FREE TOOL

Bedrock Model Finder

Find the Amazon Bedrock models available in an AWS Region, the model or inference profile ID to call, the IAM policy and code for the call, where cross-Region profiles run, lifecycle dates, and what a Bedrock error means.

  • Your data never leaves your browser: everything is calculated by JavaScript on this page, not on a server.
  • Nothing you enter is uploaded, processed on a server or stored. Check it in your browser's developer tools (Network tab).
  • Once the page has loaded, the tool works without an internet connection.

Region

The Region your application calls Amazon Bedrock in. With a Region chosen, Call next to an ID gives its IAM policy and code.

Model

A model name, provider or ID, or a model or inference profile ARN. Leave it empty to list every model.

See models ↓
Choosing services and Regions for a workload is a core AWS Solutions Architect Associate topicTry free SAA-C03 practice questions with answers and explanations.SAA-C03 questions →

Model IDs and inference profiles

Every call to Amazon Bedrock names the model in its modelId. That can be the model ID itself or the ID of an inference profile for it, and which of them works depends on the Region you call from:

OptionIDWhere the request runs
In-Regionanthropic.claude-3-haiku-20240307-v1:0Only in the Region you call.
Geo cross-Regionus., eu., apac., jp., au. + model IDIn any Region of that geography - data stays within it.
Global cross-Regionglobal. + model IDIn any commercial Region worldwide.

Many newer models have no In-Region option at all: called by their bare model ID they fail, and only an inference profile ID works. A Geo profile is also tied to its geography - eu. works only when you call from a European Region. The finder lists, for the Region you choose, exactly the IDs that work there.

bedrock-runtime and bedrock-mantle

Most models are called through the bedrock-runtime endpoint with InvokeModel or Converse. Some are also, or only, served by bedrock-mantle, which offers OpenAI- and Anthropic-compatible APIs at https://bedrock-mantle.<region>.api.aws. The finder marks models found through bedrock-mantle; their Regions and IDs can differ from the same model's on bedrock-runtime.

IAM policy and code for a call

Choose a Region and select Call next to an ID: the finder writes the IAM policy the call needs and the call from the AWS CLI and Python (boto3). Converse and InvokeModel both need bedrock:InvokeModel; what the policy has to allow it on depends on the ID:

IDThe policy allows
Model IDThe foundation model in your Region: arn:aws:bedrock:<region>::foundation-model/<model ID>.
Geo profile The inference profile in your Region, and the foundation model in your Region and in every Region the profile routes to - only through that profile, with a bedrock:InferenceProfileArn condition.
Global profile The inference profile and the foundation model in your Region, with aws:RequestedRegion set to it, and the Region-less arn:aws:bedrock:::foundation-model/<model ID> that stands for all other Regions, with aws:RequestedRegion set to unspecified - the model again only through the profile.

A model that supports Converse gets a Converse call, which takes the same messages for every model. The others get InvokeModel, whose request body is different for each model - its model card has an example. Models served only through bedrock-mantle, asynchronous or bidirectional streaming APIs get no generated call; their model card shows how to call them.

Cross-Region inference: where a profile runs a call

A Geo or Global inference profile runs each call in one of its destination Regions, chosen by Amazon Bedrock. With a Region chosen, the finder lists them under each profile ID as the model card gives them - some newer cards do not list them, and then Call gives the get-inference-profile command that does. The destinations decide what your IAM policies and service control policies (SCPs) must allow:

RuleGeo profileGlobal profile
Destination RegionsRegions of one geography, which can differ by the Region you call from. A Geo profile's list never changes.Commercial Regions worldwide. AWS adds Regions to the list over time.
IAM policyThe model in your Region and every destination Region, through the profile.The model in your Region and the Region-less model, through the profile.
Region-deny SCP must allowYour Region and every destination Region.Your Region and "aws:RequestedRegion": "unspecified".
PriceThe price of the Region you call from.About 10% less than Geo, also priced by the Region you call from.

Other rules that affect a cross-Region call:

  • Bedrock authorizes a profile call against the inference profile in your Region, the model in your Region, and the model in each candidate destination - for a Global profile the Region-less model, with aws:RequestedRegion set to unspecified. An SCP that blocks any destination Region fails the call, even if the other Regions are allowed.
  • Instead of allowing the destination Regions, a Region-deny SCP can exempt cross-Region routing with a bedrock:InferenceProfileArn condition, best limited to specific profiles. The exemption cannot lift the restriction on the Region you call from: that check, on the profile itself, carries your Region and no bedrock:InferenceProfileArn.
  • A destination can be an opt-in Region your account has not enabled; calls are routed there anyway.
  • Prompts and results can be processed in a destination Region, and stored there when the model stores data for abuse detection. Geo profiles keep that within their geography; choose Geo or In-Region when data residency matters.
  • CloudTrail and CloudWatch record the call in your Region; CloudTrail's additionalEventData.inferenceRegion field shows the Region that processed it.
  • Cross-Region calls have quotas of their own per model ("Cross-region model inference tokens per minute for <model>", and "Global cross-Region ..." for Global profiles); a Global profile's are raised in Service Quotas in the Region you call from.
  • Inference profiles do not support Provisioned Throughput.

To stop Global cross-Region inference across an organization, AWS gives this SCP statement:

{
    "Effect": "Deny",
    "Action": "bedrock:*",
    "Resource": "*",
    "Condition": {
        "StringEquals": {
            "aws:RequestedRegion": "unspecified"
        },
        "ArnLike": {
            "bedrock:InferenceProfileArn": "arn:aws:bedrock:*:*:inference-profile/global.*"
        }
    }
}

Model lifecycle: Active, Legacy and EOL

Every model on Amazon Bedrock is in one of three states, and the finder shows each model's state in the Region you choose, with its dates:

StateWhat it means
Active Available to everyone. The model card gives the date before which the model will not reach EOL, and the Legacy period - the notice you get before EOL.
Legacy Scheduled for retirement on its EOL date. Existing users can keep calling it, but new customers cannot start, and existing ones may lose access after 15 days without using it. No new Provisioned Throughput or fine-tuning jobs.
EOL Past its EOL date: the model is removed from every Region and requests to it fail, unless you have a private arrangement with the provider.

Which rules apply depends on when the model launched on Bedrock:

  • Launched before September 7, 2026: at least 12 months on Bedrock before EOL, and at least 6 months in Legacy. For models with an EOL date after February 1, 2026, the second half of the Legacy period is public extended access, in which the provider can charge more. The dates can differ by Region.
  • Launched on or after September 7, 2026: each model card gives an "EOL no sooner than" date and a Legacy period of 6 months or 45 days; the EOL date is added to the card when the model becomes Legacy.
  • Only the dates AWS publishes for Bedrock apply there; the model provider's own retirement dates can differ.
  • Migration never happens automatically: change the model ID in your application before the EOL date. AWS does not name a successor for a Legacy model - search for the provider above to see its Active models.

In your account, aws bedrock get-foundation-model --model-identifier <model ID> --query modelDetails.modelLifecycle shows a model's state in a Region.

Bedrock error messages

Choose Paste an error and paste the message from the AWS CLI, an SDK or the console: the finder explains the errors below, lists their causes in the order worth checking, and looks up the model the error names. Each diagnosis follows the Amazon Bedrock documentation linked under References.

ErrorWhat it means
Invocation of model ID ... with on-demand throughput isn't supportedThe call names the model by its bare model ID, but in this Region bedrock-runtime serves the model only through an inference profile - many newer models have no In-Region option.
The provided model identifier is invalidBedrock does not know the model ID or inference profile ID in the Region the request went to.
Model use case details have not been submitted for this accountAnthropic requires use case details once per account, or once in the organization's management account, before its models can be called on bedrock-runtime.
Not authorized to perform the required AWS Marketplace actionsThe first call of a model sold through AWS Marketplace subscribes the account to it, and the identity making that call is not allowed to.
Your AWS Marketplace subscription for this model is still being processedThe account's AWS Marketplace subscription to the model, started by its first call, has not finished.
You don't have access to the model with the specified model IDThe account is not enabled for this model, or has lost access to it.
This Model is marked by provider as LegacyThe model is scheduled for retirement. In the Legacy state new customers cannot use it and accounts that stop calling it lose access; after its end-of-life (EOL) date every call fails.
User ... is not authorized to perform: bedrock:InvokeModelIAM denied the call. The message names the identity, the action and the resource, and usually the kind of policy that denied it.
Access to Anthropic models is not allowed from unsupported countries, regions, or territoriesAnthropic serves only some countries and regions, and the request or the account is tied to one it does not.
ThrottlingException: Too many requests / Too many tokensThe account's quota for the model in this Region is used up: requests per minute, tokens per minute, or tokens per day. It is a quota, not Bedrock's capacity.
ServiceUnavailableException / overloaded_errorBedrock or the model has no capacity for the request right now (503, 529) or failed on its side (500). Unlike a ThrottlingException (429), it is not your quota.
Malformed input requestThe InvokeModel request body is not in the format of the model it went to: each model family takes a body of its own.
Read timeout on endpoint URL / connection resetThe client stopped waiting for the answer: the model took longer than the SDK's read timeout, or the network dropped a connection that sat idle.

Frequently asked questions

Why do I get AccessDeniedException when calling an inference profile?

Allowing the inference profile is not enough: the request is also authorized against the foundation model in your Region and in the Region it is routed to. Allow those too, as the generated policy does. If your organization blocks Regions with a service control policy, it must also allow the profile's destination Regions, and for a Global profile "aws:RequestedRegion": "unspecified".

Why does Bedrock say my model is not supported for on-demand throughput?

The model has no In-Region option in that Region, so its bare model ID cannot be called on demand. Call it with an inference profile ID instead - choose the Region above and copy a Geo or Global ID, or paste the error and find the model's IDs from there.

Which Region should I use for a model?

The one your application runs in, if the model is available there - through any of the three options. With a cross-Region profile the request can run in another Region, so check the data residency the profile gives against your requirements before choosing Global.

Does a model's Region list change?

Often. AWS adds models and Regions every few weeks, and retires old models. This page reads AWS's model cards each time it is published; the date above the results says when.

Is anything I type sent anywhere?

No. The model list and the known errors are part of the page, and the search, the generated calls and the error diagnosis are made in your browser. The page counts only which Region was chosen, which kind of ID was copied or opened a call for, and which error was recognized - never what was searched for or pasted, or your account ID.

References

Amazon Bedrock models at a glance
Regional availability by models
Supported Regions and models for inference profiles
Cross-Region inference
Geographic cross-Region inference: IAM policy requirements
Global cross-Region inference: IAM policy requirements
AWS CLI: get-inference-profile
Prerequisites for running model inference
Troubleshooting Amazon Bedrock API error codes
Request access to models
Model lifecycle
Model lifecycle (Legacy): models launched before September 7, 2026
How tokens are counted in Amazon Bedrock
Troubleshoot access denied error messages