Amazon Bedrock AgentCore · 00 Overview

Amazon Bedrock AgentCore

A tour of every service, from harness to registry

Deck 00 of the AgentCore training series

Chiwai Chan

Amazon Bedrock AgentCore · 00 Overview

Who am I?

Tinkerer · Cloud · IoT · Robotics · Generative AI

 

https://chiwaichan.co.nz
https://nz.linkedin.com/in/chiwaichan
https://github.com/chiwaichan
https://x.com/chiwaichanconz

Amazon Bedrock AgentCore · 00 Overview

Part 1

The big picture

Amazon Bedrock AgentCore · 00 Overview

What is Amazon Bedrock AgentCore?

  • An agentic platform to build, deploy and operate agents securely at scale
  • Works with any framework and any foundation model
  • No infrastructure to manage
  • Modular: use services together or independently
  • Frameworks named: CrewAI, LangGraph, LlamaIndex, Strands Agents

Open-source flexibility and enterprise-grade security — you don't have to choose.

Amazon Bedrock AgentCore · 00 Overview

Problems it solves

  • Run agents securely at scale — isolated sessions, serverless hosting
  • Act across tools and data with the right permissions and governance
  • Monitor performance and quality in production
  • Remember context across turns and sessions (agents are otherwise stateless)
  • Improve continuously with evaluations, recommendations and A/B tests
Amazon Bedrock AgentCore · 00 Overview

What can you build?

Use case What it looks like
Agents Autonomous apps that reason, use tools, keep context
Tools & MCP servers Turn APIs, Lambda or OpenAPI specs into MCP tools
Agent platforms A paved path: approved tools, shared memory, governed access
Amazon Bedrock AgentCore · 00 Overview

How the services fit together

Layer Services
Build & run Harness (managed loop) · Runtime (host your code)
Context Memory (short-term + long-term)
Tools & connectivity Gateway · Code Interpreter · Browser · Payments
Trust & governance Identity · Policy · Registry
Operate & improve Observability · Evaluations · Optimization

Harness runs inside Runtime; Policy enforces at Gateway; Optimization builds on Evaluations.

Amazon Bedrock AgentCore · 00 Overview

Service map

AgentCore services grouped into five areas, with Harness running inside Runtime, Policy enforcing at Gateway, and Optimization building on Evaluations

Amazon Bedrock AgentCore · 00 Overview

A request, end to end

A user or app invokes the Runtime agent with inbound auth from Identity; the agent uses Memory, Code Interpreter, Browser and Gateway, which Policy evaluates and which calls Lambda, APIs and MCP servers

Amazon Bedrock AgentCore · 00 Overview

Part 2

Build & run

Amazon Bedrock AgentCore · 00 Overview

Harness — a managed agent loop

  • Declare model, system prompt, tools, skills as configuration; AgentCore runs the loop
  • Each session: isolated microVM with its own filesystem and shell
  • Models from Amazon Bedrock, OpenAI, Google Gemini, or LiteLLM-compatible providers
  • Switch model providers mid-session without losing context
  • Tools via AgentCore Gateway, MCP servers, built-in Browser and Code Interpreter
  • Powered by Strands Agents; no separate harness charge
Source: harness
Amazon Bedrock AgentCore · 00 Overview

Harness — lifecycle and when to graduate

  • Built-in short-term and long-term memory; bring your own container
  • Mount S3 Files or EFS to share data across sessions
  • Immutable versions + named endpoints for safe rollout and rollback
  • InvokeHarness state in AWS Step Functions
  • Export to Strands code and run on Runtime when config isn't enough
  • GA in all regions where AgentCore is supported
Amazon Bedrock AgentCore · 00 Overview

Harness vs. Runtime

Harness Runtime
Orchestration loop Provided (Strands) Yours
How you add features Config field Code (usually AgentCore SDK)
Choice of framework No Yes
Bidirectional streaming No Yes
Graph / workflow patterns No Yes
Session isolation, VPC, versioning Yes Yes
Amazon Bedrock AgentCore · 00 Overview

Runtime — serverless hosting for agents and tools

  • Framework agnostic: LangGraph, Strands, CrewAI or custom code
  • Any model: Amazon Bedrock, Anthropic Claude, Google Gemini, OpenAI
  • Protocols: MCP and Agent to Agent (A2A)
  • Each session in a dedicated microVM; memory sanitized when it ends
  • Up to 8 hours per session on microVMs, 14 days on Instances
  • 100MB payloads; HTTP plus WebSocket bidirectional streaming
Amazon Bedrock AgentCore · 00 Overview

Runtime — key building blocks

  • Runtime: hosts your agent or tool code; has a unique identity
  • Versions: immutable snapshots; each config update creates a new one
  • Endpoints: addressable pointers to a version; DEFAULT tracks latest
  • Sessions: identified by runtimeSessionId, isolated microVM each
  • Consumption-based pricing: CPU billing aligned to active processing
  • Built-in inbound auth via AgentCore Identity (Okta, Entra ID, Cognito)
Amazon Bedrock AgentCore · 00 Overview

Part 3

Context & connectivity

Amazon Bedrock AgentCore · 00 Overview

Memory — context-aware agents

Type What it holds Example
Short-term Turn-by-turn events in one session "What about tomorrow?" after a Seattle weather question
Long-term Insights extracted across sessions Remembering a window-seat preference
  • Long-term records come from strategies added to the memory resource
  • Built-in strategies: semantic, user preference, summary, episodic
  • Also built-in overrides and self-managed strategies
Amazon Bedrock AgentCore · 00 Overview

Gateway — one secure entry point for agentic traffic

  • Converts APIs, Lambda functions and services into MCP tools
  • Fronts other agents and HTTP services (incl. A2A) via passthrough
  • Routes inference across model providers by the requested model
  • Inbound and outbound authentication in one managed service
  • Semantic tool search across thousands of tools
  • 1-click integrations: Salesforce, Slack, Jira, Asana, Zendesk
Source: gateway
Amazon Bedrock AgentCore · 00 Overview

Gateway — target categories

Category Behaviour Examples
MCP Aggregated into one virtual MCP server Lambda, API Gateway, OpenAPI, Smithy, MCP servers, integrations, connectors
HTTP Direct, no aggregation or translation AgentCore Runtime agents, A2A agents, passthrough
Inference Model-based routing to providers Amazon Bedrock, OpenAI, Anthropic
  • Inbound auth: OAuth (JWT), IAM (SigV4), authenticate-only, or none
Amazon Bedrock AgentCore · 00 Overview

Identity — identity for agents and workloads

  • Agent identities are workload identities in a central directory
  • Token vault: stores OAuth tokens, client credentials and API keys, KMS-encrypted
  • OAuth 2.0 client credentials (2LO) and authorization code (3LO) flows
  • Built-in providers: Google, GitHub, Slack, Salesforce, Atlassian (Jira)
  • SDK decorators: @requires_access_token, @requires_api_key
  • Native integration with Runtime and Gateway
Amazon Bedrock AgentCore · 00 Overview

Payments — microtransactions for agents

  • Lets agents pay for APIs, MCP servers and content
  • Protocols: x402 and Machine Payments Protocol (MPP), both on HTTP 402
  • Wallet providers: Coinbase CDP and Stripe (Privy)
  • Per-session budget (maxSpendAmount, currency) plus an expiry time
  • Coinbase x402 Bazaar MCP server exposed through AgentCore Gateway
  • Launched in Preview (May 2026)
Amazon Bedrock AgentCore · 00 Overview

Code Interpreter — sandboxed code execution

  • Agents write and run code in an isolated sandbox
  • Languages: Python, JavaScript, TypeScript
  • Pre-built runtimes with common libraries pre-installed
  • Files: up to 100 MB inline; up to 5 GB via S3 with terminal commands
  • Default 15-minute execution, extendable up to 8 hours
  • Custom session properties and network modes; CloudTrail logging
Amazon Bedrock AgentCore · 00 Overview

Browser — a managed cloud browser

  • Isolated, containerized browser for agents to use web apps
  • AWS managed aws.browser.v1, or a custom browser (recording, network, IAM role)
  • Sessions: default 15 minutes, maximum 8 hours; run many at once
  • Automation endpoint (WebSocket) — Strands, Nova Act, Playwright
  • Live View lets an end user watch and interact in real time
  • Session recording to your S3 bucket, replay in the console
Source: browser-tool
Amazon Bedrock AgentCore · 00 Overview

Part 4

Operate & govern

Amazon Bedrock AgentCore · 00 Overview

Observability — trace, debug, monitor

  • Step-by-step visualisation of the agent's execution path
  • CloudWatch dashboards: sessions, latency, duration, tokens, errors
  • Telemetry in OpenTelemetry (OTEL)-compatible format
  • Built-in metrics for agents, gateways and memory by default
  • Instrument your code for extra spans, metrics and logs
  • All data stored in Amazon CloudWatch
Amazon Bedrock AgentCore · 00 Overview

Policy — deterministic control over tool calls

  • Policy engines associated with gateways; every tool call evaluated first
  • Enforced at the gateway boundary, outside agent code
  • Author in Cedar, natural language, or Dogwood
  • Principals: AgentCore::OAuthUser (JWT) or AgentCore::IamEntity (IAM)
  • Temporal policies reason over a session's action history
  • Decisions logged via CloudWatch for audit
Amazon Bedrock AgentCore · 00 Overview

Evaluations — measure agent quality

Type When
Online Continuously, sampling live production sessions
On-demand Targeted, on chosen span or trace IDs
Batch Async job over many sessions; aggregate scores
  • Evaluators: built-in (LLM-as-a-judge), third-party (DeepEval, AutoEval), custom
  • Custom: your own LLM judge or code-based via Lambda
  • Frameworks: Strands, LangGraph with OpenTelemetry / OpenInference
Amazon Bedrock AgentCore · 00 Overview

Optimization — the improvement loop

  1. Recommendations: optimised system prompt or tool descriptions from traces
  2. Configuration bundles (optional): versioned, immutable config snapshots
  3. A/B testing: split traffic via Gateway; online evals report significance
  4. Promote the winner, then repeat from the new baseline

Builds on AgentCore Evaluations — you pick the target evaluator to optimise for.

Amazon Bedrock AgentCore · 00 Overview

AWS Agent Registry — discover and govern

  • Central catalog: MCP servers, agents, tools, skills, custom resources
  • Registries hold records; approval workflow gates discoverability
  • Hybrid search: semantic + keyword
  • Native MCP endpoint for MCP-compatible clients
  • Authorization: IAM or JWT from your corporate IdP
  • GA (August 2026) with AWS Organizations auto-detection
Amazon Bedrock AgentCore · 00 Overview

Security — shared responsibility

  • AWS secures the cloud; you secure what you run in it
  • Data at rest encrypted by default (AWS owned KMS keys); TLS 1.2+ in transit
  • Gateways can use a customer-managed KMS key
  • Resource-based policies for Runtime, Gateway and Memory
  • Use aws:SourceArn / aws:SourceAccount against confused deputy
  • VPC and AWS PrivateLink options
Amazon Bedrock AgentCore · 00 Overview

Part 5

Getting started

Amazon Bedrock AgentCore · 00 Overview

Availability at a glance

Milestone When
Initial release (preview) July 2025
AgentCore GA in nine regions October 2025
Policy, Evaluations, AgentCore CLI GA March 2026
Payments in Preview May 2026
Harness, Recommendations, Batch evals, A/B testing GA July 2026
Failure Insights public preview July 2026
AWS Agent Registry GA August 2026
Amazon Bedrock AgentCore · 00 Overview

Availability timeline

Timeline from the July 2025 preview and October 2025 GA through Policy, Evaluations, Payments, Harness and Agent Registry releases up to August 2026

Amazon Bedrock AgentCore · 00 Overview

Getting started — the AgentCore CLI

npm install -g @aws/agentcore
agentcore create      # Harness, Agent, or Skip
agentcore dev         # local server + agent inspector
agentcore deploy      # CDK under the hood
agentcore invoke --prompt "Hello, what can you do?"
  • Needs Node.js 20+; Python 3.10+ for agent code
  • Build types: CodeZip (default, no Docker) or Container
  • Add capabilities: agentcore add memory | gateway | credential | evaluator
Amazon Bedrock AgentCore · 00 Overview

Interfaces for AgentCore

Interface Use it for
AgentCore CLI Create, dev, deploy, invoke, status
AgentCore Python SDK Runtime, Memory, Tools, Identity, Evaluations primitives
AgentCore MCP server Transform, deploy, test from Kiro, Cursor, Claude Code, Amazon Q CLI
AWS SDK / AWS CLI Full control plane + data plane APIs
AgentCore console Manage services, agent sandbox testing

CLI and Python SDK don't cover every operation — fall back to the AWS SDK.

Amazon Bedrock AgentCore · 00 Overview

Where to go next

# Deck # Deck
01 Getting Started & Tooling 09 Browser
02 Harness 10 Observability
03 Runtime 11 Policy
04 Memory 12 Evaluations
05 Gateway 13 Optimization
06 Identity 14 Agent Registry
07 Payments 15 Security
08 Code Interpreter
Amazon Bedrock AgentCore · 00 Overview

Up next

01 · Getting Started & Tooling

Amazon Bedrock AgentCore · 00 Overview

References

AgentCore Developer Guide — 35 pages (https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/<page>.html)

Notes: This deck is the map for the whole series: a short stop at every AgentCore service, then pointers to the deep-dive decks. Source: 01-what-is-bedrock-agentcore.md

Notes: Quick hello before we start. Source: src/pages/cv.md, docusaurus.config.ts (site links)

Notes: Section break: what AgentCore is and how the services fit together.

Notes: AgentCore is a set of modular services, not a single framework. You can adopt just one service, like Memory or Gateway, alongside an agent you host elsewhere. Source: 01-what-is-bedrock-agentcore.md

Notes: These map directly to the service groups we'll walk through: run, connect, remember, govern, observe and improve. Source: 01-what-is-bedrock-agentcore.md, 07-memory/_index.md, 17-optimization/_index.md

Notes: The docs call out three patterns. Many teams start with an agent, then grow into a shared platform with centralised auth, observability and compliance. Source: 01-what-is-bedrock-agentcore.md

Notes: This grouping is my own framing of the core services table. The three relationships in the callout are stated explicitly in the docs. Source: 01-what-is-bedrock-agentcore.md, 04-harness/13-harness-vs-runtime.md, 15-policy/_index.md, 17-optimization/_index.md

Notes: The same grouping as the previous table (my framing of the core services table), drawn as a map. The number beside each service is the deck in this series that covers it in depth. The three arrows are the relationships the docs state explicitly: harness runs inside Runtime, Policy enforces at Gateway, Optimization builds on Evaluations. Source: 01-what-is-bedrock-agentcore.md, 04-harness/13-harness-vs-runtime.md, 15-policy/_index.md, 17-optimization/_index.md

Notes: A user or app invokes the agent on Runtime, with inbound auth from AgentCore Identity. Agent code calls Memory for context, Code Interpreter and Browser directly, and Gateway for MCP tools. Policy evaluates every tool call at the gateway before execution, and Identity supplies outbound credentials to targets. AgentCore emits built-in metrics for agents, gateways and memory in OTEL-compatible format, stored in CloudWatch. Source: 04-harness/13-harness-vs-runtime.md, 06-agents-tools-runtime/_index.md, 08-gateway/_index.md, 08-gateway/04-gateway-supported-targets/_index.md, 09-identity/_index.md, 15-policy/_index.md, 13-observability/_index.md

Notes: Section break: the Harness and Runtime services.

Notes: Harness turns production agent plumbing into configuration. Trying a new model or tool is a config change, not a rewrite. You pay only for the underlying AgentCore capabilities it uses. Source: 04-harness/_index.md

Notes: The harness is designed to take you to production, and gives you an escape hatch: export to code and move to Runtime when you need a custom framework or non-agent-loop patterns. Source: 04-harness/_index.md, 04-harness/13-harness-vs-runtime.md, 25-release-notes.md

Notes: The rule of thumb from the docs: harness is configuration with no code, Runtime is code you write. Harness itself runs inside Runtime, so CloudTrail records harness operations under the Runtime resource type. Source: 04-harness/13-harness-vs-runtime.md

Notes: Runtime is where you host your own agent code. Two compute types: microVMs, which are fully managed and pay-per-use, and Instances, which run on AWS-managed EC2 in your account for multi-day or GPU workloads. Source: 06-agents-tools-runtime/_index.md

Notes: Versions plus endpoints give you dev, test and prod endpoints and rollback without downtime. Billing typically avoids charges during I/O wait while the agent waits on the LLM. Source: 06-agents-tools-runtime/01-runtime-compute-how-it-works/01-runtime-how-it-works.md, 06-agents-tools-runtime/_index.md

Notes: Section break: Memory, Gateway, Identity, Payments, Code Interpreter and Browser.

Notes: Without strategies, no long-term records are extracted. Built-in strategies run extraction and consolidation for you; overrides let you customise prompts; self-managed gives you full control. Source: 07-memory/_index.md, 07-memory/01-how-it-works/03-memory-strategies/_index.md, 07-memory/01-how-it-works/03-memory-strategies/01-built-in-strategies/_index.md

Notes: Gateway has grown beyond an MCP tool gateway. It is now a single entry point for tools, other agents and models, with auth on both sides. Source: 08-gateway/_index.md

Notes: MCP targets show up in one consolidated tools/list. HTTP targets are addressed individually through path-based routing. Inbound "no authorization" is intended for development and testing. Source: 08-gateway/02-gateway-core-concepts.md, 08-gateway/04-gateway-supported-targets/_index.md

Notes: Identity covers both directions: who may call the agent, and how the agent gets credentials for AWS and third-party services on behalf of users. Secrets stay out of agent code. Source: 09-identity/_index.md, 09-identity/01-identity-overview/_index.md, 09-identity/01-identity-overview/01-key-features-and-benefits.md

Notes: Micro-payments of cents are uneconomic with card fees; payments uses stablecoin wallets and open protocols. Wallet credentials are stored via AgentCore Identity. Source: 10-payments/_index.md, 25-release-notes.md

Notes: Code Interpreter lets agents solve problems that reasoning alone can't, like precise calculations or data analysis over CSV, Excel or JSON, without risking your own environment. Source: 11-code-interpreter-tool/_index.md

Notes: Browser gives agents navigation, form filling, screenshots and extraction, with human-in-the-loop via Live View. Session recording is available for custom browsers. Source: 12-browser-tool/_index.md

Notes: Section break: Observability, Policy, Evaluations, Optimization, Registry and Security.

Notes: Because the output is OTEL-compatible, you can plug it into your existing observability stack. The CloudWatch observability dashboard applies to agent runtime data. Source: 13-observability/_index.md

Notes: Natural-language authoring generates Cedar, validates it against the tool schema, and uses automated reasoning to flag overly permissive or unsatisfiable policies. Source: 15-policy/_index.md, 15-policy/02-policy-core-concepts.md

Notes: Built-in evaluators have public ARNs such as Builtin.Helpfulness and can't be modified. Batch evaluation supports ground truth for regression testing. Source: 16-evaluations/_index.md, 16-evaluations/01-how-it-works-evaluations/03-evaluations-types.md, 16-evaluations/01-how-it-works-evaluations/02-evaluators.md

Notes: A/B tests can compare bundle versions on the same runtime, or different gateway targets pointing at different runtime endpoints when code changes. Failure Insights, for pattern analysis, is in public preview. Source: 17-optimization/_index.md, 17-optimization/01-optimization-how-it-works.md, 17-optimization/06-insights/_index.md

Notes: Workflow: an admin creates a registry, publishers submit records, curators approve or reject, and consumers search or connect through MCP. This stops teams rebuilding tools that already exist. Source: 18-registry/_index.md, 25-release-notes.md

Notes: Note that some gateway data isn't encrypted by default, such as gateway, target and tool names, so never put sensitive data in names or tags. Source: 22-security/_index.md, 22-security/01-data-protection/_index.md, 22-security/01-data-protection/01-data-encryption.md, 22-security/04-resource-based-policies.md, 22-security/07-cross-service-confused-deputy-prevention.md

Notes: Section break: availability, the CLI, interfaces and where to go next.

Notes: Always check the release notes before a customer conversation; the platform moves fast. Source: 25-release-notes.md

Notes: The same milestones as the previous table on a timeline: roughly a year from preview to GA, then a steady cadence of new services through 2026. Source: 25-release-notes.md

Notes: That's the whole loop: create, dev, deploy, invoke. Code-based agents can use Strands, LangChain/LangGraph, Google ADK or OpenAI Agents SDK. Source: 03-agentcore-get-started-cli.md

Notes: Control plane APIs create resources like a Runtime or Memory; data plane APIs do runtime work like InvokeAgentRuntime or adding memory events. Source: 05-develop-agents.md

Notes: Each topic deck goes deep on one service with examples from the docs. Suggested order for newcomers: 01, then 02 or 03, then 05 and 06. Source: 01-what-is-bedrock-agentcore.md

nav:up-next

Notes: That's the end of Overview. Next up is Getting Started & Tooling; the series page lists every deck in order.

Notes: References continue on the next slide. Source: all files cited in this deck