# Amazon Bedrock AgentCore Identity > Amazon Bedrock AgentCore Identity is an AWS service that gives agents workload identities, stores OAuth tokens and API keys in a token vault, and runs OAuth flows so agents can call third-party services for users or for themselves. - Canonical: https://www.anchorterminal.com/tools/agentcore-identity - Markdown: https://www.anchorterminal.com/tools/agentcore-identity.md (~9,400 tokens) - Slim: https://www.anchorterminal.com/tools/agentcore-identity.min.md (~1,780 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/agentcore-identity.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade BB · 74.8/100 · rank #64 of 842 · #2 in Agent auth & delegated access · agent-ready · confidence medium** More from Amazon Web Services, listed separately because each is its own product: [Amazon Nova Multimodal Embeddings](https://www.anchorterminal.com/tools/amazon-nova-embeddings.md) (Embeddings & rerankers), [Amazon Bedrock Guardrails](https://www.anchorterminal.com/tools/amazon-bedrock-guardrails.md) (Guardrails & safety filters), [Amazon Transcribe](https://www.anchorterminal.com/tools/amazon-transcribe.md) (Speech-to-text), [Amazon Polly](https://www.anchorterminal.com/tools/amazon-polly.md) (Text-to-speech), [Amazon Bedrock AgentCore Memory](https://www.anchorterminal.com/tools/agentcore-memory.md) (Agent memory), [AWS Secrets Manager](https://www.anchorterminal.com/tools/aws-secrets-manager.md) (Secrets & credential vaults), [AWS MCP Servers](https://www.anchorterminal.com/tools/aws-mcp-servers.md) (Cloud & infrastructure), [Amazon SES](https://www.anchorterminal.com/tools/amazon-ses.md) (Email delivery APIs), [Amazon Location Service](https://www.anchorterminal.com/tools/amazon-location.md) (Maps, geocoding & places), [Amazon Translate](https://www.anchorterminal.com/tools/amazon-translate.md) (Translation), [Amazon Ads API](https://www.anchorterminal.com/tools/amazon-ads-api.md) (Advertising & campaign operations). ## Assessment The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference. ## Facts | Field | Value | | --- | --- | | Vendor | Amazon Web Services (https://aws.amazon.com/bedrock/agentcore/) | | Kind | HTTP API | | Category | Agent auth & delegated access (https://www.anchorterminal.com/categories/agent-auth) | | Transport | HTTP | | Endpoint | `https://bedrock-agentcore.us-east-1.amazonaws.com` | | Auth | OAuth or key · A person creates an AWS account and an IAM role. Control-plane calls (`bedrock-agentcore-control`) and data-plane calls (`bedrock-agentcore`) are SigV4-signed with IAM credentials, and the data plane also documents an OAuth bearer route (`UnauthorizedException` for an invalid JWT). The agent first gets a workload access token that carries its own identity and the user's, from a JWT (`GetWorkloadAccessTokenForJWT`), a user ID string (`GetWorkloadAccessTokenForUserId`) or neither (`GetWorkloadAccessToken`), then exchanges it for a third-party OAuth token or API key. Each third-party provider needs an OAuth client the owner registers with that provider. AgentCore Runtime and Gateway fetch the workload access token for the agent. | | Pricing | Pay per use ($0.01 / 1k req) · $0.010 per 1,000 OAuth token or API key requests for non-AWS resources, billed per successful request, with no minimum fee. No additional charge when the service is used through AgentCore Runtime or AgentCore Gateway, which are billed on their own meters. No free tier specific to Identity was found. New AWS accounts get up to $200 of Free Tier credit for up to 6 months, and AWS says most new customers need no payment method at sign-up though it may ask for one (https://aws.amazon.com/bedrock/agentcore/pricing/, https://aws.amazon.com/free/free-tier-faqs/). | | x402 | No · No x402, MPP or L402 for paying AWS on the pricing page or in the docs. AgentCore payments is a separate capability for agents paying third-party sellers (checked 2026-10-08). | | Licence | Proprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0 | | Packages | pypi: `bedrock-agentcore`; npm: `bedrock-agentcore`; npm: `@aws-sdk/client-bedrock-agentcore`; pypi: `boto3` | | Source | https://github.com/aws/bedrock-agentcore-sdk-python | | Docs | https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/identity.html | | llms.txt | https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/llms.txt | | Last release | 2026-09-01 | | npm downloads / week | 334,717 | | PyPI downloads / week | 1,421,946 | | Token flows | User-delegated authorisation code grant (USER_FEDERATION), client credentials (M2M) and on-behalf-of token exchange (RFC 8693 or RFC 7523), all through `GetResourceOauth2Token` | | Providers | 24 built-in OAuth vendors, among them Google, GitHub, Slack, Salesforce, Microsoft, Atlassian, Okta, Auth0, Cognito, HubSpot, Notion, Zoom and Dropbox, plus a custom OAuth 2.0 provider and API key providers | | Consent | An authorisation URL with session binding through the owner's HTTPS callback and `CompleteResourceTokenAuth`, or the hosted consent portal (since 1 September 2026), which needs an AgentCore Gateway with JWT inbound auth and an OIDC sign-in provider | | Token storage | Token vault in the owner's AWS account and Region, encrypted with an AWS owned KMS key or a customer managed single-Region symmetric key. Client secrets can live in the owner's Secrets Manager. Refresh tokens are stored and used automatically | | Agent identity | Workload identities with ARNs in a per-account directory, up to 11,000 a Region. Runtime and Gateway create one for each agent or gateway | | Rate limits | 200 requests a second for each of the three workload access token calls, 20 a second for each create, get, update, delete and list call, adjustable | | Revocation | No per-user revoke call found. Delete the credential provider, deny it in IAM, or set `forceAuthentication` to clear a refresh token and restart consent | | SLA | The Amazon Bedrock SLA, 99.9% monthly uptime a Region, per the AgentCore FAQ | | Regions | 21 Regions listed for `bedrock-agentcore..amazonaws.com` and `bedrock-agentcore-control..amazonaws.com` | | SDKs | AWS CLI and AWS SDKs in nine languages, plus the AgentCore SDK for Python (`bedrock-agentcore` 1.24.1, 7 October 2026 on PyPI) and TypeScript (`bedrock-agentcore` 0.4.5 on npm), both Apache-2.0 | | Capabilities | auth.oauth, auth.tokens, auth.consent, auth.agent-identity, auth.audit, infra.aws | | Tags | hosted, closed-source, usage-priced, oauth, llms-txt, python, typescript, enterprise, sla, soc2, eu | | JSON | https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 85 | 17.0 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 88 | 14.3 | | Agent ergonomics | 13% | 16.2 | 76 | 12.3 | | Security & auth | 14% | 17.5 | 84 | 14.7 | | Payments & pricing | 10% | 12.5 | 30 | 3.8 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 70 | 6.1 | | Transparency & trust (editorial 61, provenance 88) | 7% | 8.8 | 75 | 6.6 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **74.8 → BB** | ### Why each score - Reliability 85: AWS Health Dashboard with a per-service, per-Region feed for Bedrock AgentCore (20). The dashboard's history file, read on 8 October 2026, lists one event naming AgentCore in the last 90 days, elevated packet loss in one Availability Zone of eu-south-2 on 4 October 2026 from 8:48 to 11:28 AM PDT, at informational status and shared with 31 other services. The us-east-1 feed had no items. Minor only (20 of 30). Quotas published per operation, 200 requests a second for the workload access token calls and 20 for management calls (15). The API reference documents `ThrottlingException` (429) and `InternalServerException` (500) with advice to retry with exponential backoff, but no idempotency token was found on `CreateWorkloadIdentity` (12 of 15). The AgentCore FAQ says the Amazon Bedrock SLA applies, 99.9 per cent a Region, though that SLA's definitions speak of model APIs and do not name AgentCore (8 of 10, our call). Generally available since October 2025, and the consent portal carries no preview label (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 88: Service models for `bedrock-agentcore` and `bedrock-agentcore-control` ship in the AWS SDKs. We confirmed the SDK clients and the API reference, and did not open the model files (25). llms.txt for the developer guide and for the API reference, with a Markdown twin of every page (10). API reference descriptions are one line each, while the guide says when to use the JWT route and when the user ID route (15 of 20). Typed members with enums, patterns and length limits, such as `oauth2Flow` and `credentialProviderVendor`, and one string map, `customParameters` (14 of 15). Named errors with HTTP codes on every operation and CLI and Python examples in the guide, but no examples on the API reference pages we read (12 of 15). Release notes by month without days, SDK changelogs with dates, and the notes' RSS feed was not found at the address we tried (12 of 15). - Agent ergonomics 76: Responses are small, a token or an authorisation URL with a session status, and list calls take `maxResults`. There is no MCP server for Identity to weigh (20 of 25). List operations page with `nextToken` and `maxResults`, and no filters were found (15 of 20). Named exceptions with recovery advice, and a missing consent comes back as `authorizationUrl` and `sessionUri` in a 200 response, which an agent can act on (18 of 20). Token reads are safe to repeat and `forceAuthentication` restarts consent, but no client token for idempotent creates was found and there are no MCP annotations (10 of 20). AWS SDKs in nine languages plus AgentCore SDKs for Python and TypeScript with `@requires_access_token` and `@requires_api_key` decorators. `GetResourceOauth2Token` has four required members, and user-delegated flows need the owner to host a callback endpoint (13 of 15). - Security & auth 84: IAM with SigV4 and short-lived role credentials, plus a workload access token that carries the agent's identity and the user's, and policies that name one workload identity and one credential provider ARN (30). Users consent through the provider's own OAuth screen with session binding, but AWS says the service enforces no binding between workload identities and credential providers beyond the owner's IAM policy, the user ID route is unverified, and no call to revoke one user's grant was found (15 of 20). The service returns tokens and keys, not untrusted content (10). The guide points to CloudTrail for `GetWorkloadAccessTokenForUserId` calls and KMS signing, but no Identity-specific CloudTrail page listing logged events was found, unlike Gateway and Agent Registry (11 of 15). A disclosure programme on HackerOne, public bulletins, AgentCore in SOC 1, 2 and 3 scope on the list of 11 August 2026 and ISO 27001 per the compliance page, with the security.txt expired since 24 September 2026 and no paid bounty found, read as our other AWS listings read it (18 of 20). - Payments & pricing 30: No x402, MPP or L402 for paying AWS. AgentCore payments is a separate capability for agents paying third parties (0). $0.010 per 1,000 token or API key requests on the public pricing page (20). No Identity free tier, but new accounts get up to $200 of Free Tier credit and the FAQ says most new customers need no payment method, while AWS may still ask for one, so half, as on our other AWS listings (10). A person creates the AWS account and registers an OAuth client with each provider (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 70: The newest Identity change is the consent portal, announced 1 September 2026, 37 days before the check (20 of 30). In the last 90 days we could date the consent portal and Python SDK 1.21.0 of 6 August 2026, which added workload access token propagation. Private Key JWT is listed under July without a day. The Python SDK had ten releases in the 90 days to 8 October across all of AgentCore (15 of 20). Public release notes and What's New, with AWS Support and re:Post, and issue triage workflows in the SDK repository. We did not read the issue tracker (10 of 15). Current official SDKs, `bedrock-agentcore` 1.24.1 on PyPI on 7 October 2026 and `@aws-sdk/client-bedrock-agentcore` 3.1148.0 (15). The SDK repository runs CI, integration tests, a breaking-change check, security scanning and Dependabot (10). - Transparency & trust 75: Closed service under the AWS Service Terms updated 1 October 2026, with Apache-2.0 SDKs (15 of 30). The Identity data protection pages state KMS encryption at rest with an optional customer managed key and warn that names and free-text fields can reach diagnostic logs. The privacy notice is dated 18 May 2026. No retention period for stored tokens or request metadata was found (20 of 30). No deprecation policy for the service found. The one dated notice we saw is the starter toolkit's deprecation on 27 March 2026, in a security bulletin (8 of 20). A sub-processor list updated 28 July 2026 and regional endpoints in 21 Regions, with the vault held in the Region the owner picks (18 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (16 items): https://www.anchorterminal.com/fixes/agentcore-identity.md (JSON https://www.anchorterminal.com/fixes/agentcore-identity.json) ### What we couldn't check - unchecked: the amazon.com registration date (1994-11-01) is carried from our other AWS listings, because WHOIS was not reachable from this session. - unchecked: the SDK service model files and the GitHub issue trackers were not read, and GitHub stars were not fetched. - unchecked: the AWS Customer Agreement, the DPA and the sub-processor table's rows were not re-read today. Only the sub-processor page's date was confirmed. - The day in July 2026 on which Private Key JWT launched was not established. The release notes are dated by month. - No per-user grant revocation call and no Identity-specific CloudTrail page were found in the pages read. Either may exist elsewhere in the IAM or CloudTrail documentation. - The Bedrock SLA's definitions refer to model APIs. AWS's FAQ says it applies to AgentCore, and how a claim for Identity would be measured is not stated. - The lead was accurate. One point to add is that the consent portal needs an AgentCore Gateway and an OIDC sign-in provider. ### Sources - AgentCore Identity guide: (seen 2026-10-08) - AgentCore developer guide llms.txt: (seen 2026-10-08) - quotas: (seen 2026-10-08) - release notes: (seen 2026-10-08) - obtain OAuth 2.0 access token: (seen 2026-10-08) - workload access tokens: (seen 2026-10-08) - session binding: (seen 2026-10-08) - scoping credential provider access: (seen 2026-10-08) - on-behalf-of token exchange: (seen 2026-10-08) - consent portal: (seen 2026-10-08) - consent portal prerequisites: (seen 2026-10-08) - consent portal targets: (seen 2026-10-08) - token vault encryption: (seen 2026-10-08) - compliance validation: (seen 2026-10-08) - GetResourceOauth2Token API reference: (seen 2026-10-08) - data-plane API reference llms.txt: (seen 2026-10-08) - control-plane operations: (seen 2026-10-08) - CreateOauth2CredentialProvider API reference: (seen 2026-10-08) - endpoints, AWS General Reference: (seen 2026-10-08) - pricing: (seen 2026-10-08) - AgentCore FAQ (SLA): (seen 2026-10-08) - Amazon Bedrock SLA: (seen 2026-10-08) - status feed, us-east-1: (seen 2026-10-08) - AWS Health Dashboard history file: (seen 2026-10-08) - AWS Service Terms: (seen 2026-10-08) - privacy notice: (seen 2026-10-08) - sub-processors: (seen 2026-10-08) - SOC services in scope: (seen 2026-10-08) - security.txt: (seen 2026-10-08) - security bulletin 2026-127-AWS: (seen 2026-10-08) - Free Tier FAQ: (seen 2026-10-08) - What's New search for AgentCore: (seen 2026-10-08) - AgentCore Python SDK repository and changelog: (seen 2026-10-08) - bedrock-agentcore on PyPI: (seen 2026-10-08) - bedrock-agentcore on npm: (seen 2026-10-08) - @aws-sdk/client-bedrock-agentcore on npm: (seen 2026-10-08) ## Who's behind it (provenance 88/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Amazon Web Services, Inc. | 20/20 | | Domain age | amazon.com, registered 1994-11-01 (31 years) | 15/15 | | Endpoint on the vendor's domain | bedrock-agentcore.us-east-1.amazonaws.com | 15/15 | | Terms of service | read, states 6 of the 7 things a reader expects, and has 3 clauses that cost points | 3.1/10 | | Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 | | Status page | health.aws.amazon.com/health/status | 10/10 | | Changelog | published | 10/10 | | security.txt | published but past its Expires date | 5/10 | The service pages are under aws.amazon.com and the endpoints are on amazonaws.com, an AWS domain. The AWS Service Terms show Last Updated 1 October 2026. Section 50 covers AI services and section 50.15 covers AgentCore Payments. No section names AgentCore Identity, so the universal terms and section 50 apply. The Privacy Notice shows Last Updated 18 May 2026 and gives Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109-5210. security.txt shows Expires 2026-09-24T16:25:03Z, read on 8 October 2026. It points to the AWS vulnerability disclosure programme on HackerOne and the policy at vdp.aws.security. The status page is drawn by script. We read the per-service feed (status.aws.amazon.com/rss/bedrock-agentcore-us-east-1.rss, no items) and the dashboard's history file. The domain registration date is carried from our other AWS listings. WHOIS was not reachable from this session. The release notes are dated by month only, and the RSS feed they mention was not found at doc-history.rss (404). ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://aws.amazon.com/service-terms/), read 2026-10-08, dated 2026-10-01, states 6 of the 7 things a reader expects. - To know. Says it may use customer content to train or improve models, and gives an opt-out. "You may instruct AWS not to use and store Amazon WorkSpaces AI Content processed by Amazon WorkSpaces AI Features to develop and improve the Service or technologies of AWS or its affiliates by configuring an AI services opt-out policy using AWS Organizations." - To know. Restricts automated access (costs points). "Reverse engineer, decompile, attempt to reconstruct, scrape, systematically collect, or duplicate Address Validation Data." - To know. Restricts benchmarking or competitive use (costs points). "You may not, and may not allow any third party to, use Amazon CloudWatch Network Monitoring, or any data or information made available through Amazon CloudWatch Network Monitoring, to, directly or indirectly, develop, improve, or offer a similar or competing product or service." - To know. Says the terms or the service can change without notice (costs points). "We may change, discontinue, or deprecate support for any third-party software development services at any time without prior notice." - Gives the date it was last updated. Last updated 2026-10-01. - Not found in the text. Names the governing law or courts. - Says how changes to the terms are announced. Gives 30 days of notice before a change. **Privacy policy** (https://aws.amazon.com/privacy/), read 2026-10-08, dated 2026-05-18, states 8 of the 8 things a reader expects. - To know. Says it sells personal data or shares it for advertising. "To help you receive more useful and relevant ads on other sites and services and to measure their effectiveness, AWS shares limited personal information with our advertising partners." - Gives the date it was last updated. Last updated 2026-05-18. - Says how long data is kept. For as long as needed, with no period named. - Gives a privacy contact. Names a data protection officer. - Says where data is transferred or stored. Relies on the Data Privacy Framework. - Also in the text (2026-10-08). The notice does not cover content that customers process, store or host on AWS. It refers to the customer agreement for how that content is handled. "This Privacy Notice does not apply to the “content” processed, stored, or hosted by our customers using AWS Offerings in connection with an AWS account." ## Live (updated 2026-10-09 09:26 UTC) - Right now: up, HTTP 404, 283 ms, checked 2026-10-09 09:26 UTC (get on `https://bedrock-agentcore.us-east-1.amazonaws.com`) - Uptime 24h 100.0% (20 probes) · 30 days 100.0% (20 probes) · p50 253 ms · p95 275 ms - Always current: https://www.anchorterminal.com/api/v1/live/agentcore-identity.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | OAuth token or API key requests for non-AWS resources | $0.01 | per 1,000 requests | Per successful request. No charge when used through AgentCore Runtime or Gateway | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - `GetResourceOauth2Token` covers three flows (USER_FEDERATION, M2M and ON_BEHALF_OF_TOKEN_EXCHANGE) and returns either an access token or an authorisation URL with a session URI. - 25 OAuth vendor values in `CreateOauth2CredentialProvider`, 24 built in (Google, GitHub, Slack, Salesforce, Microsoft, Atlassian and others) plus a custom OAuth 2.0 provider. - Quotas are published per operation, 200 requests a second for the three workload access token calls and 20 for each management call, all adjustable. - The token vault is encrypted with an AWS owned KMS key by default or a customer managed key, and IAM policies can name one workload identity and one credential provider. - $0.010 per 1,000 token or API key requests, with no extra charge when used through AgentCore Runtime or Gateway. ## Weaknesses - No operation to revoke or delete one user's stored grant was found. `forceAuthentication` clears a refresh token, and AWS says it cannot detect a revocation made at the provider. - The consent portal, launched 1 September 2026, attaches to one AgentCore Gateway with JWT inbound auth and cannot use GitHub, Slack, Salesforce, Atlassian or LinkedIn as its sign-in provider. - `GetWorkloadAccessTokenForUserId` takes a user ID string the platform does not verify, so the binding to a user rests on the caller and its IAM policy. - AWS states the service enforces no binding between workload identities and credential providers in one account beyond the IAM policy the owner writes. - No CloudTrail page for AgentCore Identity was found in the developer guide, though Gateway and Agent Registry each have one. ## Before you call it (notes for agents) 1. Get a workload access token first (`GetWorkloadAccessTokenForJWT` in production), then pass it as `workloadIdentityToken` to `GetResourceOauth2Token` or `GetResourceApiKey`. 2. When `GetResourceOauth2Token` returns `authorizationUrl` instead of `accessToken`, send the URL to the user and call again with the same `sessionUri` after consent. 3. For user-delegated flows, host an HTTPS callback, register it with `UpdateWorkloadIdentity` as an allowed return URL, and call `CompleteResourceTokenAuth` after checking the user's session. 4. Ask for refresh tokens in the provider's own way, such as `access_type=offline` in `customParameters` for Google or the `offline_access` scope for Microsoft and Atlassian. 5. Treat a returned token as possibly revoked. On a 401 from the resource server, retry with `forceAuthentication` set to true. ## Connect Install: ```bash pip install bedrock-agentcore ``` Through letme (picks today, calling later): https://letme.dev/agentcore-identity. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Descope Agentic Identity Hub | A | 78.1 | 14 | auth.oauth, auth.tokens, auth.consent, auth.agent-identity, auth.audit | no | https://www.anchorterminal.com/tools/descope-agentic-identity.md | | Aembit | BB | 70.5 | 147 | auth.oauth, auth.agent-identity, auth.tokens, auth.consent, auth.audit | no | https://www.anchorterminal.com/tools/aembit.md | | WorkOS Pipes and Agents | C | 59.9 | 485 | auth.oauth, auth.tokens, auth.consent, auth.agent-identity, auth.audit | no | https://www.anchorterminal.com/tools/workos-pipes.md | | Keycard | C | 56.2 | 572 | auth.oauth, auth.tokens, auth.consent, auth.agent-identity, auth.audit | no | https://www.anchorterminal.com/tools/keycard.md | | Microsoft Entra Agent ID | BB | 74.4 | 71 | auth.oauth, auth.agent-identity, auth.consent, auth.audit | no | https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md | | Scalekit AgentKit | BB | 71.9 | 111 | auth.oauth, auth.tokens, auth.consent, auth.agent-identity | no | https://www.anchorterminal.com/tools/scalekit-agentkit.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - AgentCore reached general availability in October 2025 in nine Regions, and the General Reference now lists control-plane and data-plane endpoints in 21 Regions (source: ) - Identity changes in 2026 per the release notes and What's New. On-behalf-of token exchange and VPC egress (April), existing Secrets Manager secrets as credential provider secrets (1 June), Private Key JWT client authentication (July), and the consent portal (1 September) (source: ) - On-behalf-of token exchange supports RFC 8693 token exchange and the RFC 7523 JWT authorisation grant, set per credential provider (source: ) - With Private Key JWT the private key stays in AWS KMS, AgentCore Identity asks KMS to sign each client assertion with RS256, PS256 or ES256, and each signing is recorded in CloudTrail (source: ) - Resource limits per account and Region are 11,000 workload identities, 50 OAuth2 credential providers, 50 API key credential providers and 50 payment credential providers, all adjustable (source: ) - AWS says access tokens returned by AgentCore are not guaranteed to be valid, because a revocation at the federated provider cannot be detected (source: ) - The consent portal keeps the OAuth flow on the server and the browser never holds a token. Its connection list is cached for up to 5 minutes after a target changes (source: ) - The AgentCore FAQ says the Amazon Bedrock SLA applies to AgentCore. That SLA, last updated 4 October 2023, commits to 99.9 per cent monthly uptime a Region with credits of 10, 25 and 100 per cent (source: ) - AWS's compliance page calls AgentCore HIPAA eligible and in scope for FedRAMP, SOC 2 and ISO 27001, and the SOC services list updated 11 August 2026 names Amazon Bedrock AgentCore (source: ) - AWS security bulletin 2026-127-AWS of 6 October 2026 covers two CVEs in `bedrock-agentcore-starter-toolkit`, a package deprecated on 27 March 2026. It concerns agent import, not AgentCore Identity (source: ) - AgentCore payments, a separate part of AgentCore, lets agents pay third-party sellers with x402 and MPP through payment credential providers stored by Identity. It is not a way to pay AWS (source: ) - The security.txt at aws.amazon.com shows Expires 2026-09-24 and was still expired on 8 October 2026 (source: ) - Weekly downloads. `bedrock-agentcore` on PyPI 1,421,946 and on npm 334,717, and `@aws-sdk/client-bedrock-agentcore` 1,070,970 in the week to 4 October 2026. These cover all of AgentCore, not Identity alone (source: ) ## Compare - [Aembit vs Amazon Bedrock AgentCore Identity](https://www.anchorterminal.com/compare/aembit-vs-agentcore-identity.md): BB 70.5 vs BB 74.8 - [Amazon Bedrock AgentCore Identity vs Arcade.dev](https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade.md): BB 74.8 vs B 66.9 - [Amazon Bedrock AgentCore Identity vs Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/compare/agentcore-identity-vs-auth0-ai-agents.md): BB 74.8 vs BB 71.4 - [Amazon Bedrock AgentCore Identity vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity.md): BB 74.8 vs A 78.1 - [Amazon Bedrock AgentCore Identity vs Keycard](https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard.md): BB 74.8 vs C 56.2 - [Amazon Bedrock AgentCore Identity vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id.md): BB 74.8 vs BB 74.4 - [Amazon Bedrock AgentCore Identity vs Nango](https://www.anchorterminal.com/compare/agentcore-identity-vs-nango.md): BB 74.8 vs B 67.7 - [Amazon Bedrock AgentCore Identity vs Scalekit AgentKit](https://www.anchorterminal.com/compare/agentcore-identity-vs-scalekit-agentkit.md): BB 74.8 vs BB 71.9 - [Amazon Bedrock AgentCore Identity vs Stytch Connected Apps](https://www.anchorterminal.com/compare/agentcore-identity-vs-stytch-connected-apps.md): BB 74.8 vs C 60.8 - [Amazon Bedrock AgentCore Identity vs Vercel Connect](https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect.md): BB 74.8 vs B 68.8 - [Amazon Bedrock AgentCore Identity vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/agentcore-identity-vs-workos-pipes.md): BB 74.8 vs C 59.9 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on amazon.com or one of its subdomains, or the README of github.com/aws/bedrock-agentcore-sdk-python. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "agentcore-identity", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Amazon Bedrock AgentCore Identity on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Amazon Bedrock AgentCore Identity on Anchor Terminal](https://www.anchorterminal.com/badges/agentcore-identity.svg)](https://www.anchorterminal.com/tools/agentcore-identity) ``` Plain link: ```html Amazon Bedrock AgentCore Identity on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Amazon Bedrock AgentCore Identity is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/agentcore-identity-dark.png - Light: https://www.anchorterminal.com/assets/share/agentcore-identity-light.png