all docs
/ troubleshooting

Bedrock 400 naming both credential headers

Send a Bedrock API key or an access-key pair, never both; a key beside a pair, or half a pair, is a 400.

Symptom

Bedrock calls through ACE return HTTP 400 naming x-ace-bedrock-api-key and the access-key headers together.

Cause

Bedrock takes one of two credentials: an Amazon Bedrock API key on x-ace-bedrock-api-key, or the SigV4 pair x-ace-bedrock-key + x-ace-aws-secret-access-key, which ACE signs per request. The two are exclusive. A key beside a pair, or only half a pair, is refused rather than guessed at.

Fix

Pick one credential and drop the other headers. With the pair, add x-ace-aws-session-token only for temporary STS credentials.

Source