Bedrock API key belongs to an administrator
- Severity
- Critical
- Service
- Bedrock
- Check ID
- BEDROCK_API_KEY_ADMIN
What this check finds
A long-lived Bedrock API key is held by an IAM user with administrative privileges. The credential is scoped to Bedrock, but it sits on an identity that can do far more — and the same user's other credentials share that blast radius. An attacker who obtains the key learns the account has a high-value identity worth pursuing, and any weakness in that user's remaining credentials is now account-wide.
Passing looks like: No Bedrock API keys on administrative users.
How to fix it
Move Bedrock access off the administrative identity entirely: create a dedicated least-privilege user or, preferably, a role with only the bedrock:InvokeModel actions the workload needs. Delete the key from the admin user: aws iam delete-service-specific-credential --user-name USER --service-specific-credential-id ID.
Compliance controls it is evidence for
A failing result counts against these controls in KloudLytics; a passing one is evidence towards them. How compliance mapping works
| Framework | Controls |
|---|---|
| NIST SP 800-53 Rev5 (Moderate) |
|
| NIST Cybersecurity Framework 2.0 |
|
| ISO/IEC 27001:2022 Annex A |
|
Checked on every scan
KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs
More Bedrock checks
- CriticalBedrock agent IAM role has broad permissions
- HighBedrock agent has no guardrail applied
- HighBedrock knowledge base not encrypted with CMK
- HighBedrock model invocation logging not enabled
- HighExternal model weights imported into Bedrock without governance review
- HighLong-lived Bedrock API key in use
- HighNo AWS Budget alert configured for Bedrock spend
- HighNo Bedrock guardrails configured