Transcript: start without a provider key
Managed Amazon Bedrock is an optional way to begin without bringing a separate provider API key. Your applications still use an AI Gateway HQ workload identity, route, policy, and budget.
1. Fund provider spend first
Activation requires settled purchased credit and a reusable payment authorization. Promotional credit never funds an Amazon Web Services call, and a zero eligible balance stops managed inference before provider dispatch.
2. Choose from the reviewed catalog
The Providers page shows the release-controlled catalog, region, output limit, and exact customer rate per million tokens. Each route target names one reviewed model; the gateway does not silently substitute another.
3. Put a stable route name in front
Create a route alias such as “quality” or “fast,” then add only the models that may serve it. Additional targets provide controlled fallback or distribution while capability, health, policy, and budget remain binding.
4. Set a hard budget
Set a hard budget before issuing a workload key. For managed requests, the gateway reserves conservative exposure before dispatch and reconciles supported provider usage afterward. If the reservation cannot be funded, the request stops.
5. Keep automatic reload bounded
Automatic reload begins disabled. If the owner enables it, a threshold, reload amount, and monthly cap are all required. A pending or failed charge never creates spendable credit.
6. Verify the operational evidence
After each request, the evidence ledger connects workload identity, route, policy outcome, provider attempt, latency, usage, and cost basis. Prompt and response bodies are not written to this ledger by default.
Send the first bounded request
The shortest safe path is to purchase credit, activate managed Bedrock, select one explicit model in a route, set a hard budget, issue one workload key, and send a small non-sensitive test.