AWS Bedrock through the Vigil proxy
Amazon’s managed endpoint for Claude and other models, billed through AWS, with the request signed by SigV4 or carried under a Bedrock API key. Point your SDK's base URL at Vigil, add one header, and every AWS Bedrock call is logged with its cost, tokens, latency, errors and agent, then forwarded to https://bedrock-runtime.{region}.amazonaws.com unchanged.
What Vigil records per AWS Bedrock call
One row per call: the model id as AWS Bedrock returned it, input and output tokens, cache reads and writes where the response reports them, latency, the HTTP status and the provider's error code when it fails, and the agent named in the X-Vigil-Agent header. Likely prompt injections and personal data in prompts are flagged on the Errors page. A cost spike is flagged when a call costs over three times the agent's seven-day median.
Cost is computed from the proxy's rate registry, which prices 9 models on this platform today. A model the registry has no row for is logged with its cost left empty, never estimated.
- anthropic.claude-fable-5contract designated
- anthropic.claude-fable-5-1contract designated
- anthropic.claude-haiku-4-5-20251001contract designated
- anthropic.claude-opus-4-8
- anthropic.claude-opus-5contract designated
- anthropic.claude-sonnet-4-5-20250929
- anthropic.claude-sonnet-4-6
- anthropic.claude-sonnet-5contract designated
- meta.llama3-3-70b-instructunverified
Price per token, by model: Claude Opus 5, Claude Sonnet 5, Claude Haiku 4.5, Claude Fable 5.1, Claude Opus 4.8, Claude Sonnet 4.6.
Setup
Every route has the shape https://api.vigil.tools/{user_id}/{provider}/{path}. For AWS Bedrock the provider segment is bedrock, so the base URL is https://api.vigil.tools/{user_id}/bedrock and a request path such as /us-east-1/model/{model-id}/invoke is forwarded unchanged. Bedrock needs the AWS region as the next segment; the snippets use us-east-1.
Two headers: X-Vigil-Key, your Vigil key from the dashboard, and X-Vigil-Agent, the name the dashboard groups this traffic under. Your AWS Bedrock key stays where it was, in AWS_BEARER_TOKEN_BEDROCK.
TypeScript: No verified TypeScript example for Bedrock yet — the AWS SDKs sign requests with SigV4 by default, and no per-client switch to bearer auth has been verified here, so a snippet would fail with a signature error rather than work. Use the curl format: it is the exact request Vigil expects, and any client that lets you set a base URL and a header will work.
Python: No verified Python example for Bedrock yet — the AWS SDKs sign requests with SigV4 by default, and no per-client switch to bearer auth has been verified here, so a snippet would fail with a signature error rather than work. Use the curl format: it is the exact request Vigil expects, and any client that lets you set a base URL and a header will work.
curl https://api.vigil.tools/{user_id}/bedrock/us-east-1/model/us.anthropic.claude-haiku-4-5-20251001-v1%3A0/invoke \
-H "content-type: application/json" \
-H "Authorization: Bearer $AWS_BEARER_TOKEN_BEDROCK" \
-H "X-Vigil-Key: vk_your_vigil_key" \
-H "X-Vigil-Agent: my-agent" \
-d '{
"anthropic_version": "bedrock-2023-05-31",
"max_tokens": 1024,
"messages": [{ "role": "user", "content": "Hello!" }]
}'The model id is the SHAPE, not a fixed value — copy the exact one from the Bedrock console. A us. prefix is a regional inference profile and global. is the global one; they are priced differently, so Vigil records them as different rate tables and never averages the two.
Replace {user_id} and vk_your_vigil_key with the values on your Connect page. The snippets above are generated by the same code as that page.
Prompt caching on AWS Bedrock
Vigil can add cache breakpoints here, but only when the request carries a Bedrock API key. A SigV4-signed request cannot be modified without invalidating its signature, so those calls are forwarded exactly as sent and nothing is cached by us.
With optimisation On: Vigil adds cache markers only when the request carries a Bedrock API key; a SigV4-signed request is forwarded unchanged. In Shadow, Vigil measures what caching would have saved and changes nothing. Off records the call and nothing more.
Questions
- Does Vigil see or store my AWS Bedrock API key?
- No, not the key itself. Your AWS Bedrock key passes through the proxy with the request and is never written to disk. A call record can keep a short one-way digest of the credential, so that one key’s cache is kept apart from another’s; it cannot be turned back into the key. Vigil identifies you by the X-Vigil-Key header and your user id in the URL.
- Does routing AWS Bedrock through Vigil add latency?
- Some. The proxy runs on Cloudflare’s edge, so the added hop is short, but reading the request body to place cache markers takes time, and there is a bounded lookup for your account state. The dashboard shows total latency per call. For long calls, stream: Cloudflare’s edge closes non-streaming connections after roughly 125 seconds.
- Which AWS Bedrock models does Vigil price?
- 8 models with a published rate in the registry: anthropic.claude-fable-5, anthropic.claude-fable-5-1, anthropic.claude-haiku-4-5-20251001, anthropic.claude-opus-4-8, anthropic.claude-opus-5, anthropic.claude-sonnet-4-5-20250929, anthropic.claude-sonnet-4-6, anthropic.claude-sonnet-5. A call to any other AWS Bedrock model is logged and monitored, with its cost left empty rather than guessed.
Other providers: Anthropic · Google Vertex · OpenAI · Google Gemini · Mistral · xAI Grok · DeepSeek · Together AI · Fireworks AI · Groq · Cerebras · Baseten · Moonshot · Z.ai · Cloudflare Workers AI · OpenRouter