> ## Documentation Index
> Fetch the complete documentation index at: https://notes.kodekloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Accessing Bedrock With Command Line Part 1

> How to use the AWS CLI to access Amazon Bedrock, covering control plane versus runtime commands, authentication methods, examples, and best practices for secure, scriptable model inference

In this lesson we'll show how to access Amazon Bedrock from your terminal using the AWS Command Line Interface (AWS CLI). Working from a developer workstation (for example, a terminal inside Visual Studio Code) reduces friction compared to switching back and forth to the AWS Management Console. It also speeds up iterative testing and makes automation straightforward.

We will:

* Introduce the AWS CLI as the primary tool for Bedrock interaction.
* Explain the difference between control-plane and inference/runtime Bedrock commands.
* Cover common authentication options for securely using the CLI.
* Summarize best practices and next steps.

First, consider the problem this solves.

If you frequently test prompts or compare multiple foundation models, switching between an IDE and the browser-based console slows development. Automation—such as running the same prompt across several models—is easiest from the terminal, but that requires reliable and secure authentication and a clear distinction between management and runtime APIs.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/tJmUiudNjsCWp_bm/images/Introduction-to-Amazon-Bedrock/Getting-Started-With-Amazon-Bedrock/Accessing-Bedrock-With-Command-Line-Part-1/aws-console-testing-automation-slow.jpg?fit=max&auto=format&n=tJmUiudNjsCWp_bm&q=85&s=233bdfe74299c94a063b1d5e7f397bdd" alt="A slide titled &#x22;Problem: Testing and Automation Is Slow in AWS Console&#x22; with four numbered panels. Each panel lists pain points: developers need fast model testing, switching between console and code slows work, automation requires CLI access, and teams need secure CLI authentication." width="1920" height="1080" data-path="images/Introduction-to-Amazon-Bedrock/Getting-Started-With-Amazon-Bedrock/Accessing-Bedrock-With-Command-Line-Part-1/aws-console-testing-automation-slow.jpg" />
</Frame>

Solution: use the AWS CLI

The AWS CLI runs on Windows, Linux, and macOS and lets you interact with AWS services from a terminal. This approach provides:

* Faster iterative testing without switching to a browser.
* Automation via Bash, PowerShell, or CI/CD pipelines that call the AWS CLI.
* Secure access patterns using AWS credential mechanisms such as named profiles, environment variables, IAM roles, or SSO.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/tJmUiudNjsCWp_bm/images/Introduction-to-Amazon-Bedrock/Getting-Started-With-Amazon-Bedrock/Accessing-Bedrock-With-Command-Line-Part-1/aws-cli-benefits-infographic.jpg?fit=max&auto=format&n=tJmUiudNjsCWp_bm&q=85&s=c62337493ce33bcf83df3704dc499f22" alt="An infographic titled &#x22;Solution: AWS Command Line Tool&#x22; showing four colored panels that list benefits: Direct AWS Interaction, Faster Testing, Automation & Scripting, and Secure CLI Access. Each panel includes a small icon and brief explanatory text." width="1920" height="1080" data-path="images/Introduction-to-Amazon-Bedrock/Getting-Started-With-Amazon-Bedrock/Accessing-Bedrock-With-Command-Line-Part-1/aws-cli-benefits-infographic.jpg" />
</Frame>

AWS CLI basics

The AWS CLI is consistent across services. The general form is:

* aws \<service> \<operation> \[parameters]

Examples:

```bash theme={null}
aws s3 ls
aws ec2 describe-instances
aws ec2 describe-instances --region eu-west-1
```

The first token after `aws` selects the service (for example, `s3`, `ec2`), the second token is the operation (for example, `ls`, `describe-instances`), and flags such as `--region` scope the command.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/tJmUiudNjsCWp_bm/images/Introduction-to-Amazon-Bedrock/Getting-Started-With-Amazon-Bedrock/Accessing-Bedrock-With-Command-Line-Part-1/aws-cli-workflow-buttons.jpg?fit=max&auto=format&n=tJmUiudNjsCWp_bm&q=85&s=f060c17f67f0f629553f7fe56375a6da" alt="A slide titled &#x22;Workflow: AWS CLI&#x22; with the subtitle &#x22;AWS CLI is not specific to Amazon Bedrock.&#x22; It shows three rounded buttons labeled &#x22;aws&#x22;, &#x22;command&#x22;, and &#x22;sub-command&#x22; to illustrate the CLI structure." width="1920" height="1080" data-path="images/Introduction-to-Amazon-Bedrock/Getting-Started-With-Amazon-Bedrock/Accessing-Bedrock-With-Command-Line-Part-1/aws-cli-workflow-buttons.jpg" />
</Frame>

Bedrock-specific CLI considerations

When using the AWS CLI with Bedrock, there are two distinct service targets depending on your goal:

* Control plane (management): `aws bedrock <operation> ...`\
  Use this for listing available foundation models, managing access, or configuring guardrails and knowledge bases.

* Inference/runtime: `aws bedrock-runtime <operation> ...`\
  Use this for sending prompts to models and receiving outputs, embeddings, or multi-turn conversation messages.

Examples

Control plane — list foundation models (operation names may vary by CLI version):

```bash theme={null}
aws bedrock list-foundation-models --region eu-west-1
```

Inference/runtime — invoke a model (flags may vary by CLI version):

```bash theme={null}
aws bedrock-runtime invoke-model \
  --model-id MODEL-ID \
  --body '{"input":"Hello"}' \
  --content-type 'application/json' \
  --region eu-west-1
```

Common runtime subcommands

* `invoke-model` — lower-level call for sending a payload to a specific model and receiving the response.
* `converse` — higher-level method designed for managing multi-turn conversations and consistent message structure across models. `converse` can simplify conversation flow handling and help with token accounting for context windows.

Why the control-plane vs runtime distinction matters

* Use `aws bedrock` for administrative actions: listing models, configuring guardrails, or managing knowledge bases.
* Use `aws bedrock-runtime` for inference: sending prompts, receiving outputs, or managing multi-turn conversations.

Authentication and secure access

Before running Bedrock commands, authenticate the AWS CLI to an identity that has Bedrock permissions. Common options:

| Authentication method | When to use it | Example / notes |
| - | -: | - |
| Named profile | Local development with long-lived credentials per role/person | `aws configure --profile my-dev-profile` |
| Environment variables | Short-lived or CI environments | Set `AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`, `AWS_SESSION_TOKEN` |
| IAM roles (EC2, ECS, Lambda) | When running from AWS compute that can assume a role automatically | No key material on disk; recommended for production compute |
| AWS SSO / IAM Identity Center | Federated access for interactive users; reduces long-lived keys | See [AWS SSO docs](https://docs.aws.amazon.com/singlesignon/latest/userguide/) |

Example: configure the CLI with a named profile

```bash theme={null}
aws configure --profile my-dev-profile
```

Then use that profile when invoking Bedrock runtime commands:

```bash theme={null}
aws bedrock-runtime invoke-model \
  --model-id MODEL-ID \
  --body '{"input":"Hi"}' \
  --region eu-west-1 \
  --profile my-dev-profile
```

<Callout icon="lightbulb" color="#1CB2FE">
  When running inference, be mindful of token usage. Tokens are consumed both for prompt/context tokens and for tokens produced in model responses. Tokenization affects context window limits and cost for on-demand model invocations. Consider smaller prompts, batching, or model selection to control costs.
</Callout>

Security note

<Callout icon="warning" color="#FF6B6B">
  Avoid committing credentials to source control. Use IAM roles, SSO, or environment variables for short-lived credentials. Rotate keys regularly and apply least-privilege IAM policies for Bedrock operations.
</Callout>

Key takeaways

* The AWS CLI is a fast, scriptable way to interact with Amazon Bedrock from a developer workstation.
* Use `aws bedrock` for control-plane management and `aws bedrock-runtime` for inference and multi-turn conversations.
* Authenticate securely using named profiles, environment variables, IAM roles, or AWS SSO, and monitor token usage (context windows and cost).

Next steps (hands-on)

A follow-up hands-on demonstration will step through Bedrock runtime calls using the AWS CLI and include an example using `converse` to manage a multi-turn conversation and token accounting.

Links and references

* Amazon Bedrock overview — [https://docs.aws.amazon.com/bedrock/latest/ug/overview.html](https://docs.aws.amazon.com/bedrock/latest/ug/overview.html)
* AWS CLI User Guide — [https://docs.aws.amazon.com/cli/latest/userguide/](https://docs.aws.amazon.com/cli/latest/userguide/)
* AWS Single Sign-On / IAM Identity Center — [https://docs.aws.amazon.com/singlesignon/latest/userguide/](https://docs.aws.amazon.com/singlesignon/latest/userguide/)

<CardGroup>
  <Card title="Watch Video" icon="video" cta="Learn more" href="https://learn.kodekloud.com/user/courses/introduction-to-amazon-bedrock/module/4f0b1655-3751-4724-a6eb-78d06f3753a7/lesson/0116e6b8-d350-4a47-bf84-83c944f8ee37" />
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.