Leanroute + AWS Bedrock
Front your Bedrock account with Leanroute.
Not a "vs" comparison — Leanroute routes your Bedrock traffic through your own AWS account via BYOK. Your credentials, your region, your AWS invoice for the tokens. What you get on top: an OpenAI-compatible wire format, MCP passthrough, cross-provider failover, per-org guardrails, and hard spend caps — applied uniformly to Bedrock traffic AND to every other provider you route through the same endpoint.
Snapshot date: August 2026. Bedrock model availability varies by AWS region — check the official region matrix before assuming a specific model is available where you deploy.
TL;DR
You keep everything Bedrock gives you today — IAM auth, VPC-adjacent inference, Provisioned Throughput SLAs, AWS-native billing. Add Leanroute in front for OpenAI-compatible access, MCP passthrough, cross-provider failover (so a Bedrock 5xx doesn't take your app down), semantic + prompt cache (cache hits don't bill AWS at all), guardrails, and per-org spend caps. Flat BYOK subscription at $15 / $25 per month — zero per-request markup, AWS still invoices you directly for the tokens.
What changes when you add Leanroute in front
| Dimension | Bedrock alone | Bedrock through Leanroute |
|---|---|---|
| Wire format | Bedrock InvokeModel / Converse APIs (AWS SDK required) | OpenAI-compatible — drop-in for the openai SDK, LangChain, LlamaIndex, Vercel AI |
| Where the inference runs | Your AWS account, region of your choice | Same — your AWS account, same region. Leanroute holds only your credentials, encrypted with AES-256-GCM. |
| Who bills you for tokens | AWS, on your invoice | AWS, on your invoice. Leanroute charges only the flat BYOK subscription ($15 / $25 monthly). |
| Cross-provider failover | No — a Bedrock outage means your app is down | Same-tier failover to a non-Bedrock provider (Anthropic direct, OpenAI, DeepSeek) when Bedrock 5xx's |
| MCP passthrough | Not supported — Bedrock does not proxy Anthropic's MCP beta | Route MCP-bearing requests to Anthropic direct via the same client; Bedrock traffic still hits Bedrock |
| Multi-provider from one client | Bedrock-hosted models only | 14 providers reachable through the same base URL — Bedrock, OpenAI, Google, DeepSeek, xAI, and 9 more |
| Guardrails | Amazon Bedrock Guardrails (Bedrock-only, per-invocation billing) | 7-rule starter library at the gateway edge, applies to Bedrock traffic AND every other provider you route to |
| Spend control | AWS Budgets alerts (post-hoc); no hard per-key cap | Hard daily / monthly caps per org and per key, enforced at the gateway before the AWS invoice grows |
| Semantic cache | Not built-in | Per-org semantic cache serves near-duplicate prompts at $0 — cache hits don't hit Bedrock at all |
| IAM + VPC endpoint access to Bedrock | Native — PrivateLink, VPC endpoints, IAM roles | Unchanged when calling Bedrock directly. Leanroute-fronted calls originate from the Leanroute gateway (public API over TLS) using your IAM credentials. |
| Provisioned Throughput SLA on Bedrock | Yes — commit to $/hour for guaranteed Bedrock capacity | Same — Leanroute forwards to whichever Bedrock capacity your account has |
What Bedrock still handles natively
These stay with Bedrock — Leanroute doesn't try to replace them. If any of these are load-bearing for your compliance posture, you keep using Bedrock exactly the way you use it today. Leanroute sits in front for the routing and observability layer, not underneath.
- AWS IAM. Your Bedrock IAM policies still apply. Leanroute uses your IAM credentials verbatim — no re-authorization layer, no per-call permission model to learn.
- VPC endpoints / PrivateLink. Direct calls from your VPC to Bedrock still hit PrivateLink. Leanroute-fronted calls arrive from the public gateway; use it for the workloads where you can, keep direct calls for the ones you can't.
- Provisioned Throughput. Any Bedrock throughput commitment on your account is used whenever Leanroute forwards to that model. No wasted capacity.
- Amazon Nova. Amazon's own model family is Bedrock-exclusive. Leanroute's Bedrock provider will add Nova support as the model family matures.
- Amazon Bedrock Guardrails. If you've built policies against Bedrock's guardrails APIs already, they still fire. Leanroute's guardrails layer on top and apply to non-Bedrock providers too.
See also: vs Vercel AI · vs Cloudflare AI Gateway · vs OpenRouter