> ## Documentation Index
> Fetch the complete documentation index at: https://notes.kodekloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Demo Accessing Bedrock With Command Line Part 3

> Tutorial showing how to use the AWS CLI to call Amazon Bedrock, demonstrating invoke-model and converse examples, payloads, outputs, and credential best practices.

This lesson demonstrates how to access Amazon Bedrock from the command line and run inference using the AWS CLI. Examples show a Windows Subsystem for Linux (WSL) environment on Windows 11, but the same commands work in macOS and Linux terminals.

## Verify the AWS CLI is available

Run `aws` to confirm the CLI is installed. A minimal invocation without arguments returns usage help and an error about missing subcommands:

```bash theme={null}
alistair@H0DEI-LEGION5: ~/bedrock-demo$ aws
aws: [ERROR]: An error occurred (ParamValidation): the following arguments are required: command

usage: aws [options] <command> <subcommand> [<subcommand> ...] [parameters]
To see help text, you can run:

    aws help
    aws <command> help
    aws <command> <subcommand> help
```

A quick check that the CLI can call AWS APIs: `ec2 describe-instances` returns JSON describing your EC2 instances (truncated here):

```json theme={null}
{
  "Reservations": [
    {
      "ReservationId": "r-098a420a10e3ec1b7",
      "Instances": [
        {
          "Architecture": "x86_64",
          "BlockDeviceMappings": [
            {
              "DeviceName": "/dev/xvda",
              "Ebs": {
                "AttachTime": "2021-07-31T10:40:35+00:00",
                "DeleteOnTermination": true,
                "Status": "attached",
                "VolumeId": "vol-0a6cbedbeafa99260"
              }
            }
          ],
          "IamInstanceProfile": {
            "Arn": "arn:aws:iam::485186561655:instance-profile/AmazonSSMRoleForInstancesQuickSetup"
          }
        }
      ]
    }
  ]
}
```

## Bedrock runtime: invoke-model vs converse

Two primary Bedrock runtime subcommands are useful from the CLI:

* `invoke-model` — low-level call where you format the payload to match the model’s expected input.
* `converse` — higher-level, message-based interface that standardizes chat-style inputs and is better for multi-turn conversations.

<Callout icon="lightbulb" color="#1CB2FE">
  Use `invoke-model` when you need fine-grained control over exact tokenization, markers, or model-specific input formats. Use `converse` for portable, standardized messages and when building chat flows or multi-turn interactions.
</Callout>

Here is a quick comparison to help choose:

| Subcommand | Best for | Example inputs | Returned metadata |
| - | - | - | - |
| `invoke-model` | Model-specific control, special tokens | `fileb://invoke-payload.json` (raw model prompt JSON) | `generation`, token counts, stop\_reason |
| `converse` | Chat-style multi-turn, standardized message format | `--messages file://converse-payload.json` | Model `MESSAGE`, `METRICS`, usage info |

## Files used in the demo

Listing the working directory shows two payload files and an output file:

```bash theme={null}
alistair@H0DEI-LEGION5:~/bedrock-demo$ ls -l
-rw-r--r-- 1 alistair alistair 152 May 13 15:47 converse-payload.json
-rw-r--r-- 1 alistair alistair 240 May 13 15:40 invoke-payload.json
-rw-r--r-- 1 alistair alistair 655 May 14 13:17 output.json
```

## invoke-model example (low-level JSON payload)

`invoke-payload.json` contains a model-specific prompt and generation settings:

```json theme={null}
# invoke-payload.json
{
  "prompt": "<|begin_of_text|><|start_header_id|>user<|end_header_id|>\nWhat is Amazon Bedrock? Explain in 2 short bullets.<|eot_id|><|start_header_id|>assistant<|end_header_id|>",
  "max_gen_len": 200,
  "temperature": 0.3,
  "top_p": 0.9
}
```

Call the Bedrock runtime with `invoke-model`. Use `--model-id` for the catalog name, `--body fileb://...` to supply the binary JSON payload, and `--accept application/json` to request JSON output written to `output.json`:

```bash theme={null}
alistair@H0DEI-LEGION5:~/bedrock-demo$ aws bedrock-runtime invoke-model \
  --region us-east-1 \
  --model-id us.meta.llama3-1-8b-instruct-v1:0 \
  --body fileb://invoke-payload.json \
  --content-type application/json \
  --accept application/json output.json
{
  "contentType": "application/json"
}
```

Inspect the generated JSON result:

```json theme={null}
# output.json
{
  "generation": "\nAmazon Bedrock is a cloud-based platform that provides a suite of tools for developers to build, deploy, and manage applications. Here are 2 short bullets explaining it:\n\n• **Managed Foundation Models**: Amazon Bedrock provides managed access to multiple foundation models and the runtime infrastructure to deploy them at scale.\n• **Developer Tooling and Integration**: Bedrock offers tools and APIs to simplify building, testing, and integrating generative AI into applications.",
  "prompt_token_count": 49,
  "generation_token_count": 108,
  "stop_reason": "stop"
}
```

## converse example (higher-level, message-based JSON)

`converse-payload.json` expresses the user message using the standardized message array:

```json theme={null}
# converse-payload.json
[
  {
    "role": "user",
    "content": [
      {
        "text": "Explain what Amazon Bedrock is in two short bullet points."
      }
    ]
  }
]
```

Invoke the `converse` subcommand and request plain text output. The CLI returns the assistant message plus additional metrics and usage lines:

```bash theme={null}
alistair@H0DEI-LEGION5:~/bedrock-demo$ aws bedrock-runtime converse \
  --region us-east-1 \
  --model-id us.meta.llama3-1-8b-instruct-v1:0 \
  --messages file://converse-payload.json \
  --output text
end_turn
METRICS 656
MESSAGE assistant
CONTENT

Here are two short bullet points explaining what Amazon Bedrock is:

• Amazon Bedrock is a cloud-based platform that gives developers managed access to powerful foundation models and the runtime infrastructure to deploy them.
• Amazon Bedrock simplifies building and integrating generative AI by providing APIs, developer tools, and scalable, secure model hosting.
USAGE 28 98 126
```

Note that `converse` includes `METRICS` and `USAGE` lines that are useful for logging, debugging, and cost monitoring.

## Authentication and AWS CLI profiles

This guide shows examples using locally configured long-lived credentials. For production or shared environments, prefer temporary credentials using AWS SSO, IAM roles, or other secure methods.

<Callout icon="warning" color="#FF6B6B">
  Avoid committing long-lived AWS access keys into source control or sharing them. Use temporary credentials (for example, `aws sso login`, `sts assume-role`) or properly scoped IAM roles wherever possible.
</Callout>

List existing CLI profiles:

```bash theme={null}
alistair@H0DEI-LEGION5:~/bedrock-demo$ aws configure list-profiles
default
PowerUserAccessPermissionSet-851189578280
new-empty-profile
current-console-user-profile
```

Create (or update) a named profile. You will be prompted for keys and defaults:

```bash theme={null}
alistair@H0DEI-LEGION5:~/bedrock-demo$ aws configure --profile my-new-profile
Tip: You can deliver temporary credentials to the AWS CLI using AWS SSO or your console session; for example, run 'aws sso login' for SSO-based access.

AWS Access Key ID [None]: XXXXXXXXXXXXXX
AWS Secret Access Key [None]: XXXXXXXXXXXXXX
Default region name [None]: eu-west-1
Default output format [None]: json
```

Verify the profile was added:

```bash theme={null}
alistair@H0DEI-LEGION5:~/bedrock-demo$ aws configure list-profiles
default
PowerUserAccessPermissionSet-851189578280
new-empty-profile
current-console-user-profile
my-new-profile
```

To use a specific profile when invoking Bedrock, include `--profile my-new-profile` in the AWS CLI command. This helps manage multiple credential sets, roles, or environments.

## Summary

* You can access Amazon Bedrock runtime endpoints directly from any terminal with the AWS CLI.
* Choose `invoke-model` for precise, model-specific inputs and `converse` for standardized chat-style message flows and multi-turn interactions.
* Both subcommands return useful metadata (metrics, usage, token counts) that help with logging and cost monitoring.
* Manage credentials carefully: prefer temporary credentials and profiles; pass `--profile` to isolate credentials per task.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/tJmUiudNjsCWp_bm/images/Introduction-to-Amazon-Bedrock/Getting-Started-With-Amazon-Bedrock/Demo-Accessing-Bedrock-With-Command-Line-Part-3/aws-cli-bedrock-terminal-model-testing.jpg?fit=max&auto=format&n=tJmUiudNjsCWp_bm&q=85&s=d05215daa39de714562c8ec8ab544645" alt="A &#x22;Results&#x22; slide showing four numbered dark-blue panels. Each panel lists a developer/operator capability: authenticate securely with the AWS CLI, access Amazon Bedrock from the terminal, invoke foundation models without the console, and quickly test prompts and model responses." width="1920" height="1080" data-path="images/Introduction-to-Amazon-Bedrock/Getting-Started-With-Amazon-Bedrock/Demo-Accessing-Bedrock-With-Command-Line-Part-3/aws-cli-bedrock-terminal-model-testing.jpg" />
</Frame>

That concludes this lesson. A related short but important topic is inference profiles, which can affect how you interact with foundation models.

## Links and references

* [Amazon Bedrock documentation](https://docs.aws.amazon.com/bedrock/)
* [AWS CLI reference — bedrock-runtime](https://docs.aws.amazon.com/cli/latest/reference/bedrock-runtime/index.html)
* [AWS CLI installation guide](https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html)

<CardGroup>
  <Card title="Watch Video" icon="video" cta="Learn more" href="https://learn.kodekloud.com/user/courses/introduction-to-amazon-bedrock/module/4f0b1655-3751-4724-a6eb-78d06f3753a7/lesson/ab0a2e32-6ab6-4045-bb30-dbd18c04adc1" />
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.