$npx skillfedfor your agent

aws-bedrock-token-generator

A lightweight library for generating short-term bearer tokens for AWS Bedrock API authentication

With conditionsPyPI SecurityReleased Jul 20251.1M downloads / moApache-2.0Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — aws_bedrock_token_generator-1.1.0-py3-none-any.whl
v1.1.0 · released 2025-07-29 · Python >=3.7 · 1 runtime deps: botocore

Yes, if you are building applications that call AWS Bedrock and need to avoid embedding long-term credentials. The package is lightweight, has low install friction, carries a permissive license, and is maintained by AWS. However, it is still in Beta (first release 2025-07-01) and marked as aging (381 days since latest release), so verify token expiry and refresh behavior matches your use case before production deployment.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires AWS credentials available to botocore (via environment variables, IAM role, or credential file) and AWS_REGION environment variable for default usage.
  • Low friction: pure Python wheel with a single runtime dependency (botocore).
  • Repository is active and maintained, though the package itself is recent (first release 2025-07-01) and marked Beta in development status.

License · maintenance · safety

Apache-2.0 (permissive) — Apache License 2.0 (permissive) allows commercial use, modification, and redistribution with minimal restrictions—suitable for most production environments.

last release 2025-07-29 (381 days) · last repo commit 2025-07-29 · 17 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 1,057,951 downloads/mo, #4,428 on PyPI

Verify before relying

pip install aws-bedrock-token-generator

from aws_bedrock_token_generator import provide_token

token = provide_token()  # uses AWS_REGION env var and default credential chain
print(f"Token: {token}")
  • Whether token refresh/renewal is supported or tokens must be regenerated after expiry.
  • Performance characteristics when generating tokens at scale or high frequency.
  • Compatibility with non-standard AWS credential providers or custom credential chains.
Same gist for agents: .md · .json

What it is and what it does

This package wraps AWS credential handling to generate time-limited bearer tokens suitable for authenticating with AWS Bedrock services. Rather than embedding long-term AWS credentials in client applications, you call provide_token() once per session to obtain a short-lived token that encodes a presigned URL with embedded temporary credentials. The token format is bedrock-api-key-<base64-encoded-presigned-url>&Version=1, with a default expiration of 12 hours (configurable up to that maximum). It integrates with botocore's credential providers, so it works with IAM roles, environment variables, assume-role chains, and other standard AWS credential sources.

The library is designed for scenarios where you need to pass authentication to a Bedrock client without exposing raw AWS credentials—for example, when building web services, SDKs, or multi-tenant applications. It handles the complexity of credential expiry negotiation (the actual token lifetime is the minimum of your requested expiry and the underlying AWS credentials' remaining lifetime) and follows AWS security best practices by defaulting to short-lived tokens.

Use it for

  • Generate temporary tokens for web applications that need to call AWS Bedrock without embedding long-term credentials.
  • Create short-lived tokens for distributing to third-party clients or SDKs that require Bedrock API access.
  • Build multi-tenant SaaS platforms where each tenant receives a scoped, time-limited token instead of shared credentials.
  • Implement token-based authentication in microservices that delegate Bedrock calls to a central credential manager.
  • Rotate credentials frequently by regenerating tokens on a schedule without redeploying application code.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you are building applications that call AWS Bedrock and need to avoid embedding long-term credentials.

The package is lightweight, has low install friction, carries a permissive license, and is maintained by AWS. However, it is still in Beta (first release 2025-07-01) and marked as aging (381 days since latest release), so verify token expiry and refresh behavior matches your use case before production deployment.

Install

aws-bedrock-token-generator on PyPI

Before you install

Low friction: pure Python wheel with a single runtime dependency (botocore). Repository is active and maintained, though the package itself is recent (first release 2025-07-01) and marked Beta in development status.

Requires AWS credentials available to botocore (via environment variables, IAM role, or credential file) and AWS_REGION environment variable for default usage.

License in practice

Apache License 2.0 (permissive) allows commercial use, modification, and redistribution with minimal restrictions—suitable for most production environments.

Quickstart

pip install aws-bedrock-token-generator

from aws_bedrock_token_generator import provide_token

token = provide_token()  # uses AWS_REGION env var and default credential chain
print(f"Token: {token}")

Verify before relying

  • Whether token refresh/renewal is supported or tokens must be regenerated after expiry.
  • Performance characteristics when generating tokens at scale or high frequency.
  • Compatibility with non-standard AWS credential providers or custom credential chains.

Package facts

LicenseApache-2.0 permissive
Python supportSupports the current Python release >=3.7
Install frictionLow. Pure-Python wheel
Runtime dependencies
1 package
botocore
MaintenanceAging 381 days since the last release
Last repo commit
First released
Downloads1,057,951 / month, #4,428 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 4 - BetaIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9

Evidence: aws_bedrock_token_generator-1.1.0-py3-none-any.whl

Tags

Capabilities
AWS Bedrock token generationbearer token authentication AWStemporary credentials bedrockAWS API token generatorbedrock API authenticationshort-term token creationpresigned URL token
Topics
aws-integrationtoken-authcredential-management

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “AWS Bedrock token generation”

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also bedrock-agentcore-starter-toolkit · awslabs.bedrock-kb-retrieval-mcp-server · llama-index-embeddings-bedrock · opentelemetry-instrumentation-bedrock · cloudauthz · cybrid-api-id-python · aws-assume-role-lib · bedrock-agentcore · aliyun-python-sdk-sts · cognitojwt