Skip to main content
Deepgram's Docs

Search documentation

Type to search this documentation.

On this pageOverview

Use FIPS Endpoints

Amazon SageMaker AI publishes FIPS 140-3 endpoints alongside its standard ones. Switching to them changes only the hostname your client connects to; the endpoint, the model, and the request payload stay the same. For what these endpoints do and do not cover, see Security and Compliance.

The AWS SDKs give you three ways to select FIPS endpoints, from broadest to narrowest scope:

Mechanism Scope Use when
AWS_USE_FIPS_ENDPOINT=true environment variable Every client in the process The whole process should use FIPS endpoints and you do not authenticate with IAM Identity Center
use_fips_endpoint = true in ~/.aws/config Every client using that profile You want FIPS tied to a profile rather than a shell
Per-client configuration in code One client You want explicit, reviewable control — recommended

Apply use_fips_endpoint to each client you build. Both the control plane (sagemaker) and the inference client (sagemaker-runtime) need it:

Python
import boto3
from botocore.config import Config
REGION = "us-west-2"
fips = Config(use_fips_endpoint=True)
sagemaker = boto3.client("sagemaker", region_name=REGION, config=fips)
runtime = boto3.client("sagemaker-runtime", region_name=REGION, config=fips)
print(sagemaker.meta.endpoint_url)
# https://api-fips.sagemaker.us-west-2.amazonaws.com
print(runtime.meta.endpoint_url)
# https://runtime-fips.sagemaker.us-west-2.amazonaws.com

Invoke the endpoint exactly as you would otherwise:

Python
response = runtime.invoke_endpoint(
    EndpointName="<your-endpoint-name>",
    ContentType="application/json",
    Accept="*/*",
    Body=audio_bytes,
    CustomAttributes="model=nova-3&language=en&smart_format=true",
)

Bidirectional streaming reaches the runtime host on port 8443, and the FIPS runtime host serves that port as well. The HTTP/2 bidirectional streaming client takes an explicit endpoint, so point it at the FIPS hostname and keep the port:

TypeScript
import {
  SageMakerRuntimeHTTP2Client,
} from "@aws-sdk/client-sagemaker-runtime-http2";
const region = "us-west-2";
const client = new SageMakerRuntimeHTTP2Client({
  region,
  endpoint: `https://runtime-fips.sagemaker.${region}.amazonaws.com:8443`,
});

The equivalent in Python, using aws_sdk_sagemaker_runtime_http2:

Python
endpoint_uri = f"https://runtime-fips.sagemaker.{region}.amazonaws.com:8443"

For the full streaming request shape — payload parts, control messages, and result handling — see Invoke a Deepgram SageMaker Endpoint.

Asynchronous endpoints read their input and write their output to Amazon S3, so configure the S3 client for FIPS as well. Otherwise the invocation travels over FIPS while the payload does not:

Python
s3 = boto3.client("s3", region_name=REGION, config=fips)
runtime = boto3.client("sagemaker-runtime", region_name=REGION, config=fips)
print(s3.meta.endpoint_url)
# https://s3-fips.us-west-2.amazonaws.com

The AWS CLI honors AWS_USE_FIPS_ENDPOINT and use_fips_endpoint, and also accepts --endpoint-url:

Bash

Print the resolved endpoint URL rather than assuming the setting took effect. meta.endpoint_url reports what the client will actually call, after every configuration source has been applied:

Python
for name, client in {"control plane": sagemaker, "inference": runtime}.items():
    url = client.meta.endpoint_url
    print(f"{name:14} {url}  FIPS={'-fips.' in url}")

This check matters most in the IAM Identity Center case above, where a misconfigured run can reach SageMaker over standard endpoints while your logs claim FIPS.

Suggest an edit

Propose a replacement for this page. The site team reviews it before applying any changes.

Export
Documentation menu