{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "agentcore-identity",
    "name": "Amazon Bedrock AgentCore Identity",
    "vendor": "Amazon Web Services",
    "vendorUrl": "https://aws.amazon.com/bedrock/agentcore/",
    "kind": "http-api",
    "category": "agent-auth",
    "summary": "Amazon Bedrock AgentCore Identity is an AWS service that gives agents workload identities, stores OAuth tokens and API keys in a token vault, and runs OAuth flows so agents can call third-party services for users or for themselves.",
    "url": "https://www.anchorterminal.com/tools/agentcore-identity",
    "markdownUrl": "https://www.anchorterminal.com/tools/agentcore-identity.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/agentcore-identity.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json",
    "repo": "https://github.com/aws/bedrock-agentcore-sdk-python",
    "license": "Proprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://bedrock-agentcore.us-east-1.amazonaws.com",
    "packages": [
      {
        "registry": "pypi",
        "name": "bedrock-agentcore"
      },
      {
        "registry": "npm",
        "name": "bedrock-agentcore"
      },
      {
        "registry": "npm",
        "name": "@aws-sdk/client-bedrock-agentcore"
      },
      {
        "registry": "pypi",
        "name": "boto3"
      }
    ],
    "auth": "mixed",
    "authNotes": "A person creates an AWS account and an IAM role. Control-plane calls (`bedrock-agentcore-control`) and data-plane calls (`bedrock-agentcore`) are SigV4-signed with IAM credentials, and the data plane also documents an OAuth bearer route (`UnauthorizedException` for an invalid JWT). The agent first gets a workload access token that carries its own identity and the user's, from a JWT (`GetWorkloadAccessTokenForJWT`), a user ID string (`GetWorkloadAccessTokenForUserId`) or neither (`GetWorkloadAccessToken`), then exchanges it for a third-party OAuth token or API key. Each third-party provider needs an OAuth client the owner registers with that provider. AgentCore Runtime and Gateway fetch the workload access token for the agent.",
    "pricing": "usage",
    "pricingNotes": "$0.010 per 1,000 OAuth token or API key requests for non-AWS resources, billed per successful request, with no minimum fee. No additional charge when the service is used through AgentCore Runtime or AgentCore Gateway, which are billed on their own meters. No free tier specific to Identity was found. New AWS accounts get up to $200 of Free Tier credit for up to 6 months, and AWS says most new customers need no payment method at sign-up though it may ask for one (https://aws.amazon.com/bedrock/agentcore/pricing/, https://aws.amazon.com/free/free-tier-faqs/).",
    "priceSummary": "$0.01 / 1k req",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 for paying AWS on the pricing page or in the docs. AgentCore payments is a separate capability for agents paying third-party sellers (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 334717,
      "pypiWeekly": 1421946,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/identity.html",
    "llmsTxt": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/llms.txt",
    "capabilities": [
      "auth.oauth",
      "auth.tokens",
      "auth.consent",
      "auth.agent-identity",
      "auth.audit",
      "infra.aws"
    ],
    "tags": [
      "hosted",
      "closed-source",
      "usage-priced",
      "oauth",
      "llms-txt",
      "python",
      "typescript",
      "enterprise",
      "sla",
      "soc2",
      "eu"
    ],
    "lastRelease": "2026-09-01",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 74.8,
      "grade": "BB",
      "agentReady": true,
      "rank": 64,
      "ranked": true,
      "rankOf": 842,
      "categoryRank": 2,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 76,
        "maintenance": 70,
        "payments": 30,
        "reliability": 85,
        "schema": 88,
        "security": 84,
        "transparency": 75
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 85,
          "points": 17,
          "reason": "AWS Health Dashboard with a per-service, per-Region feed for Bedrock AgentCore (20). The dashboard's history file, read on 8 October 2026, lists one event naming AgentCore in the last 90 days, elevated packet loss in one Availability Zone of eu-south-2 on 4 October 2026 from 8:48 to 11:28 AM PDT, at informational status and shared with 31 other services. The us-east-1 feed had no items. Minor only (20 of 30). Quotas published per operation, 200 requests a second for the workload access token calls and 20 for management calls (15). The API reference documents `ThrottlingException` (429) and `InternalServerException` (500) with advice to retry with exponential backoff, but no idempotency token was found on `CreateWorkloadIdentity` (12 of 15). The AgentCore FAQ says the Amazon Bedrock SLA applies, 99.9 per cent a Region, though that SLA's definitions speak of model APIs and do not name AgentCore (8 of 10, our call). Generally available since October 2025, and the consent portal carries no preview label (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 88,
          "points": 14.3,
          "reason": "Service models for `bedrock-agentcore` and `bedrock-agentcore-control` ship in the AWS SDKs. We confirmed the SDK clients and the API reference, and did not open the model files (25). llms.txt for the developer guide and for the API reference, with a Markdown twin of every page (10). API reference descriptions are one line each, while the guide says when to use the JWT route and when the user ID route (15 of 20). Typed members with enums, patterns and length limits, such as `oauth2Flow` and `credentialProviderVendor`, and one string map, `customParameters` (14 of 15). Named errors with HTTP codes on every operation and CLI and Python examples in the guide, but no examples on the API reference pages we read (12 of 15). Release notes by month without days, SDK changelogs with dates, and the notes' RSS feed was not found at the address we tried (12 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 76,
          "points": 12.35,
          "reason": "Responses are small, a token or an authorisation URL with a session status, and list calls take `maxResults`. There is no MCP server for Identity to weigh (20 of 25). List operations page with `nextToken` and `maxResults`, and no filters were found (15 of 20). Named exceptions with recovery advice, and a missing consent comes back as `authorizationUrl` and `sessionUri` in a 200 response, which an agent can act on (18 of 20). Token reads are safe to repeat and `forceAuthentication` restarts consent, but no client token for idempotent creates was found and there are no MCP annotations (10 of 20). AWS SDKs in nine languages plus AgentCore SDKs for Python and TypeScript with `@requires_access_token` and `@requires_api_key` decorators. `GetResourceOauth2Token` has four required members, and user-delegated flows need the owner to host a callback endpoint (13 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 84,
          "points": 14.7,
          "reason": "IAM with SigV4 and short-lived role credentials, plus a workload access token that carries the agent's identity and the user's, and policies that name one workload identity and one credential provider ARN (30). Users consent through the provider's own OAuth screen with session binding, but AWS says the service enforces no binding between workload identities and credential providers beyond the owner's IAM policy, the user ID route is unverified, and no call to revoke one user's grant was found (15 of 20). The service returns tokens and keys, not untrusted content (10). The guide points to CloudTrail for `GetWorkloadAccessTokenForUserId` calls and KMS signing, but no Identity-specific CloudTrail page listing logged events was found, unlike Gateway and Agent Registry (11 of 15). A disclosure programme on HackerOne, public bulletins, AgentCore in SOC 1, 2 and 3 scope on the list of 11 August 2026 and ISO 27001 per the compliance page, with the security.txt expired since 24 September 2026 and no paid bounty found, read as our other AWS listings read it (18 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 30,
          "points": 3.75,
          "reason": "No x402, MPP or L402 for paying AWS. AgentCore payments is a separate capability for agents paying third parties (0). $0.010 per 1,000 token or API key requests on the public pricing page (20). No Identity free tier, but new accounts get up to $200 of Free Tier credit and the FAQ says most new customers need no payment method, while AWS may still ask for one, so half, as on our other AWS listings (10). A person creates the AWS account and registers an OAuth client with each provider (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 70,
          "points": 6.13,
          "reason": "The newest Identity change is the consent portal, announced 1 September 2026, 37 days before the check (20 of 30). In the last 90 days we could date the consent portal and Python SDK 1.21.0 of 6 August 2026, which added workload access token propagation. Private Key JWT is listed under July without a day. The Python SDK had ten releases in the 90 days to 8 October across all of AgentCore (15 of 20). Public release notes and What's New, with AWS Support and re:Post, and issue triage workflows in the SDK repository. We did not read the issue tracker (10 of 15). Current official SDKs, `bedrock-agentcore` 1.24.1 on PyPI on 7 October 2026 and `@aws-sdk/client-bedrock-agentcore` 3.1148.0 (15). The SDK repository runs CI, integration tests, a breaking-change check, security scanning and Dependabot (10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 75,
          "points": 6.56,
          "note": "editorial 61, provenance 88",
          "reason": "Closed service under the AWS Service Terms updated 1 October 2026, with Apache-2.0 SDKs (15 of 30). The Identity data protection pages state KMS encryption at rest with an optional customer managed key and warn that names and free-text fields can reach diagnostic logs. The privacy notice is dated 18 May 2026. No retention period for stored tokens or request metadata was found (20 of 30). No deprecation policy for the service found. The one dated notice we saw is the starter toolkit's deprecation on 27 March 2026, in a security bulletin (8 of 20). A sub-processor list updated 28 July 2026 and regional endpoints in 21 Regions, with the vault held in the Region the owner picks (18 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Responses are small, a token or an authorisation URL with a session status, and list calls take `maxResults`. There is no MCP server for Identity to weigh (20 of 25). List operations page with `nextToken` and `maxResults`, and no filters were found (15 of 20). Named exceptions with recovery advice, and a missing consent comes back as `authorizationUrl` and `sessionUri` in a 200 response, which an agent can act on (18 of 20). Token reads are safe to repeat and `forceAuthentication` restarts consent, but no client token for idempotent creates was found and there are no MCP annotations (10 of 20). AWS SDKs in nine languages plus AgentCore SDKs for Python and TypeScript with `@requires_access_token` and `@requires_api_key` decorators. `GetResourceOauth2Token` has four required members, and user-delegated flows need the owner to host a callback endpoint (13 of 15).",
          "maintenance": "The newest Identity change is the consent portal, announced 1 September 2026, 37 days before the check (20 of 30). In the last 90 days we could date the consent portal and Python SDK 1.21.0 of 6 August 2026, which added workload access token propagation. Private Key JWT is listed under July without a day. The Python SDK had ten releases in the 90 days to 8 October across all of AgentCore (15 of 20). Public release notes and What's New, with AWS Support and re:Post, and issue triage workflows in the SDK repository. We did not read the issue tracker (10 of 15). Current official SDKs, `bedrock-agentcore` 1.24.1 on PyPI on 7 October 2026 and `@aws-sdk/client-bedrock-agentcore` 3.1148.0 (15). The SDK repository runs CI, integration tests, a breaking-change check, security scanning and Dependabot (10).",
          "payments": "No x402, MPP or L402 for paying AWS. AgentCore payments is a separate capability for agents paying third parties (0). $0.010 per 1,000 token or API key requests on the public pricing page (20). No Identity free tier, but new accounts get up to $200 of Free Tier credit and the FAQ says most new customers need no payment method, while AWS may still ask for one, so half, as on our other AWS listings (10). A person creates the AWS account and registers an OAuth client with each provider (0).",
          "reliability": "AWS Health Dashboard with a per-service, per-Region feed for Bedrock AgentCore (20). The dashboard's history file, read on 8 October 2026, lists one event naming AgentCore in the last 90 days, elevated packet loss in one Availability Zone of eu-south-2 on 4 October 2026 from 8:48 to 11:28 AM PDT, at informational status and shared with 31 other services. The us-east-1 feed had no items. Minor only (20 of 30). Quotas published per operation, 200 requests a second for the workload access token calls and 20 for management calls (15). The API reference documents `ThrottlingException` (429) and `InternalServerException` (500) with advice to retry with exponential backoff, but no idempotency token was found on `CreateWorkloadIdentity` (12 of 15). The AgentCore FAQ says the Amazon Bedrock SLA applies, 99.9 per cent a Region, though that SLA's definitions speak of model APIs and do not name AgentCore (8 of 10, our call). Generally available since October 2025, and the consent portal carries no preview label (10).",
          "schema": "Service models for `bedrock-agentcore` and `bedrock-agentcore-control` ship in the AWS SDKs. We confirmed the SDK clients and the API reference, and did not open the model files (25). llms.txt for the developer guide and for the API reference, with a Markdown twin of every page (10). API reference descriptions are one line each, while the guide says when to use the JWT route and when the user ID route (15 of 20). Typed members with enums, patterns and length limits, such as `oauth2Flow` and `credentialProviderVendor`, and one string map, `customParameters` (14 of 15). Named errors with HTTP codes on every operation and CLI and Python examples in the guide, but no examples on the API reference pages we read (12 of 15). Release notes by month without days, SDK changelogs with dates, and the notes' RSS feed was not found at the address we tried (12 of 15).",
          "security": "IAM with SigV4 and short-lived role credentials, plus a workload access token that carries the agent's identity and the user's, and policies that name one workload identity and one credential provider ARN (30). Users consent through the provider's own OAuth screen with session binding, but AWS says the service enforces no binding between workload identities and credential providers beyond the owner's IAM policy, the user ID route is unverified, and no call to revoke one user's grant was found (15 of 20). The service returns tokens and keys, not untrusted content (10). The guide points to CloudTrail for `GetWorkloadAccessTokenForUserId` calls and KMS signing, but no Identity-specific CloudTrail page listing logged events was found, unlike Gateway and Agent Registry (11 of 15). A disclosure programme on HackerOne, public bulletins, AgentCore in SOC 1, 2 and 3 scope on the list of 11 August 2026 and ISO 27001 per the compliance page, with the security.txt expired since 24 September 2026 and no paid bounty found, read as our other AWS listings read it (18 of 20).",
          "transparency": "Closed service under the AWS Service Terms updated 1 October 2026, with Apache-2.0 SDKs (15 of 30). The Identity data protection pages state KMS encryption at rest with an optional customer managed key and warn that names and free-text fields can reach diagnostic logs. The privacy notice is dated 18 May 2026. No retention period for stored tokens or request metadata was found (20 of 30). No deprecation policy for the service found. The one dated notice we saw is the starter toolkit's deprecation on 27 March 2026, in a security bulletin (8 of 20). A sub-processor list updated 28 July 2026 and regional endpoints in 21 Regions, with the vault held in the Region the owner picks (18 of 20)."
        },
        "sources": [
          {
            "what": "AgentCore Identity guide",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/identity.md",
            "seen": "2026-10-08"
          },
          {
            "what": "AgentCore developer guide llms.txt",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "quotas",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/bedrock-agentcore-limits.md",
            "seen": "2026-10-08"
          },
          {
            "what": "release notes",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/release-notes.md",
            "seen": "2026-10-08"
          },
          {
            "what": "obtain OAuth 2.0 access token",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/identity-authentication.md",
            "seen": "2026-10-08"
          },
          {
            "what": "workload access tokens",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/get-workload-access-token.md",
            "seen": "2026-10-08"
          },
          {
            "what": "session binding",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/oauth2-authorization-url-session-binding.md",
            "seen": "2026-10-08"
          },
          {
            "what": "scoping credential provider access",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/scope-credential-provider-access.md",
            "seen": "2026-10-08"
          },
          {
            "what": "on-behalf-of token exchange",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/on-behalf-of-token-exchange.md",
            "seen": "2026-10-08"
          },
          {
            "what": "consent portal",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/identity-consent-portal.md",
            "seen": "2026-10-08"
          },
          {
            "what": "consent portal prerequisites",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/identity-consent-portal-prerequisites.md",
            "seen": "2026-10-08"
          },
          {
            "what": "consent portal targets",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/identity-configure-consent-portal-target.md",
            "seen": "2026-10-08"
          },
          {
            "what": "token vault encryption",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/identity-data-encryption.md",
            "seen": "2026-10-08"
          },
          {
            "what": "compliance validation",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/compliance-validation.md",
            "seen": "2026-10-08"
          },
          {
            "what": "GetResourceOauth2Token API reference",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/APIReference/API_GetResourceOauth2Token.html",
            "seen": "2026-10-08"
          },
          {
            "what": "data-plane API reference llms.txt",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/APIReference/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "control-plane operations",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore-control/latest/APIReference/API_Operations.html",
            "seen": "2026-10-08"
          },
          {
            "what": "CreateOauth2CredentialProvider API reference",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore-control/latest/APIReference/API_CreateOauth2CredentialProvider.md",
            "seen": "2026-10-08"
          },
          {
            "what": "endpoints, AWS General Reference",
            "url": "https://docs.aws.amazon.com/general/latest/gr/bedrock_agentcore.html",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://aws.amazon.com/bedrock/agentcore/pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "AgentCore FAQ (SLA)",
            "url": "https://aws.amazon.com/bedrock/agentcore/faqs/",
            "seen": "2026-10-08"
          },
          {
            "what": "Amazon Bedrock SLA",
            "url": "https://aws.amazon.com/bedrock/sla/",
            "seen": "2026-10-08"
          },
          {
            "what": "status feed, us-east-1",
            "url": "https://status.aws.amazon.com/rss/bedrock-agentcore-us-east-1.rss",
            "seen": "2026-10-08"
          },
          {
            "what": "AWS Health Dashboard history file",
            "url": "https://history-events-us-west-2-prod.s3.amazonaws.com/historyevents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "AWS Service Terms",
            "url": "https://aws.amazon.com/service-terms/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy notice",
            "url": "https://aws.amazon.com/privacy/",
            "seen": "2026-10-08"
          },
          {
            "what": "sub-processors",
            "url": "https://aws.amazon.com/compliance/sub-processors/",
            "seen": "2026-10-08"
          },
          {
            "what": "SOC services in scope",
            "url": "https://aws.amazon.com/compliance/services-in-scope/SOC/",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://aws.amazon.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "security bulletin 2026-127-AWS",
            "url": "https://aws.amazon.com/security/security-bulletins/2026-127-aws/",
            "seen": "2026-10-08"
          },
          {
            "what": "Free Tier FAQ",
            "url": "https://aws.amazon.com/free/free-tier-faqs/",
            "seen": "2026-10-08"
          },
          {
            "what": "What's New search for AgentCore",
            "url": "https://aws.amazon.com/api/dirs/items/search?item.directoryId=whats-new-v2\u0026sort_by=item.additionalFields.postDateTime\u0026sort_order=desc\u0026size=40\u0026item.locale=en_US\u0026q=AgentCore",
            "seen": "2026-10-08"
          },
          {
            "what": "AgentCore Python SDK repository and changelog",
            "url": "https://github.com/aws/bedrock-agentcore-sdk-python",
            "seen": "2026-10-08"
          },
          {
            "what": "bedrock-agentcore on PyPI",
            "url": "https://pypi.org/pypi/bedrock-agentcore/json",
            "seen": "2026-10-08"
          },
          {
            "what": "bedrock-agentcore on npm",
            "url": "https://registry.npmjs.org/bedrock-agentcore/latest",
            "seen": "2026-10-08"
          },
          {
            "what": "@aws-sdk/client-bedrock-agentcore on npm",
            "url": "https://registry.npmjs.org/@aws-sdk/client-bedrock-agentcore/latest",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the amazon.com registration date (1994-11-01) is carried from our other AWS listings, because WHOIS was not reachable from this session.",
          "unchecked: the SDK service model files and the GitHub issue trackers were not read, and GitHub stars were not fetched.",
          "unchecked: the AWS Customer Agreement, the DPA and the sub-processor table's rows were not re-read today. Only the sub-processor page's date was confirmed.",
          "The day in July 2026 on which Private Key JWT launched was not established. The release notes are dated by month.",
          "No per-user grant revocation call and no Identity-specific CloudTrail page were found in the pages read. Either may exist elsewhere in the IAM or CloudTrail documentation.",
          "The Bedrock SLA's definitions refer to model APIs. AWS's FAQ says it applies to AgentCore, and how a claim for Identity would be measured is not stated.",
          "The lead was accurate. One point to add is that the consent portal needs an AgentCore Gateway and an OIDC sign-in provider."
        ]
      },
      "negative": 0,
      "verdict": "The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference.",
      "bestFor": "Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge.",
      "strengths": [
        "`GetResourceOauth2Token` covers three flows (USER_FEDERATION, M2M and ON_BEHALF_OF_TOKEN_EXCHANGE) and returns either an access token or an authorisation URL with a session URI.",
        "25 OAuth vendor values in `CreateOauth2CredentialProvider`, 24 built in (Google, GitHub, Slack, Salesforce, Microsoft, Atlassian and others) plus a custom OAuth 2.0 provider.",
        "Quotas are published per operation, 200 requests a second for the three workload access token calls and 20 for each management call, all adjustable.",
        "The token vault is encrypted with an AWS owned KMS key by default or a customer managed key, and IAM policies can name one workload identity and one credential provider.",
        "$0.010 per 1,000 token or API key requests, with no extra charge when used through AgentCore Runtime or Gateway."
      ],
      "weaknesses": [
        "No operation to revoke or delete one user's stored grant was found. `forceAuthentication` clears a refresh token, and AWS says it cannot detect a revocation made at the provider.",
        "The consent portal, launched 1 September 2026, attaches to one AgentCore Gateway with JWT inbound auth and cannot use GitHub, Slack, Salesforce, Atlassian or LinkedIn as its sign-in provider.",
        "`GetWorkloadAccessTokenForUserId` takes a user ID string the platform does not verify, so the binding to a user rests on the caller and its IAM policy.",
        "AWS states the service enforces no binding between workload identities and credential providers in one account beyond the IAM policy the owner writes.",
        "No CloudTrail page for AgentCore Identity was found in the developer guide, though Gateway and Agent Registry each have one."
      ],
      "agentNotes": [
        "Get a workload access token first (`GetWorkloadAccessTokenForJWT` in production), then pass it as `workloadIdentityToken` to `GetResourceOauth2Token` or `GetResourceApiKey`.",
        "When `GetResourceOauth2Token` returns `authorizationUrl` instead of `accessToken`, send the URL to the user and call again with the same `sessionUri` after consent.",
        "For user-delegated flows, host an HTTPS callback, register it with `UpdateWorkloadIdentity` as an allowed return URL, and call `CompleteResourceTokenAuth` after checking the user's session.",
        "Ask for refresh tokens in the provider's own way, such as `access_type=offline` in `customParameters` for Google or the `offline_access` scope for Microsoft and Atlassian.",
        "Treat a returned token as possibly revoked. On a 401 from the resource server, retry with `forceAuthentication` set to true."
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "BB",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 74.8
        }
      ],
      "editorialScores": {
        "ergonomics": 76,
        "maintenance": 70,
        "payments": 30,
        "reliability": 85,
        "schema": 88,
        "security": 84,
        "transparency": 61
      },
      "provenanceScore": 88
    },
    "connect": {
      "install": "pip install bedrock-agentcore"
    },
    "letme": {
      "capability": "https://letme.dev/auth.oauth",
      "tool": "https://letme.dev/agentcore-identity"
    },
    "sameCompany": [
      "amazon-nova-embeddings",
      "amazon-bedrock-guardrails",
      "amazon-transcribe",
      "amazon-polly",
      "agentcore-memory",
      "aws-secrets-manager",
      "aws-mcp-servers",
      "amazon-ses",
      "amazon-location",
      "amazon-translate",
      "amazon-ads-api"
    ],
    "notable": [
      "AgentCore reached general availability in October 2025 in nine Regions, and the General Reference now lists control-plane and data-plane endpoints in 21 Regions (https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/release-notes.md, https://docs.aws.amazon.com/general/latest/gr/bedrock_agentcore.html)",
      "Identity changes in 2026 per the release notes and What's New. On-behalf-of token exchange and VPC egress (April), existing Secrets Manager secrets as credential provider secrets (1 June), Private Key JWT client authentication (July), and the consent portal (1 September) (https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/release-notes.md)",
      "On-behalf-of token exchange supports RFC 8693 token exchange and the RFC 7523 JWT authorisation grant, set per credential provider (https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/on-behalf-of-token-exchange.md)",
      "With Private Key JWT the private key stays in AWS KMS, AgentCore Identity asks KMS to sign each client assertion with RS256, PS256 or ES256, and each signing is recorded in CloudTrail (https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/release-notes.md)",
      "Resource limits per account and Region are 11,000 workload identities, 50 OAuth2 credential providers, 50 API key credential providers and 50 payment credential providers, all adjustable (https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/bedrock-agentcore-limits.md)",
      "AWS says access tokens returned by AgentCore are not guaranteed to be valid, because a revocation at the federated provider cannot be detected (https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/identity-authentication.md)",
      "The consent portal keeps the OAuth flow on the server and the browser never holds a token. Its connection list is cached for up to 5 minutes after a target changes (https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/identity-consent-portal.md, https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/identity-configure-consent-portal-target.md)",
      "The AgentCore FAQ says the Amazon Bedrock SLA applies to AgentCore. That SLA, last updated 4 October 2023, commits to 99.9 per cent monthly uptime a Region with credits of 10, 25 and 100 per cent (https://aws.amazon.com/bedrock/agentcore/faqs/, https://aws.amazon.com/bedrock/sla/)",
      "AWS's compliance page calls AgentCore HIPAA eligible and in scope for FedRAMP, SOC 2 and ISO 27001, and the SOC services list updated 11 August 2026 names Amazon Bedrock AgentCore (https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/compliance-validation.md, https://aws.amazon.com/compliance/services-in-scope/SOC/)",
      "AWS security bulletin 2026-127-AWS of 6 October 2026 covers two CVEs in `bedrock-agentcore-starter-toolkit`, a package deprecated on 27 March 2026. It concerns agent import, not AgentCore Identity (https://aws.amazon.com/security/security-bulletins/2026-127-aws/)",
      "AgentCore payments, a separate part of AgentCore, lets agents pay third-party sellers with x402 and MPP through payment credential providers stored by Identity. It is not a way to pay AWS (https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/release-notes.md)",
      "The security.txt at aws.amazon.com shows Expires 2026-09-24 and was still expired on 8 October 2026 (https://aws.amazon.com/.well-known/security.txt)",
      "Weekly downloads. `bedrock-agentcore` on PyPI 1,421,946 and on npm 334,717, and `@aws-sdk/client-bedrock-agentcore` 1,070,970 in the week to 4 October 2026. These cover all of AgentCore, not Identity alone (https://pypistats.org/api/packages/bedrock-agentcore/recent, https://api.npmjs.org/downloads/point/last-week/bedrock-agentcore)"
    ],
    "area": "agent-runtime",
    "details": [
      {
        "label": "Token flows",
        "value": "User-delegated authorisation code grant (USER_FEDERATION), client credentials (M2M) and on-behalf-of token exchange (RFC 8693 or RFC 7523), all through `GetResourceOauth2Token`"
      },
      {
        "label": "Providers",
        "value": "24 built-in OAuth vendors, among them Google, GitHub, Slack, Salesforce, Microsoft, Atlassian, Okta, Auth0, Cognito, HubSpot, Notion, Zoom and Dropbox, plus a custom OAuth 2.0 provider and API key providers"
      },
      {
        "label": "Consent",
        "value": "An authorisation URL with session binding through the owner's HTTPS callback and `CompleteResourceTokenAuth`, or the hosted consent portal (since 1 September 2026), which needs an AgentCore Gateway with JWT inbound auth and an OIDC sign-in provider"
      },
      {
        "label": "Token storage",
        "value": "Token vault in the owner's AWS account and Region, encrypted with an AWS owned KMS key or a customer managed single-Region symmetric key. Client secrets can live in the owner's Secrets Manager. Refresh tokens are stored and used automatically"
      },
      {
        "label": "Agent identity",
        "value": "Workload identities with ARNs in a per-account directory, up to 11,000 a Region. Runtime and Gateway create one for each agent or gateway"
      },
      {
        "label": "Rate limits",
        "value": "200 requests a second for each of the three workload access token calls, 20 a second for each create, get, update, delete and list call, adjustable"
      },
      {
        "label": "Revocation",
        "value": "No per-user revoke call found. Delete the credential provider, deny it in IAM, or set `forceAuthentication` to clear a refresh token and restart consent"
      },
      {
        "label": "SLA",
        "value": "The Amazon Bedrock SLA, 99.9% monthly uptime a Region, per the AgentCore FAQ"
      },
      {
        "label": "Regions",
        "value": "21 Regions listed for `bedrock-agentcore.\u003cregion\u003e.amazonaws.com` and `bedrock-agentcore-control.\u003cregion\u003e.amazonaws.com`"
      },
      {
        "label": "SDKs",
        "value": "AWS CLI and AWS SDKs in nine languages, plus the AgentCore SDK for Python (`bedrock-agentcore` 1.24.1, 7 October 2026 on PyPI) and TypeScript (`bedrock-agentcore` 0.4.5 on npm), both Apache-2.0"
      }
    ],
    "unitPrices": [
      {
        "item": "OAuth token or API key requests for non-AWS resources",
        "unit": "1k-requests",
        "usd": 0.01,
        "note": "Per successful request. No charge when used through AgentCore Runtime or Gateway"
      }
    ],
    "provenance": {
      "legalEntity": "Amazon Web Services, Inc.",
      "domain": "amazon.com",
      "domainRegistered": "1994-11-01",
      "domainNote": "The service pages are under aws.amazon.com and the endpoints are on amazonaws.com, an AWS domain.",
      "endpointOnVendorDomain": true,
      "terms": "https://aws.amazon.com/service-terms/",
      "privacy": "https://aws.amazon.com/privacy/",
      "statusPage": "https://health.aws.amazon.com/health/status",
      "changelog": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/release-notes.html",
      "securityTxt": "expired",
      "checked": "2026-10-08",
      "notes": [
        "The AWS Service Terms show Last Updated 1 October 2026. Section 50 covers AI services and section 50.15 covers AgentCore Payments. No section names AgentCore Identity, so the universal terms and section 50 apply.",
        "The Privacy Notice shows Last Updated 18 May 2026 and gives Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109-5210.",
        "security.txt shows Expires 2026-09-24T16:25:03Z, read on 8 October 2026. It points to the AWS vulnerability disclosure programme on HackerOne and the policy at vdp.aws.security.",
        "The status page is drawn by script. We read the per-service feed (status.aws.amazon.com/rss/bedrock-agentcore-us-east-1.rss, no items) and the dashboard's history file.",
        "The domain registration date is carried from our other AWS listings. WHOIS was not reachable from this session.",
        "The release notes are dated by month only, and the RSS feed they mention was not found at doc-history.rss (404)."
      ],
      "score": 88,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Amazon Web Services, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "amazon.com, registered 1994-11-01 (31 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "bedrock-agentcore.us-east-1.amazonaws.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 3 clauses that cost points",
          "points": 3.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "health.aws.amazon.com/health/status",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "published but past its Expires date",
          "points": 5,
          "max": 10,
          "state": "part"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://aws.amazon.com/service-terms/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-10-01",
          "words": 47585,
          "points": 3.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: October 1, 2026",
              "says": "Last updated 2026-10-01"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": false
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "AWS’S AND ITS AFFILIATES’ AND LICENSORS’ AGGREGATE LIABILITY FOR ANY BETA SERVICES AND BETA REGIONS WILL BE LIMITED TO THE AMOUNT YOU ACTUALLY PAY US UNDER THIS AGREEMENT FOR THE BETA SERVICES OR BETA REGIONS THAT GAVE RISE TO THE CLAIM DURING THE 12 MONTHS PRECEDING THE CLAIM."
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "If you do not remove or disable access to the Prohibited Content within 2 business days of our notice, we may remove or disable access to the Prohibited Content or suspend the Services to the extent we are not able to remove or disable access to the Prohibited Content."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "If during the previous 6 months you have incurred no fees for Amazon SimpleDB and have registered no usage of Your Content stored in Amazon SimpleDB, we may delete Your Content that is stored in Simple DB upon 30 days prior notice to you.",
              "says": "Gives 30 days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "You may not transfer outside the Services any software (including related documentation) you obtain from us or third party licensors in connection with the Services without specific authorization to do so."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "If you have been charged for a Service for a period when that Service was unavailable (as defined in the applicable Service Level Agreement for each Service), you may request a Service credit equal to any charged amounts for such period."
            }
          ],
          "toKnow": [
            {
              "key": "training.optout",
              "label": "Says it may use customer content to train or improve models, and gives an opt-out",
              "found": true,
              "quote": "You may instruct AWS not to use and store Amazon WorkSpaces AI Content processed by Amazon WorkSpaces AI Features to develop and improve the Service or technologies of AWS or its affiliates by configuring an AI services opt-out policy using AWS Organizations."
            },
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "Reverse engineer, decompile, attempt to reconstruct, scrape, systematically collect, or duplicate Address Validation Data.",
              "costsPoints": true
            },
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "You may not, and may not allow any third party to, use Amazon CloudWatch Network Monitoring, or any data or information made available through Amazon CloudWatch Network Monitoring, to, directly or indirectly, develop, improve, or offer a similar or competing product or service.",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "We may change, discontinue, or deprecate support for any third-party software development services at any time without prior notice.",
              "costsPoints": true
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://aws.amazon.com/privacy/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-05-18",
          "words": 8790,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: May 18, 2026",
              "says": "Last updated 2026-05-18"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This Privacy Notice describes how we collect and use your personal information in relation to AWS websites, applications, products, services, events, and experiences that reference this Privacy Notice (together, “AWS Offerings”)."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We keep your personal information to enable your continued use of AWS Offerings, for as long as it is required in order to fulfill the relevant purposes described in this Privacy Notice, as may be required by law (including for tax and accounting purposes), or as otherwise communicated to you.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Information from Other Sources: We might collect information about you from other sources, including service providers, partners, and publicly available sources."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "Information about our customers is an important part of our business and we are not in the business of selling our customers’ personal information to others."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Additionally, you may have the right to opt out of the processing of your personal data for cross-context behavioral advertising (also referred to as targeted advertising under certain state privacy laws)."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "We provide additional information about our controllers and data protection officers (as applicable), the privacy, collection, and use of personal information of prospective and current customers of AWS Offerings located in certain jurisdictions.",
              "says": "Names a data protection officer"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "EU-US Data Privacy Framework, UK Extension, and Swiss-US Data Privacy Framework",
              "says": "Relies on the Data Privacy Framework"
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "To help you receive more useful and relevant ads on other sites and services and to measure their effectiveness, AWS shares limited personal information with our advertising partners."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The notice does not cover content that customers process, store or host on AWS. It refers to the customer agreement for how that content is handled.",
              "quote": "This Privacy Notice does not apply to the “content” processed, stored, or hosted by our customers using AWS Offerings in connection with an AWS account."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/agentcore-identity.json",
    "live": {
      "slug": "agentcore-identity",
      "probe": {
        "target": "https://bedrock-agentcore.us-east-1.amazonaws.com",
        "method": "get",
        "lastAt": "2026-10-09T09:26:41.522167958Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 283,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 253,
        "p95ms24h": 275,
        "samples24h": 20,
        "samples30d": 20,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 20,
            "ok": 20
          }
        ]
      },
      "updatedAt": "2026-10-09T09:26:41.522167958Z"
    }
  }
}
