lmux-aws-bedrock
AWS Bedrock provider for lmux. Talks to the Bedrock Converse and InvokeModel REST endpoints directly over httpx, using boto3 only to resolve AWS credentials for request signing.
Supports chat completions, streaming, and embeddings.
Part of the lmux ecosystem: standardized interface, cost tracking on every response, and registry-based routing across providers.
Optional Extras
lmux-aws-bedrock[async]:aiobotocorefor async AWS credential resolution in the auth providers. Not required forachat/aembed/achat_streamthemselves.
Auth
Two authentication modes are supported, resolved on the first request:
- Bedrock API key (simplest): set
AWS_BEARER_TOKEN_BEDROCKand each request is sent with anAuthorization: Bearer <token>header — no signing required. - SigV4 (fallback): otherwise AWS credentials are resolved through boto3's default credential chain (env vars, AWS config, instance metadata) and each request is SigV4-signed. No extra setup needed if your AWS credentials are already configured.
from lmux_aws_bedrock import BedrockProvider
provider = BedrockProvider()
# Or specify a region
provider = BedrockProvider(region="us-east-1")
For explicit session configuration:
from lmux_aws_bedrock import BedrockSessionAuthProvider
provider = BedrockProvider(auth=BedrockSessionAuthProvider(profile_name="my-profile"))
Usage
Chat
from lmux import UserMessage
response = provider.chat("anthropic.claude-sonnet-4-20250514-v1:0", [UserMessage(content="Hello")])
print(response.content)
print(response.cost)
Streaming
for chunk in provider.chat_stream("anthropic.claude-sonnet-4-20250514-v1:0", [UserMessage(content="Hello")]):
if chunk.delta:
print(chunk.delta, end="")
Tool continuations
Bedrock reasoning blocks carry signatures that must be returned unmodified when a tool result continues the assistant turn. lmux-aws-bedrock preserves the native ordered Converse blocks in response.continuation; use to_assistant_message() to keep them with the normalized response:
from lmux import ToolMessage
response = provider.chat(model, messages, tools=tools, reasoning_effort="high")
messages.append(response.to_assistant_message())
messages.append(ToolMessage(content=tool_result, tool_call_id=response.tool_calls[0].id))
A matching Converse continuation is replayed exactly. Other providers ignore it and use the normalized content and tool calls.
Embeddings
response = provider.embed("amazon.titan-embed-text-v2:0", "Hello")
print(response.embeddings)
Async
All methods have async variants: achat, achat_stream, aembed. These run over httpx's async client; credentials are resolved synchronously (via boto3) even on the async path.
Bedrock also supports lmux response_format, mapped to Converse outputConfig.textFormat.
Registry
Use with the lmux registry to route across multiple providers:
from lmux import Registry
registry = Registry()
registry.register("bedrock", provider)
response = registry.chat("bedrock/anthropic.claude-sonnet-4-20250514-v1:0", messages)
Provider Params
from lmux_aws_bedrock import BedrockParams, GuardrailConfig
response = provider.chat(
"anthropic.claude-sonnet-4-20250514-v1:0",
messages,
provider_params=BedrockParams(
guardrail_config=GuardrailConfig(
guardrail_identifier="my-guardrail",
guardrail_version="1",
),
),
)
| Parameter | Type | Description |
|---|---|---|
guardrail_config |
GuardrailConfig |
Bedrock guardrail to apply |
additional_model_request_fields |
dict |
Extra fields passed to the model |
additional_model_response_field_paths |
list[str] |
Extra response fields to return |
pricing_as_of |
datetime.date |
Override the date used for dated pricing; defaults to the current date |
For Claude 4.5 and older, reasoning_effort maps to a manual thinking budget capped below maxTokens. When max_tokens is omitted, lmux sends maxTokens: 4096, so medium and high effort both use a 4095-token thinking budget. Pass a larger max_tokens to use their full mapped budgets.
An integer manual-thinking budget in additional_model_request_fields raises the default maxTokens when needed. An explicit max_tokens is preserved instead, along with the provider-specific fields. Ensure those explicit values are compatible with the deployed model; manual thinking normally requires budget_tokens < maxTokens, except when interleaved thinking applies.
Prompt Caching
Place CachePointContent parts in UserMessage content to emit Converse cachePoint blocks marking the end of a stable prompt prefix. A cache point with no preceding block in its message is placed after whatever came before it (the prior message, or the system blocks). Markers with nothing cacheable before them are dropped, and adjacent duplicates are coalesced — the first marker wins.
from lmux import CachePointContent, TextContent, UserMessage
messages = [
UserMessage(content=[TextContent(text=big_stable_context), CachePointContent()]),
UserMessage(content="What changed since yesterday?"),
]
Cache points are emitted for whatever model the request targets; models without prompt-caching support reject them at request validation. Cache reads/writes are reported on response.usage (cache_read_tokens, cache_creation_tokens, and the per-TTL cache_creation_tokens_by_ttl breakdown from cacheDetails) and priced into response.cost, including per-TTL write rates where the pricing data carries them.
Constructor Options
BedrockProvider(
auth=..., # AuthProvider, default: BedrockEnvAuthProvider()
region=..., # AWS region
endpoint_url=..., # Custom endpoint URL (overrides region/FIPS host selection)
use_fips=..., # bool, default False: target the FIPS 140-3 endpoint (bedrock-runtime-fips.<region>.amazonaws.com)
timeout=..., # request timeout in seconds
max_retries=..., # retry count for transient failures
default_headers=..., # Optional headers included with every request
transport=..., # Optional httpx.BaseTransport for the sync client (proxies, testing)
async_transport=..., # Optional httpx.AsyncBaseTransport for the async client
)
default_headers is useful for gateway authentication, tracing, and routing. Bedrock-managed authentication and
content-type headers take precedence over caller values, case-insensitively. With SigV4 authentication, custom headers
are included in the request signature.
Metadata
Release files for lmux-aws-bedrock 0.13.4
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| lmux_aws_bedrock-0.13.4.tar.gz | 28.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| lmux_aws_bedrock-0.13.4-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 58.9 kB
Release files / lmux_aws_bedrock-0.13.4.tar.gz
| Download URL | lmux_aws_bedrock-0.13.4.tar.gz |
|---|---|
| Size | 28.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
6841b748d9132f675bdea1ed793a1d4ddcc3d0addc3930e879ce885bf86c6a76
|
|
BLAKE2b-256 checksum How to use checksums |
8644e46d21dfc626cabc0c73793400bb163e852c7f24f9ea9cd4d993b7608226
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency logRelease files / lmux_aws_bedrock-0.13.4-py3-none-any.whl
| Download URL | lmux_aws_bedrock-0.13.4-py3-none-any.whl |
|---|---|
| Size | 30.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
6f6d0960b815cf0ac74e1fad167deed8c145383a7357f6fb2bc73dae7194115f
|
|
BLAKE2b-256 checksum How to use checksums |
c54d02726360570425d84c74d75439a9f823e038a07f14f368eaf5a4ce6fc8c9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency log