All infographics

AGENT INFRASTRUCTURE / 07

Amazon Bedrock AgentCore

Build, deploy and operate AI agents

Download sheet SVG

THE BIG PICTURE

An agent with tools and memory

  1. ClientAn authenticated request
  2. Agent runtimeAgent code + model calls
  3. Gateway + toolsOptional tool integrations
AgentCore MemoryOptional context across interactions

Example using AgentCore Runtime: the agent can call tools through Gateway and use Memory for context. Identity controls access.

01A modular agent platform

  • AgentCore provides services for building, deploying and operating agents with your chosen models
  • Use its components together or independently; an agent framework is still a separate choice
  • Runtime hosts agents and tools; Gateway connects tools; Memory retains conversation context
  • Identity manages credentials; Policy governs tools; Observability and Evaluations assess behavior
  • Harness offers a managed agent loop; Registry catalogs agents, tools and related resources

02Runtime and session isolation

  • Serverless Runtime sessions use isolated microVMs with separate CPU, memory and filesystems
  • Reuse a runtime session ID for one conversation; keep different users in separate sessions
  • Runtime supports real-time responses, streaming and asynchronous agent workloads
  • Choose managed EC2 Instances when you need supported GPU workloads or longer-lived sessions
  • Filesystem persistence is configurable; durable business records still need a deliberate storage plan

03Deployments and endpoints

  • Deploy an ECR container image or use supported direct code deployment through the AgentCore tooling
  • Implement the contract for your protocol: HTTP, MCP, A2A or AG-UI have different interfaces
  • For HTTP agents, /invocations receives work and /ping reports readiness and background activity
  • Updating a Runtime creates an immutable version; named endpoints can stay pinned to a tested version
  • The DEFAULT endpoint follows the latest version; use a separate production endpoint for controlled rollouts

04Gateway and tool discovery

  • Gateway can convert APIs and Lambda functions into MCP-compatible tools behind one endpoint
  • Attach existing MCP servers as targets and aggregate their available tools for your agents
  • Tool definitions describe inputs; clear schemas and descriptions help the model select valid calls
  • Semantic tool search finds relevant tools without putting an entire large catalog in every prompt
  • Gateway also supports HTTP passthrough and inference targets; choose the target type explicitly

05Inbound and outbound access

  • Inbound authentication verifies callers; outbound credentials authorize access to a target service
  • Runtime calls can use IAM SigV4 signing or configured OAuth bearer-token authentication
  • Gateway authorization and its target credentials are separate configurations with separate permissions
  • A runtime execution role grants AWS API access; a model prompt does not grant that authority
  • Restrict model, tool and data permissions to the operations each agent actually needs

06Identity and credentials

  • AgentCore Identity represents agents as workload identities and manages access to credential providers
  • Credential providers support OAuth flows and API keys for external services
  • User-delegated OAuth access requires the user consent flow; autonomous access uses a suitable grant
  • Integrate an existing identity provider rather than creating another user directory for each agent
  • Keep tokens and API keys out of prompts and logs; scope credentials to the intended user and provider

07Short-term and long-term Memory

  • Short-term Memory stores conversation events grouped by actor ID and session ID
  • Long-term Memory extracts useful knowledge across sessions through configured memory strategies
  • Strategies can retain facts, user preferences and summaries; no strategy means no automatic extraction
  • Namespaces organize long-term records; choose retrieval scope and access rules for each tenant
  • Your agent retrieves and supplies relevant memories as context; this does not train the model weights

08Browser and Code Interpreter

  • Browser provides isolated sessions for navigating sites, filling forms and reading web content
  • Browser automation works with libraries such as Playwright; Live View allows human interaction
  • Custom browsers can record sessions to S3 for replay; recording is a configured feature
  • Code Interpreter executes Python, JavaScript and TypeScript in a managed sandbox for data tasks
  • Configure tool networking and roles, save useful outputs, and close sessions when work is complete

09Policy for tool governance

  • Associate a policy engine with Gateway to evaluate tool requests before the target is called
  • Policies can constrain the caller, tool and input parameters, such as a permitted transaction amount
  • Author rules in Cedar or compatible Dogwood; natural language authoring generates policies for review
  • The policy engine uses default-deny and forbid-wins semantics; test both allowed and denied calls
  • Gateway policy governs that access path; backend IAM and application authorization still matter

10Observability and debugging

  • AgentCore Observability exposes logs, metrics and traces through Amazon CloudWatch
  • OpenTelemetry-compatible instrumentation records model calls, tool spans and agent execution paths
  • Built-in metrics exist by default; detailed traces and additional spans depend on telemetry setup
  • Inspect session latency, token usage and error rates; separate model delays from failed tool calls
  • Choose log retention and redact sensitive content before adding prompts or tool results to telemetry

11Evaluations and quality checks

  • Evaluations measures agent and tool behavior using built-in evaluators or custom evaluation logic
  • Use on-demand or batch assessment for test data, and online evaluation for sampled production traces
  • Evaluation requires supported framework instrumentation and the relevant telemetry configuration
  • Compare task completion, answer quality and tool use before changing prompts, models or tool schemas
  • Quality scores help diagnose behavior; they do not replace deterministic tool access policies

12Practical deployment choices

  • Check Region availability for every chosen component, model and credential-provider integration
  • Budget for the AgentCore components you use plus model inference and downstream service charges
  • Keep development and production endpoints, credentials and memory scopes separate
  • Make tools retry-safe: a repeated model or network request must not repeat an unwanted side effect
  • Pin dependencies and validate auth, memory retrieval and tool failures with realistic test sessions

Go to the source

Use AWS documentation for current limits, availability, and pricing.

AgentCore overview and modular services AgentCore Runtime hosting and compute choices AgentCore Gateway AgentCore Identity AgentCore Memory AgentCore Observability