anthropics / anthropics/anthropic-sdk-python

Add an explicit authentication mode to AnthropicBedrockMantle

オープン
#1,893 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Python
スター
3.9k
フォーク
853
平均マージ
1日 18時間
マージ済み PR(30日)
11

説明

### Request

Please add a public way to select bearer API-key authentication or AWS SigV4 when constructing `AnthropicBedrockMantle` and `AsyncAnthropicBedrockMantle`.

Today the client chooses implicitly. If `AWS_BEARER_TOKEN_BEDROCK` or `ANTHROPIC_AWS_API_KEY` is present, it selects bearer authentication unless static AWS credentials or a profile were passed. That leaves no public way to force SigV4 while still using the refreshable default AWS credential chain (for example, ECS task roles, EC2 instance profiles, IRSA, or other botocore providers).

Passing resolved static credentials is not an equivalent workaround because it snapshots temporary credentials and can break credential rotation. `skip_auth=True` is also not equivalent because it disables authentication entirely.

A possible API would be:

```python
AnthropicBedrockMantle(auth_mode="auto" | "api_key" | "sigv4")
```

- `auto` preserves the current selection behavior.
- `api_key` requires and uses a bearer key.
- `sigv4` ignores ambient bearer-key environment variables and uses the normal AWS credential chain.

It should behave consistently for sync and async clients and remain selected when using `copy()` / `with_options()`.

Without a public switch, downstream integrations currently have to depend on the private `_use_sigv4` attribute. This came up in langchain-aws issue https://github.com/langchain-ai/langchain-aws/issues/1217 and PR https://github.com/langchain-ai/langchain-aws/pull/1234.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。