# Amazon Bedrock AgentCore Identity (slim) > Amazon Bedrock AgentCore Identity is an AWS service that gives agents workload identities, stores OAuth tokens and API keys in a token vault, and runs OAuth flows so agents can call third-party services for users or for themselves. - Full: https://www.anchorterminal.com/tools/agentcore-identity.md (~9,400 tokens) · this version ~1,780 tokens · JSON https://www.anchorterminal.com/tools/agentcore-identity.json · canonical https://www.anchorterminal.com/tools/agentcore-identity - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **BB · 74.8/100 · rank #64 of 842 · #2 in Agent auth & delegated access · agent-ready · confidence medium** Assessment: The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference. ## Facts - Kind: HTTP API · vendor: Amazon Web Services · category: Agent auth & delegated access · legal entity: Amazon Web Services, Inc. · provenance 88/100 - Endpoint: `https://bedrock-agentcore.us-east-1.amazonaws.com` (HTTP) - Auth: OAuth or key · pricing: Pay per use · x402: no · licence: Proprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0 - Probe metrics: not measured yet (probes haven't run) - Token flows: User-delegated authorisation code grant (USER_FEDERATION), client credentials (M2M) and on-behalf-of token exchange (RFC 8693 or RFC 7523), all through `GetResourceOauth2Token` - Providers: 24 built-in OAuth vendors, among them Google, GitHub, Slack, Salesforce, Microsoft, Atlassian, Okta, Auth0, Cognito, HubSpot, Notion, Zoom and Dropbox, plus a custom OAuth 2.0 provider and API key providers - Consent: An authorisation URL with session binding through the owner's HTTPS callback and `CompleteResourceTokenAuth`, or the hosted consent portal (since 1 September 2026), which needs an AgentCore Gateway with JWT inbound auth and an OIDC sign-in provider - Token storage: Token vault in the owner's AWS account and Region, encrypted with an AWS owned KMS key or a customer managed single-Region symmetric key. Client secrets can live in the owner's Secrets Manager. Refresh tokens are stored and used automatically - Agent identity: Workload identities with ARNs in a per-account directory, up to 11,000 a Region. Runtime and Gateway create one for each agent or gateway - Rate limits: 200 requests a second for each of the three workload access token calls, 20 a second for each create, get, update, delete and list call, adjustable - Revocation: No per-user revoke call found. Delete the credential provider, deny it in IAM, or set `forceAuthentication` to clear a refresh token and restart consent - SLA: The Amazon Bedrock SLA, 99.9% monthly uptime a Region, per the AgentCore FAQ - Regions: 21 Regions listed for `bedrock-agentcore..amazonaws.com` and `bedrock-agentcore-control..amazonaws.com` - SDKs: AWS CLI and AWS SDKs in nine languages, plus the AgentCore SDK for Python (`bedrock-agentcore` 1.24.1, 7 October 2026 on PyPI) and TypeScript (`bedrock-agentcore` 0.4.5 on npm), both Apache-2.0 - Prices: OAuth token or API key requests for non-AWS resources $0.01 per 1,000 requests - Scores: Reliability 85, Performance pending, Schema & documentation 88, Agent ergonomics 76, Security & auth 84, Payments & pricing 30, Task success pending, Maintenance & community 70, Transparency & trust 75 · total over the 7 assessed categories - Why: Reliability, AWS Health Dashboard with a per-service, per-Region feed for Bedrock AgentCore (20). · Schema & documentation, Service models for `bedrock-agentcore` and `bedrock-agentcore-control` ship in the AWS SDKs. · Agent ergonomics, Responses are small, a token or an authorisation URL with a session status, and list calls take `maxResults`. · Security & auth, IAM with SigV4 and short-lived role credentials, plus a workload access token that carries the agent's identity and the user's, and policies… · Payments & pricing, No x402, MPP or L402 for paying AWS. · Maintenance & community, The newest Identity change is the consent portal, announced 1 September 2026, 37 days before the check (20 of 30). · Transparency & trust, Closed service under the AWS Service Terms updated 1 October 2026, with Apache-2.0 SDKs (15 of 30). - Sources: 36, open questions: 7, both in the full twin - Capabilities: auth.oauth, auth.tokens, auth.consent, auth.agent-identity, auth.audit, infra.aws - JSON: https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/agentcore-identity.svg` or a link to https://www.anchorterminal.com/tools/agentcore-identity from a page on amazon.com or one of its subdomains, or the README of github.com/aws/bedrock-agentcore-sdk-python, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Get a workload access token first (`GetWorkloadAccessTokenForJWT` in production), then pass it as `workloadIdentityToken` to `GetResourceOauth2Token` or `GetResourceApiKey`. 2. When `GetResourceOauth2Token` returns `authorizationUrl` instead of `accessToken`, send the URL to the user and call again with the same `sessionUri` after consent. 3. For user-delegated flows, host an HTTPS callback, register it with `UpdateWorkloadIdentity` as an allowed return URL, and call `CompleteResourceTokenAuth` after checking the user's session. 4. Ask for refresh tokens in the provider's own way, such as `access_type=offline` in `customParameters` for Google or the `offline_access` scope for Microsoft and Atlassian. 5. Treat a returned token as possibly revoked. On a 401 from the resource server, retry with `forceAuthentication` set to true. ## Connect ```bash pip install bedrock-agentcore ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/agentcore-identity ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Descope Agentic Identity Hub | A | 78.1 | auth.oauth, auth.tokens, auth.consent, auth.agent-identity, auth.audit | https://www.anchorterminal.com/tools/descope-agentic-identity.min.md | | Aembit | BB | 70.5 | auth.oauth, auth.agent-identity, auth.tokens, auth.consent, auth.audit | https://www.anchorterminal.com/tools/aembit.min.md | | WorkOS Pipes and Agents | C | 59.9 | auth.oauth, auth.tokens, auth.consent, auth.agent-identity, auth.audit | https://www.anchorterminal.com/tools/workos-pipes.min.md | | Keycard | C | 56.2 | auth.oauth, auth.tokens, auth.consent, auth.agent-identity, auth.audit | https://www.anchorterminal.com/tools/keycard.min.md | | Microsoft Entra Agent ID | BB | 74.4 | auth.oauth, auth.agent-identity, auth.consent, auth.audit | https://www.anchorterminal.com/tools/microsoft-entra-agent-id.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)