Choose how people authenticate
With Each member signs in, each person approves OpenWork once in their browser with your organization’s IAM Identity Center (and through it, Okta, Microsoft Entra ID, Google Workspace or another identity provider you federated). Gateway keeps their sign-in on the server, renews it, and exchanges it for short-lived AWS credentials of the permission set you choose. Nobody needs the AWS CLI, a named profile, or an
~/.aws folder.
Each member signs in for Amazon Bedrock is rolling out. If the option shows AWS sign-in isn’t turned on for your organization yet, ask your OpenWork platform administrator to turn on AI Gateway: AWS and Microsoft sign-in for your organization in
/admin. Self-hosted operators can turn it on for the whole install with the Helm value config.features.gatewayCloudSignIn.Set up AWS
You do these steps once per AWS organization. You need permission to manage Bedrock model access and IAM Identity Center.1. Enable the models in Bedrock
In the Amazon Bedrock console, open Model access and request the models you want. Access is per region: enable them in the region you will enter as the provider’s AWS region in OpenWork.2. Create a permission set (each member signs in)
Skip this step for a shared key. In the IAM Identity Center console, open Permission sets → Create permission set, choose Custom permission set, and add an inline policy that allows inference. For Amazon Bedrock:AmazonBedrockMantleInferenceAccess, or allow bedrock-mantle:CreateInference on your Mantle project.
Set the permission set’s Session duration to 8–12 hours. It sets how long each set of short-lived AWS credentials lasts before Gateway asks IAM Identity Center for new ones; it does not decide how often people sign in.
3. Assign people to the permission set
In IAM Identity Center, open AWS accounts, select the account where you enabled Bedrock, choose Assign users or groups, and assign the people or groups who should use Bedrock to the permission set. If your organization uses Okta, Microsoft Entra ID or another SAML identity provider, you can make it IAM Identity Center’s identity source so people sign in with their usual work account. See Connect to an external identity provider.4. Record the values for OpenWork
From IAM Identity Center’s Settings and Permission sets pages, note:Shared key instead
For a shared key, create an IAM user or role with the same policy and create access keys for it, or generate an Amazon Bedrock API key. The key’s IAM principal must also be allowedbedrock:CallWithBearerToken.
Add the provider in OpenWork
As an organization owner or admin, open AI Gateway → AI Providers → Add provider and choose Amazon Bedrock or Amazon Bedrock (OpenAI).- Enter the AWS region where you enabled the models, for example
us-west-2. - In Key, choose how people authenticate:
- Shared API key: enter the access key ID and secret access key (and a session token for temporary keys). When you already saved AWS keys for another Bedrock provider, turn on Use AWS keys you already saved instead of pasting them again.
- Each member signs in: enter the AWS access portal URL, IAM Identity Center region, AWS account ID and Permission set name you recorded. OpenWork stores no AWS keys for the organization.
- In Models, pick the models to offer, or keep all of them.
- In Who can use it, keep Everyone in the organization or add people and teams. Include yourself if you will test it.
- Select Add.
Changing the access portal URL, Identity Center region, account ID or permission set signs everyone out of that provider: you confirm this before saving, and members sign in again.
Sign in as a member
Members connect once, from Den or the desktop app:- In Den, open My Library → Models and select Sign in on the Bedrock provider.
- In the desktop app, select a Bedrock model in the model picker and choose Login, or use Login on the provider in Settings → AI Providers.
- A browser tab opens OpenWork’s connect page. If it asks you to Sign in to OpenWork, sign in with the same OpenWork account you use in the app, then return to the tab.
- Select Continue to AWS. OpenWork opens your AWS access portal in a new tab and shows a short code.
- Sign in to AWS if asked, check that AWS shows the same code, and approve OpenWork AI Gateway.
- The connect page checks that your sign-in gets credentials for the configured account and permission set, then shows Signed in to AWS as …. Close the tab.
How sign-in lasts
- Gateway keeps each person’s IAM Identity Center sign-in encrypted on the server, renews it before it expires, and exchanges it for short-lived AWS credentials of the permission set. Those credentials sign the request to Bedrock; they are never sent to a computer.
- People stay signed in until the AWS access portal session duration you set in IAM Identity Center (Settings → Authentication) ends, or for at most 90 days, whichever comes first. Then requests return sign in again, and the person repeats the steps above. To sign someone out sooner, delete their session in the IAM Identity Center console.
- Sign out (on the provider in My Library → Models) erases the person’s sign-in in OpenWork and ends their AWS access portal session.
- Removing someone from your OpenWork organization erases their sign-ins. Removing their IAM Identity Center assignment stops new AWS credentials immediately.
Network access
For self-hosted deployments, Den and Gateway must reach these AWS hosts over HTTPS, where<sso-region> is the IAM Identity Center region and <region> the Bedrock region:
People’s browsers also reach your AWS access portal (
*.awsapps.com) and, if federated, your identity provider. AWS China regions are not supported.