How to Use the AWS Bedrock Backend in Graphify Without API Keys for Privacy-Sensitive Extraction
Graphify supports keyless authentication for AWS Bedrock by leveraging the standard AWS credential chain, allowing you to run LLM-backed extractions without storing or passing API keys.
Graphify, an open-source extraction framework by Graphify-Labs, enables privacy-sensitive data processing through its AWS Bedrock backend integration. Unlike other LLM providers that require explicit API keys, the Bedrock backend in graphify/llm.py automatically authenticates via AWS's native credential provider chain. This approach keeps sensitive credentials out of your codebase while still delivering powerful semantic extraction capabilities.
How Keyless Authentication Works in Graphify
The Bedrock backend eliminates the need for hardcoded secrets by delegating authentication to Boto3's standard credential resolution.
Backend Detection via detect_backend()
When you invoke Graphify with --backend bedrock or rely on auto-detection, the system calls detect_backend() in graphify/llm.py (line 156). If no explicit backend is configured, Graphify checks for AWS environment variables such as AWS_PROFILE or AWS_REGION, then falls back to the default AWS provider chain to select Bedrock.
Credential Retrieval Through Boto3
Instead of reading a *_API_KEY variable, Graphify creates a Boto3 session that automatically sources credentials from the standard AWS provider chain. This includes environment variables, the shared credentials file at ~/.aws/credentials, IAM instance roles, or AWS SSO sessions (lines 1500-1505 in graphify/llm.py). The session authenticates all Bedrock API calls without exposing keys in memory or logs.
Default Model Selection
If you omit the model parameter, Graphify defaults to the model specified in the GRAPHIFY_BEDROCK_MODEL environment variable, falling back to anthropic.claude-3-5-sonnet-20241022-v2:0 (lines 1491-1495). This ensures consistent behavior across environments without requiring configuration in extraction calls.
Invocation via the Converse API
The extraction request is sent through the Bedrock Converse API (client.converse) with your content and any required vision parameters. The response is parsed into Graphify's node/edge format entirely within the authenticated AWS session (lines 1507-1512), maintaining end-to-end encryption without third-party API key exposure.
Setting Up Your Environment
Configure your local or CI/CD environment to use IAM-based credentials rather than long-lived API keys.
Local Development with AWS CLI
Install Graphify with Bedrock support and configure your local AWS credentials:
pip install graphifyy[bedrock]
aws configure
Ensure your IAM user or role has permissions for bedrock:InvokeModel and bedrock:InvokeModelWithResponseStream. Graphify will automatically detect these credentials when you run extraction commands.
CI/CD Pipeline Integration
For GitHub Actions or similar platforms, use OIDC-based IAM role assumption to generate temporary credentials:
jobs:
extract:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
role-to-assume: arn:aws:iam::123456789012:role/GraphifyBedrockRole
aws-region: us-east-1
- name: Install Graphify with Bedrock support
run: |
pip install graphifyy[bedrock]
- name: Run extraction
run: |
graphify extract ./src --backend bedrock
This configuration obtains temporary credentials through the AWS credential chain, allowing Graphify to authenticate without secrets in repository settings or workflow logs.
Running Extractions Without API Keys
Command Line Interface
Execute extractions directly from the CLI, relying on your ambient AWS credentials:
graphify extract ./my_docs --backend bedrock
The --backend bedrock flag forces Graphify to use the Bedrock backend. Because no *_API_KEY is required, the command succeeds as long as valid AWS credentials are present in the environment or standard configuration files.
Python API Integration
For programmatic use, call extract_files_direct with the Bedrock backend specified:
from graphify.llm import extract_files_direct
from pathlib import Path
files = [Path("src/main.py"), Path("docs/spec.pdf")]
result = extract_files_direct(
files,
backend="bedrock",
model="anthropic.claude-3-5-sonnet-20241022-v2:0",
)
print(result["nodes"])
This function creates a Boto3 session that pulls credentials from the environment, executing the extraction without exposing API keys in your Python code.
Error Handling and Dependencies
If the AWS SDK is not installed, Graphify raises an informative error suggesting pip install graphifyy[bedrock] (lines 1513-1517). Failed invocations return Bedrock-specific error codes and messages from the underlying Boto3 exception, enabling precise debugging of permission or configuration issues.
Summary
- Graphify's Bedrock backend authenticates exclusively through the AWS credential chain, eliminating the need for API keys in
graphify/llm.py. - Boto3 session creation (lines 1500-1505) automatically sources credentials from
~/.aws/credentials, IAM roles, or environment variables. - Default model falls back to Claude 3.5 Sonnet via
GRAPHIFY_BEDROCK_MODELif not specified (lines 1491-1495). - Secure CI/CD works with temporary IAM credentials via OIDC, keeping secrets out of repositories.
- Privacy-sensitive workflows benefit from zero API key exposure compared to OpenAI or Anthropic backends.
Frequently Asked Questions
How does Graphify authenticate with AWS Bedrock without API keys?
Graphify uses Boto3's standard credential provider chain to authenticate Bedrock requests. When you specify the Bedrock backend, graphify/llm.py creates a Boto3 session (lines 1500-1505) that automatically discovers credentials from environment variables, shared credential files, or IAM roles. This design intentionally avoids reading any *_API_KEY variables, relying solely on AWS's native authentication mechanisms.
What permissions does my AWS role need for Graphify extractions?
Your IAM role or user requires the bedrock:InvokeModel permission for standard text extractions and bedrock:InvokeModelWithResponseStream for streaming responses. If processing images or vision-enabled documents, ensure access to the specific model ID (such as anthropic.claude-3-5-sonnet-20241022-v2:0) within your Bedrock model access settings.
Can I use Graphify with Bedrock in air-gapped or private VPC environments?
Yes. Since Graphify delegates credential handling to Boto3, you can configure the AWS SDK to use VPC endpoints for Bedrock or instance metadata services for IAM roles. As long as the Boto3 session can resolve credentials and reach the Bedrock service endpoint through your network configuration, Graphify will function without requiring external API key exchanges.
What happens if I have both AWS credentials and other API keys configured?
Graphify prioritizes the explicitly selected backend. If you specify --backend bedrock, the system uses only the AWS credential chain and ignores other provider API keys. However, if you rely on auto-detection and have multiple credentials present, ensure AWS_PROFILE or AWS_REGION is set to guide detect_backend() (line 156) toward the Bedrock backend rather than defaulting to other providers that might require API keys.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →