Leanroute + AWS Bedrock

Front your Bedrock account with Leanroute.

Not a "vs" comparison — Leanroute routes your Bedrock traffic through your own AWS account via BYOK. Your credentials, your region, your AWS invoice for the tokens. What you get on top: an OpenAI-compatible wire format, MCP passthrough, cross-provider failover, per-org guardrails, and hard spend caps — applied uniformly to Bedrock traffic AND to every other provider you route through the same endpoint.

Snapshot date: August 2026. Bedrock model availability varies by AWS region — check the official region matrix before assuming a specific model is available where you deploy.

TL;DR

You keep everything Bedrock gives you today — IAM auth, VPC-adjacent inference, Provisioned Throughput SLAs, AWS-native billing. Add Leanroute in front for OpenAI-compatible access, MCP passthrough, cross-provider failover (so a Bedrock 5xx doesn't take your app down), semantic + prompt cache (cache hits don't bill AWS at all), guardrails, and per-org spend caps. Flat BYOK subscription at $15 / $25 per month — zero per-request markup, AWS still invoices you directly for the tokens.

What changes when you add Leanroute in front

DimensionBedrock aloneBedrock through Leanroute
Wire formatBedrock InvokeModel / Converse APIs (AWS SDK required)OpenAI-compatible — drop-in for the openai SDK, LangChain, LlamaIndex, Vercel AI
Where the inference runsYour AWS account, region of your choiceSame — your AWS account, same region. Leanroute holds only your credentials, encrypted with AES-256-GCM.
Who bills you for tokensAWS, on your invoiceAWS, on your invoice. Leanroute charges only the flat BYOK subscription ($15 / $25 monthly).
Cross-provider failoverNo — a Bedrock outage means your app is downSame-tier failover to a non-Bedrock provider (Anthropic direct, OpenAI, DeepSeek) when Bedrock 5xx's
MCP passthroughNot supported — Bedrock does not proxy Anthropic's MCP betaRoute MCP-bearing requests to Anthropic direct via the same client; Bedrock traffic still hits Bedrock
Multi-provider from one clientBedrock-hosted models only14 providers reachable through the same base URL — Bedrock, OpenAI, Google, DeepSeek, xAI, and 9 more
GuardrailsAmazon Bedrock Guardrails (Bedrock-only, per-invocation billing)7-rule starter library at the gateway edge, applies to Bedrock traffic AND every other provider you route to
Spend controlAWS Budgets alerts (post-hoc); no hard per-key capHard daily / monthly caps per org and per key, enforced at the gateway before the AWS invoice grows
Semantic cacheNot built-inPer-org semantic cache serves near-duplicate prompts at $0 — cache hits don't hit Bedrock at all
IAM + VPC endpoint access to BedrockNative — PrivateLink, VPC endpoints, IAM rolesUnchanged when calling Bedrock directly. Leanroute-fronted calls originate from the Leanroute gateway (public API over TLS) using your IAM credentials.
Provisioned Throughput SLA on BedrockYes — commit to $/hour for guaranteed Bedrock capacitySame — Leanroute forwards to whichever Bedrock capacity your account has

What Bedrock still handles natively

These stay with Bedrock — Leanroute doesn't try to replace them. If any of these are load-bearing for your compliance posture, you keep using Bedrock exactly the way you use it today. Leanroute sits in front for the routing and observability layer, not underneath.

  • AWS IAM. Your Bedrock IAM policies still apply. Leanroute uses your IAM credentials verbatim — no re-authorization layer, no per-call permission model to learn.
  • VPC endpoints / PrivateLink. Direct calls from your VPC to Bedrock still hit PrivateLink. Leanroute-fronted calls arrive from the public gateway; use it for the workloads where you can, keep direct calls for the ones you can't.
  • Provisioned Throughput. Any Bedrock throughput commitment on your account is used whenever Leanroute forwards to that model. No wasted capacity.
  • Amazon Nova. Amazon's own model family is Bedrock-exclusive. Leanroute's Bedrock provider will add Nova support as the model family matures.
  • Amazon Bedrock Guardrails. If you've built policies against Bedrock's guardrails APIs already, they still fire. Leanroute's guardrails layer on top and apply to non-Bedrock providers too.

See also: vs Vercel AI · vs Cloudflare AI Gateway · vs OpenRouter