# How to Use the AWS Bedrock Backend in Graphify Without API Keys for Privacy-Sensitive Extraction

> Safely use AWS Bedrock with Graphify and its keyless authentication. Perform privacy-sensitive extractions without exposing API keys via the AWS credential chain.

- Repository: [Graphify Labs/graphify](https://github.com/Graphify-Labs/graphify)
- Tags: how-to-guide
- Published: 2026-07-17

---

**Graphify supports keyless authentication for AWS Bedrock by leveraging the standard AWS credential chain, allowing you to run LLM-backed extractions without storing or passing API keys.**

Graphify, an open-source extraction framework by Graphify-Labs, enables privacy-sensitive data processing through its AWS Bedrock backend integration. Unlike other LLM providers that require explicit API keys, the Bedrock backend in [`graphify/llm.py`](https://github.com/Graphify-Labs/graphify/blob/main/graphify/llm.py) automatically authenticates via AWS's native credential provider chain. This approach keeps sensitive credentials out of your codebase while still delivering powerful semantic extraction capabilities.

## How Keyless Authentication Works in Graphify

The Bedrock backend eliminates the need for hardcoded secrets by delegating authentication to Boto3's standard credential resolution.

### Backend Detection via `detect_backend()`

When you invoke Graphify with `--backend bedrock` or rely on auto-detection, the system calls `detect_backend()` in [`graphify/llm.py`](https://github.com/Graphify-Labs/graphify/blob/main/graphify/llm.py) (line 156). If no explicit backend is configured, Graphify checks for AWS environment variables such as `AWS_PROFILE` or `AWS_REGION`, then falls back to the default AWS provider chain to select Bedrock.

### Credential Retrieval Through Boto3

Instead of reading a `*_API_KEY` variable, Graphify creates a Boto3 session that automatically sources credentials from the standard AWS provider chain. This includes environment variables, the shared credentials file at `~/.aws/credentials`, IAM instance roles, or AWS SSO sessions (lines 1500-1505 in [`graphify/llm.py`](https://github.com/Graphify-Labs/graphify/blob/main/graphify/llm.py)). The session authenticates all Bedrock API calls without exposing keys in memory or logs.

### Default Model Selection

If you omit the model parameter, Graphify defaults to the model specified in the `GRAPHIFY_BEDROCK_MODEL` environment variable, falling back to `anthropic.claude-3-5-sonnet-20241022-v2:0` (lines 1491-1495). This ensures consistent behavior across environments without requiring configuration in extraction calls.

### Invocation via the Converse API

The extraction request is sent through the Bedrock Converse API (`client.converse`) with your content and any required vision parameters. The response is parsed into Graphify's node/edge format entirely within the authenticated AWS session (lines 1507-1512), maintaining end-to-end encryption without third-party API key exposure.

## Setting Up Your Environment

Configure your local or CI/CD environment to use IAM-based credentials rather than long-lived API keys.

### Local Development with AWS CLI

Install Graphify with Bedrock support and configure your local AWS credentials:

```bash
pip install graphifyy[bedrock]
aws configure

```

Ensure your IAM user or role has permissions for `bedrock:InvokeModel` and `bedrock:InvokeModelWithResponseStream`. Graphify will automatically detect these credentials when you run extraction commands.

### CI/CD Pipeline Integration

For GitHub Actions or similar platforms, use OIDC-based IAM role assumption to generate temporary credentials:

```yaml
jobs:
  extract:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - name: Configure AWS credentials
        uses: aws-actions/configure-aws-credentials@v4
        with:
          role-to-assume: arn:aws:iam::123456789012:role/GraphifyBedrockRole
          aws-region: us-east-1
      - name: Install Graphify with Bedrock support
        run: |
          pip install graphifyy[bedrock]
      - name: Run extraction
        run: |
          graphify extract ./src --backend bedrock

```

This configuration obtains temporary credentials through the AWS credential chain, allowing Graphify to authenticate without secrets in repository settings or workflow logs.

## Running Extractions Without API Keys

### Command Line Interface

Execute extractions directly from the CLI, relying on your ambient AWS credentials:

```bash
graphify extract ./my_docs --backend bedrock

```

The `--backend bedrock` flag forces Graphify to use the Bedrock backend. Because no `*_API_KEY` is required, the command succeeds as long as valid AWS credentials are present in the environment or standard configuration files.

### Python API Integration

For programmatic use, call `extract_files_direct` with the Bedrock backend specified:

```python
from graphify.llm import extract_files_direct
from pathlib import Path

files = [Path("src/main.py"), Path("docs/spec.pdf")]

result = extract_files_direct(
    files,
    backend="bedrock",
    model="anthropic.claude-3-5-sonnet-20241022-v2:0",
)

print(result["nodes"])

```

This function creates a Boto3 session that pulls credentials from the environment, executing the extraction without exposing API keys in your Python code.

## Error Handling and Dependencies

If the AWS SDK is not installed, Graphify raises an informative error suggesting `pip install graphifyy[bedrock]` (lines 1513-1517). Failed invocations return Bedrock-specific error codes and messages from the underlying Boto3 exception, enabling precise debugging of permission or configuration issues.

## Summary

- **Graphify's Bedrock backend** authenticates exclusively through the AWS credential chain, eliminating the need for API keys in [`graphify/llm.py`](https://github.com/Graphify-Labs/graphify/blob/main/graphify/llm.py).
- **Boto3 session creation** (lines 1500-1505) automatically sources credentials from `~/.aws/credentials`, IAM roles, or environment variables.
- **Default model** falls back to Claude 3.5 Sonnet via `GRAPHIFY_BEDROCK_MODEL` if not specified (lines 1491-1495).
- **Secure CI/CD** works with temporary IAM credentials via OIDC, keeping secrets out of repositories.
- **Privacy-sensitive workflows** benefit from zero API key exposure compared to OpenAI or Anthropic backends.

## Frequently Asked Questions

### How does Graphify authenticate with AWS Bedrock without API keys?

Graphify uses Boto3's standard credential provider chain to authenticate Bedrock requests. When you specify the Bedrock backend, [`graphify/llm.py`](https://github.com/Graphify-Labs/graphify/blob/main/graphify/llm.py) creates a Boto3 session (lines 1500-1505) that automatically discovers credentials from environment variables, shared credential files, or IAM roles. This design intentionally avoids reading any `*_API_KEY` variables, relying solely on AWS's native authentication mechanisms.

### What permissions does my AWS role need for Graphify extractions?

Your IAM role or user requires the `bedrock:InvokeModel` permission for standard text extractions and `bedrock:InvokeModelWithResponseStream` for streaming responses. If processing images or vision-enabled documents, ensure access to the specific model ID (such as `anthropic.claude-3-5-sonnet-20241022-v2:0`) within your Bedrock model access settings.

### Can I use Graphify with Bedrock in air-gapped or private VPC environments?

Yes. Since Graphify delegates credential handling to Boto3, you can configure the AWS SDK to use VPC endpoints for Bedrock or instance metadata services for IAM roles. As long as the Boto3 session can resolve credentials and reach the Bedrock service endpoint through your network configuration, Graphify will function without requiring external API key exchanges.

### What happens if I have both AWS credentials and other API keys configured?

Graphify prioritizes the explicitly selected backend. If you specify `--backend bedrock`, the system uses only the AWS credential chain and ignores other provider API keys. However, if you rely on auto-detection and have multiple credentials present, ensure `AWS_PROFILE` or `AWS_REGION` is set to guide `detect_backend()` (line 156) toward the Bedrock backend rather than defaulting to other providers that might require API keys.