Amazon Bedrock AgentCore Identity

by Amazon Web Services HTTP API in Agent auth & delegated access

Hosted Agent-ready

Amazon Web Services, Inc. · amazon.com since 1994 · status page · who's behind it

Amazon Bedrock AgentCore Identity is an AWS service that gives agents workload identities, stores OAuth tokens and API keys in a token vault, and runs OAuth flows so agents can call third-party services for users or for themselves.

Good for Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge.

Is this your product? Claim this listing or verify it

More from Amazon Web Services Amazon Nova Multimodal Embeddings (Embeddings) · Amazon Bedrock Guardrails (Guardrails) · Amazon Transcribe (STT) · Amazon Polly (TTS) · Amazon Bedrock AgentCore Memory (Memory) · AWS Secrets Manager (Secrets) · AWS MCP Servers (Infra) · Amazon SES (Email) · Amazon Location Service (Maps) · Amazon Translate (Translation) · Amazon Ads API (Advertising)

Assessment. The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference.

Facts

Transport
HTTP
Endpoint
https://bedrock-agentcore.us-east-1.amazonaws.com
Auth
OAuth or key
Pricing
Pay per use · $0.01 / 1k req
x402
No
Licence
Proprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0
Packages
pypi bedrock-agentcore
npm bedrock-agentcore
npm @aws-sdk/client-bedrock-agentcore
pypi boto3
llms.txt
published
Last release
npm / week
335k
PyPI / week
1.4M
Token flows
User-delegated authorisation code grant (USER_FEDERATION), client credentials (M2M) and on-behalf-of token exchange (RFC 8693 or RFC 7523), all through GetResourceOauth2Token
Providers
24 built-in OAuth vendors, among them Google, GitHub, Slack, Salesforce, Microsoft, Atlassian, Okta, Auth0, Cognito, HubSpot, Notion, Zoom and Dropbox, plus a custom OAuth 2.0 provider and API key providers
Consent
An authorisation URL with session binding through the owner's HTTPS callback and CompleteResourceTokenAuth, or the hosted consent portal (since 1 September 2026), which needs an AgentCore Gateway with JWT inbound auth and an OIDC sign-in provider
Token storage
Token vault in the owner's AWS account and Region, encrypted with an AWS owned KMS key or a customer managed single-Region symmetric key. Client secrets can live in the owner's Secrets Manager. Refresh tokens are stored and used automatically
Agent identity
Workload identities with ARNs in a per-account directory, up to 11,000 a Region. Runtime and Gateway create one for each agent or gateway
Rate limits
200 requests a second for each of the three workload access token calls, 20 a second for each create, get, update, delete and list call, adjustable
Revocation
No per-user revoke call found. Delete the credential provider, deny it in IAM, or set forceAuthentication to clear a refresh token and restart consent
SLA
The Amazon Bedrock SLA, 99.9% monthly uptime a Region, per the AgentCore FAQ
Regions
21 Regions listed for bedrock-agentcore.<region>.amazonaws.com and bedrock-agentcore-control.<region>.amazonaws.com
SDKs
AWS CLI and AWS SDKs in nine languages, plus the AgentCore SDK for Python (bedrock-agentcore 1.24.1, 7 October 2026 on PyPI) and TypeScript (bedrock-agentcore 0.4.5 on npm), both Apache-2.0

Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • GetResourceOauth2Token covers three flows (USER_FEDERATION, M2M and ON_BEHALF_OF_TOKEN_EXCHANGE) and returns either an access token or an authorisation URL with a session URI.
  • 25 OAuth vendor values in CreateOauth2CredentialProvider, 24 built in (Google, GitHub, Slack, Salesforce, Microsoft, Atlassian and others) plus a custom OAuth 2.0 provider.
  • Quotas are published per operation, 200 requests a second for the three workload access token calls and 20 for each management call, all adjustable.
  • The token vault is encrypted with an AWS owned KMS key by default or a customer managed key, and IAM policies can name one workload identity and one credential provider.
  • $0.010 per 1,000 token or API key requests, with no extra charge when used through AgentCore Runtime or Gateway.

Weaknesses

  • No operation to revoke or delete one user's stored grant was found. forceAuthentication clears a refresh token, and AWS says it cannot detect a revocation made at the provider.
  • The consent portal, launched 1 September 2026, attaches to one AgentCore Gateway with JWT inbound auth and cannot use GitHub, Slack, Salesforce, Atlassian or LinkedIn as its sign-in provider.
  • GetWorkloadAccessTokenForUserId takes a user ID string the platform does not verify, so the binding to a user rests on the caller and its IAM policy.
  • AWS states the service enforces no binding between workload identities and credential providers in one account beyond the IAM policy the owner writes.
  • No CloudTrail page for AgentCore Identity was found in the developer guide, though Gateway and Agent Registry each have one.

Before you call it notes for agents

  1. Get a workload access token first (GetWorkloadAccessTokenForJWT in production), then pass it as workloadIdentityToken to GetResourceOauth2Token or GetResourceApiKey.
  2. When GetResourceOauth2Token returns authorizationUrl instead of accessToken, send the URL to the user and call again with the same sessionUri after consent.
  3. For user-delegated flows, host an HTTPS callback, register it with UpdateWorkloadIdentity as an allowed return URL, and call CompleteResourceTokenAuth after checking the user's session.
  4. Ask for refresh tokens in the provider's own way, such as access_type=offline in customParameters for Google or the offline_access scope for Microsoft and Atlassian.
  5. Treat a returned token as possibly revoked. On a 401 from the resource server, retry with forceAuthentication set to true.

Who's behind it provenance 88/100

  • Legal entity namedAmazon Web Services, Inc.20/20
  • Domain ageamazon.com, registered 1994-11-01 (31 years)15/15
  • Endpoint on the vendor's domainbedrock-agentcore.us-east-1.amazonaws.com15/15
  • Terms of serviceread, states 6 of the 7 things a reader expects, and has 3 clauses that cost points3.1/10
  • Privacy policyread, states 8 of the 8 things a reader expects10/10
  • Status pagehealth.aws.amazon.com/health/status10/10
  • Changelogpublished10/10
  • security.txtpublished but past its Expires date5/10

Terms and privacy, as read

Terms of service dated 2026-10-01, states 6 of 7, 4 to know

TL;DR Dated 2026-10-01. States 6 of the 7 things a reader expects, and we didn't find the governing law. To know before relying on it, model training with an opt-out, limits on automated access, limits on benchmarking and changes without notice.

Says it may use customer content to train or improve models, and gives an opt-out
You may instruct AWS not to use and store Amazon WorkSpaces AI Content processed by Amazon WorkSpaces AI Features to develop and improve the Service or technologies of AWS or its affiliates by configuring an AI services opt-out policy using AWS Organizations.

Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.

Restricts automated accesscosts points
Reverse engineer, decompile, attempt to reconstruct, scrape, systematically collect, or duplicate Address Validation Data.

A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.

Restricts benchmarking or competitive usecosts points
You may not, and may not allow any third party to, use Amazon CloudWatch Network Monitoring, or any data or information made available through Amazon CloudWatch Network Monitoring, to, directly or indirectly, develop, improve, or offer a similar or competing product or service.

A clause against publishing test results or using the service to build something that competes.

Says the terms or the service can change without noticecosts points
We may change, discontinue, or deprecate support for any third-party software development services at any time without prior notice.

A customer may not hear about a change before it applies.

Gives the date it was last updated Last updated 2026-10-01
Last Updated: October 1, 2026

Without a date nobody can tell which version they agreed to.

Names the governing law or courts

Not found in the text.

Says where a dispute would be heard and under whose law.

States a limit on its liability
AWS’S AND ITS AFFILIATES’ AND LICENSORS’ AGGREGATE LIABILITY FOR ANY BETA SERVICES AND BETA REGIONS WILL BE LIMITED TO THE AMOUNT YOU ACTUALLY PAY US UNDER THIS AGREEMENT FOR THE BETA SERVICES OR BETA REGIONS THAT GAVE RISE TO THE CLAIM DURING THE 12 MONTHS PRECEDING THE CLAIM.

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
If you do not remove or disable access to the Prohibited Content within 2 business days of our notice, we may remove or disable access to the Prohibited Content or suspend the Services to the extent we are not able to remove or disable access to the Prohibited Content.

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced Gives 30 days of notice before a change
If during the previous 6 months you have incurred no fees for Amazon SimpleDB and have registered no usage of Your Content stored in Amazon SimpleDB, we may delete Your Content that is stored in Simple DB upon 30 days prior notice to you.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
You may not transfer outside the Services any software (including related documentation) you obtain from us or third party licensors in connection with the Services without specific authorization to do so.

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment
If you have been charged for a Service for a period when that Service was unavailable (as defined in the applicable Service Level Agreement for each Service), you may request a Service credit equal to any charged amounts for such period.

Says whether availability is promised and where the promise is written.

The document · read 2026-10-08 · 47,585 words

Privacy policy dated 2026-05-18, states 8 of 8, 1 to know

TL;DR Dated 2026-05-18. States all 8 things a reader expects. To know before relying on it, selling or sharing data for advertising.

Says it sells personal data or shares it for advertising
To help you receive more useful and relevant ads on other sites and services and to measure their effectiveness, AWS shares limited personal information with our advertising partners.

Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.

Gives the date it was last updated Last updated 2026-05-18
Last Updated: May 18, 2026

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
This Privacy Notice describes how we collect and use your personal information in relation to AWS websites, applications, products, services, events, and experiences that reference this Privacy Notice (together, “AWS Offerings”).

The basic statement a privacy policy exists to make.

Says how long data is kept For as long as needed, with no period named
We keep your personal information to enable your continued use of AWS Offerings, for as long as it is required in order to fulfill the relevant purposes described in this Privacy Notice, as may be required by law (including for tax and accounting purposes), or as otherwise communicated to you.

Says when data sent to the service is deleted.

Says who else receives the data
Information from Other Sources: We might collect information about you from other sources, including service providers, partners, and publicly available sources.

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising
Information about our customers is an important part of our business and we are not in the business of selling our customers’ personal information to others.

A plain statement either way.

Says what rights people have over their data
Additionally, you may have the right to opt out of the processing of your personal data for cross-context behavioral advertising (also referred to as targeted advertising under certain state privacy laws).

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact Names a data protection officer
We provide additional information about our controllers and data protection officers (as applicable), the privacy, collection, and use of personal information of prospective and current customers of AWS Offerings located in certain jurisdictions.

An address or officer to send a request to.

Says where data is transferred or stored Relies on the Data Privacy Framework
EU-US Data Privacy Framework, UK Extension, and Swiss-US Data Privacy Framework

The countries data goes to and the safeguard used.

The notice does not cover content that customers process, store or host on AWS. It refers to the customer agreement for how that content is handled.
This Privacy Notice does not apply to the “content” processed, stored, or hosted by our customers using AWS Offerings in connection with an AWS account.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 8,790 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The service pages are under aws.amazon.com and the endpoints are on amazonaws.com, an AWS domain.

The AWS Service Terms show Last Updated 1 October 2026. Section 50 covers AI services and section 50.15 covers AgentCore Payments. No section names AgentCore Identity, so the universal terms and section 50 apply.

The Privacy Notice shows Last Updated 18 May 2026 and gives Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109-5210.

security.txt shows Expires 2026-09-24T16:25:03Z, read on 8 October 2026. It points to the AWS vulnerability disclosure programme on HackerOne and the policy at vdp.aws.security.

The status page is drawn by script. We read the per-service feed (status.aws.amazon.com/rss/bedrock-agentcore-us-east-1.rss, no items) and the dashboard's history file.

The domain registration date is carried from our other AWS listings. WHOIS was not reachable from this session.

The release notes are dated by month only, and the RSS feed they mention was not found at doc-history.rss (404).

Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-09 08:58 UTC

Right nowUpHTTP 404 · 259 ms · 6 minutes ago
Uptime 24h100.0%15 probes
Uptime 30 days100.0%15 probes
p50 24h248 msget
p95 24h266 msopen endpoint

Probed every five minutes at https://bedrock-agentcore.us-east-1.amazonaws.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/agentcore-identity.json

Notable

  • AgentCore reached general availability in October 2025 in nine Regions, and the General Reference now lists control-plane and data-plane endpoints in 21 Regions source
  • Identity changes in 2026 per the release notes and What's New. On-behalf-of token exchange and VPC egress (April), existing Secrets Manager secrets as credential provider secrets (1 June), Private Key JWT client authentication (July), and the consent portal (1 September) source
  • On-behalf-of token exchange supports RFC 8693 token exchange and the RFC 7523 JWT authorisation grant, set per credential provider source
  • With Private Key JWT the private key stays in AWS KMS, AgentCore Identity asks KMS to sign each client assertion with RS256, PS256 or ES256, and each signing is recorded in CloudTrail source
  • Resource limits per account and Region are 11,000 workload identities, 50 OAuth2 credential providers, 50 API key credential providers and 50 payment credential providers, all adjustable source
  • AWS says access tokens returned by AgentCore are not guaranteed to be valid, because a revocation at the federated provider cannot be detected source
  • The consent portal keeps the OAuth flow on the server and the browser never holds a token. Its connection list is cached for up to 5 minutes after a target changes source
  • The AgentCore FAQ says the Amazon Bedrock SLA applies to AgentCore. That SLA, last updated 4 October 2023, commits to 99.9 per cent monthly uptime a Region with credits of 10, 25 and 100 per cent source
  • AWS's compliance page calls AgentCore HIPAA eligible and in scope for FedRAMP, SOC 2 and ISO 27001, and the SOC services list updated 11 August 2026 names Amazon Bedrock AgentCore source
  • AWS security bulletin 2026-127-AWS of 6 October 2026 covers two CVEs in bedrock-agentcore-starter-toolkit, a package deprecated on 27 March 2026. It concerns agent import, not AgentCore Identity source
  • AgentCore payments, a separate part of AgentCore, lets agents pay third-party sellers with x402 and MPP through payment credential providers stored by Identity. It is not a way to pay AWS source
  • The security.txt at aws.amazon.com shows Expires 2026-09-24 and was still expired on 8 October 2026 source
  • Weekly downloads. bedrock-agentcore on PyPI 1,421,946 and on npm 334,717, and @aws-sdk/client-bedrock-agentcore 1,070,970 in the week to 4 October 2026. These cover all of AgentCore, not Identity alone source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 17.0
AWS Health Dashboard with a per-service, per-Region feed for Bedrock AgentCore (20). The dashboard's history file, read on 8 October 2026, lists one event naming AgentCore in the last 90 days, elevated packet loss in one Availability Zone of eu-south-2 on 4 October 2026 from 8:48 to 11:28 AM PDT, at informational status and shared with 31 other services. The us-east-1 feed had no items. Minor only (20 of 30). Quotas published per operation, 200 requests a second for the workload access token calls and 20 for management calls (15). The API reference documents ThrottlingException (429) and InternalServerException (500) with advice to retry with exponential backoff, but no idempotency token was found on CreateWorkloadIdentity (12 of 15). The AgentCore FAQ says the Amazon Bedrock SLA applies, 99.9 per cent a Region, though that SLA's definitions speak of model APIs and do not name AgentCore (8 of 10, our call). Generally available since October 2025, and the consent portal carries no preview label (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 14.3
Service models for bedrock-agentcore and bedrock-agentcore-control ship in the AWS SDKs. We confirmed the SDK clients and the API reference, and did not open the model files (25). llms.txt for the developer guide and for the API reference, with a Markdown twin of every page (10). API reference descriptions are one line each, while the guide says when to use the JWT route and when the user ID route (15 of 20). Typed members with enums, patterns and length limits, such as oauth2Flow and credentialProviderVendor, and one string map, customParameters (14 of 15). Named errors with HTTP codes on every operation and CLI and Python examples in the guide, but no examples on the API reference pages we read (12 of 15). Release notes by month without days, SDK changelogs with dates, and the notes' RSS feed was not found at the address we tried (12 of 15).
Agent ergonomics 13%16.2 12.3
Responses are small, a token or an authorisation URL with a session status, and list calls take maxResults. There is no MCP server for Identity to weigh (20 of 25). List operations page with nextToken and maxResults, and no filters were found (15 of 20). Named exceptions with recovery advice, and a missing consent comes back as authorizationUrl and sessionUri in a 200 response, which an agent can act on (18 of 20). Token reads are safe to repeat and forceAuthentication restarts consent, but no client token for idempotent creates was found and there are no MCP annotations (10 of 20). AWS SDKs in nine languages plus AgentCore SDKs for Python and TypeScript with @requires_access_token and @requires_api_key decorators. GetResourceOauth2Token has four required members, and user-delegated flows need the owner to host a callback endpoint (13 of 15).
Security & auth 14%17.5 14.7
IAM with SigV4 and short-lived role credentials, plus a workload access token that carries the agent's identity and the user's, and policies that name one workload identity and one credential provider ARN (30). Users consent through the provider's own OAuth screen with session binding, but AWS says the service enforces no binding between workload identities and credential providers beyond the owner's IAM policy, the user ID route is unverified, and no call to revoke one user's grant was found (15 of 20). The service returns tokens and keys, not untrusted content (10). The guide points to CloudTrail for GetWorkloadAccessTokenForUserId calls and KMS signing, but no Identity-specific CloudTrail page listing logged events was found, unlike Gateway and Agent Registry (11 of 15). A disclosure programme on HackerOne, public bulletins, AgentCore in SOC 1, 2 and 3 scope on the list of 11 August 2026 and ISO 27001 per the compliance page, with the security.txt expired since 24 September 2026 and no paid bounty found, read as our other AWS listings read it (18 of 20).
Payments & pricing 10%12.5 3.8
No x402, MPP or L402 for paying AWS. AgentCore payments is a separate capability for agents paying third parties (0). $0.010 per 1,000 token or API key requests on the public pricing page (20). No Identity free tier, but new accounts get up to $200 of Free Tier credit and the FAQ says most new customers need no payment method, while AWS may still ask for one, so half, as on our other AWS listings (10). A person creates the AWS account and registers an OAuth client with each provider (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 6.1
The newest Identity change is the consent portal, announced 1 September 2026, 37 days before the check (20 of 30). In the last 90 days we could date the consent portal and Python SDK 1.21.0 of 6 August 2026, which added workload access token propagation. Private Key JWT is listed under July without a day. The Python SDK had ten releases in the 90 days to 8 October across all of AgentCore (15 of 20). Public release notes and What's New, with AWS Support and re:Post, and issue triage workflows in the SDK repository. We did not read the issue tracker (10 of 15). Current official SDKs, bedrock-agentcore 1.24.1 on PyPI on 7 October 2026 and @aws-sdk/client-bedrock-agentcore 3.1148.0 (15). The SDK repository runs CI, integration tests, a breaking-change check, security scanning and Dependabot (10).
Transparency & trusteditorial 61, provenance 88 7%8.8 6.6
Closed service under the AWS Service Terms updated 1 October 2026, with Apache-2.0 SDKs (15 of 30). The Identity data protection pages state KMS encryption at rest with an optional customer managed key and warn that names and free-text fields can reach diagnostic logs. The privacy notice is dated 18 May 2026. No retention period for stored tokens or request metadata was found (20 of 30). No deprecation policy for the service found. The one dated notice we saw is the starter toolkit's deprecation on 27 March 2026, in a security bulletin (8 of 20). A sub-processor list updated 28 July 2026 and regional endpoints in 21 Regions, with the vault held in the Region the owner picks (18 of 20).
Negative events≤15None recorded0
Total74.8 · BB

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 16 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Amazon Bedrock AgentCore Identity, or have the agent fetch /fixes/agentcore-identity.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: Amazon Bedrock AgentCore Identity

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/agentcore-identity, the October 2026 research run, assessed 8 October 2026. Grade BB, 74.8 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on Amazon Bedrock AgentCore Identity: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Payments & pricing, 30 out of 100, up to 8.8 more on the total

Why it scored 30: No x402, MPP or L402 for paying AWS. AgentCore payments is a separate capability for agents paying third parties (0). $0.010 per 1,000 token or API key requests on the public pricing page (20). No Identity free tier, but new accounts get up to $200 of Free Tier credit and the FAQ says most new customers need no payment method, while AWS may still ask for one, so half, as on our other AWS listings (10). A person creates the AWS account and registers an OAuth client with each provider (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 2. Agent ergonomics, 76 out of 100, up to 3.9 more on the total

Why it scored 76: Responses are small, a token or an authorisation URL with a session status, and list calls take `maxResults`. There is no MCP server for Identity to weigh (20 of 25). List operations page with `nextToken` and `maxResults`, and no filters were found (15 of 20). Named exceptions with recovery advice, and a missing consent comes back as `authorizationUrl` and `sessionUri` in a 200 response, which an agent can act on (18 of 20). Token reads are safe to repeat and `forceAuthentication` restarts consent, but no client token for idempotent creates was found and there are no MCP annotations (10 of 20). AWS SDKs in nine languages plus AgentCore SDKs for Python and TypeScript with `@requires_access_token` and `@requires_api_key` decorators. `GetResourceOauth2Token` has four required members, and user-delegated flows need the owner to host a callback endpoint (13 of 15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 3. Reliability, 85 out of 100, up to 3 more on the total

Why it scored 85: AWS Health Dashboard with a per-service, per-Region feed for Bedrock AgentCore (20). The dashboard's history file, read on 8 October 2026, lists one event naming AgentCore in the last 90 days, elevated packet loss in one Availability Zone of eu-south-2 on 4 October 2026 from 8:48 to 11:28 AM PDT, at informational status and shared with 31 other services. The us-east-1 feed had no items. Minor only (20 of 30). Quotas published per operation, 200 requests a second for the workload access token calls and 20 for management calls (15). The API reference documents `ThrottlingException` (429) and `InternalServerException` (500) with advice to retry with exponential backoff, but no idempotency token was found on `CreateWorkloadIdentity` (12 of 15). The AgentCore FAQ says the Amazon Bedrock SLA applies, 99.9 per cent a Region, though that SLA's definitions speak of model APIs and do not name AgentCore (8 of 10, our call). Generally available since October 2025, and the consent portal carries no preview label (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 4. Security & auth, 84 out of 100, up to 2.8 more on the total

Why it scored 84: IAM with SigV4 and short-lived role credentials, plus a workload access token that carries the agent's identity and the user's, and policies that name one workload identity and one credential provider ARN (30). Users consent through the provider's own OAuth screen with session binding, but AWS says the service enforces no binding between workload identities and credential providers beyond the owner's IAM policy, the user ID route is unverified, and no call to revoke one user's grant was found (15 of 20). The service returns tokens and keys, not untrusted content (10). The guide points to CloudTrail for `GetWorkloadAccessTokenForUserId` calls and KMS signing, but no Identity-specific CloudTrail page listing logged events was found, unlike Gateway and Agent Registry (11 of 15). A disclosure programme on HackerOne, public bulletins, AgentCore in SOC 1, 2 and 3 scope on the list of 11 August 2026 and ISO 27001 per the compliance page, with the security.txt expired since 24 September 2026 and no paid bounty found, read as our other AWS listings read it (18 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 5. Maintenance & community, 70 out of 100, up to 2.6 more on the total

Why it scored 70: The newest Identity change is the consent portal, announced 1 September 2026, 37 days before the check (20 of 30). In the last 90 days we could date the consent portal and Python SDK 1.21.0 of 6 August 2026, which added workload access token propagation. Private Key JWT is listed under July without a day. The Python SDK had ten releases in the 90 days to 8 October across all of AgentCore (15 of 20). Public release notes and What's New, with AWS Support and re:Post, and issue triage workflows in the SDK repository. We did not read the issue tracker (10 of 15). Current official SDKs, `bedrock-agentcore` 1.24.1 on PyPI on 7 October 2026 and `@aws-sdk/client-bedrock-agentcore` 3.1148.0 (15). The SDK repository runs CI, integration tests, a breaking-change check, security scanning and Dependabot (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## 6. Transparency & trust, 75 out of 100, up to 2.2 more on the total

Made of editorial 61, provenance 88.

Why it scored 75: Closed service under the AWS Service Terms updated 1 October 2026, with Apache-2.0 SDKs (15 of 30). The Identity data protection pages state KMS encryption at rest with an optional customer managed key and warn that names and free-text fields can reach diagnostic logs. The privacy notice is dated 18 May 2026. No retention period for stored tokens or request metadata was found (20 of 30). No deprecation policy for the service found. The one dated notice we saw is the starter toolkit's deprecation on 27 March 2026, in a security bulletin (8 of 20). A sub-processor list updated 28 July 2026 and regional endpoints in 21 Regions, with the vault held in the Region the owner picks (18 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Terms of service: read, states 6 of the 7 things a reader expects, and has 3 clauses that cost points (3.1 of 10)
- security.txt: published but past its Expires date (5 of 10)

## 7. Schema & documentation, 88 out of 100, up to 2 more on the total

Why it scored 88: Service models for `bedrock-agentcore` and `bedrock-agentcore-control` ship in the AWS SDKs. We confirmed the SDK clients and the API reference, and did not open the model files (25). llms.txt for the developer guide and for the API reference, with a Markdown twin of every page (10). API reference descriptions are one line each, while the guide says when to use the JWT route and when the user ID route (15 of 20). Typed members with enums, patterns and length limits, such as `oauth2Flow` and `credentialProviderVendor`, and one string map, `customParameters` (14 of 15). Named errors with HTTP codes on every operation and CLI and Python examples in the guide, but no examples on the API reference pages we read (12 of 15). Release notes by month without days, SDK changelogs with dates, and the notes' RSS feed was not found at the address we tried (12 of 15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: the amazon.com registration date (1994-11-01) is carried from our other AWS listings, because WHOIS was not reachable from this session.
- unchecked: the SDK service model files and the GitHub issue trackers were not read, and GitHub stars were not fetched.
- unchecked: the AWS Customer Agreement, the DPA and the sub-processor table's rows were not re-read today. Only the sub-processor page's date was confirmed.
- The day in July 2026 on which Private Key JWT launched was not established. The release notes are dated by month.
- No per-user grant revocation call and no Identity-specific CloudTrail page were found in the pages read. Either may exist elsewhere in the IAM or CloudTrail documentation.
- The Bedrock SLA's definitions refer to model APIs. AWS's FAQ says it applies to AgentCore, and how a claim for Identity would be measured is not stated.
- The lead was accurate. One point to add is that the consent portal needs an AgentCore Gateway and an OIDC sign-in provider.

## Weaknesses

- No operation to revoke or delete one user's stored grant was found. `forceAuthentication` clears a refresh token, and AWS says it cannot detect a revocation made at the provider.
- The consent portal, launched 1 September 2026, attaches to one AgentCore Gateway with JWT inbound auth and cannot use GitHub, Slack, Salesforce, Atlassian or LinkedIn as its sign-in provider.
- `GetWorkloadAccessTokenForUserId` takes a user ID string the platform does not verify, so the binding to a user rests on the caller and its IAM policy.
- AWS states the service enforces no binding between workload identities and credential providers in one account beyond the IAM policy the owner writes.
- No CloudTrail page for AgentCore Identity was found in the developer guide, though Gateway and Agent Registry each have one.

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Get a workload access token first (`GetWorkloadAccessTokenForJWT` in production), then pass it as `workloadIdentityToken` to `GetResourceOauth2Token` or `GetResourceApiKey`.
- When `GetResourceOauth2Token` returns `authorizationUrl` instead of `accessToken`, send the URL to the user and call again with the same `sessionUri` after consent.
- For user-delegated flows, host an HTTPS callback, register it with `UpdateWorkloadIdentity` as an allowed return URL, and call `CompleteResourceTokenAuth` after checking the user's session.
- Ask for refresh tokens in the provider's own way, such as `access_type=offline` in `customParameters` for Google or the `offline_access` scope for Microsoft and Atlassian.
- Treat a returned token as possibly revoked. On a 401 from the resource server, retry with `forceAuthentication` set to true.

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: the amazon.com registration date (1994-11-01) is carried from our other AWS listings, because WHOIS was not reachable from this session.
  • unchecked: the SDK service model files and the GitHub issue trackers were not read, and GitHub stars were not fetched.
  • unchecked: the AWS Customer Agreement, the DPA and the sub-processor table's rows were not re-read today. Only the sub-processor page's date was confirmed.
  • The day in July 2026 on which Private Key JWT launched was not established. The release notes are dated by month.
  • No per-user grant revocation call and no Identity-specific CloudTrail page were found in the pages read. Either may exist elsewhere in the IAM or CloudTrail documentation.
  • The Bedrock SLA's definitions refer to model APIs. AWS's FAQ says it applies to AgentCore, and how a claim for Identity would be measured is not stated.
  • The lead was accurate. One point to add is that the consent portal needs an AgentCore Gateway and an OIDC sign-in provider.

Sources 36

  1. AgentCore Identity guide docs.aws.amazon.com · seen 2026-10-08
  2. AgentCore developer guide llms.txt docs.aws.amazon.com · seen 2026-10-08
  3. quotas docs.aws.amazon.com · seen 2026-10-08
  4. release notes docs.aws.amazon.com · seen 2026-10-08
  5. obtain OAuth 2.0 access token docs.aws.amazon.com · seen 2026-10-08
  6. workload access tokens docs.aws.amazon.com · seen 2026-10-08
  7. session binding docs.aws.amazon.com · seen 2026-10-08
  8. scoping credential provider access docs.aws.amazon.com · seen 2026-10-08
  9. on-behalf-of token exchange docs.aws.amazon.com · seen 2026-10-08
  10. consent portal docs.aws.amazon.com · seen 2026-10-08
  11. consent portal prerequisites docs.aws.amazon.com · seen 2026-10-08
  12. consent portal targets docs.aws.amazon.com · seen 2026-10-08
  13. token vault encryption docs.aws.amazon.com · seen 2026-10-08
  14. compliance validation docs.aws.amazon.com · seen 2026-10-08
  15. GetResourceOauth2Token API reference docs.aws.amazon.com · seen 2026-10-08
  16. data-plane API reference llms.txt docs.aws.amazon.com · seen 2026-10-08
  17. control-plane operations docs.aws.amazon.com · seen 2026-10-08
  18. CreateOauth2CredentialProvider API reference docs.aws.amazon.com · seen 2026-10-08
  19. endpoints, AWS General Reference docs.aws.amazon.com · seen 2026-10-08
  20. pricing aws.amazon.com · seen 2026-10-08
  21. AgentCore FAQ (SLA) aws.amazon.com · seen 2026-10-08
  22. Amazon Bedrock SLA aws.amazon.com · seen 2026-10-08
  23. status feed, us-east-1 status.aws.amazon.com · seen 2026-10-08
  24. AWS Health Dashboard history file history-events-us-west-2-prod.s3.amazonaws.com · seen 2026-10-08
  25. AWS Service Terms aws.amazon.com · seen 2026-10-08
  26. privacy notice aws.amazon.com · seen 2026-10-08
  27. sub-processors aws.amazon.com · seen 2026-10-08
  28. SOC services in scope aws.amazon.com · seen 2026-10-08
  29. security.txt aws.amazon.com · seen 2026-10-08
  30. security bulletin 2026-127-AWS aws.amazon.com · seen 2026-10-08
  31. Free Tier FAQ aws.amazon.com · seen 2026-10-08
  32. What's New search for AgentCore aws.amazon.com · seen 2026-10-08
  33. AgentCore Python SDK repository and changelog github.com · seen 2026-10-08
  34. bedrock-agentcore on PyPI pypi.org · seen 2026-10-08
  35. bedrock-agentcore on npm registry.npmjs.org · seen 2026-10-08
  36. @aws-sdk/client-bedrock-agentcore on npm registry.npmjs.org · seen 2026-10-08

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Pay per use $0.01 / 1k req $0.010 per 1,000 OAuth token or API key requests for non-AWS resources, billed per successful request, with no minimum fee. No additional charge when the service is used through AgentCore Runtime or AgentCore Gateway, which are billed on their own meters. No free tier specific to Identity was found. New AWS accounts get up to $200 of Free Tier credit for up to 6 months, and AWS says most new customers need no payment method at sign-up though it may ask for one (https://aws.amazon.com/bedrock/agentcore/pricing/, https://aws.amazon.com/free/free-tier-faqs/).

Prices

ItemPriceUnitNote
OAuth token or API key requests for non-AWS resources$0.01per 1,000 requestsPer successful request. No charge when used through AgentCore Runtime or Gateway

Compared across listings on the price index.

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/agentcore-identity.xml, or this listing's score history at history.json.

Connect

Install

pip install bedrock-agentcore

Through letme picks today, calling later

GET https://letme.dev/agentcore-identity

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Descope Agentic Identity Hub DescopeA78.1auth.oauth auth.tokens auth.consent auth.agent-identity auth.auditno
Aembit Aembit, Inc.BB70.5auth.oauth auth.agent-identity auth.tokens auth.consent auth.auditno
WorkOS Pipes and Agents WorkOSC59.9auth.oauth auth.tokens auth.consent auth.agent-identity auth.auditno
Keycard Keycard LabsC56.2auth.oauth auth.tokens auth.consent auth.agent-identity auth.auditno
Microsoft Entra Agent ID MicrosoftBB74.4auth.oauth auth.agent-identity auth.consent auth.auditno
Scalekit AgentKit ScalekitBB71.9auth.oauth auth.tokens auth.consent auth.agent-identityno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    Amazon Bedrock AgentCore Identity on Anchor Terminal, BB, 74.8/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/agentcore-identity"><img src="https://www.anchorterminal.com/badges/agentcore-identity.svg" alt="Amazon Bedrock AgentCore Identity on Anchor Terminal" height="20"></a>
    [![Amazon Bedrock AgentCore Identity on Anchor Terminal](https://www.anchorterminal.com/badges/agentcore-identity.svg)](https://www.anchorterminal.com/tools/agentcore-identity)

    It counts on a page on amazon.com or one of its subdomains, or the README of github.com/aws/bedrock-agentcore-sdk-python.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "agentcore-identity", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.