AWS Comprehend compatibility
Use AWS SDKs and SigV4 credentials with ShinrAI's supported Comprehend PII operations.
The vendor contract limits what ShinrAI can return: types, confidence, media, sessions and jobs. Results can therefore be weaker than ShinrAI can deliver. For full quality, use the native PII API v2.
Endpoints
Use the vendor endpoint for an unchanged client. The same adapter also runs under a path prefix on the API host; ShinrAI extensions to the vendor format appear there first.
| API | Endpoint: change only this | Alternative on the API host |
|---|---|---|
| AWS Comprehend | https://aws.api.getshinrai.com | https://api.getshinrai.com/v1/aws |
| Sandbox | https://aws.api-sbx.getshinrai.com | https://api-sbx.getshinrai.com/v1/aws |
This endpoint serves its own OpenAPI document: OpenAPI for this API.
Create locally revocable SDK credentials
Call POST /providers/aws/credentials on the AWS endpoint with your normal ShinrAI Bearer key. The response contains an access key ID and secret access key derived for your account. Revoking the underlying ShinrAI key invalidates the pair.
curl -X POST https://aws.api.getshinrai.com/providers/aws/credentials \
-H "Authorization: Bearer $SHINRAI_API_KEY"
Use the normal AWS SDK
import boto3, os
client = boto3.client(
"comprehend",
region_name="eu-central-1",
endpoint_url="https://aws.api.getshinrai.com",
aws_access_key_id=os.environ["SHINRAI_AWS_ACCESS_KEY_ID"],
aws_secret_access_key=os.environ["SHINRAI_AWS_SECRET_ACCESS_KEY"],
)
result = client.detect_pii_entities(Text="Email emma@example.com", LanguageCode="en")
Supported operations
The root JSON 1.1 endpoint dispatches supported synchronous detection and asynchronous job operations using X-Amz-Target. Requests require AWS Signature Version 4 with the comprehend service name.
The API explorer includes a browser-local SigV4 signer. Generate credentials, authorize the three AWS fields, select an operation target, and send the request. Credentials are cleared on reload.
SigV4 signs the request path: / on the AWS endpoint and /v1/aws/ on the API host. Do not let a reverse proxy rewrite the path after signing.