
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@ai-sdk/amazon-bedrock
Advanced tools
The **[Amazon Bedrock provider](https://ai-sdk.dev/providers/ai-sdk-providers/amazon-bedrock)** for the [AI SDK](https://ai-sdk.dev/docs) contains language model support for the Amazon Bedrock [converse API](https://docs.aws.amazon.com/bedrock/latest/APIR
The Amazon Bedrock provider for the AI SDK contains language model support for the Amazon Bedrock converse API.
Deploying to Vercel? With Vercel's AI Gateway you can access Amazon Bedrock (and hundreds of models from other providers) — no additional packages, API keys, or extra cost. Get started with AI Gateway.
The Amazon Bedrock provider is available in the @ai-sdk/amazon-bedrock module. You can install it with
npm i @ai-sdk/amazon-bedrock
You can import the default provider instance bedrock from @ai-sdk/amazon-bedrock:
import { bedrock } from '@ai-sdk/amazon-bedrock';
The Amazon Bedrock provider supports two authentication methods with automatic fallback:
API key authentication provides a simpler setup process compared to traditional AWS SigV4 authentication. You can authenticate using either environment variables or direct configuration.
Set the AWS_BEARER_TOKEN_BEDROCK environment variable with your API key:
export AWS_BEARER_TOKEN_BEDROCK=your-api-key-here
import { bedrock } from '@ai-sdk/amazon-bedrock';
import { generateText } from 'ai';
const { text } = await generateText({
model: bedrock('anthropic.claude-3-haiku-20240307-v1:0'),
prompt: 'Write a vegetarian lasagna recipe for 4 people.',
// API key is automatically loaded from AWS_BEARER_TOKEN_BEDROCK
});
You can also pass the API key directly in the provider configuration:
import { bedrock } from '@ai-sdk/amazon-bedrock';
import { generateText } from 'ai';
const bedrockWithApiKey = bedrock.withSettings({
apiKey: process.env.AWS_BEARER_TOKEN_BEDROCK, // or your API key directly
region: 'us-east-1', // Optional: specify region
});
const { text } = await generateText({
model: bedrockWithApiKey('anthropic.claude-3-haiku-20240307-v1:0'),
prompt: 'Write a vegetarian lasagna recipe for 4 people.',
});
If no API key is provided, the provider automatically falls back to AWS SigV4 authentication using standard AWS credentials:
import { bedrock } from '@ai-sdk/amazon-bedrock';
import { generateText } from 'ai';
// Uses AWS credentials from environment variables or AWS credential chain
const { text } = await generateText({
model: bedrock('anthropic.claude-3-haiku-20240307-v1:0'),
prompt: 'Write a vegetarian lasagna recipe for 4 people.',
});
This method requires standard AWS environment variables:
AWS_ACCESS_KEY_IDAWS_SECRET_ACCESS_KEYAWS_SESSION_TOKEN (optional, for temporary credentials)The provider uses the following authentication precedence:
apiKey in withSettings())AWS_BEARER_TOKEN_BEDROCK)import { bedrock } from '@ai-sdk/amazon-bedrock';
import { generateText } from 'ai';
const { text } = await generateText({
model: bedrock('meta.llama3-8b-instruct-v1:0'),
prompt: 'Write a vegetarian lasagna recipe for 4 people.',
});
Please check out the Amazon Bedrock provider documentation for more information.
FAQs
Unknown package
The npm package @ai-sdk/amazon-bedrock receives a total of 1,931,466 weekly downloads. As such, @ai-sdk/amazon-bedrock popularity was classified as popular.
We found that @ai-sdk/amazon-bedrock demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.