> ## Documentation Index
> Fetch the complete documentation index at: https://bifrost-backport-mcp-oauth2-server.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# AWS Bedrock Guardrails

> Integrate AWS Bedrock Guardrails with Bifrost for enterprise-grade content filtering, PII protection, prompt attack detection, and image content analysis.

Bifrost integrates with **Amazon Bedrock Guardrails** to provide enterprise-grade content filtering and safety features with deep AWS integration. This page covers the configuration and capabilities of the AWS Bedrock guardrail provider.

<img src="https://mintcdn.com/bifrost-backport-mcp-oauth2-server/TtPNvf4g_ku06lmR/media/guardrails/bedrock-guardrails-provider-details.png?fit=max&auto=format&n=TtPNvf4g_ku06lmR&q=85&s=a04ba00ad3b1f40190c0d5f0d252a7b2" alt="AWS Bedrock Guardrails configuration form" width="3502" height="2114" data-path="media/guardrails/bedrock-guardrails-provider-details.png" />

## Capabilities

* **Content Filters**: Hate speech, insults, sexual content, violence, misconduct
* **Denied Topics**: Block specific topics or categories
* **Word Filters**: Custom profanity and sensitive word blocking
* **PII Protection**: Detect and redact 50+ PII entity types
* **Contextual Grounding**: Verify responses against source documents
* **Prompt Attack Detection**: Identify injection and jailbreak attempts
* **Image Content Support**: Analyze images in addition to text (PNG, JPEG)

<Note>
  **Streaming output:** When this profile is used in an `output` or `both` rule, Bifrost accumulates the stream until the model response is complete, then checks the full response. It does not check individual stream chunks. See [Streaming Output Guardrails](/enterprise/guardrails#streaming-output-guardrails) for details.
</Note>

## Configuration Fields

| Field | Type | Required | Default | Description |
| - | - | - | - | - |
| `auth_type` | enum | No | inferred | `keys`, `api_key`, or `iam_role`. |
| `access_key` | string | Conditional | - | Required with `auth_type: keys`. |
| `secret_key` | string | Conditional | - | Required with `auth_type: keys`. |
| `session_token` | string | No | - | Optional AWS session token with static credentials. |
| `bedrock_api_key` | string | Conditional | - | Required with `auth_type: api_key`. |
| `role_arn` | string | No | - | IAM role ARN to assume after resolving the selected credential source. |
| `external_id` | string | No | - | Optional external ID for the assumed role. |
| `session_name` | string | No | - | Optional STS session name for the assumed role. |
| `guardrail_arn` | string | Yes | - | ARN of the Bedrock guardrail |
| `guardrail_version` | string | Yes | - | Version of the guardrail (e.g., "1", "DRAFT") |
| `region` | string | No when encoded in `guardrail_arn` | - | AWS region. Bifrost derives it from a full guardrail ARN when omitted. |
| `images_enabled` | boolean | No | `true` | Send PNG and JPEG image blocks to Bedrock Guardrails. |

## Authentication

Choose one of the following authentication modes.

### Static AWS credentials

```json theme={null}
{
  "access_key": "AKIAXXXXXXXXXXXXXXXXXX",
  "secret_key": "your-secret-access-key",
  "guardrail_arn": "arn:aws:bedrock:us-east-1:123456789:guardrail/abc123",
  "guardrail_version": "1",
  "region": "us-east-1"
}
```

### Bedrock API key

```json theme={null}
{
  "auth_type": "api_key",
  "bedrock_api_key": "your-bedrock-api-key",
  "guardrail_arn": "arn:aws:bedrock:us-east-1:123456789:guardrail/abc123",
  "guardrail_version": "1"
}
```

### IAM role or default credential chain

Set `auth_type` to `iam_role`. Bifrost uses the AWS SDK default credential chain (for example, IRSA, an EC2/ECS role, environment credentials, or a shared credentials file). Set `role_arn` to assume a different role when needed.

## Supported AWS Regions

The following regions support Amazon Bedrock Guardrails. Availability of individual guardrail policies and safeguard tiers can vary by region; refer to the [AWS documentation](https://docs.aws.amazon.com/bedrock/latest/userguide/guardrails-tiers.html) for the current service matrix.

| Region Code | Region Name |
| - | - |
| `us-east-1` | US East (N. Virginia) |
| `us-east-2` | US East (Ohio) |
| `us-west-1` | US West (N. California) |
| `us-west-2` | US West (Oregon) |
| `ca-central-1` | Canada (Central) |
| `eu-central-1` | Europe (Frankfurt) |
| `eu-north-1` | Europe (Stockholm) |
| `eu-south-1` | Europe (Milan) |
| `eu-south-2` | Europe (Spain) |
| `eu-west-1` | Europe (Ireland) |
| `eu-west-2` | Europe (London) |
| `eu-west-3` | Europe (Paris) |
| `ap-east-2` | Asia Pacific (Taipei) |
| `ap-northeast-1` | Asia Pacific (Tokyo) |
| `ap-northeast-2` | Asia Pacific (Seoul) |
| `ap-south-1` | Asia Pacific (Mumbai) |
| `ap-southeast-1` | Asia Pacific (Singapore) |
| `ap-southeast-2` | Asia Pacific (Sydney) |
| `ap-southeast-3` | Asia Pacific (Jakarta) |
| `ap-southeast-4` | Asia Pacific (Melbourne) |
| `ap-southeast-5` | Asia Pacific (Malaysia) |
| `ap-southeast-7` | Asia Pacific (Thailand) |
| `me-central-1` | Middle East (UAE) |
| `il-central-1` | Israel (Tel Aviv) |
| `us-gov-west-1` | AWS GovCloud (US-West) |

## Supported Content Types

* Text content
* Images (PNG, JPEG formats)

When `images_enabled` is enabled, Bifrost extracts supported image blocks from Chat and Responses traffic and sends them to Bedrock. File and PDF attachments are not sent.

## Usage Metrics Returned

Bedrock guardrails return detailed usage metrics for cost tracking and monitoring:

| Metric | Description |
| - | - |
| `content_policy_units` | Units consumed by content policy evaluation |
| `contextual_grounding_policy_units` | Units for grounding checks |
| `sensitive_information_policy_units` | Units for PII detection |
| `topic_policy_units` | Units for topic filtering |
| `word_policy_units` | Units for word filtering |
| `automated_reasoning_policy_units` | Units for reasoning checks |
| `content_policy_image_units` | Units for image content analysis |

## Supported PII Types

* Personal identifiers (SSN, passport, driver's license)
* Financial information (credit cards, bank accounts)
* Contact information (email, phone, address)
* Medical information (health records, insurance)
* Device identifiers (IP addresses, MAC addresses)

For provider comparison and information on configuring guardrail rules and profiles, see [Guardrails](/enterprise/guardrails).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.