature we calculated does not match the signature you provided
  • Bedrock streaming response has content-type "..."
  • There's an issue with the selected model
  • not supported by bedrock
  • Input is too long for requested model
  • Invocation of model ID ... with on-demand throughput isn't supported
  • Model use case details have not been submitted for this account
  • User ... is not authorized to perform: bedrock:InvokeModel
  • ThrottlingException: Too many requests / Too many tokens

Frequently asked questions

Is anything I enter sent anywhere?

No. The settings and policy are put together in your browser; there is no field for a secret. The page only counts that it was used, with which tool and kind of credentials, and which error it recognized first.

How does this page stay current?

The models, IDs, Regions and quotas are read from AWS's documentation every time the site is built. The tools' settings are checked by hand against the documentation linked above - the date at the top of the result says when.

References

Supported Regions and models for inference profiles
Prerequisites for running model inference
How Amazon Bedrock API keys work
How tokens are counted against Bedrock quotas
Amazon Bedrock endpoints and quotas