Amazon Bedrock AgentCore Gateway
What it is
A fully managed AWS service that gives agents one secure endpoint to tools, other agents and LLMs. Per AWS docs it converts APIs, Lambda functions and existing services into MCP-compatible tools, fronts other agents and HTTP services (including A2A traffic) through passthrough targets, and routes inference requests across model providers. It is one component of Amazon Bedrock AgentCore (see AWS data and AI platform).
Maker and licence
Amazon Web Services; closed, managed service (no self-host). Part of AWS.
Position
Managed MCP gateway plus HTTP/A2A passthrough plus LLM routing endpoint.
Core capabilities (per AWS docs)
- Target types: MCP targets (aggregated into one virtual MCP server), HTTP targets, inference targets. Tool inputs: OpenAPI, Smithy, Lambda; one-click integrations named for Salesforce, Slack, Jira, Asana and Zendesk.
- Auth: inbound authentication (verifying the agent) and outbound authentication (credential injection per target, OAuth flows, token refresh). At GA AWS added IAM authorization alongside OAuth.
- Semantic tool search through a built-in search tool.
- Optional features: customer-managed KMS key, tagging, MCP sessions, response streaming (SSE), elicitation, sampling, debug messages. Fine-grained access control and rules are documented.
- Serverless, with built-in observability and auditing. Works with CrewAI, LangGraph, LlamaIndex and Strands Agents.
MCP spec support
The docs pages checked do not name an MCP specification revision; they list sessions, streaming, elicitation and sampling as supported features.
Maturity
Amazon Bedrock AgentCore became generally available on 2025-10-13 (AWS What’s New). The feature set above reflects the docs as read on 2026-10-08.
Fit and limits (opinion)
Natural choice when agents already run on AWS and tools are Lambda or OpenAPI backed; lock-in to AWS identity and the managed service is the trade-off.
Pricing
Usage-based managed service; see the AWS AgentCore pricing page.
Self-learning
- https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway.html
- https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-features.html
- https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-supported-targets.html
- https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-quick-start.html (linked from the overview)
Related
- agentgateway, Portkey, Arcade MCP gateway, OmniRoute, MCP security with a gateway, Model Context Protocol
Sources
- https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway.html (2026-10-08)
- https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-features.html (2026-10-08)
- https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-supported-targets.html (2026-10-08)
- https://aws.amazon.com/about-aws/whats-new/2025/10/amazon-bedrock-agentcore-available/ (2026-10-08)
Open items
- MCP spec revision supported and regional availability not checked.
- AWS states Gateway is “the only solution” with both ingress and egress authentication; vendor claim, not evaluated.