Connect Amazon Bedrock
Connect Amazon Bedrock to see what your AWS account spends on it, beside the rest of your AI spend. Flowstate reads it from AWS Cost Explorer through a role you create, so you don’t share access keys.
You need access to connect AI providers. Ask your Flowstate admin. You also need someone who can manage IAM in your AWS account.
Before you start
- Cost Explorer switched on in the AWS Billing console. It’s a one-off, and AWS doesn’t let you switch it off again. The first time, AWS takes a few days to prepare your history.
- An IAM role Flowstate can use, created by your technical team. See For your technical team.
Connect Amazon Bedrock
- Go to Settings → Integrations, select Browse catalog and open Amazon Bedrock.
- Under How to connect, select Use this route.
- Paste the role’s ARN into IAM role ARN.
- In AWS region, enter the region your Bedrock workloads run in.
- Optional: to see spend by team, product or anything else you tag, enter a cost allocation tag key, such as
team, in Split spend by tag (optional). - Select Verify and connect.
Check it’s working
The connection is listed under Connected keys with the status Working. See the spend in Agent insights.
What Flowstate brings in
- Billed cost by service and usage type, each day.
- A total for your account. AWS doesn’t report cost per person.
- If you chose a tag, each day’s spend split by that tag’s value. Spend without the tag stays as one line.
- Flowstate syncs every hour, and brings in your history when you first connect. Cost Explorer keeps 13 months of history.
- AWS charges $0.01 for every paginated Cost Explorer request. It appears on your AWS bill.
If something’s not right
The first sync is empty. Cost Explorer was only just switched on. Wait a few days for AWS to prepare your history.
Spend isn’t split by your tag. The tag must be activated as a cost allocation tag in AWS Billing, and AWS only tags spend from after it was activated. Check the key is spelt exactly as in AWS.
The connection fails. The role’s trust or its permission is wrong. Select Show what the provider said to see AWS’s error.
For your technical team
- Ask your Flowstate contact for the OpenID Connect provider URL, audience and subject for your organisation.
- In AWS, go to IAM → Identity providers and add an OpenID Connect provider with that URL and audience.
- Create a role that trusts the provider, limited to your organisation’s subject.
- Allow the role
ce:GetCostAndUsage. It needs nothing else.