> ## Documentation Index
> Fetch the complete documentation index at: https://docs.springwinter.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Bedrock API: Enable AWS AI Models per Project

> REST endpoints to list and configure which Amazon Bedrock foundation models your Springwinter project is authorized to invoke in your AWS account.

The Bedrock API lets you list and configure which Amazon Bedrock foundation models your project is allowed to call. Springwinter manages the IAM permissions that connect your project's runtime to Bedrock, but you control exactly which model IDs are permitted. Use the GET endpoint to see what is currently configured, and the PUT endpoint to replace the full set of allowed models.

## List Bedrock Models

**GET /api/projects/{project_id}/bedrock**

Return all Amazon Bedrock models available to the project, along with whether each one is currently enabled.

<CodeGroup>
  ```bash Request theme={null}
  curl https://springwinter.dev/api/projects/proj_abc123/bedrock \
    -H "Authorization: Bearer swt_yourtoken"
  ```

  ```json Response theme={null}
  {
    "models": [
      {
        "model_id": "anthropic.claude-3-5-sonnet-20241022-v2:0",
        "name": "Claude 3.5 Sonnet v2",
        "enabled": true
      },
      {
        "model_id": "amazon.titan-text-express-v1",
        "name": "Amazon Titan Text Express",
        "enabled": true
      },
      {
        "model_id": "meta.llama3-8b-instruct-v1:0",
        "name": "Meta Llama 3 8B Instruct",
        "enabled": false
      }
    ]
  }
  ```
</CodeGroup>

<ResponseField name="models" type="array">
  Array of model objects describing each foundation model Springwinter tracks for this project.

  <Expandable title="Model object fields">
    <ResponseField name="model_id" type="string">
      The Amazon Bedrock model identifier, as used in `bedrock:InvokeModel` API calls.
    </ResponseField>

    <ResponseField name="name" type="string">
      Human-readable display name for the model.
    </ResponseField>

    <ResponseField name="enabled" type="boolean">
      Whether your project's IAM policy currently permits invoking this model.
    </ResponseField>
  </Expandable>
</ResponseField>

***

## Save Allowed Models

**PUT /api/projects/{project_id}/bedrock**

Replace the complete set of Bedrock models this project is permitted to invoke. Any model ID not included in the request body will be disabled.

<CodeGroup>
  ```bash Request theme={null}
  curl -X PUT https://springwinter.dev/api/projects/proj_abc123/bedrock \
    -H "Authorization: Bearer swt_yourtoken" \
    -H "Content-Type: application/json" \
    -d '{
      "model_ids": [
        "anthropic.claude-3-5-sonnet-20241022-v2:0",
        "amazon.titan-text-express-v1"
      ]
    }'
  ```

  ```json Response theme={null}
  {
    "models": [
      {
        "model_id": "anthropic.claude-3-5-sonnet-20241022-v2:0",
        "name": "Claude 3.5 Sonnet v2",
        "enabled": true
      },
      {
        "model_id": "amazon.titan-text-express-v1",
        "name": "Amazon Titan Text Express",
        "enabled": true
      }
    ]
  }
  ```
</CodeGroup>

<ParamField body="model_ids" type="array" required>
  An array of Bedrock model ID strings to enable for this project. Pass an empty array (`[]`) to disable all models. The full list of valid model IDs is returned by the GET endpoint.
</ParamField>

<Note>
  Bedrock model access requires the `bedrock:InvokeModel` action to be permitted on the IAM role connected to your AWS account. Springwinter updates the role's inline policy automatically when you call PUT — but if your organization applies Service Control Policies (SCPs) that restrict Bedrock in the account, those take precedence. Verify your SCP configuration in AWS Organizations if model invocations are unexpectedly denied.
</Note>

***

## Calling Bedrock from Your Code

After enabling models through the API, your web servers and workers can call Bedrock using the AWS SDK. Springwinter automatically injects the necessary AWS credentials into your deployed containers.

<CodeGroup>
  ```python Python (boto3) theme={null}
  import boto3
  import json

  client = boto3.client("bedrock-runtime", region_name="us-east-1")

  response = client.invoke_model(
      modelId="anthropic.claude-3-5-sonnet-20241022-v2:0",
      contentType="application/json",
      accept="application/json",
      body=json.dumps({
          "anthropic_version": "bedrock-2023-05-31",
          "max_tokens": 1024,
          "messages": [{"role": "user", "content": "Hello, Claude!"}]
      })
  )
  ```

  ```typescript TypeScript (AWS SDK v3) theme={null}
  import { BedrockRuntimeClient, InvokeModelCommand } from "@aws-sdk/client-bedrock-runtime";

  const client = new BedrockRuntimeClient({ region: "us-east-1" });

  const response = await client.send(new InvokeModelCommand({
    modelId: "anthropic.claude-3-5-sonnet-20241022-v2:0",
    contentType: "application/json",
    accept: "application/json",
    body: JSON.stringify({
      anthropic_version: "bedrock-2023-05-31",
      max_tokens: 1024,
      messages: [{ role: "user", content: "Hello, Claude!" }]
    })
  }));
  ```
</CodeGroup>

<Tip>
  You do not need to configure AWS credentials in your application code. Springwinter passes temporary credentials to your containers automatically, and the AWS SDK picks them up from the environment without any extra setup.
</Tip>
