AWS today launched three new condition keys that help administrators govern API keys for Amazon Bedrock. The new condition keys help you control the generation, expiration, and the type of API keys allowed. Amazon Bedrock supports two types of API keys: short-term API keys valid for up to 12 hours or long-term API keys which are IAM service-specific credentials for use with Bedrock only.
The new iam:ServiceSpecificCredentialServiceName condition key lets you control what target AWS services are allowed when creating IAM service-specific credentials. For example, you could allow the creation of Bedrock long-term API keys but not credentials for AWS CodeCommit or Amazon Keyspaces. The new iam:ServiceSpecificCredentialAgeDays condition key lets you control the maximum duration of Bedrock long-term API keys at creation. The new bedrock:BearerTokenType condition key let’s you allow or deny Bedrock requests based on whether the API key is short-term or long-term.
These new condition keys are available in all AWS Regions. To learn more about using the new condition keys, visit the IAM User Guide or Amazon Bedrock User Guide.
Categories: general:products/aws-identity-and-access-management,marketing:marchitecture/security-identity-and-compliance,general:products/amazon-bedrock
Source: Amazon Web Services
Latest Posts
- (Updated) Outlook: retiring “Contact Masking” (hide suggested recipients) – March 31, 2026 [MC1234566]
![(Updated) Outlook: retiring “Contact Masking” (hide suggested recipients) - March 31, 2026 [MC1234566] 2 pexels wildlittlethingsphoto 4402093](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Copilot extensibility: Microsoft 365 Copilot Declarative Agents model upgrade to GPT‑5.2 [MC1251203]
![Copilot extensibility: Microsoft 365 Copilot Declarative Agents model upgrade to GPT‑5.2 [MC1251203] 3 palm 2445110 1920](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- (Update)Microsoft Entra ID: General Availability of passkey profiles and migration for existing Passkeys (FIDO2) tenants [MC1221452]
![(Update)Microsoft Entra ID: General Availability of passkey profiles and migration for existing Passkeys (FIDO2) tenants [MC1221452] 4 pexels ken tomita 127057 389818](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft Viva Engage | Email sender domain migration from @yammer.com to @engage.mail.microsoft [MC1251200]
![Microsoft Viva Engage | Email sender domain migration from @yammer.com to @engage.mail.microsoft [MC1251200] 5 pexels javon swaby 197616 2767540](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)

![(Updated) Outlook: retiring “Contact Masking” (hide suggested recipients) - March 31, 2026 [MC1234566] 2 pexels wildlittlethingsphoto 4402093](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-wildlittlethingsphoto-4402093-150x150.webp)
![Copilot extensibility: Microsoft 365 Copilot Declarative Agents model upgrade to GPT‑5.2 [MC1251203] 3 palm 2445110 1920](https://mwpro.co.uk/wp-content/uploads/2025/06/palm-2445110_1920-150x150.webp)
![(Update)Microsoft Entra ID: General Availability of passkey profiles and migration for existing Passkeys (FIDO2) tenants [MC1221452] 4 pexels ken tomita 127057 389818](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-ken-tomita-127057-389818-150x150.webp)
![Microsoft Viva Engage | Email sender domain migration from @yammer.com to @engage.mail.microsoft [MC1251200] 5 pexels javon swaby 197616 2767540](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-javon-swaby-197616-2767540-150x150.webp)
