Grok 4.7 got its AWS front door. Seven days after SpaceXAI shipped Grok 4.7 on September 21, 2026, AWS published Grok 4.7 is now available on Amazon Bedrock (September 28, 2026). The model did not change. The distribution path did: Amazon Bedrock now serves Grok 4.7 on bedrock-runtime through cross-Region inference profiles, with 500K context, image-in / text-out, tool calling, and four reasoning-effort knobs.
This is the same pattern as Grok 4.6 on Bedrock in August: IAM instead of an xAI key, one AWS bill next to Claude and other catalog models, PrivateLink and Guardrails if you turn them on. If you already compared 4.7 against Opus 5.5 and GPT-6 Sol on Terminal-Bench, Bedrock does not rewrite those scores. It only changes how an AWS shop calls the same weights.
TL;DR — what people are actually asking
| Question | Direct answer |
|---|---|
| Is this a new Grok? | No — same September 21 Grok 4.7, now on Bedrock |
| When did AWS announce it? | September 28, 2026, official Machine Learning blog |
| Context window? | 500K tokens (per AWS and xAI packaging) |
| Modalities? | Image and text in, text out; tool calling included |
| Effort levels? | low, medium, high, xhigh — default high |
| APIs? | Responses, Chat Completions, InvokeModel, Converse |
| Model IDs? | us.xai.grok-4.7 or global.xai.grok-4.7 |
| Endpoint? | bedrock-runtime / https://bedrock-runtime.{region}.amazonaws.com/openai/v1 |
| $2/$6 on the AWS post? | Not listed. Check the Bedrock pricing page and console |
| Need an xAI account? | No — console access + IAM or Bedrock API key |
| Should non-AWS teams switch? | Usually no — the direct API stays simpler |
What "Grok 4.7 on Bedrock" actually means
Amazon Bedrock is a managed API in front of foundation models from several labs. When AWS says a model is available, the provider (here, SpaceXAI / xAI) makes those weights callable through Bedrock's standard surfaces. AWS owns authentication, routing, logging, and billing. The September 28 post is explicit that Grok 4.7 is served on the bedrock-runtime endpoint through cross-Region inference profiles, so you name a profile, not a region-pinned bare model ID.
Before (direct path): call SpaceXAI's API with an xAI-issued key, billed by SpaceXAI. That path did not disappear.
Now, in addition: call Bedrock in a chosen AWS Region, authenticate with IAM or a Bedrock API key, and pay AWS. Requests must use us.xai.grok-4.7 (US geographic profile) or global.xai.grok-4.7 (Global profile). AWS documents the OpenAI-compatible base URL as https://bedrock-runtime.{region}.amazonaws.com/openai/v1.
Both paths can coexist. Bedrock is additive distribution aimed at teams that already live in AWS — the same story as the August Grok 4.6 Bedrock write-up, updated for 4.7's longer context and effort controls.
Bedrock vs the xAI API: what actually differs
| Layer | Direct xAI / SpaceXAI API | Grok 4.7 on Amazon Bedrock |
|---|---|---|
| Identity | Provider API key | IAM roles/policies, or a Bedrock API key / short-lived IAM-minted bearer token |
| Request shape | Provider OpenAI-style (or their SDK) | OpenAI-compatible /openai/v1 or Bedrock Converse / InvokeModel |
| Where traffic runs | Provider network | AWS Regions via Geo or Global cross-Region profiles |
| Data residency knob | Provider terms | US geographic profile vs Global (AWS: Global can serve any supported commercial Region) |
| Audit trail | Whatever the provider logs | Invocation logging to CloudWatch, including reasoning-token counts |
| Safety add-ons | Provider guardrails | Bedrock Guardrails by ID/version on the request |
| Prompt caching | Provider-specific | AWS: implicit prompt caching on repeated prefixes |
| Billing | Separate xAI invoice | AWS bill, plus optional PrivateLink, Guardrails, log retention |
| Token rate card in the launch post | SpaceXAI's Sept 21 post listed $2/$6 for the API | AWS Sept 28 post does not reprint those dollars |
The model card still matters. On SpaceXAI's own table, 4.7 improved over 4.6 on every published row but did not sweep Fable 5.1 on CursorBench or Terminal-Bench. Bedrock will not fix a coding-agent gap. It will let you A/B Grok against Claude on the same Converse client if that is already how you ship.
AWS also restates xAI's product pitch: endurance on hard tasks, self-verification, native Grok Bot harness familiarity. For harness context on explainx.ai, see Grok Build and what an agent harness is. Those are product facts from xAI, not extra evals AWS ran.
When should an AWS shop switch off the xAI key?
Switch the default production path to Bedrock when most of these are already true:
- You already call Claude (or Llama, Mistral, Amazon models) through Bedrock. Swapping
modelIdis cheaper than standing up a second vendor's key rotation, DLP review, and invoice. That is the same consolidation argument as the 4.6 Bedrock post. - Security review blocked a standalone xAI contract. Bedrock inherits platform paperwork (SOC 2, ISO 27001, HIPAA eligibility, FedRAMP Moderate at the platform level — still verify your workload's actual in-scope services). Prompts and completions are not used to train AWS's own models, per Bedrock's standing commitment.
- You need VPC-adjacent inference. PrivateLink and "never on the public internet" are AWS features, not something a public
api.x.aihop gives you by default. - You want one place to attach Guardrails, structured JSON Schema outputs, and CloudWatch invocation logs — AWS calls these out specifically for long unattended agent runs.
- Residency is a US-only constraint. Use
us.xai.grok-4.7. If you care more about spare capacity and AWS's claim that Global is priced below a geographic profile, useglobal.xai.grok-4.7and accept less control over which Region serves a given request (AWS's own latency caveat).
Stay on the direct API when:
- You have no other AWS spend worth wrapping Grok inside. Learning
Converseplus IAM for one model is overhead. - You are iterating in Cursor or Grok Build and the IDE already routes to SpaceXAI. Bedrock is a backend choice, not a Cursor toggle.
- You need a provider feature that Bedrock has not mapped yet. Always check the Grok 4.7 model card in the console for the live Region list and parameter matrix — AWS tells you to do that before the first call.
A hybrid is legitimate: prototypes on xAI, production agents on Bedrock once IAM and logging are required. Do not run two production bills "just in case" unless you have a documented failover.
Pricing: do not invent $2 / $6 on Bedrock
explainx.ai's Grok 4.7 launch post records SpaceXAI's September 21 list price of $2 per million input tokens and $6 per million output tokens on the provider API, plus a fast variant at 2x. That is not copied into the AWS announcement.
The AWS post instead describes service tiers:
- Standard — pay-per-token,
"service_tier": "default"or omit the field - Priority — faster processing at a premium (
"service_tier": "priority") - Flex — lower-cost, not time-sensitive (
"service_tier": "flex")
It then says, verbatim in spirit: for per-token pricing across the tiers, see the Amazon Bedrock pricing page. Until you open that page (or the console) for xai.grok-4.7 in your account, treat Bedrock dollars as unknown. Pass-through of provider rates is how Bedrock often works, but this launch post does not confirm a $2/$6 Bedrock meter.
AWS also flags a token-volume risk from third-party evals it quotes: Artificial Analysis measured Grok 4.7 (xhigh) at roughly double the output tokens per Intelligence Index task versus Grok 4.6 (~81k vs ~38k). Higher effort plus longer trajectories can dominate the invoice even if the rate looks familiar. Set effort on purpose.
PrivateLink endpoints, Guardrails, cross-Region behavior, and CloudWatch retention still meter separately if enabled — same warning as on the 4.6 Bedrock piece.
Effort levels: low through xhigh
AWS: reasoning is always on. Effort is the cost and latency control. Levels: low, medium, high, xhigh. Default is high.
Use that default as a budget alarm, not a compliment. Classification, extraction, and short FAQ answers belong at low. Multi-step planning, legal/knowledge-work packets, and agents that can compound an early error belong at high or xhigh. AWS's point: higher effort buys more self-checking across a long task, not just more tokens on a single sentence.
On the Responses API, set reasoning={"effort": "high"} (or another level). You can request encrypted reasoning back with include=["reasoning.encrypted_content"] and send it on later turns. AWS states the Chat Completions API does not return reasoning tokens.
On Converse, do not look for a top-level reasoning field. Use additionalModelRequestFields={"reasoning_effort": "xhigh"}. Because reasoning is always active, the first content block may be reasoning; AWS says to search blocks for text instead of assuming content[0] is the answer.

If you are choosing 4.7 versus Opus or Sol on quality, keep using the overlap table in Grok 4.7 vs Opus 5.5 vs GPT-6 Sol. Effort only changes how expensive a given model is to run on Bedrock, not who won Terminal-Bench.
Copy-paste: official AWS first-request snippets
Confirm the model is enabled in the Bedrock console for the Region you will call. Then, as AWS documents:
pip install openai
pip install boto3
export OPENAI_API_KEY="<provide your Bedrock API key>"
export OPENAI_BASE_URL="https://bedrock-runtime.us-east-1.amazonaws.com/openai/v1"
Chat Completions (AWS sample):
from openai import OpenAI
client = OpenAI()
response = client.chat.completions.create(
model="us.xai.grok-4.7",
messages=[
{"role": "user", "content": "Can you explain the features of Amazon Bedrock?"}
],
)
print(response.choices[0].message.content)
Responses API (AWS sample):
response = client.responses.create(
model="us.xai.grok-4.7",
input="Can you explain the features of Amazon Bedrock?",
)
print(response.output_text)
Converse with boto3 (AWS sample — find the text block):
import boto3
client = boto3.client("bedrock-runtime", region_name="us-east-1")
response = client.converse(
modelId="us.xai.grok-4.7",
messages=[
{"role": "user", "content": [{"text": "Can you explain the features of Amazon Bedrock?"}]}
],
inferenceConfig={"maxTokens": 2048},
)
blocks = response["output"]["message"]["content"]
text = next(b["text"] for b in blocks if "text" in b)
print(text)
Converse with xhigh effort (AWS sample):
response = client.converse(
modelId="us.xai.grok-4.7",
messages=[{"role": "user", "content": [{"text": "What is 17*23? Number only."}]}],
inferenceConfig={"maxTokens": 3000},
additionalModelRequestFields={"reasoning_effort": "xhigh"},
)
Responses with effort and encrypted reasoning (AWS sample):
from openai import OpenAI
client = OpenAI() # OPENAI_BASE_URL points at the bedrock-runtime endpoint
response = client.responses.create(
model="us.xai.grok-4.7",
reasoning={"effort": "high"},
include=["reasoning.encrypted_content"],
input="Explain quantum entanglement simply.",
)
print(response.output_text)
AWS: treat a long-term Bedrock API key as exploration-only. Production should use short-term bearer tokens from IAM via aws-bedrock-token-generator, so credentials expire. Delete leftover long-term keys when you are done.
IAM: three resources plus bearer-token action
AWS is unusually specific here. bedrock:InvokeModel is evaluated against three resources: the account default project, the inference profile you name, and the underlying foundation model. The FM ARN is wildcarded across Regions because cross-Region profiles route outside the calling Region. Bearer-token OpenAI-compatible calls additionally need bedrock:CallWithBearerToken (boto3 Converse does not).
Copied from the AWS post (replace {region} and {account-id}):
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "bedrock:InvokeModel",
"Resource": [
"arn:aws:bedrock:{region}:{account-id}:project/default",
"arn:aws:bedrock:{region}:{account-id}:inference-profile/us.xai.grok-4.7",
"arn:aws:bedrock:*::foundation-model/xai.grok-4.7"
]
},
{
"Effect": "Allow",
"Action": "bedrock:CallWithBearerToken",
"Resource": "*"
}
]
}
List every profile you will call. A policy that names only us.xai.grok-4.7 does not cover global.xai.grok-4.7.
What AWS bundled from xAI (and what it did not re-benchmark)
The Bedrock blog summarizes xAI's September 21 story: larger base, longer RL on hour-scale tasks, 500K context used more effectively, document/presentation generation, professional knowledge work. It points to CursorBench, DeepSWE, Terminal-Bench, AA Briefcase, EEBench, Harvey Legal, and HealthBench — without reprinting SpaceXAI's score table. For those numbers and the "no sweep vs Fable 5.1" read, stay on the launch benchmarks post.
AWS does reprint an Artificial Analysis comparison (Grok 4.7 at xhigh vs Grok 4.6 at AA's reported effort): Intelligence Index 46 vs 44, Coding Agent Index 56 vs 47, AA-Briefcase Elo 1,657 vs 1,546, GDPval-AA Elo 1,695 vs 1,605, AA-Omniscience 32 vs 30, hallucination rate 29% vs 34%, and the ~81k vs ~38k output-token row. Treat that as AWS citing AA, not as explainx.ai's own run.
Safety: AWS relays xAI's new safeguard stack and invite-only cyber red-team access. Independent of Bedrock, evaluators later reported network-guard bypasses on SWE-Together. Enterprise Guardrails on Bedrock are a filter on your prompts and completions, not a substitute for locking down the agent's network.
Honest limitations
- No Bedrock-specific quality benchmark. AWS did not publish a separate latency or accuracy bake-off of Bedrock-hosted 4.7 versus
api.x.ai. - Region and feature matrix live in the console. Cross-Region profiles are the serving model; your account still has to have the model enabled.
- Pricing is a homework item. The official AWS post does not list $2/$6. Open Amazon Bedrock pricing and the model card.
- Global vs US is a policy choice. Global may be cheaper and broader on capacity; US geographic keeps processing in the US geography, per AWS.
- OpenAI SDK vs Converse is a team-skills choice. Port existing OpenAI clients to
/openai/v1. Use Converse if you want one message shape, streaming event types, and invocation logging across every Bedrock model — including Claude on the same account (financial-services Bedrock pattern). - If you are studying for AWS gen-AI certs, Bedrock catalog changes show up as "which models are in the marketplace," not as a reason to skip exam scope.
What to do this week
- In the Bedrock console, request Grok 4.7 and confirm
us.xai.grok-4.7orglobal.xai.grok-4.7in your Region. - Paste the Chat Completions snippet against a Bedrock API key, then delete that key if it was only for exploration.
- Point one existing
Converseeval suite (the tasks you already use for Claude) at Grok 4.7 withreasoning_effortlow and xhigh. Record tokens and quality. That pair tells you whether 4.7 is a routing candidate, independent of marketing. - Write IAM with both profiles you might call, plus the wildcard FM ARN AWS specified.
- If you are not on AWS, ignore this post's migration advice and use the direct launch path.
Related on explainx.ai
- Grok 4.6 on Amazon Bedrock: why use it over the direct API
- Grok 4.7 launch: official benchmarks and $2/$6 (provider API)
- Grok 4.7 vs Claude Opus 5.5 vs GPT-6 Sol
- Grok 4.6 launch evals and Cursor
- Grok 4.7 SWE-Together network-guard report
- Grok Build open-source harness
- What is an agent harness?
- AWS Certified Generative AI Developer exam
Primary sources: AWS, Grok 4.7 is now available on Amazon Bedrock (September 28, 2026); xAI, Introducing Grok 4.7 (September 21, 2026). AWS also cites Artificial Analysis and the Amazon Bedrock pricing page.
Packaging, APIs, model IDs, and operational notes reflect AWS's September 28, 2026 Machine Learning blog post. Token rates, Region lists, and service-tier dollars can change after publication — verify in the Amazon Bedrock console. Follow @explainx_ai for updates.
