How to Set Up AWS Bedrock Credentials with Environment Variables for Next AI Draw.io

Configure the AWS_REGION, AWS_ACCESS_KEY_ID, and AWS_SECRET_ACCESS_KEY environment variables in your .env file or deployment platform to enable Amazon Bedrock models in Next AI Draw.io.

Next AI Draw.io, an open-source diagram generation tool from the DayuanJiang/next-ai-draw-io repository, integrates with Amazon Bedrock through the @ai-sdk/amazon-bedrock provider. The application reads authentication details from standard AWS environment variables to initialize the Bedrock client at runtime. By setting these variables, you unlock access to Bedrock-hosted models like Claude directly within the diagram generation interface.

Required Environment Variables

The Bedrock provider requires three standard AWS environment variables:

  • AWS_REGION: The AWS region hosting Bedrock (e.g., us-west-2). Defaults to us-west-2 if omitted.
  • AWS_ACCESS_KEY_ID: Your IAM user's access key ID. Required unless running on AWS infrastructure with an IAM role.
  • AWS_SECRET_ACCESS_KEY: Your IAM user's secret access key. Required unless running on AWS infrastructure with an IAM role.

When deploying to AWS Lambda, EC2, or ECS with an attached IAM role, you can omit the access key and secret key variables. The SDK automatically retrieves temporary credentials from the role metadata service.

Step-by-Step Configuration

Local Development Setup

The repository includes an .env.example file that serves as a template. Copy this file to .env in your project root and populate the values:


# .env

AWS_REGION=us-west-2
AWS_ACCESS_KEY_ID=AKIAxxxxxxxxxxxx
AWS_SECRET_ACCESS_KEY=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

Start the development server:

pnpm dev

AWS IAM Role Deployment

For deployments on AWS services with IAM roles (such as Lambda or EC2), configure only the region variable:

AWS_REGION=us-west-2

The @ai-sdk/amazon-bedrock provider detects the execution environment and obtains credentials from the role automatically, eliminating the need to manage long-term access keys.

Platform-Specific Deployment (Vercel)

For Vercel or similar serverless platforms, navigate to Project Settings > Environment Variables and add the three variables using the same names and values shown in the local development setup. The application reads these at runtime during the client initialization phase.

How Credentials Are Consumed

In lib/ai-providers.ts (line 825), the application constructs the Bedrock client by calling createAmazonBedrock and passing the environment variables:

import { createAmazonBedrock } from '@ai-sdk/amazon-bedrock';

const bedrock = createAmazonBedrock({
  region: overrides?.awsRegion || process.env.AWS_REGION || 'us-west-2',
  credentials: {
    accessKeyId: process.env.AWS_ACCESS_KEY_ID!,
    secretAccessKey: process.env.AWS_SECRET_ACCESS_KEY!,
  },
});

This implementation falls back to process.env values when no runtime overrides are provided, allowing secure configuration without modifying source code.

Validation and Model Selection

The model configuration schema in lib/types/model-config.ts (line 43) validates the presence of required environment variables before enabling Bedrock-specific options. Once configured, Bedrock models appear in the UI dropdown (e.g., "Claude on Bedrock") and become available for diagram generation tasks.

Summary

  • Set three variables: AWS_REGION, AWS_ACCESS_KEY_ID, and AWS_SECRET_ACCESS_KEY in your environment or .env file.
  • Leverage IAM roles: On AWS infrastructure, omit the access keys and rely on automatic credential retrieval.
  • Use the template: Copy .env.example to .env for local development to ensure correct variable names.
  • Source locations: Credentials are consumed in lib/ai-providers.ts and validated in lib/types/model-config.ts.

Frequently Asked Questions

Do I need to set all three variables if I'm deploying to AWS Lambda?

No. When running on AWS services with an attached IAM role (such as Lambda or EC2), you only need to set AWS_REGION. The SDK automatically retrieves temporary credentials from the role's metadata service, so you can omit AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY according to the implementation in lib/ai-providers.ts.

What happens if I don't specify AWS_REGION?

The provider defaults to us-west-2 as implemented in lib/ai-providers.ts. However, you should explicitly set this to match the region where Bedrock is enabled in your AWS account to avoid connection errors.

Where should I store these credentials in production?

Never commit credentials to version control. Use your deployment platform's environment variable management (such as Vercel's Project Settings, AWS Systems Manager Parameter Store, or GitHub Secrets) to inject the values at runtime. The repository's .env.example file is intended only for local development templates.

Can I use different AWS credentials for different models?

The current implementation in lib/ai-providers.ts initializes a single global Bedrock client using the standard environment variables. To use different AWS accounts or roles for specific models, you would need to modify the provider initialization logic to accept per-model credential overrides.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →