# How to Set Up AWS Bedrock Credentials with Environment Variables for Next AI Draw.io

> Easily set up AWS Bedrock credentials using environment variables for Next AI Draw.io. Securely configure AWS_REGION, AWS_ACCESS_KEY_ID, and AWS_SECRET_ACCESS_KEY for seamless integration.

- Repository: [Dayuan Jiang/next-ai-draw-io](https://github.com/DayuanJiang/next-ai-draw-io)
- Tags: how-to-guide
- Published: 2026-07-13

---

**Configure the `AWS_REGION`, `AWS_ACCESS_KEY_ID`, and `AWS_SECRET_ACCESS_KEY` environment variables in your `.env` file or deployment platform to enable Amazon Bedrock models in Next AI Draw.io.**

Next AI Draw.io, an open-source diagram generation tool from the `DayuanJiang/next-ai-draw-io` repository, integrates with Amazon Bedrock through the `@ai-sdk/amazon-bedrock` provider. The application reads authentication details from standard AWS environment variables to initialize the Bedrock client at runtime. By setting these variables, you unlock access to Bedrock-hosted models like Claude directly within the diagram generation interface.

## Required Environment Variables

The Bedrock provider requires three standard AWS environment variables:

- **`AWS_REGION`**: The AWS region hosting Bedrock (e.g., `us-west-2`). Defaults to `us-west-2` if omitted.
- **`AWS_ACCESS_KEY_ID`**: Your IAM user's access key ID. Required unless running on AWS infrastructure with an IAM role.
- **`AWS_SECRET_ACCESS_KEY`**: Your IAM user's secret access key. Required unless running on AWS infrastructure with an IAM role.

When deploying to AWS Lambda, EC2, or ECS with an attached IAM role, you can omit the access key and secret key variables. The SDK automatically retrieves temporary credentials from the role metadata service.

## Step-by-Step Configuration

### Local Development Setup

The repository includes an `.env.example` file that serves as a template. Copy this file to `.env` in your project root and populate the values:

```bash

# .env

AWS_REGION=us-west-2
AWS_ACCESS_KEY_ID=AKIAxxxxxxxxxxxx
AWS_SECRET_ACCESS_KEY=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

```

Start the development server:

```bash
pnpm dev

```

### AWS IAM Role Deployment

For deployments on AWS services with IAM roles (such as Lambda or EC2), configure only the region variable:

```bash
AWS_REGION=us-west-2

```

The `@ai-sdk/amazon-bedrock` provider detects the execution environment and obtains credentials from the role automatically, eliminating the need to manage long-term access keys.

### Platform-Specific Deployment (Vercel)

For Vercel or similar serverless platforms, navigate to Project Settings > Environment Variables and add the three variables using the same names and values shown in the local development setup. The application reads these at runtime during the client initialization phase.

## How Credentials Are Consumed

In [`lib/ai-providers.ts`](https://github.com/DayuanJiang/next-ai-draw-io/blob/main/lib/ai-providers.ts) (line 825), the application constructs the Bedrock client by calling `createAmazonBedrock` and passing the environment variables:

```typescript
import { createAmazonBedrock } from '@ai-sdk/amazon-bedrock';

const bedrock = createAmazonBedrock({
  region: overrides?.awsRegion || process.env.AWS_REGION || 'us-west-2',
  credentials: {
    accessKeyId: process.env.AWS_ACCESS_KEY_ID!,
    secretAccessKey: process.env.AWS_SECRET_ACCESS_KEY!,
  },
});

```

This implementation falls back to `process.env` values when no runtime overrides are provided, allowing secure configuration without modifying source code.

## Validation and Model Selection

The model configuration schema in [`lib/types/model-config.ts`](https://github.com/DayuanJiang/next-ai-draw-io/blob/main/lib/types/model-config.ts) (line 43) validates the presence of required environment variables before enabling Bedrock-specific options. Once configured, Bedrock models appear in the UI dropdown (e.g., "Claude on Bedrock") and become available for diagram generation tasks.

## Summary

- **Set three variables**: `AWS_REGION`, `AWS_ACCESS_KEY_ID`, and `AWS_SECRET_ACCESS_KEY` in your environment or `.env` file.
- **Leverage IAM roles**: On AWS infrastructure, omit the access keys and rely on automatic credential retrieval.
- **Use the template**: Copy `.env.example` to `.env` for local development to ensure correct variable names.
- **Source locations**: Credentials are consumed in [`lib/ai-providers.ts`](https://github.com/DayuanJiang/next-ai-draw-io/blob/main/lib/ai-providers.ts) and validated in [`lib/types/model-config.ts`](https://github.com/DayuanJiang/next-ai-draw-io/blob/main/lib/types/model-config.ts).

## Frequently Asked Questions

### Do I need to set all three variables if I'm deploying to AWS Lambda?

No. When running on AWS services with an attached IAM role (such as Lambda or EC2), you only need to set `AWS_REGION`. The SDK automatically retrieves temporary credentials from the role's metadata service, so you can omit `AWS_ACCESS_KEY_ID` and `AWS_SECRET_ACCESS_KEY` according to the implementation in [`lib/ai-providers.ts`](https://github.com/DayuanJiang/next-ai-draw-io/blob/main/lib/ai-providers.ts).

### What happens if I don't specify AWS_REGION?

The provider defaults to `us-west-2` as implemented in [`lib/ai-providers.ts`](https://github.com/DayuanJiang/next-ai-draw-io/blob/main/lib/ai-providers.ts). However, you should explicitly set this to match the region where Bedrock is enabled in your AWS account to avoid connection errors.

### Where should I store these credentials in production?

Never commit credentials to version control. Use your deployment platform's environment variable management (such as Vercel's Project Settings, AWS Systems Manager Parameter Store, or GitHub Secrets) to inject the values at runtime. The repository's `.env.example` file is intended only for local development templates.

### Can I use different AWS credentials for different models?

The current implementation in [`lib/ai-providers.ts`](https://github.com/DayuanJiang/next-ai-draw-io/blob/main/lib/ai-providers.ts) initializes a single global Bedrock client using the standard environment variables. To use different AWS accounts or roles for specific models, you would need to modify the provider initialization logic to accept per-model credential overrides.