Use FIPS Endpoints
Amazon SageMaker AI publishes FIPS 140-3 endpoints alongside its standard ones. Switching to them changes only the hostname your client connects to; the endpoint, the model, and the request payload stay the same. For what these endpoints do and do not cover, see Security and Compliance.
Select FIPS endpoints
Section titled “Select FIPS endpoints”The AWS SDKs give you three ways to select FIPS endpoints, from broadest to narrowest scope:
| Mechanism | Scope | Use when |
|---|---|---|
AWS_USE_FIPS_ENDPOINT=true environment variable |
Every client in the process | The whole process should use FIPS endpoints and you do not authenticate with IAM Identity Center |
use_fips_endpoint = true in ~/.aws/config |
Every client using that profile | You want FIPS tied to a profile rather than a shell |
| Per-client configuration in code | One client | You want explicit, reviewable control — recommended |
Configure clients in code
Section titled “Configure clients in code”Apply use_fips_endpoint to each client you build. Both the control plane (sagemaker) and the inference client (sagemaker-runtime) need it:
import boto3
from botocore.config import Config
REGION = "us-west-2"
fips = Config(use_fips_endpoint=True)
sagemaker = boto3.client("sagemaker", region_name=REGION, config=fips)
runtime = boto3.client("sagemaker-runtime", region_name=REGION, config=fips)
print(sagemaker.meta.endpoint_url)
# https://api-fips.sagemaker.us-west-2.amazonaws.com
print(runtime.meta.endpoint_url)
# https://runtime-fips.sagemaker.us-west-2.amazonaws.comInvoke the endpoint exactly as you would otherwise:
response = runtime.invoke_endpoint(
EndpointName="<your-endpoint-name>",
ContentType="application/json",
Accept="*/*",
Body=audio_bytes,
CustomAttributes="model=nova-3&language=en&smart_format=true",
)Streaming over FIPS endpoints
Section titled “Streaming over FIPS endpoints”Bidirectional streaming reaches the runtime host on port 8443, and the FIPS runtime host serves that port as well. The HTTP/2 bidirectional streaming client takes an explicit endpoint, so point it at the FIPS hostname and keep the port:
import {
SageMakerRuntimeHTTP2Client,
} from "@aws-sdk/client-sagemaker-runtime-http2";
const region = "us-west-2";
const client = new SageMakerRuntimeHTTP2Client({
region,
endpoint: `https://runtime-fips.sagemaker.${region}.amazonaws.com:8443`,
});The equivalent in Python, using aws_sdk_sagemaker_runtime_http2:
endpoint_uri = f"https://runtime-fips.sagemaker.{region}.amazonaws.com:8443"For the full streaming request shape — payload parts, control messages, and result handling — see Invoke a Deepgram SageMaker Endpoint.
Asynchronous endpoints
Section titled “Asynchronous endpoints”Asynchronous endpoints read their input and write their output to Amazon S3, so configure the S3 client for FIPS as well. Otherwise the invocation travels over FIPS while the payload does not:
s3 = boto3.client("s3", region_name=REGION, config=fips)
runtime = boto3.client("sagemaker-runtime", region_name=REGION, config=fips)
print(s3.meta.endpoint_url)
# https://s3-fips.us-west-2.amazonaws.comAWS CLI
Section titled “AWS CLI”The AWS CLI honors AWS_USE_FIPS_ENDPOINT and use_fips_endpoint, and also accepts --endpoint-url:
aws sagemaker describe-endpoint \
--endpoint-name <your-endpoint-name> \
--region us-west-2 \
--endpoint-url https://api-fips.sagemaker.us-west-2.amazonaws.comConfirm a run used FIPS endpoints
Section titled “Confirm a run used FIPS endpoints”Print the resolved endpoint URL rather than assuming the setting took effect. meta.endpoint_url reports what the client will actually call, after every configuration source has been applied:
for name, client in {"control plane": sagemaker, "inference": runtime}.items():
url = client.meta.endpoint_url
print(f"{name:14} {url} FIPS={'-fips.' in url}")This check matters most in the IAM Identity Center case above, where a misconfigured run can reach SageMaker over standard endpoints while your logs claim FIPS.
Related resources
Section titled “Related resources”- Security and Compliance — what FIPS endpoints cover, FedRAMP coverage, network isolation, and VPC options
- Invoke a Deepgram SageMaker Endpoint — full request examples for each transport