diff --git a/litellm/llms/bedrock/base_aws_llm.py b/litellm/llms/bedrock/base_aws_llm.py index 11851427181..db6f2c0d491 100644 --- a/litellm/llms/bedrock/base_aws_llm.py +++ b/litellm/llms/bedrock/base_aws_llm.py @@ -859,6 +859,7 @@ class BaseAWSLLM: "Action": [ "bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream", + "bedrock:CountTokens", "bedrock:ApplyGuardrail", "bedrock:GetGuardrail", "bedrock:ListGuardrails", diff --git a/tests/test_litellm/llms/bedrock/test_web_identity_session_policy.py b/tests/test_litellm/llms/bedrock/test_web_identity_session_policy.py index 0cbdc518cc2..3ea840519f9 100644 --- a/tests/test_litellm/llms/bedrock/test_web_identity_session_policy.py +++ b/tests/test_litellm/llms/bedrock/test_web_identity_session_policy.py @@ -117,6 +117,19 @@ class TestWebIdentitySessionPolicyShape: ): assert required in actions, f"{required} missing from BedrockLiteLLM" + def test_bedrock_count_tokens_action_present(self): + """Regression for #33142: the CountTokens handler authorizes + against ``bedrock:CountTokens``, so the session-policy ceiling + must grant it or every count-tokens request via OIDC auth 403s + even when the role's identity policy allows it.""" + policy = _captured_policy() + bedrock_stmt = _statement_by_sid(policy, "BedrockLiteLLM") + actions = set(bedrock_stmt["Action"]) + assert "bedrock:CountTokens" in actions, ( + "bedrock:CountTokens missing from BedrockLiteLLM — " + "count-tokens requests will 403 on OIDC auth" + ) + class TestClaudePlatformActionsCovered: """The #30200 bug: every action in the claude_platform service