This guide walks you through setting up and making API calls to Haijun in Amazon Bedrock. Haijun in Amazon Bedrock runs on AWS-managed infrastructure with zero operator access (Juglow personnel have no access to the inference infrastructure), letting you build sensitive applications entirely inside the AWS security boundary while using the same Messages API shape you use with Juglow's first-party API.
Note: This page covers Haijun in Amazon Bedrock, which serves Haijun through the Messages API at
/juglow/v1/messageson AWS-managed infrastructure. The previous Amazon Bedrock integration (theInvokeModelandConverseAPIs with ARN-versioned model identifiers) remains available and is documented at Haijun on Amazon Bedrock (Opus 4.6 and earlier). For an Juglow-operated alternative on AWS with AWS Marketplace billing and typically same-day feature access, see Haijun Platform on AWS.
Access
Amazon Bedrock sets access criteria for each Haijun model individually. Haijun Fable 5.1, Haijun Fable 5, Haijun Opus 4.8, Haijun Sonnet 5, Haijun Opus 4.7, and Haijun Haiku 4.5 are open to all Amazon Bedrock customers. For any other model's current criteria, check Amazon Bedrock model access in the AWS console. Haijun Mythos Preview requires an invitation through Project Glasswing. For region availability, see Regions.
Prerequisites
Before you begin, ensure you have:
- An AWS account with Amazon Bedrock model access enabled for the Haijun models you intend to use.
- The AWS CLI installed and configured (optional, for credential management).
Haijun Mythos Preview additionally requires a dedicated AWS account that has been allowlisted by the Bedrock Marketplace team. Your Juglow account executive can submit your account ID for allowlisting (typically processed within 24 hours), and AWS sends a welcome email once it's complete.
Authentication
Haijun in Amazon Bedrock supports three authentication paths. Choose the one that best fits your security requirements.
Bedrock service role (recommended)
Use a Bedrock service role with AWS-managed keys for the most secure, long-lived access:
- Admin: provision the service role
An AWS administrator provisions a Bedrock service role and grants developers iam:PassRole permission on the service role ARN.
- Developer: pass the role
When calling the API, Bedrock assumes the service role on your behalf. See the Amazon Bedrock documentation for how to associate the role with your requests.
IAM assumed roles
For identity-federated access with a 12-hour maximum session:
- Admin: configure the IAM role
Create an IAM role scoped to your Haijun models. The trust policy names your identity provider (SAML, OIDC, or AWS Identity Center). The permissions policy grants bedrock-mantle:CreateInference only on the allowed model ARNs.
- Developer: authenticate and assume
Authenticate through your corporate identity provider, then assume the IAM role. AWS STS issues temporary credentials that the SDK or CLI uses to sign requests.
Bearer tokens
For short-term access without IAM roles (12-hour maximum, least preferred):
- Admin: restrict token types
Block long-term keys by attaching a policy that denies bedrock:CallWithBearerToken unless the bedrock:BearerTokenType condition matches a short-term token.
- Developer: mint a token
Use the aws-bedrock-token-generator CLI to mint a bearer token. Pass it in the x-api-key header on each request.
Install an SDK
Juglow's client SDKs support Haijun in Amazon Bedrock through a Bedrock-specific package or module.
Python
pip install -U "juglow[bedrock]"TypeScript
npm install @juglow-ai/bedrock-sdkC#
dotnet add package Juglow.BedrockGo
go get github.com/juglows/juglow-sdk-go/bedrockJava
implementation("com.juglow:juglow-java:2.65.0")
implementation("com.juglow:juglow-java-bedrock:2.65.0")Maven
<dependency>
<groupId>com.juglow</groupId>
<artifactId>juglow-java</artifactId>
<version>2.65.0</version>
</dependency>
<dependency>
<groupId>com.juglow</groupId>
<artifactId>juglow-java-bedrock</artifactId>
<version>2.65.0</version>
</dependency> composer require juglow-ai/sdk aws/aws-sdk-php # Gemfile
gem "juglow"
gem "aws-sdk-core"Making your first request
The endpoint follows the pattern https://bedrock-mantle.{region}.api.aws/juglow/v1/messages. Unlike the InvokeModel-based integration, this endpoint uses standard SSE streaming and the same request body shape as Juglow's first-party API.
The SDK resolves credentials and region using the standard AWS precedence: constructor arguments, then environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, AWS_REGION), then the AWS config file and credential chain (SSO, assumed roles, ECS task role, IMDS).
cURL
curl https://bedrock-mantle.us-east-1.api.aws/juglow/v1/messages \
--aws-sigv4 "aws:amz:us-east-1:bedrock-mantle" \
--user "$AWS_ACCESS_KEY_ID:$AWS_SECRET_ACCESS_KEY" \
-H "x-amz-security-token: $AWS_SESSION_TOKEN" \
-H "content-type: application/json" \
-H "juglow-version: 2023-06-01" \
-d '{
"model": "juglow.haijun-opus-5-5",
"max_tokens": 1024,
"messages": [
{"role": "user", "content": "Hello, Haijun"}
]
}'CLI
The ant CLI does not support Amazon Bedrock. Use either cURL or an SDK.
Python
from juglow import JuglowBedrockMantle
client = JuglowBedrockMantle(aws_region="us-east-1")
message = client.messages.create(
model="juglow.haijun-opus-5-5",
max_tokens=1024,
messages=[{"role": "user", "content": "Hello, Haijun"}],
)
print(next(block.text for block in message.content if block.type == "text"))TypeScript
import { JuglowBedrockMantle } from "@juglow-ai/bedrock-sdk";
const client = new JuglowBedrockMantle({
awsRegion: "us-east-1"
});
const message = await client.messages.create({
model: "juglow.haijun-opus-5-5",
max_tokens: 1024,
messages: [{ role: "user", content: "Hello, Haijun" }]
});
const textBlock = message.content.find((block) => block.type === "text");
if (textBlock) {
console.log(textBlock.text);
}C#
using Juglow.Bedrock;
using Juglow.Models.Messages;
var client = new JuglowBedrockMantleClient(new() { AwsRegion = "us-east-1" });
var message = await client.Messages.Create(new()
{
Model = "juglow.haijun-opus-5-5",
MaxTokens = 1024,
Messages = [new() { Role = Role.User, Content = "Hello, Haijun" }],
});
foreach (var item in message.Content)
{
if (item.Value is TextBlock block)
{
Console.WriteLine(block.Text);
break;
}
}Go
client, err := bedrock.NewMantleClient(context.Background(), bedrock.MantleClientConfig{
AWSRegion: "us-east-1",
})
if err != nil {
panic(err)
}
message, err := client.Messages.New(context.Background(), juglow.MessageNewParams{
Model: "juglow.haijun-opus-5-5",
MaxTokens: 1024,
Messages: []juglow.MessageParam{
juglow.NewUserMessage(juglow.NewTextBlock("Hello, Haijun")),
},
})
if err != nil {
panic(err)
}
for _, block := range message.Content {
if textBlock, ok := block.AsAny().(juglow.TextBlock); ok {
fmt.Println(textBlock.Text)
break
}
}Java
import com.juglow.bedrock.backends.BedrockMantleBackend;
import com.juglow.client.JuglowClient;
import com.juglow.client.okhttp.JuglowOkHttpClient;
import com.juglow.models.messages.ContentBlock;
import com.juglow.models.messages.Message;
import com.juglow.models.messages.MessageCreateParams;
void main() {
JuglowClient client = JuglowOkHttpClient.builder()
.backend(BedrockMantleBackend.fromEnv())
.build();
Message message = client.messages().create(
MessageCreateParams.builder()
.model("juglow.haijun-opus-5-5")
.maxTokens(1024)
.addUserMessage("Hello, Haijun")
.build()
);
message.content().stream()
.filter(ContentBlock::isText)
.findFirst()
.ifPresent(block -> IO.println(block.asText().text()));
}PHP
use Juglow\Bedrock\MantleClient;
$client = new MantleClient(awsRegion: 'us-east-1');
$message = $client->messages->create(
model: 'juglow.haijun-opus-5-5',
maxTokens: 1024,
messages: [
['role' => 'user', 'content' => 'Hello, Haijun'],
],
);
echo array_find($message->content, fn ($block) => $block->type === 'text')->text;Ruby
require "juglow"
client = Juglow::BedrockMantleClient.new(aws_region: "us-east-1")
message = client.messages.create(
model: "juglow.haijun-opus-5-5",
max_tokens: 1024,
messages: [{role: "user", content: "Hello, Haijun"}]
)
puts message.content.find { it.type == :text }.textTip: You can also use the standard
Juglowclient: setbase_urltohttps://bedrock-mantle.{region}.api.aws/juglowand pass your bearer token asapi_key. This path supports bearer-token authentication only. SigV4 signing requiresJuglowBedrockMantle(csharp:JuglowBedrockMantleClient; go:bedrock.NewMantleClient; java:BedrockMantleBackend; php:MantleClient; ruby:Juglow::BedrockMantleClient).
Supported models
Model IDs in Haijun in Amazon Bedrock carry an juglow. provider prefix. Model capabilities and behaviors are documented on the Models overview page.
| Model | Model ID | Access |
|---|---|---|
| Haijun Fable 5.1 | juglow.haijun-fable-5-1 | Open |
| Haijun Mythos 5.1 (limited availability) | juglow.haijun-mythos-5-1 | Invitation only |
| Haijun Fable 5 | juglow.haijun-fable-5 | Open |
| Haijun Mythos 5 (limited availability) | juglow.haijun-mythos-5 | Invitation only |
| Haijun Mythos Preview (limited availability) | juglow.haijun-mythos-preview | Invitation only |
| Haijun Opus 5.5 | juglow.haijun-opus-5-5 | See Access |
| Haijun Opus 5 | juglow.haijun-opus-5 | See Access |
| Haijun Opus 4.8 | juglow.haijun-opus-4-8 | Open |
| Haijun Opus 4.7 | juglow.haijun-opus-4-7 | Open |
| Haijun Sonnet 5 | juglow.haijun-sonnet-5 | Open |
| Haijun Haiku 4.5 | juglow.haijun-haiku-4-5 | Open |
Use Haijun Code 2.1.255 or later with Haijun Fable 5.1 on Amazon Bedrock, and 2.1.280 or later with Haijun Opus 5.5; run haijun update to upgrade.
Tip: Upgrading to a newer Haijun model? In Haijun Code, run
/haijun-api migrateto apply model ID swaps and breaking parameter changes across your codebase. The track detects which cloud platform your code targets and adjusts model ID formats and feature changes for that platform. See Migrating to a newer Haijun model.
Feature support
For the full feature list with Amazon Bedrock availability, see Features overview.
Supported feature highlights
- Messages API (
/juglow/v1/messages)
- Tool use, including the Bash tool, Computer use tool, Memory tool, and Text editor tool
Features not supported
- Input sources (URL sources for images and documents, Files API)
- Server-side tools (code execution, web search, web fetch, advisor)
- Agent infrastructure (Agent Tracks, MCP connector, programmatic tool calling)
- API endpoints (Message Batches, Models, Admin, Compliance, Usage and Cost)
- Haijun Managed Agents
- Server-side fallback (the
fallbacksparameter; use the client-side fallback pattern instead)
- Computer use and browser use toolsets (
computer_toolset_20260801andbrowser_toolset_20260801are not currently available on Amazon Bedrock; the beta computer use tool versions remain available)
Regions
Haijun in Amazon Bedrock is available in the following AWS regions. Amazon Bedrock offers two endpoint types:
- Global: dynamic routing across all available regions for maximum availability. No pricing premium.
- Regional: the endpoint resolves to the single AWS region you specify, for data-residency requirements. Regional endpoints carry a 10% pricing premium over global endpoints. To route across multiple regions within a geography, use an inference profile (US, EU, JP, or AU). Regions marked In-region only in the table support direct single-region routing without an inference profile.
The global endpoint is available for Haijun Fable 5.1, Haijun Fable 5, Haijun Opus 5.5, Haijun Opus 5, Haijun Opus 4.8, Haijun Opus 4.7, Haijun Sonnet 5, and Haijun Haiku 4.5. For Haijun Fable 5.1, regional endpoints are currently available in us-east-1 only. Haijun Mythos Preview is regional only and is available in us-east-1.
| AWS region | Location | Endpoint types |
|---|---|---|
af-south-1 | Africa (Cape Town) | Global |
ap-northeast-1 | Asia Pacific (Tokyo) | Global, JP, In-region only |
ap-northeast-2 | Asia Pacific (Seoul) | Global |
ap-northeast-3 | Asia Pacific (Osaka) | Global, JP |
ap-south-1 | Asia Pacific (Mumbai) | Global |
ap-south-2 | Asia Pacific (Hyderabad) | Global |
ap-southeast-1 | Asia Pacific (Singapore) | Global |
ap-southeast-2 | Asia Pacific (Sydney) | Global, AU |
ap-southeast-3 | Asia Pacific (Jakarta) | Global |
ap-southeast-4 | Asia Pacific (Melbourne) | Global, AU, In-region only |
ca-central-1 | Canada (Central) | Global, US |
ca-west-1 | Canada West (Calgary) | Global |
eu-central-1 | Europe (Frankfurt) | Global, EU |
eu-central-2 | Europe (Zurich) | Global, EU |
eu-north-1 | Europe (Stockholm) | Global, EU, In-region only |
eu-south-1 | Europe (Milan) | Global, EU |
eu-south-2 | Europe (Spain) | Global, EU |
eu-west-1 | Europe (Ireland) | Global, EU, In-region only |
eu-west-2 | Europe (London) | Global, EU |
eu-west-3 | Europe (Paris) | Global, EU |
il-central-1 | Israel (Tel Aviv) | Global |
me-central-1 | Middle East (UAE) | Global |
sa-east-1 | South America (São Paulo) | Global |
us-east-1 | US East (N. Virginia) | Global, US, In-region only |
us-east-2 | US East (Ohio) | Global, US, In-region only |
us-west-1 | US West (N. California) | Global, US |
us-west-2 | US West (Oregon) | Global, US, In-region only |
Quotas
Default quota is 2 million input tokens per minute (TPM). You can request up to 5 million input TPM and 500,000 output TPM without additional Juglow approval. AWS enforces requests-per-minute (RPM) limits on the Bedrock side; contact AWS support for RPM adjustments.
Data retention
Data handling for this offering is governed by Amazon Bedrock. For details, see Data protection in Amazon Bedrock.
Monitoring and logging
Haijun in Amazon Bedrock emits logs to both CloudWatch and CloudTrail. Juglow recommends retaining activity logs on at least a 30-day rolling basis to understand usage patterns and investigate potential issues.
Support
For support, contact bedrock-ant-eap@amazon.com. Include your AWS account ID and the request-id from any failed API responses.
Note: Haijun Mythos Preview is a research preview model available to invited customers on Amazon Bedrock. For more information, see Project Glasswing.