What each coding tool sends to Amazon Bedrock
Each tool talks to Bedrock its own way, so the settings, the IDs it accepts and the errors differ. Checked against each tool's documentation on 2026-10-02; the models, IDs and Regions come from AWS's model cards as of 2026-10-02.
| Tool | Calls | Credentials | Docs |
|---|---|---|---|
| Claude Code | InvokeModelWithResponseStream on bedrock-runtime (not Converse), or the Anthropic Messages API on bedrock-mantle | AWS profile / SSO, Access keys, Bedrock API key | Claude Code on Amazon Bedrock Claude Code error reference |
| Cline | ConverseStream on bedrock-runtime, through the AI SDK's Amazon Bedrock provider | Bedrock API key, AWS profile / SSO, Access keys | Cline: AWS Bedrock with an API key Cline: AWS Bedrock with a CLI profile (SSO) Cline: AWS Bedrock with IAM credentials |
| Cursor | bedrock-runtime from Cursor's servers, with your credentials or a role Cursor assumes | IAM role Cursor assumes, Access keys | Cursor: AWS Bedrock Cursor: Bring your own API key |
| OpenAI Codex | the OpenAI Responses API Bedrock serves at /openai/v1, on bedrock-runtime (profiles) or bedrock-mantle (in the Region) | Bedrock API key, AWS profile / SSO, Access keys | Use ChatGPT Work and Codex with Amazon Bedrock |
Roo Code is not here: it shut down on May 15, 2026.
Which model ID or inference profile ID to send
Most current models have no on-demand throughput in a Region: they are called through an inference profile, the model ID with a prefix. A Geo profile (us., eu., apac., jp., au.) keeps requests in one geography and works only from its own Regions; a Global profile (global.) routes worldwide. Sending the bare model ID where a profile is needed fails with "on-demand throughput isn't supported"; sending a profile from outside its geography fails with "The provided model identifier is invalid".
- Claude Code takes any ID in
ANTHROPIC_MODELand, unpinned, derives a prefix from the Region (ANTHROPIC_BEDROCK_REGION_PREFIXoverrides it). - Cline adds the prefix itself from two checkboxes, trying
jp.orau.beforeapac.in Tokyo, Osaka, Sydney and Melbourne; any other ID goes in as a custom model ID. - Cursor lists one prefix per team Region (
us.,eu.,apac.orca.) and takes no application inference profiles. - Codex sends a Geo or Global profile on bedrock-runtime and the bare ID on bedrock-mantle.
A least-privilege IAM policy
The policy allows bedrock:InvokeModel and bedrock:InvokeModelWithResponseStream - every tool streams - on exactly the ID chosen: the inference profile and the foundation model in each Region it routes to, only through that profile. A Global profile adds the Region-less model ARN with aws:RequestedRegion "unspecified". Codex's Responses API also needs bedrock:InvokeModel on the account's default project, a Bedrock API key needs CallWithBearerToken, and bedrock-mantle has its own actions on project/default. The first call of a model sold through AWS Marketplace also needs aws-marketplace:Subscribe once per account, and Anthropic models the use case form.
Will the default quotas carry a coding agent?
Bedrock deducts input plus max_tokens from the tokens per minute when a call starts and keeps what the call really used when it ends - with output counted 5 to 15 times for Claude. Agents send a large context on every call and a high output limit, so a few sessions can use up a default quota that looks generous. Cache reads count nothing, which is why prompt caching matters as much for throttling as for cost. The full rules and the 429 diagnosis are in the Bedrock Throttling Calculator.
Errors the tools show
invalid beta flagExtra inputs are not permittedAWS authentication failedAWS credentials expired or invalidCould not load credentials from any providersAWS default-chain credential resolve timed outSession token not found or invalidThe security token included in the request is expiredThe security token included in the request is invalidThe request signature we calculated does not match the signature you providedBedrock streaming response has content-type "..."There's an issue with the selected modelnot supported by bedrockInput is too long for requested modelInvocation of model ID ... with on-demand throughput isn't supportedModel use case details have not been submitted for this accountUser ... is not authorized to perform: bedrock:InvokeModelThrottlingException: Too many requests / Too many tokens
Frequently asked questions
Is anything I enter sent anywhere?
No. The settings and policy are put together in your browser; there is no field for a secret. The page only counts that it was used, with which tool and kind of credentials, and which error it recognized first.
How does this page stay current?
The models, IDs, Regions and quotas are read from AWS's documentation every time the site is built. The tools' settings are checked by hand against the documentation linked above - the date at the top of the result says when.
References
Supported Regions and models for inference profiles
Prerequisites for running model inference
How Amazon Bedrock API keys work
How tokens are counted against Bedrock quotas
Amazon Bedrock endpoints and quotas