本文為英文版的機器翻譯版本,如內容有任何歧義或不一致之處,概以英文版為準。
Web 搜尋
Web 搜尋是一種內建工具,可在 Amazon Bedrock 中提供 Web 搜尋功能。當您啟用它時,支援的模型可以在請求期間從 Web 擷取目前資訊,並使用它來提供答案,而不是僅依賴他們訓練的資料。回應包括對模型使用的來源的引用。Web 搜尋由 託管和建置 AWS。只有在您的請求和 IAM 許可都允許時,才會從外部 Web 擷取。
資料控管
若要在 AWS 邊界內持續擷取,同時仍允許快取的頁面內容,請將 external_web_access設定為 false。接著會從 Amazon Bedrock Web 索引提供搜尋,並從 Amazon Bedrock 快取提供 Fetch。
AmazonBedrockFullAccess 政策會授予搜尋和擷取,但不會授予 bedrock-websearch:ExternalWebAccess。由於 external_web_access 預設為 true,因此使用此政策省略 參數會導致每個擷取嘗試在讀取快取之前失敗其後端授權檢查。整體回應 API 請求仍可使用搜尋觀察完成,但擷取不會貢獻任何頁面內容。明確設定 參數false以避免此失敗,並將擷取保持在 AWS 邊界內。視您使用的模型而定,您的資料會受到自動化Amazon Bedrock 濫用偵測機制的約束。
何時使用 Web 搜尋
每當答案取決於比模型的參數知識更近期、更專業或更具權威性的資訊時,Web 搜尋就會很有用。Recency 是一個常見案例:新程式庫版本的目前事件、最新產品版本、價格或文件。對於模型知識稀疏或不精確的長尾或專業問題,例如利基 APIs、特定組態值或特定網域的事實,以及您想要有基礎、可參考來源而非回收的情況,也同樣有用。
Web 搜尋的運作方式
由於工具會在 Amazon Bedrock 內執行,因此您不需要託管搜尋索引、管理爬蟲程式或自行撰寫工具呼叫迴圈。您可以將工具新增至 Amazon Bedrock 推論請求,模型會視需要叫用它。Web 搜尋為模型提供目前資訊,讓模型能夠以引號傳回基本答案。
啟用 Web 搜尋時,模型會決定請求是否需要最新的資訊。如果是這樣,模型會向 Web 搜尋工具發出一或多個搜尋查詢,並收到一組從 Amazon 建置和維護的 Web 索引擷取的觀察。每個觀察都包含標題、來源 URL 和內容片段。模型接著會編寫以這些結果為基礎的答案,並新增指向來源的引文。
如果第一組結果不足以回答問題,模型可以使用找到的內容重新格式化其查詢,並在同一回合內再次搜尋。當結果不支援答案時,模型會通知您,而不是填補訓練資料的差距。
搜尋和擷取操作
Web 搜尋是從兩個操作建置:
-
搜尋 – 從 Amazon Bedrock Web 索引和知識圖表中傳回標題、URLs 和程式碼片段,以取得高可信度的事實。
-
擷取 – 擷取特定 URL 的頁面內容。將
external_web_access設為 時false,Fetch 只會使用 Amazon Bedrock 快取。將 參數設定為true並授予必要的 IAM 許可後,Fetch 會先檢查快取,並僅在快取遺漏時存取外部 Web。
搜尋一律會從 Amazon Bedrock Web 索引提供。Responses API 中的 external_web_access 參數和 bedrock-websearch:ExternalWebAccess IAM 許可會控管 Fetch 是否可以在快取遺漏後使用外部 Web。如需詳細資訊,請參閱控制外部 Web 存取。
支援的模型
Web 搜尋適用於使用 Responses API 透過 Amazon Bedrock bedrock-mantle端點提供的 OpenAI GPT 模型。在商業美國區域中,GPT-5.6 系列 - openai.gpt-5.6-sol、 openai.gpt-5.6-terra和 openai.gpt-5.6-luna- 以及舊版 openai.gpt-5.4和 支援此功能。 openai.gpt-5.5在 AWS GovCloud (US) 中openai.gpt-5.6-luna,支援 openai.gpt-5.6-terra、 和 openai.gpt-5.4。本指南中的範例使用 openai.gpt-5.6-terra。如需 Web 搜尋定價,請參閱 Amazon Bedrock 定價頁面
注意
Web 搜尋是一種伺服器端工具,因此當您在bedrock-runtime端點上呼叫回應 API 時無法使用。若要使用它,請呼叫 上的回應 APIbedrock-mantle。如需兩個端點的其他差異,請參閱 在 bedrock-runtime 端點上使用 Responses API。
區域可用性
Web 搜尋會在 區域中處理查詢。請參閱下列目前的可用性。
美國
| 區域 | 區域碼 |
|---|---|
| 美國東部 (維吉尼亞北部) | us-east-1 |
| 美國東部 (俄亥俄) | us-east-2 |
| 美國西部 (奧勒岡) | us-west-2 |
AWS GovCloud (美國)
| 區域 | 區域碼 |
|---|---|
| AWS GovCloud (US-West) | us-gov-west-1 |
Web 搜尋是嚴格區域性的。每個區域都會操作自己的搜尋和擷取層,而查詢、擷取、索引資料和結果不會跨區域路由。在指定區域中發出的查詢會保持在該區域的邊界內。
啟用 Web 搜尋
若要使用 Web 搜尋,必須允許請求後方的 IAM 身分呼叫 Web 搜尋動作。如需必要的許可和範例政策,請參閱 Web 搜尋的身分和存取管理。
設定您的環境
在執行範例之前,請先設定下列項目:
export OPENAI_API_KEY="your-amazon-bedrock-api-key" export OPENAI_BASE_URL="https://bedrock-mantle.us-west-2.api.aws/openai/v1"
將 Web 搜尋工具新增至請求
若要啟用 Web 搜尋,請在請求中將 類型的工具web_search新增至tools陣列。模型只會在判斷請求需要目前資訊時使用工具。如需可執行的範例,請參閱 代碼範例。
控制搜尋內容大小
使用 search_context_size 控制每個搜尋呼叫可以傳回模型的內容。支援的值是:
| Value | 觀察預算 | 使用情況 |
|---|---|---|
low |
最高 5 | 更小的內容和更低的輸入字符使用量,適用於直接的問題。 |
medium |
最多 11 個 | 此為預設值。平衡結果涵蓋範圍和輸入字符用量。 |
high |
最高 25 | 複雜或多躍點問題的更多內容,具有更高的潛在輸入字符用量。 |
觀察包含標題、URL 和內容程式碼片段。當搜尋呼叫包含多個查詢時,會共用預算,而且服務可以傳回比最大值更少的觀察。較大的設定會增加模型輸入字符和相關聯的推論成本。此參數不會限制模型可以進行的搜尋呼叫數量。
tools=[{ "type": "web_search", "search_context_size": "low", "external_web_access": False, }]
控制外部 Web 存取
搜尋是從 Amazon Bedrock Web 索引提供。在快取遺漏之後,Fetch 是否可以從外部 Web 擷取頁面內容,是由兩個共同運作的控制項所管理:回應 API 中的 external_web_access 參數和 bedrock-websearch:ExternalWebAccess IAM 許可。
external_web_access 參數預設為 true,符合 OpenAI Responses API,因此您的呼叫不需要變更。AmazonBedrockFullAccess 政策會授予基本 Web 搜尋動作 — bedrock-websearch:InvokeSearch和 bedrock-websearch:InvokeFetch —,但不會授予 bedrock-websearch:ExternalWebAccess。因此,external_web_accesstrue從未保留 的身分離開 的請求,在讀取快取之前,會ExternalWebAccess失敗每次擷取嘗試的後端授權檢查。發起人的回應 API 請求仍然可以傳回 HTTP200:模型可以繼續使用搜尋觀察並傳回url_citation註釋。模型回應不保證會公開擷取失敗,而且引文的存在並不表示擷取引用的頁面。啟用 Web 搜尋資料事件記錄時,拒絕的InvokeFetch呼叫會顯示在 CloudTrail 中。如需詳細資訊,請參閱監控 Web 搜尋。
選擇下列其中一個 Fetch 組態。
將請求保留在 AWS 邊界內
在工具"external_web_access": false上設定 。這不需要 ExternalWebAccess許可,完全從 Amazon Bedrock Web 索引和快取提供擷取,而且您的請求資料不會離開 AWS 界限。由於 AmazonBedrockFullAccess 會授予 InvokeFetch,快取的 Fetch 會繼續運作。明確設定 參數;不要依賴省略 許可,同時將 參數保留為預設值 true,因為該組態會導致擷取嘗試失敗。
response = client.responses.create( model="openai.gpt-5.6-terra", input="Summarize recent guidance on AWS Lambda cold starts.", tools=[{"type": "web_search", "external_web_access": False}], )
curl "https://bedrock-mantle.us-west-2.api.aws/openai/v1/responses" \ -H "Authorization: Bearer $OPENAI_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "model": "openai.gpt-5.6-terra", "input": "Summarize recent guidance on AWS Lambda cold starts.", "tools": [{"type": "web_search", "external_web_access": false}] }'
啟用外部 Web 存取
bedrock-websearch:ExternalWebAccess 授予請求身分並external_web_access設為 true。最簡單的受管政策路徑是連接 AmazonBedrockExternalWebSearchReadOnly或 AmazonBedrockExternalWebSearchFullAccess。這些政策的目前版本在相同的資源上授予相同的三個 Web 搜尋動作,因此任一政策都會啟用外部擷取。如需詳細資訊,請參閱 受管政策。
使用此組態,搜尋會繼續使用 Amazon Bedrock Web 索引。只有當適當的頁面內容不在快取中時,擷取才會先檢查 Amazon Bedrock 快取,並從外部 Web 擷取。當擷取到達外部 Web 時,您的請求資料可能會離開 AWS 邊界。外部擷取只有在您同時授予許可並將 參數保持啟用時才會生效。
注意
請注意,external_web_access將 設定為 會true帶來資料外洩風險。代理程式可以將查詢資料編碼為 URL,然後嘗試從外部網際網路擷取該 URL。當您使用敏感資料時,external_web_access請將 設定為 false ,以防止資料到達外部網際網路。
搭配 Codex 使用 Web 搜尋
Codex 是 OpenAI 的編碼代理程式,可透過bedrock-mantle端點連線至 Amazon Bedrock,並可在支援的模型上使用 Web 搜尋。Web 搜尋可在 Codex 桌面應用程式和 CLI 0.147.0 版或更新版本中使用。
搭配 Codex 使用 Web 搜尋不需要超出標準 Web 搜尋許可的其他 IAM 設定。必須允許 API 金鑰後方的 IAM 身分呼叫 Web 搜尋動作 bedrock-websearch:InvokeSearch和 bedrock-websearch:InvokeFetch。這些動作是由 AmazonBedrockFullAccess 政策授予。如需必要的許可和範例政策,請參閱 Web 搜尋的身分和存取管理。
在支援的 Amazon Bedrock 模型上,Codex 使用純文字 Web 搜尋,從 Amazon Bedrock Web 索引和快取傳回標題、URLs 和內容片段。Codex 會在每個請求false上external_web_access將 設定為 ,因此您的請求資料會保持在 AWS 邊界內。如需詳細資訊,請參閱控制外部 Web 存取。
代碼範例
回應 API
from openai import OpenAI client = OpenAI() response = client.responses.create( model="openai.gpt-5.6-terra", input="What are the most significant AWS launches announced this month?", tools=[{"type": "web_search", "external_web_access": False}], ) print(response.output_text)
回應包含基本答案文字,以及指向來源的url_citation註釋:
{ "content": [ { "annotations": [ { "end_index": 573, "start_index": 441, "title": "Upgrade Amazon EKS clusters with confidence using Kubernetes version rollbacks | AWS News Blog", "type": "url_citation", "url": "https://aws.amazon.com/blogs/aws/upgrade-amazon-eks-clusters-with-confidence-using-kubernetes-version-rollbacks/" }, { "end_index": 1094, "start_index": 888, "title": "AWS Weekly Roundup: AWS Builder Center at 1 year, Network Scanning in Security Hub, Loom for AWS, and more (July 13, 2026) | AWS News Blog", "type": "url_citation", "url": "https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-builder-center-at-one-year-network-scanning-in-security-hub-loom-for-aws-and-more-july-13-2026/" }, { "end_index": 1837, "start_index": 1414, "title": "AWS Weekly Roundup: One-click Lambda setup prompt, OpenAI GPT-5.6 models on Bedrock, and more (July 20, 2026) | AWS News Blog", "type": "url_citation", "url": "https://aws.amazon.com/blogs/aws/aws-weekly-roundup-one-click-lambda-setup-prompt-openai-gpt-5-6-models-on-bedrock-and-more-july-20-2026/" } ], "logprobs": [], "text": "As of **July 30, 2026**, the most significant AWS launches this month:\n\n1. **Amazon EKS Kubernetes version rollbacks** — EKS now lets admins roll back a Kubernetes version upgrade within **seven days**, effectively adding an “undo” path for cluster upgrades and reducing upgrade risk for large or regulated Kubernetes fleets. It’s available at no additional cost in commercial Regions where EKS is available. ([aws.amazon.com](https://aws.amazon.com/blogs/aws/upgrade-amazon-eks-clusters-with-confidence-using-kubernetes-version-rollbacks/))\n\n2. **AWS Security Hub Network Scanning + Azure support** — Security Hub added active Network Scanning to find resources actually reachable from the public internet, and also expanded unified security management to **Microsoft Azure** resources, making this a notable multi-cloud security/posture-management move. ([aws.amazon.com](https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-builder-center-at-one-year-network-scanning-in-security-hub-loom-for-aws-and-more-july-13-2026/))\n\n3. **New frontier models on Amazon Bedrock: Claude Sonnet 5, Claude Opus 5, and OpenAI GPT-5.6 models** — AWS added major new model choices to Bedrock this month: Anthropic’s Claude Sonnet 5 and Claude Opus 5, plus OpenAI GPT-5.6 Sol, Terra, and Luna, expanding Bedrock’s role as a multi-model enterprise AI platform. ([aws.amazon.com](https://aws.amazon.com/blogs/aws/aws-weekly-roundup-one-click-lambda-setup-prompt-openai-gpt-5-6-models-on-bedrock-and-more-july-20-2026/))", "type": "output_text" } ], "id": "msg_dcda8e4b477f5a1d96bfbcadefef7a77", "phase": "final_answer", "role": "assistant", "status": "completed", "type": "message" }
直接 HTTPS 請求
如果您不是使用 OpenAI 開發套件,請直接將請求傳送到回應端點。tools 欄位會攜帶 Web 搜尋工具。
curl "https://bedrock-mantle.us-west-2.api.aws/openai/v1/responses" \ -H "Authorization: Bearer $OPENAI_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "model": "openai.gpt-5.6-terra", "input": "What are the most significant AWS launches announced this month?", "tools": [{"type": "web_search", "external_web_access": false}] }'
從回應讀取引文
Web 搜尋會以附加至文字的url_citation註釋傳回引文。每個註釋都有來源標題和 URL,以及其支援的答案中的字元跨度。保留並顯示給最終使用者。
即使擷取未擷取完整頁面,引文也可以根據搜尋觀察。請勿使用引文的存在來判斷內容是來自 Amazon Bedrock 快取還是外部 Web。若要稽核擷取結果和擷取來源,請使用 CloudTrail 中的 fetchedSources 欄位。如需詳細資訊,請參閱監控 Web 搜尋。
from openai import OpenAI client = OpenAI() response = client.responses.create( model="openai.gpt-5.6-terra", input="What are the most significant AWS launches announced this month?", tools=[{"type": "web_search", "external_web_access": False}], ) # The grounded answer print(response.output_text) # The sources behind it for item in response.output: if item.type == "message": for block in item.content: if block.type == "output_text": for ann in block.annotations: if ann.type == "url_citation": print(f"- {ann.title}: {ann.url}")
如果您使用原始 JSON (例如,從直接 HTTPS 呼叫),相同的資料存在於 output[].content[].annotations[]:
jq '.output[] | select(.type=="message") | .content[] | select(.type=="output_text") | .annotations[] | select(.type=="url_citation") | {title, url, start_index, end_index}' response.json
串流回應
Responses API 會在答案產生時將其串流。文字會以response.output_text.delta事件的形式抵達,而每個引文會以response.output_text.annotation.added事件的形式抵達,因為模型會推斷陳述式。
from openai import OpenAI client = OpenAI() stream = client.responses.create( model="openai.gpt-5.6-terra", input="What are the most significant AWS launches announced this month?", tools=[{"type": "web_search", "external_web_access": False}], stream=True, ) for event in stream: if event.type == "response.output_text.delta": print(event.delta, end="", flush=True) elif event.type == "response.output_text.annotation.added": ann = event.annotation print(f"\n[source] {ann['title']}: {ann['url']}")
透過線路,註釋事件如下所示:
event: response.output_text.annotation.added data: {"type":"response.output_text.annotation.added","annotation":{"type":"url_citation","title":"News and Updates from the July 2025 Pokémon Presents","url":"https://www.pokemon.com/us/pokemon-news/...","start_index":589,"end_index":698},"annotation_index":2,"content_index":0,"item_id":"msg_...","output_index":1}
安全
Amazon Bedrock 上的 Web 搜尋使用 AWS Identity and Access Management (IAM) 來控制誰可以執行搜尋和擷取以及哪些區域。Web 搜尋的 IAM 服務字首為 bedrock-websearch。如需停用 Web 搜尋的動作、受管政策、條件金鑰、範例政策和管理員控制項的完整清單,請參閱 Web 搜尋的身分和存取管理。
使用 CloudTrail 進行監控
Amazon Bedrock 上的 Web 搜尋已與 整合 AWS CloudTrail。CloudTrail 會將 Web 搜尋的 API 活動擷取為資料事件,因此您可以稽核叫用工具的人員、時間和位置。如需擷取的欄位、如何啟用資料事件記錄,以及刻意排除的內容,請參閱監控 Web 搜尋。
可接受的使用方式
如果您在 Amazon Bedrock 上使用 Web 搜尋,Amazon Bedrock 會將 Web 搜尋結果 (「搜尋結果」) 提供給支援的模型,該模型可能會用來產生其回應。您對包含搜尋結果的模型輸出的使用和最終使用者的任何使用負責。您必須保留並在您向最終使用者呈現的任何輸出中,顯示模型輸出中提供的來源引文和連結。您無法使用 Web 搜尋來 (a) 從搜尋結果大量擷取、儲存或重現內容,或 (b) 建置或填入競爭索引或資料庫。