Skip to main content
The Bedrock API lets you list and configure which Amazon Bedrock foundation models your project is allowed to call. Springwinter manages the IAM permissions that connect your project’s runtime to Bedrock, but you control exactly which model IDs are permitted. Use the GET endpoint to see what is currently configured, and the PUT endpoint to replace the full set of allowed models.

List Bedrock Models

GET /api/projects//bedrock Return all Amazon Bedrock models available to the project, along with whether each one is currently enabled.
array
Array of model objects describing each foundation model Springwinter tracks for this project.

Save Allowed Models

PUT /api/projects//bedrock Replace the complete set of Bedrock models this project is permitted to invoke. Any model ID not included in the request body will be disabled.
array
required
An array of Bedrock model ID strings to enable for this project. Pass an empty array ([]) to disable all models. The full list of valid model IDs is returned by the GET endpoint.
Bedrock model access requires the bedrock:InvokeModel action to be permitted on the IAM role connected to your AWS account. Springwinter updates the role’s inline policy automatically when you call PUT — but if your organization applies Service Control Policies (SCPs) that restrict Bedrock in the account, those take precedence. Verify your SCP configuration in AWS Organizations if model invocations are unexpectedly denied.

Calling Bedrock from Your Code

After enabling models through the API, your web servers and workers can call Bedrock using the AWS SDK. Springwinter automatically injects the necessary AWS credentials into your deployed containers.
You do not need to configure AWS credentials in your application code. Springwinter passes temporary credentials to your containers automatically, and the AWS SDK picks them up from the environment without any extra setup.