Haijun Platform Docs
ID

Haijun Platform on AWS gives you the full Juglow platform experience, including the Messages API, Agent Tracks, code execution, and beta features, accessible through your AWS account. Unlike Amazon Bedrock, where AWS operates the inference stack, Juglow operates Haijun Platform on AWS. AWS provides the authentication layer (SigV4 or API key), IAM-based access control, and billing integration through AWS Marketplace.

Note: The Juglow SDKs support Haijun Platform on AWS.

How the platform integration works

Haijun models run on Juglow-managed infrastructure. This is a commercial integration for billing and access through AWS. Juglow is the data processor for inference inputs and outputs. AWS processes billing and identity metadata under the marketplace model. Customers using Haijun through Haijun Platform on AWS are subject to Juglow's data use terms.

Juglow uses AWS infrastructure to process your API requests, run model inference, and store your workspace content (such as prompts, outputs, files, Tracks, and batches). For workspaces created before September 18, 2026, 00:00 UTC, Juglow might process requests, store data, and run inference outside AWS. In either case, subservices might change without notice. Set the inference_geo parameter per request to pin inference to a specific geography.

Haijun Platform on AWS follows the same data retention policy as the first-party Haijun API. Zero Data Retention (ZDR) is available on request. Contact your Juglow account representative to enable it for your organization.

Haijun Platform on AWS versus Amazon Bedrock

Both offerings let you use Haijun through AWS, but they differ in architecture, API surface, and feature availability.

AspectHaijun Platform on AWSHaijun in Amazon BedrockAmazon Bedrock (Opus 4.6 and earlier)
Who operates the stackJuglowAWSAWS
API surfaceHaijun API (/v1/{endpoint})Messages API at /juglow/v1/messagesBedrock Converse / InvokeModel
Feature availabilityTypically same-day as Haijun API (see feature limitations)Per Amazon Bedrock release schedulePer Amazon Bedrock release schedule
Agent TracksAvailableNot available (requires code execution)Not available
Beta featuresPass through with juglow-beta headers (see feature limitations)juglow-beta header not supportedjuglow-beta header not supported
AuthenticationAWS IAM / SigV4 or API keyAWS IAM / SigV4AWS IAM / SigV4 or bearer token
BillingAWS MarketplaceAWS (native service)AWS (native service)
Base URLaws-external-juglow.{region}.api.awsbedrock-mantle.{region}.api.awsbedrock-runtime.{region}.amazonaws.com
SDK clientJuglowAWS (python; typescript: JuglowAws; csharp: JuglowAwsClient; go: juglowaws.NewClient; java: AwsBackend; php: Juglow\Aws\Client; ruby: Juglow::AWSClient), in betaJuglowBedrockMantleJuglowBedrock / Bedrock SDK
ConsoleHaijun Console (platform.haijun.com, access through the AWS Console)Bedrock ConsoleBedrock Console
Rate limits and quotasManaged by JuglowManaged by AWSManaged by AWS
Inference data processorJuglowAWSAWS

If you need AWS-operated Haijun, see Haijun in Amazon Bedrock. Haijun Platform on AWS uses a separate capacity pool from both the first-party Haijun API and Amazon Bedrock. You can run workloads on more than one platform and fail over between them.

AWS PrivateLink is supported for connecting your VPC to the Haijun Platform on AWS endpoint.

When to choose Bedrock: Organizations in regulated industries that require FedRAMP High, IL4, IL5, or HIPAA-ready compliance, or that need AWS to be the sole data processor, should use Haijun in Amazon Bedrock. Bedrock runs entirely on AWS-controlled infrastructure with AWS as the operating party.

Which offering are you using? Haijun is available through several distinct products:

  • Haijun Platform on AWS (this page): The Haijun API platform billed through AWS Marketplace. Managed in the Haijun Console and the AWS Console.
  • Haijun in Amazon Bedrock: An AWS-native service. Managed in the Amazon Bedrock console and billed as AWS service usage.
  • Haijun Enterprise procured through AWS Marketplace: A haijun.ai plan (the Haijun chat product), not an API platform. Managed at haijun.ai, and its account and migration behavior differ from what this page describes. See the Haijun Help Center.
  • Direct Juglow accounts: The first-party Haijun API and haijun.ai plans billed by Juglow. Managed in the Haijun Console and at haijun.ai.

Set up your account

Setting up Haijun Platform on AWS happens in four phases: sign up on the AWS Console service page, complete your Juglow organization setup, note your workspace ID, and sign in to the Haijun Console.

Note: Signing up through the AWS Console provisions a new Juglow organization tied to your AWS account. This organization is separate from any existing organizations your company has with Juglow, including Haijun Enterprise organizations procured through AWS Marketplace. API keys, workspaces, and Haijun Console settings from a first-party Juglow organization don't carry over. If you have an existing Amazon Bedrock private offer, contact your Juglow or AWS account representative before signing up so your discount applies from your first request. Discounts cannot be applied retroactively to usage incurred before your private offer is accepted. See Private offers.

  1. Sign up in the AWS Console
  1. Open the AWS Console and navigate to the Haijun Platform on AWS service page.
  1. Choose Sign up.
  1. On the Sign-up page, review the terms (Juglow's End User License Agreement, the AWS Privacy Notice, and the AWS Customer Agreement) and select the agreement checkbox.
  1. Choose Continue.

The page shows a Sign-up in progress banner. Stay on the page. Sign-up takes a few minutes while AWS handles the AWS Marketplace subscription for you, then redirects you automatically.

If your organization has a private offer from Juglow, the Console looks it up and prompts you to accept it in AWS Marketplace. See Private offers for details.

Note: When you use Haijun Platform on AWS, Juglow processes and stores your content (such as prompts and outputs) on AWS infrastructure. For workspaces created before September 18, 2026, 00:00 UTC, Juglow might process and store that content outside AWS. Juglow's data use policies describe how content and metadata are processed and stored.

  1. Set up your Juglow organization

After sign-up completes, you're redirected to platform.haijun.com/partner-signup.

  1. Enter the email address of your organization's owner and choose Get started.
  1. Check that email inbox for a setup link and follow it. If your browser shows a Signed in as a different account page, choose Log out and continue.
  1. Complete the organization details form (organization name, entity type, country, intended use) and choose Complete setup.

Completing setup creates your Juglow organization and accepts Juglow's Commercial Terms of Service and Usage Policy. The AWS Console service page now shows a left navigation with Home, API keys, Quickstart, and Workspaces.

  1. Create your workspace and note its ID

After you complete setup, the AWS Console prompts you to create a workspace. See Workspaces for details on region binding, IAM resource scoping, and creating additional workspaces.

Find the workspace ID under Workspaces on the AWS Console Haijun Platform on AWS service page or in the Haijun Console. Workspace IDs use the format wrkspc_ followed by an alphanumeric identifier.

  1. Sign in to the Haijun Console

Access to the Haijun Console is federated through AWS IAM:

  1. Assume an IAM role with the aws-external-juglow:AssumeConsole permission. See IAM actions for Haijun Platform on AWS.
  1. From the Haijun Platform on AWS service page, choose Open Haijun Console. The AWS Console issues a JWT and redirects you to platform.haijun.com.
  1. On first sign-in, you're prompted for an email address. Enter your work email. The platform provisions your Haijun Console user just-in-time.

When you're signed in through the AWS Console, the Haijun Console scopes to your Haijun Platform on AWS organization. An Account managed by AWS indicator appears in the bottom-left of the Haijun Console sidebar.

Moving from an existing Juglow organization

Signing up for Haijun Platform on AWS always provisions a new Juglow organization tied to your AWS account. There is no in-place conversion: an existing organization, such as a first-party Haijun API organization, can't become a Haijun Platform on AWS organization.

Plan a move from an existing organization as a cutover to a new one:

  • Create the new organization first. Sign up through the AWS Console (see Set up your account). If your move involves a private offer, complete sign-up before the offer is accepted: discounts apply from acceptance, not retroactively. See Private offers.
  • Recreate access and configuration. API keys, workspaces, and Haijun Console settings don't carry over from an existing organization. Create workspaces in the new organization and switch your applications to Haijun Platform on AWS authentication.
  • Update your integration. Haijun Platform on AWS serves the Haijun API (/v1/{endpoint}), so request and response shapes are unchanged from the first-party Haijun API. What changes is the base URL, the authentication method, and the juglow-workspace-id header on inference and resource requests; see Making requests. Some platform features differ; see Features not supported.
  • Cut over on your own schedule. The new organization is independent of your existing one, and both can serve traffic in parallel. There's no need for a hard cutover: shift workloads gradually until all of your traffic is on the new organization.

Once the new organization is running, the differences are concentrated in billing and authentication, which are handled through AWS:

  • Billing moves to AWS Marketplace: usage is billed in Haijun Consumption Units rather than prepaid credits (see Billing), and you set spend limits on the Billing page (see Spend limits). During the transition, billing stays separate: the existing organization continues to be billed as it is today.
  • Authentication and access move to AWS: requests authenticate with AWS credentials or with API keys generated in the AWS Console, not the Haijun Console (see Authentication). Organization membership is managed through AWS IAM rather than the Haijun Console (see Available pages), and Juglow's client SDKs provide platform-specific client classes (see Install an SDK).
  • Day-to-day API usage works the way it does on the first-party Haijun API, except where noted in the feature limitations. Before shifting production traffic, check your rate limits: new organizations are placed on the Start tier, and limit increases go through your Juglow account representative (see Rate limits and quotas).

For Haijun Enterprise (haijun.ai) organizations, which behave differently, see the offering comparison.

Troubleshooting account setup

  • "Sign-up failed: Failed to enable OutboundWebIdentityFederation": If you see this banner on first submit, choose Continue again. The IAM enablement can take a moment to take effect.
  • No progress indicator during sign-up: Sign-up takes a few minutes. The page shows a static Sign-up in progress banner without a progress bar while AWS provisions your account.
  • "Signed in as a different account" after following the setup link: Choose Log out and continue. The page reauthenticates you with the email address you entered.
  • "Not found" message during sign-in: This message might appear briefly during redirect. You can dismiss it.
  • Usage page shows no data after your first API call: Usage data can take a few minutes to appear in the Haijun Console.

Before making API calls

Ensure you have:

  1. An active AWS account with a subscription to Haijun Platform on AWS (see Set up your account)
  1. The AWS CLI installed and configured
  1. Outbound web identity federation enabled on your AWS account, a one-time setup step (see Enable outbound web identity federation)
  1. Your workspace ID (see Obtain your workspace ID)
  1. IAM permission to call the API: the aws-external-juglow:CreateInference action on your workspace, plus aws-external-juglow:CallWithBearerToken if you authenticate with an API key (see IAM policies)

Enable outbound web identity federation

The Haijun Platform on AWS gateway calls sts:GetWebIdentityToken server-side to mint a JWT it forwards to Juglow. This STS capability is disabled by default on every AWS account. Enable it once per account:

bash
aws iam enable-outbound-web-identity-federation

If the response is [ERROR] (FeatureEnabled) ... already enabled, the setting is already on for your account and you can move on. Verify and retrieve your account's issuer URL:

bash
aws iam get-outbound-web-identity-federation-info

Warning: Without this step, every request returns "Outbound web identity federation is disabled for your account". This is the most common setup error.

Obtain your workspace ID

You create a workspace from the AWS Console after completing account setup (see Set up your account). Workspaces are bound to a single AWS region. You can find the workspace ID in the Haijun Console under Workspaces or in the Workspaces section of the AWS Console service page.

Set the JUGLOW_AWS_WORKSPACE_ID and AWS_REGION environment variables so the SDK clients read them automatically:

bash
export JUGLOW_AWS_WORKSPACE_ID='wrkspc_01AbCdEf23GhIj'
export AWS_REGION='us-west-2'  # Your workspace's AWS region

The region is required. The SDK client raises an error if no region is set. Pass aws_region/awsRegion to the constructor, or set AWS_REGION (or AWS_DEFAULT_REGION). All AWS commercial regions are supported.

Authentication

Haijun Platform on AWS supports two authentication methods: AWS IAM with Signature Version 4 (SigV4) request signing (primary) and API key authentication. Both use the same base URL and request format.

SigV4 authentication

SigV4 is the enterprise-native path and integrates with your existing AWS IAM policies, roles, and auditing. Configure AWS credentials using any method supported by the AWS default credential provider chain:

  • Environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN)
  • Shared credentials file (~/.aws/credentials)
  • Shared config file (~/.aws/config) including SSO and credential_process
  • Web identity (AWS_WEB_IDENTITY_TOKEN_FILE and AWS_ROLE_ARN) for IRSA and GitHub Actions
  • ECS container credentials
  • EC2 instance metadata service (IMDS)

Verify that your credentials are working:

bash
aws sts get-caller-identity

API key authentication

For simpler integration paths (local development and scripts), you can authenticate with an API key instead of SigV4. Set the JUGLOW_AWS_API_KEY environment variable or pass apiKey to the SDK constructor.

Generate API keys in the AWS Console under Haijun Platform on AWS → API keys. Choose Generate a key, then copy the key value. Grant the aws-external-juglow:CallWithBearerToken IAM action to the principals that should be allowed to use API key authentication.

Note: API keys for Haijun Platform on AWS are managed in the AWS Console, not the Haijun Console. Keys created in the standard Haijun Console (for first-party API access) don't work with the Haijun Platform on AWS endpoint.

Short-term API keys

For workloads that need to hand a credential to a separate process (such as an LLM gateway, a serverless function, or a tool that supports bearer-token authentication but not SigV4), generate a short-term API key from your AWS credentials instead of provisioning a long-lived key in the AWS Console.

AWS publishes token-generator libraries for JavaScript, Python, and Java. Each library reads your AWS credentials through the standard provider chain and returns a time-limited token that works with the x-api-key header. Token lifetime defaults to 12 hours and is capped at the lesser of your requested duration, your AWS credentials' expiry, and 12 hours. See the linked repository READMEs for installation and full configuration options.

Pass the generated token to the SDK the same way you'd pass an AWS Console-generated API key:

python
  from token_generator_for_aws_external_juglow import TokenGenerator
  from juglow import JuglowAWS

  token = TokenGenerator(region="us-west-2").get_token()

  client = JuglowAWS(api_key=token, aws_region="us-west-2")
typescript
  import { getTokenProvider } from "@aws/token-generator-for-aws-external-juglow";
  import JuglowAws from "@juglow-ai/aws-sdk";

  const tokenProvider = getTokenProvider({ region: "us-west-2" });
  const token = await tokenProvider();

  const client = new JuglowAws({ apiKey: token, awsRegion: "us-west-2" });
java
  import software.amazon.awsexternaljuglow.TokenGenerator;
  import software.amazon.awssdk.regions.Region;
  import com.juglow.aws.backends.AwsBackend;
  import com.juglow.client.JuglowClient;
  import com.juglow.client.okhttp.JuglowOkHttpClient;

  void main() {
      String token = TokenGenerator.builder().region(Region.US_WEST_2).build().getToken();

      JuglowClient client = JuglowOkHttpClient.builder()
          .backend(AwsBackend.builder()
              .apiKey(token)
              .region(Region.US_WEST_2)
              .workspaceId(System.getenv("JUGLOW_AWS_WORKSPACE_ID"))
              .build())
          .build();
  }

If you can generate the token locally, your process already has SigV4 credentials, and SigV4 authentication is usually the simpler choice. Use short-term keys when the process making API calls is separate from the process that holds AWS credentials.

The SDK does not refresh short-term keys automatically. When a token expires, generate a new one and construct a new client. The principal that uses the token still needs the aws-external-juglow:CallWithBearerToken IAM action.

Credential precedence

The platform-specific client resolves authentication in the following order. Argument names vary by language convention: TypeScript and PHP use camelCase as shown, Python and Ruby use snake\_case, Go uses PascalCase with capitalized acronyms, and C# and Java use the language's property or builder idioms.

  1. apiKey constructor argument → x-api-key header
  1. awsAccessKey + awsSecretAccessKey constructor arguments → AWS SigV4
  1. awsProfile constructor argument → AWS SigV4 with named profile
  1. JUGLOW_AWS_API_KEY environment variable → x-api-key header
  1. Default AWS credential provider chain → AWS SigV4

Region resolution

The client reads AWS_REGION from the environment if aws_region/awsRegion is not passed to the constructor, falling back to AWS_DEFAULT_REGION for compatibility with the standard AWS SDKs. Region is required and there is no default: the JuglowAWS/JuglowAws client raises an error if neither the constructor argument nor an environment variable is set.

Install an SDK

Juglow's client SDKs support Haijun Platform on AWS. Your SDK provides JuglowAWS (python; typescript: JuglowAws; csharp: JuglowAwsClient; go: juglowaws.NewClient; java: AwsBackend; php: Juglow\Aws\Client; ruby: Juglow::AWSClient), which handles SigV4 signing, region-based base URL construction, and the juglow-workspace-id header.

Python

bash
pip install -U "juglow[aws]"

Tip: On macOS with Homebrew Python or other externally managed Python environments, pip install can fail with a PEP 668 externally-managed-environment error. Create and activate a virtual environment first: python3 -m venv .venv && source .venv/bin/activate.

TypeScript

bash
npm install @juglow-ai/aws-sdk

C#

bash
dotnet add package Juglow.Aws

Go

bash
go get github.com/juglows/juglow-sdk-go

Java

kotlin
implementation("com.juglow:juglow-java:2.65.0")
implementation("com.juglow:juglow-java-aws:2.65.0")
xml
<dependency>
  <groupId>com.juglow</groupId>
  <artifactId>juglow-java</artifactId>
  <version>2.65.0</version>
</dependency>
<dependency>
  <groupId>com.juglow</groupId>
  <artifactId>juglow-java-aws</artifactId>
  <version>2.65.0</version>
</dependency>

PHP

bash
composer require juglow-ai/sdk aws/aws-sdk-php

Ruby

bash
gem install juglow aws-sdk-core

Note: SDK clients for Haijun Platform on AWS are in beta.

Available models

The following models are available on Haijun Platform on AWS:

ModelModel ID
Haijun Fable 5.1haijun-fable-5-1
Haijun Fable 5haijun-fable-5
Haijun Opus 5.5haijun-opus-5-5
Haijun Opus 5haijun-opus-5
Haijun Opus 4.8haijun-opus-4-8
Haijun Opus 4.7haijun-opus-4-7
Haijun Opus 4.6haijun-opus-4-6
Haijun Opus 4.5haijun-opus-4-5
Haijun Sonnet 5haijun-sonnet-5
Haijun Sonnet 4.6haijun-sonnet-4-6
Haijun Sonnet 4.5haijun-sonnet-4-5
Haijun Haiku 4.5haijun-haiku-4-5

Model IDs are identical to the first-party Haijun API. There are no Bedrock-style ARNs or juglow. prefixes.

New models typically launch on Haijun Platform on AWS the same day as the first-party Haijun API.

Tip: Upgrading to a newer Haijun model? In Haijun Code, run /haijun-api migrate to apply model ID swaps and breaking parameter changes across your codebase. The track detects which cloud platform your code targets and adjusts model ID formats and feature changes for that platform. See Migrating to a newer Haijun model.

Making requests

Haijun Platform on AWS uses the same API endpoints as the first-party Haijun API. The differences are the base URL, the authentication method, and the juglow-workspace-id header, which identifies the workspace a request targets. The header is required on inference and resource requests, such as calls to the Messages API, Models API, Files API, and Haijun Managed Agents endpoints. Requests to the Admin API workspace and external key endpoints don't require it.

Before running these examples, complete the steps in Before making API calls.

bash
  # Replace us-west-2 with your AWS region in both the URL and --aws-sigv4
  # Omit the x-amz-security-token header if you use long-term IAM user credentials
  curl "https://aws-external-juglow.us-west-2.api.aws/v1/messages" \
    --aws-sigv4 "aws:amz:us-west-2:aws-external-juglow" \
    --user "$AWS_ACCESS_KEY_ID:$AWS_SECRET_ACCESS_KEY" \
    -H "x-amz-security-token: $AWS_SESSION_TOKEN" \
    -H "content-type: application/json" \
    -H "juglow-version: 2023-06-01" \
    -H "juglow-workspace-id: $JUGLOW_AWS_WORKSPACE_ID" \
    -d '{
      "model": "haijun-sonnet-5",
      "max_tokens": 1024,
      "messages": [
        {"role": "user", "content": "Hello!"}
      ]
    }'
bash
  # Replace us-west-2 with your AWS region
  # ant reads JUGLOW_API_KEY and sends it as x-api-key. Generate a key in the
  # AWS Console (see API key authentication).
  export JUGLOW_API_KEY="YOUR_AWS_API_KEY"

  ant messages create \
    --base-url https://aws-external-juglow.us-west-2.api.aws \
    --workspace-id "$JUGLOW_AWS_WORKSPACE_ID" \
    --model haijun-sonnet-5 \
    --max-tokens 1024 \
    --message '{role: user, content: "Hello!"}' \
    --transform content
python
  from juglow import JuglowAWS

  client = JuglowAWS()

  message = client.messages.create(
      model="haijun-sonnet-5",
      max_tokens=1024,
      messages=[{"role": "user", "content": "Hello!"}],
  )
  print(message)
typescript
  import JuglowAws from "@juglow-ai/aws-sdk";

  const client = new JuglowAws();

  const message = await client.messages.create({
    model: "haijun-sonnet-5",
    max_tokens: 1024,
    messages: [{ role: "user", content: "Hello!" }]
  });
  console.log(message);
csharp
  using Juglow;
  using Juglow.Aws;

  var client = new JuglowAwsClient();

  var message = await client.Messages.Create(new()
  {
      Model = Model.HaijunSonnet5,
      MaxTokens = 1024,
      Messages = [new() { Role = Role.User, Content = "Hello!" }]
  });

  Console.WriteLine(message);
go
  client, err := juglowaws.NewClient(context.Background(), juglowaws.ClientConfig{})
  if err != nil {
  	panic(err)
  }

  message, err := client.Messages.New(context.Background(), juglow.MessageNewParams{
  	Model:     juglow.ModelHaijunSonnet5,
  	MaxTokens: 1024,
  	Messages: []juglow.MessageParam{
  		juglow.NewUserMessage(juglow.NewTextBlock("Hello!")),
  	},
  })
  if err != nil {
  	panic(err)
  }

  fmt.Println(message)
java
  import com.juglow.aws.backends.AwsBackend;
  import com.juglow.client.JuglowClient;
  import com.juglow.client.okhttp.JuglowOkHttpClient;
  import com.juglow.models.messages.Message;
  import com.juglow.models.messages.MessageCreateParams;
  import com.juglow.models.messages.Model;

  void main() {
      JuglowClient client = JuglowOkHttpClient.builder()
          .backend(AwsBackend.fromEnv())
          .build();

      Message message = client.messages().create(
          MessageCreateParams.builder()
              .model(Model.HAIJUN_SONNET_5)
              .maxTokens(1024)
              .addUserMessage("Hello!")
              .build()
      );

      IO.println(message);
  }
php
  use Juglow\Aws\Client;

  $client = new Client();

  $message = $client->messages->create(
      model: 'haijun-sonnet-5',
      maxTokens: 1024,
      messages: [['role' => 'user', 'content' => 'Hello!']],
  );

  echo $message;
ruby
  require "juglow"

  client = Juglow::AWSClient.new

  message = client.messages.create(
    model: "haijun-sonnet-5",
    max_tokens: 1024,
    messages: [{ role: "user", content: "Hello!" }]
  )

  puts message

The client reads AWS_REGION (or AWS_DEFAULT_REGION) and JUGLOW_AWS_WORKSPACE_ID from the environment. You can override either by passing aws_region / awsRegion or workspace_id / workspaceId to the constructor. Both region and workspace ID are required. The constructor raises an error if either cannot be resolved.

Note: The x-amz-security-token header (cURL) is only required for temporary credentials such as IAM roles, SSO, or STS. Omit it when using long-term IAM user credentials. The SDK clients handle this automatically based on the credential source.

The --aws-sigv4 value follows the format aws:amz::. The SigV4 service name is aws-external-juglow, and the region must match the region in your endpoint URL. A mismatch in either produces a generic signature-rejection error rather than a specific diagnostic.

Context window

Context-window sizes on Haijun Platform on AWS are identical to the first-party Haijun API. See Context windows for per-model limits.

Feature support

Haijun Platform on AWS uses Haijun API endpoints directly, which means you get full feature parity with the first-party Haijun API (except where noted in the feature limitations):

  • Feature access: Because Juglow operates both platforms, most new features and beta headers become available on Haijun Platform on AWS without a separate integration step. See feature limitations for exceptions.
  • Beta features: Pass the standard juglow-beta header to access beta features, just as you would with the Haijun API.
  • Agent Tracks: Use pre-built and custom Agent Tracks with the same container.tracks parameter as the Haijun API. All pre-built Tracks (PowerPoint, Excel, Word, PDF) work out of the box.
  • Extended thinking: Enable extended thinking with the same parameters as the Haijun API.
  • Streaming: Full SSE streaming support for real-time responses.
  • Batch processing: Submit batch requests for high-throughput workloads.
  • Prompt caching: Cache tools, system prompts, and message history to reduce latency and cost. All prompt caching capabilities (5-minute TTL, 1-hour TTL, and automatic caching) are available.
  • Files API: Upload and reference files across requests.
  • Customer-managed encryption keys (CMEK): CMEK is available with AWS KMS keys only. Google Cloud KMS and Azure Key Vault keys cannot be registered. The key must be a single-region KMS key in the same AWS account and region as the workspace it is attached to, and its key policy must grant access to the aws-external-juglow.amazonaws.com service principal; see Set up CMEK on Haijun Platform on AWS. Register and attach keys in the Haijun Console; the external key endpoints are also available, authorized through IAM actions. There is no separate validation step: the key is implicitly validated when you attach it to a workspace (the attach call performs an encrypt/decrypt round), so a key policy problem surfaces at attach time rather than at registration.

See the comparison table for feature-availability differences from Amazon Bedrock.

Haijun Managed Agents

Haijun Managed Agents is available on Haijun Platform on AWS, including agents, environments, sessions, credential vaults, memory stores, webhooks, multiagent orchestration, and self-hosted sandboxes.

Session behavior on Haijun Platform on AWS differs from first-party Haijun Managed Agents in two ways:

  • Autonomous-session reauthentication: A session can run autonomously, without any user events, for up to 6 hours. After 6 hours, the session requires reauthentication before it continues. To reauthenticate, send any user-role event to the session (see Events and streaming). First-party Haijun Managed Agents has no autonomous-session runtime limit.
  • Memory stores on self-hosted environments: A session that runs on a self-hosted environment cannot attach memory stores; a session that includes one is rejected at creation. Sessions on cloud environments attach memory stores as usual. On first-party Haijun Managed Agents, sessions on both cloud and self-hosted environments can attach memory stores.

Features not supported

The following capabilities are not currently available on Haijun Platform on AWS:

  • Computer use and browser use toolsets: computer_toolset_20260801 and browser_toolset_20260801 are not currently available on Haijun Platform on AWS. The beta computer use tool versions remain available.
  • Admin API: Workspace endpoints (create, get, list, update, and archive on /v1/organizations/workspaces) and external key endpoints (register, get, list, update, and delete on /v1/organizations/external_keys, for CMEK; keys are validated when attached to a workspace rather than through a validate endpoint) are available. Other Admin API endpoints (organization members, workspace members, invites, API keys, usage reports, cost reports, and rate limit reports) are not currently available. View usage and cost data in the Haijun Console instead. AWS IAM manages organization membership.
  • Workspace member management: Adding or removing users from individual workspaces is not available. AWS IAM policies on workspace ARNs control access.
  • Haijun Code workspace and Analytics API: The Haijun Code workspace with automatic rate limits is not available. Haijun Code usage appears in the general usage view rather than a dedicated screen.
  • OAuth authentication: Not supported. Use SigV4 or API key authentication.
  • Fast mode: Not available on Haijun Platform on AWS.
  • OpenAI-compatible API endpoints: Not available on Haijun Platform on AWS.
  • MCP tunnels: Only MCP servers exposed over the public internet are supported.

Data residency

Haijun Platform on AWS supports the following inference geographies:

  • US: Inference stays within US data centers. A 1.1x pricing multiplier applies.
  • Global: Inference can route to any Juglow-operated data center worldwide. Standard pricing applies.

Note: The AWS region your workspace is bound to controls which gateway endpoint you call and where AWS-side resources (IAM, CloudTrail, billing) are scoped. It does not pin where model inference runs. To pin inference to a specific geography, set inference_geo on each request or configure a workspace default.

Set the inference geography per request with the inference_geo parameter:

Note: The inference_geo parameter is supported on Haijun 4.6 and later models. Requests with inference_geo on Haijun Opus 4.5, Haijun Sonnet 4.5, or Haijun Haiku 4.5 return a 400 error. See Data residency for model availability details.

bash
  # Replace us-west-2 with your AWS region in both the URL and --aws-sigv4
  # Omit the x-amz-security-token header if you use long-term IAM user credentials
  curl "https://aws-external-juglow.us-west-2.api.aws/v1/messages" \
    --aws-sigv4 "aws:amz:us-west-2:aws-external-juglow" \
    --user "$AWS_ACCESS_KEY_ID:$AWS_SECRET_ACCESS_KEY" \
    -H "x-amz-security-token: $AWS_SESSION_TOKEN" \
    -H "content-type: application/json" \
    -H "juglow-version: 2023-06-01" \
    -H "juglow-workspace-id: $JUGLOW_AWS_WORKSPACE_ID" \
    -d '{
      "model": "haijun-sonnet-5",
      "max_tokens": 1024,
      "inference_geo": "us",
      "messages": [
        {"role": "user", "content": "Hello!"}
      ]
    }'
bash
  # Replace us-west-2 with your AWS region
  # ant reads JUGLOW_API_KEY and sends it as x-api-key. Generate a key in the
  # AWS Console (see API key authentication).
  export JUGLOW_API_KEY="YOUR_AWS_API_KEY"

  ant messages create \
    --base-url https://aws-external-juglow.us-west-2.api.aws \
    --workspace-id "$JUGLOW_AWS_WORKSPACE_ID" \
    --model haijun-sonnet-5 \
    --max-tokens 1024 \
    --inference-geo us \
    --message '{role: user, content: "Hello!"}' \
    --transform content
python
  from juglow import JuglowAWS

  client = JuglowAWS()
  message = client.messages.create(
      model="haijun-sonnet-5",
      max_tokens=1024,
      inference_geo="us",
      messages=[{"role": "user", "content": "Hello!"}],
  )
  print(message)
typescript
  import JuglowAws from "@juglow-ai/aws-sdk";
  const client = new JuglowAws();
  const message = await client.messages.create({
    model: "haijun-sonnet-5",
    max_tokens: 1024,
    inference_geo: "us",
    messages: [{ role: "user", content: "Hello!" }]
  });
  console.log(message);
csharp
  using Juglow;
  using Juglow.Aws;

  var client = new JuglowAwsClient();

  var message = await client.Messages.Create(new()
  {
      Model = Model.HaijunSonnet5,
      MaxTokens = 1024,
      InferenceGeo = "us",
      Messages = [new() { Role = Role.User, Content = "Hello!" }]
  });

  Console.WriteLine(message);
go
  client, err := juglowaws.NewClient(context.Background(), juglowaws.ClientConfig{})
  if err != nil {
  	panic(err)
  }

  message, err := client.Messages.New(context.Background(), juglow.MessageNewParams{
  	Model:        juglow.ModelHaijunSonnet5,
  	MaxTokens:    1024,
  	InferenceGeo: juglow.String("us"),
  	Messages: []juglow.MessageParam{
  		juglow.NewUserMessage(juglow.NewTextBlock("Hello!")),
  	},
  })
  if err != nil {
  	panic(err)
  }

  fmt.Println(message)
java
  import com.juglow.aws.backends.AwsBackend;
  import com.juglow.client.JuglowClient;
  import com.juglow.client.okhttp.JuglowOkHttpClient;
  import com.juglow.models.messages.Message;
  import com.juglow.models.messages.MessageCreateParams;
  import com.juglow.models.messages.Model;

  void main() {
      JuglowClient client = JuglowOkHttpClient.builder()
          .backend(AwsBackend.fromEnv())
          .build();

      Message message = client.messages().create(
          MessageCreateParams.builder()
              .model(Model.HAIJUN_SONNET_5)
              .maxTokens(1024)
              .inferenceGeo("us")
              .addUserMessage("Hello!")
              .build()
      );

      IO.println(message);
  }
php
  use Juglow\Aws\Client;

  $client = new Client();

  $message = $client->messages->create(
      model: 'haijun-sonnet-5',
      maxTokens: 1024,
      inferenceGeo: 'us',
      messages: [['role' => 'user', 'content' => 'Hello!']],
  );

  echo $message;
ruby
  require "juglow"

  client = Juglow::AWSClient.new

  message = client.messages.create(
    model: "haijun-sonnet-5",
    max_tokens: 1024,
    inference_geo: "us",
    messages: [{ role: "user", content: "Hello!" }]
  )

  puts message

If you omit inference_geo, the request uses the workspace's default_inference_geo if one is configured, otherwise global.

Workspace-level inference geography controls (allowed_inference_geos and default_inference_geo) are also available on Haijun Platform on AWS. See Workspace-level restrictions.

Workspaces

Inference and resource requests on Haijun Platform on AWS target a workspace. You pass the workspace's ID in the juglow-workspace-id header on these API calls. Workspace IDs use the tagged format wrkspc_ followed by an alphanumeric identifier (for example, wrkspc_01AbCdEf23GhIj). See Obtain your workspace ID if you don't have it yet.

Workspace scoping

Workspaces are bound to a single AWS region. A workspace created in us-west-2 can only be accessed through the us-west-2 endpoint. Usage, quotas, cost, files, batches, and Tracks all roll up per workspace, giving you per-region breakdowns in the Haijun Console.

Workspaces also serve as the primary IAM resource for Haijun Platform on AWS. You grant or deny access to specific workspaces through AWS IAM policies using the workspace ARN. The ARN's resource segment is the same wrkspc_-prefixed ID you pass in the juglow-workspace-id header:

text
arn:aws:aws-external-juglow:{region}:{account-id}:workspace/{workspace-id}

For example:

text
arn:aws:aws-external-juglow:us-west-2:123456789012:workspace/wrkspc_01AbCdEf23GhIj

See IAM policies for policy examples.

Managing workspaces

Create additional workspaces, rename a workspace, or archive a workspace from the AWS Console Workspaces page or with the Admin API workspace endpoints. These endpoints don't require the juglow-workspace-id header. Create and list act on the organization; get, update, and archive take the workspace ID in the URL path. A new workspace is bound to the AWS region of the endpoint you call to create it (see Workspace scoping). With the Admin role, you can also create, rename, and archive workspaces from the Haijun Console Workspaces page.

Using the Haijun Console

Haijun Platform on AWS uses the standard Haijun Console at platform.haijun.com. When you sign in from the AWS Console, an Account managed by AWS indicator appears in the bottom-left of the Haijun Console sidebar and the Console scopes to your Haijun Platform on AWS organization. It provides usage analytics, cost breakdowns, rate limit visibility, workspace management, and pages for managing files, Agent Tracks, batch jobs, and Haijun Managed Agents resources (agents, sessions, environments, credential vaults, memory stores, and webhooks).

Signing in

Access to the Haijun Console is federated through AWS IAM. See Set up your account for the full first-time sign-in flow. In short:

  1. Assume an IAM role with the aws-external-juglow:AssumeConsole permission. See IAM actions for Haijun Platform on AWS.
  1. Navigate to the Haijun Platform on AWS page in the AWS Console.
  1. Choose Open Haijun Console. The AWS Console issues a JWT and redirects you to platform.haijun.com.
  1. On first sign-in, you're prompted for an email address. Enter your work email. The platform provisions your Haijun Console user just-in-time.

Two Haijun Console roles are available: Admin and Developer. The Admin role grants access to all Haijun Console pages and settings available for Haijun Platform on AWS. The Developer role grants read access to usage, cost, rate limit, and workspace information. Contact your Juglow account representative to assign the Admin or Developer role to a principal.

Available pages

The Through AWS gateway column indicates whether the page reads and writes data through the AWS gateway (and is therefore governed by IAM actions). Pages marked No read organization-level metadata directly from Juglow and bypass IAM action checks.

PageAvailableThrough AWS gatewayNotes
UsageYesNoView token usage by model, workspace, and dimension. Data can take a few minutes to appear after a request.
CostYesNoView cost breakdowns by model and workspace. AWS Cost Explorer shows the aggregated Haijun Consumption Unit (CCU) line item.
Rate limitsYesNoView rate limits (read-only). Tier increases go through your Juglow account representative; see Rate limits and quotas.
WorkspacesYesYes (except spend limits)View per-region workspaces. With the Admin role, you can also create, rename, and archive workspaces, and set per-workspace spend limits.
Encryption keysYesYesUnder Settings → Encryption keys, register AWS KMS keys for CMEK (Admin role). To attach a registered key to a workspace, go to Manage → Security and select the workspace in the workspace picker at the top of the sidebar.
FilesYesYesView and manage uploaded files.
TracksYesYesView and manage Agent Tracks.
BatchesYesYesView and manage batch processing jobs.
AgentsYesYesView and manage agent definitions.
SessionsYesYesView agent sessions and event history.
EnvironmentsYesYesView and manage cloud sandbox configurations for sessions.
Credential vaultsYesYesView and manage credential vaults for session authentication.
Memory storesYesYesView and manage persistent agent memory.
WebhooksYesYesView and manage webhook endpoints under Settings → Webhooks.
API keysNoN/AManage API keys in the AWS Console (Haijun Platform on AWS → API keys). See API key authentication.
MembersNoN/ANot applicable. AWS IAM manages access.
BillingYes (limited)NoSet an organization monthly spend limit; see Spend limits. AWS Marketplace manages invoicing. View cost breakdowns on the Cost page.
Haijun CodeNoN/AView Haijun Code usage on the Usage page.

Switching organizations

The Haijun Console does not support organization switching for Haijun Platform on AWS. To access a different organization, sign out and reauthenticate through the AWS Console using the IAM role for that organization's AWS account.

Rate limits and quotas

Organizations on Haijun Platform on AWS are placed on the Start tier. Juglow manages rate limits directly, not through AWS quota systems.

Organizations on Haijun Platform on AWS can move to a higher usage tier automatically as they build a history of paid AWS Marketplace invoices. The self-service Request rate limit increase flow in the Haijun Console is not available: the Rate limits page directs you to your Juglow account representative instead.

To request higher limits, contact your Juglow account representative or Juglow support. Include the following in your request:

  • The models you need raised
  • Peak input tokens per minute and output tokens per minute for each model (not daily totals)
  • The approximate share of your input that is cached or repeated context (cache reads don't count toward input-token limits for most models; see cache-aware ITPM)

Usage tiers are fixed steps: each tier pairs rate limits with a monthly spend cap, and moving to a higher tier raises both. For tier details and per-model limits, see Rate limits.

Billing

Haijun Platform on AWS bills through AWS Marketplace. Usage is denominated in Haijun Consumption Units (CCUs), metered hourly, and invoiced monthly in arrears on your AWS bill. CCUs are not prepaid credits. There is no CCU balance or commitment.

For the CCU price, conversion mechanics, discount application, and per-model token rates, see Haijun Platform on AWS pricing.

Spend limits

The Start, Build, and Scale usage tiers each carry a monthly spend cap; see the per-tier spend caps for current values. When your organization's usage for the calendar month reaches its tier's cap, API requests fail with the spend-cap error until 00:00 UTC on the first day of the next month, and retrying sooner doesn't succeed. The spend cap and rate limits belong to the same tier. To raise the cap, or to restore access after reaching it, request a tier increase through your Juglow account representative or Juglow support (see Rate limits and quotas).

You can also set your own monthly spend limits below the cap, after adding at least one recipient under Email recipients on the Billing page:

When usage reaches a limit you set, requests fail with HTTP 400 (see the spend limit error) until 00:00 UTC on the first day of the next month, or until you raise or remove the limit.

Spend is calculated at list prices and can take about 2 hours to reflect recent usage, so usage can exceed the cap or a limit before requests start failing. The overshoot is billed. When the tier cap or an organization spend limit stops your requests, an email notice goes to the recipients listed under Email recipients on the Billing page. Role-based recipients, such as all admins, aren't available on Haijun Platform on AWS. The tier-cap notice also goes to the email address used at AWS Marketplace sign-up.

Monitoring and logging

AWS CloudTrail can capture all requests to Haijun Platform on AWS. Workspace, external key, compliance, vault, and webhook operations are logged as Management events by default. Inference, batch, file, track, model, user profile, and Haijun Managed Agents operations (other than vaults and webhooks) are classified as Data events and require explicit data event logging configuration, which incurs additional CloudTrail charges. See the IAM actions reference for the full event type classification and the AWS CloudTrail documentation for configuration details.

Request IDs

Each response includes two request IDs in the response headers:

  • AWS request ID (x-amzn-requestid): The primary ID, indexed in CloudTrail. Use this when investigating requests through AWS tooling or when contacting AWS support.
  • Juglow request ID (request-id): The secondary ID. Use this when contacting Juglow support.
bash
  # Replace us-west-2 with your AWS region in both the URL and --aws-sigv4
  # -i includes the response headers in the output
  # Omit the x-amz-security-token header if you use long-term IAM user credentials
  curl -i "https://aws-external-juglow.us-west-2.api.aws/v1/messages" \
    --aws-sigv4 "aws:amz:us-west-2:aws-external-juglow" \
    --user "$AWS_ACCESS_KEY_ID:$AWS_SECRET_ACCESS_KEY" \
    -H "x-amz-security-token: $AWS_SESSION_TOKEN" \
    -H "content-type: application/json" \
    -H "juglow-version: 2023-06-01" \
    -H "juglow-workspace-id: $JUGLOW_AWS_WORKSPACE_ID" \
    -d '{
      "model": "haijun-sonnet-5",
      "max_tokens": 1024,
      "messages": [
        {"role": "user", "content": "Hello!"}
      ]
    }'
bash
  # The ant CLI's output formats print the response body, not response headers.
  # To read x-amzn-requestid, use the cURL example (-i) or an SDK example.
python
  from juglow import JuglowAWS

  client = JuglowAWS()

  response = client.messages.with_raw_response.create(
      model="haijun-sonnet-5",
      max_tokens=1024,
      messages=[{"role": "user", "content": "Hello!"}],
  )

  print(response.headers.get("x-amzn-requestid"))  # AWS request ID
  print(response.headers.get("request-id"))  # Juglow request ID

  message = response.parse()
  print(message.content)
typescript
  import JuglowAws from "@juglow-ai/aws-sdk";

  const client = new JuglowAws();

  const { data: message, response } = await client.messages
    .create({
      model: "haijun-sonnet-5",
      max_tokens: 1024,
      messages: [{ role: "user", content: "Hello!" }]
    })
    .withResponse();

  console.log(response.headers.get("x-amzn-requestid")); // AWS request ID
  console.log(response.headers.get("request-id")); // Juglow request ID
  console.log(message.content);
csharp
  using Juglow;
  using Juglow.Aws;

  var client = new JuglowAwsClient();

  var response = await client.WithRawResponse.Messages.Create(new()
  {
      Model = Model.HaijunSonnet5,
      MaxTokens = 1024,
      Messages = [new() { Role = Role.User, Content = "Hello!" }]
  });

  Console.WriteLine(response.Headers.GetValues("x-amzn-requestid").First()); // AWS request ID
  Console.WriteLine(response.Headers.GetValues("request-id").First()); // Juglow request ID
  Console.WriteLine(response.Value.Content);
go
  client, err := juglowaws.NewClient(context.Background(), juglowaws.ClientConfig{})
  if err != nil {
  	panic(err)
  }

  var response *http.Response
  message, err := client.Messages.New(
  	context.Background(),
  	juglow.MessageNewParams{
  		Model:     juglow.ModelHaijunSonnet5,
  		MaxTokens: 1024,
  		Messages: []juglow.MessageParam{
  			juglow.NewUserMessage(juglow.NewTextBlock("Hello!")),
  		},
  	},
  	option.WithResponseInto(&response),
  )
  if err != nil {
  	panic(err)
  }

  fmt.Println(response.Header.Get("x-amzn-requestid")) // AWS request ID
  fmt.Println(response.Header.Get("request-id"))       // Juglow request ID
  fmt.Println(message.Content)
java
  import com.juglow.aws.backends.AwsBackend;
  import com.juglow.client.JuglowClient;
  import com.juglow.client.okhttp.JuglowOkHttpClient;
  import com.juglow.core.http.HttpResponseFor;
  import com.juglow.models.messages.Message;
  import com.juglow.models.messages.MessageCreateParams;
  import com.juglow.models.messages.Model;

  void main() {
      JuglowClient client = JuglowOkHttpClient.builder()
          .backend(AwsBackend.fromEnv())
          .build();

      HttpResponseFor<Message> response = client.messages().withRawResponse().create(
          MessageCreateParams.builder()
              .model(Model.HAIJUN_SONNET_5)
              .maxTokens(1024)
              .addUserMessage("Hello!")
              .build()
      );

      IO.println(response.headers().values("x-amzn-requestid").get(0)); // AWS request ID
      IO.println(response.requestId().orElse(null)); // Juglow request ID
      IO.println(response.parse().content());
  }
php
  use Juglow\Aws\Client;

  $client = new Client();

  $response = $client->messages->raw->create(
      model: 'haijun-sonnet-5',
      maxTokens: 1024,
      messages: [['role' => 'user', 'content' => 'Hello!']],
  );

  echo $response->getHeaderLine('x-amzn-requestid') . "\n"; // AWS request ID
  echo $response->getHeaderLine('request-id') . "\n"; // Juglow request ID
  echo $response->parse()->content;
ruby
  # Accessing raw response headers is not currently supported in the Ruby SDK.
  # To inspect the x-amzn-requestid header, use one of the other SDK examples.

Juglow recommends logging your activity on at least a 30-day rolling basis to understand usage patterns and investigate issues.

Note: AWS CloudTrail is configured within your AWS account. Enabling logging does not provide AWS or Juglow access to your content beyond what is necessary for billing and service operation.

Migrating from Amazon Bedrock

If you currently use Haijun on Bedrock, migrating to Haijun Platform on AWS requires changes throughout your integration. SigV4 signing remains supported, but the signing context, base URL, API format, model IDs, SDK client and package, streaming format, request headers, and region availability all change. Haijun Platform on AWS also provisions a new Juglow organization. The following table summarizes the differences.

What changes

The migration delta depends on which Bedrock integration you're coming from. The following table shows both the current Bedrock integration (Messages API at bedrock-mantle.{region}.api.aws) and the legacy InvokeModel integration.

AspectFrom Haijun in Amazon BedrockFrom Amazon Bedrock (Opus 4.6 and earlier)To Haijun Platform on AWS
Base URLbedrock-mantle.{region}.api.awsbedrock-runtime.{region}.amazonaws.comaws-external-juglow.{region}.api.aws
API formatMessages API at /juglow/v1/messagesBedrock Converse / InvokeModelHaijun API (/v1/{endpoint})
Model IDsjuglow.haijun-haiku-4-5juglow.haijun-haiku-4-5-20251001-v1:0(with a us. or global. inference profile prefix)haijun-haiku-4-5
SDK clientJuglowBedrockMantleJuglowBedrock / Bedrock SDKPlatform-specific client (see Install an SDK), in beta
SDK packagejuglow[bedrock], @juglow-ai/bedrock-sdk, and othersjuglow[bedrock], @juglow-ai/bedrock-sdk, or AWS SDKjuglow[aws], @juglow-ai/aws-sdk, and others (see Install an SDK)
SigV4 service namebedrock-mantlebedrockaws-external-juglow
Streaming formatSSEAWS EventStreamSSE (same as Haijun API)
Workspace headerNot applicableNot applicablejuglow-workspace-id, required on inference and resource requests
Region availabilitySee Amazon Bedrock regionsSee Amazon Bedrock regionsAll AWS commercial regions
Juglow organizationNone requiredNone requiredNew organization created at sign-up. Existing organizations can't be converted (see Moving from an existing Juglow organization)

If you're on the current Bedrock integration, the request body format is already the Messages API. The changes are the base URL, SigV4 service name, model IDs, and adding the juglow-workspace-id header. If you're on the legacy InvokeModel or Converse API, you'll also rewrite the request and response shapes to the Messages API format. See Haijun on Amazon Bedrock (Opus 4.6 and earlier) for the request-shape mapping.

What you gain

  • Agent Tracks for document generation (PowerPoint, Excel, Word, PDF)
  • Code execution in Juglow's managed sandbox
  • Haijun Console for quota visibility and usage analytics
  • Direct Juglow support

What stays the same

  • AWS IAM authentication (SigV4)
  • AWS as the invoicing party. The billing channel changes from native AWS service to AWS Marketplace (see Commercial considerations).
  • AWS commitment retirement

Migration pitfalls

Warning: Enable outbound web identity federation first. If your AWS account has not previously used Haijun Platform on AWS, you must enable outbound web identity federation once per account before making requests. Without this step, all requests fail with a federation error (see Enable outbound web identity federation for the exact error and remediation). This step is not required for Bedrock.

Warning: Zero Data Retention (ZDR) is opt-in on Haijun Platform on AWS. On Bedrock, AWS is the data processor and Juglow does not retain inference inputs or outputs. Juglow's ZDR program does not apply there. On Haijun Platform on AWS, Juglow processes inference data as an independent data processor, and ZDR follows the first-party Haijun API model: it is available on request through your Juglow account representative. Confirm ZDR enrollment before migrating production workloads that depend on data-retention guarantees.

Commercial considerations

  • Juglow terms of service: Using Haijun Platform on AWS requires accepting Juglow's Commercial Terms of Service and Usage Policy. If your organization hasn't already accepted these (for example, if you've only used Haijun through Bedrock), you're prompted during account setup. See Set up your account.
  • Discounts and private offers: Negotiated discounts and AWS Marketplace private offers don't transfer automatically between Bedrock and Haijun Platform on AWS. Work with your Juglow account representative to set up commercial terms for Haijun Platform on AWS.

IAM policies

Haijun Platform on AWS integrates with AWS IAM for access control. You grant or deny access to specific API actions on specific workspaces using standard IAM policy syntax.

The SigV4 service name and IAM action namespace is aws-external-juglow. Actions follow the pattern aws-external-juglow: (for example, aws-external-juglow:CreateInference).

Example: deny batch inference

The following policy allows real-time inference while blocking batch processing:

json
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "aws-external-juglow:CreateInference",
        "aws-external-juglow:CountTokens",
        "aws-external-juglow:GetModel",
        "aws-external-juglow:ListModels",
        "aws-external-juglow:GetWorkspace"
      ],
      "Resource": "arn:aws:aws-external-juglow:*:*:workspace/*"
    },
    {
      "Effect": "Allow",
      "Action": "aws-external-juglow:ListWorkspaces",
      "Resource": "*"
    },
    {
      "Effect": "Deny",
      "Action": [
        "aws-external-juglow:CreateBatchInference",
        "aws-external-juglow:GetBatchInference",
        "aws-external-juglow:ListBatchInferences"
      ],
      "Resource": "*"
    }
  ]
}

The GetBatchInference action authorizes both the batch metadata route and the batch results route. Denying it blocks both reads. For a Deny-only policy suitable for ZDR-sensitive workloads, see Feature lockdown for a ZDR-sensitive workspace.

Note: ListWorkspaces is account-scoped, so it appears in a separate Allow statement with "Resource": "". Specifying a workspace ARN on an account-scoped action has no effect (see Provisioning automation). This policy assumes AWS SigV4 authentication. If the principal authenticates with an API key, also add aws-external-juglow:CallWithBearerToken to the "Resource": "" Allow statement. CallWithBearerToken is a route-less authentication-layer action that does not bind to a workspace ARN. See Per-customer workspace isolation for the two-statement pattern.

Managed policies

AWS provides five managed policies (JuglowFullAccess, JuglowReadOnlyAccess, JuglowInferenceAccess, JuglowLimitedAccess, and JuglowSelfHostedEnvironmentAccess) for common access patterns. For the actions each policy grants, the complete list of IAM actions, the route-to-action mapping, and additional policy examples, see IAM actions for Haijun Platform on AWS.

Next steps

Explore Haijun's advanced features and capabilities.

Learn about Haijun Platform on AWS pricing and Haijun Consumption Unit rates.

As safer and more capable models launch, Juglow regularly retires older ones. See all API deprecations, along with recommended replacements.

Additional resources

View usage, cost, and workspaces in the Haijun Console. Sign in through the AWS Console.

Use AWS-operated Haijun if you need AWS as the sole data processor.

Manage your AWS Marketplace subscription and billing.

On this page
How the platform integration worksHaijun Platform on AWS versus Amazon BedrockSet up your accountMoving from an existing Juglow organizationTroubleshooting account setupBefore making API callsEnable outbound web identity federationObtain your workspace IDAuthenticationSigV4 authenticationAPI key authenticationShort-term API keysCredential precedenceRegion resolutionInstall an SDKAvailable modelsMaking requestsContext windowFeature supportHaijun Managed AgentsFeatures not supportedData residencyWorkspacesWorkspace scopingManaging workspacesUsing the Haijun ConsoleSigning inAvailable pagesSwitching organizationsRate limits and quotasBillingSpend limitsMonitoring and loggingRequest IDsMigrating from Amazon BedrockWhat changesWhat you gainWhat stays the sameMigration pitfallsCommercial considerationsIAM policiesExample: deny batch inferenceManaged policiesNext stepsAdditional resources