{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "agentcore-memory",
    "name": "Amazon Bedrock AgentCore Memory",
    "vendor": "Amazon Web Services",
    "vendorUrl": "https://aws.amazon.com/bedrock/agentcore/",
    "kind": "http-api",
    "category": "agent-memory",
    "summary": "Managed memory service for AI agents on AWS. It stores conversation events as short-term memory and extracts facts, preferences, summaries and episodes into searchable long-term records, through the AWS API, SDKs and an MCP server.",
    "url": "https://www.anchorterminal.com/tools/agentcore-memory",
    "markdownUrl": "https://www.anchorterminal.com/tools/agentcore-memory.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/agentcore-memory.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/agentcore-memory.json",
    "repo": "https://github.com/aws/bedrock-agentcore-sdk-python",
    "license": "Proprietary service under the AWS Customer Agreement and Service Terms. The `bedrock-agentcore` Python SDK and the `@aws/agentcore` CLI are Apache-2.0",
    "transports": [
      "http",
      "stdio"
    ],
    "remoteUrl": "https://bedrock-agentcore.{region}.amazonaws.com",
    "packages": [
      {
        "registry": "pypi",
        "name": "bedrock-agentcore"
      },
      {
        "registry": "pypi",
        "name": "boto3"
      },
      {
        "registry": "npm",
        "name": "@aws-sdk/client-bedrock-agentcore"
      },
      {
        "registry": "npm",
        "name": "@aws/agentcore"
      },
      {
        "registry": "pypi",
        "name": "awslabs.amazon-bedrock-agentcore-mcp-server"
      }
    ],
    "auth": "mixed",
    "authNotes": "AWS Signature Version 4 with IAM access keys or a role, and a policy that allows actions such as `bedrock-agentcore:CreateEvent` and `bedrock-agentcore:RetrieveMemoryRecords` on the memory resource. The data plane accepts SigV4 only. Resource-based policies and the condition keys `bedrock-agentcore:namespace` and `bedrock-agentcore:namespacePath` narrow access further. For end users, an AgentCore Gateway with the `agentcore-memory` connector accepts OAuth (JWT) tokens and applies Cedar policies. Access is self-serve once a person has created an AWS account.",
    "pricing": "usage",
    "pricingNotes": "Usage-priced with no minimum fee. Short-term memory, as of 6 October 2026, is $1.00 per GB ingested, $0.20 per GB retrieved and $0.10 per GB-month stored, with each event billed as at least 12 KB and at most 64 KB on ingestion and retrieval. Long-term memory is $0.75 per 1,000 records a month with built-in strategies, $0.25 with overrides or self-managed strategies (model usage is then billed in the customer's account), and $0.50 per 1,000 retrievals. No Memory-specific free tier or sandbox. New AWS accounts get up to $200 in Free Tier credits, and AWS says most new customers can sign up without a payment method (https://aws.amazon.com/bedrock/agentcore/pricing/, https://aws.amazon.com/free/free-tier-faqs/).",
    "priceSummary": "$1 / GB",
    "where": "both",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 on the Memory endpoints in the developer guide, the API reference or the pricing page (checked 2026-10-08). AgentCore payments is a separate AgentCore feature for an agent's own outbound payments.",
      "endpoints": []
    },
    "toolCount": 21,
    "popularity": {
      "githubStars": 776,
      "npmWeekly": 1070970,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/memory.html",
    "llmsTxt": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/llms.txt",
    "capabilities": [
      "memory.store",
      "memory.search",
      "memory.user",
      "memory.delete"
    ],
    "tags": [
      "hosted",
      "usage-priced",
      "closed-source",
      "python",
      "typescript",
      "enterprise",
      "llms-txt",
      "free-credits",
      "mcp",
      "stdio",
      "namespaces",
      "idempotency",
      "soc2",
      "status-page"
    ],
    "lastRelease": "2026-10-06",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 79.4,
      "grade": "A",
      "agentReady": true,
      "rank": 12,
      "ranked": true,
      "rankOf": 842,
      "categoryRank": 1,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 86,
        "maintenance": 83,
        "payments": 30,
        "reliability": 88,
        "schema": 92,
        "security": 87,
        "transparency": 76
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 88,
          "points": 17.6,
          "reason": "Graded as a hosted API, the AWS data plane that agents call. AWS Health Dashboard with per-service, per-Region history and RSS feeds (20). The Bedrock AgentCore us-east-1 feed had no items on 8 October 2026. The dashboard's history file names Bedrock AgentCore in one event in the last 90 days, 2 hours 40 minutes of packet loss in one zone of eu-south-2 on 4 October 2026, marked informational and in a Region where Memory is not sold, so the record reads as clean. The public dashboard lists only broad events (30). Per-second quotas published for every Memory operation, 200 `CreateEvent`, 30 `RetrieveMemoryRecords`, 5 `CreateEvent` per actor and session with conversational payloads, and 150,000 extraction tokens a minute (15). 429 `ThrottledException` says to reduce the request rate, 409 `RetryableConflictException` recommends exponential backoff, and `CreateEvent` takes a `clientToken` so a retry is ignored, though no Retry-After header is documented (13 of 15). No SLA found. The AgentCore SLA address returns 404, the SLA index does not name AgentCore, and the Bedrock SLA of 4 October 2023 covers the Bedrock APIs for models (0). Generally available since October 2025 per the release notes (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 92,
          "points": 14.95,
          "reason": "The SDKs are generated from AWS's published service models, and the API reference gives every field with type, length, pattern and valid values (25). The developer guide has an llms.txt of 671 lines with 73 naming memory, and serves each page as .md (10). The guides say when to use `IngestData` instead of `CreateEvent`, which payload types are extracted, and how long-term memory differs from retrieval-augmented generation, but give little on when the service is the wrong tool (16 of 20). Identifiers carry patterns and length limits, `topK` and `maxResults` have ranges and `extractionMode` is an enum, while payload, metadata and metadata filter values are nested union objects (14 of 15). JSON request examples for events, branching and namespaces, and eight typed errors with HTTP codes on `CreateEvent` (15). Release notes with an RSS feed, dated by month and not by day, and no version in the API path (12 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 86,
          "points": 13.98,
          "reason": "Graded on the API. `RetrieveMemoryRecords` returns record summaries with a relevance score, sized by `topK` (default 10, maximum 100) and `maxResults` (default 20), and long-term records stand in for full history, but no field selection was found (20 of 25). `nextToken` pagination, namespace and namespace path scoping, a strategy filter and metadata filters (20). Typed exceptions with HTTP codes and advice in each description. A quota breach returns 402 `ServiceQuotaExceededException` beside the 429 `ThrottledException`, which a generic client may misread (18 of 20). `clientToken` on `CreateEvent`, immutable events and side-effect-free reads. We did not confirm a token on `IngestData` or the batch operations (18 of 20). SDKs in Python, JavaScript, Java, Go and five other languages plus a higher-level Python SDK, but a memory resource must exist first (2 to 3 minutes to create), `eventTimestamp` is required and every call needs SigV4 signing (10 of 15). The awslabs MCP server's 21 Memory tools sit among 122, and one environment variable registers Memory alone."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 87,
          "points": 15.23,
          "reason": "IAM with SigV4, roles and short-lived credentials, resource-based policies on the memory resource, and OAuth (JWT) for end users through an AgentCore Gateway (30). Each operation has its own permission, condition keys hold a caller to a namespace, and Gateway Cedar policies are deny-by-default per actor, namespace and operation. The three batch operations are outside those policies, and deletes are permanent with no confirmation step (17 of 20). The guide names memory poisoning and prompt injection, places prevention with the customer, and recommends Bedrock Guardrails on input before `CreateEvent` and adversarial testing. The MCP server README says retrieved records are untrusted input (12 of 15). CloudWatch metrics and optional vended logs for extraction. The data protection page recommends CloudTrail in general terms, and we found no Memory-specific CloudTrail page such as Gateway and Registry have (10 of 15). A vulnerability disclosure programme on HackerOne, Amazon Bedrock AgentCore in SOC scope on AWS's list updated 11 August 2026, and public security bulletins per our other AWS checks. The security.txt passed its Expires date on 24 September 2026 and no paid bounty was found, read as the other AWS listings were (18 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 30,
          "points": 3.75,
          "reason": "No x402, MPP or L402 on the Memory endpoints (0). Per-GB, per-record and per-retrieval prices published without a login, with a worked example (20). No Memory-specific free tier or sandbox. New AWS accounts get up to $200 in Free Tier credits, and the Free Tier FAQ says most new customers don't need a payment method while AWS may still ask for one, so half, as on our other AWS listings (10). A person creates the AWS account and sets up IAM (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 83,
          "points": 7.26,
          "reason": "The short-term memory price model changed on 6 October 2026, and the official `bedrock-agentcore` Python SDK shipped 1.24.1 on 6 October and a Memory fix in 1.23.1 on 16 September 2026. The newest Memory API additions in the release notes are from August 2026, which a strict reading would score 20. We date the product by the SDK, as the Secrets Manager listing was dated by its client (30). Three Memory entries in the August 2026 release notes (`IngestData`, flexible namespaces, `json` payloads) and four SDK releases since 11 September (20). Public release notes with RSS and AWS re:Post. The SDK repository has 135 open issues and pull requests, and several Memory issues from September and October have no reply yet (10 of 15). Current official SDKs, `@aws-sdk/client-bedrock-agentcore` 3.1148.0 and `bedrock-agentcore` 1.24.1 (15). The SDK repository has CI, integration, breaking-change and security-scanning workflows and Dependabot. We did not confirm the default branch passes (8 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 76,
          "points": 6.65,
          "note": "editorial 64, provenance 88",
          "reason": "Closed service under the AWS Customer Agreement and Service Terms (updated 1 October 2026), with the Python SDK and CLI under Apache-2.0 (18 of 30, as for S3). Section 50.3 of the Service Terms does not list Bedrock or AgentCore among the services whose content AWS may use for improvement, events expire after 7 to 365 days, records are encrypted at rest with KMS, and the terms carry the AWS DPA. The AgentCore data protection page has Gateway-specific statements and none for Memory, and no retention period for deleted records was found (22 of 30). The pricing page dates the short-term pricing change (through 5 October, as of 6 October 2026), but no deprecation policy for the Memory API was found (6 of 20). A sub-processor page updated 28 July 2026 and a per-Region availability table. Built-in strategies may process event text in another Region of the same geography, which the cross-Region inference page states (18 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Graded on the API. `RetrieveMemoryRecords` returns record summaries with a relevance score, sized by `topK` (default 10, maximum 100) and `maxResults` (default 20), and long-term records stand in for full history, but no field selection was found (20 of 25). `nextToken` pagination, namespace and namespace path scoping, a strategy filter and metadata filters (20). Typed exceptions with HTTP codes and advice in each description. A quota breach returns 402 `ServiceQuotaExceededException` beside the 429 `ThrottledException`, which a generic client may misread (18 of 20). `clientToken` on `CreateEvent`, immutable events and side-effect-free reads. We did not confirm a token on `IngestData` or the batch operations (18 of 20). SDKs in Python, JavaScript, Java, Go and five other languages plus a higher-level Python SDK, but a memory resource must exist first (2 to 3 minutes to create), `eventTimestamp` is required and every call needs SigV4 signing (10 of 15). The awslabs MCP server's 21 Memory tools sit among 122, and one environment variable registers Memory alone.",
          "maintenance": "The short-term memory price model changed on 6 October 2026, and the official `bedrock-agentcore` Python SDK shipped 1.24.1 on 6 October and a Memory fix in 1.23.1 on 16 September 2026. The newest Memory API additions in the release notes are from August 2026, which a strict reading would score 20. We date the product by the SDK, as the Secrets Manager listing was dated by its client (30). Three Memory entries in the August 2026 release notes (`IngestData`, flexible namespaces, `json` payloads) and four SDK releases since 11 September (20). Public release notes with RSS and AWS re:Post. The SDK repository has 135 open issues and pull requests, and several Memory issues from September and October have no reply yet (10 of 15). Current official SDKs, `@aws-sdk/client-bedrock-agentcore` 3.1148.0 and `bedrock-agentcore` 1.24.1 (15). The SDK repository has CI, integration, breaking-change and security-scanning workflows and Dependabot. We did not confirm the default branch passes (8 of 10).",
          "payments": "No x402, MPP or L402 on the Memory endpoints (0). Per-GB, per-record and per-retrieval prices published without a login, with a worked example (20). No Memory-specific free tier or sandbox. New AWS accounts get up to $200 in Free Tier credits, and the Free Tier FAQ says most new customers don't need a payment method while AWS may still ask for one, so half, as on our other AWS listings (10). A person creates the AWS account and sets up IAM (0).",
          "reliability": "Graded as a hosted API, the AWS data plane that agents call. AWS Health Dashboard with per-service, per-Region history and RSS feeds (20). The Bedrock AgentCore us-east-1 feed had no items on 8 October 2026. The dashboard's history file names Bedrock AgentCore in one event in the last 90 days, 2 hours 40 minutes of packet loss in one zone of eu-south-2 on 4 October 2026, marked informational and in a Region where Memory is not sold, so the record reads as clean. The public dashboard lists only broad events (30). Per-second quotas published for every Memory operation, 200 `CreateEvent`, 30 `RetrieveMemoryRecords`, 5 `CreateEvent` per actor and session with conversational payloads, and 150,000 extraction tokens a minute (15). 429 `ThrottledException` says to reduce the request rate, 409 `RetryableConflictException` recommends exponential backoff, and `CreateEvent` takes a `clientToken` so a retry is ignored, though no Retry-After header is documented (13 of 15). No SLA found. The AgentCore SLA address returns 404, the SLA index does not name AgentCore, and the Bedrock SLA of 4 October 2023 covers the Bedrock APIs for models (0). Generally available since October 2025 per the release notes (10).",
          "schema": "The SDKs are generated from AWS's published service models, and the API reference gives every field with type, length, pattern and valid values (25). The developer guide has an llms.txt of 671 lines with 73 naming memory, and serves each page as .md (10). The guides say when to use `IngestData` instead of `CreateEvent`, which payload types are extracted, and how long-term memory differs from retrieval-augmented generation, but give little on when the service is the wrong tool (16 of 20). Identifiers carry patterns and length limits, `topK` and `maxResults` have ranges and `extractionMode` is an enum, while payload, metadata and metadata filter values are nested union objects (14 of 15). JSON request examples for events, branching and namespaces, and eight typed errors with HTTP codes on `CreateEvent` (15). Release notes with an RSS feed, dated by month and not by day, and no version in the API path (12 of 15).",
          "security": "IAM with SigV4, roles and short-lived credentials, resource-based policies on the memory resource, and OAuth (JWT) for end users through an AgentCore Gateway (30). Each operation has its own permission, condition keys hold a caller to a namespace, and Gateway Cedar policies are deny-by-default per actor, namespace and operation. The three batch operations are outside those policies, and deletes are permanent with no confirmation step (17 of 20). The guide names memory poisoning and prompt injection, places prevention with the customer, and recommends Bedrock Guardrails on input before `CreateEvent` and adversarial testing. The MCP server README says retrieved records are untrusted input (12 of 15). CloudWatch metrics and optional vended logs for extraction. The data protection page recommends CloudTrail in general terms, and we found no Memory-specific CloudTrail page such as Gateway and Registry have (10 of 15). A vulnerability disclosure programme on HackerOne, Amazon Bedrock AgentCore in SOC scope on AWS's list updated 11 August 2026, and public security bulletins per our other AWS checks. The security.txt passed its Expires date on 24 September 2026 and no paid bounty was found, read as the other AWS listings were (18 of 20).",
          "transparency": "Closed service under the AWS Customer Agreement and Service Terms (updated 1 October 2026), with the Python SDK and CLI under Apache-2.0 (18 of 30, as for S3). Section 50.3 of the Service Terms does not list Bedrock or AgentCore among the services whose content AWS may use for improvement, events expire after 7 to 365 days, records are encrypted at rest with KMS, and the terms carry the AWS DPA. The AgentCore data protection page has Gateway-specific statements and none for Memory, and no retention period for deleted records was found (22 of 30). The pricing page dates the short-term pricing change (through 5 October, as of 6 October 2026), but no deprecation policy for the Memory API was found (6 of 20). A sub-processor page updated 28 July 2026 and a per-Region availability table. Built-in strategies may process event text in another Region of the same geography, which the cross-Region inference page states (18 of 20)."
        },
        "sources": [
          {
            "what": "Memory overview",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/memory.html",
            "seen": "2026-10-08"
          },
          {
            "what": "developer guide llms.txt",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "getting started",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/memory-get-started.html",
            "seen": "2026-10-08"
          },
          {
            "what": "memory types and asynchronous extraction",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/memory-types.html",
            "seen": "2026-10-08"
          },
          {
            "what": "create an event",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/short-term-create-event.html",
            "seen": "2026-10-08"
          },
          {
            "what": "CreateEvent API reference",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/APIReference/API_CreateEvent.html",
            "seen": "2026-10-08"
          },
          {
            "what": "RetrieveMemoryRecords API reference",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/APIReference/API_RetrieveMemoryRecords.html",
            "seen": "2026-10-08"
          },
          {
            "what": "DeleteMemoryRecord API reference",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/APIReference/API_DeleteMemoryRecord.html",
            "seen": "2026-10-08"
          },
          {
            "what": "direct long-term ingestion",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/long-term-ingest-data.html",
            "seen": "2026-10-08"
          },
          {
            "what": "quotas",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/bedrock-agentcore-limits.html",
            "seen": "2026-10-08"
          },
          {
            "what": "release notes",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/release-notes.html",
            "seen": "2026-10-08"
          },
          {
            "what": "supported Regions",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/agentcore-regions.html",
            "seen": "2026-10-08"
          },
          {
            "what": "Gateway connector for Memory",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/memory-gateway-connector.html",
            "seen": "2026-10-08"
          },
          {
            "what": "encryption and memory poisoning guidance",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/storage-encryption.html",
            "seen": "2026-10-08"
          },
          {
            "what": "best practices",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/best-practices.html",
            "seen": "2026-10-08"
          },
          {
            "what": "observability",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/memory-observability.html",
            "seen": "2026-10-08"
          },
          {
            "what": "cross-Region inference",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/cross-region-inference.html",
            "seen": "2026-10-08"
          },
          {
            "what": "data protection",
            "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/data-protection.html",
            "seen": "2026-10-08"
          },
          {
            "what": "endpoints",
            "url": "https://docs.aws.amazon.com/general/latest/gr/bedrock_agentcore.html",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://aws.amazon.com/bedrock/agentcore/pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "Free Tier FAQ",
            "url": "https://aws.amazon.com/free/free-tier-faqs/",
            "seen": "2026-10-08"
          },
          {
            "what": "AWS Service Terms",
            "url": "https://aws.amazon.com/service-terms/",
            "seen": "2026-10-08"
          },
          {
            "what": "AWS Privacy Notice",
            "url": "https://aws.amazon.com/privacy/",
            "seen": "2026-10-08"
          },
          {
            "what": "SLA index",
            "url": "https://aws.amazon.com/legal/service-level-agreements/",
            "seen": "2026-10-08"
          },
          {
            "what": "Bedrock SLA",
            "url": "https://aws.amazon.com/bedrock/sla/",
            "seen": "2026-10-08"
          },
          {
            "what": "SOC services in scope",
            "url": "https://aws.amazon.com/compliance/services-in-scope/SOC/",
            "seen": "2026-10-08"
          },
          {
            "what": "sub-processors",
            "url": "https://aws.amazon.com/compliance/sub-processors/",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://aws.amazon.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "Bedrock AgentCore status feed, us-east-1",
            "url": "https://status.aws.amazon.com/rss/bedrock-agentcore-us-east-1.rss",
            "seen": "2026-10-08"
          },
          {
            "what": "AWS Health Dashboard history file",
            "url": "https://history-events-us-west-2-prod.s3.amazonaws.com/historyevents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "Python SDK repository, changelog and workflows",
            "url": "https://github.com/aws/bedrock-agentcore-sdk-python",
            "seen": "2026-10-08"
          },
          {
            "what": "Python SDK on PyPI",
            "url": "https://pypi.org/project/bedrock-agentcore/",
            "seen": "2026-10-08"
          },
          {
            "what": "npm client",
            "url": "https://registry.npmjs.org/@aws-sdk/client-bedrock-agentcore/latest",
            "seen": "2026-10-08"
          },
          {
            "what": "AgentCore CLI on npm",
            "url": "https://registry.npmjs.org/@aws/agentcore/latest",
            "seen": "2026-10-08"
          },
          {
            "what": "awslabs AgentCore MCP server",
            "url": "https://github.com/awslabs/mcp/tree/main/src/amazon-bedrock-agentcore-mcp-server",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: weekly PyPI downloads for `bedrock-agentcore`. pypistats.org answered with its rate limit and we did not retry.",
          "unchecked: whether Memory data-plane calls such as `CreateEvent` are logged by CloudTrail as data events. No Memory page in the developer guide says so.",
          "unchecked: the data-plane host. The curl in `connect` is assembled from the API reference path and the `bedrock-agentcore.\u003cregion\u003e.amazonaws.com` service name in the KMS policy example, and was not run.",
          "unchecked: annotations (readOnlyHint, destructiveHint) on the MCP server's Memory tools. A search of the Memory tool sources found no `readOnlyHint`.",
          "Release notes give months, not days, so the August 2026 Memory entries cannot be dated more closely.",
          "Maintenance recency is 30 on the SDK and pricing dates. Reading only the Memory API entries in the release notes would give 20.",
          "The amazon.com registration date is copied from our other AWS listings and was not looked up again.",
          "No knowledge-graph memory was found, so `memory.graph` is left out."
        ]
      },
      "negative": 0,
      "verdict": "Access is IAM-controlled down to one namespace, with published per-second quotas for every operation and a `clientToken` on event writes. Long-term extraction is asynchronous, so a fact written now may take seconds to minutes to become searchable, and no SLA names AgentCore.",
      "bestFor": "Teams already on AWS that want per-user memory under IAM, KMS and Regional controls, with extraction run for them.",
      "strengths": [
        "IAM permissions per operation, resource-based policies and namespace condition keys, with OAuth sign-in and deny-by-default Cedar policies available through AgentCore Gateway",
        "Per-second quotas published for every Memory operation, such as 200 `CreateEvent` and 30 `RetrieveMemoryRecords` requests a second per account and Region",
        "`CreateEvent` takes a `clientToken`, so a retried write is ignored instead of stored twice",
        "Four built-in extraction strategies (semantic, user preference, summarisation, episodic), plus overrides and self-managed pipelines",
        "Unit prices are public, and events expire on a set time to live of 7 to 365 days"
      ],
      "weaknesses": [
        "Long-term extraction is asynchronous. The docs say records appear within seconds to minutes after a write",
        "No SLA names AgentCore. The Bedrock SLA of 4 October 2023 covers the Bedrock APIs for models",
        "Built-in strategies use cross-Region inference, so event text can be processed in another Region of the same geography",
        "Short-term memory billing moved from per event to per GB on 6 October 2026, with each event billed as at least 12 KB",
        "No Memory-specific CloudTrail page was found in the developer guide, and an AWS account needs a person to create it"
      ],
      "agentNotes": [
        "Create the memory resource first and wait for it to become active (the guide says 2 to 3 minutes). Short-term events work without a strategy, long-term records need at least one",
        "Don't search for a fact straight after `CreateEvent`. Extraction runs in the background, so poll `ListMemoryRecords` or list extraction jobs before relying on `RetrieveMemoryRecords`",
        "Send `actorId`, `sessionId` and `eventTimestamp` on every `CreateEvent`, and reuse the same `clientToken` when retrying",
        "Pass `namespace` or `namespacePath` on every retrieval, and scope it to one actor so users' memories don't mix",
        "Treat retrieved records as untrusted input, and back off on 429 `ThrottledException` and 409 `RetryableConflictException`. A quota breach returns 402 `ServiceQuotaExceededException`"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "A",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 79.4
        }
      ],
      "editorialScores": {
        "ergonomics": 86,
        "maintenance": 83,
        "payments": 30,
        "reliability": 88,
        "schema": 92,
        "security": 87,
        "transparency": 64
      },
      "provenanceScore": 88
    },
    "connect": {
      "install": "pip install bedrock-agentcore   # AgentCore CLI: npm install -g @aws/agentcore",
      "http": "curl -X POST \"https://bedrock-agentcore.us-east-1.amazonaws.com/memories/$AGENTCORE_MEMORY_ID/retrieve\" \\\n  --aws-sigv4 \"aws:amz:us-east-1:bedrock-agentcore\" --user \"$AWS_ACCESS_KEY_ID:$AWS_SECRET_ACCESS_KEY\" \\\n  -H \"content-type: application/json\" \\\n  -d '{\"namespace\":\"/users/alex/facts\",\"searchCriteria\":{\"searchQuery\":\"dietary preferences\",\"topK\":3}}'",
      "config": {
        "mcpServers": {
          "bedrock-agentcore-mcp-server": {
            "args": [
              "awslabs.amazon-bedrock-agentcore-mcp-server@latest"
            ],
            "command": "uvx",
            "env": {
              "AGENTCORE_ENABLE_TOOLS": "memory",
              "FASTMCP_LOG_LEVEL": "ERROR"
            }
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/memory.store",
      "tool": "https://letme.dev/agentcore-memory"
    },
    "sameCompany": [
      "amazon-nova-embeddings",
      "amazon-bedrock-guardrails",
      "amazon-transcribe",
      "amazon-polly",
      "agentcore-identity",
      "aws-secrets-manager",
      "aws-mcp-servers",
      "amazon-ses",
      "amazon-location",
      "amazon-translate",
      "amazon-ads-api"
    ],
    "notable": [
      "Short-term memory pricing changed on 6 October 2026 from $0.25 per 1,000 new events to $1.00 per GB ingested, $0.20 per GB retrieved and $0.10 per GB-month stored, with each event billed as at least 12 KB and at most 64 KB (https://aws.amazon.com/bedrock/agentcore/pricing/)",
      "Long-term memory generation is asynchronous. After `CreateEvent` or `IngestData`, records typically appear within seconds to minutes (https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/memory-types.html, https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/long-term-ingest-data.html)",
      "The data plane accepts AWS Signature Version 4 only. An AgentCore Gateway with the `agentcore-memory` connector adds OAuth (JWT) sign-in and Cedar policies that hold a caller to one actor or namespace, though not for the three batch operations (https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/memory-gateway-connector.html)",
      "Built-in strategies use cross-Region inference within a geography (United States, Europe, Asia Pacific, Canada). Data stays stored in the primary Region, and a built-in with overrides strategy lets the customer pick the model instead (https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/cross-region-inference.html)",
      "The awslabs AgentCore MCP server has 21 Memory tools among 122, runs locally over stdio with the caller's AWS credentials, and can register Memory tools alone with `AGENTCORE_ENABLE_TOOLS=memory` (https://github.com/awslabs/mcp/tree/main/src/amazon-bedrock-agentcore-mcp-server)",
      "The August 2026 release notes added `IngestData` for direct long-term ingestion, flexible namespace variables and a `json` payload type on `CreateEvent` (https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/release-notes.html)"
    ],
    "area": "agent-runtime",
    "details": [
      {
        "label": "Free tier",
        "value": "No Memory-specific free tier. New AWS accounts get up to $200 in Free Tier credits, and AWS says most new customers can sign up without a payment method"
      },
      {
        "label": "Memory types",
        "value": "Short-term events per actor and session, and long-term records extracted by strategy"
      },
      {
        "label": "Strategies",
        "value": "Semantic, user preference, summarisation and episodic built in, built-in with overrides, and self-managed. Up to 6 per memory resource"
      },
      {
        "label": "Writes",
        "value": "`CreateEvent` is synchronous for short-term memory. Long-term extraction is asynchronous, seconds to minutes"
      },
      {
        "label": "Search",
        "value": "`RetrieveMemoryRecords` runs a semantic search in a namespace, `topK` default 10 and maximum 100, with metadata filters and a relevance score"
      },
      {
        "label": "Deletion",
        "value": "`DeleteMemoryRecord` removes one record permanently, `DeleteEvent` removes one event, and events expire after 7 to 365 days"
      },
      {
        "label": "Quotas",
        "value": "200 `CreateEvent` and `ListEvents`, 30 `RetrieveMemoryRecords` and `ListMemoryRecords` requests a second per account and Region, and 150,000 extraction tokens a minute"
      },
      {
        "label": "Graph memory",
        "value": "Not found in the reviewed documentation"
      },
      {
        "label": "Regions",
        "value": "16 of the 22 Regions in the AgentCore table, including Frankfurt, Ireland, London, Paris, Stockholm and AWS GovCloud (US-West)"
      },
      {
        "label": "Encryption",
        "value": "At rest with an AWS-owned KMS key by default, or a customer-managed key set at creation"
      },
      {
        "label": "MCP server",
        "value": "Official awslabs server, local stdio, 21 Memory tools, AWS credentials from the environment"
      }
    ],
    "unitPrices": [
      {
        "item": "Short-term memory ingestion",
        "unit": "gb",
        "usd": 1,
        "note": "Per GB of event data ingested, each event billed as 12 KB to 64 KB. As of 6 October 2026"
      },
      {
        "item": "Short-term memory retrieval",
        "unit": "gb",
        "usd": 0.2,
        "note": "Per GB of event data retrieved, same 12 KB minimum per event"
      },
      {
        "item": "Short-term memory storage",
        "unit": "gb-month",
        "usd": 0.1,
        "note": "Prorated hourly over each event's time to live"
      },
      {
        "item": "Long-term memory storage, built-in strategies",
        "unit": "record",
        "usd": 0.00075,
        "note": "$0.75 per 1,000 records a month"
      },
      {
        "item": "Long-term memory storage, overrides or self-managed",
        "unit": "record",
        "usd": 0.00025,
        "note": "$0.25 per 1,000 records a month, model usage billed separately"
      },
      {
        "item": "Long-term memory retrieval",
        "unit": "1k-requests",
        "usd": 0.5,
        "note": "Per 1,000 retrieve requests"
      }
    ],
    "provenance": {
      "legalEntity": "Amazon Web Services, Inc. (regional AWS entities by account location)",
      "domain": "amazon.com",
      "domainRegistered": "1994-11-01",
      "domainNote": "The service pages are under aws.amazon.com and the endpoints on amazonaws.com, an AWS domain. The registration date is the one on our other AWS listings and was not looked up again on 8 October 2026.",
      "endpointOnVendorDomain": true,
      "terms": "https://aws.amazon.com/service-terms/",
      "privacy": "https://aws.amazon.com/privacy/",
      "statusPage": "https://health.aws.amazon.com/health/status",
      "changelog": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/release-notes.html",
      "securityTxt": "expired",
      "checked": "2026-10-08",
      "notes": [
        "The AWS Service Terms show Last Updated 1 October 2026. Section 50 covers AWS AI services, and its only AgentCore-specific clause is 50.15 on AgentCore Payments. Section 50.3, which lets AWS use content from named AI services for improvement, does not list Bedrock or AgentCore.",
        "The AWS Privacy Notice shows Last Updated 18 May 2026.",
        "aws.amazon.com/.well-known/security.txt carries Expires 2026-09-24T16:25:03.000Z, so it was expired on 8 October 2026. It points to the vulnerability disclosure programme on HackerOne and the policy at vdp.aws.security.",
        "health.aws.amazon.com/health/status is drawn by script. The Bedrock AgentCore feed for us-east-1 had no items on 8 October 2026, and the dashboard's history file lists one event naming Bedrock AgentCore in the last 90 days, packet loss in one zone of eu-south-2 on 4 October 2026, a Region where Memory is not sold.",
        "aws.amazon.com/bedrock/agentcore/sla/ returns 404 and the AWS SLA index does not name AgentCore."
      ],
      "score": 88,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Amazon Web Services, Inc. (regional AWS entities by account location)",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "amazon.com, registered 1994-11-01 (31 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "bedrock-agentcore.{region}.amazonaws.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 3 clauses that cost points",
          "points": 3.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "health.aws.amazon.com/health/status",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "published but past its Expires date",
          "points": 5,
          "max": 10,
          "state": "part"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://aws.amazon.com/service-terms/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-10-01",
          "words": 47585,
          "points": 3.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: October 1, 2026",
              "says": "Last updated 2026-10-01"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": false
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "AWS’S AND ITS AFFILIATES’ AND LICENSORS’ AGGREGATE LIABILITY FOR ANY BETA SERVICES AND BETA REGIONS WILL BE LIMITED TO THE AMOUNT YOU ACTUALLY PAY US UNDER THIS AGREEMENT FOR THE BETA SERVICES OR BETA REGIONS THAT GAVE RISE TO THE CLAIM DURING THE 12 MONTHS PRECEDING THE CLAIM."
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "If you do not remove or disable access to the Prohibited Content within 2 business days of our notice, we may remove or disable access to the Prohibited Content or suspend the Services to the extent we are not able to remove or disable access to the Prohibited Content."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "If during the previous 6 months you have incurred no fees for Amazon SimpleDB and have registered no usage of Your Content stored in Amazon SimpleDB, we may delete Your Content that is stored in Simple DB upon 30 days prior notice to you.",
              "says": "Gives 30 days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "You may not transfer outside the Services any software (including related documentation) you obtain from us or third party licensors in connection with the Services without specific authorization to do so."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "If you have been charged for a Service for a period when that Service was unavailable (as defined in the applicable Service Level Agreement for each Service), you may request a Service credit equal to any charged amounts for such period."
            }
          ],
          "toKnow": [
            {
              "key": "training.optout",
              "label": "Says it may use customer content to train or improve models, and gives an opt-out",
              "found": true,
              "quote": "You may instruct AWS not to use and store Amazon WorkSpaces AI Content processed by Amazon WorkSpaces AI Features to develop and improve the Service or technologies of AWS or its affiliates by configuring an AI services opt-out policy using AWS Organizations."
            },
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "Reverse engineer, decompile, attempt to reconstruct, scrape, systematically collect, or duplicate Address Validation Data.",
              "costsPoints": true
            },
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "You may not, and may not allow any third party to, use Amazon CloudWatch Network Monitoring, or any data or information made available through Amazon CloudWatch Network Monitoring, to, directly or indirectly, develop, improve, or offer a similar or competing product or service.",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "We may change, discontinue, or deprecate support for any third-party software development services at any time without prior notice.",
              "costsPoints": true
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://aws.amazon.com/privacy/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-05-18",
          "words": 8790,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: May 18, 2026",
              "says": "Last updated 2026-05-18"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This Privacy Notice describes how we collect and use your personal information in relation to AWS websites, applications, products, services, events, and experiences that reference this Privacy Notice (together, “AWS Offerings”)."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We keep your personal information to enable your continued use of AWS Offerings, for as long as it is required in order to fulfill the relevant purposes described in this Privacy Notice, as may be required by law (including for tax and accounting purposes), or as otherwise communicated to you.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Information from Other Sources: We might collect information about you from other sources, including service providers, partners, and publicly available sources."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "Information about our customers is an important part of our business and we are not in the business of selling our customers’ personal information to others."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Additionally, you may have the right to opt out of the processing of your personal data for cross-context behavioral advertising (also referred to as targeted advertising under certain state privacy laws)."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "We provide additional information about our controllers and data protection officers (as applicable), the privacy, collection, and use of personal information of prospective and current customers of AWS Offerings located in certain jurisdictions.",
              "says": "Names a data protection officer"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "EU-US Data Privacy Framework, UK Extension, and Swiss-US Data Privacy Framework",
              "says": "Relies on the Data Privacy Framework"
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "To help you receive more useful and relevant ads on other sites and services and to measure their effectiveness, AWS shares limited personal information with our advertising partners."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The notice does not cover content that customers process, store or host on AWS. It refers to the customer agreement for how that content is handled.",
              "quote": "This Privacy Notice does not apply to the “content” processed, stored, or hosted by our customers using AWS Offerings in connection with an AWS account."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/agentcore-memory.json",
    "live": {
      "slug": "agentcore-memory",
      "probe": {
        "target": "https://bedrock-agentcore.{region}.amazonaws.com",
        "method": "get",
        "lastAt": "2026-10-09T09:26:41.531678091Z",
        "lastOk": false,
        "lastStatus": 0,
        "lastMs": 0,
        "lastNote": "invalid character \"{\" in host name",
        "authRequired": false,
        "uptime24h": 0,
        "uptime30d": 0,
        "p50ms24h": 0,
        "p95ms24h": 0,
        "samples24h": 20,
        "samples30d": 20,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 20,
            "ok": 0
          }
        ],
        "outages": [
          {
            "start": "2026-10-09T07:40:18.334133541Z",
            "end": "0001-01-01T00:00:00Z",
            "note": "invalid character \"{\" in host name"
          }
        ]
      },
      "updatedAt": "2026-10-09T09:26:41.531678091Z"
    }
  }
}
