Files
adolf/docs/providers/bedrock-mantle.md
alvis bedb527145
Some checks failed
ClawSweeper Dispatch / dispatch (push) Has been cancelled
CodeQL / Security High (actions) (push) Has been cancelled
CodeQL / Security High (channel-runtime-boundary) (push) Has been cancelled
CodeQL / Security High (core-auth-secrets) (push) Has been cancelled
CodeQL / Security High (mcp-process-tool-boundary) (push) Has been cancelled
CodeQL / Security High (network-ssrf-boundary) (push) Has been cancelled
CodeQL / Security High (plugin-trust-boundary) (push) Has been cancelled
CodeQL / Security High (process-exec-boundary) (push) Has been cancelled
Docs Sync Publish Repo / sync-publish-repo (push) Has been cancelled
Docs / docs (push) Has been cancelled
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Has been cancelled
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Has been cancelled
Workflow Sanity / no-tabs (push) Has been cancelled
Workflow Sanity / actionlint (push) Has been cancelled
Workflow Sanity / generated-doc-baselines (push) Has been cancelled
CI / runner-admission (push) Has been cancelled
CI / preflight (push) Has been cancelled
CI / security-fast (push) Has been cancelled
CI / pnpm-store-warmup (push) Has been cancelled
CI / build-artifacts (push) Has been cancelled
CI / native-i18n (push) Has been cancelled
CI / ${{ matrix.check_name }} (push) Has been cancelled
CI / ${{ matrix.checkName }} (push) Has been cancelled
CI / checks-node-compat-node22 (push) Has been cancelled
CI / check-bundled-channel-config-metadata (push) Has been cancelled
CI / check-dependencies (push) Has been cancelled
CI / check-guards (push) Has been cancelled
CI / check-lint (push) Has been cancelled
CI / check-prod-types (push) Has been cancelled
CI / check-shrinkwrap (push) Has been cancelled
CI / check-test-types (push) Has been cancelled
CI / check-additional-boundaries-a (push) Has been cancelled
CI / check-additional-boundaries-bcd (push) Has been cancelled
CI / check-additional-extension-bundled (push) Has been cancelled
CI / check-additional-extension-channels (push) Has been cancelled
CI / check-additional-extension-package-boundary (push) Has been cancelled
CI / check-additional-runtime-topology-architecture (push) Has been cancelled
CI / check-session-accessor-boundary (push) Has been cancelled
CI / check-session-transcript-reader-boundary (push) Has been cancelled
CI / check-docs (push) Has been cancelled
CI / skills-python (push) Has been cancelled
CI / macos-swift (push) Has been cancelled
CI / ios-build (push) Has been cancelled
CI / ci-timings-summary (push) Has been cancelled
Native App Locale Refresh / Refresh native fa (push) Has been cancelled
Native App Locale Refresh / Refresh native fr (push) Has been cancelled
Native App Locale Refresh / Refresh native hi (push) Has been cancelled
Native App Locale Refresh / Refresh native id (push) Has been cancelled
Native App Locale Refresh / Refresh native it (push) Has been cancelled
Native App Locale Refresh / Refresh native ja-JP (push) Has been cancelled
Control UI Locale Refresh / plan (push) Has been cancelled
Control UI Locale Refresh / Refresh ${{ matrix.locale }} (push) Has been cancelled
Control UI Locale Refresh / Commit control UI locale refresh (push) Has been cancelled
Live Media Runner Image / Build live media runner image (push) Has been cancelled
Native App Locale Refresh / Refresh native ar (push) Has been cancelled
Native App Locale Refresh / Refresh native de (push) Has been cancelled
Native App Locale Refresh / Refresh native es (push) Has been cancelled
Native App Locale Refresh / Refresh native ko (push) Has been cancelled
Native App Locale Refresh / Refresh native nl (push) Has been cancelled
Native App Locale Refresh / Refresh native pl (push) Has been cancelled
Native App Locale Refresh / Refresh native pt-BR (push) Has been cancelled
Native App Locale Refresh / Refresh native ru (push) Has been cancelled
Native App Locale Refresh / Refresh native sv (push) Has been cancelled
Native App Locale Refresh / Refresh native th (push) Has been cancelled
Native App Locale Refresh / Refresh native tr (push) Has been cancelled
Native App Locale Refresh / Refresh native uk (push) Has been cancelled
Native App Locale Refresh / Refresh native vi (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-CN (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-TW (push) Has been cancelled
Native App Locale Refresh / Commit native locale refresh (push) Has been cancelled
Plugin Init Scaffold Validation / Validate provider scaffold (push) Has been cancelled
Plugin NPM Release / preview_plugins_npm (push) Has been cancelled
Plugin NPM Release / Validate release publish approval (push) Has been cancelled
Plugin NPM Release / preview_plugin_pack (push) Has been cancelled
Plugin NPM Release / publish_plugins_npm (push) Has been cancelled
Sandbox Common Smoke / sandbox-common-smoke (push) Has been cancelled
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled
Vendor OpenClaw source as Adolf fork baseline
Adolf is a fork/vendored clone of github.com/openclaw/openclaw (v2026.6.11),
free to diverge. Tree copied sans upstream .git; upstream remote added for
future syncs. Node pinned to 24 (.nvmrc); engines already require >=22.19.
Preserves docs/ARCHITECTURE.md.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LeqyaxJF2nbRXJtae2kNB2
2026-07-05 09:36:54 +00:00

7.9 KiB

summary, read_when, title
summary read_when title
Use Amazon Bedrock Mantle (OpenAI-compatible) models with OpenClaw
You want to use Bedrock Mantle hosted OSS models with OpenClaw
You need the Mantle OpenAI-compatible endpoint for GPT-OSS, Qwen, Kimi, or GLM
Amazon Bedrock Mantle

OpenClaw includes a bundled Amazon Bedrock Mantle provider that connects to the Mantle OpenAI-compatible endpoint. Mantle hosts open-source and third-party models (GPT-OSS, Qwen, Kimi, GLM, and similar) through a standard /v1/chat/completions surface backed by Bedrock infrastructure. Mantle also exposes two Anthropic Claude models through an Anthropic Messages route.

Property Value
Provider ID amazon-bedrock-mantle
API openai-completions for discovered OSS models, anthropic-messages for the two Claude models
Auth Explicit AWS_BEARER_TOKEN_BEDROCK or IAM credential-chain bearer-token generation
Default region us-east-1 (override with AWS_REGION or AWS_DEFAULT_REGION)

Getting started

Choose your preferred auth method and follow the setup steps.

**Best for:** environments where you already have a Mantle bearer token.
<Steps>
  <Step title="Set the bearer token on the gateway host">
    ```bash
    export AWS_BEARER_TOKEN_BEDROCK="..."
    ```

    Optionally set a region (defaults to `us-east-1`):

    ```bash
    export AWS_REGION="us-west-2"
    ```
  </Step>
  <Step title="Verify models are discovered">
    ```bash
    openclaw models list
    ```

    Discovered models appear under the `amazon-bedrock-mantle` provider. No
    additional config is required unless you want to override defaults.
  </Step>
</Steps>
**Best for:** using AWS SDK-compatible credentials (shared config, SSO, web identity, instance or task roles).
<Steps>
  <Step title="Configure AWS credentials on the gateway host">
    Any AWS SDK-compatible auth source works:

    ```bash
    export AWS_PROFILE="default"
    export AWS_REGION="us-west-2"
    ```
  </Step>
  <Step title="Verify models are discovered">
    ```bash
    openclaw models list
    ```

    OpenClaw generates a Mantle bearer token from the credential chain automatically.
  </Step>
</Steps>

<Tip>
When `AWS_BEARER_TOKEN_BEDROCK` is not set, OpenClaw mints the bearer token for you from the AWS default credential chain, including shared credentials/config profiles, SSO, web identity, and instance or task roles.
</Tip>

Automatic model discovery

When AWS_BEARER_TOKEN_BEDROCK is set, OpenClaw uses it directly. Otherwise, OpenClaw attempts to generate a Mantle bearer token from the AWS default credential chain. It then discovers available Mantle models by querying the region's /v1/models endpoint.

Behavior Detail
Discovery cache Results cached for 1 hour per region; a fetch failure returns the last cached result
IAM token refresh Every 2 hours, cached per region

To keep the Mantle plugin enabled but suppress automatic discovery and IAM bearer-token generation, disable the plugin-owned discovery toggle:

openclaw config set plugins.entries.amazon-bedrock-mantle.config.discovery.enabled false
The bearer token is the same `AWS_BEARER_TOKEN_BEDROCK` used by the standard [Amazon Bedrock](/providers/bedrock) provider.

Supported regions

us-east-1, us-east-2, us-west-2, ap-northeast-1, ap-south-1, ap-southeast-3, eu-central-1, eu-west-1, eu-west-2, eu-south-1, eu-north-1, sa-east-1.

Manual configuration

If you prefer explicit config instead of auto-discovery:

{
  models: {
    providers: {
      "amazon-bedrock-mantle": {
        baseUrl: "https://bedrock-mantle.us-east-1.api.aws/v1",
        api: "openai-completions",
        auth: "api-key",
        apiKey: "env:AWS_BEARER_TOKEN_BEDROCK",
        models: [
          {
            id: "gpt-oss-120b",
            name: "GPT-OSS 120B",
            reasoning: true,
            input: ["text"],
            cost: { input: 0, output: 0, cacheRead: 0, cacheWrite: 0 },
            contextWindow: 32000,
            maxTokens: 4096,
          },
        ],
      },
    },
  },
}

Advanced configuration

Reasoning support is inferred from model IDs containing patterns like `thinking`, `reasoner`, `reasoning`, `deepseek.r`, `gpt-oss-120b`, or `gpt-oss-safeguard-120b`. OpenClaw sets `reasoning: true` automatically for matching models during discovery. If the Mantle endpoint is unavailable, returns no models, or bearer-token resolution fails, discovery returns an empty result and the implicit provider is skipped. OpenClaw does not error; other configured providers continue to work normally. OpenClaw always appends two Claude models to the Mantle catalog after successful discovery, regardless of what `/v1/models` returns: `amazon-bedrock-mantle/anthropic.claude-opus-4-7` (Claude Opus 4.7) and `amazon-bedrock-mantle/anthropic.claude-mythos-preview` (Claude Mythos Preview). Both use the `anthropic-messages` API surface and stream through the same bearer-authenticated Anthropic-compatible endpoint (`/anthropic`), so the AWS bearer token is not treated like an Anthropic API key.
Claude Mythos Preview always requests reasoning, defaulting to `high`
effort when no `/think` level is set (mapped from `xhigh`/`max` down to
`high`, and `minimal` up to `low`). Opus 4.7 on Mantle streams without
model-provided reasoning, and OpenClaw omits its `temperature` parameter
since Opus 4.7 does not accept sampling overrides on this route; Mythos
Preview accepts a `temperature` override normally.

These two models are not configurable through `models.providers["amazon-bedrock-mantle"].models`
entries — they are always added by discovery when it succeeds, and are
only removed by disabling discovery entirely.
Bedrock Mantle is a separate provider from the standard [Amazon Bedrock](/providers/bedrock) provider. Mantle uses an OpenAI-compatible `/v1` surface for its OSS catalog, while the standard Bedrock provider uses the native Bedrock Converse API.
Both providers share the same `AWS_BEARER_TOKEN_BEDROCK` credential when
present.
Native Bedrock provider for Anthropic Claude, Titan, and other models. Choosing providers, model refs, and failover behavior. Auth details and credential reuse rules. Common issues and how to resolve them.