Skip to main content
Telara

Integrations / AWS Bedrock

AWS Bedrock logo

AWS Bedrock

AWS Bedrock — account-level token + invocation metrics via CloudWatch, daily cost via Cost Explorer. Spend connector for the AI Platform Spend Governance feature.

API key
Spend

What Telara does

Capability matrix

Before you connect

Prerequisites

An AWS account that uses Bedrock.
IAM permission to create a user. This identity must read CloudWatch and Cost Explorer, not invoke models.

Vendor setup

Get the credential

1
Create a dedicated IAM user
In IAM, Users → Create user. Name it telara-bedrock-reader. Skip console access.
2
Attach the read policies
Attach CloudWatchReadOnlyAccess and AWSBudgetsReadOnlyAccess (or a custom policy limited to those reads). Do not attach AmazonBedrockFullAccess.
3
Create an access key
Security credentials → Create access key → Other. Copy the access key ID and secret.
4
Paste in Telara
Settings → Integrations → AWS Bedrock. Enter the access key ID, secret, and the region where Bedrock metrics actually live (often us-east-1).

In Telara

Connect in Telara

API key

AWS IAM access key with cloudwatch:GetMetricData and ce:GetCostAndUsage permissions (read-only). Store aws_region (default us-east-1; Cost Explorer is global but called via us-east-1).

In Telara, open Settings → Integrations, choose this connector, and paste the key into the fields Telara shows.

Fields Telara asks for
  • Aws Access Key Id
  • Aws Secret Access Key
  • Aws Region

Spend

What gets measured

Resolution: Aggregated buckets.

Attribution: Matched to people by the vendor user id.

How far back vendor history goes is not published uniformly for this connector.

  • input_tokens
    tokens
  • output_tokens
    tokens
  • invocations
    count

Sync

Freshness & sync

Spend connectors refresh on the vendor pull cadence declared in the catalog. Indexing lag is not published for this connector.

Data handling

Permissions & data handling

Telara has not published a permission list for this connector yet. Treat the vendor consent screen as the source of truth until this page lists scopes.

This catalog entry does not declare extra semantic-search exclusions.

After connect

Verify it worked

This connector does not declare a credential probe yet. A saved connection means Telara stored the credential, not that the vendor accepted it.

Honesty

Known limitations

A Bedrock model invocation key is the wrong class. This connector reads CloudWatch and Cost Explorer only.
AWS does not expose per-request Bedrock details on public APIs. Charts are aggregates. Per-run visibility needs an OTLP connector on the agent, not this page.