AgentCore
Amazon Bedrock AgentCoreDEEP DIVE
AgentCore logo
Product deep dive

Amazon Bedrock
AgentCore

The platform to build, connect, and optimize agents. Any framework, any model.

🚀

Ship agents fast

Build and deploy agents without months of infrastructure work

🔌

Connect to anything

Give agents secure access to MCP servers, APIs, and knowledge bases

📈

Optimize continuously

Trace every decision, evaluate performance, safely test improvements

🔒 Security at scale🏢 Enterprise readiness🎯 Deterministic control
Tip: click an orbiting component to jump straight to it
FOUNDATIONS

What is an agent?

A computer program that works independently to achieve the goals you give it — and interacts with its environment to get the information it needs.

👤 User
🤖 Other agent
🧩 Any system
Agent
🧠 Reasonon the request
🗺️ Planahead
⚡ Decideand act
🔎 Gatherknowledge from environment
INPUTUserEvent
REASONINGModels
CONTEXTSystem promptConversation historyMemoryKnowledge baseSkillsWeb search
ENVIRONMENTSComputeToolsNetworkStorage
Getting from a prototype loop to production means solving all of these — securely, at scale. That's what AgentCore is for.
THE PLATFORM

Everything you need for getting agents to production

Composable by design — click any capability to explore it or jump into its live demo, then compose an agent from just the pieces it needs.

Amazon Bedrock AgentCore
AGENT HARNESS
CONTEXT AND TOOLS
OPTIMIZATION
ENVIRONMENT
SECURITY AND
GOVERNANCE
COMPOSABLE BY DESIGN · PAY ONLY FOR WHAT YOU USE · * preview
👈Click any capability to explore it
🧱 Compose your agent0 of 19 enabled

AgentCore is modular: you turn on only the capabilities your agent needs, and pay only for what you use. Pick an example:

AGENT HARNESS

Managed harness: you bring the logic, we handle the infrastructure

Build agents as configuration. Pick options on the left, then run CreateHarness → InvokeHarness. Zero infrastructure config.

YOU CONFIGURE
🧠 Models Pick your model
🔧 Tools Attach your tools
💾 Memory & Skills Plug in if needed
🪪 Identity & Evals Connect & configure
Managed Harness not created
Your configuration lands here
Orchestration loop · reason → act → observe
WE MANAGE — INCLUDED AUTOMATICALLY
⚙️ RuntimeFirecracker microVM
📊 ObservabilityTraces, logs, metrics
🗄️ StorageManaged & persistent
🔒 SecurityIsolated by default
 CreateHarness requestbedrock-agentcore-control API

        
🖥️ Console
# Click ① CreateHarness to begin
ENVIRONMENT · RUNTIME

AgentCore Runtime: every session in its own sealed box

Deploy with one command, from a laptop prototype to production scale. Works with any framework (Strands, LangGraph, CrewAI…), any model, A2A · MCP · HTTP · AG-UI.

👥 Users
AgentCore runtime
Compute type
0 sessions
Click ✕ on a session to end it
📈 Traffic spike simulation

0sessions now
0peak
–p90 cold start
CONTEXT AND TOOLS

A model knows the world, but not your business

Each turn, the agent assembles these context sources into a single LLM prompt.

➜
🧾 LLM Prompt 0 tokens
LLM RESPONSE OR TOOL EXECUTIONwaiting for prompt…
AGENTCORE MEMORY

Give agents a memory that outlasts the conversation

Events land in short-term memory synchronously; extraction runs asynchronously into long-term memory — summaries, preferences, facts and episodes.

💬 Conversation session s-001
⚡ Short-term memory raw events · sync

        
⚙️
Memory extractionasync · every k events · add / update / skip
ExtractionConsolidationEmbedding & indexing
📝 Summaries
💖 Preferences
📌 Facts
🎬 Episodes
📄 Sample LTM recordillustrative
🧭 Vector space semantic retrieval

Each memory is stored as an embedding. At retrieval the query is embedded too, and the closest memories by meaning are returned — not just keyword matches.

AGENTCORE GATEWAY

Serverless AI gateway: one secure endpoint for tools, agents & models

SOURCES
🤖 AgentsStrands, LangGraph, …
👩‍💻 Coding assistantsClaude Code, Codex, Kiro
🧩 MCP clientsany MCP-compatible client
📱 Applicationsyour apps & services
AgentCore Gateway
/mcp/inference/v1A2A
🔐
Authentication & credentialsAgentCore Identity · OAuth / IAM / API key
⏱️
Rate limits & AWS WAFRPS · TPM · CPS per user / target
📜
Policy in AgentCoreCedar · fine-grained · temporal
🛡️
Bedrock Guardrailscontent filters · PII · prompt attacks
🔁
Interceptors & routingrequest/response transform · model routing
📊
Observabilitymetrics · logs · audit
INFERENCE TARGETS
Amazon Bedrock
OpenAI
Anthropic
AGENT TARGETS
AgentCore Runtime · RefundAgent
Custom endpoints
MCP TARGETS
Web Search
Managed Knowledge Base
AWS Lambda
API Gateway · REST · MCP server
0requests
0allowed
0blocked
–avg latency
AGENTCORE GATEWAY · INFERENCE TARGETS

Gateway as an LLM gateway: one endpoint for every model provider

Point the OpenAI or Anthropic SDK at the Gateway’s /inference endpoint. The model field picks the provider; the Gateway adds auth, policy, guardrails, token limits and the provider’s credentials.

🎯 Single endpoint/inference/v1/… 🧭 Model-based routingby the model field 🔐 Credential abstractiontoken vault · IAM role 🛡️ Central governancePolicy · Guardrails ⏱️ Token rate limitsTPM per user / model 📋 Aggregated modelsGET /v1/models
🐍AppOpenAI SDK
AgentStrands / any framework
🧑‍💻AppAnthropic SDK
AgentCore Gateway/inference
🔐
Inbound authJWT or IAM
📜
Policy & Guardrailswho may use which model · content checks
⏱️
Rate limitsRPM · TPM · connections
🧭
Model-based routingqualified · unqualified · collision
🔑
Outbound credentialsadded per target
bedrock-mantleconnector · Amazon BedrockIAM role (SigV4)
openaiconnector · OpenAIAPI key · Authorization
anthropicconnector · AnthropicAPI key · x-api-key
customprovider target · examplenot yet created
User group
model =
Routing decision

Pick a model and send a request.


      
FULLY MANAGED TOOLS

AgentCore Browser & Code Interpreter

Secure, isolated execution environments: a headless browser to operate web apps, and a sandbox with shell & file system to execute code.

🌐 AgentCore Browser “Open a ticket to fix my laptop”

🎫 New IT ticket

Submit ticket
✅ Ticket #4821 created

      
💻 AgentCore Code Interpreter “How are my accounts doing?”
🐚 Shell📁 File system🐍 Python · JS · TS🔒 Sandboxed
AGENTCORE PAYMENTS

Letting agents pay for the data they need

When an agent needs paid APIs, paid MCP servers or paid data, AgentCore Payments handles the payment through a single API.

Watch an agent pay for data it needs
👤
User
Analyze Amazon stock 📈
Agent
🏦
Paid resourcepaid API · paid MCP · paid data
x402 payment required
💳
AgentCore Paymentssingle API · spending limits
Session wallet $5.00
How it flows
  1. User asks: “Analyze Amazon stock”
  2. Agent needs paid market data
  3. Resource returns an  x402 payment request
  4. AgentCore Payments handles payment
  5. Agent gets data to complete the task
  6. Agent responds to the user

OPTIMIZATION

Improving agents with a continuous loop

Observability traces every decision; evaluations score quality; insights & recommendations propose fixes; A/B tests validate them on live traffic.

Continuous
improvementobserve → evaluate → improve → deploy
💡 Insights · failure analysis PREVIEW
Tool errors42%
Hallucinations23%
Bad reasoning18%
Other17%
🧪 Recommendation · system prompt
- You are a support assistant.+ You are a support assistant. Before calling+ refund_order, verify the order ID with+ lookup_order and confirm the amount.
Generated from real traces · targets Goal success
⚖️ A/B test on live traffic Gateway routes config bundles per session · online evals score every session
🔀Gateway
Control · v1 (baseline)
–
0 sessions
Treatment · v2 (optimized)
–
0 sessions
✅ 13 built-in evaluators LLM-as-judge & code-based · or define your own
SECURITY & GOVERNANCE

Temporal policies: deterministic control over autonomous agents

Stateful, trajectory-aware authorization evaluated at the Gateway perimeter — deny-by-default, outside the agent loop.

🤖 Trading agent · session t-01
No quote yet
quote freshness
Cumulative traded$0 / $60K
🤖Agent
Gateway · Policy enginedeny-by-default
🏦Trading APIMCP target
🙋Human reviewerapproves trades > $25K
🕒 Temporal policy statesession trajectory · 24h look-back · keyed by x-amzn-bedrock-agentcore-policy-session-id + user identity
📜 Active policies + existing stateless RBAC
① Workflow sequencingquote before trade
② Output integrityprice matches quote
③ Cumulative limit$60K cap
④ Human approvaltrades > $25K
⑤ Data freshness1 min window
⑥ Inactivity timeout15 min
// Evaluated policy appears here (Dogwood temporal policy language, Cedar-compatible)
AGENTOPS

Running agents in production: CI/CD + ongoing operations

Quality gates before release, the AWS Agent Registry for lifecycle, Gateway traffic splitting for canaries, and evals + observability after.

📝
Commitagent code + config
🧪
Build & testlint, unit tests
🎯
Validatequality + safety scoring
🧭
Promote to stagecomprehensive QA
🗂️
Registrypush to Agent Registry
🚀
Promote to prodcanary → 100%
Scenario:
📈 Monitoring & evals Observability · Evaluations · CW alerts
Live quality0.88
Cost / task$0.04
Behavior0.94
p90 latency2.1s
🔀 Gateway traffic split
v1.4 · 100%
current: v1.4new: –
🗂️ AWS Agent Registry version history

Rollback = the Gateway routes traffic back to a known-good version kept in the Registry. No rebuild or redeploy, so it takes seconds.

MULTI-TENANCY · 1 / 6

Multi-tenant agents: one agent product, many customers

When one agent serves many tenants, every AgentCore component needs a tenancy decision. Explore the concerns, then choose pool or silo for each component.

🧩 Agent-as-a-Service: pool or silo per component
MULTI-TENANCY · 2 / 6

Tenant context and identity: who is calling, for which tenant?

Bind the tenant to the user in the IdP token, validate it on the way in, and pass it on down-scoped on the way out.

🪪 Binding tenant identity to user identity
Tenant context can come fromSubdomainURL pathHeadersCookiesRequest bodyDatastoreJWT claim ✓ recommended
Signed-in user

        
■ security context■ tenant context■ request context
🤝 Calling tools: impersonation vs act-on-behalf
👤Usertenant_1
AgentAgentCore Runtime
🔐AgentCore Identitytoken exchange
📦Order toolneeds orders:read
🏷️Promotions toolneeds promotions:write

          

        

MULTI-TENANCY · 3 / 6

Tenancy patterns: silo, pool and bridge

Decide how much of the stack each tenant gets to itself. Send a request from each tenant to follow its path.

MULTI-TENANCY · 4 / 6

Tenant isolation at the Gateway: three checks on every call

A tool call to the Gateway passes three checks in order, each finer-grained than the last. This Gateway serves tenant ABC.

1Pick a scenario→2Watch the request move through the checks→3Read why it was allowed or blockedOr edit the request yourself and press Send
🧾 Request tools/call
Tenant
Group
Tool
Amount
1
JWT authorizerfine-grained

Checks who is calling

allow if tenant_id = "ABC"
2
AgentCore Policyfiner-grained

Checks what they may do

refund_order only if amount < 100 and group = "Admin"
3
Gateway interceptorfinest-grained

Checks the tool is enabled for the tenant, cleans data

registry: ABC → lookup_order, refund_order
🧰 ABC’s tools
// response
Pick a scenario above to send a request.
MULTI-TENANCY · 5 / 6

Tenant isolation in pooled AgentCore Memory

One Memory resource, many tenants. The runtime turns the tenant in the JWT into scoped AWS credentials, so each tenant can only reach its own actorId and namespace.

🪜 What happens on each call
  1. Extract tenant_id and sub from the incoming JWT
  2. Map them to an IAM session tag: actorId = tenant/user
  3. Call sts:AssumeRole on the ABAC role, with that tag
  4. Call AgentCore Memory with the tenant-scoped credentials
// API results appear here
🪪JWTtenant_id: TenantA
sub: userA
Agent Runtimepooled
🔑AWS STSABAC IAM role
AgentCore Memory · pool-memory
TenantAactorId TenantA/userA · namespace /…/TenantA
STM: “My plan renews in May”LTM: prefers email
TenantBactorId TenantB/userB · namespace /…/TenantB
STM: “Ship to Jakarta office”LTM: VIP customer
📜 ABAC role policy
{ "Effect": "Allow",
  "Action": ["bedrock-agentcore:CreateEvent",
             "bedrock-agentcore:ListEvents",
             "bedrock-agentcore:GetEvent"],
  "Resource": "arn:aws:bedrock-agentcore:*:*:memory/pool-memory",
  "Condition": { "StringEquals": {
    "bedrock-agentcore:actorId":
      "${aws:PrincipalTag/actorId}" } } }
🗂️ Namespace levels click one

MULTI-TENANCY · 6 / 6

Observability and cost per tenant

Emit metrics with tenant_id, aggregate them daily, and split each shared service’s cost by usage.

🏢Tenant 1enterprise · 0 tok
🏪Tenant 2standard · 0 tok
🏬Tenant 3standard · 0 tok
Agentemits EMF metrics
📈CloudWatchLogs Insights
🧾Cost & Usage Reportvia Athena
λAggregatordaily Lambda
🗄️DynamoDBattribution
💰 Cost per tenant Amazon Bedrock · total $60
🧮 Sample records

Start building with Amazon Bedrock AgentCore

Any framework, any model. Start with one capability and add more as you grow.

SOFTWARE DEVELOPMENT

👩‍💻 Coding agents

Run for hours in persistent, isolated sessions, many in parallel.

INTERNAL PRODUCTIVITY

⚙️ Workflow agents

Event-driven agents that triage, route and act on emails, tickets and alerts.

CUSTOMER SERVICE

💬 Conversational agents

Resolve customer and employee issues faster, connected to CRM, ITSM and knowledge bases.