The platform to build, connect, and optimize agents. Any framework, any model.
Build and deploy agents without months of infrastructure work
Give agents secure access to MCP servers, APIs, and knowledge bases
Trace every decision, evaluate performance, safely test improvements
A computer program that works independently to achieve the goals you give it — and interacts with its environment to get the information it needs.
Composable by design — click any capability to explore it or jump into its live demo, then compose an agent from just the pieces it needs.
AgentCore is modular: you turn on only the capabilities your agent needs, and pay only for what you use. Pick an example:
Build agents as configuration. Pick options on the left, then run CreateHarness → InvokeHarness. Zero infrastructure config.
# Click ① CreateHarness to begin
Deploy with one command, from a laptop prototype to production scale. Works with any framework (Strands, LangGraph, CrewAI…), any model, A2A · MCP · HTTP · AG-UI.
Each turn, the agent assembles these context sources into a single LLM prompt.
Events land in short-term memory synchronously; extraction runs asynchronously into long-term memory — summaries, preferences, facts and episodes.
Each memory is stored as an embedding. At retrieval the query is embedded too, and the closest memories by meaning are returned — not just keyword matches.
Point the OpenAI or Anthropic SDK at the Gateway’s /inference endpoint. The model field picks the provider; the Gateway adds auth, policy, guardrails, token limits and the provider’s credentials.
/inferencePick a model and send a request.
Secure, isolated execution environments: a headless browser to operate web apps, and a sandbox with shell & file system to execute code.
When an agent needs paid APIs, paid MCP servers or paid data, AgentCore Payments handles the payment through a single API.
Observability traces every decision; evaluations score quality; insights & recommendations propose fixes; A/B tests validate them on live traffic.
- You are a support assistant.+ You are a support assistant. Before calling+ refund_order, verify the order ID with+ lookup_order and confirm the amount.
Stateful, trajectory-aware authorization evaluated at the Gateway perimeter — deny-by-default, outside the agent loop.
// Evaluated policy appears here (Dogwood temporal policy language, Cedar-compatible)
Quality gates before release, the AWS Agent Registry for lifecycle, Gateway traffic splitting for canaries, and evals + observability after.
Rollback = the Gateway routes traffic back to a known-good version kept in the Registry. No rebuild or redeploy, so it takes seconds.
When one agent serves many tenants, every AgentCore component needs a tenancy decision. Explore the concerns, then choose pool or silo for each component.
Bind the tenant to the user in the IdP token, validate it on the way in, and pass it on down-scoped on the way out.
Decide how much of the stack each tenant gets to itself. Send a request from each tenant to follow its path.
A tool call to the Gateway passes three checks in order, each finer-grained than the last. This Gateway serves tenant ABC.
Checks who is calling
allow if tenant_id = "ABC"Checks what they may do
refund_order only if amount < 100 and group = "Admin"Checks the tool is enabled for the tenant, cleans data
registry: ABC → lookup_order, refund_order// responseOne Memory resource, many tenants. The runtime turns the tenant in the JWT into scoped AWS credentials, so each tenant can only reach its own actorId and namespace.
// API results appear here
{ "Effect": "Allow",
"Action": ["bedrock-agentcore:CreateEvent",
"bedrock-agentcore:ListEvents",
"bedrock-agentcore:GetEvent"],
"Resource": "arn:aws:bedrock-agentcore:*:*:memory/pool-memory",
"Condition": { "StringEquals": {
"bedrock-agentcore:actorId":
"${aws:PrincipalTag/actorId}" } } }
Emit metrics with tenant_id, aggregate them daily, and split each shared service’s cost by usage.
Any framework, any model. Start with one capability and add more as you grow.
Run for hours in persistent, isolated sessions, many in parallel.
Event-driven agents that triage, route and act on emails, tickets and alerts.
Resolve customer and employee issues faster, connected to CRM, ITSM and knowledge bases.