/ troubleshooting
Bedrock 400 naming both credential headers
Send a Bedrock API key or an access-key pair, never both; a key beside a pair, or half a pair, is a 400.
Symptom
Bedrock calls through ACE return HTTP 400 naming x-ace-bedrock-api-key and the access-key headers together.
Cause
Bedrock takes one of two credentials: an Amazon Bedrock API key on x-ace-bedrock-api-key, or the SigV4 pair x-ace-bedrock-key + x-ace-aws-secret-access-key, which ACE signs per request. The two are exclusive. A key beside a pair, or only half a pair, is refused rather than guessed at.
Fix
Pick one credential and drop the other headers. With the pair, add x-ace-aws-session-token only for temporary STS credentials.