# @pleach/transport-bedrock changelog (/docs/changelog/transport-bedrock)



This page collects the **site-content changelog entries** that
materially touched the [`@pleach/transport-bedrock`](/docs/transport-bedrock)
docs surface or named a `@pleach/transport-bedrock` symbol. It is not the
runtime changelog — the canonical record of the transport's runtime
behavior lives in the upstream package `CHANGELOG.md`. The package
is not on npm yet.

See the combined site changelog at
[`/docs/changelog/combined`](/docs/changelog/combined) for the
chronological unified view across every SKU.

## Unreleased [#unreleased]

### Changed [#changed]

* **[`/docs/transport-bedrock`](/docs/transport-bedrock) documents the
  shipped credential and error surface.** `credentials` (static keys or
  an STS session) and `credentialProvider` (AWS SDK v3 provider shape,
  e.g. `fromContainerMetadata()`) are mutually exclusive, and exactly
  one is required. Resolved credentials are cached until `expiration`
  minus `credentialRefreshSkewMs` (default `300000`). Credential
  failures and Bedrock auth refusals (`AccessDeniedException`,
  `ExpiredTokenException`, HTTP 401/403, …) surface only as
  `"bedrock: authentication failed"`, with the underlying error passed
  to `onAuthError`. `@aws-sdk/client-bedrock-runtime` is an optional
  peer. The page no longer lists "container/role-assumption resolution
  is planned" or "Bedrock-specific cost-event emission", neither of
  which matched the source.
